avtobizz.ru(Locky Ransomware Hosted In Romania Craiova Nforce Entertainment B.v.)

Protected by cloudflare but not hard to find the hoster.

avtobizz.ru 104.31.89.136

Use hxxp://www.skypeipresolver.net/cloudflare.php to find the real ip.

Locky here is hosted by blazinfast.io

Logs from infected computers and samples here : hxxp://213.108.44.167/logiplya/

Hosting Infos :

http://whois.domaintools.com/185.11.145.10

serv6625.servep2p.com(Win32.Trojan.WisdomEyes Hosted In Colombia Bogota Unus Inc.)

Domain : serv6625.servep2p.com

Port : 6625

Sample : hxxp://107.170.8.163/dwn/winsys.exe

Hosting Infos :
http://whois.domaintools.com/128.90.115.105

myfirstdatibon.ru(UDS:DangerousObject.Multi.Generic)

Domain : myfirstdatibon.ru

domain:        MYFIRSTDATIBON.RU
nserver:       ns1.uldiok.at.
nserver:       ns2.uldiok.at.
nserver:       ns3.uldiok.at.
nserver:       ns4.uldiok.at.
state:         REGISTERED, NOT DELEGATED, UNVERIFIED
person:        Private Person
registrar:     ARDIS-RU
admin-contact: http://ardis.ru/whois/
created:       2016.02.20
paid-till:     2017.02.20
free-date:     2017.03.23
source:        TCI

Sample : hxxp://85.93.31.152/files/IeH4uk.exe

The rest of samples : hxxp://85.93.31.152/files/


Hosting Infos :
http://who.is/whois/myfirstdatibon.ru

eiqdfngoghledf.pw(Locky Ransomware Hosted In France ASN: 16276 OVH SAS)

Domains :

eiqdfngoghledf.pw
emijtrjhnrddoxr.org
ofsrsykqd.pl
whrilkltsrvggxsj.click
fphnnnkaei.org
ntdvwoousyc.pl
kmarheql.info
pobqrwoxltcy.pl
eyetuesq.ru
djxmxiahj.biz
kdyoevbcxy.su
ajqjdjblfdjti.work
clsfnbwpekrxmcj.xyz
qkpdsttc.pw
ihxkjsgmloij.work
rhiqtgs.info
jbtnnvqkwakpitxk.pl
awcweto.xyz

URL'S :

hxxp://93.170.131.108/submit.php
hxxp://5.135.76.18/submit.php
hxxp://82.146.37.200/submit.php


Sample :
hxxp://mundogostoso.com.br/zFN1Lg.exe

Hosting infos :
http://whois.domaintools.com/5.135.76.18

jcngtodnjlcr.it(Ransomware Locky Hosted In United Kingdom Belfast Barefruit Ltd.)

Domains :

jcngtodnjlcr.it
mneqmmunsee.us
xdryy.uk
awrobhtsxpmcro.tf
boapooihhqkthvm.de
gfyttdu.ru
dpirlysijsbyy.pm
whetujmpw.pm

POSTs files to a webserver :

   "POST /main.php HTTP/1.1
    Host: 5.34.183.136

Sample : hxxp://bitmeyenkartusistanbul.com/system/logs/87h754/fXBvKHcBd.exe

Hosting Infos :
http://whois.domaintools.com/92.242.144.2