Results 1 to 10 of 302

Thread: Malware Domain Blocklist updated...

Threaded View

Previous Post Previous Post   Next Post Next Post
  1. #31
    Adviser Team AplusWebMaster's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    6,881

    Thumbs down More sites to block...

    FYI...

    More sites to block...
    - http://blog.dynamoo.com/2012/08/even...-block-on.html
    13 August 2012 - "More evil sites to block on 194.28.115.150 (Specialist ISP*) following on from these:
    idi42nga .rr.nu, kprud89entia .rr.nu, hin66gof .rr.nu, iste03dengi .rr.nu, hing30emplo .rr.nu,
    ize84dso .rr.nu, ind42icat .rr.nu, lack33andw .rr.nu"
    * http://blog.dynamoo.com/2012/08/yet-...-block-on.html
    10 August 2012 - "... blocking access to 91.211.200.0/22 and 194.28.112.0/22 (Specialist ISP) plus -all- .rr.nu domains would be even better."

    > http://blog.dynamoo.com/2012/08/scan...-pro-spam.html
    13 August 2012 - "..."46.51.218.71 (Amazon, Ireland)
    71.89.140.153 (Cloudaccess.net, US)
    203.80.16.81 (Myren, Malaysia)
    Blocking access to these IPs will prevent other malicious sites on the same servers from being a problem..."

    Something evil on 178.63.195.128/26
    - http://blog.dynamoo.com/2012/08/some...319512826.html
    13 August 2012 - "The IP address range 178.63.195.128/26 nominally belongs to grey hat host Hetzner in Germany, although it has been reallocated to a registrant in Israel. This block recently came up as the source for a ZeroAccess infection picked up from 178.63.195.170. A look at the 178.63.195.128/26 range (178.63.195.128 - 178.63.195.191) shows several suspicious websites with domains apparently generated by DoItQuick (more info here*). Most of the domains are too new to have any reputation, although given the live distribution of malware and the randomly chosen names then they are unlikely to be doing anything nice... quite a lot of suspect sites have recently been moved from this range to point at 127.0.0.1 instead, a common trick when malcious domains needs to be pointed somewhere else quickly.
    The registrant for this block is:
    inetnum: 178.63.195.128 - 178.63.195.191
    address: RUSSIAN FEDERATION
    178.63.195.163...
    178.63.195.167...
    178.63.195.168...
    178.63.195.170...
    178.63.195.171..."
    * https://krebsonsecurity.com/2012/07/...r-black-deeds/

    Last edited by AplusWebMaster; 2012-08-15 at 17:37.
    The machine has no brain.
    ......... Use your own.
    Browser check for updates here.
    YOU need to defend against -all- vulnerabilities.
    Hacks only need to find -1- to get in...
    .

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •