Skip to content

Instantly share code, notes, and snippets.

View jedisct1's full-sized avatar

Frank Denis jedisct1

View GitHub Profile
@jedisct1
jedisct1 / serialize-bench.txt
Created February 17, 2014 23:32
serialize-bench.txt
running 3 tests
test bench_capnp ... bench: 4086276 ns/iter (+/- 52750)
test bench_json ... bench: 354789480 ns/iter (+/- 4444226)
test bench_msgpack ... bench: 63255533 ns/iter (+/- 1401449)
test result: ok. 0 passed; 0 failed; 0 ignored; 3 measured
@jedisct1
jedisct1 / 188.138.116.45.txt
Last active August 29, 2015 13:56
188.138.116.45
bzfkd.ru
fqhyt.ru
ljoqz.su
mvpln.ru
qzjzi.su
tcdbu.su
ufamh.ru
wgijg.ru
xfhp.ru
cxfvj.su
@jedisct1
jedisct1 / 198.50.143.65.txt
Last active August 29, 2015 13:56
Nuclear Exploit new home 198.50.143.65
!!! Full list of Nuclear Exploit Pack DGAs using the .in.net domain: https://gist.github.com/jedisct1/9168821
!!! Block all of these
A few names resolving to 198.50.143.65:
ahfz0.cavetips.ru. IN A 198.50.143.65
pinzw.cavetips.ru. IN A 198.50.143.65
y0tmq.cavetips.ru. IN A 198.50.143.65
cvvtqo.cavetips.ru. IN A 198.50.143.65
isic6b.cavetips.ru. IN A 198.50.143.65
@jedisct1
jedisct1 / nuclear-ek-dict.txt
Last active August 29, 2015 13:56
Dictionary used by the Nuclear Exploit Pack for its DGA
accelerate
accountant
actor
actress
actuary
advisor
aide
ambassador
animator
archer
@jedisct1
jedisct1 / nuclear-ek-gen.txt
Created February 23, 2014 08:43
Nuclear Exploit Kit DGA prediction
This file has been truncated, but you can view the full file.
accelerateaccountant.in.net
accelerateactor.in.net
accelerateactress.in.net
accelerateactuary.in.net
accelerateadvisor.in.net
accelerateaide.in.net
accelerateambassador.in.net
accelerateanimator.in.net
acceleratearcher.in.net
acceleratearchery.in.net
@jedisct1
jedisct1 / sinkhole-nmap.txt
Created February 24, 2014 03:06
sinkhole nmap
Starting Nmap 5.21 ( http://nmap.org ) at 2014-02-24 02:06 UTC
Host is up (0.0031s latency).
PORT STATE SERVICE VERSION
1/tcp open tcpmux?
3/tcp open compressnet?
4/tcp open unknown
6/tcp open unknown
7/tcp open echo?
9/tcp open discard?
@jedisct1
jedisct1 / nuclear ek new dga.txt
Created February 24, 2014 20:15
Nuclear EK new DGA
icefishingsouvenir.pw
frostbittencamera.pw
dogsledcamera.pw
sleetstay.pw
beretsuitcase.pw
stovebus.pw
snowstormchart.pw
stoveleisure.pw
@jedisct1
jedisct1 / nuclear-dga2.txt
Last active August 29, 2015 13:56
Nuclear Exploit Kit alternative DGA
airplaneairport.pw
airplaneaquarter.pw
airplanearctic.pw
airplaneathlete.pw
airplaneathletics.pw
airplanebackpack.pw
airplanebaggage.pw
airplanebags.pw
airplanebaseball.pw
airplaneberet.pw
@jedisct1
jedisct1 / pddns.info.txt
Created February 24, 2014 21:19
pddns.info used for DNS amplification attacks
pddns.info. 3600 IN MX 0 3mobilemailserver-mobilemailserver-mobilemailserver.pddns.info.
pddns.info. 3600 IN MX 0 4mobilemailserver-mobilemailserver-mobilemailserver.pddns.info.
pddns.info. 3600 IN MX 0 51mobilemailserver-mobilemailserver-mobilemailserver.pddns.info.
pddns.info. 3600 IN MX 0 52mobilemailserver-mobilemailserver-mobilemailserver.pddns.info.
pddns.info. 3600 IN MX 0 53mobilemailserver-mobilemailserver-mobilemailserver.pddns.info.
pddns.info. 3600 IN MX 0 54mobilemailserver-mobilemailserver-mobilemailserver.pddns.info.
pddns.info. 3600 IN MX 0 55mobilemailserver-mobilemailserver-mobilemailserver.pddns.info.
pddns.info. 3600 IN MX 0 56mobilemailserver-mobilemailserver-mobilemailserver.pddns.info.
pddns.info. 3600 IN MX 0 57mobilemailserver-mobilemailserver-mobilemailserver.pddns.info.
pddns.info. 3600 IN MX 0 22mobilemailserver-mobilemailserver-mobilemailserver.pddns.info.
@jedisct1
jedisct1 / mine.hashbros.co.in.txt
Created February 25, 2014 20:54
mine.hashbros.co.in
% drill -T mine.hashbros.co.in
in. 172800 IN NS a0.in.afilias-nst.info.
in. 172800 IN NS a2.in.afilias-nst.info.
in. 172800 IN NS c0.in.afilias-nst.info.
in. 172800 IN NS b0.in.afilias-nst.org.
in. 172800 IN NS b2.in.afilias-nst.org.
in. 172800 IN NS a1.in.afilias-nst.in.
in. 172800 IN NS ns7.cdns.net.
in. 172800 IN NS b1.in.afilias-nst.in.
hashbros.co.in. 86400 IN NS art.ns.cloudflare.com.