Malicious Toolkit Website 14 #3, 4
Ok this is fourth time in the last two day I got a warning from Norton of a attack block from
Toolkit Website 14
When I do a WHOIS lookup it say it was registered the day before and end like today
The last one said the domain name was open to register ?????
I believe it come from the add on fire-hose there always three off them
Now if it happen to you could you post which three add was showing
Maybe between all of us we can narrow it down to a few so ATS owner can do something about it
Also note ip address is the same ???
mysammers.net (91.229.210.195)
Onlieinglisheng.net (91.229.210.195)
Three add visible was
Register .com
The American Express Gold Rewards Card
Grand Chase
From Whois
Registration Service Provided By: BIGROCK.COM
Contact: +01.4153580892
Website:
www.bigrock.com...
Domain Name: MYSAMMERS.NET
Registrant:
PrivacyProtect.org
Domain Admin (&&&&&&&&&&&)
ID#10760, PO Box 16
Note - All Postal Mails Rejected, visit Privacyprotect.org
Nobby Beach
null,QLD 4218
AU
Tel. +45.36946676
Creation Date: 16-Jun-2012
Expiration Date: 16-Jun-2013
Domain servers in listed order:
dns1.bigrock.com
dns2.bigrock.com
dns3.bigrock.com
dns4.bigrock.com
Administrative Contact:
PrivacyProtect.org
Domain Admin (&&&&&&&&&&&)
ID#10760, PO Box 16
.
From Whois
[Querying whois.ripe.net] [whois.ripe.net] % This is the RIPE Database query service. % The objects are in RPSL format. % % The RIPE Database is
subject to Terms and Conditions. % See
www.ripe.net... % Note: this output has been filtered. % To receive
output for a database update, use the "-B" flag. % Information related to '91.229.210.0 - 91.229.210.255' inetnum: 91.229.210.0 - 91.229.210.255
netname: SIBHOST descr: ChP Timchenko Evgeniy Nikolaevich remarks: SibHost Network country: RU org: ORG-TIMC1-RIPE admin-c: TIMC1-RIPE tech-c:
TIMC1-RIPE status: ASSIGNED PI mnt-by: RIPE-NCC-END-MNT mnt-lower: RIPE-NCC-END-MNT mnt-by: TIMCHENKO-MNT mnt-routes: TIMCHENKO-MNT mnt-domains:
TIMCHENKO-MNT source: RIPE # Filtered organisation: ORG-TIMC1-RIPE org-name: ChP Timchenko Evgeniy Nikolaevich org-type: OTHER address: Ukraine, g.
Kiev, Ivana Kudri str. 2211 address: Russia, Novosibirsk, pr Oktyabrya str. 7119 mnt-ref: TIMCHENKO-MNT mnt-by: TIMCHENKO-MNT source: RIPE #
Filtered person: Timchenko Evgeniy address: Ukraine, Kyiv, Ivana Kudri str. 22/11 address: Russia, Novosibirsk, pr Oktyabrya str. 7119 phone:
+380661648341 phone: +79712941322 nic-hdl: TIMC1-RIPE mnt-by: TIMCHENKO-MNT source: RIPE # Filtered % Information related to '91.229.210.0/24AS49505'
route: 91.229.210.0/24 descr: Selectel PI origin: AS49505 mnt-by: MNT-SELECTEL source: RIPE # Filtered % This query was served by the RIPE Database
Query Service version 1.12.2 (WHOIS2)
91.229.210.195 - Geo Information IP Address 91.229.210.195 Host 91.229.210.195 Location RU, Russian Federation City -, - - Organization ChP Timchenko
Evgeniy Nikolaevich ISP ChP Timchenko Evgeniy Nikolaevich AS Number AS49505 Selectel Ltd. Latitude 60°00'00" North Longitude 100°00'00" East
Distance 5314.36 km (3302.19 miles)
cqcounter.com...
www.ip-adress.com...
network-tools.com...
91.229.210.195 is from Russian Federation(RU) in region Eastern Europe
TraceRoute to 91.229.210.195
Hop (ms) (ms) (ms) IP Address Host name
1 0 0 0 8.9.232.73 xe-5-3-0.edge3.dallas1.level3.net
2 0 0 0 4.69.145.254 vlan90.csw4.dallas1.level3.net
3 0 0 0 4.69.151.170 ae-93-93.ebr3.dallas1.level3.net
4 20 23 24 4.69.134.22 ae-7-7.ebr3.atlanta2.level3.net
5 35 34 40 4.69.132.86 ae-2-2.ebr1.washington1.level3.net
6 34 34 39 4.69.134.138 ae-81-81.csw3.washington1.level3.net
7 33 36 33 4.69.134.149 ae-72-72.ebr2.washington1.level3.net
8 114 115 124 4.69.137.53 ae-42-42.ebr2.paris1.level3.net
9 128 123 135 4.69.143.145 ae-48-48.ebr1.frankfurt1.level3.net
10 129 124 124 4.69.140.2 ae-61-61.csw1.frankfurt1.level3.net
11 121 121 121 4.69.154.7 ae-1-60.edge3.frankfurt1.level3.net
12 121 121 120 212.162.19.30 dialup-212.162.19.30.frankfurt1.mik.net
13 155 155 155 87.245.233.133 ae5-6.rt.km.spb.ru.retn.net
14 155 167 155 87.245.252.86 gw-selectel.retn.net
15 200 202 202 91.229.210.195 -
Trace complete
edit on 17-6-2012 by Trillium because: (no reason given)