Blog for hpHosts, and whatever else I feel like writing about ....

Saturday, 16 January 2010

Botnet domains + DNS resolution

Just a note folks, whilst investigating why the domains associated with botnets weren't resolving (been receiving a plethora of e-mails for everything from SendSpace to HM Revenue and Customs to HSBC etc etc), I did a check on OpenDNS's servers and discovered an issue with their Lodon based server (still failed to resolve even after a cache check).

All of their other servers are unaffected by whatever is causing the issue, and correctly resolve these domains.

As an FYI, the following is a list of those from the latest e-mails;

Subjects:

Notice of Underreported Income
Obtain Digital Certificate
This Document Contains Important Information
Please read this important information concerning your privacy
Fw: look
Re: your photo
A new settings file for the dev_null@it-mate.co.uk mailbox has just been released
Hello my friend , you have received a new greeting from somebody who cares you !!!
Fw: techrepublic@gauging.co.uk's photo


NB: The subject with "dev_null@it-mate.co.uk" in it, for those unaware, is the subject used for the OWA lookie-like, and contained whatever e-mail address it was being sent to, i.e. victim@their-domain.com

Links:

http://online.hmrc.gov.uk.yuf6.kr/SecurityWebApp/httpsmode/statement.php?id=428730841651702408676439861796&email=bodyshop@gaynorsmotorcompany.co.uk&tid=bodyshop-00000176220410UK
http://online.hmrc.gov.uk.yuf6.ne.kr/SecurityWebApp/httpsmode/statement.php?id=438381855880902695061364876864959676477948842673595379553191581446&email=hqwvoh@it-mate.co.uk&tid=hqwvoh-00000675902201UK
http://online.hmrc.gov.uk.yuf6.ne.kr/SecurityWebApp/httpsmode/statement.php?id=438381855880902695061364876864959676477948842673595379553191581446&email=hqwvoh@it-mate.co.uk&tid=hqwvoh-00000675902201UK
http://online.hmrc.gov.uk.olpiku5b.com.pl/SecurityWebApp/httpsmode/statement.php?id=888102433856823215207197652103993816158087526528379422593293919&email=baldybrothersfann@it-mate.co.uk&tid=baldybrothersfann-00000113885815UK
http://online.hmrc.gov.uk.olpiku5b.com.pl/SecurityWebApp/httpsmode/statement.php?id=888102433856823215207197652103993816158087526528379422593293919&email=baldybrothersfann@it-mate.co.uk&tid=baldybrothersfann-00000113885815UK
http://online.hmrc.gov.uk.olpiku5b.com.pl/SecurityWebApp/httpsmode/statement.php?id=888102433856823215207197652103993816158087526528379422593293919&email=baldybrothersfann@it-mate.co.uk&tid=baldybrothersfann-00000113885815UK
http://online.hmrc.gov.uk.olpiku5b.com.pl/SecurityWebApp/httpsmode/statement.php?id=888102433856823215207197652103993816158087526528379422593293919&email=baldybrothersfann@it-mate.co.uk&tid=baldybrothersfann-00000113885815UK
http://online.hmrc.gov.uk.olpiku5b.com.pl/SecurityWebApp/httpsmode/statement.php?id=888102433856823215207197652103993816158087526528379422593293919&email=baldybrothersfann@it-mate.co.uk&tid=baldybrothersfann-00000113885815UK
