Feed

The Suspicious Domains List at SANS

Posted on April 18th, 2012 in Domain News by dglosser

After some maintenance downtime, the Suspicious Domains lists at https://isc.sans.edu/tools/suspicious_domains.html have been re-launched. This project was developed by handler Jason Lam and is an effort to assemble weighted lists of suspicious domains based on tracking, malware and other sources

.

 

 

List revalidation: 1700+ domains removed

Posted on April 3rd, 2012 in Domain News,Removed Domains by dglosser

We just reevaluated 1824 domains… 1720 were removed,  79 were STILL actively blacklisted by google after many months and were added our  “immortal” list.

List of removed domains is: http://mirror2.malwaredomains.com/files/removed-domains-20120402.txt

List of “immortal” malware domains:  http://mirror2.malwaredomains.com/files/immortal_domains.txt

 

 

List Recertification: Over 1300 Domains Removed

Posted on February 25th, 2012 in Domain News,Removed Domains by dglosser

Over 1300 domains have been delisted.   Please update your blocklists

Reminders:

  • the main site does not contain any zone files. Please download files from one our our download mirrors
  • Pull ONLY the file you need – there is no need to pull every zone file!  Abusers will be banned!
  • Anyone pulling files more than every 12 hours will be banned!
  • We also have a mirror dedicated to research and Open Source Projects – contact us for details.
  • Please use the “datestamp” and “timestamp” file to determine if the list has been updated and ONLY pull the files you need – abusers will be banned! Use the “wget -N”!

Mirror is Back Online (also new mirror)

Posted on February 15th, 2012 in Domain News by dglosser

mirror2.malwaredomains.com is back up – direct access to the zone files is working but things like displaying directory indices is a work-in-progress.

We are also testing another mirror  –  compressed full zone files only  –  located at  http://www.malware-domains.com/ (note the dash)

Please give it a try and let us know…

 

 

mirror2.malwaredomains.com temporarily down

Posted on February 14th, 2012 in Domain News by dglosser

mirror2.malwaredmains.com is temporarily down; we will update you once it is back up.  In the meantime, please use one of the other mirrors or contact us for details regarding the mirror handling only compressed files.

 

Guy Bruneau’s DNS Sinkhole Script – Fixes & Updates

Posted on January 21st, 2012 in Domain News by dglosser

Guy has updated his DNS Sinkhole Scripts. More info here.  Also check out his DNS Sinkhole ISO.

Immortal Malware Domains

Posted on January 4th, 2012 in Domain News,immortal,Removed Domains by dglosser

We recently revalidated about 800 long-lived, “immortal” malware domains.

These are domains which were identified as malicious anywhere between 90 and 360 days ago. but according to google safebrowsing, are still actively involved in badness.
Some of these domains have been on the DNS-BH List for YEARS.

Of these 800 domains,  55 were removed. That means that 745, or over 93%, are still actively associated with malware.

List of removed (non immortal?) domains:  removed-domains-20120104.txt

List of “the immortals: immortal_domains.txt

A “psychohistory” of these long-lived malicious domains would be interesting and we’d be happy to help with any of those research efforts.

745 still “immortal”
55 removed

Domain download abuse

Posted on January 1st, 2012 in Domain News by dglosser

We just checked some server statistics… Started fresh for 2012…  How is it possible for 17.51 MB of files to be downloaded in 2012 and the day isn’t over yet???

Unfortunately, we are forced to continue to ban IP addresses which for whatever reason continue to abuse our download servers.

Hosting costs money. Please contribute whatever you can.

DNS Blackhole with iRules

Posted on December 31st, 2011 in Domain News by dglosser

Interesting article about integrating Blackhole DNS with F5 irules.

Free Domain Name Registrars

Posted on December 28th, 2011 in Domain News by dglosser

The Internet Storm Center recommends blocking the following domains in this post:

  • .nl.ai
  • .c0m.li
  • .cd.am
  • .coom.in

We want to make you aware that we have the following lists:

The domains listed in each of these files are NOT included in the DNS-BH Blocklists.

It’s up to you if you wish to block, track, or allow access to these domains.