Pages

Monday 4 February 2013

Chinese Threat Actor Part 4

Hugesoft.org is an espionage domain which goes back several years connected to uglygorilla@163.com.

http://www.whoismind.com/whois/hugesoft.org.html

Domain ID:D105044855-LROR
Domain Name:HUGESOFT.ORG
Created On:25-Oct-2004 09:46:18 UTC
Last Updated On:10-Sep-2012 12:39:43 UTC
Expiration Date:25-Oct-2013 09:46:18 UTC
Sponsoring Registrar:eNom, Inc. (R39-LROR)
Status:OK
Registrant ID:3D553CC3140BB142
Registrant Name:huge soft
Registrant Organization:hugesoft
Registrant Street1:shanghai
Registrant Street2:
Registrant Street3:
Registrant City:shanghai
Registrant State/Province:S
Registrant Postal Code:200001
Registrant Country:CN
Registrant Phone:+86.21000021
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email:
Admin ID:3D553CC3140BB142

The "ug-" sub domains are connected to this guy.

email.hugesoft.org
leets.hugesoft.org
happy.hugesoft.org
ne.hugesoft.org
sllaw.hugesoft.org
slnoa.hugesoft.org
sw.hugesoft.org
cdc01.hugesoft.org
ug-aaon.hugesoft.org
ug-aeai.hugesoft.org
ug-ag.hugesoft.org
ug-asg.hugesoft.org
ug-ati.hugesoft.org
ug-bdai.hugesoft.org
ug-bdfa.hugesoft.org
ug-bpd.hugesoft.org
ug-cccc.hugesoft.org
ug-ccr.hugesoft.org
ug-co.hugesoft.org
ug-cono.hugesoft.org
ug-cti.hugesoft.org
ug-dfait.hugesoft.org
ug-enrc.hugesoft.org
ug-ga.hugesoft.org
ug-hst.hugesoft.org
ug-irpf.hugesoft.org
ug-kfc.hugesoft.org
ug-man.hugesoft.org
ug-mbi.hugesoft.org
ug-nema.hugesoft.org
ug-opm.hugesoft.org
ug-piec.hugesoft.org
ug-pmet.hugesoft.org
ug-pnl.hugesoft.org
ug-rev.hugesoft.org
ug-rj.hugesoft.org
ug-sbig.hugesoft.org
ug-tree.hugesoft.org
ug-tta.hugesoft.org
ug-volpe.hugesoft.org


Attribution

uglygorilla@163.com is the registrant email of rootkit.com. This database is leaked and available in public domain.

'WangJack','uglygorilla@163.com',1,1125921689,'','','','','','',0,'','',1148883119,'58.246.255.28',0,0,0,0,0,0,0,'','','','','',0,''


IP Address: 58.246.255.28
Location CHINA, SHANGHAI, SHANGHAI
Latitude, Longitude 31.22222, 121.45806 (31°13'20"N 121°27'29"E)
Connection through CHINA UNICOM SHANGHAI NETWORK


uglygorilla@163.com is also the registrant email of chinese social networks like renren.com, weibo.cn and tianya.cn


He is a member of many chinese boards.

http://bbs.chinamil.com.cn/forum/bbsui.jsp?id=(o)5681



http://www.verycd.com/i/1401285/



http://my.csdn.net/uglygorilla



http://www.chinaunix.net/old_jh/52/1036982.html



http://www.tianya.cn/19462717



http://bbs.sjtu.edu.cn/bbsanc?path=%2Fgroups%2FGROUP_0%2Fmessage%2FD4EFC2634%2FD7AC8E3A8%2FG.1092960050.A


uglygorilla (uglygorilla) on station 2 times, net age [ 17 ] days [ Leo ]
Last: [ August 3, 2004 10:23:38 Tuesday ] from [ 210.22.114.46 ] to the site a visit.

IP Address: 210.22.114.46
Location CHINA, SHANGHAI, SHANGHAI
Latitude, Longitude 31.22222, 121.45806 (31°13'20"N 121°27'29"E)

He appears to be a student of Shanghai Jiotang University (SJTU) in 2004

Previous Posts


No comments:

Post a Comment