http://online.hmrc.gov.uk.olpiku5b.com.pl/SecurityWebApp/httpsmode/statement.php?id=888102433856823215207197652103993816158087526528379422593293919&email=baldybrothersfann@it-mate.co.uk&tid=baldybrothersfann-00000113885815UK
http://online.hmrc.gov.uk.yuf6.co.kr/SecurityWebApp/httpsmode/statement.php?id=77986821101726399897686260687866453064443516585276907027111012303404630054605&email=hqwvohn@it-mate.co.uk&tid=hqwvohn-00000909247537UK
http://online.hmrc.gov.uk.t111uy.me.uk/SecurityWebApp/httpsmode/statement.php?id=6227556064290035219392055848660162543047873437&email=hqwvoh@it-mate.co.uk&tid=hqwvoh-00000096450372UK
http://online.hmrc.gov.uk.tgyr5rtc.kr/SecurityWebApp/httpsmode/statement.php?id=507985516433377977129236649953144597794601&email=baldybrothersfannn@it-mate.co.uk&tid=baldybrothersfannn-00000344450625UK
http://online.hmrc.gov.uk.tgyr5rtc.kr/SecurityWebApp/httpsmode/statement.php?id=507985516433377977129236649953144597794601&email=baldybrothersfannn@it-mate.co.uk&tid=baldybrothersfannn-00000344450625UK
http://online.hmrc.gov.uk.tgyr5rtc.kr/SecurityWebApp/httpsmode/statement.php?id=507985516433377977129236649953144597794601&email=baldybrothersfannn@it-mate.co.uk&tid=baldybrothersfannn-00000344450625UK
http://online.hmrc.gov.uk.tgyr5rtc.kr/SecurityWebApp/httpsmode/statement.php?id=507985516433377977129236649953144597794601&email=baldybrothersfannn@it-mate.co.uk&tid=baldybrothersfannn-00000344450625UK
http://online.hmrc.gov.uk.tgyr5rtc.kr/SecurityWebApp/httpsmode/statement.php?id=507985516433377977129236649953144597794601&email=baldybrothersfannn@it-mate.co.uk&tid=baldybrothersfannn-00000344450625UK
http://online.hmrc.gov.uk.ujo9it.com.pl/SecurityWebApp/httpsmode/statement.php?id=8509392666869312311531809049611251194241034577170914126002518387256499790792&email=anjlee@paperdragon.info&tid=anjlee-00000864352228UK
http://www.hsbc.co.uk/1/2/HSBCINTEGRATION/banking.php?jsessionid=30250772278461137747641563692466383157613894539823377&email=maria@it-mate.co.uk
http://www.hsbc.co.uk.visdlpro1.com.pl/1/2/HSBCINTEGRATION/banking.php?jsessionid=30250772278461137747641563692466383157613894539823377&email=maria@it-mate.co.uk
http://www.hsbc.co.uk/1/2/HSBCINTEGRATION/banking.php?jsessionid=9244003359048209403608110207157652792565425229380158691271568924&email=dunganrfpkivaq@it-mate.co.uk
http://www.hsbc.co.uk.leptprs.or.kr/1/2/HSBCINTEGRATION/banking.php?jsessionid=9244003359048209403608110207157652792565425229380158691271568924&email=dunganrfpkivaq@it-mate.co.uk
http://www.hsbc.co.uk/1/2/HSBCINTEGRATION/banking.php?jsessionid=0623649991646807373416679766220612261050665329103042871724326353995821418&email=ces@it-mate.co.uk
http://www.hsbc.co.uk.dezzzzx.com.pl/1/2/HSBCINTEGRATION/banking.php?jsessionid=0623649991646807373416679766220612261050665329103042871724326353995821418&email=ces@it-mate.co.uk
http://www.hsbc.co.uk/1/2/HSBCINTEGRATION/banking.php?jsessionid=0623649991646807373416679766220612261050665329103042871724326353995821418&email=ces@it-mate.co.uk
http://www.hsbc.co.uk.dezzzzx.com.pl/1/2/HSBCINTEGRATION/banking.php?jsessionid=0623649991646807373416679766220612261050665329103042871724326353995821418&email=ces@it-mate.co.uk
