NOTHINK

"excusatio non petita, accusatio manifesta"





Nothink.org is a private project with no commercial interests. These pages are free and automatically created. You can find statistics, data and others stuff about malware/spyware. In particular lets you know the correspondence between a malicious binary (collected from my honeypot) and its activities in the network (DNS, HTTP and IRC connections).

This information can be used to perform analysis and filters in your work and home networks. If you have any doubts please consult the FAQ page or send me an email. Warning: all domains on this website should be considered dangerous. If you do not know what you are doing here, it is recommended you leave right away.

Download the last complete 'Malware Network Activity details' in XML format!
Download the last complete 'blocklist' about malware DNS,IRC and HTTP network traffic!

Latest malware binaries analyzed by the sandbox

generated 2012-02-04 23:00:04 UTC (daily)
TimestampMD5SHA1URL sandbox analysis report
2012-02-0427c9663740eef80f12c13d964ae6f8afe5275cfdcd518c4225705afd49aac426d37e05a219b9a325cf7b9599481108ded896f2b0a
2012-02-04be306aee79eb26cd5581b83e67c6bade19ac79b82f546214cc682c9b5c15b263c5af1e5b1ea67ccf6cde84c3455b2692888a0c56f
2012-02-035c9c84b2106dc294e39e528be565db7127d8412210f3158a8406833de4cdc5d8d5c420831737005d73fdd60f499015dd85bebcf85
2012-02-0265c7bab2353e3c8a320e045d142ac9765c3fcdaf3fae2c707e615b29c9887c3f5ed812471ce0c74eadc109dd47d910df6e79762e5
2012-02-021a50b8f81ef6c9d27c4d97e59cb85e9ea6439cd827b234636b7be8ff635177838b0e66de1f4c0c7f144c86dd4fd2a534d87e554fe
2012-02-01566400d3216495f8c50ced8ddb088763356276d04d6acc8866475b2fa79199802d0d508013e22cd79fe2382347df9be98dc14caee
2012-01-314375c9475bce8ca1996381ba51376d03a257b80cfaec612375127566082e89db6ca7ac3517db43a8fc79b38b4994d1f4e14c7f935
2012-01-31243aab68a7296f007d386802bd30c3149074874b06c787e9b0d903e4abe5e486c9274de91ab4120ffdf2b6a9481256146fe05d5d8
2012-01-30ad5d79b867875b98278118c70ea102c478452100e9dcd64e6b2298b70407f007e412d08e169bfa20d03ab1ce4e5afcee92746ed6e
2012-01-306660fc3fe295416b8f52e24f1a6b827cc1ecc179ef5c656e920e21b85ccd135a6fdba8e81ab467e8705076ae49d55a169ac007aa5

Latest entries about malware DNS network traffic

generated 2012-02-04 23:00:04 UTC (daily)
TimestampMD5NameQuery result
2012-02-0427c9663740eef80f12c13d964ae6f8afd.homler.net60.190.217.55 , 60.190.223.150
2012-02-04be306aee79eb26cd5581b83e67c6badegmail.comalt2.gmail-smtp-in.l.google.com , alt3.gmail-smtp-in.l.google....
2012-02-035c9c84b2106dc294e39e528be565db71d.homler.net60.190.223.150 , 60.190.217.55
2012-02-0265c7bab2353e3c8a320e045d142ac976d.homler.net60.190.217.55 , 60.190.223.150
2012-02-021a50b8f81ef6c9d27c4d97e59cb85e9ed.homler.net60.190.217.55 , 60.190.223.150
2012-02-01566400d3216495f8c50ced8ddb088763d.homler.net60.190.223.150 , 60.190.217.55
2012-01-314375c9475bce8ca1996381ba51376d03proxim.ntkrnlpa.info83.68.16.30
2012-01-31243aab68a7296f007d386802bd30c314d.homler.net60.190.223.150 , 60.190.217.55
2012-01-30ad5d79b867875b98278118c70ea102c4xi.r4t.biz-
2012-01-306660fc3fe295416b8f52e24f1a6b827cd.homler.net60.190.217.55 , 60.190.223.150

Latest entries about malware IRC network traffic

generated 2012-02-04 23:00:04 UTC (daily)
TimestampMD5IPPortNickUserPassChannelChannel pass
2012-01-30ad5d79b867875b98278118c70ea102c446.166.162.1168585"yycIaIcyudtouga-#c-
2012-01-14cf2b32e03d8985fc0b0afc55703850bf193.107.16.228718"pSLXmPYwqvryekc-#c-
2011-11-07eca3b59b3a6238f59a2dc16fbdba2b1760.190.222.1577475New{US-XP-x86}148668821838673v#3v3x3
2011-08-28ed47eabe4d203e4d4a3b8e202444950867.20.27.1898080ijJwtoxFqyxihFekFBsecretpass##+DES-256
2011-08-0531e8653e8a95ad07effa4c7bff6e8a4683.68.16.3080ayolsdplg020501---
2011-07-1728724f47348bc1c5f8ccddc22a1c522b92.241.164.1918718taAODJGmnftmukqp-#c-
2011-07-1184d9e3284d06707cddfaca3fe9f6dc4992.241.164.1918718FjFQvtVvagtyjaco-#c-
2011-06-1044de3158ba49bb1a84b4a21bf3e4c62a83.68.16.3080iljzrejwi020501---
2011-05-202e379cb2fc26b4f77fcc57edefcc1d3083.68.16.3080iuapnufwc020501---
2011-05-17342ff49fff5b134d991b1f80d034704878.24.188.20155003AUT|00|XP|SP3|L|708656cwqrqhgb-##sodoma_3s0dom4j03

Latest entries about malware HTTP network traffic

generated 2012-02-04 23:00:04 UTC (daily)
TimestampMD5IPPortHostnameRequest
2012-02-0427c9663740eef80f12c13d964ae6f8af146.185.246.6180" e146.185.246.61GET /ngk.exe
2012-02-0265c7bab2353e3c8a320e045d142ac976146.185.246.13980" e146.185.246.139GET /ngr.exe
2012-01-31243aab68a7296f007d386802bd30c314146.185.246.3480" e146.185.246.34GET /ngf.exe
2012-01-27d873945b82fa4f366a4b2b65d08ce97c146.185.246.3480" e146.185.246.34GET /ngh.exe
2012-01-2775f2a6be36973cc9f3e1cc2a821bb05b146.185.246.13980" e146.185.246.139GET /ngu.exe
2012-01-1799646b15965ff8607423319a1e281b9a146.185.246.12680" e146.185.246.126GET /ngl.exe
2012-01-13f8ddeea0b3d71b4a529847a3f5c8f284146.185.246.18080146.185.246.180GET /ngl.exe
2012-01-09f64833b8423c20414842fcb0bc2c8bc3146.185.246.18080" e146.185.246.180GET /ngv.exe
2011-12-29f6ccebd77b8be35fc56db7438132d510146.185.246.13980" e146.185.246.139GET /ngui.exe
2011-12-26b52c1e330914f8418d325682e3284ffd146.185.246.13980146.185.246.139GET /ngbn.exe

Copyright © 2004-2011 Nothink.org, All Rights Reserved. Terms of use.
Follow me on Twitter