flipcoin.co(Pony hosted in United States Piscataway Shock Hosting Llc)

Domain : "flipcoin.co"

Resolved [ flipcoin.co ] To [ 144.208.125.231 ]

Sample : hxxp://flipcoin.co/pony/bin.exe

Random panels and samples from Gaudox,Neutrino,Solar,Pony,Herpes,Betabot here : hxxp://flipcoin.co/

Hosting infos :
http://whois.domaintools.com/144.208.125.231

rkskumzb.com(SageCrypt ransomware hosted in Russian Federation Samara Jsc Er-telecom Holding

Domains used by the sample :

rkskumzb.com 46.0.141.233
gesofgamd.com 46.173.218.203

Path from webserver :

 /ykbi9t1w8/index.php


Sample : hxxps://formwest.co/nst.exe

Hosting infos :
https://whois.domaintools.com/46.0.141.233

majcc2.punkdns.vip(Imminent Monitor Hosted in Russian Federation Moscow Anmaxx Internett-tjenester)

Domain : majcc2.punkdns.vip

Host and Port : 185.145.44.11:1414

Sample : hxxp://ssd4.pdns.cz/1500/s500.exe

Hosting Infos :
https://whois.domaintools.com/185.145.44.11

Gen:Variant.Symm(Hosted In China ASN: 9808 (Guangdong Mobile Communication Co.Ltd.)

Domain : qq120668082.f3322.net

Host and Port : 120.210.207.142:5551

Sample : hxxp://117.41.185.216:9999/mimi.exe

Hosting Infos : 
https://whois.domaintools.com/120.210.207.142

farawayer.ru(Pony Hosted In Russian Federation Lenina Dom Dlya Saita Llc)

Sample here : hxxp://farawayer.ru/chibum/fire/blessing/micro.exe

Panel : http://farawayer.ru/chibum/fire/blessing/gate.php

All the rest here : http://farawayer.ru/chibum/fire/blessing/

Hosting Infos : http://whois.domaintools.com/91.227.68.183