Monday, September 15, 2014

September 11th Thoughts

Where were you on September 11, 2001?

My own story actually begins on September 6, 2001. That is the day when I hosted the first InfraGard meeting in Birmingham, Alabama. More than sixty security professionals came to Energen headquarters to hear a description of the InfraGard program and a presentation by Special Agent Mike Mauldin who described to us that when terrorist decide to attack our country, they may actually attack our critical infrastructures rather than a direct military vs. military attack.

Five days later I was in Carlsbad, California where I was supposed to be speaking to a Network Associates Customer Council meeting. I received the phone call early (Pacific time) from my wife who told me to turn on the television. I got up, got dressed, and went down to the bar where people were gathering to watch the big screen tv and try to decide what to do. Obviously, the meeting was canceled. Both planes had hit before my wife called me, but we watched together in horror as the building collapsed. I went back to my room, called my wife, and told her that I would be home as soon as possible, but that I was going to have to drive.

I had 40 hours alone in the car to think about what was going on. To think about what was important. To think about whether I was "making a difference" in what I did for a living. It was a life-changing event.

The 9-11 Memorial

Last year, my wife and I had the chance to visit the 9-11 Memorial in New York City. When we first exited the subway, we could see the new Freedom Tower.

The memorial consists of two very large squares at the location of the original Twin Towers, each has a waterfall heading into a bottomless pit. The names of the victims of the 9/11 attacks are engraved on the edges of the memorial.

The key shows that the names of First Responders are at the bottom left corner of the South Pool, which is the first place that those visiting the memorial will see. The names of those in each tower are on their respective towers, and the victims of the Pentagon and the "non twin tower" flights have also been recorded in the memorial.

While my wife and I were there as both Americans and as tourists, I had come to the memorial looking for one particular name. While there is an option to look up the names before you go to find their exact location, I told my wife that I would rather just walk around both memorials until I found the name I was looking for.

I was looking for the name John P. O'Neill. John was featured in a New Yorker story called "The Counter Terrorist" and has a page on PBS FrontLine: The Man Who Knew. John started working the FBI at age 18 as a tour guide, but after college returned as an agent and was sometimes mocked for his obsession with terrorism in general and Al Qaeda in particular. He was already investing "the Blind Sheikh" prior to the first World Trade Center bombing and his dedication to the investigation revealed the relationships between the various attacks the U.S. and its interests suffered around the world. His story is also detailed in the book The Man Who Warned America: The Life and Death of John O'Neill, the FBI's Embattled Counterterror Warrior.

I wore my Birmingham FBI shirt that day and had my wife take a picture of me standing by his name.

Many that day were victims and many were heroes. John O'Neill was the latter. People like him inspire me to do what I do in my own small way to try to protect our country.

InfraGard

Last week I was able to attend the National InfraGard Congress up in DC. I saw dozens of other American citizens who each represented their InfraGard chapter and some of the tens of thousands of InfraGard members who are each doing their part to make sure our country is as safe as they can make it. We heard from FBI Director James Comey, who presented awards to many of our members and the FBI InfraGard coordinators who work with us. We heard from FBI Assistant Director Joseph Demarest, the creator of the FBI's "New Cyber" program, and from FBI Section Chief, John Riggi, National Cyber Operations and Outreach Section, and from FBI Unit Chief, John Pi, a computer programmer turned medical doctor turned FBI Special Agent who now leads the FBI's National Industry Partnership Unit, which leads the InfraGard program from the FBI side of the partnership. Each of them stressed the same point. The FBI can't do this job alone. They need the partnership and support of the American public, and ESPECIALLY that portion of the public who is trained in security and cyber security. If your job is related to Critical Infrastructure protection, I hope you will consider joining InfraGard, because as a member of the security community, you know things about YOUR critical infrastructure that our friends in government do not know, or do not know at the same level of expertise as you.

The Birmingham InfraGard still meets on the Second Tuesday of the month, as we have every month since 9/11. If you are in the Birmingham area, we'd love for you to join us.

And if you don't work in Critical Infrastructure, I still hope you will consider, "What can I do in my role at work, at home, or in our educational system, to help educate the public about risks and threats and to help make our nation safer?"

Monday, August 18, 2014

Counterfeit Legal Notices continue to spread malware

Counterfeit legal notices continue to spread malware

Today a friend mentioned that they had seen several ASProx messages being distributed by domains that looked like law firm names warning of court appearances. I was a bit surprised that this was news to him, as we've been seeing this for some time. I thought it might be interesting to try to identify when the campaign began.

First, I was fairly certain that the campaign my friend referred to was the "Notice to appear" spam that we've written about so many times at Malcovery, but this does seem to be a bit different than the "law firm of the day" notice to appear campaigns we've seen imitating groups like Green Winick and many others including Jones Day (jonesday.com), Latham Watkins (lw.com), Hogan Lovells (hoganlovells.com), McDermitt, Will & Emery (wme.com). Those campaigns were all examples of the ASProx malware. But how are those different than the "truck lawyer" campaigns? It seemed worth taking a look.

For the month of August 2014, so far the daily count on these spam messages has looked like this:

 count |    date    
-------+------------
  1528 | 2014-08-01
   204 | 2014-08-02
  1375 | 2014-08-04
  1670 | 2014-08-05
  1571 | 2014-08-06
  1967 | 2014-08-07
  1541 | 2014-08-08
   129 | 2014-08-09
     1 | 2014-08-10
  1182 | 2014-08-11
  1399 | 2014-08-12
   191 | 2014-08-13
    58 | 2014-08-14
    25 | 2014-08-15
     1 | 2014-08-16
    21 | 2014-08-18
(16 rows)
While many of the campaigns used subject lines that included randomization, quite a few subjects did not, including these:

11727  Urgent court notice
11693  Hearing of your case in Court
11182  Notice to appear
9935  Notice of appearance in court
8424  Notice to Appear
7433  Notice of appearance
7108  Notice to appear in court
6612  Notice to Appear in Court
 643  Court hearing notice
 568  Pretrial notice
 441  Mandatory court appearance
We've seen more than 200 different "law" names involved in this campaign, including many "truck" related law domain names. Here's the batch so far just in August:

  count |                            sender_domain                            
-------+---------------------------------------------------------------------
     7 | accidentlawyers505.com
     1 | addictionrecoverylawyers.com
   328 | alabamatruckaccidentlawyers.com
   375 | alaskatruckaccidentlawyers.com
   352 | albanycountyelderlawyers.com
    11 | americanaccidentlawyers.com
     8 | anewgenerationoflawyers.com
    17 | arizonaspecialedlawyers.com
   363 | arizonatruckaccidentlawyers.com
   358 | arkansastruckaccidentlawyers.com
    12 | auburnbankruptcylawyers.com
    11 | aviationlawyersnetwork.com
   387 | az-lawyersadvice.com
     6 | bellevuebankruptcylawyers.com
   379 | bensonlawyers.com
     1 | bestlawyersinphoenix.com
     8 | bestlosangeleslawyers.com
   355 | best-ontario-lawyers.com
   361 | biofuelawyers.com
   360 | bronx-injury-lawyers.com
   316 | bronx-personal-injury-lawyers.com
    15 | brooklynelderlawyers.com
   371 | brooklyn-lawyers.com
    12 | bvslawyers.com
   326 | calgarydependentadultlawyers.com
   356 | californiatruckaccidentlawyers.com
   299 | californiaviolentcrimeslawyers.com
     5 | canadianduilawyers.com
   362 | capeannlawyers.com
   311 | caraccidentlawyerskc.com
     8 | career-lawyers.com
   318 | childsupportlawyerslosangeles.com
    13 | colobklawyers.com
   409 | coloradotruckaccidentlawyers.com
   395 | columbus-dui-lawyers.com
     9 | commoninterestlawyers.com
   326 | compasslawyers.com
   390 | connecticuttruckaccidentlawyers.com
    14 | contracosta-caraccident-lawyers.com
    17 | criminalcourtlawyers.com
   334 | criminaldefenselawyers360.com
     4 | crownpointindianawilltrustsprobateestatelderlawattorneyslawyers.com
     9 | csduilawyers.com
     5 | deferredstatuslawyers.com
   401 | delawaretruckaccidentlawyers.com
     1 | divorcelawyersinjacksonvillefl.com
     8 | drugcrimedefenselawyers.com
     5 | dubairealestatelawyers.com
     4 | easternnclawyers.com
    11 | employmentlawyersfortlauderdale.com
    10 | ernestolawyers.com
    10 | escortdefenselawyers.com
     1 | estateprotectionlawyers.com
    12 | falveylawyers.com
   354 | familylawyersoforangecounty.com
    10 | fla-injury-lawyers-blog.com
     9 | fl-criminal-defense-lawyers.com
    10 | fl-criminal-lawyers-blog.com
     7 | fllawyersonline.com
    11 | florida-criminal-defense-lawyers.com
     9 | floridaseniorlawyersassoc.com
   370 | floridatruckaccidentlawyers.com
    15 | fortmyersrealestatelawyers.com
    12 | garzalawyers.com
     9 | gatewaylawyers.com
   388 | georgiatruckaccidentlawyers.com
    12 | gofindlawyers.com
    13 | greatnecklawyersassociation.com
    10 | hartfordctlawyers.com
   361 | hawaiitruckaccidentlawyers.com
     9 | hcvlawyers.com
   351 | highdesertlawyers.com
     7 | hounslowlawyers.com
   372 | houstonmesotheliomalawyers.com
     6 | hphlawyersonbloor.com
     9 | huntingtonaccidentlawyers.com
   385 | idahotruckaccidentlawyers.com
    13 | illinoisbicyclelawyers.com
   347 | illinoistruckaccidentlawyers.com
   308 | immlawyers.com
   330 | indianatruckaccidentlawyers.com
     7 | indy-lawyers.com
     5 | institutionalinvestorlawyers.com
   352 | iowatruckaccidentlawyers.com
   340 | kansastruckaccidentlawyers.com
   300 | kentuckytruckaccidentlawyers.com
     9 | kentuckyyounglawyers.com
   337 | lakelanddivorcelawyers.com
    12 | lancasterautoaccidentlawyers.com
     1 | lawusa.com
     6 | lawyeringforlawyers.com
   311 | lawyersadviceinarizona.com
   350 | lawyersadviceinphoenix.com
     8 | lawyersandloans.com
    14 | lawyersbankruptcysolutions.com
     9 | lawyersbocaraton.com
    11 | lawyerscaringforamerica.com
     7 | lawyerscaringforarizona.com
     8 | lawyerscfo.com
   393 | lawyers-connecting.com
     7 | lawyersforeclosuresolutions.com
     8 | lawyers-germany.com
     8 | lawyersinbalance.com
    15 | lawyersinthecloud.com
     3 | lawyerslawfirms.com
     7 | lawyerslongisland.com
    14 | lawyersonlineguide.com
    13 | lawyerstaxsolutions.com
     1 | lawyersthatrock.com
     5 | lawyersvirtualbookkeeper.com
    10 | lawyerswithdepression.com
    11 | loan-modification-lawyers.com
   364 | long-island-lawyers.com
   356 | louisianatruckaccidentlawyers.com
    11 | mailfrauddefenselawyers.com
   376 | mainetruckaccidentlawyers.com
    10 | malpracticelawyersnewyorkcity.com
   329 | manhattan-injury-lawyers.com
   362 | manhattan-personal-injury-lawyers.com
   318 | marylandtruckaccidentlawyers.com
   807 | massachusettstruckaccidentlawyers.com
    10 | medicalmalpraticelawyers.com
   388 | mesotheliomalawyersonline.com
   402 | michigantruckaccidentlawyers.com
     8 | millbrooklawyers.com
   398 | minnesotatruckaccidentlawyers.com
   374 | mississippitruckaccidentlawyers.com
   361 | missouritruckaccidentlawyers.com
     8 | mitpatentlawyers.com
    11 | mittrademarklawyers.com
     7 | mmspersonalinjurylawyers.com
   374 | montanatruckaccidentlawyers.com
    12 | mylawyersolicitors.com
    14 | myreallawyers.com
     7 | naplesbusinesslawyers.com
   373 | nassau-county-lawyers.com
   329 | nebraskaboatinjurylawyers.com
   315 | nebraskatruckaccidentlawyers.com
     1 | nebraskatruckaccidentlawyers.com.com
   351 | nevadatruckaccidentlawyers.com
   384 | newhampshiretruckaccidentlawyers.com
   398 | newjerseytruckaccidentlawyers.com
   370 | newmexicotruckaccidentlawyers.com
   365 | new-york-city-lawyers.com
     9 | newyorkscaffoldlawyers.com
   393 | newyorktruckaccidentlawyers.com
   339 | njlandlordtenantlawyers.com
   351 | northcarolinatruckaccidentlawyers.com
   377 | northdakotatruckaccidentlawyers.com
   284 | nyautoaccidentlawyers.com
   312 | nycaraccidentlawyers.com
    14 | ohadoptionlawyers.com
   383 | ohiotruckaccidentlawyers.com
   344 | oklahomatruckaccidentlawyers.com
   404 | oregon-lawyers.com
   373 | oregontruckaccidentlawyers.com
    11 | palmbayinjurylawyers.com
     8 | panamacitysocialsecuritydisabilityclaimlawyers.com
   321 | phoenixlawyersadvice.com
     8 | pittsburgaccidentlawyers.com
    12 | poptodorova-lawyers.com
     1 | portstlucie-duilawyers.com
    11 | prescriptiondiversiondefenselawyers.com
    17 | probateadministrationlawyers.com
   314 | productsliabilitylawyers360.com
     9 | refineryfirelawyers.com
   356 | rhodeislandtruckaccidentlawyers.com
    13 | robberydefenselawyers.com
   361 | rockland-county-lawyers.com
   343 | saintpaulinjurylawyers.com
    11 | seattlesbestduilawyers.com
     9 | seattle-trial-lawyers.com
    11 | sfmesolawyers.com
   401 | southcarolinatruckaccidentlawyers.com
   396 | southdakotatruckaccidentlawyers.com
     6 | southfloridaworkerscompensationlawyers.com
   316 | southhamptoninjurylawyers.com
   368 | staten-island-lawyers.com
   358 | stentinjurylawyers.com
    14 | success4lawyers.com
   324 | suffolk-county-lawyers.com
     7 | tacomabankruptcylawyers.com
   386 | tennesseetruckaccidentlawyers.com
    13 | thebusinessgrowthlawyers.com
   362 | thechicago-deportationlawyers.com
   307 | the-consumer-lawyers.com
    12 | thelawyerscfo.com
    12 | themauilawyers.com
   333 | thenationstoplawyers.com
     8 | topmultimilliondollartriallawyers.com
   294 | trivalleylawyers.com
   325 | tuscaloosa-lawyers.com
   359 | utahtruckaccidentlawyers.com
   326 | vermonttruckaccidentlawyers.com
   338 | villanuevalawyers.com
     6 | virginia-non-compete-lawyers.com
     7 | virginianoncompetelawyers.com
   395 | virginiatruckaccidentlawyers.com
   361 | washingtontruckaccidentlawyers.com
   338 | westchester-county-lawyers.com
   379 | westvirginiatruckaccidentlawyers.com
     1 | westvirginiatruckaccidentlawyers.com.com
     1 | whsbf-law.com
   386 | wisconsintruckaccidentlawyers.com
    12 | wolfegrouplawyers.com
     8 | wrongfulldeathlawyers.com
   377 | wyomingtruckaccidentlawyers.com
   283 | yourvegaslawyers.com
(208 rows)
This group tends to have email addresses that were a single word followed by three digits, so we use those to search in the Spam Data Mine:

([account|answer|confirmation|customer|customercare|customersupport|
customerservice|custservice|custsupport|details|dontreply|help|
identdep|infonum|login|mail|no-reply|noreply|onlinesupport|operate|
operator|reference|reply|security|support|supprefnum|time|update|
verification|][0-9]{3})

From June 1, 2014 to August 18, 2014 more than 25,000 different combinations of the above were used in emails that sent email to the Malcovery Spam Data Mine.

The attached .zip files during that period of time, when unpacked, revealed 39,571 distinct executables, all of which are variants of the "Kuluoz" or "DoFoil" malware.

Because of the apparent polymorphic nature of many of the samples, where each binary is unique, I've only shared the hashes of the non-polymorphic versions - where the same binary was used many times. If the final column is clickable, the link shows the VirusTotal detection rate at the time of our original reporting.

A recent trend in these file names is that the first character, which looks like the letter "C" is actually the Russian "S", a cyrillic look alike for our "C", expressed with the characters: С (ampersand, pound sign, 1057, semicolon). When the word "Court" is spelled with the Cyrillic S instead, a search for the word "Court" will not find it! Here is the word Court twice, first with a "C" and then with the cyrillic equivalent: Court Сourt

CountDateFilenameFilesizeMD5 (VT Link)
50 2014-03-07 Copy_Court_Notice.exe178688 55a60b91143c5c91849237f8e6bc3235
31 2014-03-07 Copy_Court_Notice.exe78447 6f8a65b02fea37530af50e65483300db
48 2014-03-10 Copy_Court_Notice.exe81400 13b519634c4a03001122def3f471616a
31 2014-03-10 Copy_Court_Notice.exe78446 1f9570e4b628f81578ae0fb03cddd137
33 2014-03-11 Court_Notice_Copy.exe140800 202a8720eddc389b91fb4d398df95da0
29 2014-03-11 Court_Notice_Copy.exe181248 49723312b73067e66b0f4db453231825
41 2014-03-11 Court_Notice_Copy.exe144384 8cd13060037ddd790c41a4ea4b209a06
34 2014-03-12 Court_Notice_Copy.exe78447 bc08d0c5f5a5e4e6a199fce5e243e8aa
43 2014-03-20 Court_Notice_Copy_doc.exe82856 0a2be62df1320b4f20d4777f7b69f1a4
34 2014-03-20 Court_Notice_Copy_doc.exe81395 1c549f6bc1afcfd7f0af9b2e3ada1e9f
29 2014-03-20 Court_Notice_Copy_doc.exe178688 786cb67c6f8409ce1933bb838e80d2a8
29 2014-03-20 Court_Notice_Copy_doc.exe78198 861530485284fc46c37b41400810477a
49 2014-03-20 Court_Notice_Copy_doc.exe78447 93b678cbcc583079cf7e0082910fc51f
50 2014-03-20 Court_Notice_Copy_doc.exe183808 99fc4dbc2082ee2d111086affd2c623e
29 2014-03-21 Court_Notice_Copy_doc.exe178688 040196c76bc37ede48262dddbb871df6
50 2014-03-21 Court_Notice_Copy_doc.exe78967 305bcd56a92c0ecfbe0a498bb920ea89
49 2014-03-21 Court_Notice_Copy_doc.exe181248 546608757bde754251975a5deefff67f
30 2014-03-21 Court_Notice_Copy_doc.exe181248 6e3021203febb924372c87af1d239b26
27 2014-03-21 Court_Notice_Copy_doc.exe78199 d4f214e94467070e09fac5f762769f39
39 2014-03-22 Court_Notice_Copy_doc.exe82265 e7175f3ac0f29146967da11375528d4f
159 2014-03-26 Court_Notice.exe181248 68c8cd0bde8b38780a2d2d7862f4e02d
27 2014-03-27 Court_Notice.exe114176 8b1fa6be2aa31212fe15cee8c4e0cedb
3634 2014-03-28 Court_Notice_Copy.exe177152 096402c1e21da0df9465511b600a135e
2244 2014-03-28 Court_Notice_Copy.exe110080 27c7f219798ad65b158dd9c4b4658743
1685 2014-03-31 Court_Notice_Copy.exe211968 36b3d44816b933c2a3c2000ed50d4685
3378 2014-03-31 Court_Notice_Copy.exe103936 d185a21bf355ad67b8e75e0ecb28acb8
6037 2014-04-01 Court_Notice_Copy.exe148480 4adee84193b467d0ea2a2a64e4767586
446 2014-04-02 Court_Notice_Copy.exe209920 3368e248a76a7b7d090d0ce7cb7335be
2183 2014-04-03 Court_Notice_Copy_03-04-14_AP.exe143360 790cba7836b71b666592891f7bf75b32
2698 2014-04-03 Court_Notice_Copy_03-04-14_AP.exe201216 7f268ff0850a623de27dbb835d13cd60
2248 2014-04-04 Court_Notice_Copy_04-04-14_AP.exe133120 0ef2108030990e2f8914639b3c1d2098
2049 2014-04-04 Court_Notice_Copy_04-04-14_AP.exe141312 24826d752ee438e78d689b5416170cd9
3657 2014-04-07 Court_Notice_Copy_07-04-14_AP.exe110592 52e5589b6fe5be00a3959e0da2d08413
1841 2014-04-07 Court_Notice_Copy_07-04-14_AP.exe146944 a1e0804d0bbc17b895194d88a61c85e4
1338 2014-04-08 Court_Notice_Copy_08-04-14_AP.exe110080 66b286f769753a9e51695205ae07ffb8
2165 2014-04-09 Court_Notice_Copy_09-04-14_AP.exe139264 7e28325f5bc307646097a1481512f726
228 2014-04-09 Court_Notice_Copy_09-04-14.exe216064 bccc5c02d4341de68dc5195497e5a909
38 2014-05-07 Court_Notice_Date_May-7_2014CV-D.exe181248 e3cbfdd4dfa6561e22e19177a4f60e7a
75 2014-05-08 Court_Notice_May-8_Date_2014FHK.exe181248 648401ae4f3b5f2f7f9198a2fc3fe072
106 2014-05-09 Court_Notice_May-9_Date_2014FHK.exe150016 413d43f0e5431b58de0d37d4fc5dd333
79 2014-05-09 Court_Notice_May-9_Date_2014FHK.exe78447 b6029ee57a3f6b8ca73fb1699106d9cf
255 2014-05-12 Court_Notice_May-12_Date_2014_FEN.exe178176 512c867583c1ba6cdf8857bdd8d84ff9
263 2014-05-12 Court_Notice_May-12_Date_2014_FES.exe108544 5752260d7e2ac9e57083792a5f87e4ce
197 2014-05-13 Court_Notice_May-13_Date_2014_A-DC.exe141312 530eed9bc14c386b10d38c77bef44a4d
167 2014-05-13 Court_Notice_May-13_Date_2014_D-SER-N.exe144384 b15932cb2a15f06de49773400c6e1f07
41 2014-05-14 Court_Notice_May-14_Date_2014_EXL-DC.exe150016 41d7b395ca4dd5b3150b35be4fad3737
51 2014-05-14 Court_Notice_May-14_Date_2014_.exe78200 71ab11b81995e8dd94b9c04813b95c04
54 2014-05-15 Court_Notice_May-15_Date_2014_EN_DOC_.exe139264 723770d9cff199c400ea0d472736428e
182 2014-05-15 Court_Notice_May-15_Date_2014_TN_DOC_.exe82857 f5a4690f12f64bbf4944980060dc56ec
120 2014-05-16 Court_Notice_May-16_Date_2014_ID-SER_DOC.exe78447 1bb1d62749258f4813c4cd1d1b62d92d
188 2014-05-16 Court_Notice_May-15_Date_2014_SE-ANDC_.exe108032 5e9b56bc10e7c1a5fcb26615de7f5923
94 2014-05-19 Court_Notice_May-19_Date_DOC-SER_2014.exe108032 fbcb2407e676c095b53196c630f16d9e
69 2014-05-19 Court_Notice_May-19_Date_DF-SER_2014.exe81396 fc89720c573184b6b0c740025bd8f0be
192 2014-05-20 Court_Notice_May-20_Date_IN-FN_2014.exe220672 110a0bc676dc2094ebaf8faad0423461
133 2014-05-20 Court_Notice_May-20_Date_EN-RM_2014.exe177152 76bd89ff3141fef1345053881797392a
147 2014-05-21 Court_Notice_May-21_Date_EN-RT_2014.exe78200 243d37f8fc6efac0a2e99d198af01d54
149 2014-05-21 Court_Notice_May-21_Date_EN-RT_2014.exe78445 8a70b33c64c5b48c9691f0ddc7826bbe
119 2014-05-22 Court_Notice_May-22_Date_DCSER-LS_2014.exe181248 08f2f21aae0c2917c19dbbe70842bf8e
111 2014-05-22 Court_Notice_May-22_2014_EN-OP.exe181248 46a6f5a0a8c2f31477cb5812f094640d
107 2014-05-22 Court_Notice_May-22_Date_DCSER-LS_2014.exe78447 d2d84503d4f43e8abeab158a351df290
286 2014-05-23 Court_Notice_May-23_Date_2014_SER-ERN-DC.exe209408 51e12bec75e8d5a0b2e434a45b7e1c67
599 2014-05-28 Plaint_Note_May-28_Date_FN-SE-DC_2014.exe209920 797f8d6da6c1ca6a6f3f60c257d9f6c5
1090 2014-06-09 DC_Court_Notice_June-09_Date_2014-SER.exe109568 7fb418b6c4ec42ca1ccc4c372293169e
1091 2014-06-10 Court_Notice_June-10_Date_2014-ID.exe229888 01535c6f5594790e458e011dc4cd7a3d
746 2014-06-10 DOC_Court_Notice_June-10_Date_2014-SER.exe109568 169e683b948ae1bce6a45350201b427d
727 2014-06-11 SR_Court_Notice_June-11_Date_2014-ID_DC.exe109568 f1542e83f0577f9d54370d9778074371
1009 2014-06-12 Court_Notice_June-12_Date_2014-DC.exe105472 9395698fbfcaa1f5b297c01e4aa52e1c
445 2014-06-13 SR_Court_Notice_June-13_Date_2014-DOC-NR.exe105472 0bc400ab22ab5fd82a3408477d7f20dd
809 2014-06-16 Detailed_Document_FAX_June-16_Date_2014_DOID.exe111104 3c5a4968f70f0883971d312f7f97d4a4
1059 2014-06-17 Detailed_Document_ID7723H_June-17_Date_2014_SRID.exe77824 55226242da24299345b45fb46751764a
700 2014-06-18 Doc_Court_Agent_Date_June-18-2014Y.exe77312 b0cae006c23ca33c36daecd32f50d9fc
1076 2014-06-19 Copy_of_document_Date_June-19-2014.exe74752 d6b9982d1b3abcb4530a7abd6a063944
27 2014-06-20 Copy_of_document_Date_June-20-2014.exe74752 73f03523e4c14ca55a92dce91b958ba1
262 2014-06-23 Copy_of_document_Date_June-23-2014.exe76800 c5b6a4c546be34642141660e7a0dbb1e
169 2014-06-24 Copy_of_document_Date_June-24-2014.exe76800 0829817d83d583f5a55075dc0017ef52
209 2014-06-25 Copy_of_document_Date_June-25-2014.exe76800 8c920901eca575593f580531e44ea62f
311 2014-07-04 Copy_of_document_Date_July-04-2014.exe80384 50daa5c135d5ad2da3b2c8a8dd4c3f50
496 2014-07-14 Copy_of_document_July-14-2014.exe135168 559fd034d76e45aec67be49c2f93cfae
552 2014-07-15 Copy_of_document_July-15-2014.exe135168 80aff3257ec4f6f7bd5e5259ea08815e
584 2014-07-16 Copy_of_document_July-16-2014.exe135168 cc19a778b730d310a1bea1518bdc7a6f
704 2014-07-17 Copy_of_document_July-17-2014.exe135168 b43e9210da3e06dc2b88ae028a13d8c5
526 2014-07-18 Copy_of_document_July-18-2014.exe139264 1531f529f73d79f1cf4dd1d6a7426429
614 2014-07-22 Copy_of_document_July-22-2014.exe135168 3c3944f52d194fd86d12ebccb2c7cf85
623 2014-07-23 Copy_of_document_July-23-2014.exe135168 046f9dbedcf03749d0e7ae5cc120897d
600 2014-07-24 Copy_of_document_July-24-2014.exe135168 a1eb4a25be83c770f38203fcc64f9419
717 2014-07-25 Copy_of_document_July-10-2014.exe135168 35850cfececd274ee5f182bd64c221ab
370 2014-07-28 Copy_of_document_July-28-2014.exe135168 6edec50da5540820682387c71434d209
613 2014-07-29 Copy_of_document_July-29-2014.exe106496 2f8a429f6e005cecc25f9bb86f4211dc
555 2014-07-30 Copy_of_document_July-30-2014.exe110592 529e7348bca26b22d0b42a7fe6c63e8d
604 2014-07-31 Copy_of_document_July-31-2014.exe106496 b2c8662858ed7a8c052a080b03ca26b2
806 2014-08-01 Copy_of_document_August-01-2014.exe102400 2ca1e3d6312c3f844de919caec77fc1f
711 2014-08-04 Copy_of_document_August-04-2014.exe110592 6c83a7e471421899141e7e13a635abbd
973 2014-08-05 Copy_of_document_August-05-2014.exe143360 1463aaa9b393a1591df049534e9f9ddd
734 2014-08-06 Copy_of_document_August-06-2014.exe106496 49985d6ae2805c2301bd941c783991e4
447 2014-08-07 Copy_of_document_August-07-2014.exe127488 659f348503f30952f19816e2afb1e595
447 2014-08-07 Сopy_of_Document_ID4923.zip75375 802529cf5a1c85eb0389f9e0e0f309da
826 2014-08-08 Copy_of_document_August-08-2014.exe106496 804f0d437f3c500c9d5a340d4f783b6b
4 2014-08-11 Copy_of_document_August-11-2014.exe118272 2fc5cc07700d3eacd0d063f93aebfa14
768 2014-08-11 Copy_of_document_August-11-2014.exe104448 ebb9e152618e4b0a871aceb1966b8f85
4 2014-08-11 Copy_of_document_August-11-2014.exe118272 ffa9f70e72fb7eea06fea313ef979502
739 2014-08-12 Copy_of_document_August-12-2014.exe103424 c6a53a80b7425215d2f32332e2721a49
22 2014-08-13 Copy_of_document_August-13-2014.exe113152 6bb5e1502b8cdfaa5ae78238cee7ab85
36 2014-08-14 Copy_of_document_August-14-2014.exe94720 956f9551579314bbe74e55fbdbe4b869
14 2014-08-15 Copy_of_document_August-15-2014.exe90624 d38c3aa977745be341ae26e439d8e111
15 2014-08-18 Copy_of_document_August-18-2014.exe92672 49aef017ad8880a7b4d24c8190acc068

Tuesday, July 29, 2014

SFR phish: the Gateway to all French banks

Back in April, we wrote about the French power company, EDF, being used as a universal phishing target in our article, Multi-Brand French Phisher uses EDF Group for ID Theft. Since that time we are seeing that those targeting French speaking victims are choosing yet another large utility to serve as proxy for all of the French banking world. This time the phishing lures are for SFR.

This phish has been especially popular this year. Malcovery's PhishIQ service has seen more than 1,000 SFR phish on more than 330 hacked servers so far this year, including dozens just in the month of July 2014. More importantly though, the attackers are growing more sophisticated! The attack described below is one of the most sophisticated phish we've seen to date, employing "man-in-the-middle" logins where SFR credentials are tested before the victim is allowed to proceed, and nearly a dozen customized bank security procedure questions being processed.

In a typical example of these phish, the victim receives an email that appears to be from SFR informing them that an error was made in their bill, "Ce mail vous a été envoyé dans le but de vous informer qu une erreur est survenue lors de l établissement de la dernière facture" and to "Cliquer ici pour ouvrir le formulaire de remboursement" (Click here to open the refund form). The victim is also warned that they need to fill out the form completely, or they won't get their refund (in some cases 95 Euros!):

Veuillez accepter nos excuses par cette erreur comptable. SFR : Service comptabilité de SFR Toute omission, mauvaise saisie, ou non réponse a ce mail entrainera automatiquement une amputation de la somme de quatre-vingt-quinze (95) euros sur votre compte, et aucune réclamation de sera acceptée.

While there are several versions of the SFR phish, the most sophisticated that we have encountered so far can be seen on a British horse enthusiasts website (obviously hacked). What makes this one particularly compelling is that it begins by requiring the victim to be using their true SFR userid and password. On the originating screen, the user is told to "Connectez-vous" by entering his userid (Identifiant) and password (Mot de passe).

The Action of this form of the phishing site actually passes the userid and password to SFR and confirms whether or not a true identifier has been used. If false information is provided, the phishing victim receives a message back informing him that

Vos coordonnées n'ont polo été reconnues. -- Your details have not been recognized.
Veuillez recommencer. -- Please try again.
Suite à 5 erreurs sur votre mot de passe, -- After 5 errors on your password
votre compte est bloqué. -- Your account will be blocked.

So, with a little incentive to not lie to the criminal, and a fairly strong reason to believe they are really speaking with SFR, the victim continues to page two after providing true login credentials.

On the second page, the victim is invited to choose their bank from a long list of French banks. Depending on which bank they choose, they will be prompted for appropriate additional verification details used by that bank. Banks on the list include:

  • AXA Banque
  • Banque AGF / Allianz
  • Banque de Savoie
  • Banque Dupuy de Parseval
  • Banque Marze
  • Banque Palatine
  • Banque Populaire
  • Banque Postale
  • Barclays
  • BforBank
  • Binck.fr
  • BNP
  • BNP Paribas La NET Agence
  • Boursorama Banque
  • BPE
  • Caisse d'Epargne
  • CIC
  • Coopabanque
  • Crédit Agricole
  • Crédit Cooperatif
  • Crédit du Nord
  • Crédit Mutuel
  • Crédit Mutuel de Bretagne
  • Crédit Mutuel Massif Central
  • Crédit Mutuel Sud-Ouest
  • e.LCL
  • Fortis Banque
  • Fortuneo Banque
  • Groupama Banque
  • HSBC
  • ING Direct
  • LCL
  • Monabanq
  • Societe Generale
  • Société Marseillaisle de Crédit
  • Autre Banque
Here are some examples: (Click on any image to enlarge)

Some banks require the visitor to enter their 3DSecure code

AXA Banque has a custom code for their clients

Banque Postale has security questions, such as:
  • Quel est le prénom de l'aîné(e) de vos cousins et cousines ?
  • Quel était le prénom de votre meilleur(e) ami(e) d'enfance ?
  • Quel était votre dessin animé préféré ?
  • Quel a été votre lieu de vacances préféré durant votre enfance ?

Caisse d'Epargne also provides a personalized Client code.

Even the "Cyberplus" electronic password generators used by Banque Populaire are included in this phish!

Some banks also require information about the victim's birthplace


After successfully acquiring both your SFR.com userid and password, and the necessary information to take over the bank account of the phishing victim, the criminal sends you on your way, after congratulating you on your success!
(The update was successful. SFR thanks you for using its Bank Assurance services. You can continue browsing the site with full security.)

After seeing this message briefly, the visitor is forwarded to the true www.SFR.fr website.

Tuesday, July 15, 2014

.pif files, Polish spam from Orange, and Tiny Banker (Tinba)

Tonight I was looking at my Twitter feed and saw @SCMagazine talking about ZBerp. It was actually a tweet back to a story from July 11th where Danielle Walker wrote ZBerp Evolves: Spreads through Phishing Campaign which was actually quoting the July 7th story from WebSense Labs, where Elad Sharf wrote Zeus PIF: The Evolving Strain Looking to Defeat Your Security Software. I thought that sounded interesting, so I went over to the Malcovery Security systems to see what the malware team had done with .PIF files recently.

.PIF files are like those organs we are said to have for some reason that are not necessary in these modern times. If you still remember the pain of migrating from DOS 5.0 to Windows 3.0, you will remember that we had .PIF files because DOS binaries did not have all the niceties of Windows programs, such as embedded icons and a place to store the default start-up path. Back when Ugg the Caveman was discovering fire and Bill Gates was leading a development team, you could make your DOS Executables APPEAR to be Windows files by sticking a .PIF file of the same name in the same directory. Windows knew that it should associate the .PIF file with the .EXE or .COM file of the same name, and suddenly we had icons! Of course the malware authors have done some sneaky things with this in the past. When Sality was a young pup, browsing a directory that contained the ".pif" format of Sality was enough to get Windows to execute the malware -- because "Active Desktop" knew that if it saw a .PIF file, it should load it so it would know what graphical icon to associate with which programs in the directory listing. Unfortunately, that was all Sality needed to launch itself! So many people were victimized thinking that the AUTORUN=OFF on their thumb drive had failed without realizing it was just what .PIF files did back then.

So, this morning in the Malcovery Spam Data Mine we saw 1,440 copies of a spam message claiming to be from "orange.pl" with the subject "MMS-ie" and a 70,390 byte .zip file with a randomly numbered IMG#####.zip filename. The .ZIP file contained a 126,976 byte .PIF file that was named "IMG875002763.JPEG.pif" and had an MD5 hash of d382068a8666914584d0ae51dd162c6b. When I just checked the file a few minutes ago on VirusTotal, thinking I would see various Zeus-related malware names based on the SCMag / WebSense articles, I was surprised to see that the file was actually TinBa or "Tiny Banker"!

Late last week I was one of the many folks trying to get a friend to get me a copy of the Tinba source code that had been leaked, as Peter Kruse over at CSIS told us on July 10, 2014 (See Tinba/Hunterz source code published. Peter shared a talk The Hunterz Inside Tinba at the recent Cyber Threat Summit, and, with Trend Micro's Robert McArdle and Feike Hacquebord, released a paper called "W32.Tinba, The Turkish Incident" (a 24-page PDF that gives great insights into the malware family).

Tinba: The Polish Incident

If the earlier paper was called "The Turkish Incident", perhaps the current version should be called "The Polish Incident". Here is the email that was distributed so prolifically this morning:

Jeżeli Twój telefon nie obsługuje wiadomości multimedialnych, możesz je wysyłać i odbierać korzystając ze Skrzynki MMS lub Albumu MMS. Wystarczy, że zalogujesz się na www.orange.pl. O każdym otrzymanym na skrzynkę MMS-ie powiadomimy Cię E-mail.

Jeśli odbiorca wiadomości nie ma telefonu z obsługą MMS będzie mógł ją odebrać logując się w portalu www.orange.pl, a następnie wybierając Multi Box i zakładkę MMS. Wiadomości multimedialne możesz też wysyłać na dowolny adres e-mail.

In case you aren't as fluent in Polish as the rest of us, here is how Google Translate renders that:

If your phone does not support multimedia messages, you can send and receive using the Crates MMS or MMS Album. Simply log on www.orange.pl. For each received in an MMS message box will send you e-mail. If the recipient of the message does not have MMS-capable phone will be able to pick it up by logging into the portal www.orange.pl, and then select Multi Box and MMS tab. Multimedia messages can also be sent to any e-mail.
The spam from Monday, July 14th, was Tinba spam according to VirusTotal. Late this evening (about 18 hours after the spam campaign) VirusTotal reported a (25 of 53) detection rate.

The spam from July 11th was also in Polish, and also imitated Orange, although this time the sender was Orange.com. There was a .zip file attached, which contained a file named "DKT_Faktura_indywidualna_2014_07_11_R.pdf.pif" which was 102,400 bytes in size and had an MD5 hash of da9330aa6d275ba28954b88ecf27dedb. The .zip file was 70,323 bytes with MD5 hash of fc1e0a665f99b347e424281a8a6a2526. The spam from July 11th was also Tinba spam, according to many vendors at VirusTotal. But the email body was much simpler. The message, still in Polish, was:

Witamy,

Przesyłamy fakturę Telekomunikacji Polskiej w wersji elektronicznej za czerwiec 2014.

Welcome,

We send an invoice Polish Telecom in the electronic version for June 2014.

But of course it was more malware, disquised as an invoice but actually a .pif file.

The current detection at VirusTotal for that campaign is 33 of 53 detections.

Unlike the Turkish Incident, where Tinba was being dropped by the Blackhole Exploit Kit, in the current spam, Tinba is directly attached to the email message.

Sunday, July 13, 2014

Urgent Court Notice from GreenWinick Lawyers delivers malware

I spent some time yesterday in the Malcovery Security Spam Data Mine looking at the E-Z Pass malware campaign. The ASProx spammers behind that campaign have moved on to Court Notice again . . .

Subjects like these:

  • Hearing of your case in Court No#
  • Notice of appearance
  • Notice of appearance in court No#
  • Notice to Appear
  • Notice to Appear in Court
  • Notice to appear in court No#
  • Urgent court notice
  • Urgent court Notice No#
(All of the subjects that have "No#" are followed by a four digit integer.)


(click to enlarge)

As normal, the spammers for these "Court Appearance" spam campaigns have just grabbed an innocent law firm to imitate. No indication of any real problem at Green Winick, but I sure wish one or more of these abused law firms would step up and file a "John Doe" lawsuit against these spammers so we could get some civil discovery going on!

These are the same criminals who have Previously imitated other law firms including Jones Day (jonesday.com), Latham Watkins (lw.com), Hogan Lovells (hoganlovells.com), McDermitt, Will & Emery (wme.com), and many more! Come on! Let's go get these spammers and the malware authors that pay them!

We've seen 88 destination hosts between July 10th and this morning (list below) but it is likely there are many more!

When malware spammers use malicious links in their email instead of attachments, they tend to have a much better success rate if they deliver unique URLs for every recipient. That is what is happening in this case, and what always happens in these ASProx / Kuluoz spam campaigns. An encoded pseudo-directory is used in the path portion of the URL, which is combined with rotating through hundreds of 'pre-compromised' websites to host their malicious content.

Four patterns in the path portion of the URL are better indicators as we believe there will be MANY more destination hosts.

  • tmp/api/…STUFF…=/notice
  • components/api/…STUFF…=/notice
  • wp-content/api/…STUFF…=/notice
  • capitulo/components/api/…STUFF...=/notice
where "...STUFF..." is an encoding that we believe is related to the original recipient's email address, but have been unable to confirm at this time.

http:// arhiconigroup.com / wp-content / api / pwCYg4Ac5gk0WlQIVFEkRSPGL2E7vZhP8Qh4LMGbbAk= /notice

(to protect the spam donor, the pwCYg... string above has been slightly altered. If you want to work on de-coding, let me know and I'm happy to provide a couple hundred non-altered strings.)

Just like with last week's E-Z Pass spam campaign, visiting the destination website results in a uniquely geo-coded drop .zip file that contains a .exe file.

As an example, when downloading from my home in Birmingham Alabama where my zip code is 35242, the copy I received was named:

Notice_Birmingham_35242.zip

which contained

Notice_Birmingham_35242.exe, which is icon'ed in such a way that it appears to be a Microsoft Word document.

The MD5 of my '.exe' was: 5c255479cb9283fea75284c68afeb7d4

The VirusTotal report for my .exe is here:

VirusTotal Report (7 of 53 detects)

Extra credit points to Kaspersky and Norman for useful and accurate naming !

Kaspersky = Net-Worm.Win32.Aspxor.bpyb
Norman = Kuluoz.EP

Each of the 88 destination websites that we observed was likely compromised to host the malware. We do not believe these are necessarily "Bad Websites" but they either have a vulnerability or have had the webmaster credentials stolen by criminals.

If these are YOUR website - look for one of those directories I mentioned ...

/tmp/api/
/components/api/
/wp-content/api/
/capitulo/components/api/

www.metcalfplumbing.com
www.mikevanhattum.nl
www.mieszkaniaradomsko.pl
www.millionairemakeovertour.com
www.mkefalas.com
www.moldovatourism.ro
www.mobitrove.com
www.modultyp.com
www.mommyabc.com
www.monsterscalper.com
www.myconcilium.de
www.nellalongari.com
www.northsidecardetailers.com.au
www.parasitose.de
www.paulruminski.eu
www.petitecoach.com
www.phasebooks.net
www.plr-content.com
www.profimercadeo.com
www.propertyumbrellablueprint.com
www.proviewhomeservices.com
www.puntanews.com.uy
www.qifc.ir
www.rado-adventures.com
www.rantandraveweddingplanning.com
www.registrosakasicos.es
www.rimaconsulting.com
www.romiko.pl
www.saffronelectronics.co.uk
www.sasregion.com
www.saxonthewall.com
www.sealscandinavia.se
www.stkatharinedrexel.org
www.tecza.org
www.theanimationacademy.com
www.thehitekgroup.com
www.tusoco.com
www.urmasphoto.com
www.vicmy.net
www.viscom-online.com
www.vtretailers.com
www.warp.org.pl
www.webelonghere.ca
www.weihnachten-total.de
www.wesele.eu
www.whistlereh.com
www.wicta.nl
www.widitec.com.br
www.wonderlandinteractive.dk
www.wpprophet.com
www.xin8.org
www.zabytkowe.net
www.zeitgeistportugal.org
www.zmianywpodatkach.pl
www.znamsiebie.pl
www.zuidoost-brabant.nl
www.zs1grodzisk.pl
yourmentoraffiliatemarketing.com
atenea.edu.ec
comopuedoblanquearmisdientes.com
arhiconigroup.com
chris-coupe.com
drnancycooper.com
ian-mcconnell.com
izkigolf.com
kalemaquil.com
kingdommessengernetwork.com

Friday, July 11, 2014

New GameOver Zeus Variant uses FastFlux C&C

Over on the Malcovery Security Blog yesterday we covered a new version of GameOver Zeus (see: GameOver Zeus Mutates, Launches Attack ) that was distributed in three spam campaigns on July 10, 2014. At the bottom of that blog post, we're sharing a detailed "T3 Report" by analysts Brendan Griffin and Wayne Snow that gives all the details. In our reporting yesterday we mentioned that the new bot is using a Fast Flux Command & Control structure and that it is using a Domain Generation Algorithm to allow the malware distributed in the spam to locate and connect to the Command & Control servers.

I wanted to geek that a bit deeper for those who want more details on both of those subjects. First, let's look at the Fast Flux.

Fast Flux Command & Controlled Botnet

Fast Flux is a technique that allows a criminal who controls many servers to obfuscate the true location of his server by building a tiered infrastructure.

Sometimes there are additional "tiers" or levels of misdirection. We don't yet know how many layers there are in this newGOZ botnet.


(click to enlarge)

Here's the flow . . .

  1. the newGOZ criminal pays the Cutwail spammers to send out emails to infect new victims
  2. the Cutwail spammer sends out his emails. On July 10th, they were "Essentra Past Due" and emails imitating M&T Bank and NatWest Bank
  3. while many people delete the emails, ignore the emails, or have them blocked by spam, SOME people click on the emails
  4. the ".scr" email attachment infects their computer and starts generating "Domain Generation Algorithm" domains.
  5. each domain is queried for. the Bot computers say "Hey, Internet! Does this domain exist?"
  6. on July 10th, cfs50p1je5ljdfs3p7n17odtuw.biz existed ... "the Internet" said "Yes, this exists and NS1.ZAEHROMFUY.IN is the Nameserver that can tell you where it is."
  7. When most nameservers tell the address of a computer, they give a "Time To Live" that says "The answer I'm giving you is probably good for 24 hours" or 2 days, or a week, or whatever. But the Nameserver used in a FastFlux Bot, like, NS1.ZAEHROMFUY.IN, usually gives a "Time To Live" answer that says "The answer I'm giving you is only good for about 5 minutes. After 5 minutes, you need to ask me again in case the address has changed."
  8. NS1.ZAEHROMFUY.IN receives constant updates from "newGOZ Criminal" of servers all over the world (but mostly in Ukraine) that have been hacked. Almost every time you ask the nameserver "Where is the newGOZ domain?" it will give you a different answer.
  9. the "FastFlux C&C" boxes are now running nginx proxy software that says "Whatever you ask me, I will ask the servers at the Evil Lair of newGOZ. Whatever the Evil Lair of newGOZ wants to say, I will pass back to you.
  10. Updates from the Evil Lair get passed back THROUGH the FastFlux Proxy and give the newGOZ bots new malware or commands
  11. All traffic to and from the newGOZ bot, whether it is the bot "checking in" or the criminal pushing an "update" goes through one of the proxies, which are constantly changing.

Fast Flux newGOZ resolutions

All of the servers (or workstations) in this table were used as Fast Flux C&C nodes last night by the newGOZ botnet. We'll keep tracking this with friends from ShadowServer, DissectCyber.com and others and sharing this information with our trusted partners, but I wanted to throw out this example. If you have ability to look at "Net Flow" for any of these computers, you may be able to help us locate "The Evil Lair of the newGOZ Criminal." (Which sounds like a lot more fun than just looking at packet dumps, doesn't it? Sorry, this isn't my job, it is my passion. Geeks have to convince themselves they are Fighting Evil or we would get bored. Since the first GOZ enabled the theft of $100 Million or so ( for more see as an example Crooks Seek Revival of GameOver Zeus Botnet where Brian even shares the FBI Wanted Poster of the guy who is thought to be behind Zeus.

