Thursday, May 01, 2008

Fresh rogue and fake codec sites

In case you didn't catch these earlier at another site, here are some new domains floating around out there doing bad things.

In some cases, binaries can be captured by using the following example format:

roguesite.com/files/get.php?id=538090733

CreatedIPSite
4/29/200885.255.120.110flwplayer. com
4/29/200885.255.118.214protectalerts. com
4/29/200885.255.118.34toolbarusage. com
4/29/200885.255.116.211safehomesite. com
4/29/2008216.255.179.243getnewfiles. com
4/29/2008216.255.179.243asearchflame. com
4/29/2008216.255.179.243asearchpool. com
4/29/2008216.255.179.243asearchreview. com
4/29/2008216.255.179.243explorertool. net
4/29/2008216.255.179.243gateietool. com
4/29/2008216.255.179.243gatetofind. com
4/29/2008216.255.179.243homepagerestart. com
4/29/2008216.255.179.243ieservicegate. com
4/29/2008216.255.179.243iqsearches. com
4/29/2008216.255.179.243linkietool. com
4/29/2008216.255.179.243newuploads. net
4/29/2008216.255.179.243renewfiles. com
4/29/2008216.255.179.243searchinggate. com
4/29/2008216.255.179.243searchthruweb. com
4/29/2008216.255.179.243shareownfiles. com
4/29/2008216.255.179.243trysearchhere. com
4/29/200885.255.118.245dns404rule. com
4/29/200885.255.118.212secureprior. com

Patrick Jordan
Sunbelt Malware Research