<span id="hs_cos_wrapper_post_body" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_rich_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="rich_text" ><p style="direction: ltr;">Our story with DDoS-Guard Ltd (AS57724) starts with the IP 185.178.208[.]140 - and a spoonful of bewilderment.</p> <p style="direction: ltr;">During a regular malware-hunting day of internet infrastructure research, a ThreatSTOP analyst noticed some really suspicious domain activity on this particular IP. <span style="font-weight: normal;"><span>DDoS-Guard is a Russian Internet infrastructure company that "provides DDoS protection, content delivery network services, and web hosting services".&nbsp; </span></span>Yep, we know you're thinking it too - isn't an AS claiming to guard from DDoS (Distributed Denial of Service) attacks supposed to be <span style="font-weight: bold;">protecting</span><span style="font-weight: normal;"> its users from cyber threats, not <span style="font-weight: bold;">serving </span>them? We would think so too, so we absolutely had to take a deeper look:</span></p> <p style="direction: ltr;"><span style="font-weight: normal;"><span>A <a href="https://www.virustotal.com/gui/ip-address/185.178.208.140/relations" rel="noopener">glance</a> at the domains hosted on 185.178.208[.]140, and the related malicious files, immediately uncovered that nothing good is going on over there. I mean, come on, who has a legitimate domain that starts with blog.blog.blog...?</span></span></p> <!--more--> <p><img src="https://www.threatstop.com/hubfs/vt_ddos_guard-1.png" alt="vt_ddos_guard-1" width="1236" loading="lazy" style="width: 1236px;"><span style="font-size: 12px;"><em>Image: VirusTotal</em></span></p> <p>&nbsp;</p> <p>ThreatSTOP's <a href="/check-ioc" rel="noopener">Check IOC tool</a> shows that the IP has been in various blocklists over the last few years, including APWG, Cybercrime, and ThreatSTOP's Stealers target. Looking at some of the IPs to its left and right, we started to see some more nasty activity.</p> <div>&nbsp;</div> <div>&nbsp;</div> <div><img src="https://www.threatstop.com/hubfs/check_ioc_ddos_guard.png" alt="check_ioc_ddos_guard" width="926" loading="lazy" style="width: 926px;"></div> <div><span style="font-size: 12px;"><em>Image: Check IOC</em></span><br> <div> <p>&nbsp;</p> <p>While some Autonomous Systems (AS's) stay relatively clean from malware (usually the more expensive, official and secure ones), others are like a playground for cyber attackers. Sometimes, whole areas of the internet will be abused for malicious activity (like <a href="/blog/watch-out-for-this-bad-ip" rel="noopener" target="_blank">Selectel</a>). DDoS-Guard is double trouble in this case - a supposedly "protective" AS with malware spiderwebs hidden inside.</p> <p>Researching the 185.178.208[.]0/24 address space (hosted in Russia), our analyst discovered a whole IP range (between 185.178.208[.]129 and 185.178.208[.]190) that is being abused for malicious activity, and has been abused for months. Showing up on this range is a variety of different malicious activities, from Exploit Kits, various malware types, phishing, stealer trojans, spam and more.</p> <p><img src="https://www.threatstop.com/hubfs/ips_ddos_guard.png" alt="ips_ddos_guard" width="826" loading="lazy" style="width: 826px;"><em>IPs on&nbsp;185.178.208[.]0/24 with a malicious instance in the last 6 months, based on VT data.</em>&nbsp;</p> <p>&nbsp;</p> <p>Another area on the AS known for its maliciousness is 185.223.92[.]0/24. According to <a href="https://cleantalk.org/blacklists/as57724/185.223.92.0/24" rel="noopener" target="_blank">CleanTalk</a>, over half of the address space has recently hosted malicious activity.</p> <p style="font-size: 12px;"><img src="https://www.threatstop.com/hubfs/spam_ddos_guard.png" alt="spam_ddos_guard" width="1184" loading="lazy" style="width: 1184px;"><em>Image: CleanTalk</em></p> <p>&nbsp;</p> <p>We highly recommend <span style="font-weight: bold;">blocking all IPs in the address space that have been deemed malicious</span> by high quality threat intelligence providers such as the ones we aggregate. To find out if an IP is in our threat targets, use our free<span>&nbsp;</span><a href="https://www.threatstop.com/checkip" rel="noopener">Check IP tool</a>.</p> <p><span>ThreatSTOP subscribers are automatically protected from attacks launched from these IPs and others as they appear. They can also choose to <a href="/blog/restricted-network-communication-ofac-itar" rel="noopener" target="_blank">block traffic from certain countries</a> they don't want their networks to communicate with, such as Russia. <a href="https://www.threatstop.com/Contact" rel="noopener" target="_blank">Contact us</a>&nbsp;to know more, or see the links at the end of our post to get a demo or trial.