10/29/2008

.tk free domains used for fastflux networks

http://atlas.arbor.net/summary/fastflux 

Fastflux hosting is a technique where the nodes in a botnet are used as the endpoints in a website hosting scheme. The DNS records change frequently, often every few minutes, to point to new bots. The actual nodes themselves simply proxy the request back to the central hosting location. This gives the botnet a robust hosting infrastructure. Many different kinds of botnets use fastflux DNS techniques, for malware hosting, for illegal content hosting, for phishing site hosting, and other such activities. These hosts are likely to be infected with some form of malware.

as it is a free domain it would be quite simple (a second work) to just turn off the domain. If it is paid than they still should, if they want their business model to survive. In the mean time it becomes a domain that is a candidate for general blocking.

Longest Lived Domains ↑ ↓ _

DomainStartedEndedDuration
hao123.com2008-05-15N/A23 weeks 5 days
casinogooglewebzone.tk2008-06-17N/A19 weeks
efexexpress.tk2008-06-17N/A19 weeks
fortune777lounge.tk2008-06-17N/A19 weeks
seitensprung-vermittlung2008.tk2008-06-17N/A19 weeks
trigat.com2008-06-17N/A19 weeks
casinopaintthe-town.tk2008-06-18N/A18 weeks 5 days
dagrin.com2008-06-19N/A18 weeks 5 days
google-paintthetowncasino.tk2008-06-21N/A

18 weeks 3 days

16:47 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment