Blue Coat Malnet Dashboard

Malnets (malware networks) are distributed infrastructures within the Internet that are built and maintained for the purpose of launching a variety of attacks against unsuspecting users over extended periods of time. They gather users, typically when they are visiting trusted sites, and route them to malware, via relay, exploit and payload servers that continually shift to new domains and locations. Blue Coat is currently tracking more than 500 unique malnets though not all 500 will be active on any given day, and the actual size varies from day to day depending on the current level of malicious activities and attacks.

In 2012, Blue Coat Security Labs expects that nearly two-thirds of all new attacks will come from malnets. By identifying and tracking malnet infrastructures, the Blue Coat WebPulse collaborative defense can link new servers and domains to known malicious components and block them at the source, before they are used to launch attacks. This negative day defense delivers the most comprehensive protection against web-based threats.

Unique Host Names

135,619

Malnet Entry Points

Top Attack Site Top Level Domains

com 87,213
org 12,103
biz 8,000
net 7,106
de 5,129
info 3,732
co.uk 1,632
se 1,441
eu 1,222
pl 1,082
ru 953
it 774
pw 651
us 462
nl 411

Top Hazardous Search Term Hits

floridatreasury.com
matrigma test on line
xnxx
tank trouble swf
spiked math games
vk.com
cool math
games not blocked by school
wardrobe malfunction pics unedited
games

Network Visualizer

A malnet is comprised of unique domains, servers and websites that work together to funnel users to the malware payload. This visual mapping shows the relationships between the trusted sites that act as the entry point, the relay and exploit servers and the dynamic malware payloads.

Unique Host Names

3,716

Malnet Entry Points

Top Attack Site Top Level Domains

com 3,355
org 217
net 135
biz 5
us 2
info 2

Top Hazardous Search Term Hits

highfield motors sheffield
home tutions consultancy in hyderabad
montgomerycountyschool.com
bakekaannunci.org
games211.com
http://www.enciclopida.com
www.dcccwebstudy.com
washington elementary bethel park pa
mateus realty
www.ardmorecityschools

Network Visualizer

A malnet is comprised of unique domains, servers and websites that work together to funnel users to the malware payload. This visual mapping shows the relationships between the trusted sites that act as the entry point, the relay and exploit servers and the dynamic malware payloads.

Unique Host Names

5,034

Malnet Entry Points

Top Attack Site Top Level Domains

com 3,352
co.uk 1,655
net 23
us 3
pw 1

Top Hazardous Search Term Hits

verizon.net
Verizon
verizon email
verizon central
my verizon
verizon broadband
http://verizon.net/
verizon webmail
my verizon email
verizon.net email

Network Visualizer

A malnet is comprised of unique domains, servers and websites that work together to funnel users to the malware payload. This visual mapping shows the relationships between the trusted sites that act as the entry point, the relay and exploit servers and the dynamic malware payloads.

Unique Host Names

574

Malnet Entry Points

Top Attack Site Top Level Domains

com.br 458
co.za 54
br 49
com 13

Top Hazardous Search Term Hits

plymouth rock rv resort
physical edge webster
rodas
uairrior
look at her right before the jump
take these hands and throw them in the river lyrics
you're yesterdays news
indiansexnet
pm lodge fishing report
gallardin palace hotel

Network Visualizer

A malnet is comprised of unique domains, servers and websites that work together to funnel users to the malware payload. This visual mapping shows the relationships between the trusted sites that act as the entry point, the relay and exploit servers and the dynamic malware payloads.

Unique Host Names

681

Malnet Entry Points

Top Attack Site Top Level Domains

com 630
me 46
net 1

Network Visualizer

A malnet is comprised of unique domains, servers and websites that work together to funnel users to the malware payload. This visual mapping shows the relationships between the trusted sites that act as the entry point, the relay and exploit servers and the dynamic malware payloads.

Unique Host Names

171

Malnet Entry Points

Top Attack Site Top Level Domains

info 171

Top Hazardous Search Term Hits

times of india news
radioactive official music video
old lady dances with ellen
mangia gud bevi
times of india
jftr vol 1 af supplement attach 2
g1
denise matthews evangelist
Earnhardt at his "Whisky River" property including his "Car Graveyard."
shellac

Network Visualizer

A malnet is comprised of unique domains, servers and websites that work together to funnel users to the malware payload. This visual mapping shows the relationships between the trusted sites that act as the entry point, the relay and exploit servers and the dynamic malware payloads.

Unique Host Names

1,670

Malnet Entry Points

Top Attack Site Top Level Domains

com 1,670

Top Hazardous Search Term Hits

www.centrylink.com
centurylink.net

Network Visualizer

A malnet is comprised of unique domains, servers and websites that work together to funnel users to the malware payload. This visual mapping shows the relationships between the trusted sites that act as the entry point, the relay and exploit servers and the dynamic malware payloads.

Unique Host Names

843

Malnet Entry Points

Top Attack Site Top Level Domains

com 649
net 194

Top Hazardous Search Term Hits

http://es5pp.bartstur.net/l/295-0-59394-0-fd68-2-519e60c8572e4

Network Visualizer

A malnet is comprised of unique domains, servers and websites that work together to funnel users to the malware payload. This visual mapping shows the relationships between the trusted sites that act as the entry point, the relay and exploit servers and the dynamic malware payloads.

Unique Host Names

1,458

Malnet Entry Points

Top Attack Site Top Level Domains

net 1,458

Top Hazardous Search Term Hits

verizon webmail

Network Visualizer

A malnet is comprised of unique domains, servers and websites that work together to funnel users to the malware payload. This visual mapping shows the relationships between the trusted sites that act as the entry point, the relay and exploit servers and the dynamic malware payloads.

Unique Host Names

288

Malnet Entry Points

Top Attack Site Top Level Domains

ua 280
to 2
eu 2
uk 2

Top Hazardous Search Term Hits

HTTP://adrianastrip.dp.ua
bustyadriana.dp.ua
webcamprivate.dp.ua
HTTP://showforyou.dp.ua
http://showforyou.dp.ua
www.adrianaforyou.dp.ua

Network Visualizer

A malnet is comprised of unique domains, servers and websites that work together to funnel users to the malware payload. This visual mapping shows the relationships between the trusted sites that act as the entry point, the relay and exploit servers and the dynamic malware payloads.