CC server IP block missed? Priority 7 TCP Ports 3305 Filter deny ip host 59.124.27.180 any log ! 7 infects 10/31/12 to 01/08/13 hinet.net ISP chunghwa telecom data communication business group (info from BotHunter Filter) see: http://kb.bothunter.net/ipInfo/nowait.php?IP=59.124.27.180
evidence: http://www.threatexpert.com/report.aspx?md5=13aebb5e34baf54a7cba5fba51f92a4c
See: http://www.ipvoid.com/scan/59.124.27.180/
Also flagged here: http://rules.emergingthreats.net/blockrules/emerging-botcc.suricata.rules
See: http://urlquery.net/queued.php?id=13730629
IDS alerts: ET CNC Shadowserver Reported CnC Server IP (group 29) (severity1) &
FILEMAGIC Macromedia Flash data (severity3)
polonus
P.S. To see for yourself what is being missed by a large number of av solutions, go here: http://mtc.sri.com/live_data/cc_servers/
not reassuring, folks…not reassuring at all
D