Feed

Scareware, exploit, fake antivirus domains

Posted on April 30th, 2009 in New Domains,rogue antivirus by dglosser

Some scareware domains, fake antivirus domains,   exploit domains.  Sources: www.threatexpert.com, www.scanw.com, safelab.spaces.
live.com, www.malwaredomainlist.com and others:

0kfzzl .us kem-softwares .com
0texkax7c6hzuidk .com koha0kohaweb .com
18lxkl .com lgv97 .cn
19399 .com .cn marlene-jones .com
38zu .cn mbr2 .cn
900990 .cn mbr8 .cn
9494iei .cn megarunner .com
94mekelove .cn nameleap .net
adobesoft .co .cc net-intra .com
adobeus .com o-ap .cn
analiticstat .com onlinevirus-scannerv2 .com
antiwareprotect .com pcantimalware .com
asdy77 .cn pc-on-internet .com
atom4scan .com pc-privacydefender .com
av4321 .us perfect-banner .com
avscan-pc .net photo-posts .net
betworldwager .cn plumsauce .info
bgbtorlopos .com pornotubxxx .com
bigtopliteworld .cn qian14 .cn
bstyjx .com reopsakwww .com
chinesefreewebs .com rising .mobinil .biz
djl87 .cn rotkid .com
downloads-123 .com scan-antispyware-4pc .com
downloadv3 .com scanner-antispy-av-files .com
enjoyspringtime .com scanner-work-av .com
esfang .house .sina .com .cn skype-fly .com
facebook-gallery .org sorwwwros .cn
face-books .org sphericalart .com
fast-scanner-4pc-pro .com statsanalist .cn
fastviruscleaner .com sxd65 .cn
fdg43 .cn tomohappy .com
flickr-foto .com trucount3000 .com
freewebtown .com uszn66 .ru
fwef222 .cn wansf .net
gjk67 .cn weh8dnb .com
grafjasqq .ru wezdujur .cn
hopeextra .com xinfa8 .com
individualpeople .biz yourcountrycoupon .com
kds85 .cn zhonghr .com
Contact us if you want to help us keep the MalwareDomain Blacklist current.
Read this page if you want to report a false positive.
Domains.txt file is the complete list along with original reference.
Updates are located at http://www.malwaredomains.com/updates.
The full files are located at: http://www.malwaredomains.com/files
BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.
Also Available in AdBlock, ISA, and MaraDNS formats.
Now a trusted source on the WOT-the Web of Trust!
Used by SURBL, MOREnet, and others…

SwineFlu Domains

Posted on April 28th, 2009 in News by dglosser

F-Secure has just published a list of Swineflu related domains.  You can be sure some will will be used for spam or serve up malware:

www.f-secure.com/weblog/archives/swineflu_domains.txt

Obviously, use extreme caution when accessing these sites or clicking on links in emails related to the swineflu.

Source: http://isc.sans.org/diary.html?storyid=6280

You may want to caution your users about clicking on these links or proactively add them to your own blocklist.   Domains will only be added here once they  have been verified to be malicious.

Over 200 New Malicious Domains to Block

Posted on April 25th, 2009 in New Domains,Waledac by dglosser

Waledac,  fast_flux, trojan, rogue security domains. Sources include dnsbl.abuse.ch, secuboxlabs.fr, atlas.arbor.net, and others:

