<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malc0de</title>
	<atom:link href="http://www.blog.malc0de.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blog.malc0de.com</link>
	<description></description>
	<lastBuildDate>Tue, 23 Mar 2010 01:25:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Malc0de Database Update</title>
		<link>http://www.blog.malc0de.com/2010/03/22/malc0de-database-update/</link>
		<comments>http://www.blog.malc0de.com/2010/03/22/malc0de-database-update/#comments</comments>
		<pubDate>Tue, 23 Mar 2010 01:20:52 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=631</guid>
		<description><![CDATA[Initially malc0de.com was created to link domains that were serving the same executable. What I found out in a very short period of time is the binaries are updated so frequently that this becomes almost impossible. Storing the MD5 is still useful just not as useful as I originally thought. The only purpose malc0de.com is ]]></description>
			<content:encoded><![CDATA[<p>Initially malc0de.com was created to link domains that were serving the same executable. What I found out in a very short period of time is the binaries are updated so frequently that this becomes almost impossible. Storing the MD5 is still useful just not as useful as I originally thought. The only purpose malc0de.com is to store and keep track of domains that host malicious binaries. </p>
<p>I have recently made a few adjustments to the database which should speed up the queries. I have also linked the IP addresses to a good friend of mines newly created website <a href="http://www.malwaregroup.com">www.malwaregroup.com</a>.  Think of it as a robtex for malware domains. </p>
<p>For example <a href="http://malc0de.com/database/index.php?search=acdcwpbathr.com">here</a> we can find a domain hosting the Neosploit exploit pack. The domain is hosted on 75.125.212.58. By searching <a href="http://www.malwaregroup.com/ipaddresses/details/75.125.212.58">malwaregroup.com</a> we can see domains hosted on the same IP that are named in a similar fashion and are most likely also hosting Neosploit or being staged. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2010/03/22/malc0de-database-update/feed/</wfw:commentRss>
		<slash:comments>157</slash:comments>
		</item>
		<item>
		<title>The Command Structure of the Aurora Botnet</title>
		<link>http://www.blog.malc0de.com/2010/03/06/the-command-structure-of-the-aurora-botnet/</link>
		<comments>http://www.blog.malc0de.com/2010/03/06/the-command-structure-of-the-aurora-botnet/#comments</comments>
		<pubDate>Sun, 07 Mar 2010 04:56:16 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=626</guid>
		<description><![CDATA[A detailed write up describing the the command and control structure of the Aurora Botnet was recently released of by a security company called Damballa. The 31 page  PDF which can be found here makes some interesting connections and is definitely worth reading. Damballa’s findings concerning Operation Aurora can be summarized by the following:  ]]></description>
			<content:encoded><![CDATA[<p>A detailed write up describing the the command and control structure of the Aurora Botnet was recently released of by a security company called Damballa. The 31 page  PDF which can be found <a href="http://www.damballa.com/downloads/r_pubs/Aurora_Botnet_Command_Structure.pdf">here</a> makes some interesting connections and is definitely worth reading. </p>
<p>Damballa’s findings concerning Operation Aurora can be summarized by the following:</p>
<p><em>  At the time the attack was first noticed by Google in December 2009, systems within at least 7 countries had already been affected. By the time Google made the public disclosure of the attack on January 12 2010, systems in over 22 countries had been affected and were attempting to contact the CnC servers &#8211; the top five countries being the United States, China, Germany, Taiwan and the United Kingdom.</p>
<p> The Trojan.Hydraq malware, which has been previously identified as the primary malware used by the attackers, is actually a later staging of a series of malware used in the attacks which consisted of at least three different malware ‘families’. Two additional families of malware (and their evolutionary variants) have been identified, and they were deployed using fake antivirus infection messages tricking the victim into installing the malicious botnet agents.</p>
<p> The attacks that eventually targeted Google can be traced back to July 2009, with what appears to be the first testing of the botnet by its criminal operators. The analysis identifies the various CnC testing, deployment, management and shutdown phases of the botnet CnC channels.</p>
<p> The botnets used dozens of domains in diverse Dynamic DNS networks for CnC. Some of the botnets focused on victims outside of Google, suggesting that each set of domains might have been dedicated to a distinct class or vertical of victims.</p>
<p> Some of the CnC domains appear to have been dormant for a period of time after they had infected a number of victim systems. This can occur after the botnet operator has updated the botnet malware with new (more powerful) variants or when the criminal operator sells/trades a segment of the botnet to another criminal operator.</p>
<p> There were network artifacts that suggest that the botnet malware operating with the US-based victims’ networks made use of email services to extract the stolen data from the breached organizations.</p>
<p> There is evidence that there were multiple criminal operators involved, and that the botnet operators were of an amateur level. The botnet has a simple command topology and makes extensive use of Dynamic DNS CnC techniques. The construction of the botnet would be classed as “old-school”, and is rarely used by professional botnet criminal operators today</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2010/03/06/the-command-structure-of-the-aurora-botnet/feed/</wfw:commentRss>
