mypdns / matrix

My Privacy DNS #Matrix lists for blacklisting
https://mypdns.org/
Other
85 stars 11 forks source link

45.207.168.120 #639

Closed g0d33p3rsec closed 3 months ago

g0d33p3rsec commented 3 months ago

Comments

While cataloging IP addresses related to Mirai and Mozi earlier today I came across this IP address which is being used to distribute a variety of malware.

Wildcard domain records

32.120.168.207.45|malicious

Sub-Domain records

No response

Hosts (RFC:953) specific records, not used by DNS RPZ firewalls

No response

SeafeSearch records

No response

Screenshots

Screenshot ![image](https://github.com/mypdns/matrix/assets/108126637/93df2ca0-abfb-4cfe-9467-c2f664e790db)

Links to external sources

45.207.168.120
http://45.207.168.120:7744/ 
http://45.207.168.120:7744/has.exe
http://45.207.168.120:7744/sky.exe
http://45.207.168.120:7744/dd.exe
http://45.207.168.120:7744/c3p.exe
http://45.207.168.120:7744/22222.zip
http://45.207.168.120:7744/mm.exe
http://45.207.168.120:7744/libcurllvse.exe
http://45.207.168.120:7744/k7.exe
http://45.207.168.120:7744/conhostdhfw.exe
http://45.207.168.120:7744/DHL.exe
http://45.207.168.120:7744/8.77.dll
http://45.207.168.120:7744/77@u2.exe
http://45.207.168.120:7744/ceshi.exe

logs from uBlock Origin

N/A