DNS takeover redirects thousands of websites to malware
ID: a6cee7a4-964c-5c43-87d7-8a4e1af045e6
STIX ID: report--a6cee7a4-964c-5c43-87d7-8a4e1af045e6
Feed Name: Fox-IT blog
Threat Score
Starting 5 August 2013, attackers compromised DNS provisioning for multiple web hosters causing thousands of sites to resolve to a malicious IP (178.33.22.5) that served an iframe loading the Blackhole Exploit Kit. The kit delivered PDF and Java exploits which dropped a Tor-enabled secondary payload; the report documents the attack chain, affected domains/IPs, sample HTTP logs, file hashes, and cleanup guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
