Feed

spyeye,zeus,rbn,scam domains

Posted on October 22nd, 2011 in fraud,malvertising,New Domains,Phishing,RBN,Trojans,zeus by dglosser

Added 206 domains associated with rbn, zeus, botnets, etc. Sources:blog.dynamoo.com, www.emergingthreats.net, zeustracker.abuse.ch and many others (Every source is  listed in the domains.txt file)

Please help to keep this site free and donate whatever you can:  All donations go to hosting and infrastructure costs.

These malware block lists provided here are for free for noncommercial use as part of the fight against malware.   Any use of this list commercially is strictly prohibited without prior approval.

Yearly sponsorships are available. Full acknowledgment, an icon, and link back to your site will be placed in the left sidebar.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.

BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format. (The mirror for compressed zip files is up and running – please contact us for details.)

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, SANs, and others…

exploit, gbot, rbn, worms… 195 New Domains to Block

Posted on July 16th, 2011 in exploit,RBN,Trojans by dglosser

195 New malicious Domains associated with exploits, rbn, gbot and other badness  to add to your shun or blacklist.  Sources include www.malwareblacklist.com, support.clean-mx.de, securehomenetworks.blogspot.com, riskanalytics.com, safebrowsing.google.com (Every source is  listed in the domains.txt file).

As mentioned in the previous post, one of these domains is cw . cm, which means there will be some overlap in our blocklist until we finish cleaning up the individual entries.

Please help to keep this site free and donate whatever you can:  All donations go to hosting and infrastructure costs.

These malware block lists provided here are for free for noncommercial use as part of the fight against malware.   Any use of this list commercially is strictly prohibited without prior approval.

Yearly sponsorships are available. Full acknowledgment, an icon, and link back to your site will be placed in the left sidebar.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.

Please download files from main mirror: http://mirror1.malwaredomains.com/files/

BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, SANs, and others…

More Rogue Security, Zeus, Spyeye, RBN Domains

Posted on June 11th, 2011 in exploit,MoneyMule,New Domains,RBN,rogue antivirus,Spyeye,Trojans,zeus by dglosser

210 SpyEye, RBN,  Zeus, TDSS, bot, exploit domains. Original sources include doc.emergingthreats.net, www.malwaredomainlist.com, www.threatexpert.com (Every source is  listed in the domains.txt file):

0c7k29 .co .cc 8c1b65893ccba911b4d0aa593a8a926f .vplaylink .info
active-scan .com al1-xscript0s .com
askredpoleq .com alfacleanwin .com
b4lry1 .co .cc alghazitractors .com
bestaudia7 .com assbrotherhood .ru
bmetalvs .com bharathiyagurukulam .com
bnavs .com boards .soapcentral .com
bnavsgroup .com buqajoqunely .com
bnavsonline .com cigivasepuxy .com
bnavsxp .com cizubejiwoma .com
bo8l1a .co .cc cleanscanpro .com
ccjava-l0ad .com coldhardcash4us .com
cibabewytyl .com complete-art-group-ltd .com
ciquqamod .com complete-art-uk .net
cknovt .com condor-llc-uk .net
cleartraf .ru condorllc-uk .com
clnovt .com crackrapidshare .net
crackshare .net crackserialkeys .net
cwnovt .com damskezimnibundy .cz
de-kadegroup .cc defender-sdvup .in
defender-tmp .in fapyrypumumuva .com
depotex .com fitevejetety .com
derlsplay .com fosimoxexora .com
dirnaster .com fuhocogupyneko .com
diverthigh .com gexopetoqoco .com
docrealtor .com ghavspacquiao .com
docweds .com google-analitycs .cz .cc
evelismag .info hermes .divinusdeus .net
ewa .kz huzatifizama .com
fabviolu .com hyviwysoqizege .com
fajomowiqy .com ideaidiosyncratic .info
famopaips .com isoftwaretvdownloads .com
fephgobd .com isoftwaretvstations .com
ffickibo .com itunesdownloadstore .com
figumsin .com jexelabexomeco .com
filmome .com jukebox-download-new .com
fugalike .com jukebox-new-download .com
fullkeygen .net juxukupyzemi .com
fuqikabyko .com jynogobefukor .com
gestaded .com kiqevinarelo .com
ghavs .com lejicolyxudy .com
ghavsgroup .com lugecunecaxez .com
ghavsinc .com moxopurarite .com
ghavsonline .com mupesatupukyqi .com
ghavsxp .com net-jaghori .webphoto .ir
h4g5kjhbk3h .com newflash1news .com
howtotws .cz .cc newflash2news .com
iproshare .vv .cc newflash3news .com
itraf .in newflash4news .com
jagbibiv .cn newflash5news .com
joyawpan .com newflash6news .com
juqesumycuz .com newflash7news .com
karbrrbrr .co .cc newflash8news .com
khumemit .cn newflash9news .com
krasava .cz .cc newplayer-downloads .com
lakersavsxp .com newsatellite-tv-forpc .com
lakersnavs .com notimexonline .com
lecuvubaja .com official-2010-version .com
mao .kz official-antivirus .com
marquee8 .co .cc official-online-download .com
mazafaka .w2c .ru official-pdf-2010 .com
mijokoquvon .com official-pdf-download .com
musclescan .com official-pdf-pro .com
mybnavs .com official-pdf2010 .com
myghavs .com official-pdfdownload .com
newbnavs .com official-version-2011 .com
newghavs .com officialbirthcertificates .org
newpdf9 .com officialbirthforms .org
noo .kz officialgreencard .org
nurulicovy .com officialimmigration .org
ohbl .in officialmarriagerecords .org
opera24 .ru officialpdf-2010 .com
overtn .com pacquiaoavs .com
patchcrack .net philippine-embassy .ir
pavahikexu .com piwetyzififa .com
picvance .com pobazepukatyc .com
pyduhomyc .com qibahovybicu .com
q27vqa .co .cc quakearena32 .ru
q714 .co .cc repavukoqipez .com
quickbroom .com rodmi4e .dlinkddns .com
qupasebyve .com ropeqeginora .com
realtraf .ru rs-323-service .ru
s106 .cz .cc ru .coolnuff .com
sisawylum .com rukizypufygejy .com
slmaat .com ryqytobogociw .com
solaraterm .com shadowoperations .co .cc
synduk .ru skyline-antique .com
tarakan2011 .ru skyline-ltd .net
thebnavs .com socawycerumyxi .com
theghavs .com spider-se0rch .com
ultimawin .com squadroshield .co .cc
vanhold .com tedowyhubal .com
vgsinfo .com tesipohycuco .com
vinuko .de thesurfrack .com
w2c .ru topnglchecker .co .be
wap-files .mobi united-trans .org
warez4me .ru vudehebaviwod .com
warez72 .ru vuvodiguqewuxe .com
warez75 .ru wacumohuqos .com
webfrogs .ru wascosafaries .com
woxoqehed .com wepomagidysaky .com
yamarsian .in xedycekycimohu .com
zaqewoqake .com ya-toptal-tvoyu-dushu .com
zdravnadzor .ru zagohitapuzog .com
zlen .ru zearch-lntr0duct10n .com

Please help to keep this site free and donate whatever you can:  All donations go to hosting and infrastructure costs.

This malware block lists provided here are for free for noncommercial use as part of the fight against malware.   Any use of this list commercially is strictly prohibited without prior approval.

Yearly sponsorships are available. Full acknowledgment, an icon, and link back to your site will be placed in the left sidebar.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.

Please download files from main mirror: http://mirror1.malwaredomains.com/files/

BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, SANs, and others…


RBN, Rogue, koobface domains

Posted on May 25th, 2011 in koobface,New Domains,RBN,rogue antivirus by dglosser

330 domains associated with RBN, rogue/fake AV and other maliciousness were added. Sources include emergingthreats.net, securehomenetworks.blogspot.com (Every source is  listed in the domains.txt file):

afiveless .com americanpoloavs .com
aievb .com analyticgoogle .net
antispyst .com avsblcamericanstatecan .com
antispyst .net avsblcksplayoffs .com
avblckscan .com avsdixieland .com
aveesca .co .cc avsgreenscangroup .com
avgreenscan .com avsgreenscaninc .com
avkok .com avsgreenscanonline .com
avkokxp .com avsgreenspassword .com
avless .com avslessgroup .com
avoffxp .com avsoffxpgroup .com
avoops .com avsoffxpinning .com
avs-jazz .com avsoffxponline .com
avs-jive .com avsxpoffgroup .com
avs-music .com avsxpoffonline .com
avs-swing .com basydiduwahaw .com
avsa-daisy .com beachpoloavs .com
avsblckscan .com betakywaxekof .com
avsbluescan .com bigoxefyfaluh .com
avsdon .com bipakypusiby .com
avsgo .com bozygawunefi .com
avsgreencan .com bucoqypynynej .com
avskok .com cajikohinele .com
avskokepub .com cheappoloavs .com
avsless .com computerplaces .info
avslessinc .com cuneqyqetyroj .com
avslessnail .com custompoloavs .com
avsll .com cynyhafyzetov .com
avsllgroup .com dadesignlive .com
avsoffxp .com deletevsgreenscan .com
avssorry .com diwamajucovy .com
avsxpoff .com dytebyhekaqa .com
avxpoff .com eyeavsexamine .com
babisotot .com eyeavsscanonline .com
bakubuniho .com eyeavstaylor .com
baxivenom .com eyereaderavs .com
betavs .com eyereaderavsxp .com
betavsgroup .com eyescannerav .com
bikepoloavs .com eyescanneravs .com
blowavs .com eyescanneravsgroup .com
bnetns .ru eyescanneravxp .com
boxisosypi .com fifotojylahe .com
bytypupecex .com filteringlavs .com
cacirowec .com fohohovugoredo .com
cagolasevaj .com gasavsonline .com
califepro .com gavorydigejizy .com
capurasaf .com gilebifabusexa .com
cilybodyd .com giwomylywokof .com
cudokopipi .com globalpoloavs .com
cygogonabeq .com hawaiipoloavs .com
danoduc .wo .tc hebypudukotih .com
dihisalyh .com inningavsxpoff .com
dowemawema .com inningvsoffxp .com
eacvb .com jojevijehajyx .com
eievb .com jywujodocivine .com
eonvb .com kilumixefiki .com
epubvskok .com lakersscanneravs .com
eyeabscan .com lessavsonline .com
eyeavscan .com llanorthwestern .com
eyeavsscan .com logapacquiao .com
eyeavssee .com logavsonline .com
fakovuhuju .com lutheranantivirxp .com
foqadobyve .com lutherantivirxp .com
fyhykubux .com lysocoharogyg .com
gasavs .com lywicoxyvuby .com
gasavsgroup .com m00vable-fiesta .com
gasicekymas .com myavsblckscan .com
geduhijykes .com myavsgreenscan .com
gidewuboler .com myeyeavsscan .com
gilodivere .com myeyescanneravs .com
goinprivate .com mywinantivirusxp .com
h3456345 .cn nabubymepicizu .com
hifoqaxinaj .com newavsblckscan .com
hupnb .com newavsgreenscan .com
jocusacegir .com newavspridewin .com
jukecoruvut .com neweyeavsscan .com
kesykijigut .com neweyescanneravs .com
kyqegovujug .com nodihykyhopyz .com
lessavs .com nupecehededave .com
lessavsinc .com pacquiaologavs .com
lettervs .com passportantivirusxp .com
lidvb .com passwordavsgreenscan .com
llavsonline .com passwordvsgreenscan .com
logafive .com pipugodupexug .com
logav .com playoffsvsblckscan .com
logavs .com poreavsgroup .com
logavsgroup .com poreavsonline .com
logavsmanny .com premiumantivirusfreescan .com
loseavs .com premiumfreescan .com
luqotazih .com pulirutugeqaf .com
mannyavs .com punanufawenyk .com
mannybetavs .com qikawykytapysy .com
mavsloidol .com qixaxyrujuqici .com
mecaqyvupi .com qukocacilogoti .com
mezibehab .com qyfimeluxeqok .com
mufobapix .com recabikixyse .com
myavsboom .com rinepigelowot .com
myavsdam .com rugabujotidil .com
myavsoffxp .com ruvahekamefan .com
myavsxpoff .com seiningcarno .co .cc
mybetavs .com sixihyqecyfuku .com
mygasavs .com snailessavs .com
mygolavs .com sonycojaqowik .com
myllavs .com syfurojoxereku .com
mylogavs .com tayloravsscan .com
myporeavs .com tedowuveqakej .com
mywinavs .com theantivscanfree .com
ncaaavs .com theavsblckscan .com
newavsboom .com theavsgreenscan .com
newavsdam .com theavsoffxp .com
newavsll .com theavspridewin .com
newavsoffxp .com theavsxpoff .com
newavsxpoff .com theeyeavsscan .com
newbetavs .com thewinantivirxp .com
newgasavs .com tinocusebawu .com
newgolavs .com tsunepspatiz .co .cc
newlessavs .com tumevamusytoc .com
newllavs .com turezidejuzok .com
newlogavs .com tutupeqyrar .com
newporeavs .com tycalinumijotu .com
newwinavs .com tytunajilac .com
nihedimes .com vadyrokufubu .com
nupnb .com vefyqylepahuga .com
oilavs .com vekoxarotucev .com
owavb .com vepizujefewa .com
piavb .com video-playerpro .com
polossavs .com vikitarurepuq .com
poqacelufeq .com viraltraffic-guide .com
poreafigure .com virustest01 .cz .cc
poreav .com vivasidasaves .com
potasajic .com voice-ip-download .com
puvepydilaj .com voip-2010-download .com
qatijoxuna .com voip-2010-new-download .com
qovukezur .com voip-2011-version .com
ranamujesu .com voip-access-now .com
rhpavsxpoff .com voip-new-online-download .com
rhpvsxpoff .com voip-official-download .com
ronadosim .com vovyjaryguwu .com
rsravs .com vywobohexinipa .com
salysymyp .com waginujiwoha .com
savicypacy .com watch-football-tv-live .com
seekartists .com watch-hd-movies-online .com
semuvajako .com watch-hockey-online .net
sobudajib .com watch-hockeyonline .com
taxhiking .com watch-live-2010-football .com
theavsboom .com watch-online-basketball .com
theavsdam .com watch-online-boxing .com
thebetavs .com watch-sports-network .com
thegasavs .com watch-superbowl-online .com
thegolavs .com watch-ufc-live .com
thelessavs .com watch-ufc-online .com
thelogavs .com watchonline-football .com
togizypad .com website-support .ru
tuwifotiju .com wedytatuxug .com
vehepumac .com wenomepodipiby .com
virafix .com wiqesidavevod .com
vkodewol .cn wirybidyzufij .com
vsefurug .cn xeruraxagum .com
vtuyocew .cn xifuzakotyk .com
wetyotix .cn ximeqeteporaco .com
wihoraqite .com xisohyrydily .com
wupnb .com xynixucujeduru .com
xajizukoxo .com zizudadidura .com
yupbn .com zizyhaqizod .com
zyejanag .cn zymaqamusowibu .com

Please help to keep this site free and donate whatever you can:  All donations go to hosting and infrastructure costs.

This malware block lists provided here are for free for noncommercial use as part of the fight against malware. Any use of this list commercially is strictly prohibited without prior approval.

Yearly sponsorships are available. Full acknowledgment, an icon, and link back to your site will be placed in the left sidebar.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.

Please download files from main mirror: http://mirror1.malwaredomains.com/files/

BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, SANs, and others…

80 New Malware Domains to Block

Posted on March 15th, 2008 in fake codecs,New Domains,RBN,rogue antivirus by dglosser

80 new domains associated with malware, from various sources:

01478963.com 0339106262.co.jp
3000tvchannels.net 360-share-music.com
360share.cn 360share.net
360sharepro.com acrobat8download.com
acrobatdownload-ib.com ad-zero.com
adobe-reader-it.com adobeacrobatpack.com
adobeacrobatreader-8.com adobepack.com
adultmoviesmembersarea.com adwarepro.com
adwarepro.org alguiennoteadmite.com
alm7tas.64mb.org antivirus-ib.com
antivirus-panda-suite.com archive.easydownloadsoft.com
arqtxthost.extra.hu arquivos.pop3.ru
assuntosnow.extra.hu awnn-efvz.com
bankdiyed.cn bimoo.com.cn
blase.tu1.ru build-myspace.com
caiyi8.com carlosassociacao.com
cash-point.co.kr cash5678.com
cashbagmoll.com cashengines.com
cashslinger.com ce.83195900.cn
centerkras-tv.biz cevapcic.eu
cybertvpartner.com dvd-codec.com
free-download-center.com free-satellite-network.com
free-spybot.com gogo52o.com
hamakarin.ch interactivebrands.com
intrich.com kh4l3d.net
kit.net kv8.info
maxyouripod.com mcafee-antivirus-2007.com
mcafee-suite.com mcafeebundle.com
mcafeepack.com mizane.com
mp3downloading.com mybil1.com
mybil2.com mybil3.com
mybil4.com mybil5.com
mybil6.com mybil7.com
mybil8.com mybil9.com
netmp3downloads.com panda-2008.com
panda-anti-virus.com panda-antivirus-2008.com
pandaantivirus-2008.com pandaantivirus2008.com
pandasecurity2008.com sexoffender-registry.com
sqmnoopt.com themusicsmembersarea.com
unifi5h.com xingaide8.cn

Help fight spyware: Join the Spyware Listening Post!

domains.txt file is the complete list along with original reference

Updates are located at http://www.malwaredomains.com/updates
The full files are located at: http://www.malwaredomains.com/files

BOOT file is in MS DNS format
spywaredomains.zones file is in BIND format

Almost 500 new RBN/CoolWebsearch Domains Added

Posted on March 9th, 2008 in New Domains by dglosser

Almost 500 new domains associated with malware, mainly from Webhelper.

Too many to list, view in the http://www.malwaredomains.com/updates directory.

Help fight spyware: Join the Spyware Listening Post!

domains.txt file is the complete list along with original reference

Updates are located at http://www.malwaredomains.com/updates
The full files are located at: http://www.malwaredomains.com/files

BOOT file is in MS DNS format
spywaredomains.zones file is in BIND format

New RBN and CoolWebSearch Domains

Posted on March 7th, 2008 in New Domains by dglosser

Over 100 new RBN and CoolWebSearch domains from webhelper:

anonimutente.com antievidence.com
antivirusfiable.com antivirusforalle.com
antivirusmagique.com anzentsuru.com
archivosenestado.com aucunchoixpourvirus.com
aucunefaute.com aucuninfection.com
aucunmenace.com aucunserreurs.com
avcompleto.com avseguro.com
bandoalleinfezioni.com bastioneantivirus.com
beskyttendevaerktoj.com bestsellerantivirus.com
blanchdisc.com borresuspasos.com
brossedesfautes.com ceroamenazas.com
chasseurdeserreures.com cleanpctool.com
cleanuptool.com confidentsurf.com
confidentuser.com contenidoseguros.com
contenteraser.com curerrores.com
dataconfidentiality.com defensecelebre.com
defensededriver.com defensedinformation.com
defensedudisque.com defensenetsurfage.com
defensivesystem.com dejitarufukugen.com
dejitarukyoikira.com dejitaruwakuchin.com
detaripea.com diskretter.com
disksaeuberung.com disksizesaver.com
disksparare.com disukushuri.com
doubledefender.com driversecurise.com
eliminadordeamenazas.com elmejorantivirus.com
enmiendaerrores.com eracheisa.com
erreurchasseur.com errorfighter.com
essentialeraser.com exterminadordevirus.com
fairukyua.com fejlreparering.com
felfixare.com ferramentasegura.com
fiksdinpc.com fixthemnow.com
fjernervirus.com geheugenredder.com
guardiandelaprivacidad.com gubbishremover.com
harddriveguard.com herramientasegura.com
historialout.com hotbevakning.com
ingavirus.com ingenmulighetforvirus.com
inhaltsaeuberung.com inmunepc.com
kakujitsutsuru.com keineviren.com
knowhowprotection.com konsekiauto.com
kontentsufiruta.com kurinkonseki.com
kyoiireza.com largavidapc.com
laufwerkcleaner.com limpietodo.com
lomejorenantivirus.com longlifepc.com
lungavitapc.com memorisebu.com
menacefighter.com menacemonitor.com
menacescrubber.com monitordeamenazas.com
moteurpcpro.com netsurfageassure.com
nettoyeurdeserreures.com nettoyeurdevirus.com
nurdeinpc.com omelhorantivirus.com
onrainpurotekuta.com oruripea.com
pasderreurs.com pasdesfautes.com
pasdesmenaces.com pasendommagement.com
pcantiviruspro.com pcassertor.com
pcbewaker.com pcboosterpro.com
pceternel.com pcforfender.com
pchealthkeeper.com pclibredevirus.com
pcohnespuren.com pcsecurise.com
pctoolpro.com pcveiligheidstool.com
pcvirussweeper.com preservingtool.com
privacidadgarantizada.com privacidadyseguridad.com
privacyredder.com privacywaker.com
privacywarrior.com protecaoconfiavel.com
proteccionasegurada.com proteccioncompleta.com
protectionassuree.com protectionconue.com
protectiondedriver.com protectiondenetsurfage.com
puraibashihosho.com puraibashitoshinrai.com
reparaerrores.com repareja.com
reparemenaces.com repareya.com
riparaminacce.com riparasubito.com
riservatezzanet.com safepctool.com
safudaijoubu.com sansendommagement.com
sayonarabaggu.com schijfbewaker.com
schijfcontroleur.com schijfredder.com
secretissimosoft.com secretopertutti.com
secretosasalvo.com secretoseguro.com
sefunahimitsu.com senzadoppioni.com
shingaidome.com shinraihogo.com
shisutemudifensu.com sicherheitstool.com
sikkerbrukere.com sikkerpcredskap.com
sinataques.com sinrrastros.com
sinsenales.com sistemupyua.com
sisutemuantei.com sisutemuorugurin.com
smittfri.com speichertool.com
superanonimo.com surfforsure.com
surfremover.com syssauvegarde.com
systemesansfaute.com systemhoover.com
toolsicuro.com trasheraser.com
trustedantivirus.com trygpcbruger.com
turnkeyantivirus.com unidadessanas.com
usuarioprotegido.com utiledereparation.com
utilisateursur.com virusurimuva.com
virusvanger.com virusvijand.com
winchesterprotector.com wirusufinisshu.com
wirusuk.com wirusukyua.com
wirusushattodaun.com wirusushuryo.com
yourprivacyguard.com zentaiwakuchin.com

Help fight spyware: Join the Spyware Listening Post!

domains.txt file is the complete list along with original reference

Updates are located at http://www.malwaredomains.com/updates
The full files are located at: http://www.malwaredomains.com/files

BOOT file is in MS DNS format
spywaredomains.zones file is in BIND format

RBN and Rock Phish Domains

Posted on March 3rd, 2008 in Domain News,Phishing by dglosser

Two interesting articles:

New RBN Overview.   Lists networks and Domains used by the Russian Business Network (by Shadowserver):  http://www.shadowserver.org/wiki/uploads/Information/RBN_Rizing.pdf

Anatomy of a Rock Phish. Lists Dozens of Rock Phish Domains (by F-Secure):
http://www.f-secure.com/weblog/archives/00001390.html