http://www.hsbc.co.uk/1/2/HSBCINTEGRATION/banking.php?jsessionid=0623649991646807373416679766220612261050665329103042871724326353995821418&email=ces@it-mate.co.uk
http://www.hsbc.co.uk.dezzzzx.com.pl/1/2/HSBCINTEGRATION/banking.php?jsessionid=0623649991646807373416679766220612261050665329103042871724326353995821418&email=ces@it-mate.co.uk
http://www.hsbc.co.uk/1/2/HSBCINTEGRATION/banking.php?jsessionid=5475883831707584790056259275139130567901955318368102881574020&email=claire@richardsonbrown.co.uk
http://www.hsbc.co.uk.dezzzzd.com.pl/1/2/HSBCINTEGRATION/banking.php?jsessionid=5475883831707584790056259275139130567901955318368102881574020&email=claire@richardsonbrown.co.uk
http://www.hsbc.co.uk/1/2/HSBCINTEGRATION/banking.php?jsessionid=5475883831707584790056259275139130567901955318368102881574020&email=claire@richardsonbrown.co.uk
http://www.hsbc.co.uk.dezzzzd.com.pl/1/2/HSBCINTEGRATION/banking.php?jsessionid=5475883831707584790056259275139130567901955318368102881574020&email=claire@richardsonbrown.co.uk
http://www.hsbc.co.uk/1/2/HSBCINTEGRATION/banking.php?jsessionid=5475883831707584790056259275139130567901955318368102881574020&email=claire@richardsonbrown.co.uk
http://www.hsbc.co.uk.dezzzzd.com.pl/1/2/HSBCINTEGRATION/banking.php?jsessionid=5475883831707584790056259275139130567901955318368102881574020&email=claire@richardsonbrown.co.uk
http://www.sendspace.com.iko999jw.com.pl/file/shares/upload.php?file_id=sh5u3o9pejeb49w8vg871kigpl5tyn1mr31tvc6l0pscqckjx&email=ent-m1_com@it-mate.co.uk
http://www.sendspace.com.iko999jw.com.pl/file/shares/upload.php?file_id=sh5u3o9pejeb49w8vg871kigpl5tyn1mr31tvc6l0pscqckjx&email=ent-m1_com@it-mate.co.uk
http://www.sendspace.com.iko999je.com.pl/file/shares/upload.php?file_id=43j48eulqcfdqwxi98gcyi49nhu0y6swskctxrs9y&email=baldybrothersfannn@it-mate.co.uk
http://it-mate.co.uk/owa/service_directory/settings.php?email=dev_null@it-mate.co.uk&from=it-mate.co.uk&fromname=dev_null
http://it-mate.co.uk.vcrtp.eu/owa/service_directory/settings.php?email=dev_null@it-mate.co.uk&from=it-mate.co.uk&fromname=dev_null
http://it-mate.co.uk/owa/service_directory/settings.php?email=dev_null@it-mate.co.uk&from=it-mate.co.uk&fromname=dev_null
http://it-mate.co.uk.vcrtp.eu/owa/service_directory/settings.php?email=dev_null@it-mate.co.uk&from=it-mate.co.uk&fromname=dev_null
http://www.sendspace.com.iko999j0.com.pl/file/shares/upload.php?file_id=l25thky0ven5qmw356dxmsngwunwu035erpx14ke72565hz3p7&email=techrepublic@gauging.co.uk
http://www.sendspace.com.iko999j0.com.pl/file/shares/upload.php?file_id=l25thky0ven5qmw356dxmsngwunwu035erpx14ke72565hz3p7&email=techrepublic@gauging.co.uk
http://www.sendspace.com.iko999j1.com.pl/file/shares/upload.php?file_id=jnfiah3zmpx0d0n2avlgry4brpjwypfd3w14ln129adk3djw3q&email=technicdlsupport@it-mate.co.uk
http://www.sendspace.com.iko999j1.com.pl/file/shares/upload.php?file_id=jnfiah3zmpx0d0n2avlgry4brpjwypfd3w14ln129adk3djw3q&email=technicdlsupport@it-mate.co.uk


