International Exploit Kit Angler Thwarted By Cisco Security Team
An anonymous reader writes: Researchers at a Cisco security unit have successfully interrupted the spread of a massive international exploit kit which is commonly used in ransomware attacks. The scientists discovered that around 50% of computers infected with Angler were connecting with servers based at a Dallas facility, owned by provider Limestone Networks. Once informed, Limestone cut the servers from its network and handed over the data to the researchers who were able to recover Angler authentication protocols, information needed to disrupt future diffusion.
The published Angler nginx proxy server configuration contains
deny 150.26.0.0/16;
That block belongs to the Japanese "Ministry of Agriculture,Forestry and Fisheries - Agriculture,Forestry and Fisheries Research Council". I wonder what the story is behind that.
Donate free food here