Author Topic: hs.2-107.zlkon.lv (94.247.2.107)  (Read 13907 times)

0 Members and 1 Guest are viewing this topic.

April 08, 2009, 10:35:18 am
Read 13907 times

Mr Clean

  • Special Members
  • Hero Member

  • Offline
  • *

  • 331
Code: [Select]
hxxp://clipan.net/download/4f3334764e513d3df0c9d80d/Playboy.The.Mansion.Gold.Edition..exe

$ dig clipan.net +short
94.247.2.107

$ dig -x 94.247.2.107 +short
hs.2-107.zlkon.lv.

http://www.virustotal.com/analisis/266475edf5ef3cf171e605f1fbbf2cff
http://anubis.iseclab.org/?action=result&task_id=1810e467179cb12a42dc3e6c489742f0b


April 08, 2009, 12:57:42 pm
Reply #1

sowhat-x

  • Guest
...noticed the "Registry Values Modified" ? Cernel Network Ltd.,heh...

Code: [Select]
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Tcpip\​Parameters\​
DhcpNameServer  85.255.112.215,85.255.112.94
Code: [Select]
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Tcpip\​Parameters\​
NameServer      85.255.112.215,85.255.112.94
Code: [Select]
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Interfaces\​{B2B51064-BBF5-4528-B62B-E6D62A782874}
DhcpNameServer  85.255.112.215,85.255.112.94
Code: [Select]
HKLM\​SYSTEM\​CurrentControlSet\​Services\​Tcpip\​Parameters\​Interfaces\​{B2B51064-BBF5-4528-B62B-E6D62A782874}
NameServer      85.255.112.215,85.255.112.94

April 08, 2009, 01:00:18 pm
Reply #2

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
...noticed the "Registry Values Modified" ? Cernel Network Ltd.,heh...

Aha, DNSChanger !
Ruining the bad guy's day

April 08, 2009, 01:02:21 pm
Reply #3

sowhat-x

  • Guest

April 08, 2009, 03:17:12 pm
Reply #4

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Code: [Select]
http://clipan.net/download/5a45475a35673d3de0ebc52f/FlashPlayer.exe
http://ingclip.com/download/5a45475a35673d3de0ebc52f/FlashPlayer.exe

Micha told me that you can use any file name for those DNSChangers.
As long as the number inside the url is valid then you can use whatyoulikename.exe.

Ruining the bad guy's day

April 15, 2009, 07:21:45 am
Reply #5

SysAdMini

  • Administrator
  • Hero Member

  • Offline
  • *****

  • 3335
Code: [Select]
bulkso.com/download/6271737536513d3d6d8f85ef/mediaplayer.exehttp://www.virustotal.com/analisis/b96399b7b37b72dac880731f5ca9a521 15/40
Ruining the bad guy's day

April 18, 2009, 04:44:10 am
Reply #6

MarcusB

  • Guest
OSX DNSChanger
Quote
hxxp://geodawn.com/download/3933657064413d3d7de86a0f/CodecUpdate.v1.19.dmg
hxxp://pligeo.com/download/3933657064413d3d7de86a0f/CodecUpdate.v1.19.dmg