1ilhf.com 9aga999a9gg99a .com
9e7fs .com anispy-storage-ms .com
acceptslim .com antivir-4pc-ms-av .com
airplugin .com antivir-scanner-ms-av .com
any6scan .com antivirus360remover .com
attemptright .com antivirus-av-ms-check .com
augustbody .com anytoplikedsite .com
auntbody .com attentionbody .com
authorbody .com audienceright .com
bestcover4u .cn australiabody .com
bestscan7 .com av360removaltool .com
bigcoverlive .cn availablebody .com
cavle-online .com bestdefenselive .cn
cenpak .net bestexaminedisease .cn
chani990 .cn bestprotectiononline .cn
cyberagthor .tk bigprotectionlive .cn
data4scan .info botnetinkey .co .cc
data6scan .info constructadvancedblock .cn
datascan4 .info discountfreesms .com
dayrss .com easyaddedantivirus .com
dengtai .cn easypersonalprotection .cn
dfg34 .cn easyserviceprotection .cn
duplozavr .com eccellentesms .com
easy4scan .info esnetscanonline .com
easyscan4 .info examinepoisonstore .cn
egu8c .com exstra-av-scanner .net
ever4scan .info extremetube09 .com
ever6scan .info fastantivirus09 .com
everscan4 .info feds-r-watching .us
everscan6 .info files .scanner-antispy-av-files .com
extraspray .com freecoverstore .cn
ftpgeoit .com freesmsorange .com
gameicity .com friskdiseaselive .cn
getips .info fullsecurityshield .com
godatascan .com greatstabilitytraceonline .com
gofanscan .com hot-girl-sex-tube .com
golitescan .com jinzhuangzhuang .cn
goluxscan .com managesystem32 .com
goonlyscan .com mega-antiviral-ms .com
goscandata .com ms-antivir-scan .com
goscanhigh .com ms-anti-vir-scan .com
gosidescan .com msantivir-storage .com
gostarscan .com ms-antivirus-storage .com
gotipscan .com ms-av-storage-best .com
gpdvinc .com msscan-files-antivir .com
hi5-book .com msscanner-files-av .com
installing .cc msscanner-top-av .com
ipersmstext .com mycheckdiseasepro .cn
leaphe .com myexaminevirusstore .cn
linescan6 .info networkstabilitytrace .com
liteauction .cn no-as-scanner .com
log6scan .info nuovosmsclub .com
loyalvideoz .com ogggooogoggoog .com
main6scan .info onlinespywarescanner .net
mainscan6 .info onlinestabilityscanada .com
mixbunch .cn pantispyware09 .com
morefreesms .com pay-virusdoctor .com
mydefense4u .cn plasticsurgeryworld .info
mysuperviser .com powelldirects .com
new7scan .com primosmsfree .com
newguard4u .cn pro-scanner-av-pc .com
newscan4 .info protectionexamine .com
newtransfer .cn quickstabilityscan .com
odmina .ru remove-antivirus-360 .com
oirooke .com remove-av360 .com
onlyfind .net remove-ie-security .com
pdjsj .com remove-malware-defender .com
photo-msn .org remove-spyware-guard .com
prrrr .com .cn remove-spyware-protect .com
qdvideo .com remove-spyware-protect-2009 .com
refugepro .cn remove-system-guard .com
remove-a360 .com remove-total-security .com
reporting32 .com remove-ultra-antivir-2009 .com
scan6fast .com remove-ultra-antivirus-2009 .com
scan6step .com remove-virus-alarm .com
scanbest6 .com remove-virus-melt .com
scaneasy4 .info remove-winpc-defender .com
scanline6 .com safetyexamine .com
scanline6 .info scan-antispy-4pc .com
scanlog6 .info searchrizotto .com
scanmix4 .com securityhelpcenter .com
scannew4 .info spyware-file .info
scanstep6 .com spyware-files .info
scantool4 .info stabilityinetscan .com
selectusers .com statxservice .com
seresult .com sunmaiamibich .ru
shaimokale .com swiftsafetyexamine .com
smsinlinea .com tds1 .onlineredirsystem .com
smsluogo .com toppromooffer .com
stats4x .com topsecurity4you .com
sufujilisi .info trustsecurityshield .com
texasvino .com vazasaki-ji .info
thevann .com virusalarmpro .com
tool4scan .info vmfastscanner .com
true6scan .com vundofixtool .com
webantispy .com yourcheckpoisonpro .cn
wj-asys .com yourcountedantivirus .com
workfuse .cn yourfriskdisease .cn
xhyydingbi .cn yourguardonline .cn
yah00520 .cn yourguardstore .cn
yourguardpro .cn zsgszzzszggzzs .com

Scareware Domains and others to block

Posted on April 19th, 2009 in Domain News,New Domains,rogue antivirus by dglosser

Some mebroot and waledac domains, scareware domains, exploit domains. Sources include: secuboxlabs.fr, www3.malekal.com, www.threatexpert.com, and others:

2981 .net .cn 82siddefault .com
2icqmag .ru achyutheil .ac .ohost .de
5dsa4d .cn actual .homelinux .com
6129 .net .cn antivirus2009plus .com
6330 .net .cn attmyjoker .com
7ioi .biz bdsm-movies .info
antispyme .com chartseye .com
avtode777 .com checkantiddos .info
bakeloaf .com chinamobilesms .com
bobo111 .cn chorussoft .com
botlife .cn corporatefootprint .co .uk
c .tes85 .cn dfdsfdsfcdsc .com
cashpanic .com download .favorit-network .com
ccj5 .cn downloadfreesms .com
coralarm .com errorstool .com
counnter .cn formerlyus .com
criter .ru freecolorsms .com
cupit-dom .ru freeonlinehostguide .com
d0lphin .biz freeservesms .com
dew7f .cn freewebhostguide .com
dv7q .com goldfixonline .com
fryroll .com google .netcdn .com
fwef333 .cn lastlabel .com
gmer .net liteautogreatest .cn
goodtraff .ru loyal-porno .com
hostteam .org miosmsclub .com
it3s5 .com moneymedal .com
kroto .biz munobatuno .com
meng3130 .cn netcorbina .org
nuovosms .com pantispyware09a com
okfilm .ru photo-uploader .ru
okwit .com pinigeliai .com
paksusic .cn prodownloadmanager .com
paylayos .cn rapidantivirus09 .com
qqc2009qq .cn rapidantivirus-09 .com
qwr2 .cn screenalias .com
rifnasax .cn sh-hostz9 .net
roxmiced .cn silver-services .net
s0si .ru siski-piski .biz
sgqw .info smsclubnet .com
spaeioer .com smsdiretto .com
tagdebt .com smspianeta .com
tes85 .cn tochtonenado .com
tiq38e .cn tradepark .info
truff .biz tran .tr .ohost .de
vert4 .cn update-xp .com
wfwwlleo .cn virtualesms .com
wvvexfux .com wealthleaf .com
xtjhvcjh .com winpcdown99 .com
yrd9 .cn yourbarrier .com
Contact us if you want to help us keep the MalwareDomain Blacklist current.
Read this page if you want to report a false positive.
Domains.txt file is the complete list along with original reference.
Updates are located at http://www.malwaredomains.com/updates.
The full files are located at: http://www.malwaredomains.com/files
BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.
Also Available in AdBlock, ISA, and MaraDNS formats.
Now a trusted source on the WOT-the Web of Trust!
Used by SURBL, MOREnet, and others…

Over 185 new malicious domains

Posted on April 15th, 2009 in Domain News,fake codecs,New Domains,Phishing,rogue antivirus by dglosser

Domains associated with rogue  antivirus,  fake security sites, phishing, malspam, and others.   Sources include blackip.ustc.edu.cn, ddanchev.blogspot.com, ilion.blog47.fc2.com, and others:

