Quantcast
Channel: 24/7 Live Malware Mix
Viewing all articles
Browse latest Browse all 4651

.nl.ai ?, (Wed, Dec 28th)

$
0
0





Now .. where is nl.ai ?? Dot-ai is Anguilla, a speck of land in the Caribbean, to the east of Puerto Rico. And probably has nothing at all to do with what follows. Dot-nl-dot-ai, on the other hand, appears to be a free domain name registrar.

If you're into malware analysis, you've probably seen your fair share of .nl.ai domains recently. And not just these. Feeding nl.ai into RUS-CERTs Passive DNS collectorhttp://www.bfk.de/bfk_dnslogger.html?query=ns1.cd.am#resultgives us the name server for .nl.ai (one ns1.cd.am), which in turn shows a couple of other domains that are currently very familiar to the malware analyst. Like .c0m.li, and .cc.ai.

If you are blocking domains on your gateway or DNS server, blackholing these few

.cc.ai




.nl.ai




.c0m.li




.cd.am




.coom.in

might be a reasonable move, at least until someone in your business can show that they have a legitimate need to access one of the sub domains of these pseudo top level domains.Mind you, chances are that not all domains hosted there in fact are bad. But all the ones that I've seen in my logs so far: were.










(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Source: http://isc.sans.edu/diary.html?storyid=12280&rss

Viewing all articles
Browse latest Browse all 4651

Trending Articles