AplusWebMaster
2007-06-27, 04:40
FYI...
- http://isc.sans.org/diary.html?storyid=3060
Last Updated: 2007-06-26 22:44:49 UTC ...(Version: 2)
"...A number of MySpace profiles include drive by exploits. The exploits will install a version of "flux bot", a very popular proxy network bot.
FluxBot (aka "Fast-Flux") is typically used to hide phishing and malware delivery sites behind complex ever changing networks of proxy servers... The actual exploit/malware is served via an existing flux network... once its all set and done, you will be a proud new member of the flux net and soon you
will find your system to participate in phishing and similar endevours.
Couple IPs that may be worthwhile to block:
AS13767 | 72.232.254.218
AS15083 | 65.111.176.176
AS25761 | 72.20.18.86
AS25761 | 72.20.6.10 ..."
:fear::FF:
- http://isc.sans.org/diary.html?storyid=3060
Last Updated: 2007-06-26 22:44:49 UTC ...(Version: 2)
"...A number of MySpace profiles include drive by exploits. The exploits will install a version of "flux bot", a very popular proxy network bot.
FluxBot (aka "Fast-Flux") is typically used to hide phishing and malware delivery sites behind complex ever changing networks of proxy servers... The actual exploit/malware is served via an existing flux network... once its all set and done, you will be a proud new member of the flux net and soon you
will find your system to participate in phishing and similar endevours.
Couple IPs that may be worthwhile to block:
AS13767 | 72.232.254.218
AS15083 | 65.111.176.176
AS25761 | 72.20.18.86
AS25761 | 72.20.6.10 ..."
:fear::FF: