Blog | G5 Cyber Security

Suspension announcement of 97 .RU domains (registered in REGGI.RU) used by Kelihos Crime Group to spread payload via Red Kit Exploit Pack

MalwareMustDie, NPO, during its research activities, is following the process of suspension malware bad domains as important milestones in malware fighting steps. The Kelihos Trojan were distributed in (mainly) East European (Ukrainian, Latvia, Belarus, Russia) and Asia servers (Japan, Korea, Taiwan and Hongkong) as the secondary layers, with also using the scattered world wide hacked machines. The usage of the DGA-like randomisation for the domain used for the payload is the MO of this distribution.”]

Source: https://blog.malwaremustdie.org/2013/07/suspension-announcement-of-97-ru.html

Exit mobile version