supercarsinfo.net(malware hosted in Russian Federation Antarktida-plus Llc)

supercarsinfo.net
Download URLs
http://0.0.0.0/l_distrib/knock_test_start.php?ver=1.25&sid=2900468492924 (0.0.0.0)
http://0.0.0.0/l_distrib/knock_test_start.php?type=2&step=1&err=&reg_ver=1%2E25&ver=1%2E25&sid=2900468492924 (0.0.0.0)

Outgoing connection to remote server: 0.0.0.0 TCP port 80
Outgoing connection to remote server: 0.0.0.0 TCP port 80DNS Lookup
Host Name IP Address
drivers-z2012.com 91.220.62.53
free-pac.net 91.220.62.53
r-golos.ru 91.220.62.53
vn-66.ru 91.220.62.53
Download URLs
http://91.220.62.53/distrib_serv/ip_list.php (drivers-z2012.com)
http://91.220.62.53/distrib_serv/ip_list.php (drivers-z2012.com)
http://91.220.62.53/distrib_serv/ip_list.php (drivers-z2012.com)

Outgoing connection to remote server: drivers-z2012.com TCP port 80
Outgoing connection to remote server: drivers-z2012.com TCP port 80
Outgoing connection to remote server: drivers-z2012.com TCP port 80
Outgoing connection to remote server: drivers-z2012.com TCP port 80

exe file:
http://www.multiupload.com/QAYPTCVO8J

infos about hosting:
http://whois.domaintools.com/91.220.62.53

Categories: Uncategorized