Thanks to all of you. I see the same starting ISP# (66,67,24 and 10) - when I "mouse hover" over suspicious (or proven downright bad) files . . . so I use the following host filters (and YES, they are mainly T1/T3s!):
10.*.*.*
24.*.*.*
66.*.*.*
67.*.*.*
This is becuase SO MANY bad files (dozens or hundreds of results) always point to some variation of above ISPs. Those 4 filters seem to cut out a lot, as well as keywords:
.exe
AWESOME
PLEASE SHARE
I hadn't thought of the innocent being infected and thereby killing potential "good sources" -- I'll try and start "bypassing" rather than willy-nilly blocking of more and more hosts.
Thanks - VERY much appreciated /p |