1000league .com 28sslput-search .com
123dcy .com 48reg-sslid .name
163-sohu-sina .cn activesecurityshield .com
177bt .com adult-tube-downloads .net
1bnk-log .net allsoftwarepayments .com
48rdirjava .com all-software-payments .com
63mode .me alltoitworld .com
765access .com antispywareupdatesystem .com
88code-tcp .com antivirusonlineproscan .com
9845account .com antivirusonlineproscanner .com
advabnr .com antivirus-pro-live-scan .com
af9f440dcc .com avs-online-scan .org
agu4idfir .com awardspacelooksbig .cn
ainigc .cn bdbdbddbdddbdd .cn
am-scan .com bestsecurityupdate .com
aoc8 .com beststabilityscans .com
atlanticbody .com bsd3-1 .elaninet .com
baidu-1163 .cn cat-browse30 .net
bankitrade .com checkonlinesecurity .com
bellezkino .biz cmdidverify82 .name
best6scan .info devinepromotions .cn
bezotezi .wz .cz download-pro-as .com
bigdefense2u .cn dwnld .offer-provider .com
bookadorable .cn easycheckpoisonpro .cn
bszyxy .cn easydefenseonline .cn
coco-ifc .net examineillnesslive .cn
codecvistaz .com fjfnfnfnaaswwospotyacai .com
crustat .com fullandtotalsecurity .com
cvbnmdgesc .cn futuremedshop .com
data6scan .com getsecuritywall .com
davidkramm .net greatsecurityshield .com
dbrgf .ru greatvirusscan .com
dddbbbddbbdbd .cn hqviewworldmy1 .com
designroots .cn hyperliteautoservices .cn
directitfast .com initialsecurityscan .com
drawingstyle .cn ipdatacenter .net
etyj .ru kvk .housevisual .cn
fikjugsg .com load-pro-antispy .com
gceakrpa .net macroviewonline .cn
gohardscan .com mikeyylolz .uuuq .com
goscanhard .com moneystyle .com .cn
goscanmind .com myascertainpoison .cn
goscanport .com offer-provider .com
goscanstep .com onlinedetect .com
grgdidfir .com onlinescanservice .com
hansali4 .com overpoweredsystem .cn
housevisual .cn powerdownloadserver .com
ie854 .cn pub .oceandealer .cn
iioo4567 .com rapid-antivir-2009 .com
ik326 .cn runpcscannow .com
in4ck .com scanalertspage .com
ir078 .cn scanner-wiz-1 .com
kevin-jok .cn scanspywareonline .com
ks630 .cn sdahidsahidsahi .
letomerin .cn secure .bestbillingpro .com
lijg .ru securedantivirusonlinecom
lite6scan .com securedliveuploads .com
litebest .cn securedosupdates .cn
mainscan6 .com securedprosoftwareupdate .cn
megavipsite .cn securedsoftwareupdate .cn
mixante .cn securedsystemresources .cn
msngk6 .ru securedupdateslive .cn
murka-best .com securitysoftwarecheck .com
new-mrcash .net securitytopagent .com
nhdiw .com securityupdatessystem .cn
oceandealer .cn soft-traffic .com
pbtgr .ru softwareupdatessystem .com
peopleopera .cn spy-protector-pro .com
pharm-on-net .com sys-scanner-1 .biz
pnfzetnax .net sys-scan-wiz .biz
projectns .biz system-scan-1 .biz
qwuioz .cn thankyou4check .com
r6c8d .cn thebestsecurityspot .com
rainfinish .cn thegreatsecurity .com
rd-point .net todaybestscan .com
scan7live .com totalantispyware .com
schoolh .cn totalantispyware .net
sykalab .net totalantispyware2009 .com
top-name .cn total-malwareprotection .com
traffbox .com total-virusprotection .com
traxxk .cn transformercity .cn
uwgcn8 .com truescansecurity .com
uye123 .com webprotectionscan .com
vas4k .cn websecuritymaster .com
vitamingood .cn websecurityvoice .com
vjhdo .com websiteflower .cn
wgcn8 .com webwidesecurity .com
worksean .cn weisichuanxiongqi .cn
wuc9 .com windowssecurityupdates .cn
yourpharmweb .com wwwsafetyread .com
ys8c .com xfln .housevisual .cn
zafiraworld .com youbenshizaifen .cn
zeterods .com zenji .freehostia .com
professionalsoftwareupdates .com

Blackhole-DNS Update 4/11

Posted on April 11th, 2009 in Domain News,rogue antivirus by dglosser

Sources include: www.malwaredomainlist.com, safelab.spaces.live.com, www.google.com/safebrowsing, and others:

0314w .com 087control .com
1300li .com 654control .com
176r .com 7657control .com
2c2d .cn addantivirus .com
33control .com antivirus-av-ms-checker .com
49control .com asdfgsdfgsdf .cn
518mk .cn bestfindaloan .cn
991uu .net bestguideinc .net
999mimi .net bigtopescorts .cn
a88b88 .com bitspirit .com .cn
adfsgsdgfb .cn casinobigtop .cn
anyscan6 .com consignmena5173 .cn
arhjfgjdrf .cn coolnameshop .cn
buidnote .com daslxzcewralrocjn .cn
catch-you .ru dave-wijnhoven .nl
ccqmjcthr .com dotcomnameshop .cn
chezswing .com dramaserials .com
clarafin .info easter-egg-design-funny .diwyze .net
cokiran .com educationbigtop .cn
daratop .cn famajormusic .ru
dnf-gg .cn files .download-av-ms .com
eub0t .6te .net fiminauar .info
finik .us findbigthinker .cn
genwjq .com fun .crossroadscapebreton .ca
gonewscan .com gitoeanai .info
goscanweb .com googleadserver .com
gosscan .com goooogleadsence .biz
haoxia18 .com goooogleadsence .com
jd9k .cn hugetopnonfat .cn
kegod .cn hyperliteautoservices .cn
limitin .de inetsecuritycenter .com
lotante .cn interinetskim .com
lotbetsite .cn internet-antivirus-pro .com
myrx8 .net internetnamestore .cn
mysscan .com japanhostnet .com
poshlivse .com jeans0nline .cn
qq163-eild .cn kallagoon13 .cn
qqnn .net liteautofinestsite .cn
scan6main .com litedownloadfinest .cn
scan6tool .com litehitscar .cn
scanweb4 .info livestopbadware .com
sftcp .cn lotbetworld .cn
stased .com lotwageronline
stepscan6 .com luisababa .com .cn
taobaoot .com namestorefilmlife .cn
thelotbet .cn nemesis .feed .parkingspa .com
vivne .cn orferhuijj .com
websscan .com playbetwager .cn
wohenleile .cn puerkoric .info
woxiaohei .cn regantivirus .com
wwwfbcdn .net scan4best .info
xiaonei .com topsecurityapp .com
xuan666 .com tubeloyaln .com
yutergfrg .cn wwwmobilereads .com
zodune .info zeus-logs .biz
Contact us if you want to help us keep the MalwareDomain Blacklist current.
Read this page if you want to report a false positive.
Domains.txt file is the complete list along with original reference.
Updates are located at http://www.malwaredomains.com/updates.
The full files are located at: http://www.malwaredomains.com/files
BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.
Also Available in AdBlock, ISA, and MaraDNS formats.
Now a trusted source on the WOT-the Web of Trust!
Used by SURBL, MOREnet, and others…

