Blog for hpHosts, and whatever else I feel like writing about ....

Wednesday, 9 March 2011

Franebook.com: An update - part 3

Second verse, same as the first. Same registrar, same registrant, same multi-residential IP setup, same content - same everything.

usabbc.info - Vlad Marks / vladmarks@yahoo.ca eNom, Inc. (R126-LRMS)
utgroup.info - Vlad Marks / vladmarks@yahoo.ca eNom, Inc. (R126-LRMS)
waterspa.info - Vlad Marks / vladmarks@yahoo.ca eNom, Inc. (R126-LRMS)
werace.info - Vlad Marks / vladmarks@yahoo.ca eNom, Inc. (R126-LRMS)
xlnic.info - Vlad Marks / vladmarks@yahoo.ca eNom, Inc. (R126-LRMS)
xxlpool.info - Vlad Marks / vladmarks@yahoo.ca eNom, Inc. (R126-LRMS)
zakabi.info - Vlad Marks / vladmarks@yahoo.ca eNom, Inc. (R126-LRMS)
zencarbon.info - Vlad Marks / vladmarks@yahoo.ca eNom, Inc. (R126-LRMS)
zgjjw.info - Vlad Marks / vladmarks@yahoo.ca eNom, Inc. (R126-LRMS)
zintec.info - Vlad Marks / vladmarks@yahoo.ca eNom, Inc. (R126-LRMS)


The IP list count currently stands at 63, so if it is a botnet, it's a relatively small one compared to others.