		<slash:comments>670</slash:comments>
		</item>
		<item>
		<title>Past 30 Days of Malicious Activity</title>
		<link>http://www.blog.malc0de.com/2010/02/22/past-30-days-of-malicious-activity/</link>
		<comments>http://www.blog.malc0de.com/2010/02/22/past-30-days-of-malicious-activity/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 00:44:26 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=607</guid>
		<description><![CDATA[The past 30 days of data collected and stored in the malc0de database shows the United States is the top offender when it comes to domains hosting malware. The first graph represents how much malware was collected each day between 01/21/2010 &#8211; 02/21/2010.  We can see a spike around Valentines days which can probably be ]]></description>
			<content:encoded><![CDATA[<p>The past 30 days of data collected and stored in the malc0de database shows the United States is the top offender when it comes to domains hosting malware. The first graph represents how much malware was collected each day between 01/21/2010 &#8211; 02/21/2010.  We can see a spike around Valentines days which can probably be attributed spam/malware taking advantage of the holiday. The dip on the 9th is likely related to something breaking so ignore that.</p>
<p><img class="alignnone" title="Past 30 Days of Activity" src="http://malc0de.com/images/pas30day.jpg" alt="" width="473" height="307" /></p>
<p>I thought it would also be interesting to create a graph based on which countries have hosted the most malware during the previous 30 days. I was a little surprised at the results seeing the United States at the top of the list with China coming in second place.</p>
<p><img class="alignnone" title="Count of MD5s per Country " src="http://malc0de.com/images/md5vscountry.jpg" alt="" width="471" height="306" /></p>
<p>Keep in mind that this data only represents a tiny snapshot in the overall scheme of things and is specific to malware collected by malc0de.com. </p>
<p>Last but not least the list below represents the top ten binaries seen during the past 30 days. </p>
<p>Count &#8211; MD5<br />
251 &#8211; <a href="http://malc0de.com/database/index.php?search=7981f884202bf9f50bb5cb9bf3adbeb1&#038;MD5=on">7981f884202bf9f50bb5cb9bf3adbeb1</a><br />
200 &#8211; <a href="http://malc0de.com/database/index.php?search=105082712e5a14db357fb9432bc9ca22&#038;MD5=on">105082712e5a14db357fb9432bc9ca22</a><br />
198 &#8211; <a href="http://malc0de.com/database/index.php?search=eeda586b324d69ebf6b537724ad122cb&#038;MD5=on">eeda586b324d69ebf6b537724ad122cb</a><br />
178 &#8211; <a href="http://malc0de.com/database/index.php?search=1bf3bbfa188f1b8fd0ffc498be481d53&#038;MD5=on">1bf3bbfa188f1b8fd0ffc498be481d53</a><br />
171 &#8211; <a href="http://malc0de.com/database/index.php?search=eec01f6a39e56ae3efe0a9866ba09b33&#038;MD5=on">eec01f6a39e56ae3efe0a9866ba09b33</a><br />
125 &#8211; <a href="http://malc0de.com/database/index.php?search=9ec690317e2109169c371c81341ec3d3&#038;MD5=on">9ec690317e2109169c371c81341ec3d3</a><br />
82   &#8211; <a href="http://malc0de.com/database/index.php?search=4f4a22a1391fe11be2c9c9b77ded0949&#038;MD5=on">4f4a22a1391fe11be2c9c9b77ded0949</a><br />
75   &#8211; <a href="http://malc0de.com/database/index.php?search=a1e96a96471e08dae17d0b9b6873d726&#038;MD5=on">a1e96a96471e08dae17d0b9b6873d726</a><br />
75   &#8211; <a href="http://malc0de.com/database/index.php?search=a17a76e2f0f8343bbd4c49c9eaef83a3&#038;MD5=on">a17a76e2f0f8343bbd4c49c9eaef83a3</a><br />
67   &#8211; <a href="http://malc0de.com/database/index.php?search=1620ef6bb04e2ca548f3e7951f2a8a6f&#038;MD5=on">1620ef6bb04e2ca548f3e7951f2a8a6f</a></p>
<p>The MD5&#8242;s above are all related to Trojan <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Search.aspx?query=Koobface">Koobface</a>. If you are interested in tracking domains and IP&#8217;s contacted by or distributing Koobface click <a href="http://malc0de.com/database/index.php?search=%2F.sys%2F">here</a> for an updated list. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2010/02/22/past-30-days-of-malicious-activity/feed/</wfw:commentRss>
		<slash:comments>25</slash:comments>
		</item>
		<item>
		<title>Zief.pl And Friends Distribute Trojan Virut</title>
		<link>http://www.blog.malc0de.com/2010/01/31/zief-pl-and-friends-distribute-trojan-virut/</link>
		<comments>http://www.blog.malc0de.com/2010/01/31/zief-pl-and-friends-distribute-trojan-virut/#comments</comments>
		<pubDate>Sun, 31 Jan 2010 15:49:43 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Virut]]></category>
		<category><![CDATA[Zeif.pl]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=600</guid>
		<description><![CDATA[Zief[dot]pl and a handful of other domains hosted on the same IP address (61.235.117.71) are currently attempting to distribute Trojan W32/Virut by using various client side exploits. The Trojan W32/Virut family is particularly nasty and  consists of file infecting viruses that target and infect .EXE and .SCR files accessed on infected systems. Win32/Virut also opens a backdoor by ]]></description>
			<content:encoded><![CDATA[<p>Zief[dot]pl and a handful of other domains hosted on the same IP address (<a href="http://malc0de.com/database/index.php?search=61.235.117.71&amp;IP=on">61.235.117.71</a>) are currently attempting to distribute Trojan <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Search.aspx?query=virut">W32/Virut</a> by using various client side exploits. The Trojan W32/Virut family is particularly nasty and  consists of file infecting viruses that target and infect .EXE and .SCR files accessed on infected systems. Win32/Virut also opens a backdoor by connecting to an IRC server, allowing a remote attacker to download and run files on the infected computer.</p>