2014-07-10 20:37:10-05 92.248.160.157 92.248.128.0/17 OLYMPUS-NSP-AS ZAO _AKADO-Ekaterinburg_,RU 30868 RU ripencc
2014-07-10 20:38:04-05 108.20.219.49 108.20.0.0/16 UUNET - MCI Communications Services, Inc. d/b/a Verizon Business,US 701 US arin
2014-07-10 20:38:36-05 113.163.13.252 113.163.0.0/19 VNPT-AS-VN VNPT Corp,VN 45899 VN apnic
2014-07-10 20:39:03-05 114.46.251.46 114.46.0.0/16 HINET Data Communication Business Group,TW 3462 TW apnic
2014-07-10 20:39:24-05 176.108.15.141 176.108.0.0/19 KADRTV-AS Cadr-TV LLE TVRC,CZ 57800 UA ripencc
2014-07-10 20:40:39-05 178.150.136.252 178.150.136.0/22 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-10 20:40:52-05 37.25.4.162 37.25.0.0/19 BELCOMUA-AS ZAO _Belcom_,UA 25385 UA ripencc
2014-07-10 20:41:05-05 69.143.45.75 69.143.0.0/16 CMCS - Comcast Cable Communications, Inc.,US 33657 US arin
2014-07-10 20:41:18-05 77.242.172.30 77.242.172.0/24 UHT-AS UHT - Ukrainian High Technologies Ltd.,UA 30955 UA ripencc
2014-07-10 20:41:31-05 85.29.179.7 85.29.179.0/24 ORBITA-PLUS-AS ORBITA-PLUS Autonomous System,KZ 21299 KZ ripencc
2014-07-10 20:47:43-05 24.101.46.15 24.101.32.0/19 ACS-INTERNET - Armstrong Cable Services,US 27364 US arin
2014-07-10 20:47:56-05 37.115.246.222 37.115.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 20:48:10-05 67.68.99.137 67.68.96.0/22 BACOM - Bell Canada,CA 577 CA arin
2014-07-10 20:48:23-05 70.24.225.245 70.24.224.0/22 BACOM - Bell Canada,CA 577 CA arin
2014-07-10 20:48:43-05 75.76.166.8 75.76.128.0/17 WOW-INTERNET - WideOpenWest Finance LLC,US 12083 US arin
2014-07-10 20:48:57-05 76.127.161.112 76.127.128.0/17 COMCAST-7015 - Comcast Cable Communications Holdings, Inc,US 7015 US arin
2014-07-10 20:49:21-05 91.197.171.38 91.197.168.0/22 INTRAFFIC-AS Intraffic LLC,UA 43658 UA ripencc
2014-07-10 20:49:44-05 99.248.110.218 99.224.0.0/11 ROGERS-CABLE - Rogers Cable Communications Inc.,CA 812 CA arin
2014-07-10 20:50:02-05 100.44.184.18 100.44.160.0/19 WAYPORT - Wayport, Inc.,US 14654 US arin
2014-07-10 20:52:54-05 109.207.127.59 109.207.112.0/20 TELELAN-AS Teleradiocompany TeleLan LLC,UA 196740 UA ripencc
2014-07-10 21:07:24-05 178.214.223.104 178.214.192.0/19 UOS Ukraine Optical Systems LLC,UA 42546 UA ripencc
2014-07-10 21:07:56-05 212.22.192.224 212.22.192.0/24 FREENET-AS Freenet Ltd.,UA 31148 UA ripencc
2014-07-10 21:08:11-05 31.133.118.121 31.133.118.0/24 ENTERRA-AS Private Enterprise _Enterra_,UA 48964 UA ripencc
2014-07-10 21:08:24-05 37.229.149.56 37.229.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 21:08:45-05 46.119.77.105 46.119.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 21:09:21-05 98.14.34.141 98.14.0.0/16 SCRR-12271 - Time Warner Cable Internet LLC,US 12271 US arin
2014-07-10 21:09:37-05 98.109.164.97 98.109.0.0/16 UUNET - MCI Communications Services, Inc. d/b/a Verizon Business,US 701 US arin
2014-07-10 21:12:28-05 109.162.0.21 109.162.0.0/18 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 21:12:41-05 178.140.183.193 178.140.0.0/16 NCNET-AS OJSC Rostelecom,RU 42610 RU ripencc
2014-07-10 21:13:42-05 178.158.135.20 178.158.134.0/23 ISP-EASTNET-AS EAST.NET Ltd.,UA 50780 UA ripencc
2014-07-10 21:28:15-05 192.162.118.118 192.162.116.0/22 ANOXIN FIZICHNA OSOBA-PIDPRIEMEC ANOHIN IGOR VALENTINOVICH,UA 39056 UA ripencc
2014-07-10 21:28:18-05 208.120.58.109 208.120.0.0/18 SCRR-12271 - Time Warner Cable Internet LLC,US 12271 US arin
2014-07-10 21:28:18-05 213.111.221.67 213.111.192.0/18 MAINSTREAM-AS PP MainStream,UA 44924 UA ripencc
2014-07-10 21:28:18-05 24.207.209.129 24.207.128.0/17 CHARTER-NET-HKY-NC - Charter Communications,US 20115 US arin
2014-07-10 21:28:18-05 46.181.215.20 46.180.0.0/15 ELIGHT-AS E-Light-Telecom,RU 39927 RU ripencc
2014-07-10 21:28:19-05 68.45.64.5 68.44.0.0/15 CMCS - Comcast Cable Communications, Inc.,US 33659 US arin
2014-07-10 21:28:19-05 75.131.252.100 75.131.224.0/19 CHARTER-NET-HKY-NC - Charter Communications,US 20115 US arin
2014-07-10 21:28:19-05 91.196.60.108 91.196.60.0/22 ARHAT-AS PE Bondar TN,UA 50204 UA ripencc
2014-07-10 21:28:19-05 91.243.218.157 91.243.192.0/19 ID-TELECOM-AS Intellect Dnepr Telecom LLC,UA 59567 UA ripencc
2014-07-10 21:28:19-05 96.246.91.160 96.246.0.0/17 UUNET - MCI Communications Services, Inc. d/b/a Verizon Business,US 701 US arin
2014-07-10 21:28:19-05 134.249.11.2 134.249.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 21:49:21-05 188.190.5.162 188.190.0.0/19 ASINTTEL Inttel Ltd.,UA 56370 UA ripencc
2014-07-10 21:49:22-05 5.248.110.252 5.248.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 21:49:22-05 31.43.162.96 31.43.160.0/19 KRASNET-UA-AS Krasnet ltd.,UA 50576 UA ripencc
2014-07-10 21:49:22-05 31.135.144.54 31.135.144.0/22 Technical Centre Radio Systems Ltd.,UA 20539 UA ripencc
2014-07-10 21:49:22-05 37.112.195.140 37.112.192.0/22 KRSK-AS CJSC _ER-Telecom Holding_,RU 50544 RU ripencc
2014-07-10 21:49:22-05 46.119.181.97 46.118.0.0/15 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 21:49:22-05 50.83.36.2 50.83.32.0/21 MEDIACOM-ENTERPRISE-BUSINESS - Mediacom Communications Corp,US 30036 US arin
2014-07-10 21:49:23-05 176.8.92.131 176.8.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 21:49:23-05 176.98.12.218 176.98.0.0/19 CRYSTAL-AS Crystal Telecom Ltd,CZ 49889 UA ripencc
2014-07-10 21:49:23-05 178.137.8.215 178.137.0.0/17 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 22:08:06-05 95.110.45.151 95.110.0.0/17 JSCBIS-AS OJSC _Bashinformsvyaz_,RU 28812 RU ripencc
2014-07-10 22:08:08-05 176.8.21.85 176.8.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 22:08:08-05 178.150.89.211 178.150.89.0/24 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-10 22:08:08-05 188.231.191.140 188.231.191.0/24 FREENET-AS Freenet Ltd.,UA 31148 UA ripencc
2014-07-10 22:08:08-05 80.66.79.74 80.66.76.0/22 RISS-AS LLC _Ris-Tel_,RU 20803 RU ripencc
2014-07-10 22:08:09-05 81.200.148.6 81.200.144.0/20 ARTEM-CATV-AS JSC Artemovskoye Interaktivnoe Televidenie,RU 41070 RU ripencc
2014-07-10 22:08:09-05 95.46.219.178 95.46.219.0/24 VITEBSK-TV-ISP-AS OAO Vitebskiy Oblastnoy Techno-Torgoviy Center Garant,BY 50528 CZ ripencc
2014-07-10 22:08:09-05 95.78.166.17 95.78.128.0/18 ERTH-CHEL-AS CJSC _ER-Telecom Holding_,RU 41661 RU ripencc
2014-07-10 22:29:38-05 178.214.169.234 178.214.160.0/19 LUGANET-AS ARTA Ltd,UA 39728 UA ripencc
2014-07-10 22:29:38-05 188.16.223.225 188.16.192.0/18 USI OJSC Rostelecom,RU 6828 RU ripencc
2014-07-10 22:29:38-05 194.246.105.173 194.246.104.0/23 ASN-FUJILINE Trade House _Inet_ Ltd,UA 31000 UA ripencc
2014-07-10 22:29:39-05 70.75.230.0 70.75.0.0/16 SHAW - Shaw Communications Inc.,CA 6327 CA arin
2014-07-10 22:29:39-05 78.137.17.91 78.137.0.0/19 MCLAUT-AS LLC _McLaut-Invest_,UA 25133 UA ripencc
2014-07-10 22:29:39-05 176.117.86.162 176.117.80.0/20 LURENET-AS PP _Lurenet_,UA 50643 UA ripencc
2014-07-10 22:48:09-05 213.111.163.205 213.111.128.0/18 ALNET-AS PP SKS-Lugan,UA 35804 UA ripencc
2014-07-10 22:48:10-05 99.249.29.20 99.249.0.0/16 ROGERS-CABLE - Rogers Cable Communications Inc.,CA 812 CA arin
2014-07-10 22:48:10-05 109.254.35.236 109.254.0.0/16 DEC-AS Donbass Electronic Communications Ltd.,UA 20590 UA ripencc
2014-07-10 22:48:10-05 136.169.151.67 136.169.128.0/19 UBN-AS OJSC _Ufanet_,RU 24955 RU ripencc
2014-07-10 22:48:10-05 176.102.209.127 176.102.192.0/19 KUTS-AS Center for Information Technologies _Fobos_ Ltd.,UA 39822 UA ripencc
2014-07-10 22:48:10-05 178.141.160.202 178.141.0.0/16 MTS-KRV-AS MTS OJSC,RU 44677 RU ripencc
2014-07-10 22:48:10-05 178.213.191.181 178.213.184.0/21 SKYNET-UA-AS FOP Shoruk Andriy Olexanderovich,UA 196777 UA ripencc
2014-07-10 22:48:10-05 184.152.102.159 184.152.0.0/16 SCRR-12271 - Time Warner Cable Internet LLC,US 12271 US arin
2014-07-10 22:48:10-05 213.110.137.77 213.110.128.0/19 SUNNET-AS PE Gritcun Oleksandr Viktorovich,UA 47889 UA ripencc
2014-07-10 23:08:56-05 91.219.254.25 91.219.254.0/24 MONOLITH-AS LLC MONOLITH.NET,UA 48230 UA ripencc
