Feed

128 new zeus, rogue, exploit domains

Posted on June 22nd, 2010 in exploit,New Domains,rogue antivirus,zeus by dglosser

128 new domains associated with exploits, zeus, rogue and other maliciousness:

vsmd .kz wanko-manma .com
chto .su searchrinup .org
psdrv .ru caer-doofer .com
ewet .org breefingteam .com
xe54 .com lineage .cn .km .ua
kqmxd .cn dijitalkalip .com
07168 .net moviecoupons .com
world .com am-remorquage .fr
ads .co .in domain460008 .com
rctds .net eu-analytics .com
teafun .sk grigga-sinna .com
balem .net homes-belair .com
necice .in ligawebradio .com
alsons .ru mediasuperbe .com
traskl .ru phimhanquoc .info
finson .com secure-stats .org
galaay .com solidarregion .at
shgics .com space-fblogs .com
blogjo .biz sicha-linna8 .com
equiny .com doctornimnul .com
hermes1 .nl update-kabul .com
kdsa .or .kr cashmaker-mom .com
popcorn .ma makesfasesite .com
uoptyr .com 30th-birthday .com
adwa23 .com megaantispy80 .com
bcbcnc .com romeunplugged .com
ceterz .com sorqusuzrapci .com
hsaaba .com getnewfreeporn .in
mog4jr .net grandeducation .ru
crewbiz .net wtcfirstmovie .com
hosanmt .net fleur-de-sante .ru
qsponik .com martinandwood .com
huashna .com 2012babah2012 .com
speedpos .com googie-update .com
bogobogo .net nelmafirstusa .com
spacecake .se panmiamibeach .com
vmcogulf .com sonyproduction .in
malbobro .org emailtheplanet .com
sex-gifts .ru adobesoftech .co .tv
voidrage .com microtrendsa .co .cc
z0mb13 .do .am solaruploaderz .com
tyhomkol .com miror-counters .org
annintus .com hikmesanbukais .com
bits4ever .ru netsharingsite .com
s-yahoo .info kindservicezeb .net
wandianji .com thegalleriesxxx .com
scanbase4 .com medianservicebz .net
arpeggi0s .com webmizersystems .com
ootaivilei .ru portland-traffic .com
fileland .co .kr breakingnewsofmom .com
bgknoccout .com inmobiliariapymsa .com
kalekehert .net explorer-download .net
msn-fblogs .com microsoft-update .name
pamparampa .net joylol .awardspace .info
saveoursoul .es atechnologyscanner .com
down .unovt .com chicken09 .thruhere .net
volgo-marun .cn sidematch .linkprice .com
3pulenepro .net cashmakermomsecrets .com
xvaluegate .com makemoneyathome-site .com
dfgswfodoxk .com startprotectyoutoday .com
diarqdndoxk .com mastersurpreenda0 .t35 .com
imagehacks .info momismakingcashathome .com
newdaypeace .org sosyalguvenlikmerkezi .org
senders2010 .com lib .willyselectronics .com

This malware block lists here are provided for free for noncommercial use as part of the fight against malware.

Please help to keep this site free and donate whatever you can. All donations go to hosting and infrastructure costs.

Also, yearly sponsorships are available. Full acknowledgment, an icon, and link back to your site will be placed in the left sidebar.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.
Updates are located at http://www.malwaredomains.com/updates or one of the mirrors

The full files are located at: http://www.malwaredomains.com/files or one of the mirrors
Primary Mirror: http://mirror1.malwaredomains.com/files
BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, and others…

Urgent block: volgo-marun .cn & sicha-linna8 .com

Posted on June 22nd, 2010 in New Domains by dglosser

From cyberinsecure.com:

The support site of leading Chinese PC manufacturer Lenovo has been compromised by unknown attackers who injected a rogue IFrame into the pages over the weekend. Security researchers warn that unwary visitors looking for drivers are exposed to several exploits that install the Bredolab trojan onto their computers.

The IFrame points to an exploit kit hosted on a domain called volgo-marun.  cn. After performing several checks to determine what vulnerable software they had installed on their computer, the visitors were served with exploits targeting older versions of Internet Explorer, Adobe Reader or Adobe Flash player. ….  and receives commands from C&C server with domain sicha-linna8 .com