109.110.40.235    -    (Failed resolution    -    196949    -    196949 109.110.32.0/19 PODRYAD-AS Kozitskiy A.M. PI
109.184.201.194    -    (109-184-201-194.dynamic.mts-nn.ru    -    25405    -    25405 109.184.0.0/16 NMTS-AS OJSC VolgaTelecom, Nizhny Novgorod
109.184.225.161    -    (109-184-225-161.dynamic.mts-nn.ru    -    25405    -    25405 109.184.0.0/16 NMTS-AS OJSC VolgaTelecom, Nizhny Novgorod
109.229.103.134    -    (134-103-229-109.broadband.telenettv.ru    -    49136    -    49136 109.229.103.0/24 TELECOM-NETWORKS-AS Telecommunication networks JSC
109.87.243.137    -    (Failed resolution    -    13188    -    13188 109.87.128.0/17 BANKINFORM-AS Ukraine
109.94.72.11    -    (109-94-72-11.an-net.ru    -    50060    -    50060 109.94.72.0/23 ANNET Annet Ltd.
112.202.207.15    -    (112.202.207.15.pldt.net    -    9299    -    9299 112.202.192.0/19 IPG-AS-AP Philippine Long Distance Telephone Company
122.173.86.128    -    (ABTS-North-Dynamic-128.86.173.122.airtelbroadband.in    -    24560    -    24560 122.173.0.0/17 AIRTELBROADBAND-AS-AP Bharti Airtel Ltd., Telemedia Services
122.174.84.73    -    (ABTS-TN-dynamic-073.84.174.122.airtelbroadband.in    -    24560    -    24560 122.174.0.0/16 AIRTELBROADBAND-AS-AP Bharti Airtel Ltd., Telemedia Services
122.3.47.21    -    (122.3.47.21.pldt.net    -    9299    -    9299 122.3.32.0/19 IPG-AS-AP Philippine Long Distance Telephone Company
123.24.185.18    -    (Failed resolution    -    45899    -    45899 123.24.128.0/18 VNPT-AS-VN VNPT Corp
124.104.133.3    -    (124.104.133.3.pldt.net    -    9299    -    9299 124.104.128.0/19 IPG-AS-AP Philippine Long Distance Telephone Company
174.6.12.212    -    (S01060015b7c35258.vc.shawcable.net    -    6327    -    6327 174.6.0.0/16 SHAW - Shaw Communications Inc.
178.239.117.60    -    (Failed resolution    -    41989    -    41989 178.239.112.0/20 KTBAC-AS ET BAC Dobrinka Bacanova
178.74.246.81    -    (cpe-178-74-246-81.enet.vn.ua    -    49223    -    49223 178.74.192.0/18 EVEREST-AS _Everest_ Broadcasting Company Ltd
186.18.175.203    -    (cpe-186-18-175-203.telecentro-reversos.com.ar    -    27747    -    27747 186.18.172.0/22 Telecentro S.A.
199.48.221.14    -    (pppoe-199-48-221-14.isnwireless.ca    -    33040    -    33040 199.48.216.0/21 ISNW-AS - ISN Wireless
201.213.212.250    -    (201-213-212-250.net.prima.net.ar    -    10481    -    10481 201.213.192.0/19 Prima S.A.
201.254.31.122    -    (201-254-31-122.speedy.com.ar    -    22927    -    22927 201.254.0.0/16 Telefonica de Argentina
24.121.132.155    -    (Failed resolution    -    25994    -    25994 24.121.132.0/24 NPG-001 - NPG Cable, INC
24.21.222.13    -    (c-24-21-222-13.hsd1.or.comcast.net    -    33490    -    7922 24.16.0.0/13 COMCAST-7922 - Comcast Cable Communications, Inc.
24.34.229.143    -    (c-24-34-229-143.hsd1.ma.comcast.net    -    7015    -    7015 24.34.128.0/17 COMCAST-7015 - Comcast Cable Communications Holdings, Inc
46.118.73.142    -    (SOL-FTTB.142.73.118.46.sovam.net.ua    -    12530    -    12530 46.118.64.0/18 GOLDENTELECOM-UKRAINE Golden Telecom
46.146.18.231    -    (net18-231.perm.ertelecom.ru    -    12768    -    12768 46.146.16.0/22 ER-TELECOM-AS JSC ER-Telecom
46.158.222.119    -    (Failed resolution    -    25490    -    25490 46.158.0.0/16 STC-AS Southen Telecommunication Autonomous Systems
46.8.157.233    -    (Failed resolution    -    51501    -    51501 46.8.128.0/17 KHD-AS Khabarovsk home networks Ltd
61.7.189.248    -    (Failed resolution    -    18252    -    18252 61.7.128.0/18 CAT-AS-AP The Communication Authoity of Thailand, CAT
61.81.70.69    -    (Failed resolution    -    4766    -    4766 61.80.0.0/14 KIXS-AS-KR Korea Telecom
64.188.224.203    -    (host-64-188-224-203.windjammercable.net    -    1246    -    1246 64.188.224.0/22 WINDJAMMER - Windjammer Communications LLC
67.187.251.116    -    (c-67-187-251-116.hsd1.ca.comcast.net    -    33651    -    33651 67.187.240.0/20 CMCS - Comcast Cable Communications, Inc.
67.191.123.51    -    (c-67-191-123-51.hsd1.fl.comcast.net    -    20214    -    20214 67.191.112.0/20 COMCAST-20214 - Comcast Cable Communications Holdings, Inc
67.48.25.133    -    (mta-67-48-25-133.new.res.rr.com    -    11955    -    11955 67.48.16.0/20 SCRR-11955 - Road Runner HoldCo LLC
