{"id":42149,"date":"2018-02-12T05:00:00","date_gmt":"2018-02-12T10:00:00","guid":{"rendered":"https:\/\/www.cira.ca\/blog\/top-10-canadian-cyber-threat-blocks-feb-3-9\/"},"modified":"2023-03-10T10:57:11","modified_gmt":"2023-03-10T15:57:11","slug":"top-10-canadian-cyber-threat-blocks-feb-3-9","status":"publish","type":"cira_news","link":"https:\/\/www.cira.ca\/fr\/ressources\/nouvelles\/cybersecurite\/top-10-canadian-cyber-threat-blocks-feb-3-9\/","title":{"rendered":"Top 10 Canadian cyber-threat blocks for Feb 3-9"},"content":{"rendered":"<p>Last week&#8217;s top ten\u00a0most blocked domains represent many of the usual suspects but under different domains it is a reminder that\u00a0malware is pervasive, nasty and ever-changing.<\/p>\n<p><!--more--><\/p>\n<p>Last week&#8217;s top ten&nbsp;most blocked domains represent many of the usual suspects. Notably, you would be unlikely to spot any of these on your network without running scans or using a firewall. That is until it is too late.<\/p>\n<table border=\"1\" cellpadding=\"0\" cellspacing=\"0\">\n<tbody>\n<tr>\n<td style=\"width:208px\">\n<p>Domain Name<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>Category<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>Threat Type<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:208px\">\n<p>ns6.wowrack.com<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>Malware Call Home<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:208px\">\n<p>ns5.wowrack.com<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>Malware Call Home<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:208px\">\n<p>zws12.com<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>Mirai<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:208px\">\n<p>vcfs6ip5h6.bid<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>Mirai<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:208px\">\n<p>juice.losmibracala.org<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>Malware Call Home<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:208px\">\n<p>c0i8h8ac7e.bid<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>Malware Call Home<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:208px\">\n<p>redwassheptal.com<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>Palevo<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:208px\">\n<p>fge9vbrzwt.bid<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>Malware Call Home<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:208px\">\n<p>avualrhg9p.bid<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>jRAT<\/p>\n<\/td>\n<\/tr>\n<tr>\n<td style=\"width:208px\">\n<p>aqqgli3vle.bid<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>BLOCK<\/p>\n<\/td>\n<td style=\"width:208px\">\n<p>Malware Call Home<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Malware Call Home<\/strong><\/p>\n<p>Domains used for malware post-infection communications. You want to block this stuff so it (generally) can&#8217;t work. We see this issue the majority of the time meaning that users on the network are likely infected.&nbsp;<\/p>\n<p><strong>Mirai<\/strong><\/p>\n<p>An IoT botnet that is used primarily to launch DDoS Attacks.<\/p>\n<p><strong>Palevo<\/strong><\/p>\n<p>A family of worms\/viruses that allows unrestricted remote access to infected computers. Spreads via the network and removable media. Depending on what it is used to execute you may see degraded system performance, crashing, software launching itself, missing files, unwanted programs on desktop.<\/p>\n<p><strong>jRAT<\/strong><\/p>\n<p>A cross-platform remote access Trojan, can be run on any machine installed with Java, including Windows, MacOSC, Linux, and Android. Can be used to install any number of malware variants including those that keylog.&nbsp;For the most part to get this you need to have Java installed AND accept the change when the application package&nbsp;tries to install itself. This should render infection rates low, but users are users, and this is cross-platform,&nbsp;so good virus protection and firewalls should be present.<\/p>\n<p>In conclusion, this week is \u201cbusiness&nbsp;as usual&#8221; with no major&nbsp;new cybsecurity&nbsp;stories trending. This top ten&nbsp;is another&nbsp;reminder that malware is pervasive,&nbsp;nasty and ever-changing. If you have a method to block these top ten&nbsp;then we recommend you consider&nbsp;adding them to your block lists. If not, then we recommend a <a href=\"\/cybersecurity-services\/firewall\/d-zone-dns-firewall\">cloud-based DNS Firewall<\/a> that can help do it for you. &nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last week&#8217;s top ten\u00a0most blocked domains represent many of the usual suspects but under different domains it is a reminder that\u00a0malware is pervasive, nasty and ever-changing.<\/p>\n","protected":false},"featured_media":1949,"template":"","meta":{"_acf_changed":false,"content-type":"","inline_featured_image":false,"ngg_post_thumbnail":0,"slim_seo":{"title":"Top 10 Canadian cyber-threat blocks for Feb 3-9 - CIRA","description":"Last week's top ten\u00a0most blocked domains represent many of the usual suspects but under different domains it is a reminder that\u00a0malware is pervasive, nasty and"},"footnotes":""},"topic":[1066],"class_list":["post-42149","cira_news","type-cira_news","status-publish","has-post-thumbnail","hentry","cira_news_type-cira-news-type-blogue","cira_topic-cira-topic-cybersecurite","cira_author-robwilliamson-fr"],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.cira.ca\/fr\/wp-json\/cira\/v1\/news\/42149","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cira.ca\/fr\/wp-json\/cira\/v1\/news"}],"about":[{"href":"https:\/\/www.cira.ca\/fr\/wp-json\/wp\/v2\/types\/cira_news"}],"version-history":[{"count":0,"href":"https:\/\/www.cira.ca\/fr\/wp-json\/cira\/v1\/news\/42149\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cira.ca\/fr\/wp-json\/wp\/v2\/media\/1949"}],"wp:attachment":[{"href":"https:\/\/www.cira.ca\/fr\/wp-json\/wp\/v2\/media?parent=42149"}],"wp:term":[{"taxonomy":"cira_topic","embeddable":true,"href":"https:\/\/www.cira.ca\/fr\/wp-json\/cira\/v1\/topic?post=42149"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}