DNS ืคืกื™ื‘ื™ ื‘ื™ื“ื™ื• ืฉืœ ืื ืœื™ืกื˜

ืžืขืจื›ืช ืฉืžื•ืช ื”ื“ื•ืžื™ื™ืŸ (DNS) ื”ื™ื ื›ืžื• ืกืคืจ ื˜ืœืคื•ื ื™ื ืฉืžืชืจื’ื ืฉืžื•ืช ื™ื“ื™ื“ื•ืชื™ื™ื ืœืžืฉืชืžืฉ ื›ืžื• "ussc.ru" ืœื›ืชื•ื‘ื•ืช IP. ืžื›ื™ื•ื•ืŸ ืฉืคืขื™ืœื•ืช DNS ืงื™ื™ืžืช ื›ืžืขื˜ ื‘ื›ืœ ื”ืคืขืœื•ืช ื”ืชืงืฉื•ืจืช, ืœืœื ืงืฉืจ ืœืคืจื•ื˜ื•ืงื•ืœ. ืœืคื™ื›ืš, ืจื™ืฉื•ื DNS ื”ื•ื ืžืงื•ืจ ื—ืฉื•ื‘ ืฉืœ ื ืชื•ื ื™ื ืขื‘ื•ืจ ืžื•ืžื—ื™ ืื‘ื˜ื—ืช ืžื™ื“ืข, ื”ืžืืคืฉืจ ืœื”ื ืœื–ื”ื•ืช ื—ืจื™ื’ื•ืช ืื• ืœื”ืฉื™ื’ ื ืชื•ื ื™ื ื ื•ืกืคื™ื ืขืœ ื”ืžืขืจื›ืช ื”ื ื—ืงืจืช.

ื‘ืฉื ืช 2004, ืคืœื•ืจื™ืืŸ ื•ื™ืžืจ ื”ืฆื™ืข ืฉื™ื˜ืช ืจื™ืฉื•ื ืฉื ืงืจืืช Passive DNS, ื”ืžืืคืฉืจืช ืœืš ืœืฉื—ื–ืจ ืืช ื”ื”ื™ืกื˜ื•ืจื™ื” ืฉืœ ืฉื™ื ื•ื™ื™ื ื‘ื ืชื•ื ื™ DNS ืขื ื™ื›ื•ืœืช ืื™ื ื“ืงืก ื•ื—ื™ืคื•ืฉ, ืžื” ืฉื™ื›ื•ืœ ืœืกืคืง ื’ื™ืฉื” ืœื ืชื•ื ื™ื ื”ื‘ืื™ื:

  • ืฉื ื“ื•ืžื™ื™ืŸ
  • ื›ืชื•ื‘ืช ื”-IP ืฉืœ ืฉื ื”ื“ื•ืžื™ื™ืŸ ื”ืžื‘ื•ืงืฉ
  • ืชืืจื™ืš ื•ืฉืขืช ืชื’ื•ื‘ื”
  • ืกื•ื’ ืชื’ื•ื‘ื”
  • ื•ื›ื• '

ื ืชื•ื ื™ื ืขื‘ื•ืจ DNS ืคืกื™ื‘ื™ ื ืืกืคื™ื ืžืฉืจืชื™ DNS ืจืงื•ืจืกื™ื‘ื™ื™ื ืขืœ ื™ื“ื™ ืžื•ื“ื•ืœื™ื ืžื•ื‘ื ื™ื ืื• ืขืœ ื™ื“ื™ ื™ื™ืจื•ื˜ ืชื’ื•ื‘ื•ืช ืžืฉืจืชื™ DNS ื”ืื—ืจืื™ื ืขืœ ื”ืื–ื•ืจ.

