Thứ Ba, 28 tháng 6, 2011

Looks like HostNOC/Burst, finally pulled their finger out. Over the past 24 hours, they've now moved to a bulletproof host (193.105.171.70, AS50669 COOLVDS-as FOP Kutcevol Maksum Mukolaevich). If you've not already, you may want to consider blackholing the following;91.218.120.0/22193.105.171.0/24Registrars used haven't changed, still using DirectI resellers, DomainContext and UK2. Thankfully,

Thứ Hai, 27 tháng 6, 2011

Ever get the feeling HostNOC/Burst aren't taking this seriously? They took 3 years to boot these guys the first time, and now all they're doing, is jumping across different IPs on the HostNOC/Burst AS.The new IP they're using as of today, 173.212.255.31Filenames occasionally change (new ones: New-Video-Addon.40028.exe, FlashPlayer.40028.exe, old ones produce fake 404s), but the infection

Thứ Năm, 23 tháng 6, 2011

Opinion A recent newspaper investigation uncovered evidence that companies are paying agencies to create false online reviews for their services. But what those companies may not realise is that this is illegal and could ruin their businesses.The practice is called astroturfing, because it fakes grass-roots support, and it is not only ethically questionable, it is illegal. And if the law doesn't

Thứ Tư, 22 tháng 6, 2011

Well that didn't take them long. They're back to .in domains, and have moved to the well known SwiftWay (AS35017).New payload URL;rhyzilch.in/FlashPlayer.40028.exeIP: 46.21.159.228PTR: 228.159.21.46.inferno.nameMD5: 42a61ad4f894d9d21434cc5d5819aaefThis /24 of course, as with all SwiftWay ranges, is no stranger to malicious content, having hosted everything from fake AVs to trojans, and even fake
Well, the bad guys tried fooling everyone by changing the filename yet again (sorry Mr Bad Guy - we're not that stupid).You'll remember that they were using HostNOC as of the latest incarnations, and I both e-mailed, and phoned HostNOC on the 20th, the day the move was made, and the person I spoke to advised me they were giving the customer a 24 hour warning. 3 days later, and it was still online
The move to the new server has now completed. DNS propogation should be complete for most, but if you're still seeing the old 208. address, please refresh your DNS cache.Please let me know if you notice any problems.
Tip: don't get your hair stuck in the car window when closing it - it hurts like hell!Just a note folks, the hpHosts website and forums, are in the process of being moved to a new server, so will be down for around an hour or so.My apologies for any inconvenience.