<p>Upon execution Win32/Virut will open a connection with one of the IRC servers over a non standard IRC port. This channel is used for communication allowing the attacker to  control the machine or download additional malicious components onto the system.</p>
<p>One example:</p>
<p><em> Server: proxima.ircgalaxy.pl<br />
Port: 65520<br />
Channel: &amp;virtu</em></p>
<p><strong>What happened when Google visited this site?</strong></p>
<blockquote><p>Of the 42 pages we tested on the site over the past 90 days, 0 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2010-01-30, and the last time suspicious content was found on this site was on 2010-01-30.Malicious software includes 738 exploit(s), 416 virus, 320 scripting exploit(s).</p>
<p>This site was hosted on 3 network(s) including <a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=AS:4134">AS4134 (China Telecom backbone)</a>, <a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=AS:9394">AS9394 (CRNET)</a>, <a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?site=AS:38356">AS38356 (TIMENET)</a>.</p></blockquote>
<p>This campaign has been going on for more then 30 days from the same IP address hosted in China (big surprise).</p>
<p>inetnum:      61.235.117.0 &#8211; 61.235.117.255<br />
netname:      CRGdSzS<br />
country:      CN<br />
descr:        China Railcom Guangdong Shenzhen Subbranch<br />
descr:        Telecommunication Company<br />
descr:        Shenzhen City,Guangdong Province</p>
<p>All activity including timeframe, domains, md5s and IP&#8217;s can be found <a href="http://malc0de.com/database/index.php?search=61.235.117.71&amp;IP=on">here</a>.</p>
<p>**Update 02/27/2010**<br />
A more detailed analysis of Trojan Virut can be found <a href="http://securitylabs.websense.com/content/Blogs/3300.aspx">here</a>.  Thanks <a href="http://twitter.com/nicolasbrulez">Nicolas Brulez</a> for bringing this to my attention. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2010/01/31/zief-pl-and-friends-distribute-trojan-virut/feed/</wfw:commentRss>
		<slash:comments>447</slash:comments>
		</item>
		<item>
		<title>Fake UPS spam distributes Trojan Bredolab</title>
		<link>http://www.blog.malc0de.com/2010/01/12/fake-ups-spam-distributes-trojan-bredolab/</link>
		<comments>http://www.blog.malc0de.com/2010/01/12/fake-ups-spam-distributes-trojan-bredolab/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 04:15:51 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[bredolab]]></category>
		<category><![CDATA[fake UPS spam]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=591</guid>
		<description><![CDATA[Early December I wrote about a fake DHL spam campaign which was found to be distributing Trojan Bredolab. The new spam campaign is very similar to the last but this time appears to be from UPS. Example Subject: UPS Tracking Number 5845190 &#8220;Hello! The courier company was not able to deliver your parcel by your address. ]]></description>
			<content:encoded><![CDATA[<p>Early December I wrote about a <a href="http://www.blog.malc0de.com/2009/12/17/fake-dhl-spam-distributes-bredolab/">fake DHL spam campaign </a>which was found to be distributing Trojan Bredolab. The new spam campaign is very similar to the last but this time appears to be from UPS.</p>
<p>Example</p>
<p><strong>Subject: UPS Tracking Number 5845190</strong></p>
<p><strong><em>&#8220;Hello!<br />
The courier company was not able to deliver your parcel by your address.<br />
Cause: Error in shipping address.</em></strong></p>
<p><strong><em>You may pickup the parcel at our post office personaly!</em></strong></p>
<p><strong><em>Please attention!<br />
The shipping label is attached to this e-mail.<br />
Please print this label to get this package at our post office.</em></strong></p>
<p><strong><em>Please do not reply to this e-mail, it is an unmonitored mailbox.</em></strong></p>
<p><strong><em>Thank you.<br />
United Parcel Service of America.</em></strong></p>
<p><strong><strong>[attachment UPS_invoice_NR12944.zip"</strong></strong></p>
<p><strong><span style="font-weight: normal;">VirusTotal results for the attachment can be found </span><a href="http://www.virustotal.com/analisis/fb61286b4f1c926786949e79af1302d0bf3b445166cacf3f7d75ad7b6dd608ff-1263332647"><span style="font-weight: normal;">here</span></a><span style="font-weight: normal;">. Domains known to be  contacted by Trojan </span><a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Search.aspx?query=Bredolab"><span style="font-weight: normal;">Bredolab</span></a><span style="font-weight: normal;"> listed below.</span></p>
<p><span style="font-weight: normal;">20091217:http://mmsfoundsystem.ru, 193.104.12.20<br />
20091227:http://preflopp.com, 95.211.8.170<br />
20100105:http://greatmoder.cn, 122.115.63.19<br />
20100108:http://213.108.56.125, 213.108.56.125</span></p>
<p></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2010/01/12/fake-ups-spam-distributes-trojan-bredolab/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>BETA3 multi-format shellcode encoding tool</title>
		<link>http://www.blog.malc0de.com/2010/01/06/beta3-multi-format-shellcode-encoding-tool/</link>
		<comments>http://www.blog.malc0de.com/2010/01/06/beta3-multi-format-shellcode-encoding-tool/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 01:31:41 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[decode shellcode]]></category>
		<category><![CDATA[encode shellcode]]></category>
		<category><![CDATA[shellcode]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=588</guid>
		<description><![CDATA[BETA can convert raw binary shellcode into text that can be used in exploit source-code. It can convert raw binary data to a large number of encodings. It can also do the reverse: decode encoded data into binary from the same types of encodings. The official page where you can download it can be found here]]></description>
			<content:encoded><![CDATA[<p>BETA can convert raw binary shellcode into text that can be used in exploit source-code. It can convert raw binary data to a large number of encodings. It can also do the reverse: decode encoded data into binary from the same types of encodings. The official page where you can download it can be found <a href="http://code.google.com/p/beta3/">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2010/01/06/beta3-multi-format-shellcode-encoding-tool/feed/</wfw:commentRss>
		<slash:comments>35</slash:comments>
		</item>
		<item>
		<title>Koobface Blogspot Campaign Continues</title>
		<link>http://www.blog.malc0de.com/2009/12/21/koobface-blogspot-campaign-continues/</link>
		<comments>http://www.blog.malc0de.com/2009/12/21/koobface-blogspot-campaign-continues/#comments</comments>
		<pubDate>Tue, 22 Dec 2009 03:38:06 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Koobface]]></category>
		<category><![CDATA[Koobface worm]]></category>
		<category><![CDATA[trojan koobface]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=578</guid>
		<description><![CDATA[The distribution of Koobface through Google Blogspot continues.  Detailed information documented by Jorge Mieres of Pistus Malware Intelligence can be found here. The quick version is 39 domains using Googles Blogspot service redirect unsuspecting users to other domains which deliver Koobface using social engineering tactics. The domains being used for delivery starting showing up in early ]]></description>
			<content:encoded><![CDATA[<p>The distribution of <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Search.aspx?query=koobface">Koobface</a> through Google Blogspot continues.  Detailed information documented by Jorge Mieres of Pistus Malware Intelligence can be found <a href="http://www.efblog.net/2009/12/koobface-campaign-spread-through.html">here</a>. The quick version is 39 domains using Googles Blogspot service redirect unsuspecting users to other domains which deliver Koobface using social engineering tactics.</p>
<p>The domains being used for delivery starting showing up in early December and can be found <a href="http://malc0de.com/tools/db.php?search=%2F.sys%2F">here</a>. A majority of the 350+ <a href="http://malc0de.com/images/KoobFaceDomains.txt">domains</a> are being hosted in the United States using GoDaddys web hosting service.The domains are geographically dispersed around the globe using a variety of hosting providers which helps the attackers ensure a slow takedown.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2009/12/21/koobface-blogspot-campaign-continues/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Fake DHL Spam Distributes Bredolab</title>
		<link>http://www.blog.malc0de.com/2009/12/17/fake-dhl-spam-distributes-bredolab/</link>
		<comments>http://www.blog.malc0de.com/2009/12/17/fake-dhl-spam-distributes-bredolab/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 20:20:09 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[bredolab]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=570</guid>
		<description><![CDATA[Watch out for the fake DHL emails claiming your item wasn&#8217;t shipped. e.g. &#8220;Hello! The courier company was not able to deliver your parcel by your address. Cause: Error in shipping address. You may pickup the parcel at our post office personaly. Please attention! The shipping label is attached to this e-mail. Print this label ]]></description>
			<content:encoded><![CDATA[<p>Watch out for the fake DHL emails claiming your item wasn&#8217;t shipped.</p>
<p>e.g.</p>
<p><em>&#8220;Hello!</p>
<p>The courier company was not able to deliver your parcel by your address.<br />
Cause: Error in shipping address.</p>
<p>You may pickup the parcel at our post office personaly.</p>
<p>Please attention!<br />
The shipping label is attached to this e-mail.<br />
Print this label to get this package at our post office.</p>
<p>Please do not reply to this e-mail, it is an unmonitored mailbox!</p>
<p>Thank you,<br />
DHL Services.</em>&#8221;</p>
<p>The email contains the following attachment </p>
<p>&#8220;DHL_Office_Get_Your_Parcel_NR.4957.zip&#8221;</p>
<p>Which is detected as TrojanDownloader:Win32/Bredolab.AB.  Win32/Bredolab is a downloader which is able to download and execute arbitrary files from a remote host. Additional information can be found <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32/Bredolab">here</a> Currently this sample is detected by  27 out of 41 <a href="http://www.virustotal.com/analisis/a9b7b3eca1fc69154093a0ae15d8b528f5b7e89e4dc7d660f979ece7068ea405-1261079478"> antivirus vendors</a>. </p>
<p>List of Bredolab drop sites being used. </p>
<p>20091201:hxxp://greatmoder.cn, 125.65.110.46<br />
20091201:hxxp://greatmoder.cn, 125.65.110.46<br />
20091201:hxxp://statcount.cn, 218.93.205.228<br />
20091201:hxxp://statcount.cn, 218.93.205.228<br />
20091202:hxxp://greatmoder.cn, 125.65.110.46<br />
20091202:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091203:hxxp://greatmoder.cn, 125.65.110.46<br />
20091203:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091204:hxxp://greatmoder.cn, 125.65.110.46<br />
20091204:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091205:hxxp://greatmoder.cn, 125.65.110.46<br />
20091205:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091205:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091206:hxxp://91.213.126.93, 91.213.126.93<br />
20091206:hxxp://greatmoder.cn, 125.65.110.46<br />
20091206:hxxp://greatmoder.cn, 125.65.110.46<br />
20091206:hxxp://greatmoder.cn, 125.65.110.46<br />
20091206:hxxp://greatmoder.cn, 125.65.110.46<br />
20091206:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091206:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091207:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091207:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091207:hxxp://youaskedthedomain.cn, 91.213.126.93<br />
20091208:hxxp://mmsfoundsystem.ru, 193.104.12.20<br />
20091208:hxxp://mmsfoundsystem.ru, 193.104.12.20<br />
20091208:hxxp://mmsfoundsystem.ru/, 193.104.12.20<br />
20091208:hxxp://mmsfoundsystem.ru, 193.104.12.20<br />
20091217:hxxp://mmsfoundsystem.ru, 193.104.12.20</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2009/12/17/fake-dhl-spam-distributes-bredolab/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>List of Zeus/Zbot Command and Control Servers</title>
		<link>http://www.blog.malc0de.com/2009/12/16/list-of-zeuszbot-command-and-control-servers/</link>
		<comments>http://www.blog.malc0de.com/2009/12/16/list-of-zeuszbot-command-and-control-servers/#comments</comments>
		<pubDate>Thu, 17 Dec 2009 04:26:14 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Spam]]></category>
		<category><![CDATA[C&C servers]]></category>
		<category><![CDATA[Zbot]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=546</guid>
		<description><![CDATA[Over the past few months there has been a number of ongoing spam campaigns that have been distributing Zeus/Zbot. You might have read about a few of them or you may have fallen victim. A good source of information regarding the zbot/zeus spam campaigns can be found here. When Zbot/Zeus is executed it will drop ]]></description>
			<content:encoded><![CDATA[<p>Over the past few months there has been a number of ongoing spam campaigns that have been distributing Zeus/Zbot. You might have read about a few of them or you may have fallen victim. A good source of information regarding the zbot/zeus spam campaigns can be found <a href="http://garwarner.blogspot.com/search/label/zbot">here</a>.</p>
<p>When Zbot/Zeus is executed it will drop a copy of itself in the system folder (c:/windows/system32). It also modifies the registry in order to execute each time Windows starts. Examples of which registry keys are added/modified can be found <a href="http://www.threatexpert.com/report.aspx?md5=74af2ba42786b3cb4d1a6b038219334d">here</a></p>
<p>The bot uses covert methods of injecting additional fields into online Internet banking websites, asking users to answer questions that the authentic website would not ask. This information is then forwarded to a remote database silently in the background with the victim never realizing what happened.  The image below is a graphical representation that gives you an idea how this works.</p>
<div id="attachment_549" class="wp-caption aligncenter" style="width: 510px"><img class="size-full wp-image-549 " title="bankjet" src="http://www.blog.malc0de.com/wp-content/uploads/2009/12/bankjet.gif" alt="Example of injected HTML" width="500" height="611" /><p class="wp-caption-text">Example of injected HTML</p></div>
<p>Zbot/Zeus sends information and receives instructions by contacting specific IP&#8217;s that are hardcoded into the binary. From the samples I have seen the following file names are being used by zbot/zeus to phone home.</p>
<p>/rec.php<br />
/ip.php<br />
/config.bin<br />
/cfg.bin<br />
/cfg2.bin</p>
<p>Searching the malware database I maintain reveals a list of C&amp;C servers geographically dispersed around the globe. The list of domains/IP&#8217;s is rather large so I just consolidated into a text file that can be found <a href="http://malc0de.com/images/zbot_cc_servers.txt">here</a>. Converting the IP addresses to latitude and longitude generate the red dots on the map below which represent the C&amp;C servers.</p>
<p style="text-align: center;"><img class="aligncenter" title="Zeus C&amp;C Servers " src="http://malc0de.com/images/zeus2.jpg" alt="" width="500" height="345" /></p>
<p>An updated list of domains distributing Zeus/Zbot can be found at the following link: <a href="http://malc0de.com/database/index.php?search=bot.exe"> malc0de.com Zbot Domains</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2009/12/16/list-of-zeuszbot-command-and-control-servers/feed/</wfw:commentRss>
		<slash:comments>1694</slash:comments>
		</item>
		<item>
		<title>Go Daddy Domains Serving Malware</title>
		<link>http://www.blog.malc0de.com/2009/12/02/go-daddy-domains-serving-malware/</link>
		<comments>http://www.blog.malc0de.com/2009/12/02/go-daddy-domains-serving-malware/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 07:03:49 +0000</pubDate>
		<dc:creator>JD</dc:creator>
				<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.blog.malc0de.com/?p=540</guid>
		<description><![CDATA[Looking at the past 3 days of data collected the popular web hosting company Go Daddy surfaced 36 times for being related to the distribution of malware. I have contacted abuse@godaddy.com so hopefully these domains will be shut down shortly. In reality its only a drop in the bucket but every little bit helps. **Caution ]]></description>
			<content:encoded><![CDATA[<p>Looking at the past 3 days of data collected the popular web hosting company Go Daddy surfaced 36 times for being related to the distribution of malware. I have contacted abuse@godaddy.com so hopefully these domains will be shut down shortly. In reality its only a drop in the bucket but every little bit helps.</p>
<p>**Caution All Domains Below Are Malicious**</p>
<p><strong>216.69.170.12, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://aaasublet.com/.sys/?getexe=fb.75.exe, 216.69.170.12<br />
20091201:hxxp://aaasublet.com/.sys/?getexe=get.exe, 216.69.170.12<br />
20091201:hxxp://aaasublet.com/.sys/?getexe=go.exe, 216.69.170.12<br />
20091201:hxxp://aaasublet.com/.sys/?getexe=pp.12.exe, 216.69.170.12<br />
20091201:hxxp://aaasublet.com/.sys/?getexe=v2prx.exe, 216.69.170.12</em><br />
<strong>97.74.156.157, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://brooksinfotech.com/.sys/?getexe=fb.75.exe, 97.74.156.157<br />
20091201:hxxp://brooksinfotech.com/.sys/?getexe=get.exe, 97.74.156.157<br />
20091201:hxxp://brooksinfotech.com/.sys/?getexe=pp.12.exe, 97.74.156.157<br />
20091201:hxxp://brooksinfotech.com/.sys/?getexe=v2prx.exe, 97.74.156.157</em><br />
<strong>97.74.144.168, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091124:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091124:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091124:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091124:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091124:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091125:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091125:hxxp://capitalbug.com/counter/exe.php?x=mdac, 97.74.144.168<br />
20091125:hxxp://capitalbug.com/counter/exe.php?x=pdf, 97.74.144.168<br />
20091125:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091126:hxxp://capitalbug.com/counter/exe.php?x=mdac, 97.74.144.168<br />
20091126:hxxp://capitalbug.com/counter/exe.php?x=pdf, 97.74.144.168<br />
20091126:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091127:hxxp://capitalbug.com/counter/exe.php?x=mdac, 97.74.144.168<br />
20091127:hxxp://capitalbug.com/counter/exe.php?x=pdf, 97.74.144.168<br />
20091127:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091129:hxxp://capitalbug.com/counter/exe.php?x=mdac, 97.74.144.168<br />
20091129:hxxp://capitalbug.com/counter/exe.php?x=pdf, 97.74.144.168<br />
20091129:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091201:hxxp://capitalbug.com/counter/exe.php?x=mdac, 97.74.144.168<br />
20091201:hxxp://capitalbug.com/counter/exe.php?x=pdf, 97.74.144.168<br />
20091201:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168</em><br />
<strong>72.167.232.200, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://counterstrikefc.com/.sys/?getexe=fb.75.exe, 72.167.232.200<br />
20091201:hxxp://counterstrikefc.com/.sys/?getexe=ff2ie.exe, 72.167.232.200<br />
20091201:hxxp://counterstrikefc.com/.sys/?getexe=get.exe, 72.167.232.200<br />
20091201:hxxp://counterstrikefc.com/.sys/?getexe=pp.12.exe, 72.167.232.200<br />
20091201:hxxp://counterstrikefc.com/.sys/?getexe=v2prx.exe, 72.167.232.200</em><br />
<strong>72.167.232.191, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://customizeyourstory.com/.sys/?getexe=fb.75.exe, 72.167.232.191<br />
20091201:hxxp://customizeyourstory.com/.sys/?getexe=get.exe, 72.167.232.191<br />
20091201:hxxp://customizeyourstory.com/.sys/?getexe=go.exe, 72.167.232.191<br />
20091201:hxxp://customizeyourstory.com/.sys/?getexe=pp.12.exe, 72.167.232.191<br />
20091201:hxxp://customizeyourstory.com/.sys/?getexe=v2prx.exe, 72.167.232.191</em><br />
<strong>97.74.144.118, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091125:hxxp://promed-net.com/css/abs.exe, 97.74.144.118<br />
20091126:hxxp://promed-net.com/css/abs.exe, 97.74.144.118<br />
20091127:hxxp://promed-net.com/css/abs.exe, 97.74.144.118<br />
20091201:hxxp://facilicaresavannah.com/.sys/?getexe=fb.75.exe, 97.74.144.118<br />
20091201:hxxp://facilicaresavannah.com/.sys/?getexe=get.exe, 97.74.144.118<br />
20091201:hxxp://facilicaresavannah.com/.sys/?getexe=pp.12.exe, 97.74.144.118<br />
20091201:hxxp://facilicaresavannah.com/.sys/?getexe=v2prx.exe, 97.74.144.118<br />
20091201:hxxp://promed-net.com/css/absderce2.exe, 97.74.144.118</em><br />
<strong>97.74.144.128, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://homemadesandwiches.com/.sys/?getexe=ff2ie.exe, 97.74.144.128</em><br />
<strong>72.167.232.33, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://irentphotobooths.com/.sys/?getexe=fb.75.exe, 72.167.232.33<br />
20091201:hxxp://irentphotobooths.com/.sys/?getexe=go.exe, 72.167.232.33<br />
20091201:hxxp://irentphotobooths.com/.sys/?getexe=pp.12.exe, 72.167.232.33<br />
20091201:hxxp://irentphotobooths.com/.sys/?getexe=v2prx.exe, 72.167.232.33</em><br />
<strong>72.167.232.185, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://kickwithcolors.com/.sys/?getexe=fb.75.exe, 72.167.232.185<br />
20091201:hxxp://kickwithcolors.com/.sys/?getexe=get.exe, 72.167.232.185<br />
20091201:hxxp://kickwithcolors.com/.sys/?getexe=pp.12.exe, 72.167.232.185<br />
20091201:hxxp://kickwithcolors.com/.sys/?getexe=v2prx.exe, 72.167.232.185</em><br />
<strong>97.74.64.191, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://kronosagency.com/.sys/?getexe=fb.75.exe, 97.74.64.191<br />
20091201:hxxp://kronosagency.com/.sys/?getexe=get.exe, 97.74.64.191<br />
20091201:hxxp://kronosagency.com/.sys/?getexe=pp.12.exe, 97.74.64.191<br />
20091201:hxxp://kronosagency.com/.sys/?getexe=v2prx.exe, 97.74.64.191</em><br />
<strong>68.178.173.51, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://megabesucher.eu/.sys/?getexe=fb.75.exe, 68.178.173.51<br />
20091201:hxxp://megabesucher.eu/.sys/?getexe=get.exe, 68.178.173.51<br />
20091201:hxxp://megabesucher.eu/.sys/?getexe=go.exe, 68.178.173.51<br />
20091201:hxxp://megabesucher.eu/.sys/?getexe=pp.12.exe, 68.178.173.51<br />
20091201:hxxp://megabesucher.eu/.sys/?getexe=v2prx.exe, 68.178.173.51</em><br />
<strong>97.74.144.197, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://missionoch.org/.sys/?getexe=fb.75.exe, 97.74.144.197<br />
20091201:hxxp://missionoch.org/.sys/?getexe=get.exe, 97.74.144.197<br />
20091201:hxxp://missionoch.org/.sys/?getexe=go.exe, 97.74.144.197<br />
20091201:hxxp://missionoch.org/.sys/?getexe=pp.12.exe, 97.74.144.197<br />
20091201:hxxp://missionoch.org/.sys/?getexe=tw.07.exe, 97.74.144.197<br />
20091201:hxxp://missionoch.org/.sys/?getexe=v2prx.exe, 97.74.144.197</em><br />
<strong>72.167.19.15, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://movehits.at/.sys/?getexe=fb.75.exe, 72.167.19.15<br />
20091201:hxxp://movehits.at/.sys/?getexe=get.exe, 72.167.19.15<br />
20091201:hxxp://movehits.at/.sys/?getexe=pp.12.exe, 72.167.19.15<br />
20091201:hxxp://movehits.at/.sys/?getexe=v2prx.exe, 72.167.19.15</em><br />
<strong>97.74.144.104, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://outtouch.org/.sys/?getexe=fb.75.exe, 97.74.144.104<br />
20091201:hxxp://outtouch.org/.sys/?getexe=get.exe, 97.74.144.104<br />
20091201:hxxp://outtouch.org/.sys/?getexe=go.exe, 97.74.144.104<br />
20091201:hxxp://outtouch.org/.sys/?getexe=pp.12.exe, 97.74.144.104<br />
20091201:hxxp://outtouch.org/.sys/?getexe=v2prx.exe, 97.74.144.104</em><br />
<strong>97.74.211.187, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://patriotflag.org/.sys/?getexe=fb.75.exe, 97.74.211.187<br />
20091201:hxxp://patriotflag.org/.sys/?getexe=get.exe, 97.74.211.187<br />
20091201:hxxp://patriotflag.org/.sys/?getexe=go.exe, 97.74.211.187<br />
20091201:hxxp://patriotflag.org/.sys/?getexe=pp.12.exe, 97.74.211.187<br />
20091201:hxxp://patriotflag.org/.sys/?getexe=v2prx.exe, 97.74.211.187</em><br />
<strong>72.167.232.74, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://peakgrouptravel.com/.sys/?getexe=fb.75.exe, 72.167.232.74<br />
20091201:hxxp://peakgrouptravel.com/.sys/?getexe=get.exe, 72.167.232.74<br />
20091201:hxxp://peakgrouptravel.com/.sys/?getexe=pp.12.exe, 72.167.232.74<br />
20091201:hxxp://peakgrouptravel.com/.sys/?getexe=v2prx.exe, 72.167.232.74</em><br />
<strong>72.167.232.186, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://pipelogicservices.com/.sys/?getexe=fb.75.exe, 72.167.232.186<br />
20091201:hxxp://pipelogicservices.com/.sys/?getexe=go.exe, 72.167.232.186<br />
20091201:hxxp://pipelogicservices.com/.sys/?getexe=pp.12.exe, 72.167.232.186<br />
20091201:hxxp://pipelogicservices.com/.sys/?getexe=v2prx.exe, 72.167.232.186</em><br />
<strong>97.74.144.118, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091125:hxxp://promed-net.com/css/abs.exe, 97.74.144.118<br />
20091126:hxxp://promed-net.com/css/abs.exe, 97.74.144.118<br />
20091127:hxxp://promed-net.com/css/abs.exe, 97.74.144.118<br />
20091201:hxxp://facilicaresavannah.com/.sys/?getexe=fb.75.exe, 97.74.144.118<br />
20091201:hxxp://facilicaresavannah.com/.sys/?getexe=get.exe, 97.74.144.118<br />
20091201:hxxp://facilicaresavannah.com/.sys/?getexe=pp.12.exe, 97.74.144.118<br />
20091201:hxxp://facilicaresavannah.com/.sys/?getexe=v2prx.exe, 97.74.144.118<br />
20091201:hxxp://promed-net.com/css/absderce2.exe, 97.74.144.118</em><br />
<strong>97.74.144.88, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://robertomoran.com/.sys/?getexe=fb.75.exe, 97.74.144.88<br />
20091201:hxxp://robertomoran.com/.sys/?getexe=get.exe, 97.74.144.88<br />
20091201:hxxp://robertomoran.com/.sys/?getexe=pp.12.exe, 97.74.144.88<br />
20091201:hxxp://robertomoran.com/.sys/?getexe=v2captcha.exe, 97.74.144.88<br />
20091201:hxxp://robertomoran.com/.sys/?getexe=v2googlecheck.exe, 97.74.144.88<br />
20091201:hxxp://robertomoran.com/.sys/?getexe=v2prx.exe, 97.74.144.88</em><br />
<strong>97.74.50.246, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://runningguru.com/.sys/?getexe=fb.75.exe, 97.74.50.246<br />
20091201:hxxp://runningguru.com/.sys/?getexe=get.exe, 97.74.50.246<br />
20091201:hxxp://runningguru.com/.sys/?getexe=pp.12.exe, 97.74.50.246<br />
20091201:hxxp://runningguru.com/.sys/?getexe=v2prx.exe, 97.74.50.246</em><br />
<strong>72.167.232.177, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://ryanscarter.com/.sys/?getexe=fb.75.exe, 72.167.232.177<br />
20091201:hxxp://ryanscarter.com/.sys/?getexe=get.exe, 72.167.232.177<br />
20091201:hxxp://ryanscarter.com/.sys/?getexe=pp.12.exe, 72.167.232.177<br />
20091201:hxxp://ryanscarter.com/.sys/?getexe=v2prx.exe, 72.167.232.177</em><br />
<strong>97.74.144.91, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://speedysalesletter.com/.sys/?getexe=fb.75.exe, 97.74.144.91<br />
20091201:hxxp://speedysalesletter.com/.sys/?getexe=get.exe, 97.74.144.91<br />
20091201:hxxp://speedysalesletter.com/.sys/?getexe=pp.12.exe, 97.74.144.91<br />
20091201:hxxp://speedysalesletter.com/.sys/?getexe=v2prx.exe, 97.74.144.91</em><br />
<strong>72.167.232.171, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://str8upent.com/.sys/?getexe=fb.75.exe, 72.167.232.171<br />
20091201:hxxp://str8upent.com/.sys/?getexe=get.exe, 72.167.232.171<br />
20091201:hxxp://str8upent.com/.sys/?getexe=go.exe, 72.167.232.171<br />
20091201:hxxp://str8upent.com/.sys/?getexe=pp.12.exe, 72.167.232.171<br />
20091201:hxxp://str8upent.com/.sys/?getexe=v2prx.exe, 72.167.232.171</em><br />
<strong>72.167.232.75, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://theraymondgallery.com/.sys/?getexe=fb.75.exe, 72.167.232.75<br />
20091201:hxxp://theraymondgallery.com/.sys/?getexe=get.exe, 72.167.232.75<br />
20091201:hxxp://theraymondgallery.com/.sys/?getexe=pp.12.exe, 72.167.232.75<br />
20091201:hxxp://theraymondgallery.com/.sys/?getexe=v2prx.exe, 72.167.232.75</em><br />
<strong>72.167.232.70, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://travelsigna.com/.sys/?getexe=fb.75.exe, 72.167.232.70<br />
20091201:hxxp://travelsigna.com/.sys/?getexe=get.exe, 72.167.232.70<br />
20091201:hxxp://travelsigna.com/.sys/?getexe=pp.12.exe, 72.167.232.70<br />
20091201:hxxp://travelsigna.com/.sys/?getexe=v2prx.exe, 72.167.232.70</em><br />
<strong>72.167.232.197, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://v-questtx.net/.sys/?getexe=fb.75.exe, 72.167.232.197<br />
20091201:hxxp://v-questtx.net/.sys/?getexe=get.exe, 72.167.232.197<br />
20091201:hxxp://v-questtx.net/.sys/?getexe=go.exe, 72.167.232.197<br />
20091201:hxxp://v-questtx.net/.sys/?getexe=pp.12.exe, 72.167.232.197<br />
20091201:hxxp://v-questtx.net/.sys/?getexe=v2prx.exe, 72.167.232.197</em><br />
<strong>97.74.126.232, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://www.birdystudio.com/.sys/?getexe=fb.75.exe, 97.74.126.232<br />
20091201:hxxp://www.birdystudio.com/.sys/?getexe=get.exe, 97.74.126.232<br />
20091201:hxxp://www.birdystudio.com/.sys/?getexe=pp.12.exe, 97.74.126.232<br />
20091201:hxxp://www.birdystudio.com/.sys/?getexe=v2prx.exe, 97.74.126.232</em><br />
<strong>72.167.232.94, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://www.conference-professionals.com/.sys/?getexe=fb.75.exe, 72.167.232.94<br />
20091201:hxxp://www.conference-professionals.com/.sys/?getexe=get.exe, 72.167.232.94<br />
20091201:hxxp://www.conference-professionals.com/.sys/?getexe=pp.12.exe, 72.167.232.94<br />
20091201:hxxp://www.conference-professionals.com/.sys/?getexe=v2prx.exe, 72.167.232.94</em><br />
<strong>72.167.232.198, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://www.d-dmusic.com/.sys/?getexe=fb.75.exe, 72.167.232.198<br />
20091201:hxxp://www.d-dmusic.com/.sys/?getexe=get.exe, 72.167.232.198<br />
20091201:hxxp://www.d-dmusic.com/.sys/?getexe=go.exe, 72.167.232.198<br />
20091201:hxxp://www.d-dmusic.com/.sys/?getexe=pp.12.exe, 72.167.232.198<br />
20091201:hxxp://www.d-dmusic.com/.sys/?getexe=v2prx.exe, 72.167.232.198</em><br />
<strong>97.74.127.146, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://www.emeraldsunarts.com/.sys/?getexe=fb.75.exe, 97.74.127.146<br />
20091201:hxxp://www.emeraldsunarts.com/.sys/?getexe=get.exe, 97.74.127.146<br />
20091201:hxxp://www.emeraldsunarts.com/.sys/?getexe=pp.12.exe, 97.74.127.146<br />
20091201:hxxp://www.emeraldsunarts.com/.sys/?getexe=v2prx.exe, 97.74.127.146</em><br />
<strong>72.167.232.210, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://www.fallsmediaproductions.com/.sys/?getexe=fb.75.exe, 72.167.232.210<br />
20091201:hxxp://www.fallsmediaproductions.com/.sys/?getexe=get.exe, 72.167.232.210<br />
20091201:hxxp://www.fallsmediaproductions.com/.sys/?getexe=pp.12.exe, 72.167.232.210<br />
20091201:hxxp://www.fallsmediaproductions.com/.sys/?getexe=v2prx.exe, 72.167.232.210</em><br />
<strong>72.167.232.118, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://www.integrastor.com/.sys/?getexe=fb.75.exe, 72.167.232.118<br />
20091201:hxxp://www.integrastor.com/.sys/?getexe=get.exe, 72.167.232.118<br />
20091201:hxxp://www.integrastor.com/.sys/?getexe=pp.12.exe, 72.167.232.118<br />
20091201:hxxp://www.integrastor.com/.sys/?getexe=v2prx.exe, 72.167.232.118</em><br />
<strong>97.74.141.128, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://www.onlinepcwizard.com/.sys/?getexe=fb.75.exe, 97.74.141.128<br />
20091201:hxxp://www.onlinepcwizard.com/.sys/?getexe=go.exe, 97.74.141.128<br />
20091201:hxxp://www.onlinepcwizard.com/.sys/?getexe=pp.12.exe, 97.74.141.128<br />
20091201:hxxp://www.onlinepcwizard.com/.sys/?getexe=v2prx.exe, 97.74.141.128</em><br />
<strong>72.167.232.86, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091201:hxxp://yogaramatgan.com/.sys/?getexe=fb.75.exe, 72.167.232.86<br />
20091201:hxxp://yogaramatgan.com/.sys/?getexe=get.exe, 72.167.232.86<br />
20091201:hxxp://yogaramatgan.com/.sys/?getexe=pp.12.exe, 72.167.232.86<br />
20091201:hxxp://yogaramatgan.com/.sys/?getexe=v2prx.exe, 72.167.232.86</em><br />
<strong>97.74.144.168, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091124:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091124:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091124:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091124:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091124:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091125:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091125:hxxp://capitalbug.com/counter/exe.php?x=mdac, 97.74.144.168<br />
20091125:hxxp://capitalbug.com/counter/exe.php?x=pdf, 97.74.144.168<br />
20091125:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091126:hxxp://capitalbug.com/counter/exe.php?x=mdac, 97.74.144.168<br />
20091126:hxxp://capitalbug.com/counter/exe.php?x=pdf, 97.74.144.168<br />
20091126:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091127:htxx://capitalbug.com/counter/exe.php?x=mdac, 97.74.144.168<br />
20091127:hxxp://capitalbug.com/counter/exe.php?x=pdf, 97.74.144.168<br />
20091127:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091129:hxxp://capitalbug.com/counter/exe.php?x=mdac, 97.74.144.168<br />
20091129:hxxp://capitalbug.com/counter/exe.php?x=pdf, 97.74.144.168<br />
20091129:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168<br />
20091201:hxxp://capitalbug.com/counter/exe.php?x=mdac, 97.74.144.168<br />
20091201:hxxp://capitalbug.com/counter/exe.php?x=pdf, 97.74.144.168<br />
20091201:hxxp://capitalbug.com/counter/yamba.exe, 97.74.144.168</em><br />
<strong>72.167.232.205, UNITED STATES, ARIZONA, GODADDY.COM INC</strong><br />
<em>20091126:hxxp://milantrezur.com/.sys/?getexe=pp.12.exe, 72.167.232.205<br />
20091126:hxxp://milantrezur.com/.sys/?getexe=v2prx.exe, 72.167.232.205<br />
20091129:hxxp://milantrezur.com/.sys/?getexe=pp.12.exe, 72.167.232.205<br />
20091129:hxxp://milantrezur.com/.sys/?getexe=v2prx.exe, 72.167.232.205</em></p>
<p><em><br />
</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.blog.malc0de.com/2009/12/02/go-daddy-domains-serving-malware/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 1.310 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2012-02-05 08:08:53 -->
<!-- Compression = gzip -->
