10/27/2008

Belgian IRC servers undernet.org also hotbeds of malware

Embeds = number of malware binaries in which this DNS name was discovered
Rank = 30-day importance ranking (1 to 100) of most prolific malware-related DNS
Lookups = number of observed infections in which this DNS name was looked up
DNS = malware DNS list...be afraid if your PC looks up these entries.

RankLookupsEmbedsFirstLastCCDNS
1001411009/2610/25 citi-bank.ru
100908209/2610/25 proxim.ircgalaxy.pl
8354320109/2610/25 moscow-advokat.ru
195021909/2610/25 lia.zanet.net
181219309/2610/25 siliconfireware.ru
174321909/2610/25 london.uk.eu.undernet.org
174621909/2610/25 caen.fr.eu.undernet.org
174221909/2610/25 los-angeles.ca.us.undernet.org
174720109/2610/25 broadway.ny.us.dal.net
174021909/2610/25 brussels.be.eu.undernet.org
173521909/2610/25 washington.dc.us.undernet.org
173821909/2610/25 graz.at.eu.undernet.org
164320109/2610/25 viking.dal.net
164320109/2610/25 ced.dal.net
164220109/2610/25 vancouver.dal.net
164020109/2610/25 lulea.se.eu.undernet.org
164021909/2610/25 flanders.be.eu.undernet.org
164020109/2610/25 diemen.nl.eu.undernet.org
164420109/2610/25 coins.dal.net
164020209/2610/25 gaspode.zanet.org.za

 

This proofs that IRC/ICQ traffic should be closed off (undernet.org and dal.net) and that .ru traffic is better whitelisted (only acceptable servers allowed) than blacklisted (trying to block all bad servers). More listings

11:52 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment