Sponsored by..

Tuesday 31 July 2012

Something evil on 194.28.115.150 and lasimp04risoned.rr.nu

The following domains appear to be part of an ongoing injection attack (using lasimp04risoned.rr.nu at present). They are hosted by black-hat web host Specialist ISP in Transnistria. Block the IP range of 194.28.112.0 - 194.28.115.255 (194.28.112.0/22) is a very good idea as this is one of the worst netblocks I know of.

aelis30greek.rr.nu
aff29ili.rr.nu
aljo73hnsto.rr.nu
ambers00supplem.rr.nu
ano98the.rr.nu
appoin62tmentba.rr.nu
asciia28rmcover.rr.nu
ati92oni.rr.nu
ation82gamma.rr.nu
avia83resou.rr.nu
bear37sall.rr.nu
bitr07aryc.rr.nu
bles41steve.rr.nu
carrie01rskans.rr.nu
che59mica.rr.nu
chn34olo.rr.nu
comme17rcial.rr.nu
cons63isten.rr.nu
cos69tbu.rr.nu
cov59erm.rr.nu
cthu85srisc.rr.nu
ctsc60anli.rr.nu
eates01publi.rr.nu
ection18depres.rr.nu
elew72isst.rr.nu
enedm79ultina.rr.nu
enegat43ivecon.rr.nu
engag75edfol.rr.nu
enge75sfra.rr.nu
enormousw1illa.com
ens122zzzddazz.com
entio21nsamba.rr.nu
esgen48erally.rr.nu
eside00ntwin.rr.nu
fee89edi.rr.nu
gra98desi.rr.nu
hitam41ultime.rr.nu
hoperjoper.ru
iab35ilit.rr.nu
ialac93idcod.rr.nu
icans11deskto.rr.nu
ident08winner.rr.nu
impo82rtse.rr.nu
int99onin.rr.nu
ion68you.rr.nu
ited51pala.rr.nu
ive23lit.rr.nu
kpo82stp.rr.nu
lasimp04risoned.rr.nu
lighte93dnickel.rr.nu
limina94tedefi.rr.nu
mainglobilisi.com
mals30ynta.rr.nu
mpa89qaut.rr.nu
mtube-ssl.com
ncomp97aredli.rr.nu
neou44slypa.rr.nu
ngsin45dividu.rr.nu
nstitu42tional.rr.nu
nting91uncle.rr.nu
nusi60ngmus.rr.nu
ocat47edha.rr.nu
ocum04entat.rr.nu
oneflo30orcall.rr.nu
onsco10mdexpo.rr.nu
ort26ibm.rr.nu
ort53hori.rr.nu
ovie26tther.rr.nu
pxm-tube.com
qtr49exis.rr.nu
raff60icke.rr.nu
rlyspa21rcleona.rr.nu
rsm95ario.rr.nu
scue08doral.rr.nu
selle33rsjunk.rr.nu
sicb79enef.rr.nu
sor52tium.rr.nu
ssic2061thligh.rr.nu
ssmo24king.rr.nu
sweepstakesandcontestsdo.com
sweepstakesandcontestsinfo.com
syno98nepet.rr.nu
takeo46versav.rr.nu
tanswe24ringni.rr.nu
tarts63exten.rr.nu
timel08arges.rr.nu
tiona82lclos.rr.nu
tormco48nstitu.rr.nu
tssign51stechno.rr.nu
vada86subje.rr.nu
velit30eratu.rr.nu
viv17eddr.rr.nu
whyi70splay.rr.nu
yint60eres.rr.nu
ysoci94alspec.rr.nu
zbol42lahg.rr.nu

1 comment:

omnicasa said...

we have the same attack but from other IP ranges :

96.9.0.0
66.197.0.0
64.191.0.0
173.212.0.0