Domain Blocklist Update: 72 new sites

Posted on April 8th, 2009 in Domain News,New Domains by dglosser

Sources: malwaredomainlist.com, secuboxlabs.fr, ddanchev.blogspot.com, and others:

02sta .com 1st .abdulabah .cn
5rublei .com casinoslotbet .cn
abdulabah .cn checker-pc-pro-av .com
acidbot .cn contr-softportal .com
ainill .cn dec-software .com
basesrv3 .net desktoprepairpackage .com
bvakjyr .com dnk-softwares .com
cheviram .com facebook-photo .net
com82c .cn facebook-photos .net
com87k .cn freehostinternet .com
cqfcusco .org freeportalsoftwarenow .com
daddybigtop .cn frg-softwares .com
fcuebook .com get-softwares .com
globerstube .com glk-softportal .com
globextubes .com globalstube2009 .com
googli .us glock-softwares .com
grandtraf .com hackdownload .cn
hi-bro .net illegaltopcounters .ru
iht2 .cn kol-development .com
in4sk .com liteautorepair .cn
javacsript .biz loyaldown99 .com
kolpinik .com mediahousenameshopfilm .cn
letomerin .cn pcantimalwaresolution .com
mikorki .com pesut1 .pe .ohost .de
msn-gallery .us privacyscanner15 .com
nahyu .org removespywarethreats .com
news-blog .biz sim-softportal .com
news-week .biz somefilesportalnow .com
njihemi .com spywareremover21 .com
oymomahon .com systemscanner19 .com
pibidu .com traff-direct .com
shikofotot .net tri-visionhomes .com
sobadar .cn ultra-av .googlecode .com
walterex .info vlrm .googlecode .com
xretrotube .com welovesandi .com
yfe5 .cn yournonfatbest .cn

75 Domains to Block

Posted on April 4th, 2009 in New Domains,Phishing by dglosser

Sources: www.malwaredomainlist.com,  secuboxlabs.fr, www.threatexpert.com, www.mozilla.com/en-US/firefox/phishing-protection and others:

2349panel .com av-plus-support .com
23setting .com bestnetcheckonline .com
43553panel .com bestwebexamine .com
654panel .com downloadantivirusplus .com
876panel .com downoalsdcenter .com
9607 .net .cn easynetcheckonline .com
987panel .com easywebexamine .com
98tdw .cn edwardhomepage .info
adult .oo .lv g00gleadserver .com
bytenetcom .cn houseoftreding .info
dasretokfin .com incredible .kiev .ua
files250362 .net internethomecheck .com
getpcguard .com internetsafetyexamine .com
iliketay .cn kenedydirect .com
k8l .org lieliteautobody .cn
kingf0x .net magnificents .net
krona98 .biz meetstripvideo .com
la2planet .com msn-gallery .biz
linkcanpro .com myfucking-pussy .com
loading-atm .net nullroute .balkan-hosting .net
loading-nrp .net quicksearchnet .com
loading-nso .net safeyouthnet .com
loyaldown09 .com scanbaseonline .com
loyaltube10 .com search .hopto .org
myrealtube .net sex4you .crazynet .org
peskufex .cn silentpanel .name
qicdator .cn singharmony .com
qtas .net softupdate09 .com
rscserv .com spyware-protector-2009 .com
ru98 .biz theantivirusplus .com
ru98 .net websecurecheck .com
syncupdate .com websmartcheck .com
tubeloyal .com websportscheck .com
turokgame .cn winpcdown09 .com
uszers .cn yournetascertain .com
vestelia .com yournetcheckonline .com
win5millon .com yourwebexamine .com
www-images .com