DNS ืคืกื™ื‘ื™ ื‘ื™ื“ื™ื• ืฉืœ ืื ืœื™ืกื˜

ืื™ื•ืจ 1. DNS ืคืกื™ื‘ื™ (ื ืœืงื— ืžื”ืืชืจ Ctovision.com)

ืชื›ื•ื ื” ืฉืœ DNS ืคืกื™ื‘ื™ ื”ื™ื ืฉืื™ืŸ ืฆื•ืจืš ืœืจืฉื•ื ืืช ื›ืชื•ื‘ืช ื”-IP ืฉืœ ื”ืœืงื•ื—, ืžื” ืฉืขื•ื–ืจ ืœื”ื’ืŸ ืขืœ ืคืจื˜ื™ื•ืช ื”ืžืฉืชืžืฉ.

ื ื›ื•ืŸ ืœืขื›ืฉื™ื•, ื™ืฉื ื ืฉื™ืจื•ืชื™ื ืจื‘ื™ื ื”ืžืกืคืงื™ื ื’ื™ืฉื” ืœื ืชื•ื ื™ DNS ืคืกื™ื‘ื™ื™ื:

DNSDB
VirusTotal
ืคืกื™ื‘ื™ ืกืš ื”ื›ืœ
ืชืžื ื•ืŸ
ืžืกืœื•ืœื™ ืื‘ื˜ื—ื”
ืžื˜ืจื™ื” ืœื—ืงื•ืจ

ื—ื‘ืจื”
Farsight Security
VirusTotal
ืจื™ืกืงื™ืง
SafeDNS
ืžืกืœื•ืœื™ ืื‘ื˜ื—ื”
ืกื™ืกืงื•

ื’ื™ืฉื”
ื‘ื‘ืงืฉื”
ืœื ืžืฆืจื™ืš ื”ืจืฉืžื”
ื”ื”ืจืฉืžื” ื—ื™ื ื
ื‘ื‘ืงืฉื”
ืœื ืžืฆืจื™ืš ื”ืจืฉืžื”
ื‘ื‘ืงืฉื”

API
ืžืชื ื”
ืžืชื ื”
ืžืชื ื”
ืžืชื ื”
ืžืชื ื”
ืžืชื ื”

ื–ืžื™ื ื•ืช ืฉืœ ืœืงื•ื—
ืžืชื ื”
ืžืชื ื”
ืžืชื ื”
ืืฃ ืœื ืื—ื“
ืืฃ ืœื ืื—ื“
ืืฃ ืœื ืื—ื“

ืชื—ื™ืœืช ืื™ืกื•ืฃ ื”ื ืชื•ื ื™ื
ื‘ืฉื ืช 2010
ื‘ืฉื ืช 2013
ื‘ืฉื ืช 2009
ืžืฆื™ื’ ืจืง ืืช 3 ื”ื—ื•ื“ืฉื™ื ื”ืื—ืจื•ื ื™ื
ื‘ืฉื ืช 2008
ื‘ืฉื ืช 2006

ื˜ื‘ืœื” 1. ืฉื™ืจื•ืชื™ื ืขื ื’ื™ืฉื” ืœื ืชื•ื ื™ DNS ืคืกื™ื‘ื™ื™ื

ืžืงืจื™ ืฉื™ืžื•ืฉ ืขื‘ื•ืจ DNS ืคืกื™ื‘ื™

ื‘ืืžืฆืขื•ืช DNS ืคืกื™ื‘ื™ ื ื™ืชืŸ ืœื‘ื ื•ืช ื—ื™ื‘ื•ืจื™ื ื‘ื™ืŸ ืฉืžื•ืช ื“ื•ืžื™ื™ืŸ, ืฉืจืชื™ NS ื•ื›ืชื•ื‘ื•ืช IP. ื–ื” ืžืืคืฉืจ ืœื‘ื ื•ืช ืžืคื•ืช ืฉืœ ื”ืžืขืจื›ื•ืช ื”ื ื‘ื“ืงื•ืช ื•ืœืขืงื•ื‘ ืื—ืจ ืฉื™ื ื•ื™ื™ื ื‘ืžืคื” ื›ื–ื• ืžื”ื’ื™ืœื•ื™ ื”ืจืืฉื•ืŸ ื•ืขื“ ืœืจื’ืข ื”ื ื•ื›ื—ื™.