NB: The URL with "dev_null@it-mate.co.uk" in it, for those unaware, is the URL used for the OWA lookie-like, and contained whatever e-mail address it was being sent to, i.e. victim@their-domain.com

IP Details:

NB: A few were failing to resolve at the time of posting this, I've included them in the list anyway for the sake of clarity

127.0.0.1        it-mate.co.uk.vcrtp.eu
127.0.0.1        online.hmrc.gov.uk.olpiku5b.com.pl
127.0.0.1        online.hmrc.gov.uk.t111uy.me.uk
222.231.8.226        online.hmrc.gov.uk.tgyr5rtc.kr
127.0.0.1        online.hmrc.gov.uk.ujo9it.com.pl
127.0.0.1        online.hmrc.gov.uk.yuf6.co.kr
222.231.8.226        online.hmrc.gov.uk.yuf6.kr
127.0.0.1        online.hmrc.gov.uk.yuf6.ne.kr
127.0.0.1        www.hsbc.co.uk.dezzzzd.com.pl
127.0.0.1        www.hsbc.co.uk.dezzzzx.com.pl
127.0.0.1        www.hsbc.co.uk.leptprs.or.kr
127.0.0.1        www.hsbc.co.uk.visdlpro1.com.pl
190.53.161.236        www.sendspace.com.iko999j0.com.pl
190.82.255.179        www.sendspace.com.iko999j0.com.pl
190.213.51.157        www.sendspace.com.iko999j0.com.pl
196.217.223.186        www.sendspace.com.iko999j0.com.pl
201.13.152.173        www.sendspace.com.iko999j0.com.pl
201.164.132.205        www.sendspace.com.iko999j0.com.pl
201.165.216.169        www.sendspace.com.iko999j0.com.pl
201.233.36.12        www.sendspace.com.iko999j0.com.pl
114.27.157.60        www.sendspace.com.iko999j0.com.pl
117.197.210.44        www.sendspace.com.iko999j0.com.pl
121.96.205.109        www.sendspace.com.iko999j0.com.pl
125.0.40.185        www.sendspace.com.iko999j0.com.pl
189.78.48.239        www.sendspace.com.iko999j0.com.pl
189.105.169.151        www.sendspace.com.iko999j0.com.pl
190.34.46.168        www.sendspace.com.iko999j0.com.pl
196.217.223.186        www.sendspace.com.iko999j1.com.pl
201.13.152.173        www.sendspace.com.iko999j1.com.pl
201.164.132.205        www.sendspace.com.iko999j1.com.pl
201.165.11.26        www.sendspace.com.iko999j1.com.pl
201.165.216.169        www.sendspace.com.iko999j1.com.pl
201.233.36.12        www.sendspace.com.iko999j1.com.pl
114.27.157.60        www.sendspace.com.iko999j1.com.pl
121.96.205.109        www.sendspace.com.iko999j1.com.pl
124.28.64.25        www.sendspace.com.iko999j1.com.pl
125.0.40.185        www.sendspace.com.iko999j1.com.pl
189.78.48.239        www.sendspace.com.iko999j1.com.pl
189.105.169.151        www.sendspace.com.iko999j1.com.pl
190.34.46.168        www.sendspace.com.iko999j1.com.pl
190.82.255.179        www.sendspace.com.iko999j1.com.pl
190.213.51.157        www.sendspace.com.iko999j1.com.pl
196.217.223.186        www.sendspace.com.iko999je.com.pl
201.13.152.173        www.sendspace.com.iko999je.com.pl
201.164.132.205        www.sendspace.com.iko999je.com.pl
201.165.216.169        www.sendspace.com.iko999je.com.pl
201.233.36.12        www.sendspace.com.iko999je.com.pl
114.27.157.60        www.sendspace.com.iko999je.com.pl
117.198.149.60        www.sendspace.com.iko999je.com.pl
121.96.205.109        www.sendspace.com.iko999je.com.pl
124.28.64.25        www.sendspace.com.iko999je.com.pl
125.0.40.185        www.sendspace.com.iko999je.com.pl
189.78.48.239        www.sendspace.com.iko999je.com.pl
189.105.169.151        www.sendspace.com.iko999je.com.pl
190.34.46.168        www.sendspace.com.iko999je.com.pl
190.82.255.179        www.sendspace.com.iko999je.com.pl
190.213.51.157        www.sendspace.com.iko999je.com.pl
201.164.132.205        www.sendspace.com.iko999jw.com.pl
201.165.216.169        www.sendspace.com.iko999jw.com.pl
201.233.36.12        www.sendspace.com.iko999jw.com.pl
114.27.157.60        www.sendspace.com.iko999jw.com.pl
117.198.149.60        www.sendspace.com.iko999jw.com.pl
121.96.205.109        www.sendspace.com.iko999jw.com.pl
124.28.64.25        www.sendspace.com.iko999jw.com.pl
125.0.40.185        www.sendspace.com.iko999jw.com.pl
189.78.48.239        www.sendspace.com.iko999jw.com.pl
189.105.169.151        www.sendspace.com.iko999jw.com.pl
190.34.46.168        www.sendspace.com.iko999jw.com.pl
190.82.255.179        www.sendspace.com.iko999jw.com.pl
190.213.51.157        www.sendspace.com.iko999jw.com.pl
196.217.223.186        www.sendspace.com.iko999jw.com.pl
201.13.152.173        www.sendspace.com.iko999jw.com.pl


Incase you've not also noticed, those with numbers in the hostname, also appear to be valid where the number is 0-9, for example;

iko999j0.com.pl
iko999j1.com.pl
iko999j2.com.pl
iko999j3.com.pl
iko999j4.com.pl
iko999j5.com.pl
iko999j6.com.pl
iko999j7.com.pl
iko999j8.com.pl
iko999j9.com.pl

No comments: