Unknown EK

If anyone has more information on this, please hit me up on twitter.

Seems to have been active at least since April of this year. I have only seen it delivered with advertising. Have not seen it used with domains, only IPs.

Example Chain

http://72.51. 47.66 /lldb/npbh.php?t=98&dr=yHmZvIL8vXi%2BTiaZMyyXqZY%2BBoaqrPSBcmXEHi22vQI5gAqqOeUIz4kd%2BsMJ5Cx7L1mrKHSFXkrN27ScbolKKJJg4XvclYVVosGLj6MU5b1jtjrwh3tlq2DsLOQMyTseyOY5Q9XltuzxDNQa56NArok
http://72.51. 47.66 /lldb/zuhwcys.zip
http://72.51. 47.66 /lldb/SubepTjhhfChvm.class
http://72.51. 47.66 /lldb/SubepTjhhfChvm%24UtypYtqlgg.class
http://72.51. 47.66 /lldb/hqwzmjv.php?j=203

IPs Observed

207.198.127.193
216.151.221.204
216.152.135.29
216.157.98.124
216.157.99.240
216.157.99.241
216.157.99.242
216.157.99.243
216.157.99.71
216.157.99.72
216.157.99.73
216.157.99.1
64.34.127.178
66.135.36.55
69.174.251.126
72.51.36.1
72.51.36.210
72.51.44.21
72.51.44.25
72.51.44.40
72.51.44.41
72.51.44.42
72.51.44.63
72.51.44.72
72.51.47.121
72.51.47.153
72.51.47.154
72.51.47.66
72.51.47.69
76.74.152.33
76.74.152.34
76.74.152.98
76.74.153.247
76.74.153.248
76.74.154.147
76.74.154.176
76.74.155.223
76.74.155.225
76.74.155.226
76.74.155.227
76.74.157.90
76.74.166.8
76.74.236.151
76.74.236.152
76.74.236.153
76.74.237.156
76.74.237.157

View more examples of this traffic > http://pastie.org/pastes/8396549/text?key=fwh0zzyvwqs8huiso5qxw

Thanks to @keithsalmela for helping to keep this updated!

Comments are closed.