DNS ืคืกื™ื‘ื™ ื’ื ืžืงืœ ืขืœ ื–ื™ื”ื•ื™ ื—ืจื™ื’ื•ืช ืชื ื•ืขื”. ืœื“ื•ื’ืžื”, ืžืขืงื‘ ืื—ืจ ืฉื™ื ื•ื™ื™ื ื‘ืื–ื•ืจื™ NS ื•ืจืฉื•ืžื•ืช ืžืกื•ื’ A ื•-AAAA ืžืืคืฉืจ ืœืš ืœื–ื”ื•ืช ืืชืจื™ื ื–ื“ื•ื ื™ื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืฉื™ื˜ืช ื”ืฉื˜ืฃ ื”ืžื”ื™ืจ, ืฉื ื•ืขื“ื” ืœื”ืกืชื™ืจ C&C ืžื–ื™ื”ื•ื™ ื•ื—ืกื™ืžื”. ืžื›ื™ื•ื•ืŸ ืฉืฉืžื•ืช ื“ื•ืžื™ื™ืŸ ืœื’ื™ื˜ื™ืžื™ื™ื (ืœืžืขื˜ ืืœื• ื”ืžืฉืžืฉื™ื ืœืื™ื–ื•ืŸ ืขื•ืžืกื™ื) ืœื ื™ืฉื ื• ืืช ื›ืชื•ื‘ื•ืช ื”-IP ืฉืœื”ื ืœืขืชื™ื ืงืจื•ื‘ื•ืช, ื•ืจื•ื‘ ื”ืื–ื•ืจื™ื ื”ืœื’ื™ื˜ื™ืžื™ื™ื ืžืฉื ื™ื ืืช ืฉืจืชื™ ื”-NS ืฉืœื”ื ืœืขืชื™ื ืจื—ื•ืงื•ืช.

DNS ืคืกื™ื‘ื™, ื‘ื ื™ื’ื•ื“ ืœื—ื™ืคื•ืฉ ื™ืฉื™ืจ ืฉืœ ืชืช-ื“ื•ืžื™ื™ื ื™ื ื‘ืืžืฆืขื•ืช ืžื™ืœื•ื ื™ื, ืžืืคืฉืจ ืœืš ืœืžืฆื•ื ืืคื™ืœื• ืืช ืฉืžื•ืช ื”ื“ื•ืžื™ื™ื ื™ื ื”ืืงื–ื•ื˜ื™ื™ื ื‘ื™ื•ืชืจ, ืœืžืฉืœ "222qmxacaiqaaaaazibq4aaidhmbqaaa0undefined7140c0.p.hoff.ru". ื–ื” ื’ื ืžืืคืฉืจ ืœืคืขืžื™ื ืœืžืฆื•ื ืื–ื•ืจื™ ื‘ื“ื™ืงื” (ื•ืคื’ื™ืขื™ื) ื‘ืืชืจ ื”ืื™ื ื˜ืจื ื˜, ื—ื•ืžืจื™ื ืœืžืคืชื—ื™ื ื•ื›ื•'.

ื—ื™ืคื•ืฉ ืงื™ืฉื•ืจ ืžืžื™ื™ืœ ื‘ืืžืฆืขื•ืช DNS ืคืกื™ื‘ื™

ื ื›ื•ืŸ ืœืขื›ืฉื™ื•, ืกืคืื ื”ื•ื ืื—ืช ื”ื“ืจื›ื™ื ื”ืขื™ืงืจื™ื•ืช ืฉื‘ื”ืŸ ืชื•ืงืฃ ื—ื•ื“ืจ ืœืžื—ืฉื‘ ืฉืœ ื”ืงื•ืจื‘ืŸ ืื• ื’ื•ื ื‘ ืžื™ื“ืข ืกื•ื“ื™. ื‘ื•ืื• ื ื ืกื” ืœื‘ื—ื•ืŸ ืืช ื”ืงื™ืฉื•ืจ ืžืžื›ืชื‘ ื›ื–ื” ื‘ืืžืฆืขื•ืช DNS ืคืกื™ื‘ื™ ื›ื“ื™ ืœื”ืขืจื™ืš ืืช ื”ื™ืขื™ืœื•ืช ืฉืœ ืฉื™ื˜ื” ื–ื•.

