A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #7495  by mc0blck
 Thu Jul 21, 2011 8:13 pm
Blocker: hxxp://xxx-mixxi.ru/ (95.211.111.80) -> hxxp://morexporno.ru/in.cgi?2 (95.211.111.80) -> hxxp://llz3porn.s3.amazonaws.com/index.htm (72.21.194.16) -> hxxp://llz3porn.s3.amazonaws.com/xxx_video.exe (72.21.194.16)
 #7500  by EP_X0FF
 Fri Jul 22, 2011 2:43 am
mc0blck wrote:
Blocker: hxxp://xxx-mixxi.ru/ (95.211.111.80) -> hxxp://morexporno.ru/in.cgi?2 (95.211.111.80) -> hxxp://llz3porn.s3.amazonaws.com/index.htm (72.21.194.16) -> hxxp://llz3porn.s3.amazonaws.com/xxx_video.exe (72.21.194.16)
Were off.

New trace.

hxxp://mixxporkaa.ru/ (95.211.111.80) -> hxxp://porno-vsetut.com/in.cgi?2 (95.211.111.80) -> hxxp://zx1uporn.s3.amazonaws.com/index.htm (72.21.203.149) -> hxxp://zx1uporn.s3.amazonaws.com/xxx_video.exe (72.21.203.149)
8906-798-31-34
8906-797-75-37
8909-157-39-71
8963-724-50-48
8909-157-82-99
update: Amazon has taken down the host

New trace.

hxxp://eroticzporn.ru/ (95.211.111.80) -> hxxp://eroticzporn.ru/video.htm (95.211.111.80) -> hxxp://uspornno.ru/in.cgi?2 -> hxxp://w2biporn.s3.amazonaws.com/index.htm (72.21.203.146) -> hxxp://w2biporn.s3.amazonaws.com/xxx_video.exe (72.21.203.146)

hxxp://w2biporn.s3.amazonaws.com DELETED
8906-798-28-52
8906-797-81-58
8963-650-12-80
8906-797-79-57
8963-634-37-89
hxxp://frtnnbc.s3.amazonaws.com/xxx_video.exe DELETED
8909-650-67-08
8906-798-05-28
8909-986-37-91
8909-157-42-20
8906-096-99-25
hxxp://ndcporka.s3.amazonaws.com/xxx_video.exe DELETED
8965-212-14-06
8906-798-31-24
8967-102-15-20
8906-096-61-82
8906-798-28-64
Last edited by EP_X0FF on Sat Jul 23, 2011 12:44 am, edited 7 times in total. Reason: update
 #7525  by mc0blck
 Fri Jul 22, 2011 8:14 pm
Blocker: hxxp://askpornkas.ru/ (95.211.111.80) -> hxxp://jjkpornoz.ru/in.cgi?2 (95.211.111.80) -> hxxp://cbipoxf.s3.amazonaws.com/index.htm (72.21.214.42) -> hxxp://cbipoxf.s3.amazonaws.com/xxx_video.exe (72.21.214.42)
 #7532  by EP_X0FF
 Sat Jul 23, 2011 1:20 am
Trace the same. Kids multipacked this one.

hxxp://sukazporka.s3.amazonaws.com/xxx_video.exe DELETED
8906-798-28-50
8909-650-39-08
8906-097-13-23
8906-097-10-11
8906-097-07-39
Last edited by EP_X0FF on Sun Jul 24, 2011 4:37 am, edited 1 time in total. Reason: edit
 #7536  by mc0blck
 Sat Jul 23, 2011 5:32 am
hxxp://mansboxporn.ru/ (95.211.111.80) -> hxxp://mansboxporn.ru/video.htm (95.211.111.80) -> hxxp://bhtdsnz.ru/in.cgi?2 (95.211.111.80) -> hxxp://ttedhoki.s3.amazonaws.com/index.htm (72.21.214.144) -> hxxp://ttedhoki.s3.amazonaws.com/xxx_video.exe (72.21.214.144)
 #7549  by EP_X0FF
 Sat Jul 23, 2011 3:10 pm
mc0blck wrote:
hxxp://mansboxporn.ru/ (95.211.111.80) -> hxxp://mansboxporn.ru/video.htm (95.211.111.80) -> hxxp://bhtdsnz.ru/in.cgi?2 (95.211.111.80) -> hxxp://ttedhoki.s3.amazonaws.com/index.htm (72.21.214.144) -> hxxp://ttedhoki.s3.amazonaws.com/xxx_video.exe (72.21.214.144)
Were off.

New trace.
hxxp://ninnporno.ru/ -> hxxp://ninnporno.ru/video.htm -> hxxp://jjkpornoz.ru/in.cgi?2 (95.211.111.80) -> hxxp://3rewporn.s3.amazonaws.com/index.htm -> hxxp://3rewporn.s3.amazonaws.com/xxx_video.exe
update
Were off.
8909-151-40-23
8909-155-78-09
8909-151-43-58
8909-151-34-70
8906-096-92-04
8965-361-12-10
8967-102-16-18
8967-102-15-22
8909-156-22-59
8909-650-79-84
8909-650-74-52
8909-157-81-02
8965-410-17-49
8906-798-30-15
8965-388-31-89
8906-798-30-19
8906-798-29-54
8967-041-42-04
8909-650-80-59
8909-650-39-53
8906-096-77-61
8906-096-77-25
8967-102-13-74
8906-097-03-68
8909-151-46-55
8909-650-81-51
8909-157-29-89
8965-212-13-53
8906-097-06-86
8906-797-82-20
8909-650-79-83
8909-622-14-32
8909-650-80-29
8906-797-82-87
8909-650-67-30
Last edited by EP_X0FF on Mon Jul 25, 2011 7:40 am, edited 13 times in total. Reason: edit
 #7621  by EP_X0FF
 Mon Jul 25, 2011 7:04 am
Several posts have been merged.

Starting from yesterday we will not anymore post links to Lock'Em'All ransom hosts here in this thread.
However table at first page will be updated with takedowns if they will take place.
 #7624  by EP_X0FF
 Mon Jul 25, 2011 8:23 am
nickvth2009 wrote:Does that rule now apply to all threads, or only for the Lock Em All thread?
Only for threads with ransoms. We are forced to do this because of leechers and lurkers and their parasitical behavior. Of course we will continue placing unlock codes (where they exists) in these threads.