Thứ Ba, 12 tháng 7, 2011

I've not worked out their obsession with HostNOC yet, but so far, the only two hosting companies they're flitting between, are CoolVDS (AS50669, well known to be criminal friendly) having until a few hours ago, been housed at 193.105.171.226 since their last stint on HostNOC (184.22.253.11) until July 7th.You'll no doubt not be surprised to hear, other than their flitting between the two hosts,

Thứ Tư, 6 tháng 7, 2011

64.120.151.73 was first reported to HostNOC/Burst, on July 2nd, both via e-mail and via telephone. When speaking to them on the phone, I was advised they'd give the customer a 24 hour warning.Watching the new domains popping up each day, I continued to send them reports, and resorted to a second phone call last week (Sunday if memory serves), to be told yet again, they'd give the customer a 24

Thứ Bảy, 2 tháng 7, 2011

This was never intended to be multipart, but I figured after part 1, I may as well do the other IPs they're using. As it happens, one of the other IP ranges they've got is through AS56927.The /24 in question, similar to the previous one, is 188.229.97.0/24. What's curious here, is that AS records show something interesting - an invisible link (AS52366 that AS records says doesn't exist. If we

Thứ Sáu, 1 tháng 7, 2011

Just a note folks, the network housing the likes of fspamlist.com, mysteryfcm.co.uk and the Abelhadigital.com forums, will be down for around 2 hours tomorrow, to allow for maintenance. The exact time hasn't been finalized yet, but is expected to be between 15:00-17:00.Sites affected:*.mysteryfcm.co.uk*.
The hpHOSTS Hosts file has been updated. There is now a total of 154,282 listed hostsnames.If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)Latest Updated: 01/06/2011 17:00Last Verified: 01/06/2011 12:00Download hpHosts now!http://hosts-file.net/?s=Download

Thứ Tư, 29 tháng 6, 2011

What do you do when you need lots of IPs to house your fake meds and other criminal sites? Use botnets? compromised sites/servers? That's certainly what the bad guys involved in exploits, malware and other badness like to do.Of course, another favourite of the bad guys, is to set up their own ASNs, complete with batches of IPs and IP ranges, to house their criminal activities. This is exactly

Thứ Ba, 28 tháng 6, 2011

If you've not already done so, you'll want to block 78.111.51.100 asap. It's currently housing a plethora of domains that are serving malware via exploit.Payloads are coming from paths such as;thujkdswg.tld.tc/k.php?f=20&e=3-> about.exe--> 3c6d68ea89512089df0cd7629439c378You'll no doubt notice the usual suspects as far as the ccTLD branches (redirection services serving off of ccTLDs such as .cc)