{"id":42123,"date":"2018-03-20T04:00:00","date_gmt":"2018-03-20T08:00:00","guid":{"rendered":"https:\/\/www.cira.ca\/blog\/weekly-web-security-warning-something-new-see-a-cctld-2\/"},"modified":"2023-03-10T10:57:09","modified_gmt":"2023-03-10T15:57:09","slug":"weekly-web-security-warning-something-new-see-a-cctld-2","status":"publish","type":"cira_news","link":"https:\/\/www.cira.ca\/fr\/ressources\/nouvelles\/cybersecurite\/weekly-web-security-warning-something-new-see-a-cctld-2\/","title":{"rendered":"Weekly Web Security Warning: Something new to see, a ccTLD"},"content":{"rendered":"<p>Over the last seven days, we have seen a big change to the top 10 blocked domains of the week. Specifically for the first time a country-code TLD is featured \u2013 in this case .us.\u00a0<\/p>\n<p><!--more--><\/p>\n<p>Over the last seven days, we have seen a big change to the top 10 domains blocked by <a href=\"\/cybersecurity-services\/firewall\/d-zone-dns-firewall\">D-Zone DNS Firewall<\/a>. Specifically for the first time a country-code TLD is featured \u2013 in this case .us.&nbsp; Country codes are not seen as frequently among blocked domains as they generally enforce stricter identification and ownership rules.<\/p>\n<p>A quick review of WHOIS shows that these .us domains are all registered to the same registrant. This suggests that their servers may have been compromised OR that it is intentional. In the latter&nbsp;case we would think that the registrant is&nbsp;perhaps a pseudonym. Without speculating too much, what matters is that this particular set of domains is getting blocked for botnet activity that we still need to understand better and so we have categorized it as, \u201cOther Botnet\u201d which refers to malware\/botnet activity that we have not yet definitively associated with a specific, well-studied malware\/botnet type.<\/p>\n<p>The other notable change this week is the first appearance of Morto\u2014and it tops the list.&nbsp; That said, this isn&#8217;t the threat that you may think it is. Morto is an oldie that spreads via remote desktop protocol (RDP) between windows machines with weak passwords. The URL is a more traditional (seemingly) randomly generated domain name. What this means is that this URL is not a threat that the typical IT manager needs to worry about. The very high query count we are seeing is the result of one IP address with (likely) multiple infections on their network. In this case, they are not a direct <a href=\"\/cybersecurity-services\/firewall\/d-zone-dns-firewall\">D-Zone DNS Firewall<\/a> customer but benefit from its blocking because they are with an ISP that is using the DNS firewall to help keep malware off their network (and protect their customers).<\/p>\n<table border=\"1\" cellpadding=\"0\" style=\"width:420px\" width=\"0\">\n<thead>\n<tr>\n<th style=\"width:157px\">\n<p><strong>Domain Name<\/strong><\/p>\n<\/th>\n<th style=\"width:111px\">\n<p><strong>Category<\/strong><\/p>\n<\/th>\n<th style=\"width:144px\">\n<p><strong>Threat Type<\/strong><\/p>\n<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width:157px\">\n<p>dj1.jfrmt.net<\/p>\n<\/td>\n<td style=\"width:111px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:144px\">\n<p>Morto<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:157px\">\n<p>gpreport.us<\/p>\n<\/td>\n<td style=\"width:111px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:144px\">\n<p>Other Botnet<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:157px\">\n<p>domain-extension.us<\/p>\n<\/td>\n<td style=\"width:111px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:144px\">\n<p>Other Botnet<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:157px\">\n<p>superyou.zapto.org<\/p>\n<\/td>\n<td style=\"width:111px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:144px\">\n<p>Spybot<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:157px\">\n<p>sandmining.us<\/p>\n<\/td>\n<td style=\"width:111px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:144px\">\n<p>Other Botnet<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:157px\">\n<p>pricedeals.us<\/p>\n<\/td>\n<td style=\"width:111px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:144px\">\n<p>Other Botnet<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:157px\">\n<p>desertsand.us<\/p>\n<\/td>\n<td style=\"width:111px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:144px\">\n<p>Other Botnet<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:157px\">\n<p>wine-gift.us<\/p>\n<\/td>\n<td style=\"width:111px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:144px\">\n<p>Other Botnet<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:157px\">\n<p>issuetracking.us<\/p>\n<\/td>\n<td style=\"width:111px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:144px\">\n<p>Other Botnet<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:157px\">\n<p>valuescale.us<\/p>\n<\/td>\n<td style=\"width:111px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:144px\">\n<p>Other Botnet<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Over the last seven days, we have seen a big change to the top 10 blocked domains of the week. Specifically for the first time a country-code TLD is featured \u2013 in this case .us.\u00a0<\/p>\n","protected":false},"featured_media":2475,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"ngg_post_thumbnail":0,"slim_seo":{"title":"Weekly Web Security Warning: Something new to see, a ccTLD - CIRA","description":"Over the last seven days, we have seen a big change to the top 10 blocked domains of the week. Specifically for the first time a country-code TLD is featured \u2013"},"footnotes":""},"topic":[1066],"class_list":["post-42123","cira_news","type-cira_news","status-publish","has-post-thumbnail","hentry","cira_news_type-cira-news-type-blogue","cira_topic-cira-topic-cybersecurite","cira_author-robwilliamson-fr"],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.cira.ca\/fr\/wp-json\/cira\/v1\/news\/42123","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cira.ca\/fr\/wp-json\/cira\/v1\/news"}],"about":[{"href":"https:\/\/www.cira.ca\/fr\/wp-json\/wp\/v2\/types\/cira_news"}],"version-history":[{"count":0,"href":"https:\/\/www.cira.ca\/fr\/wp-json\/cira\/v1\/news\/42123\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cira.ca\/fr\/wp-json\/wp\/v2\/media\/2475"}],"wp:attachment":[{"href":"https:\/\/www.cira.ca\/fr\/wp-json\/wp\/v2\/media?parent=42123"}],"wp:term":[{"taxonomy":"cira_topic","embeddable":true,"href":"https:\/\/www.cira.ca\/fr\/wp-json\/cira\/v1\/topic?post=42123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}