<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: botnet information center in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/botnet-information-center/m-p/1874142#M456600</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Typically you would go to Senderbase, which is the IronPort reputation database.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;"&gt;209.53.113.221&amp;amp;&lt;/DIV&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.senderbase.org/senderbase_queries/rep_lookup"&gt;http://www.senderbase.org/senderbase_queries/rep_lookup&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, the BTF (Botnet Traffic Filter) database is supposedly a subset of that database, and (in my experiences) completely hit-or-miss on whether a triggering IP address/domain name is in there or not.&amp;nbsp; I wrote some scripts to test known-malicious domain names against BTF.&amp;nbsp; Out of over 15,000 malicious/suspicious domains, BTF only triggered on about 10% of them.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can test for yourself by logging into the ASA and issuing the 'dynamic-filter database find &lt;SITENAME&gt;' command, where &lt;SITENAME&gt; is the domain name.&amp;nbsp; Sites like malwaredomainlist.com and malwaredomains.com are good sources for lists.&lt;/SITENAME&gt;&lt;/SITENAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A few other sites that can be helpful for correlation; there are plenty more out there:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;A href="http://www.trustedsource.org/"&gt;http://www.trustedsource.org&lt;/A&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;A class="jive-link-external-small" href="http://hosts-file.net/default.asp?s=123.123.123.123"&gt;http://hosts-file.net/default.asp?s=123.123.123.123&lt;/A&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;A class="jive-link-external-small" href="http://www.google.com/safebrowsing/diagnostic?site=123.123.123.123"&gt;http://www.google.com/safebrowsing/diagnostic?site=123.123.123.123&lt;/A&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Good luck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jan 2012 17:55:17 GMT</pubDate>
    <dc:creator>clausonna</dc:creator>
    <dc:date>2012-01-18T17:55:17Z</dc:date>
    <item>
      <title>botnet information center</title>
      <link>https://community.cisco.com/t5/network-security/botnet-information-center/m-p/1874141#M456599</link>
      <description>&lt;P&gt;Hi, where can I verify the nature of botnet malware-sites informations ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to detail the output of "show dynamic report top malware-sites" and I'm looking for a site where I can insert the IP (i.e. 209.53.113.221) and obtain detail, like malware that generates that traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rs&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:15:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/botnet-information-center/m-p/1874141#M456599</guid>
      <dc:creator>r.spiandorello</dc:creator>
      <dc:date>2019-03-11T22:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: botnet information center</title>
      <link>https://community.cisco.com/t5/network-security/botnet-information-center/m-p/1874142#M456600</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Typically you would go to Senderbase, which is the IronPort reputation database.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;"&gt;209.53.113.221&amp;amp;&lt;/DIV&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.senderbase.org/senderbase_queries/rep_lookup"&gt;http://www.senderbase.org/senderbase_queries/rep_lookup&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, the BTF (Botnet Traffic Filter) database is supposedly a subset of that database, and (in my experiences) completely hit-or-miss on whether a triggering IP address/domain name is in there or not.&amp;nbsp; I wrote some scripts to test known-malicious domain names against BTF.&amp;nbsp; Out of over 15,000 malicious/suspicious domains, BTF only triggered on about 10% of them.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can test for yourself by logging into the ASA and issuing the 'dynamic-filter database find &lt;SITENAME&gt;' command, where &lt;SITENAME&gt; is the domain name.&amp;nbsp; Sites like malwaredomainlist.com and malwaredomains.com are good sources for lists.&lt;/SITENAME&gt;&lt;/SITENAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A few other sites that can be helpful for correlation; there are plenty more out there:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;A href="http://www.trustedsource.org/"&gt;http://www.trustedsource.org&lt;/A&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;A class="jive-link-external-small" href="http://hosts-file.net/default.asp?s=123.123.123.123"&gt;http://hosts-file.net/default.asp?s=123.123.123.123&lt;/A&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;A class="jive-link-external-small" href="http://www.google.com/safebrowsing/diagnostic?site=123.123.123.123"&gt;http://www.google.com/safebrowsing/diagnostic?site=123.123.123.123&lt;/A&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Good luck.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jan 2012 17:55:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/botnet-information-center/m-p/1874142#M456600</guid>
      <dc:creator>clausonna</dc:creator>
      <dc:date>2012-01-18T17:55:17Z</dc:date>
    </item>
  </channel>
</rss>

