Feed

265 new domains

Posted on July 27th, 2011 in exploit,fake codecs,malspam,New Domains,rogue antivirus by dglosser

ramnit, palevo, rogue, fake codec domains were added. Sources include vxvault.siri-urz.net, www.threatexpert.com, garwarner.blogspot.com

(Every source is  listed in the domains.txt file).

Reminder: 
Starting on August 1st, the zone and text files will ONLY be available from a mirror and will no longer be available on the main site!!


Please help to keep this site free and donate whatever you can:  All donations go to hosting and infrastructure costs.

These malware block lists provided here are for free for noncommercial use as part of the fight against malware.   Any use of this list commercially is strictly prohibited without prior approval.

Yearly sponsorships are available. Full acknowledgment, an icon, and link back to your site will be placed in the left sidebar.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.

Starting August 1st, files are ONLY  available via the download mirrors. Main mirror is : http://mirror1.malwaredomains.com/files/

BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, SANs, and others…


willysy .com Mass Injection

Posted on July 26th, 2011 in 0day,Domain News,exploit by dglosser

Armorize reports on a mass injection of, 90,000 infected pages. The injected iframe points to willysy .com.

We’ll be adding those domains on tonight’s update, but please read the article and take immediate action if you can.

180 New TDL3/TDSS Botnet, cycbot, exploit, rogue domains

Posted on July 18th, 2011 in exploit,New Domains,RBN,rogue antivirus,Trojans,zeus by dglosser

Added 180 domains associated with fake security/scareware, rbn, TDSS/TDL3, TDSS4 etc. Sources include securehomenetworks.blogspot.com, scrapbook.zscaler.com, blog.eset.com and others (Every source is  listed in the domains.txt file).

Please help to keep this site free and donate whatever you can:  All donations go to hosting and infrastructure costs.

These malware block lists provided here are for free for noncommercial use as part of the fight against malware.   Any use of this list commercially is strictly prohibited without prior approval.

Yearly sponsorships are available. Full acknowledgment, an icon, and link back to your site will be placed in the left sidebar.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.

Please download files from main mirror: http://mirror1.malwaredomains.com/files/

BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, SANs, and others…


exploit, gbot, rbn, worms… 195 New Domains to Block

Posted on July 16th, 2011 in exploit,RBN,Trojans by dglosser

195 New malicious Domains associated with exploits, rbn, gbot and other badness  to add to your shun or blacklist.  Sources include www.malwareblacklist.com, support.clean-mx.de, securehomenetworks.blogspot.com, riskanalytics.com, safebrowsing.google.com (Every source is  listed in the domains.txt file).

As mentioned in the previous post, one of these domains is cw . cm, which means there will be some overlap in our blocklist until we finish cleaning up the individual entries.

Please help to keep this site free and donate whatever you can:  All donations go to hosting and infrastructure costs.

These malware block lists provided here are for free for noncommercial use as part of the fight against malware.   Any use of this list commercially is strictly prohibited without prior approval.

Yearly sponsorships are available. Full acknowledgment, an icon, and link back to your site will be placed in the left sidebar.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.

Please download files from main mirror: http://mirror1.malwaredomains.com/files/

BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, SANs, and others…

168 New Domains Added

Posted on July 12th, 2011 in asprox,exploit,MoneyMule,New Domains,RBN,rogue antivirus by dglosser

168 new domains associated with BH Exploit, fake job offers,moneymule, rbn and more. Sources include doc.emergingthreats.net, amada.abuse.ch, ddanchev.blogspot.com, securehomenetworks.blogspot.com (Every source is  listed in the domains.txt file).


Please help to keep this site free and donate whatever you can:  All donations go to hosting and infrastructure costs.

These malware block lists provided here are for free for noncommercial use as part of the fight against malware.   Any use of this list commercially is strictly prohibited without prior approval.

Yearly sponsorships are available. Full acknowledgment, an icon, and link back to your site will be placed in the left sidebar.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.

Please download files from main mirror: http://mirror1.malwaredomains.com/files/

BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, SANs, and others…

163 New Domains: Trojans, Rogue Antivirus, Zeus, PDF Exploits

Posted on June 25th, 2011 in exploit,New Domains,rogue antivirus,zeus by dglosser

163 new domains associated with fake security programs, trojans and exploits.  Sources include www.emergingthreats.net, vxvault.siri-urz.net, blog.fireeye.com and others (Every source is  listed in the domains.txt file).

We are thinking about not listing the sites individually here as users are reposting the lists to Web of Trust and other sites but not removing their comments once the site is delisted here.  Unfortunately, these other sites keep the negative reputation due to a listing here long after they’ve been removed on this site.  (Please let us know if you find the individual site listings on this blog page useful. )

June 21 Update

Posted on June 22nd, 2011 in exploit,MoneyMule,RBN,rogue antivirus,Trojans,zeus by dglosser

Added 328 domains (too many to list individually) associated with exploits, moneymule scams, rogue security, scams and other badness. Sources include www.tristatelogic.com, www.spamhaus.org, www.scamfraudalert.com and others.

Malvertising, rbn, rogue, sql injection domains

Posted on June 17th, 2011 in exploit,New Domains,RBN,rogue antivirus,sql injection,Trojans,zeus by dglosser

Added over 200 domains associated with malvertising, Rogue/fake security, sql injection, etc. Sources include blog.dynamoo.com, community.websense.com, research.zscaler.com (Every source is  listed in the domains.txt file):

azetuair .cc 77-platform .net
baooe0 .com badodybeqyk .com
baooe1 .com bestbanners1 .in
baooe2 .com bestbanners2 .in
bazagg .cz .cc bestbanners3 .in
bedioger .com bestbanners4 .in
bhbdzmjy .co .tv bestbanners5 .in
bookaros .com bestbanners6 .in
bookarra .com bestbanners7 .in
bookdolo .com bestbanners8 .in
bookfula .com bestbanners9 .in
bookgusa .com bocikivihepiqa .com
bookmonn .com bunizywytyg .com
bookmono .com clanthefallen .com
bookmylo .com creditsofast .com
bookpolo .com dead-melpomene .com
booksgou .com ecxajgff .co .tv
booksoco .com eddddbzm .co .tv
bookvivi .com enukunaziha .com
bookvoxy .com eqezifebawe .com
bookzoul .com farelfusion .com
bookzula .com fkejoten .co .tv
bqhfvvdn .co .tv gb-offerlist .com
c8s2 .com greenhopengo .com
cbneehtm .co .tv hamobamaduro .com
ccjayplh .co .tv hepotevena .com
cjr001 .com herovidacege .com
dbonis .com high-webtraffic .com
demivee .in hocxhnrl .co .tv
divinemeb .com hydezerirevy .com
drber0 .com hydyfiliduzun .com
drber1 .com ibyfolyzijym .com
drber2 .com itzqmiip .co .tv
drber3 .com jawynuvejeqini .com
drber4 .com jazafibyho .com
drber5 .com jiqixylexut .com
drber6 .com jujbytqe .co .tv
drber7 .com jyviziwopakisy .com
drber8 .com keepitunreal .in
drber9 .com kolifixewitiq .com
dzedshuw .co .tv kovejyvymuzi .com
efidaxamo .com lajogitytudaxo .com
erdvjn1 .com linuxbanners1 .in
erdvjn2 .com linuxbanners4 .in
erdvjn6 .com linuxbanners5 .in
erdvjn8 .com linuxbanners6 .in
erdvjn9 .com linuxbanners7 .in
erlvn0 .com lucuhojivinu .com
erlvn1 .com mediabulker .com
erlvn2 .com mehyqibugyluf .com
erlvn3 .com mentorcentral .com
erlvn4 .com mentorcentral .net
erlvn5 .com milotynabojavo .com
erlvn6 .com mipituhamys .com
erlvn7 .com misyneqewetypo .com
erlvn8 .com msor72-gate1 .vv .cc
erlvn9 .com mzpupkqo .co .tv
f10 .xl .cx neddhilr .co .tv
f8d3 .net okvmodps .co .tv
findclear .org orrick-media .eu
findstiff .org pacugegyfeheka .com
h94 .org pboysxaj .co .tv
hurdana .cx .cc pijynazerud .com
lawujocot .com pivysegocide .com
legse .co .cc premium-support-2011 .com
macbanners .in premiumsupport2011 .com
mediawork .com qbzaqmse .co .tv
nopirekuz .com rblvsbht .co .tv
paybal .com rowxhoai .co .tv
q9z4 .com rvcxwsmt .co .tv
qubmoviez .com sbzjrszn .co .tv
rappour .in scoregaskets .com
replity .in searchcruel .org
ripplig .in searchgrubby .org
s9w3 .com smartsecuritybox .com
s9w3 .net sositawidapezi .com
sgsge0 .com sweetnovelty .com
sgsge2 .com tesonugixamys .com
sgsge3 .com testosploitron .cx .cc
sgsge4 .com thingortwo .com
sgsge5 .com tikytudububy .com
sgsge6 .com traffic-dc .com
sgsge7 .com trjmytqlnhyovlpv .com
sgsge8 .com vakatesumuhor .com
sgsge9 .com vusysogirebymy .com
sharkpork .com vuvamewakoq .com
smrbr0 .com vyzaraputifyb .com
smrbr3 .com wamikopyzoqah .com
smrbr8 .com wekabamysugamy .com
smrbr9 .com windowsbanners .in
t9i2 .org wkrfgzoc .co .tv
t9i3 .com wkydwlkk .co .tv
t9i3 .org xazofeberus .com
tuartma .in xfrfrwjd .co .tv
uev1 .co .cc xipagymofi .com
uralgaz .ru xisebozenaj .com
uxuvoxogy .com xnnblhid .co .tv
videoskk .org zarqqasx .co .tv
y8r5 .com zhkeinzr .co .tv
yjybocore .com zonsolemonito .com
zapppo1 .org zzxfyrru .co .tv
zyfovubyv .com

Please help to keep this site free and donate whatever you can:  All donations go to hosting and infrastructure costs.

This malware block lists provided here are for free for noncommercial use as part of the fight against malware.   Any use of this list commercially is strictly prohibited without prior approval.

Yearly sponsorships are available. Full acknowledgment, an icon, and link back to your site will be placed in the left sidebar.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.

Please download files from main mirror: http://mirror1.malwaredomains.com/files/

BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, SANs, and others…

Botnet Domains, Black Hole Exploit-Kit Domains

Posted on June 14th, 2011 in exploit,iframes,New Domains,rogue antivirus,Spyeye,Trojans,zeus by dglosser

246 Domains associated with Zeus, iframes, bots, black-hole exploit and other maliciousness. Sources include safebrowsing.google.com, securehomenetworks.blogspot.com, sucuri.net. (Every source is  listed in the domains.txt file):

ajansrena .ce .ms width=”130″ bestxmobiez13 .cz .cc
anayaghma .cz .cc checker-only-safe .co .cc
bestbanners1 .com flashsecuritycenter .in
bigryans .ce .ms freeportindustries .ca
boneraffyaho .cz .cc makemoneywith-followers .com
borrowme .bij .pl managev2 .dynamicdashboard .com
bravepath3 .com media-downloadcenter .com
buyordie .osa .pl media .mp3downloadhq .com
cmakdohaio93 .in medianewdownload .com
e-faw .cz .cc member .mp3downloadhq .com
fermadeals .ce .ms members-area-ab .com
filneso .com members-area-ac .com
finelimeol .com members-area-as .com
firmasteu .com members-area-at .com
firmculips .com members-area-av .com
fishrasil .com members-area-ax .com
fixfiper .com members-area-bl .com
fizzyoime .com members-area-bu .com
flaskoof .com members-area-ca .com
flasowel .com members-area-cd .com
flus8ush .com members-area-ct .com
forozperu .com members-area-dc .com
fowtorun .com members-area-di .com
foxnegory .com members-area-do .com
framebro .com members-area-dr .com
fuvolsia .com members-area-dt .com
fuzoleup .com members-area-dv .com
gabingtag .com members-area-ec .com
gavutalk .com members-area-ef .com
geispovs .com members-area-eg .com
geocanow .com members-area-eoj .com
gifmaoers .com members-area-fd .com
giftrabcu .com members-area-fr .com
givigbacc .com members-area-fw .com
glormoafe .com members-area-gf .com
goamporee .com members-area-gg .com
goatexols .com members-area-gl .com
gocratuk .com members-area-gm .com
godeloer .com members-area-gs .com
goeinrike .com members-area-hw .com
gokocnie .com members-area-hy .com
goldeanoc .com members-area-ip .com
golenomu .com members-area-kw .com
gompogasu .com members-area-mm .com
goodatbany .com members-area-movies .com
greleklon .com members-area-mp .com
greloinna .com members-area-ms .com
groutolly .com members-area-music .com
guilarkear .com members-area-nc .com
halatylobe .com members-area-oj .com
hatfermily .com members-area-online .ru
havecone .com members-area-pd .com
heloacdores .com members-area-pe .com
helonorms .com members-area-pf .com
helvhan .com members-area-pl .com
hermanotaw .com members-area-po .com
heshareto .com members-area-re .com
hickocwins .com members-area-rg .com
hjyu .50megs .com members-area-rp .com
indometastan .in members-area-sa .com
ismailcetisli .com members-area-sc .com
jabberva .cn members-area-seo .com
jsbanners3 .com members-area-sl .com
keywordelites .info members-area-sp .com
kiraporntube .com members-area-ss .com
lavanda .345 .pl members-area-st .com
livetvreview .com members-area-ta .com
liveufc126 .com members-area-tv .com
ll-ccc .cz .cc members-area-tw .com
mcanavib .cn members-area-vi .com
medicare-forms .org members-area-vp .com
membersareaabt .com members-area-ws .com
membersareaant .com members-area-yi .com
membersareaanx .com members-site-online .com
membersareaasp .com members-stream-music .com
membersareaavr .com members-tv .freedownloadzone .com
membersareabkd .com members .freedownloadzone .com
membersareabur .com members2 .freedownloadzone .com
membersareacdt .com membersarea-allinone .com
membersareadie .com membersarea-bookdownloads .com
membersareaear .com membersarea-epa .com
membersareaeba .com membersarea-pennyauctions .com
membersareafed .com membersarea-xpa .com
membersareafit .com membersareaantivirus .com
membersareafla .com membersarealogin .com
membersareagam .com membersareamovie .com
membersareagms .com membersareamusic .com
membersareahwr .com membersareasof .com
membersareaipd .com membersareaspo .com
membersareamed .com membersareasst .com
membersareamob .com membersareatvt .com
membersareamov .com membersareatwi .com
membersareamus .com membersareavir .com
membersareaoof .com membersareawdo .com
membersareapdo .com membersareazpl .com
membersareapet .com memberssitelogin .com
membersareappl .com memberszh .freedownloadzone .ph
membersareapss .com messenger-download-2010 .com
membersareapsx .com messenger-downloads .com
membersareask .com messenger-free-download .com
membersareasky .com music-tunesdownload .com
messenger-new .com musicdownload-site .com
midgiluo .com musicdownloadreview .info
modiesto .com musicmembersarea .com
musique-2010 .com my-mediacenter .com
musique-2011 .com mydownloadings .com
mvamelov .cn net-gamedownloading .com
my-stream-tv .com net-moviedownloads .net
my-streampass .com netmoviedownloads .com
new-burner .com netmovies-download .com
new-install .com new-2010-download .com
new-pdf-2011 .com new-2010-pdf-download .com
new-pdf9 .com new-2011-online-version .com
new-recorder .com new-antivirus-version .com
new-tv-to-pc .com new-earth-locations .com
new-voice-ip .com new-gamingexperience .com
news-cmps .cz .cc new-hd-movies-online .com
noyeenf .cz .cc new-instant-download .com
nw-cpm .cz .cc new-internettelevision .com
peoria33884 .cz .cc new-music-online .com
puqwjax .cz .cc new-online-version .com
ringostart .osa .pl new-pdf-online-download .com
seaarch .info new-pdf-reader .com
senzsetive .cz .cc new-tv-online-access .com
shalisally .ce .ms new-tv-online-access .net
stats-co .cz .cc new-version-online .com
stillalives .ce .ms new-voip-2010-download .com
ticetegas .com new-voip-2011-download .com
todgekaw .com new-voip-access .com
versepurze .com new-voip-instant-access .com
warwork .info new-voip-latest-download .com
wdjpq .ne new-voip-online-access .com
we-faw .cz .cc new-web-download .com
wertlist .com newantivirusdownload .com
winupdatecentr .in stceltensarg .ce .ms
wrewa .ifrance .com varealestateblog .com

Please help to keep this site free and donate whatever you can:  All donations go to hosting and infrastructure costs.

This malware block lists provided here are for free for noncommercial use as part of the fight against malware.   Any use of this list commercially is strictly prohibited without prior approval.

Yearly sponsorships are available. Full acknowledgment, an icon, and link back to your site will be placed in the left sidebar.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.

Please download files from main mirror: http://mirror1.malwaredomains.com/files/

BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, SANs, and others…

More Rogue Security, Zeus, Spyeye, RBN Domains

Posted on June 11th, 2011 in exploit,MoneyMule,New Domains,RBN,rogue antivirus,Spyeye,Trojans,zeus by dglosser

210 SpyEye, RBN,  Zeus, TDSS, bot, exploit domains. Original sources include doc.emergingthreats.net, www.malwaredomainlist.com, www.threatexpert.com (Every source is  listed in the domains.txt file):

0c7k29 .co .cc 8c1b65893ccba911b4d0aa593a8a926f .vplaylink .info
active-scan .com al1-xscript0s .com
askredpoleq .com alfacleanwin .com
b4lry1 .co .cc alghazitractors .com
bestaudia7 .com assbrotherhood .ru
bmetalvs .com bharathiyagurukulam .com
bnavs .com boards .soapcentral .com
bnavsgroup .com buqajoqunely .com
bnavsonline .com cigivasepuxy .com
bnavsxp .com cizubejiwoma .com
bo8l1a .co .cc cleanscanpro .com
ccjava-l0ad .com coldhardcash4us .com
cibabewytyl .com complete-art-group-ltd .com
ciquqamod .com complete-art-uk .net
cknovt .com condor-llc-uk .net
cleartraf .ru condorllc-uk .com
clnovt .com crackrapidshare .net
crackshare .net crackserialkeys .net
cwnovt .com damskezimnibundy .cz
de-kadegroup .cc defender-sdvup .in
defender-tmp .in fapyrypumumuva .com
depotex .com fitevejetety .com
derlsplay .com fosimoxexora .com
dirnaster .com fuhocogupyneko .com
diverthigh .com gexopetoqoco .com
docrealtor .com ghavspacquiao .com
docweds .com google-analitycs .cz .cc
evelismag .info hermes .divinusdeus .net
ewa .kz huzatifizama .com
fabviolu .com hyviwysoqizege .com
fajomowiqy .com ideaidiosyncratic .info
famopaips .com isoftwaretvdownloads .com
fephgobd .com isoftwaretvstations .com
ffickibo .com itunesdownloadstore .com
figumsin .com jexelabexomeco .com
filmome .com jukebox-download-new .com
fugalike .com jukebox-new-download .com
fullkeygen .net juxukupyzemi .com
fuqikabyko .com jynogobefukor .com
gestaded .com kiqevinarelo .com
ghavs .com lejicolyxudy .com
ghavsgroup .com lugecunecaxez .com
ghavsinc .com moxopurarite .com
ghavsonline .com mupesatupukyqi .com
ghavsxp .com net-jaghori .webphoto .ir
h4g5kjhbk3h .com newflash1news .com
howtotws .cz .cc newflash2news .com
iproshare .vv .cc newflash3news .com
itraf .in newflash4news .com
jagbibiv .cn newflash5news .com
joyawpan .com newflash6news .com
juqesumycuz .com newflash7news .com
karbrrbrr .co .cc newflash8news .com
khumemit .cn newflash9news .com
krasava .cz .cc newplayer-downloads .com
lakersavsxp .com newsatellite-tv-forpc .com
lakersnavs .com notimexonline .com
lecuvubaja .com official-2010-version .com
mao .kz official-antivirus .com
marquee8 .co .cc official-online-download .com
mazafaka .w2c .ru official-pdf-2010 .com
mijokoquvon .com official-pdf-download .com
musclescan .com official-pdf-pro .com
mybnavs .com official-pdf2010 .com
myghavs .com official-pdfdownload .com
newbnavs .com official-version-2011 .com
newghavs .com officialbirthcertificates .org
newpdf9 .com officialbirthforms .org
noo .kz officialgreencard .org
nurulicovy .com officialimmigration .org
ohbl .in officialmarriagerecords .org
opera24 .ru officialpdf-2010 .com
overtn .com pacquiaoavs .com
patchcrack .net philippine-embassy .ir
pavahikexu .com piwetyzififa .com
picvance .com pobazepukatyc .com
pyduhomyc .com qibahovybicu .com
q27vqa .co .cc quakearena32 .ru
q714 .co .cc repavukoqipez .com
quickbroom .com rodmi4e .dlinkddns .com
qupasebyve .com ropeqeginora .com
realtraf .ru rs-323-service .ru
s106 .cz .cc ru .coolnuff .com
sisawylum .com rukizypufygejy .com
slmaat .com ryqytobogociw .com
solaraterm .com shadowoperations .co .cc
synduk .ru skyline-antique .com
tarakan2011 .ru skyline-ltd .net
thebnavs .com socawycerumyxi .com
theghavs .com spider-se0rch .com
ultimawin .com squadroshield .co .cc
vanhold .com tedowyhubal .com
vgsinfo .com tesipohycuco .com
vinuko .de thesurfrack .com
w2c .ru topnglchecker .co .be
wap-files .mobi united-trans .org
warez4me .ru vudehebaviwod .com
warez72 .ru vuvodiguqewuxe .com
warez75 .ru wacumohuqos .com
webfrogs .ru wascosafaries .com
woxoqehed .com wepomagidysaky .com
yamarsian .in xedycekycimohu .com
zaqewoqake .com ya-toptal-tvoyu-dushu .com
zdravnadzor .ru zagohitapuzog .com
zlen .ru zearch-lntr0duct10n .com

Please help to keep this site free and donate whatever you can:  All donations go to hosting and infrastructure costs.

This malware block lists provided here are for free for noncommercial use as part of the fight against malware.   Any use of this list commercially is strictly prohibited without prior approval.

Yearly sponsorships are available. Full acknowledgment, an icon, and link back to your site will be placed in the left sidebar.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.

Please download files from main mirror: http://mirror1.malwaredomains.com/files/

BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, SANs, and others…