nOtHINK

"dubium sapientiae initium"





Nothink.org is a private project with no commercial interests. These pages are free and automatically created. You can find statistics, data and others stuff about malware/spyware. In particular lets you know the correspondence between a malicious binary (collected from my honeypot) and its activities in the network (DNS, HTTP and IRC connections).

This information can be used to perform analysis and filters in your work and home networks. If you have any doubts please consult the FAQ page or send me an email. Warning: all domains on this website should be considered dangerous. If you do not know what you are doing here, it is recommended you leave right away.

Download the last complete 'Malware Network Activity details' in XML format!
Download the last complete 'blocklist' about malware DNS,IRC and HTTP network traffic!

Latest malware binaries analyzed by the sandbox

generated 2012-05-17 22:00:01 UTC (daily)
TimestampMD5SHA1URL sandbox analysis report
2012-05-1702e79ded0c1c937b72c9db02ecb05177f2acfd46f7884ff7684f7a6230b7d90d4675f18112c05abd014546bb46545df0813c28df1
2012-05-17fb86af6ba7866139c20cbe92ef71072f535d7297aa698dd609c6ca69534fb80b5de2ebbc10dbf8956d2806c14416f167dad8e6144
2012-05-17450467eb63d5f0ec997bf1ab16033e9407d9b998f1e34f6402accd316c29ccf0fab0b0131f677d530594b2884c9787c8a9f7e60b2
2012-05-179ac9d6ed7a16f54bac9e600777341513328df5825362c672c92db51f21b56908127d22bb17245eb9c372cf6f43910467d2871f828
2012-05-16e4eb48ad107d9247cd7a47f6ae1c3cef859cd6097bb72a2d55524c7778522613664c4cfe13733ddc162266f64b5f9f4308c55543a
2012-05-162d895989cf1243ee0989fa7e83e0eca79a338476fe66817681d1266c961e41c3ca2d80ef18186bcee4d31d9945940caefb77d283a
2012-05-169b491668f761a834fa8a7d283be028a4bb361f40d97060ce04cd09d06c5f8d9710ccfa7e1bb12e6ddb674be548dd80227cdbff0e5
2012-05-16321d86b4bd846bdc9ff843b4154cb3ebc5f018f377a3d72b4d1136730ec22a0e03fe1ff71f6118f84013a1b94d1d46b1b0c31e7e9
2012-05-167e31d0ae7b1778637537fab6ece410322074d4d8edf1888552ad9600bcd2be3d78e8fa56118e12cd2887b47545dedb24b6f8bba9b
2012-05-165940ab22b570854c0aab272540ce9a8cb5a7fbe46db12598e3a1dd625e9696f5de35a64c1e76f9e2eca2e6e4429001c5df407486f

Latest entries about malware DNS network traffic

generated 2012-05-17 22:00:01 UTC (daily)
TimestampMD5NameQuery result
2012-05-16321d86b4bd846bdc9ff843b4154cb3ebtv.homler.net117.21.224.29 , 122.224.6.140
2012-05-15d05276441b548403dfe814cd84e0af86xi.r4t.biz-
2012-05-15519af1366c32618d1f807457d0b588adtv.homler.net117.21.224.29 , 122.224.6.140
2012-05-14585e40a82204221a4ba2c2675cde293btv.homler.net117.21.224.29 , 122.224.6.140
2012-05-1022646e61e3e92158696169ca682a8372tv.homler.net122.224.6.140 , 117.21.224.29
2012-05-09b1efc25137fbe8d6d011e9be769ba551d.homler.net117.21.224.29 , 122.224.6.140
2012-05-07c8e54388126cb41d585b5e3e2f1d993dd.homler.net117.21.224.29 , 122.224.6.140
2012-05-075e60a735afb32c3b19b186170964ffb9gg.arrancar.org69.43.160.145
2012-05-06db9e4e86f133975e2114898f8adac417d.homler.net122.224.6.140 , 117.21.224.29
2012-05-045f9ef4e3f6fbc5ef88ee9026d38ccf8cdcppng.rania-style.com-

Latest entries about malware IRC network traffic

generated 2012-05-17 22:00:01 UTC (daily)
TimestampMD5IPPortNickUserPassChannelChannel pass
2012-05-15d05276441b548403dfe814cd84e0af8691.121.171.649040 xUVEuwUcjfsiemx-#j-
2012-05-03886d83e63011c2562a4c77b5bc48fd4b91.121.171.649040 SSCKGxsdgawscan-#c-
2012-04-252361afcdd127e86b689119672dfccf2191.121.171.649040 xgCvcsvecdaliwd-#c-
2012-04-23f61ba933ea990e83a84c2cc9cbd6dc3291.121.171.649040 yYPbbrlkuscvofb-#c-
2012-03-150f302c856d688340076859a02510507a83.68.16.3080hntrtwtrj020501---
2012-03-06fed38516f0e4f97ad3208fba3fd1bc4391.121.171.649040 FKgdmPAtrcupsvm-#c-
2012-01-30ad5d79b867875b98278118c70ea102c446.166.162.1168585yycIaIcyudtouga-#c-
2012-01-14cf2b32e03d8985fc0b0afc55703850bf193.107.16.228718pSLXmPYwqvryekc-#c-
2011-11-07eca3b59b3a6238f59a2dc16fbdba2b1760.190.222.1577475New{US-XP-x86}148668821838673v#3v3x3
2011-08-28ed47eabe4d203e4d4a3b8e202444950867.20.27.1898080ijJwtoxFqyxihFekFBsecretpass##+DES-256

Latest entries about malware HTTP network traffic

generated 2012-05-17 22:00:01 UTC (daily)
TimestampMD5IPPortHostnameRequest
2012-02-05044fed7aa87e891e4ddd2b97f7d949d2146.185.246.6180146.185.246.61GET /ngd.exe
2012-02-0427c9663740eef80f12c13d964ae6f8af146.185.246.6180146.185.246.61GET /ngk.exe
2012-02-0265c7bab2353e3c8a320e045d142ac976146.185.246.13980146.185.246.139GET /ngr.exe
2012-01-31243aab68a7296f007d386802bd30c314146.185.246.3480146.185.246.34GET /ngf.exe
2012-01-27d873945b82fa4f366a4b2b65d08ce97c146.185.246.3480146.185.246.34GET /ngh.exe
2012-01-2775f2a6be36973cc9f3e1cc2a821bb05b146.185.246.13980146.185.246.139GET /ngu.exe
2012-01-1799646b15965ff8607423319a1e281b9a146.185.246.12680146.185.246.126GET /ngl.exe
2012-01-13f8ddeea0b3d71b4a529847a3f5c8f284146.185.246.18080146.185.246.180GET /ngl.exe
2012-01-09f64833b8423c20414842fcb0bc2c8bc3146.185.246.18080146.185.246.180GET /ngv.exe
2011-12-29f6ccebd77b8be35fc56db7438132d510146.185.246.13980146.185.246.139GET /ngui.exe

Copyright © 2004-2012 Nothink.org, All Rights Reserved. Terms of use.
Follow me on Twitter