2014-07-10 23:08:58-05 109.87.83.213 109.87.80.0/22 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-10 23:09:00-05 178.137.176.9 178.137.128.0/17 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 23:09:00-05 78.109.46.210 78.109.46.0/24 SIBRON-AS Closed Joint Stock Company COMSTAR-Regiony,RU 13155 RU ripencc
2014-07-10 23:09:00-05 80.70.71.41 80.70.64.0/20 ENERGYTEL Energytel LLC,UA 51317 UA ripencc
2014-07-10 23:27:45-05 71.75.52.101 71.75.0.0/16 SCRR-11426 - Time Warner Cable Internet LLC,US 11426 US arin
2014-07-10 23:27:45-05 176.8.72.36 176.8.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 23:27:45-05 178.74.214.94 178.74.192.0/18 EVEREST-AS _Everest_ Broadcasting Company Ltd,UA 49223 UA ripencc
2014-07-10 23:27:45-05 178.141.9.72 178.141.0.0/16 MTS-KRV-AS MTS OJSC,RU 44677 RU ripencc
2014-07-10 23:27:45-05 188.230.87.17 188.230.80.0/21 ABUA-AS LLC AB Ukraine,UA 43266 UA ripencc
2014-07-10 23:27:45-05 37.229.79.59 37.229.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 23:27:45-05 62.16.38.131 62.16.32.0/19 FPIC-AS CJSC _COMSTAR-regions_,RU 15640 RU ripencc
2014-07-10 23:49:05-05 176.113.227.109 176.113.224.0/19 LUGANET-AS ARTA Ltd,UA 39728 UA ripencc
2014-07-10 23:49:05-05 193.106.184.92 193.106.184.0/22 BOSPOR-AS Bospor-Telecom LLC,UA 42238 UA ripencc
2014-07-10 23:49:05-05 46.172.231.154 46.172.224.0/19 TOPHOST-AS SPD Kurilov Sergiy Oleksandrovich,UA 45043 UA ripencc
2014-07-10 23:49:05-05 74.129.235.88 74.128.0.0/12 SCRR-10796 - Time Warner Cable Internet LLC,US 10796 US arin
2014-07-10 23:49:05-05 77.121.129.181 77.121.128.0/21 VOLIA-AS Kyivski Telekomunikatsiyni Merezhi LLC,UA 25229 UA ripencc
2014-07-10 23:49:05-05 78.27.159.112 78.27.128.0/18 DOMASHKA-AS Domashnya Merezha LLC,UA 15683 UA ripencc
2014-07-10 23:49:05-05 91.196.55.7 91.196.52.0/22 KOMITEX-AS PP KOM i TEX,UA 30886 UA ripencc
2014-07-10 23:49:06-05 94.153.23.170 94.153.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-10 23:49:06-05 109.87.222.148 109.87.222.0/24 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 00:07:17-05 178.215.178.112 178.215.176.0/20 FENIXVT-AS Private Enterprise Firma Fenix VT,RU 39399 UA ripencc
2014-07-11 00:07:19-05 195.90.130.19 195.90.128.0/18 ROSNET-AS OJSC Rostelecom,RU 6863 RU ripencc
2014-07-11 00:07:19-05 37.25.118.55 37.25.96.0/19 WILDPARK-AS ISP WildPark, Ukraine, Nikolaev,UA 31272 UA ripencc
2014-07-11 00:07:19-05 37.229.215.18 37.229.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 00:07:19-05 87.244.34.238 87.244.32.0/21 SUNLINK-AS Sunlink Telecom ISP, Tula, Russia,RU 35401 RU ripencc
2014-07-11 00:07:19-05 91.219.233.40 91.219.232.0/22 REALWEB-AS Private Enterprise RealWeb,UA 41161 UA ripencc
2014-07-11 00:07:20-05 173.95.149.72 173.92.0.0/14 SCRR-11426 - Time Warner Cable Internet LLC,US 11426 US arin
2014-07-11 00:07:20-05 178.150.221.2 178.150.220.0/23 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 00:07:20-05 178.151.165.182 178.151.165.0/24 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 00:28:03-05 109.87.42.122 109.87.40.0/21 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 00:28:04-05 109.200.228.156 109.200.224.0/19 BREEZE-NETWORK TOV TRK _Briz_,UA 34661 UA ripencc
2014-07-11 00:28:04-05 31.135.226.91 31.135.224.0/20 TRYTECH-AS Trytech Ltd.,RU 44056 RU ripencc
2014-07-11 00:28:04-05 46.172.145.109 46.172.128.0/19 UTEAM-AS Uteam LTD,UA 49125 UA ripencc
2014-07-11 00:49:18-05 109.229.198.37 109.229.192.0/19 PRONET_LV SIA _PRONETS_,LV 43075 LV ripencc
2014-07-11 00:49:20-05 178.165.98.17 178.165.64.0/18 CITYNET-AS Maxnet Autonomous System,UA 34700 UA ripencc
2014-07-11 00:49:20-05 195.114.145.69 195.114.144.0/20 DATAGROUP PRIVATE JOINT STOCK COMPANY _DATAGROUP_,UA 21219 UA ripencc
2014-07-11 00:49:20-05 5.58.15.61 5.58.0.0/18 NOLAN-AS Lanet Network Ltd,UA 43120 UA ripencc
2014-07-11 00:49:20-05 46.147.186.225 46.147.184.0/22 NEOLINK CJSC _ER-Telecom Holding_,RU 34590 RU ripencc
2014-07-11 00:49:20-05 46.219.50.56 46.219.50.0/24 FREENET-AS Freenet Ltd.,UA 31148 UA ripencc
2014-07-11 00:49:20-05 89.185.24.218 89.185.24.0/21 TVCOM-AS TVCOM Ltd.,UA 34092 UA ripencc
2014-07-11 00:49:20-05 94.158.73.89 94.158.64.0/20 BIGNET-AS PE Yuri Stanislavovich Demenin,UA 43668 UA ripencc
2014-07-11 00:49:20-05 95.47.151.247 95.47.148.0/22 TKS-AS Sumski Telecom Systems Ltd,UA 41967 CZ ripencc
2014-07-11 01:09:51-05 71.227.196.156 71.227.128.0/17 COMCAST-33650 - Comcast Cable Communications, Inc.,US 33650 US arin
2014-07-11 01:09:52-05 87.224.164.135 87.224.128.0/17 TELENET-AS OJSC Rostelecom,RU 35154 RU ripencc
2014-07-11 01:09:52-05 93.127.60.17 93.127.60.0/23 ALKAR-AS PRIVATE JOINT-STOCK COMPANY _FARLEP-INVEST_,RU 6703 UA ripencc
2014-07-11 01:09:52-05 109.227.127.25 109.227.96.0/19 MCLAUT-AS LLC _McLaut-Invest_,UA 25133 UA ripencc
2014-07-11 01:09:52-05 178.151.9.221 178.151.9.0/24 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 01:09:52-05 178.151.154.233 178.151.154.0/24 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 01:09:52-05 194.187.108.182 194.187.108.0/22 TERABIT TERABIT LLC,UA 29491 UA ripencc
2014-07-11 01:09:52-05 37.229.149.148 37.229.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 01:09:52-05 46.118.151.246 46.118.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 01:09:52-05 46.219.77.143 46.219.77.0/24 FREENET-AS Freenet Ltd.,UA 31148 UA ripencc
2014-07-11 01:28:30-05 178.137.232.234 178.137.128.0/17 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 01:28:31-05 178.150.177.83 178.150.176.0/23 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 01:28:31-05 178.151.14.223 178.151.14.0/24 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 01:28:31-05 178.151.227.102 178.151.227.0/24 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 01:28:31-05 188.231.170.228 188.231.170.0/24 FREENET-AS Freenet Ltd.,UA 31148 UA ripencc
2014-07-11 01:28:31-05 5.34.112.211 5.34.0.0/17 SATELCOM-AS SA-Telcom LLP,KZ 35566 KZ ripencc
2014-07-11 01:28:31-05 46.56.64.196 46.56.64.0/19 MTSBY-AS Mobile TeleSystems JLLC,BY 25106 BY ripencc
2014-07-11 01:28:31-05 46.173.171.188 46.173.168.0/22 BEREZHANY-AS Galitski Telekommunications Ltd,UA 49183 UA ripencc
2014-07-11 01:28:31-05 176.215.86.177 176.215.84.0/22 KRSK-AS CJSC _ER-Telecom Holding_,RU 50544 RU ripencc
2014-07-11 01:49:53-05 31.202.226.233 31.202.224.0/22 FORMAT-TV-AS MSP Format Ltd.,UA 6712 UA ripencc
2014-07-11 01:49:53-05 46.33.59.6 46.33.56.0/22 BLACKSEA TV Company _Black Sea_ Ltd,UA 31593 UA ripencc
2014-07-11 01:49:53-05 46.149.179.87 46.149.179.0/24 ISP-KIM-NET Kalush Information Network LTD,UA 197522 UA ripencc
2014-07-11 01:49:53-05 82.112.53.75 82.112.32.0/19 KTEL-AS K Telecom Ltd.,RU 48642 RU ripencc
2014-07-11 01:49:53-05 95.133.181.160 95.133.128.0/18 UKRTELNET JSC UKRTELECOM,UA 6849 UA ripencc
2014-07-11 01:49:53-05 109.86.112.170 109.86.112.0/22 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 01:49:53-05 124.197.73.68 124.197.64.0/18 MOBILEONELTD-AS-AP MobileOne Ltd. Mobile/Internet Service Provider Singapore,SG 4773 SG apnic
2014-07-11 01:49:54-05 178.137.97.155 178.137.0.0/17 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 01:49:54-05 217.112.220.202 217.112.208.0/20 TELEPORTSV PrivateJSC DataGroup,UA 15785 UA ripencc
2014-07-11 02:08:05-05 94.76.127.113 94.76.127.0/24 FREENET-AS Freenet Ltd.,UA 31148 UA ripencc
2014-07-11 02:08:05-05 213.231.6.9 213.231.0.0/18 BREEZE-NETWORK TOV TRK _Briz_,UA 34661 UA ripencc
2014-07-11 02:08:05-05 37.57.203.171 37.57.200.0/21 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 02:29:13-05 31.40.33.46 31.40.32.0/19 GORSET-AS Gorodskaya Set Ltd.,RU 49776 RU ripencc
2014-07-11 02:29:13-05 37.53.73.152 37.52.0.0/14 6849 6877 UA ripencc
2014-07-11 02:29:14-05 46.119.213.230 46.119.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 02:29:14-05 46.175.73.188 46.175.64.0/20 MEDIANA-AS Mediana ltd.,UA 56347 UA ripencc
2014-07-11 02:29:14-05 176.73.87.120 176.73.0.0/17 CAUCASUS-CABLE-SYSTEM Caucasus Online Ltd.,GE 20771 GE ripencc
2014-07-11 02:29:14-05 178.219.91.40 178.219.90.0/23 ASDNEPRONET Dnepronet Ltd.,UA 51069 UA ripencc
2014-07-11 02:29:14-05 185.14.102.108 185.14.102.0/24 ORBITA-PLUS-AS ORBITA-PLUS Autonomous System,KZ 21299 KZ ripencc
