Source |
Team Cymru |
Identifiant |
949 |
Date de publication |
2016-04-14 13:20:54 (vue: 2016-04-14 13:20:54) |
Titre |
East European Criminal Fastflux Infrastructure |
Texte |
Fast flux networks allow miscreants to make their network more resistant against takedowns. By updating and changing the A records of a domain rapidly, there is a constant changing list of IPs hosting the domain involved, making it harder to shutdown. The carding site at csh0p[.]cc is hosted on a fast flux network. The servers are largely located in the Ukraine and Russia. Analysis of IPs used by this fastflux networks showed that they were also used by a Teslacrypt ransomware payment site and a TreasureHunter POS controller (friltopyes[.]com) in March 2016. Figure 1 – Main location of fastflux IPs In late February this […] |
Notes |
|
Envoyé |
Oui |
Condensat |
2016 against allow also analysis are carding changing changing the com constant controller criminal csh0p domain east european fast fastflux february figure flux friltopyes harder hosted hosting infrastructure involved ips largely late list located location of main make making march miscreants more network networks payment pos ransomware rapidly records resistant russia servers showed shutdown site takedowns teslacrypt treasurehunter ukraine updating used  the |
Tags |
|
Stories |
Tesla
|
Move |
|