Saturday, December 7, 2013

Domain: adrenalinessss.cc

Domain: adrenalinessss.cc

If you are seeing queries for this domain, than you are likely participating in DNS Amplification attacks and your DNS server is probably reachable from the internet and has recursion enabled.

If you are seeing responses for this domain.. unlucky. You are currently beeing DDOS-ed! Good luck.


IPtables:


There are two iptable rules available. If your distribution supports Iptables 'u32' module pick this one, otherwise use the 'string' rule.

U32:
iptables --insert INPUT -p udp --dport 53 -m u32 --u32 "0x28&0xFFDFDFDF=0x0e414452 && 0x2c&0xDFDFDFDF=0x454e414c && 0x30&0xDFDFDFDF=0x494e4553 && 0x34&0xDFDFDFFF=0x53535302 && 0x38&0xDFDFFF00=0x43430000" -j DROP -m comment --comment "DROP DNS Q adrenalinessss.cc"

More U32 rules can be found here:

https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist.txt

String:
iptables --insert INPUT -p udp --dport 53 -m string --from 40 --to 59 --algo bm --hex-string '|0E616472656e616c696e657373737302636300|' -j DROP -m comment --comment "DROP DNS Q adrenalinessss.cc"
More Iptables rules for the STRING module can be found here:


https://github.com/smurfmonitor/dns-iptables-rules/blob/master/domain-blacklist-string.txt

Source:


80.82.65.206 - Ecatel

Name server:


;; ANSWER SECTION:
adrenalinessss.cc. 8053 IN NS b.dns.gandi.net.
adrenalinessss.cc. 8053 IN NS a.dns.gandi.net.
adrenalinessss.cc. 8053 IN NS c.dns.gandi.net.


Response:


A 241
NS 3
SOA 1
Rsize 3983


Whois



Whois Server Version 2.0

Domain names can now be registered with many different competing registrars.
Go to http://registrar.verisign-grs.com/whois/ for detailed information.

Domain Name: ADRENALINESSSS.CC
Domain ID: 108528673
Whois Server: whois.gandi.net
Referral URL: http://www.gandi.net
Updated Date: 2013-12-06T11:58:40Z
Creation Date: 2013-12-06T11:58:39Z
Expiration Date: 2014-12-06T11:58:39Z
Sponsoring Registrar: GANDI SAS
Sponsoring Registrar IANA ID: 81
Domain Status: CLIENT-XFER-PROHIBITED
Name Server: A.DNS.GANDI.NET
Name Server: B.DNS.GANDI.NET
Name Server: C.DNS.GANDI.NET
DNSSEC: Unsigned delegation


>>> Last update of whois database: 2013-12-07T18:47:23Z <<<

NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the
expiration date of the domain name registrant's agreement with the
sponsoring registrar. Users may consult the sponsoring registrar's
Whois database to view the registrar's reported date of expiration
for this registration.


The Registry database contains ONLY .cc, .tv, and .jobs domains
and Registrars.
--- #YAML:1.0
# GANDI Registrar whois database for .COM, .NET, .ORG., .INFO, .BIZ, .NAME
#

domain: adrenalinessss.cc
reg_created: 2013-12-06 16:58:39
expires: 2014-12-06 16:58:39
created: 2013-12-06 17:58:39
changed: 2013-12-06 18:21:36
transfer-prohibited: yes
ns0: a.dns.gandi.net
ns1: b.dns.gandi.net
ns2: c.dns.gandi.net
owner-c:
nic-hdl: MM12605-GANDI
owner-name: maryset maryset
organisation: ~
person: maryset maryset
address: 1 resident
zipcode: 27300
city: Bernay
country: France
phone: +33.232472392
fax: ~
email: t.maryse@orange.fr
lastupdated: 2013-12-06 17:53:06
admin-c:
nic-hdl: MM12605-GANDI
owner-name: maryset maryset
organisation: ~
person: maryset maryset
address: 1 resident
zipcode: 27300
city: Bernay
country: France
phone: +33.232472392
fax: ~
email: t.maryse@orange.fr
lastupdated: 2013-12-06 17:53:06
tech-c:
nic-hdl: MM12605-GANDI
owner-name: maryset maryset
organisation: ~
person: maryset maryset
address: 1 resident
zipcode: 27300
city: Bernay
country: France
phone: +33.232472392
fax: ~
email: t.maryse@orange.fr
lastupdated: 2013-12-06 17:53:06
bill-c:
nic-hdl: MM12605-GANDI
owner-name: maryset maryset
organisation: ~
person: maryset maryset
address: 1 resident
zipcode: 27300
city: Bernay
country: France
phone: +33.232472392
fax: ~
email: t.maryse@orange.fr
lastupdated: 2013-12-06 17:53:06



No comments:

Post a Comment