NoThink

"do ut des"





Nothink.org is a private project with no commercial interests. These pages are free and automatically created. You can find statistics, data and others stuff about malware/spyware. In particular lets you know the correspondence between a malicious binary (collected from my honeypot) and its activities in the network (DNS, HTTP and IRC connections).

This information can be used to perform analysis and filters in your work and home networks. If you have any doubts please consult the FAQ page or send me an email. Warning: all domains on this website should be considered dangerous. If you do not know what you are doing here, it is recommended you leave right away.

Download the last complete 'Malware Network Activity details' in XML format!
Download the last complete 'blocklist' about malware DNS,IRC and HTTP network traffic!

Latest malware binaries analyzed by the sandbox

generated 2012-01-26 23:00:04 UTC (daily)
TimestampMD5SHA1URL sandbox analysis report
2012-01-26a1da77646a58b98d7302f7ca9b1f1f3b89f6fd0ef54e2826e031b0924b982526d5f695ce19475bea39257e424f53d0287e13a463d
2012-01-26fb7e6238e6874f91144b77ebe6ca20edea4a2b9e6ecb4063fa49802a297ff29a502aa856105248bd1db5120c41d65db83640f6773
2012-01-2631b9cefce84d16ca9b5f1e83668b491a26a25881ef571da387b188a55ae8bde75f9d94e9138cd82398909d214d545b660f7f3814f
2012-01-268fa68c2c44d3b44cefaab4ec24ce3846a485a04528ec76aa302b7e1ad2699c15cc7ccfb311fa927b1b32a707415169d5b8215c7ee
2012-01-26aaedc78466673f044013f8ea51714f19564040bedae166cea3a9d7cdb2897d6224bc9bcb12e6c359d6be1b12461df8258a2b60834
2012-01-264708cc08a345fa459c2778d897138062861d42dce1be84bcc144aa076cc817a658a55c591680d12248822f9744de5c7126c10353e
2012-01-26a7782ea30ce05e4869d70f6c3c95491a65c00798222d48aeacdbd01d102379427791d00e1dd1760cd93c028249de59c1b8c782cfd
2012-01-267b5baa50e765c3abcd52aead208bcb0a9b9a977983aec6d325ae595aabb69a4d8310446f18093f9e6dcfd7594e169faa14c96792e
2012-01-265f6b787000308c6d46fdc2f8a399a20b788e3c4f44aadbfbbf5f6484126dbbddd47d0c85112f19511c943f6044946951df2c2716a
2012-01-26b0f8811efebaffc4046b1913ef2700b6d341b3d45b786859711c6b7558271a16f37a2b9f16e0c8e948826a5448d225f42a41be674

Latest entries about malware DNS network traffic

generated 2012-01-26 23:00:04 UTC (daily)
TimestampMD5NameQuery result
2012-01-2545cb35fc407b252204adc601d5f2aff6dd.ka3ek.com60.190.223.150 , 60.190.217.55
2012-01-24c8909e91c4fec7617dbc6bbdbd6c742cdd.ka3ek.com60.190.223.150 , 60.190.217.55
2012-01-24a36003cb42c7d6358769a4d0ef630825dd.ka3ek.com60.190.217.55 , 60.190.223.150
2012-01-233d74fa02baba600c57248db4f7741854dd.ka3ek.com60.190.223.150 , 60.190.217.55
2012-01-225393a8b71d68792fe5082b4deb78ae7bdd.ka3ek.com60.190.217.55 , 60.190.223.150
2012-01-21214768fb1137decf5c1c7d9d3b8b2e7edd.ka3ek.com60.190.223.150 , 60.190.217.55
2012-01-20ac79d8abd2e845d159d38a79b5f7675cdd.ka3ek.com60.190.217.55 , 60.190.223.150
2012-01-193cbe5222679a7bada5e0f834330395e2proxim.ntkrnlpa.info83.68.16.30
2012-01-19cbf77665b10c271a0f8d3665b240d198proxim.ntkrnlpa.info83.68.16.30
2012-01-18f3612f74807a98dd49c2a8493a8e0bc0dd.ka3ek.com60.190.217.55 , 60.190.223.150

Latest entries about malware IRC network traffic

generated 2012-01-26 23:00:04 UTC (daily)
TimestampMD5IPPortNickUserPassChannelChannel pass
2012-01-14cf2b32e03d8985fc0b0afc55703850bf193.107.16.228718"pSLXmPYwqvryekc-#c-
2011-11-07eca3b59b3a6238f59a2dc16fbdba2b1760.190.222.1577475New{US-XP-x86}148668821838673v#3v3x3
2011-08-28ed47eabe4d203e4d4a3b8e202444950867.20.27.1898080ijJwtoxFqyxihFekFBsecretpass##+DES-256
2011-08-0531e8653e8a95ad07effa4c7bff6e8a4683.68.16.3080ayolsdplg020501---
2011-07-1728724f47348bc1c5f8ccddc22a1c522b92.241.164.1918718taAODJGmnftmukqp-#c-
2011-07-1184d9e3284d06707cddfaca3fe9f6dc4992.241.164.1918718FjFQvtVvagtyjaco-#c-
2011-06-1044de3158ba49bb1a84b4a21bf3e4c62a83.68.16.3080iljzrejwi020501---
2011-05-202e379cb2fc26b4f77fcc57edefcc1d3083.68.16.3080iuapnufwc020501---
2011-05-17342ff49fff5b134d991b1f80d034704878.24.188.20155003AUT|00|XP|SP3|L|708656cwqrqhgb-##sodoma_3s0dom4j03
2011-04-191e3eb2a8e28930dae966a555fcbe0ebe78.47.158.336667AUT|01346zjeei-##alb##b!

Latest entries about malware HTTP network traffic

generated 2012-01-26 23:00:04 UTC (daily)
TimestampMD5IPPortHostnameRequest
2012-01-1799646b15965ff8607423319a1e281b9a146.185.246.12680" e146.185.246.126GET /ngl.exe
2012-01-13f8ddeea0b3d71b4a529847a3f5c8f284146.185.246.18080146.185.246.180GET /ngl.exe
2012-01-09f64833b8423c20414842fcb0bc2c8bc3146.185.246.18080" e146.185.246.180GET /ngv.exe
2011-12-29f6ccebd77b8be35fc56db7438132d510146.185.246.13980" e146.185.246.139GET /ngui.exe
2011-12-26b52c1e330914f8418d325682e3284ffd146.185.246.13980146.185.246.139GET /ngbn.exe
2011-12-18dbe40f79e96ed9881bab25b8bdc3c036146.185.246.13480146.185.246.134GET /ngrold.exe
2011-12-07c3976306587bc43ba40bf1a37a6803e670.38.98.23680img102.herosh.comGET /2011/12/06/771918837.gif
2011-12-026932684e7fe10d01fea5199622e3589091.121.11.698080vendor.almsyar.com:8080GET /images/crypted_build.exe
2011-11-30972e4ef408d94468daacf2acb4dbf062146.185.246.13280146.185.246.132GET /ngop.exe
2011-11-20c940f4c6d619f52ee6cab8849420a298146.185.246.10680146.185.246.106GET /ngck.exe

Copyright © 2004-2011 Nothink.org, All Rights Reserved. Terms of use.
Follow me on Twitter