69.28.212.93    -    (Failed resolution    -    13768    -    13768 69.28.212.0/22 PEER1 - Peer 1 Network Inc.
71.164.175.141    -    (pool-71-164-175-141.dllstx.fios.verizon.net    -    19262    -    19262 71.164.128.0/17 VZGNI-TRANSIT - Verizon Online LLC
76.105.44.171    -    (c-76-105-44-171.hsd1.ca.comcast.net    -    33651    -    33651 76.105.0.0/18 CMCS - Comcast Cable Communications, Inc.
76.113.188.136    -    (c-76-113-188-136.hsd1.mn.comcast.net    -    13367    -    13367 76.113.128.0/17 COMCAST-13367 - Comcast Cable Communications Holdings, Inc
76.123.172.58    -    (c-76-123-172-58.hsd1.ms.comcast.net    -    22258    -    22258 76.123.128.0/18 COMCAST-22258 - Comcast Cable Communications Holdings, Inc
77.106.199.225    -    (Failed resolution    -    42110    -    42110 77.106.192.0/20 STK-AS Closed Joint Stock Company Sochitelecom
77.121.124.29    -    (29.124.121.77.pool.smart.vn.ua    -    38962    -    38962 77.121.96.0/19 UA-SMART-AS Broadcasting company _Smart_ Ltd
77.77.245.211    -    (cable-77-77-245-211.dynamic.telemach.ba    -    42560    -    42560 77.77.192.0/18 BA-TELEMACH-AS Telemach BiH
77.87.80.54    -    (nat-77-87-80-54.gw4.omsk.multinex.ru    -    41771    -    41771 77.87.80.0/21 MKC-OMSK-AS MultiCable Networks LLC
78.106.176.47    -    (78-106-176-47.broadband.corbina.ru    -    8402    -    8402 78.106.176.0/21 CORBINA-AS Corbina Telecom
78.36.249.208    -    (78-36-249-208.dynamic.pskov.dslavangard.ru    -    8997    -    8997 78.36.0.0/15 ASN-SPBNIT OJSC North-West Telecom Autonomous System
81.56.83.158    -    (lan31-1-81-56-83-158.fbx.proxad.net    -    12322    -    12322 81.56.0.0/15 PROXAD Free SAS
82.240.161.55    -    (lam06-3-82-240-161-55.fbx.proxad.net    -    12322    -    12322 82.224.0.0/11 PROXAD Free SAS
85.65.29.199    -    (85.65.29.199.dynamic.barak-online.net    -    1680    -    1680 85.64.0.0/15 NV-ASN 013 NetVision Ltd.
86.61.43.146    -    (BSN-61-43-146.dial-up.dsl.siol.net    -    5603    -    5603 86.61.0.0/17 SIOL-NET Telekom Slovenije d.d.
87.255.93.95    -    (Failed resolution    -    15836    -    15836 87.255.64.0/19 AXAUTSYS ARAX I.S.P.
90.24.153.22    -    (AMontsouris-551-1-18-22.w90-24.abo.wanadoo.fr    -    3215    -    3215 90.24.128.0/17 AS3215 France Telecom - Orange
91.200.74.206    -    (MICROSOF-CDCC83    -    43815    -    43815 91.200.72.0/22 MMV-AS MMV
91.218.17.207    -    (pool-91-218-17-207.optima-east.net    -    48882    -    48882 91.218.16.0/22 OPTIMA-SHID-AS Optima-Shid LLC
92.114.244.200    -    (host-static-92-114-244-200.moldtelecom.md    -    8926    -    8926 92.114.128.0/17 MOLDTELECOM-AS Moldtelecom Autonomous System
92.153.130.181    -    (AMarseille-553-1-202-181.w92-153.abo.wanadoo.fr    -    3215    -    3215 92.153.0.0/16 AS3215 France Telecom - Orange
93.124.127.65    -    (host-93-124-127-65.dsl.sura.ru    -    24612    -    24612 93.124.0.0/17 PENZA-SVIAZINFORM-AS JSC Volgatelecom, Penza branch
93.124.41.254    -    (host-93-124-41-254.dsl.sura.ru    -    24612    -    24612 93.124.0.0/17 PENZA-SVIAZINFORM-AS JSC Volgatelecom, Penza branch
93.170.43.94    -    (93.170.43.94.airexpress.net.ua    -    51930    -    51930 93.170.40.0/21 AIREXPRESS-AS Buzova-Budinvest Ltd.
94.248.25.153    -    (94-248-25-153.dynamic.peoplenet.ua    -    42396    -    42396 94.248.0.0/18 PPLNETUA-AS PJSC Telesystems of Ukraine
94.41.159.5    -    (94.41.159.5.dynamic.ufanet.ru    -    24955    -    24955 94.41.144.0/20 UBN-AS OJSC _Ufanet_
95.69.141.135    -    (customer-95-69-141-135.airbites.kh.ua    -    42335    -    42335 95.69.128.0/18 SPHERE-UA Sphere Ltd.
96.245.13.28    -    (pool-96-245-13-28.phlapa.fios.verizon.net    -    19262    -    19262 96.245.0.0/16 VZGNI-TRANSIT - Verizon Online LLC
97.101.74.121    -    (121.74.101.97.cfl.res.rr.com    -    33363    -    33363 97.100.0.0/14 BHN-TAMPA - BRIGHT HOUSE NETWORKS, LLC
98.142.221.7    -    (urlproxy.registrar-servers.com    -    46562    -    46562 98.142.220.0/23 COLO-AT-55-LLC - Colo at 55, LLC
98.196.164.102    -    (c-98-196-164-102.hsd1.tx.comcast.net    -    33662    -    7922 98.192.0.0/10 COMCAST-7922 - Comcast Cable Communications, Inc.


References:

franebook: An update - Part 2
http://hphosts.blogspot.com/2011/03/franebookcom-update-part-2.html

franebook: An update
http://hphosts.blogspot.com/2011/03/franebook-update.html

Facebook app pages serve up Javascript and Acai Berry spam
http://sunbeltblog.blogspot.com/2011/03/facebook-app-pages-serve-up-javascript.html

2 comments:

ibix said...

Some ip's Franebook resolved to over the last 24 hours:

101.0.32.34, Static-BPIPL-101.0.32-34.com, @3/15/2011 9:51:37 AM,
108.23.15.167, pool-108-23-15-167.lsanca.fios.verizon.net, @3/15/2011 1:21:16 PM,
109.67.194.37, No Host Resolved
110.159.12.87, No Host Resolved, @3/15/2011 3:08:06 PM,
115.135.193.152, 135.115.in-addr.arpa, @3/15/2011 7:37:58 AM,
121.58.204.73, No Host Resolved, @3/15/2011 5:19:45 AM,
121.73.229.246, 121-73-229-246.broadband.telstraclear.net
122.174.106.81, ABTS-TN-dynamic-081.106.174.122.airtelbroadband.in, @3/15/2011 10:16:14 AM,
122.3.47.21, 122.3.47.21.pldt.net, @3/15/2011 11:56:54 AM,
122.57.91.241, 122-57-91-241.jetstream.xtra.co.nz, @3/15/2011 6:54:24 AM,
174.45.199.208, host-174-45-199-208.chy-wy.client.bresnan.net, @3/15/2011 9:47:21 AM,
174.52.227.49, c-174-52-227-49.hsd1.ut.comcast.net, @3/15/2011 7:57:08 AM,
178.53.173.20, No Host Resolved, @3/15/2011 7:59:31 AM,
178.67.192.143, No Host Resolved, @3/15/2011 7:58:45 AM,
178.90.76.194, No Host Resolved, @3/15/2011 11:56:17 AM,
190.162.109.105, pc-105-109-162-190.cm.vtr.net, @3/15/2011 2:08:02 PM,
199.48.221.14, pppoe-199-48-221-14.isnwireless.ca, @3/15/2011 5:59:05 AM,
201.215.126.10, pc-10-126-215-201.cm.vtr.net
212.142.75.249, balticom-142-75-249.balticom.lv, @3/15/2011 1:35:32 PM,
212.50.105.223, No Host Resolved, @3/15/2011 5:50:00 AM,
212.59.119.93, No Host Resolved, @3/15/2011 2:29:09 PM,
212.59.122.115, No Host Resolved, @3/15/2011 6:51:30 AM,
24.107.178.151, 24-107-178-151.dhcp.stls.mo.charter.com
24.121.132.155, No Host Resolved, @3/15/2011 5:03:24 AM,
24.147.19.94, c-24-147-19-94.hsd1.ma.comcast.net, @3/15/2011 7:22:56 AM,
24.34.229.143, c-24-34-229-143.hsd1.ma.comcast.net
24.60.168.190, c-24-60-168-190.hsd1.ma.comcast.net
24.63.88.229, c-24-63-88-229.hsd1.ma.comcast.net
24.7.252.34, c-24-7-252-34.hsd1.il.comcast.net
46.118.77.179, SOL-FTTB.179.77.118.46.sovam.net.ua, @3/15/2011 10:52:20 AM,
46.118.87.53, SOL-FTTB.53.87.118.46.sovam.net.ua, @3/15/2011 11:46:31 AM,
46.191.147.22, 46.191.147.22.dynamic.ufanet.ru
46.8.157.233, No Host Resolved
60.234.225.218, 60-234-225-218.bitstream.orcon.net.nz
61.7.186.185, No Host Resolved
62.132.123.10, static.kpn.net, @3/15/2011 7:53:05 AM,
62.205.240.74, No Host Resolved, @3/15/2011 2:47:30 PM,
64.188.224.203, host-64-188-224-203.windjammercable.net, @3/15/2011 12:13:59 PM,
65.30.15.186, cpe-65-30-15-186.wi.res.rr.com
66.215.154.29, 66-215-154-29.dhcp.ccmn.ca.charter.com
67.160.177.219, c-67-160-177-219.hsd1.wa.comcast.net
67.169.125.78, c-67-169-125-78.hsd1.ca.comcast.net
67.172.169.165, c-67-172-169-165.hsd1.ca.comcast.net, @3/15/2011 10:38:21 AM,
67.187.251.116, c-67-187-251-116.hsd1.ca.comcast.net
67.191.123.51, c-67-191-123-51.hsd1.fl.comcast.net
67.199.174.56, No Host Resolved, @3/15/2011 11:14:27 AM,
70.20.27.243, pool-70-20-27-243.bstnma.fios.verizon.net, @3/15/2011 12:27:10 PM,
71.164.175.141, pool-71-164-175-141.dllstx.fios.verizon.net
71.232.171.38, c-71-232-171-38.hsd1.ma.comcast.net, @3/15/2011 2:05:24 PM,
74.100.45.105, pool-74-100-45-105.lsanca.fios.verizon.net
74.105.138.170, pool-74-105-138-170.nwrknj.fios.verizon.net
74.78.81.155, cpe-74-78-81-155.maine.res.rr.com, @3/15/2011 6:33:41 AM,
75.83.238.135, cpe-75-83-238-135.socal.res.rr.com, @3/15/2011 11:08:46 AM,
76.105.44.171, c-76-105-44-171.hsd1.ca.comcast.net, @3/15/2011 4:01:16 AM,
76.122.248.217, c-76-122-248-217.hsd1.tn.comcast.net
76.123.172.58, c-76-123-172-58.hsd1.ms.comcast.net
76.19.241.111, c-76-19-241-111.hsd1.nh.comcast.net, @3/15/2011 8:34:34 AM,
77.169.131.94, ip4da9835e.direct-adsl.nl
77.232.38.99, No Host Resolved, @3/15/2011 11:31:37 AM,
77.52.206.69, 77-52-206-69.dialup.umc.net.ua, @3/15/2011 12:28:47 PM,
77.52.232.106, 77-52-232-106.dialup.umc.net.ua
78.101.44.25, No Host Resolved, @3/15/2011 2:35:38 PM,

