Threat Level: green Handler on Duty: Guy Bruneau

SANS ISC: ? - SANS Internet Storm Center SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free! ?

Now .. where is ?? Dot-ai is Anguilla, a speck of land in the Caribbean, to the east of Puerto Rico. And probably has nothing at all to do with what follows. Dot-nl-dot-ai, on the other hand, appears to be a free domain name registrar.

If you're into malware analysis, you've probably seen your fair share of domains recently. And not just these. Feeding "" into RUS-CERTs Passive DNS collector gives us the name server for (one, which in turn shows a couple of other domains that are currently very familiar to the malware analyst. Like, and

If you are blocking domains on your gateway or DNS server, blackholing these few

might be a reasonable move, at least until someone in your business can show that they have a legitimate need to access one of the sub domains of these pseudo top level domains. Mind you, chances are that not all domains hosted there in fact are bad. But all the ones that I've seen in my logs so far: were.




385 Posts
ISC Handler
Dec 28th 2011

Sign Up for Free or Log In to start participating in the conversation!