In addition to post of:
http://www.kernelmode.info/forum/viewto ... =90#p22036
Supporting report posted on:
http://www.kernelmode.info/forum/viewto ... =90#p22029
CABIN.SU (CryptoLocker domain reported) is still on fast flux, see result on limited query below,
in my machine these bunch of 12 uniq IP addresses came up after 5 seconds:
Code: Select all$ for i in 1 2 3 4 5; do dig +short cabin.su A; sleep 1; done
50.171.218.212
178.137.84.38
195.222.73.80
74.105.175.19
185.33.143.175
178.217.205.173
94.244.41.91
109.87.132.247
31.133.71.172
213.109.88.104
212.75.22.124
176.8.243.47
195.222.73.80
212.75.22.124
109.87.132.247
94.244.41.91
213.109.88.104
178.217.205.173
176.8.243.47
185.33.143.175
50.171.218.212
31.133.71.172
74.105.175.19
178.137.84.38
74.105.175.19
195.222.73.80
178.217.205.173
178.137.84.38
31.133.71.172
212.75.22.124
213.109.88.104
185.33.143.175
109.87.132.247
94.244.41.91
50.171.218.212
176.8.243.47
50.171.218.212
213.109.88.104
109.87.132.247
176.8.243.47
212.75.22.124
31.133.71.172
185.33.143.175
74.105.175.19
178.217.205.173
195.222.73.80
178.137.84.38
94.244.41.91
31.133.71.172
50.171.218.212
212.75.22.124
94.244.41.91
213.109.88.104
74.105.175.19
178.217.205.173
178.137.84.38
185.33.143.175
195.222.73.80
176.8.243.47
109.87.132.247
$
Just for the information, the IP sources:
Code: Select all109.87.132.247|247.132.87.109.triolan.net.|13188 | 109.87.128.0/21 | BANKINFORM | UA | UKR.NET | TOV BANK-INFORM
176.8.243.47|176-8-243-47-chg.broadband.kyivstar.net.|15895 | 176.8.0.0/16 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC
178.137.84.38|178-137-84-38-lvv.broadband.kyivstar.net.|15895 | 178.137.0.0/17 | KSNET | UA | KYIVSTAR.NET | KYIVSTAR PJSC
178.217.205.173||196767 | 178.217.205.0/24 | INMART1 | UA | INMART.NET.UA | INMART-INTERNET LTD
185.33.143.175|host175-143-33-185.lds.net.ua.|41709 | 185.33.140.0/22 | LDS | UA | LDS.NET.UA | LUGANSKY MEREZHY LTD
195.222.73.80|dynamic-vpdn-195-222-73-80.solo.by.|12358 | 195.222.64.0/20 | SOLO | BY | BELSONET.NET | SOLO LTD.
212.75.22.124|host-212-75-22-124.bbccable.net.|47982 | 212.75.0.0/19 | BBCCABLE | BG | BBCCABLE.NET | BBC CABLE LTD
213.109.88.104|s-213-109-88-104.under.net.ua.|41435 | 213.109.80.0/20 | UNDERNET | UA | UNDER.NET.UA | UNDERNET LTD.
31.133.71.172|pool-31-133-71-172.optima-east.net.|48882 | 31.133.64.0/20 | OPTIMA-SHID | UA | OPTIMA-EAST.NET | LLC OPTIMA-EAST
50.171.218.212|c-50-171-218-212.hsd1.mn.comcast.net.|7922 | 50.128.0.0/9 | COMCAST-7922 | US | COMCAST.NET | COMCAST CABLE COMMUNICATIONS HOLDINGS INC
74.105.175.19|pool-74-105-175-19.nwrknj.fios.verizon.net.|701 | 74.105.0.0/16 | UUNET | US | VERIZON.COM | VERIZON ONLINE LLC
94.244.41.91|ip-295b.proline.net.ua.|48278 | 94.244.0.0/18 | UKRDATACOM-NET | UA | RUSANOVKA-NET.KIEV.UA | UKRDATACOM LLC
As per seen above, mostly are from eastern Europe (Ukraine).
I worry for this case because these IP are used also for Kelihos botnet IPs, Noted: I am not suggesting ANY relation yet, it is too premature. Could be a shared zombies. But for the quick PoC, this sample was received from one of the IP above:
https://www.virustotal.com/en/file/7a5c ... /analysis/
is in the record in VT here:
https://www.virustotal.com/en/ip-addres ... formation/
is a Kelihos botnet trojan.
So let's get back to the usage of domain CABIN.SU ; The DNS query fluctuation of this domain can be a measure of infection hits for the reported CryptoLocker particularly.
I monitor it via Umbrella Labs (OpenDNS), and receiving activities, for example, in yesterday I saw strong query recorded below:
The query like above still happened once in a while from the first time Xyli detected this.
IMHO this is an active threat still and in effort of infection/ransom, hardly to say that is massive, but it hits.
Dilemma has occurred. Since we're not just being here to sit and watch, the request for suspension to RU side was taken 5 days ago, you all should notice this too, but it looks like there is no suspension is executed. Below is evidence of suspension request followed:
This is strange.. Any researchers or LE are on investigation / evidence collecting for CABIN.SU now that may causing pending on suspension? No?
Since this slow response is unlikely happen... Feed back please.