本月特惠 支付方式 聯絡我們

SophosLabs Finds .EU Domains Exploited Through Blackhole Exploit Kit

  • 發佈時間:2012-11-27

  • 瀏覽次數:4555

  • Recently there has been a spate of .EU domain name registration abuse, SophosLabs have claimed on their Naked Security blog.



    In their blog posting, SophosLabs claim there have been “numerous malicious .eu domains have been registered during November

    which are being used to infect PCs with malware via the Blackhole exploit kit.” Examples given of the exploit are:

     

    • owzshm.eu
    • mpxuth.eu
    • ngpsjy.eu
    • wlwhhz.eu
    • jhzopj.eu
    • jqwwgm.eu
    • pmgugq.eu
    • jkiwhy.eu
    • nrxpxq.eu
    • vjtjpy.eu
    • xzjvhs.eu
    • xipuww.eu
    • kngipu.eu
    • ptkqzo.eu
    • pyrhox.eu


    All of the domains resolve to the same IP address, a server located in the Czech Republic and are short-lived - the names only resolve to

    the target server for a brief period before the attackers move on to the next.

    SophosLabs note this type of tactic is pretty common, used by many threats in their attempts to evade security filtering.

    But it is unusual for .eu domains to be abused as normally it is TLDs.

    Having dug a little further into the WHOIS information for these registrations, SophosLabs found some interesting observations. One is a

    Finnish connection based on the registrant details provided.

    Going back a few months, SophosLabs found the same pattern for a number of .in (India) domains, and when active, the .IN domains

    resolved to the very same IP address as the .eu domains!


    About Eranet

         Eranet International Limited(Eranet.com) was incorporated in Hong Kong in 2005, directly under Todaynic.com, Inc.
    which was established in 2000. As one of the first ICANN (The Internet Corporation for Assigned Names and Numbers),
    Verisign,HKDNR, and CNNIC (The China Internet Network Information Center) accredited registrars, Eranet is also a leading
    provider ofservices in domain name registration,web hosting and Email.
    Promotion of Domain and Hosting selling with excellent discount:


    Eranet International limited(www.eranet.com) as the icann ,cnnic and hkdnr accredit registrar . 
    We have the price Dot com $11.99, dot hk $22.63 ,dot cn $17.96 ,dot cc $46.16 each year.

    You may click on our website for more detail
    http://www.eranet.com/
    http://partner.eranet.com/
    Facebook:
    http://www.facebook.com/pages/Eranet/258707884175692

    Contact Info:
    Skype Domainer27
    MSN:sales@todaynic.com
    Email:support@eranet.com
    Tel:852-35685366



搜索

Document