0
Threat Intelligence Quality
I'm looking over NextDNS as a way to protect non-VPN connected users from phishing attacks, but I'm disappointed that our latest phishing attack wasn't blocked, even with AI enabled.
Now a few days later, it is still not blocked, but 9.9.9.9 is blocking it.
% nslookup fail.gouheawo.com.de 9.9.9.9
Server: 9.9.9.9
Address: 9.9.9.9#53
** server can't find fail.gouheawo.com.de: NXDOMAIN
% nslookup fail.gouheawo.com.de 45.90.28.78
Server: 45.90.28.78
Address: 45.90.28.78#53
Non-authoritative answer:
Name: fail.gouheawo.com.de
Address: 172.64.80.1
Is this a fluke? Is there a way to improve it?
4 replies
-
% nslookup fail.gouheawo.com.de 45.90.28.78 Server: 45.90.28.78 Address: 45.90.28.78#53 Non-authoritative answer: Name: fail.gouheawo.com.de Address: 172.64.80.1 % nslookup fail.gouheawo.com.de 1.1.1.1 Server: 1.1.1.1 Address: 1.1.1.1#53 Non-authoritative answer: Name: fail.gouheawo.com.de Address: 172.64.80.1 ~ % nslookup fail.gouheawo.com.de 1.1.1.2 Server: 1.1.1.2 Address: 1.1.1.2#53 Non-authoritative answer: Name: fail.gouheawo.com.de Address: 0.0.0.0It looks like cloudflare 1.1.1.2 is also blocking now. I can see the detection on https://otx.alienvault.com/indicator/hostname/fail.gouheawo.com.de
Can I report this to nextdns? where are the sources from?
Content aside
- 5 days agoLast active
- 4Replies
- 127Views
-
2
Following
