Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Sean O'Brien
@profdiggity@privacysafe.social  ·  activity timestamp 2 days ago

🚨 There's an enormous amount of traffic at a .su domain (old Soviet Union TLD), per #Cloudflare Radar. It's outranking every other big domain out there ( #Google, #Microsoft, #Facebook, etc.) Maybe this is related to a botnet controller and the #Azure outage, but if anyone out there in #infosec knows more, please comment. The host machine(s) are at Softlayer in Texas.

#cybersecurity #security #outage #Azure #AWS #cloud #cloudcomputing

Soviet Union TLD
Soviet Union TLD
Soviet Union TLD
  • Copy link
  • Flag this post
  • Block
Sean O'Brien
@profdiggity@privacysafe.social replied  ·  activity timestamp 2 days ago

overload [dot] su now too. h/t @briankrebs this is the Aisuru botnet taking different forms. https://krebsonsecurity.com/2025/10/aisuru-botnet-shifts-from-ddos-to-residential-proxies/

Aisuru Botnet Shifts from DDoS to Residential Proxies

Aisuru, the botnet responsible for a series of record-smashing distributed denial-of-service (DDoS) attacks this year, recently was overhauled to support a more low-key, lucrative and sustainable business: Renting hundreds of thousands of infected Internet of Things (IoT) devices to proxy…
botnet
botnet
botnet
botnet
botnet
botnet
  • Copy link
  • Flag this comment
  • Block
Sean O'Brien
@profdiggity@privacysafe.social replied  ·  activity timestamp 2 days ago

Even stranger - the domain name is an address:

14emeliaterracewestroxburyma02132 [dot] su

14 Emelia Ter, West Roxbury, MA 02132

Is this just a string scraped from the web that was chosen randomly by an algorithm, or a clue / reference of some kind?

https://radar.cloudflare.com/domains/domain/14emeliaterracewestroxburyma02132.su

#cybersecurity #security #outage #Azure #AWS #cloud #cloudcomputing

  • Copy link
  • Flag this comment
  • Block
Sean O'Brien
@profdiggity@privacysafe.social replied  ·  activity timestamp 2 days ago

I mean normally I wouldn't post an address like this, but that address is literally the most popular site on the internet right now. Should the people living there be alerted?

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0-rc.3.21 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login