2014-07-11 02:29:14-05 195.225.147.101 195.225.144.0/22 UA-LINK-AS NPF LINK Ltd.,UA 34359 UA ripencc
2014-07-11 02:50:03-05 46.150.74.97 46.150.64.0/19 VIVANET-AS Vivanet Ltd,UA 44728 UA ripencc
2014-07-11 02:50:04-05 46.150.91.162 46.150.64.0/19 VIVANET-AS Vivanet Ltd,UA 44728 UA ripencc
2014-07-11 02:50:04-05 76.14.215.195 76.14.192.0/18 WAVE-CABLE - Wave Broadband,US 32107 US arin
2014-07-11 02:50:04-05 82.193.220.254 82.193.192.0/19 VODATEL-AS Metronet telekomunikacije d.d.,HR 25528 HR ripencc
2014-07-11 02:50:04-05 178.136.227.61 178.136.226.0/23 ALKAR-AS PRIVATE JOINT-STOCK COMPANY _FARLEP-INVEST_,RU 6703 UA ripencc
2014-07-11 02:50:04-05 178.137.69.209 178.137.0.0/17 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 02:50:04-05 194.28.176.201 194.28.176.0/22 KUZNETSOVSK-AS FOP Chaika Nadija Jakivna,UA 197073 UA ripencc
2014-07-11 02:50:04-05 212.87.183.197 212.87.160.0/19 EDN-AS Online Technologies LTD,UA 45025 UA ripencc
2014-07-11 02:50:04-05 213.231.12.80 213.231.0.0/18 BREEZE-NETWORK TOV TRK _Briz_,UA 34661 UA ripencc
2014-07-11 02:50:04-05 46.119.175.13 46.119.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 03:09:01-05 46.33.50.175 46.33.48.0/21 LIS Telecompany LiS LTD,UA 35588 UA ripencc
2014-07-11 03:09:04-05 46.98.237.27 46.98.0.0/16 FREGAT-AS ISP _Fregat_ Ltd.,UA 15377 UA ripencc
2014-07-11 03:09:04-05 46.185.73.100 46.185.64.0/18 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 03:09:04-05 79.164.171.236 79.164.0.0/16 CNT-AS OJSC Central telegraph,RU 8615 RU ripencc
2014-07-11 03:09:04-05 91.244.137.151 91.244.128.0/20 PERVOMAYSK-AS PP _SKS-Pervomaysk_,UA 44798 UA ripencc
2014-07-11 03:09:05-05 109.86.234.51 109.86.232.0/21 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 03:09:05-05 109.207.121.193 109.207.112.0/20 TELELAN-AS Teleradiocompany TeleLan LLC,UA 196740 UA ripencc
2014-07-11 03:09:05-05 176.108.235.203 176.108.232.0/22 SKM-AS PE Yaremenko O.V.,UA 39422 UA ripencc
2014-07-11 03:09:05-05 193.106.82.45 193.106.80.0/22 DATAGROUP PRIVATE JOINT STOCK COMPANY _DATAGROUP_,UA 21219 UA ripencc
2014-07-11 03:09:05-05 31.129.65.152 31.129.64.0/19 ASDNEPRONET Dnepronet Ltd.,UA 51069 UA ripencc
2014-07-11 03:09:05-05 37.232.181.13 37.232.160.0/19 INTERNET-CENTER-AS Net By Net Holding LLC,RU 42420 RU ripencc
2014-07-11 03:29:59-05 109.201.240.84 109.201.224.0/19 VOLIA-AS Kyivski Telekomunikatsiyni Merezhi LLC,UA 25229 UA ripencc
2014-07-11 03:30:00-05 141.101.11.69 141.101.0.0/19 WILDPARK-AS ISP WildPark, Ukraine, Nikolaev,UA 31272 UA ripencc
2014-07-11 03:30:00-05 188.230.1.99 188.230.0.0/21 ABUA-AS LLC AB Ukraine,UA 43266 UA ripencc
2014-07-11 03:30:01-05 46.119.134.13 46.118.0.0/15 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 03:30:01-05 77.79.140.237 77.79.128.0/18 UBN-AS OJSC _Ufanet_,RU 24955 RU ripencc
2014-07-11 03:30:01-05 77.121.125.112 77.121.96.0/19 VOLIA-AS Kyivski Telekomunikatsiyni Merezhi LLC,UA 25229 UA ripencc
2014-07-11 03:30:01-05 77.123.241.141 77.123.224.0/19 IVC IVC-Donbass Ltd,UA 48169 UA ripencc
2014-07-11 03:48:03-05 213.231.4.163 213.231.0.0/18 BREEZE-NETWORK TOV TRK _Briz_,UA 34661 UA ripencc
2014-07-11 03:48:03-05 5.248.133.146 5.248.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 03:48:03-05 81.163.136.160 81.163.128.0/19 DIDAN-AS Didan Group LTD,UA 47694 UA ripencc
2014-07-11 03:48:03-05 91.244.232.200 91.244.232.0/22 VITA-AS Teleradiokompaniya Vizit-A Limited Liability Company,UA 197175 UA ripencc
2014-07-11 03:48:03-05 176.112.17.229 176.112.0.0/19 MAINSTREAM-AS PP MainStream,UA 44924 UA ripencc
2014-07-11 03:48:03-05 176.124.1.31 176.124.0.0/19 DIDAN-AS Didan Group LTD,UA 47694 UA ripencc
2014-07-11 03:48:03-05 193.93.238.13 193.93.236.0/22 STAVSET-AS Kvartal Plus Ltd,RU 49325 RU ripencc
2014-07-11 04:09:03-05 46.118.136.44 46.118.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 04:09:05-05 46.172.128.249 46.172.128.0/19 UTEAM-AS Uteam LTD,UA 49125 UA ripencc
2014-07-11 04:09:05-05 94.41.219.215 94.41.192.0/18 UBN-AS OJSC _Ufanet_,RU 24955 RU ripencc
2014-07-11 04:09:05-05 109.162.59.249 109.162.0.0/18 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 04:09:05-05 178.45.188.246 178.45.160.0/19 OJSC Rostelecom,RU 15500 RU ripencc
2014-07-11 04:09:05-05 178.88.215.41 178.88.0.0/16 KAZTELECOM-AS JSC Kazakhtelecom,KZ 9198 KZ ripencc
2014-07-11 04:09:05-05 188.163.29.68 188.163.0.0/17 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 04:09:05-05 5.14.25.76 5.12.0.0/14 RCS-RDS RCS & RDS SA,RO 8708 RO ripencc
2014-07-11 04:09:05-05 5.248.99.163 5.248.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 04:27:48-05 178.151.23.241 178.151.22.0/23 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 04:27:50-05 31.169.23.129 31.169.20.0/22 DTVKZ-AS JSC Kazakhtelecom,KZ 39725 KZ ripencc
2014-07-11 04:27:50-05 77.122.235.167 77.122.192.0/18 VOLIA-AS Kyivski Telekomunikatsiyni Merezhi LLC,UA 25229 UA ripencc
2014-07-11 04:27:50-05 78.62.94.153 78.62.80.0/20 TEOLTAB TEO LT AB Autonomous System,LT 8764 LT ripencc
2014-07-11 04:27:50-05 89.209.96.231 89.209.0.0/16 MTS MTS OJSC,RU 8359 UA ripencc
2014-07-11 04:27:50-05 93.79.143.194 93.79.128.0/17 VOLIA-AS Kyivski Telekomunikatsiyni Merezhi LLC,UA 25229 UA ripencc
2014-07-11 04:27:50-05 176.8.79.228 176.8.0.0/16 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 04:27:50-05 178.141.98.171 178.141.0.0/16 MTS-KRV-AS MTS OJSC,RU 44677 RU ripencc
2014-07-11 04:49:18-05 176.113.146.32 176.113.144.0/20 BELICOM-AS FOP Bilenkiy Olexander Naumovich,UA 44010 UA ripencc
2014-07-11 04:49:21-05 178.137.109.91 178.137.0.0/17 KSNET-AS _Kyivstar_ PJSC,UA 15895 UA ripencc
2014-07-11 04:49:21-05 213.111.226.174 213.111.192.0/18 MAINSTREAM-AS PP MainStream,UA 44924 UA ripencc
2014-07-11 04:49:21-05 217.73.84.131 217.73.80.0/21 INFOMIR-NET Infomir JSC,UA 44291 UA ripencc
2014-07-11 04:49:21-05 5.20.162.237 5.20.160.0/19 CGATES-AS UAB _Cgates_,LT 21412 LT ripencc
2014-07-11 04:49:21-05 5.105.1.241 5.105.0.0/16 CDS-AS Cifrovye Dispetcherskie Sistemy,UA 43554 UA ripencc
2014-07-11 04:49:21-05 77.122.193.42 77.122.192.0/18 VOLIA-AS Kyivski Telekomunikatsiyni Merezhi LLC,UA 25229 UA ripencc
2014-07-11 04:49:21-05 91.225.162.98 91.225.160.0/22 ASSPDCHERNEGA SPD Chernega Aleksandr Anatolevich,UA 56400 UA ripencc
2014-07-11 04:49:21-05 91.236.249.33 91.236.248.0/22 SNAK-AS IP-Connect LLC,UA 57944 UA ripencc
2014-07-11 04:49:21-05 91.244.139.49 91.244.128.0/20 PERVOMAYSK-AS PP _SKS-Pervomaysk_,UA 44798 UA ripencc
2014-07-11 04:49:21-05 109.86.76.58 109.86.64.0/20 BANKINFORM-AS TOV _Bank-Inform_,UA 13188 UA ripencc
2014-07-11 04:49:21-05 176.36.67.204 176.36.0.0/14 LANETUA-AS Lanet Network Ltd.,UA 39608 UA ripencc
2014-07-11 05:08:15-05 46.46.96.199 46.46.64.0/18 FLAGMAN-AS TOV _Flagman Telecom_,UA 48045 UA ripencc
2014-07-11 05:08:16-05 46.149.178.203 46.149.176.0/20 ISP-KIM-NET Kalush Information Network LTD,UA 197522 UA ripencc
2014-07-11 05:08:16-05 95.37.213.26 95.37.128.0/17 NMTS-AS OJSC Rostelecom,RU 25405 RU ripencc
2014-07-11 05:08:16-05 178.251.109.168 178.251.104.0/21 DATALINE-AS Dataline LLC,UA 35297 UA ripencc
2014-07-11 05:08:17-05 31.41.128.57 31.41.128.0/21 ANOXIN FIZICHNA OSOBA-PIDPRIEMEC ANOHIN IGOR VALENTINOVICH,UA 39056 UA ripencc
2014-07-11 05:27:32-05 81.90.233.231 81.90.233.0/24 RADIOCOM-AS RadioCom ISP Autonomous System,UA 25071 UA ripencc
2014-07-11 05:27:32-05 81.162.70.217 81.162.64.0/20 GIGABYTE-AS Private Company Center for Development Information Technology _Gigabyte_,UA 198293 UA ripencc
2014-07-11 05:27:32-05 89.44.89.68 89.44.88.0/22 DNC-AS IM Data Network Communication SRL,MD 41053 RO ripencc
2014-07-11 05:27:32-05 91.244.148.241 91.244.144.0/21 PERVOMAYSK-AS PP _SKS-Pervomaysk_,UA 44798 UA ripencc
2014-07-11 05:27:32-05 188.168.94.122 188.168.0.0/16 TTK-RTL Closed Joint Stock Company TransTeleCom,RU 15774 RU ripencc
2014-07-11 05:27:32-05 62.80.161.77 62.80.160.0/19 INTERTELECOM-AS PJSC Inter-Telecom,UA 25386 UA ripencc
2014-07-11 05:30:03-05 198.105.254.240 198.105.254.0/24 SGINC - Search Guide Inc,US 36029 US arin
2014-07-11 05:30:03-05 198.105.244.240 198.105.244.0/24 SGINC - Search Guide Inc,US 36029 US arin