Report - CrySyS Lab
Report - CrySyS Lab
Report - CrySyS Lab
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
• The web page of bannetwork.org accidentally had a HTML tag “politnews”, and<br />
politnews.org was found to have similar structure and services like bannetwork.org.<br />
• Investigations on whois registration data revealed that the same person, Krepov Bogdan<br />
Serafimovich, registered two additional domains. These are planetanews.org and<br />
kortopla.org. Planetanews.org was found to be a functional C&C server, while kortopla.org is<br />
deregistered. This latter domain is currently sinkholed by our partners, and we do not know<br />
yet if it was used for rogue activities or not.<br />
• Investigations uncovered a sample in our malware repositories,<br />
539b0094e07e43bfced8a415ba5c84e3, that is related to a module of the TeamSpy kit. It has<br />
references to politnews.org and another domain, r2bnetwork.org, which is again expired, but<br />
the malware sample proves that it was used for C&C activity. The domain r2bdomain.org is<br />
currently sinkholed by our partners.<br />
The structure and services of the distinct C&C servers are similar, but each server is unique,<br />
containing some specific files and modules. We could not discover the internal structure of all C&C<br />
servers, but we are sure, that the listed domains are related to the TeamSpy activity (except for the<br />
deregistered kortopla.org, for which we have no such evidence). In the recent days we collaborated<br />
with multiple security companies and organizations, additional C&C servers were unveiled by their<br />
research.<br />
3.1 C&C whois information<br />
In this section we provide partial whois information for the discovered C&C domains.<br />
Domain Name:NEWSLITE.ORG<br />
Created On:27-Oct-2011 13:36:40 UTC<br />
Last Updated On:29-Oct-2012 05:40:58 UTC<br />
Expiration Date:27-Oct-2013 13:36:40 UTC<br />
Sponsoring Registrar:PDR Ltd. d/b/a PublicDomainRegistry.com (R27-LROR)<br />
Status:CLIENT TRANSFER PROHIBITED<br />
Registrant ID:DI_18504545<br />
Registrant Name:David van Cleve<br />
Registrant Organization:N/A<br />
Registrant Street1:Meester S. van Houtenstraat<br />
Registrant Street2:<br />
Registrant Street3:<br />
Registrant City:Assen<br />
Registrant State/Province:Assen<br />
Registrant Postal Code:9400-9409<br />
Registrant Country:AN<br />
Registrant Phone:+599.89261215320<br />
Registrant Phone Ext.:<br />
Registrant FAX:<br />
Registrant FAX Ext.:<br />
Registrant Email:vancleve_david@yahoo.nl<br />
Figure 6 – Politnews.org whois record<br />
8