Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: InfoSec Handlers Diary Blog - SANS Internet Storm Center InfoSec Handlers Diary Blog

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free! ?

Published: 2011-12-28
Last Updated: 2011-12-28 00:51:54 UTC
by Daniel Wesemann (Version: 1)
0 comment(s)

Now .. where is ?? Dot-ai is Anguilla, a speck of land in the Caribbean, to the east of Puerto Rico. And probably has nothing at all to do with what follows. Dot-nl-dot-ai, on the other hand, appears to be a free domain name registrar.

If you're into malware analysis, you've probably seen your fair share of domains recently. And not just these. Feeding "" into RUS-CERTs Passive DNS collector gives us the name server for (one, which in turn shows a couple of other domains that are currently very familiar to the malware analyst. Like, and

If you are blocking domains on your gateway or DNS server, blackholing these few

might be a reasonable move, at least until someone in your business can show that they have a legitimate need to access one of the sub domains of these pseudo top level domains. Mind you, chances are that not all domains hosted there in fact are bad. But all the ones that I've seen in my logs so far: were.



Keywords: malware
0 comment(s)
Diary Archives