DNS ืคืกื™ื‘ื™ ื‘ื™ื“ื™ื• ืฉืœ ืื ืœื™ืกื˜

ืื™ื•ืจ 2. ื“ื•ืืจ ื–ื‘ืœ

ื”ืงื™ืฉื•ืจ ืžื”ืžื›ืชื‘ ื”ื–ื” ื”ื•ื‘ื™ืœ ืœืืชืจ magnit-boss.rocks, ืฉื”ืฆื™ืข ืœืืกื•ืฃ ื‘ื•ื ื•ืกื™ื ืื•ื˜ื•ืžื˜ื™ืช ื•ืœืงื‘ืœ ื›ืกืฃ:

DNS ืคืกื™ื‘ื™ ื‘ื™ื“ื™ื• ืฉืœ ืื ืœื™ืกื˜

ืื™ื•ืจ 3. ื”ื“ืฃ ืžืชืืจื— ื‘ื“ื•ืžื™ื™ืŸ magnit-boss.rocks

ื›ื“ื™ ืœืœืžื•ื“ ืืช ื”ืืชืจ ื”ื–ื”, ื”ืฉืชืžืฉืชื™ API Riskiq, ืฉื›ื‘ืจ ื™ืฉ ืœื” 3 ืœืงื•ื—ื•ืช ืžื•ื›ื ื™ื ืคื™ืชื•ืŸ, ืื•ึนื“ึถื ะธ ื—ืœื•ื“ื”.

ืงื•ื“ื ื›ืœ, ื ื’ืœื” ืืช ื›ืœ ื”ื”ื™ืกื˜ื•ืจื™ื” ืฉืœ ืฉื ื”ื“ื•ืžื™ื™ืŸ ื”ื–ื”, ืœืฉื ื›ืš ื ืฉืชืžืฉ ื‘ืคืงื•ื“ื”:

pt-client pdns โ€”ืฉืื™ืœืชื” magnet-boss.rocks

ืคืงื•ื“ื” ื–ื• ืชืฆื™ื’ ืžื™ื“ืข ืขืœ ื›ืœ ืคืชืจื•ื ื•ืช ื”-DNS ื”ืžืฉื•ื™ื›ื™ื ืœืฉื ืชื—ื•ื ื–ื”.

DNS ืคืกื™ื‘ื™ ื‘ื™ื“ื™ื• ืฉืœ ืื ืœื™ืกื˜

ืื™ื•ืจ 4. ืชื’ื•ื‘ื” ืžืืช Riskiq API

ื‘ื•ืื• ื ืขื‘ื™ืจ ืืช ื”ืชื’ื•ื‘ื” ืžื”-API ืœืฆื•ืจื” ื•ื™ื–ื•ืืœื™ืช ื™ื•ืชืจ:

DNS ืคืกื™ื‘ื™ ื‘ื™ื“ื™ื• ืฉืœ ืื ืœื™ืกื˜

ืื™ื•ืจ 5. ื›ืœ ื”ืขืจื›ื™ื ืžื”ืชื’ื•ื‘ื”

ืœืžื—ืงืจ ื ื•ืกืฃ, ืœืงื—ื ื• ืืช ื›ืชื•ื‘ื•ืช ื”-IP ืฉืืœื™ื”ืŸ ื ืกื’ืจ ืฉื ื”ืชื—ื•ื ื”ื–ื” ื‘ื–ืžืŸ ืฉื”ืžื›ืชื‘ ื”ืชืงื‘ืœ ื‘-01.08.2019/92.119.113.112/85.143.219.65, ื›ืชื•ื‘ื•ืช IP ื›ืืœื” ื”ืŸ ื”ื›ืชื•ื‘ื•ืช ื”ื‘ืื•ืช XNUMX ื•-XNUMX.

ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื”:

pt-client pdns --ืฉืื™ืœืชื”

ืืชื” ื™ื›ื•ืœ ืœืงื‘ืœ ืืช ื›ืœ ืฉืžื•ืช ื”ื“ื•ืžื™ื™ืŸ ื”ืžืฉื•ื™ื›ื™ื ืœื›ืชื•ื‘ื•ืช IP ืืœื•.
ืœื›ืชื•ื‘ืช ื”-IP 92.119.113.112 ื™ืฉ 42 ืฉืžื•ืช ื“ื•ืžื™ื™ื ื™ื ื™ื™ื—ื•ื“ื™ื™ื ืฉืžืชื™ื™ื—ืกื™ื ืœื›ืชื•ื‘ืช IP ื–ื•, ื‘ื™ื ื™ื”ื ื”ืฉืžื•ืช ื”ื‘ืื™ื:

  • magnet-boss.club
  • igrovie-avtomaty.me
  • pro-x-audit.xyz
  • zep3-www.xyz
  • ื•ืื— '

ืœื›ืชื•ื‘ืช ื”-IP 85.143.219.65 ื™ืฉ 44 ืฉืžื•ืช ื“ื•ืžื™ื™ื ื™ื ื™ื™ื—ื•ื“ื™ื™ื ืฉืžืชื™ื™ื—ืกื™ื ืœื›ืชื•ื‘ืช IP ื–ื•, ื‘ื™ื ื™ื”ื ื”ืฉืžื•ืช ื”ื‘ืื™ื:

  • cvv2.name (ืืชืจ ืœืžื›ื™ืจืช ื ืชื•ื ื™ ื›ืจื˜ื™ืกื™ ืืฉืจืื™)
  • emaills.world
  • www.mailru.space
  • ื•ืื— '

ื—ื™ื‘ื•ืจื™ื ืขื ืฉืžื•ืช ื“ื•ืžื™ื™ื ื™ื ืืœื” ืžืจืžื–ื™ื ืขืœ ืคื™ืฉื™ื ื’, ืื‘ืœ ืื ื—ื ื• ืžืืžื™ื ื™ื ื‘ืื ืฉื™ื ื˜ื•ื‘ื™ื, ืื– ื‘ื•ืื• ื ื ืกื” ืœืงื‘ืœ ื‘ื•ื ื•ืก ืฉืœ 332 ืจื•ื‘ืœ? ืœืื—ืจ ืœื—ื™ืฆื” ืขืœ ื›ืคืชื•ืจ "ื›ืŸ", ื”ืืชืจ ืžื‘ืงืฉ ืžืื™ืชื ื• ืœื”ืขื‘ื™ืจ 501.72 ืจื•ื‘ืœ ืžื”ื›ืจื˜ื™ืก ื›ื“ื™ ืœื‘ื˜ืœ ืืช ื ืขื™ืœืช ื”ื—ืฉื‘ื•ืŸ ื•ืฉื•ืœื— ืื•ืชื ื• ืœืืชืจ as-torpay.info ื›ื“ื™ ืœื”ื–ื™ืŸ ื ืชื•ื ื™ื.

