logo

DNS takeover redirects thousands of websites to malware

ID: a6cee7a4-964c-5c43-87d7-8a4e1af045e6

STIX ID: report--a6cee7a4-964c-5c43-87d7-8a4e1af045e6

Feed Name: Fox-IT blog

Threat Score
75/100

Date Published: 2013-08-05

Date Updated: 2026-04-27

...
...

Starting 5 August 2013, attackers compromised DNS provisioning for multiple web hosters causing thousands of sites to resolve to a malicious IP (178.33.22.5) that served an iframe loading the Blackhole Exploit Kit. The kit delivered PDF and Java exploits which dropped a Tor-enabled secondary payload; the report documents the attack chain, affected domains/IPs, sample HTTP logs, file hashes, and cleanup guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.