Navigating the Digital Storm

Internet Weather Report

/

Archive

/

Category: Updates

  • Neiman Marcus email servers (SendGrid) have been hacked to send a phishing attack targeting OpenSea users. Here’s the full headers and body of the message for your perusement:   Delivered-To: <redacted>@gmail.com Received: by 2002:a05:612c:b8c:b0:4bc:e613:22f0 with SMTP id iq12csp925103vqb; Fri, 28 Feb 2025 04:46:03 -0800 (PST) X-Google-Smtp-Source: AGHT+IELOLo2I/Tjn/2ETiQppo+XlEYA9Wer7wVFiljwVnpJhIVFHobU8EAS3iHe1IIyq4HiNfmd X-Received: by 2002:a05:6602:3fc1:b0:855:a4a4:a938 with SMTP id ca18e2360f4ac-85881f044f0mr239496739f.2.1740746763022; Fri, 28 Feb 2025 04:46:03 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1740746763; cv=none; d=google.com; s=arc-20240605; b=jBx/BSRBsm4LaPlA8Mve3TyEslqYlMJd3Ool1Z5cmSe6luukjQKZx9lBgJx9Vvr9E4 JiagGyRLnxNWSq420x2uwe4ST4D+DYFcM+jcFWx6NpKr8AcPEH2thwSGbZ7AlyhlmMFL cqgXheLcLcE+BL2P3Ed1+9Nd26WsCYx+6/0hVvhn8deCggXgMH3PK+gKRShYSJVONoHo bvNQG0BEDSImOiHgR3H4OM6MFjtK/N91hKFCZ6rR1lT42HPdxd9hhS9BeLirkVcTA1xN mSSORPBrklUu+ICdbkhq1+ZxpX3wWGN1YXSZ4fujXFdqVZuaA7QJnFYzjeMgX//l9KYZ 9S6A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605;…

    ·

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • INTERNET WEATHER REPORT 🌧☁️☀️   AS48090 (PPTECHNOLOGY LIMITED) has just been added to ASN watchlist. This autonomous system announces only two BGP prefixes: 45.148.10.0/24 195.178.110.0/24   Abuse reports sent to dmzhostabuse@gmail.com go unanswered.   Drop It Like It’s Hot.   Latest updates to the ASN watchlist posted here: https://internetweather.net/asn-watchlist/  

    ·

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • INTERNET WEATHER REPORT 🌧☁️☀️   AS401172 (Inspici LLC) has just been added to ASN watchlist. This autonomous system announces only one BGP prefix: 45.84.89.0/24   Drop It Like It’s Hot.   Latest updates to the ASN watchlist posted here: https://internetweather.net/asn-watchlist/  

    ·

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • INTERNET WEATHER REPORT 🌧☁️☀️   AS394711 (Limenet) has just been added to ASN watchlist. This autonomous system is nothing but phishing sites and DDoS malware hosting. Lots of prefixes (netblocks) to drop: https://bgp.tools/as/394711#prefixes   Latest updates to the ASN watchlist posted here: https://internetweather.net/asn-watchlist/  

    ·

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • INTERNET WEATHER REPORT 🌧☁️☀️   AS214961 (Stellar Group SAS) has just been added to ASN watchlist. And it’s an easy one to drop:   sudo iptables –append INPUT –src 178.215.236.0/24 –jump DROP   Latest updates to the ASN watchlist posted here: https://internetweather.net/asn-watchlist/    

    ·

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Don’t delay, drop all traffic from 194.180.49.0/24 today!   As previously mentioned, AS201814 is operated by very intelligent cybercriminals who know how to speak BGP. This means those packets are already hitting your firewall, or worse, getting through it.    

    ·

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Drop all traffic to/from AS47890 (UNMANAGED LTD) immediately!   Tons of fraudulently obtained netblocks (full list here) used exclusively for cybercriminal activities.   Don’t delay, drop today!    

    ·

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Taking a break from your usual ASN and netblock blocklist updates for a moment, here is a review of a interesting phishing email campaign facilitated by cybersecurity vendor Trend Micro and web services behemoth AWS. Upon contacting the AWS abuse team, they have denied all culpability in facilitating this attack, despite relaying the message to hundreds if not thousands of potential victims.   Here’s the full headers and body of the phishing email in question:   Received: by 2002:a59:ab06:0:b0:478:9d64:fab9 with…

    ·

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • You know the drill by now. Drop it like it’s hot!   Drop traffic from all prefixes (netblocks) listed here: https://bgp.tools/as/201814#prefixes   ASN Watchlist (it’s really a drop list)        

    ·

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • You know the drill by now. Drop it like it’s hot!   Prefix | Description 31.43.191.0/24 | FOP Dmytro Nedilskyi 92.63.197.0/24 | TOV E-RISHENNYA 185.156.73.0/24 | TOV E-RISHENNYA 185.156.74.0/24 | TOV VAIZ PARTNER 185.193.88.0/24 | TOV E-RISHENNYA   ASN Watchlist (it’s really a drop list)        

    ·

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