DNS ืคืกื™ื‘ื™ ื‘ื™ื“ื™ื• ืฉืœ ืื ืœื™ืกื˜

ืื™ื•ืจ 6. ื“ืฃ ื”ื‘ื™ืช ืฉืœ ื”ืืชืจ ac-pay2day.net

ื–ื” ื ืจืื” ื›ืžื• ืืชืจ ื—ื•ืงื™, ื™ืฉ ืชืขื•ื“ืช https, ื•ื”ืขืžื•ื“ ื”ืจืืฉื™ ืžืฆื™ืข ืœื—ื‘ืจ ืืช ืžืขืจื›ืช ื”ืชืฉืœื•ื ื”ื–ื• ืœืืชืจ ืฉืœืš, ืื‘ืœ, ืื‘ื•ื™, ื›ืœ ื”ืงื™ืฉื•ืจื™ื ืœื—ื™ื‘ื•ืจ ืœื ืขื•ื‘ื“ื™ื. ืฉื ื“ื•ืžื™ื™ืŸ ื–ื” ืขื•ื ื” ืขืœ ื›ืชื•ื‘ืช IP ืื—ืช ื‘ืœื‘ื“ - 1. ื™ืฉ ืœื•, ื‘ืชื•ืจื•, 190.115.19.74 ืฉืžื•ืช ื“ื•ืžื™ื™ื ื™ื ื™ื™ื—ื•ื“ื™ื™ื ืฉืžืชื™ื™ื—ืกื™ื ืœื›ืชื•ื‘ืช IP ื–ื•, ื›ื•ืœืœ ืฉืžื•ืช ื›ืžื•:

  • ac-pay2day.net
  • ac-payfit.com
  • as-manypay.com
  • fletkass.net
  • as-magicpay.com
  • ื•ืื— '

ื›ืคื™ ืฉืื ื• ื™ื›ื•ืœื™ื ืœืจืื•ืช, DNS ืคืกื™ื‘ื™ ืžืืคืฉืจ ืœืš ืœืืกื•ืฃ ื‘ืžื”ื™ืจื•ืช ื•ื‘ื™ืขื™ืœื•ืช ื ืชื•ื ื™ื ืขืœ ื”ืžืฉืื‘ ื”ื ื—ืงืจ ื•ืืฃ ืœื‘ื ื•ืช ืžืขื™ืŸ ื˜ื‘ื™ืขืช ืืฆื‘ืข ื”ืžืืคืฉืจืช ืœืš ืœื—ืฉื•ืฃ ืชื•ื›ื ื™ืช ืฉืœืžื” ืœื’ื ื™ื‘ืช ื ืชื•ื ื™ื ืื™ืฉื™ื™ื, ื”ื—ืœ ืžื”ืงื‘ืœื” ื•ืขื“ ืœืžืงื•ื ื”ืžื›ื™ืจื” ื”ืกื‘ื™ืจ.

DNS ืคืกื™ื‘ื™ ื‘ื™ื“ื™ื• ืฉืœ ืื ืœื™ืกื˜

ืื™ื•ืจ 7. ืžืคืช ื”ืžืขืจื›ืช ื”ื ื‘ื“ืงืช

ืœื ื”ื›ืœ ื•ืจื•ื“ ื›ืžื• ืฉื”ื™ื™ื ื• ืจื•ืฆื™ื. ืœื“ื•ื’ืžื”, ื—ืงื™ืจื•ืช ื›ืืœื” ืขืœื•ืœื•ืช ืœื”ื™ื›ืฉืœ ื‘ืงืœื•ืช ื‘-CloudFlare ืื• ื‘ืฉื™ืจื•ืชื™ื ื“ื•ืžื™ื. ื•ื”ื™ืขื™ืœื•ืช ืฉืœ ืžืกื“ ื”ื ืชื•ื ื™ื ืฉื ืืกืฃ ืชืœื•ื™ื” ืžืื•ื“ ื‘ืžืกืคืจ ื‘ืงืฉื•ืช ื”-DNS ื”ืขื•ื‘ืจื•ืช ื“ืจืš ื”ืžื•ื“ื•ืœ ืœืื™ืกื•ืฃ ื ืชื•ื ื™ DNS ืคืกื™ื‘ื™ื™ื. ืืš ืขื ื–ืืช, DNS ืคืกื™ื‘ื™ ื”ื•ื ืžืงื•ืจ ืžื™ื“ืข ื ื•ืกืฃ ืขื‘ื•ืจ ื”ื—ื•ืงืจ.

ืžื—ื‘ืจ: ืžื•ืžื—ื” ืžืจื›ื– ืื•ืจืืœ ืœืžืขืจื›ื•ืช ืื‘ื˜ื—ื”

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”