Big Update: lizamoon, driveby, rogue domains

Posted on April 5th, 2011 in MoneyMule,New Domains,rogue antivirus,sql injection,Trojans,zeus by dglosser

Over 200 domains associated with zeus, lizamoon, drive-by exploits, moneymule, and  fake  security pages.  Sources include securehomenetworks.blogspot.com, ddanchev.blogspot.com, urlvoid.com (Every source is   listed in the domains.txt file):

advabnr .com afraid .orgmooo .com
ave-stats .info alternative-art-uk .co
axx1 .co .cc antivirus-2525 .co .cc
axx2 .co .cc antivirus-2932 .co .cc
azx3 .co .cc antivirus-3654 .co .cc
b949 .co .cc antivirus-713 .co .cc
bhaaa .co .cc antivirus-728 .co .cc
bhccc .co .cc antivirus-7357 .co .cc
bl0d .co .cc antivirus-8072 .co .cc
bl1f .co .cc antivirus-9638 .co .cc
bl4j .co .cc antivirus-9667 .co .cc
bl5d .co .cc autosportitalia .it
blcr .co .cc b5b15f58b4680803016eb17881f3e929 .info
blg9 .co .cc books-loader .info
blh8 .co .cc borinquensalsa .com
blh9 .co .cc casinovergelijker .com
blks .co .cc casualhopperois .com
blm9 .co .cc chelpgroup-llc .net
blnh .co .cc chepl-groupllc .biz
blnm .co .cc comdefender-abcc .in
blpk .co .cc comdefender-drnr .in
blqh .co .cc comdefender-evvj .in
blqm .co .cc comdefender-mpdfa .in
blsr .co .cc comdefender-nibea .in
blt8 .co .cc comdefender-rlob .in
bltq .co .cc comdefender-sxin .in
bluenosa .info comdefender-tpda .in
blzq .co .cc comdefender-uvag .in
ciaojfncvmt .com comdefender-wbui .in
colicie .info comdefender-xkox .in
comcmdrun .com comdefender-xqba .in
defender-aabv .in cossmar-goiano .asia
defender-abcc .in dc7e7c1a018708f .co .cc
defender-atio .in defender-aqeu .co .cc
defender-atxo .in defender-asng .co .cc
defender-fmof .in defender-eyde .co .cc
defender-gnva .in defender-fola .co .cc
defender-grlt .in globalpoweringgathering .com
defender-hipw .in google-stats47 .info
defender-hjlk .in google-stats54 .info
euy0 .co .cc google-stats73 .info
excluti .com hslfntooyyhumnp .biz
extra-911 .info ifczlmkjocnrkrvx .org
fewge .com infectedvirusxpsoft .com
frq3 .co .cc netruebtshb .co .cc
groatcoats .com netryevsirs .co .cc
gvppjnjv .net .in netrzysktlz .co .cc
image4msn .com netshwptknk .co .cc
incmt .com netskfzoygu .co .cc
kvpa .co .cc netsoftware-brvr .co .cc
mol-stats .info netsoftware-nerx .co .cc
ocservice-de .net netsoftware-q9k9 .co .cc
oregonltd-uk .cc netsoftware-sulv .co .cc
otmtg .com netsoftware-verh .co .cc
people-on .info netsoftware-werp .co .cc
planixcentral .in netspuqpphk .co .cc
ponel .biz netsqaezjdt .co .cc
prvenus-de .com netsqanvtkw .co .cc
purelandfilms .in netstpbbyzq .co .cc
qabplzoqthr .com netsuiqkpju .co .cc
rosabet .net netsystem-scanner-boep .co .cc
s0lk .co .cc netsystem-scanner-ekoi .co .cc
sabplgosvmt .com netzztoeauc .co .cc
slp1 .co .cc opytibuxi .virtue .nu
squit-llc .co oregon-ltd-uk .net
sru5 .co .cc pefpovhvstmjlmqe .biz
sru6 .co .cc pjpgvvwdmolouo .net
star-stats .info powernhgmdftkcleaner .myfw .us
suvitt .com ppeijrmuqlivgp .biz
tadygus .com pupplwpengstuf .net
talkwire .in pxpozrkjzrvtegn .biz
tea .com .pl rmtzqkuplsikots .biz
topazgmbh-de .com security-stats .info
w7-guardav .biz software-c9vv .co .cc
w7-guardav .com software-k9le .co .cc
w7-guardav .net software-z5qy .co .cc
w7guard-av .biz system-scanner-oypx .co .cc
w7guard-av .com system-scanner-qeap .co .cc
w7guard-av .net system-scanner-racv .co .cc
winadefender .biz system-scanner-ryes .co .cc
winwdefender .net system-scanner-tzii .co .cc
wsatfdwxzj .co .cc system-scanner-uemo .co .cc
wsbzaenrvm .co .cc system-scanner-uotu .co .cc
wscnfogqog .co .cc system-scanner-uyxt .co .cc
wsexirzexl .co .cc system-scanner-vpoo .co .cc
wsfmvdvera .co .cc system-stats .info
wsgskwbmhc .co .cc theantivirusxpsoft .com
wshxmhyqqq .co .cc thexpscanantivirus .com
wsirdbrvai .co .cc urllizamoon–com .rtrk .co .uk
wsjfvogzds .co .cc welcometotheglobalisnet .com
wsjjxjbfdj .co .cc world-stats598 .info
wsjknryvyw .co .cc wsantivirus-1517 .co .cc
wsjlhpadsv .co .cc wsdefender-nbev .co .cc
wslasmtlcv .co .cc wsdefender-ttii .co .cc
wslqrizgzk .co .cc wsdefender-ysyj .co .cc
wsobqiahme .co .cc wsmovies-tube-ylld .co .cc
wspwkwgaxl .co .cc wssoftway2011 .com
wsqjrralfl .co .cc wssystem-scanner-amoa .co .cc
wsqmrqlevl .co .cc wsxcacoqzt .co .cc
wsrpqsmunp .co .cc wsxkluycay .co .cc
wssgebxond .co .cc wsxnsxguyl .co .cc
wssgifitlp .co .cc wsxvwrktxa .co .cc
wssrjklbtq .co .cc wsysitfpiq .co .cc
wsubjsgtbr .co .cc wszthrboqe .co .cc
wsuconokjj .co .cc

This malware block lists provided here are for free for noncommercial use as part of the fight against malware. Any use of this list commercially is strictly prohibited without prior approval.

Domains.txt file is the complete list along with original reference.
Justdomains contains list of only the domain names.

Please download files from mirror if possible: http://mirror1.malwaredomains.com/files/

BOOT file is in MS DNS format. spywaredomains.zones file is in BIND format.

Also Available in AdBlock, ISA, and MaraDNS formats.

A trusted source on the WOT-the Web of Trust . Used by SURBL, MOREnet, SANs, and others…