ibix said...

and a few more:

78.30.208.154, 154-208-30-78.host.sevstar.net, @3/15/2011 5:14:03 AM,
82.155.10.140, bl6-10-140.dsl.telepac.pt, @3/15/2011 5:59:12 AM,
85.175.235.236, No Host Resolved, @3/15/2011 12:57:03 PM,
85.65.29.199, 85.65.29.199.dynamic.barak-online.net
85.65.29.199, 85.65.29.199.dynamic.barak-online.net, @3/15/2011 3:54:58 AM,
91.195.231.237, No Host Resolved, @3/15/2011 6:53:06 AM,
91.200.74.206, No Host Resolved
92.119.22.142, cust-22-142.on5.ontelecoms.gr
93.85.17.206, No Host Resolved, @3/15/2011 1:46:41 PM,
95.105.25.110, 95.105.25.110.dynamic.str.ufanet.ru
95.52.209.29, No Host Resolved, @3/15/2011 2:11:06 PM,
95.57.246.131, No Host Resolved, @3/15/2011 2:04:37 PM,
95.69.141.135, customer-95-69-141-135.airbites.kh.ua
96.245.13.28, pool-96-245-13-28.phlapa.fios.verizon.net, @3/15/2011 4:03:33 AM,
98.196.164.102, c-98-196-164-102.hsd1.tx.comcast.net