Urgent Block: BlackHole Exploit Kit redret Spam Domains
- http://www.malwaredo...rdpress/?p=2220
December 6th, 2011 - "From the Internet Storm Center*... IP addresses to block are also in the article*. Also see this article**. Will be added here but you shouldn’t wait."
* https://isc.sans.edu...l?storyid=12145
Last Updated: 2011-12-06 03:04:51 UTC - "... all domains still active/resolving that host BlackHole exploit kit, the actual one and not the links on the spams...
czredret .ru, curedret .ru, ctredret .ru, crredret .ru, bzredret .ru, byredret .ru, bxredret .ru, bwredret .ru, bvredret .ru, bsredret .ru,
bpredret .ru, boredret .ru, blredret .ru, bkredret .ru, biredret .ru, bhredret .ru, bgredret .ru, bfredret .ru, beredret .ru, bdredret .ru,
bcredret .ru, bbredret .ru, aredret .ru, apredret .ru, amredret .ru, alredret .ru, akredret .ru, ajredret .ru, airedret .ru, ahredret .ru,
agredret .ru, afredret .ru, aeredret .ru, adredret .ru, acredret .ru, abredret .ru, aaredret .ru
... they are resolving to:
95.163.89.193, 89.208.34.116, 94.199.51.108, 91.220.35.38, 77.79.7.136, 95.163.89.200, 91.228.133.120
In recent past, the following IPs were also observed hosting them:
188.190.99.26, 87.120.41.191, 94.199.53.14, 89.208.34.116...
Comments (12.06.2011, 19:21 UTC): 79.137.237.63 is hosting these domains crredret .ru, ctredret .ru, curedret .ru, czredret .ru"
- https://blogs.msdn.c...c...&GroupKeys=
"... malware that connects using an IP address instead of a domain name will -not- be blocked when you use just domain name lists..."
** http://blog.dynamoo....s-to-block.html
23 November 2011
Edited by AplusWebMaster, 09 December 2011 - 01:11 PM.