Tags » Malvertising

HookAds Malvertising Redirects to RIG-v EK at 217.107.219.99. EK Drops Ursnif Variant Dreambot.

IOCs:

  • 104.27.134.78 – multimediaz.net – Website hosting script for onclickads.net
  • 206.54.163.4 – onclickads.net – Checks Flash. Redirects to onclkds.com.
  • 206.54.163.50 – onclkds.com – Returns “302 Moved Temporarily,” new location is set to avatrading.org…
  • 1,171 more words
IOCs

ipfilterX Codename Whydah

>Date 17/02/2017

>UPDATES:

-Blocked Threats: 80
-Updated Threats: 4
-IP Added Record: +11k
-Deleted:(-)
-Merged/Extended:(7)

>COUNTRIES INVOLVED:

>Parsed lines/entries:22K Found IP ranges:22K Duplicate:0 Merged:0 Time:0 secs… 89 more words

Malware is Malware... except when it isn’t

So block anomalous activity first and ask questions later (please).

As IT professionals (and logical human beings) we have been taught to analyze a situation first and then act based on knowledge gained from the analysis. 600 more words

Enterprise

BossTDS and Exploit Kits

Download the Appendix – bosstds-and-exploit-kits.xlsx

Appendix A – DNS resolutions for 188.68.252.146.
Appendix B – Advetisement page Whois information.
Appendix C – Host pairs.
Appendix D… 2,932 more words

Exploit Kit

SitePro News: Malvertising Rises 132% in 2016 Over 2015, Says RiskIQ Research

Ugh. From SitePro News: Malvertising Rises 132% in 2016 Over 2015, Says RiskIQ Research. “RiskIQ, the leader in digital threat management, today released its annual malvertising report which indicates a sharp spike in malvertising in 2016, a digital threat that has become increasingly challenging for organisations to detect and mitigate. 40 more words

Security & Legal Issues

ipfilterX Codename Quartermaster

>Date 06/01/2017

>UPDATES:

-Blocked Threats: 123
-Updated Threats: 5
-IP Added Record: +8K
-Deleted:(-)
-Merged/Extended:(13)

>COUNTRIES INVOLVED:

>Parsed lines/entries:22K Found IP ranges:22K Duplicate:0 Merged:0 Time:0 secs… 88 more words

ipfilterX Codename Newgate

>Date 16/12/2016

>UPDATES:

-Blocked Threats: 57
-Updated Threats: 3
-IP Added Record: +17K
-Deleted:(-)
-Merged/Extended:(20)

>COUNTRIES INVOLVED:

>Parsed lines/entries:21K Found IP ranges:21K Duplicate:0 Merged:0 Time:0 secs… 86 more words