Jump to content

Build Theme!
  • Infected?


Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93112 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Malware Domain Blocklist - archive

  • Please log in to reply
95 replies to this topic

#1 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 10 March 2010 - 08:05 PM


DNS-BH – Malware Domain Blocklist
- http://www.malwaredomains.com/
March 10, 2010 - "250+ Fraud, neosploit, Domains, zeus, exploit domains to block..."

- http://www.malwaredo...ress/?page_id=2
The DNS-BH project creates and maintains a listing of domains that are known to be used to propagate malware and spyware. This project creates the Bind and Windows zone files required to serve fake replies to localhost for any requests to these, thus preventing many spyware installs and reporting.

This list is also available in AdBlock and ISA Format..."

To install the AdblockPlus extension in Firefox, click here:
- https://addons.mozil...efox/addon/1865


Blocking malicious sites with Adblock Plus
- http://adblockplus.o...th-adblock-plus
"... another layer of protection..."
Scroll down to: "... click here to subscribe to the list in Adblock Plus..." and click on the link - click OK to the popup for "Add subscription" - done.

- http://news.cnet.com...466753-245.html
"WhitePages.com has stopped ad networks from delivering ads to its site after they were found to contain fake antivirus malware..."



- http://www.malwaredo...ordpress/?p=880
March 13, 2010 - "151 new domains from www.malwareurl.com, malc0de.com, ddanchev.blogspot.com, safeweb.norton.com and others"



- http://www.malwaredo...ordpress/?p=886
March 17, 2010 - "217 new domains associated with rogue antivirus, fastflux, trojan, iframes, botnets, etc. Souces include secuboxlabs.fr, malwaredomainlist.com, ddanchev.blogspot.com..."



- http://www.malwaredo...ordpress/?p=889
March 20, 2010 - "201 new domains to block. Sources include ddanchev.blogspot.com, blogs.paretologic.com, support.clean-mx.de..."



- http://www.malwaredo...ordpress/?p=892
March 24, 2010 - "160 new domains flagged as drive-by downloads, scareware, zeus, and harmful by malc0de.com, jsunpack.jeek.org, malwareint.blogspot.com and others..."



- http://www.malwaredo...ordpress/?p=896
March 27, 2010 - "173 new domains to add to your shunlist and blocklist… Sources: www.malwareurl.com, malc0de.com, phil-secu.over-blog.net and others.."



Blackhole DNS Update196 new domains
- http://www.malwaredo...ordpress/?p=901
March 30, 2010 - "Sources include securehomenetwork.blogspot.com, zeustracker.abuse.ch, ddanchev.blogspot.com..."



- http://www.malwaredo...ordpress/?p=909
April 5, 2010 - "... 300 new domains have been added. Sources: support.clean-mx.de, www.freepcsecurity.co.uk, www.malwareurl.com, and others..."



- http://www.malwaredo...ordpress/?p=911
April 8, 2010 - "Added 210 koobface domains and 53 other domains associated with malicious activity. Sources: www.malwareurl.com, www.malwaredomainlist.com, secuboxlabs.fr, and others..."



- http://www.malwaredo...ordpress/?p=919
April 11, 2010 - "230 domains to add to your malware blocklist or malware domain sinkhole..."



- http://www.malwaredo...ordpress/?p=924
April 14, 2010 - "261 domains to block or redirect to your sinkhole. Sources include malc0de.com, support.clean-mx.de, and secuboxlabs.fr..."



Big Update: gumblar domains, rbn domains, trojan domains and more
- http://www.malwaredo...ordpress/?p=933
April 16, 2010 - "Over 300 domains associated with the RBN, gumblar, trojans, as well as domains associated with fraud. Sources include defintel.blogspot.com, emergingthreats.net, krebsonsecurity.com..."



MalwareDomains updated - 2010.04.19...
- http://www.malwaredo...ordpress/?p=938
April 19, 2010 - "... quick update, mainly of the domains mentioned earlier...
xfgkddya .cn, yesoc .in, yetanotherguitarsite .com, bitapardaz .net, crystaldesignlab .com, excellentblener .ru, binglbalts .com, corpadsinc .com, fourkingssports .com, mauiexperts .com, mauisportsinsider .com, 4238789324 .com"

Urgent additions
- http://www.malwaredo...ordpress/?p=935
April 18, 2010 - "... the following domains are blocked or blacklisted:
binglbalts . com, corpadsinc .com, fourkingssports .com, networkads .net, mainnetsoll .com
sources: http://ddanchev.blog...compromise.html , http://isc.sans.org/...ml?storyid=8647 ."



Blackhole DNS Update
- http://www.malwaredo...ordpress/?p=940
April 20, 2010 - "Sources: wepawet.cs.ucsb.edu, malc0de.com, jsunpack.jeek.org, ddanchev.blogspot.com and others..."



Many fastflux and rogue domains
- http://www.malwaredo...ordpress/?p=946
April 24, 2010 - "Sources include www.malwareurl.com, www.siteadvisor.com, www.malwaredomainlist.com..."


Edited by AplusWebMaster, 06 March 2012 - 09:56 PM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...


Register to Remove

#2 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 30 April 2010 - 03:15 AM


- http://www.malwaredo...ordpress/?p=948
April 29, 2010 - "rogues, backdoors, exploit domains, and other badness. Sources include www.malwaredomainlist.com, atlas.arbor.net, threatexpert.com..."


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

#3 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 01 May 2010 - 08:00 AM


Fake McAfee DAT 5959: Google SEO hijacking
- http://www.malwaredo...ordpress/?p=950
April 30, 2010 - "please block
* malware-checker-free. com
* tolstiy.co. cc
* endroiturlredirect. com
These sites are involved in google SEO hijacking and host exploits. Sites will be added on the next update.
Source: http://phil-secu.over-blog.net

:ph34r: <_<

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

#4 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 04 May 2010 - 05:41 AM


DNS-BH Update...
... rogue antivirus, zeus...
- http://www.malwaredo...ordpress/?p=952
May 3, 2010 - "Sources: secuboxlabs.fr, safeweb.norton.com. www.malwaredomainlist.com, and others..."


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

#5 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 05 May 2010 - 01:09 PM


Important additions...
- http://www.malwaredo...ordpress/?p=955
May 5, 2010 - "...Please block the following ASAP:
thejustb. com
grepad. com
ginopost. com

- http://blog.scansafe...iche-sites.html

- http://isc.sans.org/...ml?storyid=8740

- http://ddanchev.blog...-linked-to.html ..."

- http://google.com/sa...e=thejustb.com/
"... suspicious content was found on this site... on 2010-05-04. Malicious software includes 1 exploit(s)..." - Country: UA
- http://google.com/sa...e=ginopost.com/
"... suspicious content was found on this site... on 2010-04-26. Malicious software includes 6 exploit(s), 5 trojan(s)..." - Country: UA
- http://google.com/sa...ite=grepad.com/
"... suspicious content was found on this site.... on 2010-04-28. Malicious software includes 15 exploit(s), 9 trojan(s)..." - Country: UA

:ph34r: :ph34r:

Edited by AplusWebMaster, 05 May 2010 - 02:32 PM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

#6 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 06 May 2010 - 07:42 AM


exploit, fastflux, malspam, rogue domains
- http://www.malwaredo...ordpress/?p=959
May 6, 2010 - "159 domains containing malspam, rogue antivirus, trojans, or associated with fraud. Sources include www.malwareurl.com, atlas.arbor.net, hphosts.blogspot.com, ddanchev.blogspot.com..."

:ph34r: :ph34r:

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

#7 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 18 May 2010 - 03:49 AM


exploit, zeus, trojan domains
- http://www.malwaredo...ordpress/?p=970
May 17, 2010 - "Sources include: www.malwaredomainlist.com, secuboxlabs.fr, blog.sucuri.net..."


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

#8 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 20 May 2010 - 04:52 AM


Huge Update: 270 domains
- http://www.malwaredo...ordpress/?p=974
May 19, 2010 - "rogue domains, fastflux domains, exploit domains, and other malicious domains. Sources include www.malwaredomainlist.com, www.malwareurl.com, secuboxlabs.fr, and jsunpack.jeek.org..."


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

#9 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 23 May 2010 - 03:16 PM


Update: koobface,fastflux,zbot,zeus domains
- http://www.malwaredo...ordpress/?p=976
May 23, 2010 - "Over 250 new domains associated with zbot, zeus,torpig,neosploit, koobface and other maliciousness. Sources include ddanchev.blogspot.com, atlas.arbor.net/summary/fastflux, www.malc0de.com, zeustracker.abuse.ch..."

- http://atlas.arbor.n...ummary/fastflux
"... Currently monitoring 226 active fastflux domains..."

- http://www.malwaredo...ordpress/?p=979
May 24, 2010 - "trendsecure.com is incorrectly listed and has been removed. Please remove from your blocklists ASAP."


Edited by AplusWebMaster, 24 May 2010 - 09:05 PM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

#10 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 26 May 2010 - 01:12 PM


Blackhole DNS Update: 138 new domains
- http://www.malwaredo...ordpress/?p=986
May 26, 2010 - "sources: secuboxlabs.fr, www.siteadvisor.com..."


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...


Register to Remove

#11 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 28 May 2010 - 03:37 AM


Urgent addition: v-medical-dot-org/
- http://www.malwaredo...ordpress/?p=990
Posted on May 27th, 2010 in 0day, New Domains by dglosser

Please add v-medical. org ( to your blocklists.
Source: http://isc.sans.org/...ml?storyid=8860
Last Updated: 2010-05-27 18:18:30 UTC


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

#12 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 30 May 2010 - 04:39 AM


- http://www.malwaredo...ordpress/?p=993
May 29, 2010 - "Over 250 new malicious domains associated with zeus, fake security, neosploit, and other trojans and malware. Sources include malwaredomainlist.com, google.com/safebrowsing, blog.dynamoo.com..."


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

#13 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 01 June 2010 - 04:39 PM


List cleanup: 950 domains removed
- http://www.malwaredo...rdpress/?p=1000
June 1, 2010 - "950 older domains have been removed. They are located in the file “removed-domains-20100601.txt” . Please let us know ASAP if any should be placed back on active state."


Edited by AplusWebMaster, 01 June 2010 - 04:39 PM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

#14 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 02 June 2010 - 08:05 PM


Urgent Block: credittreport-dot-info Clickjacking Attacks
- http://www.malwaredo...rdpress/?p=1003
June 2, 2010 - "There has been an outbreak of clickjacking attacks on Facebook’s “Like” plugin. The target domain associated with the hidden iframe is credittreport. info. Please block that domain ASAP. Source:
- http://isc.sans.org/...ml?storyid=8893
Last Updated: 2010-06-02 19:08:01 UTC

:ph34r: :ph34r:

Edited by AplusWebMaster, 02 June 2010 - 08:59 PM.

.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

#15 AplusWebMaster



  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,472 posts
  • Interests:... The never-ending battle for Truth, Justice, and the American way.

Posted 04 June 2010 - 01:14 PM


140 Domains added...
- http://www.malwaredo...rdpress/?p=1007
June 4, 2010 - "140 new domains to shun, redirect, or just block. Sources: dnsbl.abuse.ch, www.malwaregroup.com, malc0de.com, and others..."


.The machine has no brain.
 ......... Use your own.
Browser check for updates here.
YOU need to defend against -all- vulnerabilities.
Hacks only need to find -1- to get in...

Related Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users