&nbsp;</span></p> <p>For your convenience, here is a list of all IP addresses in the<span> 185.178.208[.]0/24 range that we especially recommend blocking:</span><span></span></p> <table width="520" style="border-collapse: collapse; table-layout: fixed; margin-left: auto; margin-right: auto; border: 1px solid #99acc2; width: 746px; height: 508px;"> <tbody> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]3</td> <td style="width: 150px; height: 39px;">185.178.208[.]139</td> <td style="width: 148px; height: 39px;">185.178.208[.]152</td> <td style="width: 145px; height: 39px;">185.178.208[.]165</td> <td style="width: 153px; height: 39px;">185.178.208[.]178</td> </tr> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]4</td> <td style="width: 150px; height: 39px;">185.178.208[.]140</td> <td style="width: 148px; height: 39px;">185.178.208[.]153</td> <td style="width: 145px; height: 39px;">185.178.208[.]166</td> <td style="width: 153px; height: 39px;">185.178.208[.]179</td> </tr> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]35</td> <td style="width: 150px; height: 39px;">185.178.208[.]141</td> <td style="width: 148px; height: 39px;">185.178.208[.]154</td> <td style="width: 145px; height: 39px;">185.178.208[.]167</td> <td style="width: 153px; height: 39px;">185.178.208[.]180</td> </tr> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]129</td> <td style="width: 150px; height: 39px;">185.178.208[.]142</td> <td style="width: 148px; height: 39px;">185.178.208[.]155</td> <td style="width: 145px; height: 39px;">185.178.208[.]168</td> <td style="width: 153px; height: 39px;">185.178.208[.]181</td> </tr> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]130</td> <td style="width: 150px; height: 39px;">185.178.208[.]143</td> <td style="width: 148px; height: 39px;">185.178.208[.]156</td> <td style="width: 145px; height: 39px;">185.178.208[.]169</td> <td style="width: 153px; height: 39px;">185.178.208[.]182</td> </tr> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]131</td> <td style="width: 150px; height: 39px;">185.178.208[.]144</td> <td style="width: 148px; height: 39px;">185.178.208[.]157</td> <td style="width: 145px; height: 39px;">185.178.208[.]170</td> <td style="width: 153px; height: 39px;">185.178.208[.]183</td> </tr> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]132</td> <td style="width: 150px; height: 39px;">185.178.208[.]145</td> <td style="width: 148px; height: 39px;">185.178.208[.]158</td> <td style="width: 145px; height: 39px;">185.178.208[.]171</td> <td style="width: 153px; height: 39px;">185.178.208[.]184</td> </tr> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]133</td> <td style="width: 150px; height: 39px;">185.178.208[.]146</td> <td style="width: 148px; height: 39px;">185.178.208[.]159</td> <td style="width: 145px; height: 39px;">185.178.208[.]172</td> <td style="width: 153px; height: 39px;">185.178.208[.]185</td> </tr> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]134</td> <td style="width: 150px; height: 39px;">185.178.208[.]147</td> <td style="width: 148px; height: 39px;">185.178.208[.]160</td> <td style="width: 145px; height: 39px;">185.178.208[.]173</td> <td style="width: 153px; height: 39px;">185.178.208[.]186</td> </tr> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]135</td> <td style="width: 150px; height: 39px;">185.178.208[.]148</td> <td style="width: 148px; height: 39px;">185.178.208[.]161</td> <td style="width: 145px; height: 39px;">185.178.208[.]174</td> <td style="width: 153px; height: 39px;">185.178.208[.]187</td> </tr> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]136</td> <td style="width: 150px; height: 39px;">185.178.208[.]149</td> <td style="width: 148px; height: 39px;">185.178.208[.]162</td> <td style="width: 145px; height: 39px;">185.178.208[.]175</td> <td style="width: 153px; height: 39px;">185.178.208[.]188</td> </tr> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]137</td> <td style="width: 150px; height: 39px;">185.178.208[.]150</td> <td style="width: 148px; height: 39px;">185.178.208[.]163</td> <td style="width: 145px; height: 39px;">185.178.208[.]176</td> <td style="width: 153px; height: 39px;">185.178.208[.]189</td> </tr> <tr style="height: 39px;"> <td style="width: 150px; height: 39px;">185.178.208[.]138</td> <td style="width: 150px; height: 39px;">185.178.208[.]151</td> <td style="width: 148px; height: 39px;">185.178.208[.]164</td> <td style="width: 145px; height: 39px;">185.178.208[.]177</td> <td style="width: 153px; height: 39px;">185.178.208[.]190</td> </tr> </tbody> </table> <p>&nbsp;</p> </div> <div> <div> <p><em>Ready to try ThreatSTOP in your network? Want an expert-led demo to see how it works?</em></p> <p></p> </div> <aside> <div></div> </aside> </div> </div></span>