Thursday

A list of updated domains used in the SQL injection attacks



Shadowserver posted an interesting list of the domains used in the recent SQL attack. You could just monitor any unauthorized changes to your website if you have change management and monitoring in place. Alternatively, you could use Google alerts with some google foo like "site:www.mysite.be" in combination with some other terms or domain names to keep track of unauthorized changes. Google Alerts are email updates of the latest relevant Google results (web, news, etc.) based on your choice of query or topic. You can also use Google alerts to track certain topics like I use for "Storm Worm" for example. It could possibly be used to track Black PR activities related to your company. Something to think about. But let's have a look at those domains.

Below is a list of domains used in the mass SQL injections that insert malicious javascript into websites. We've also included an approximate number of pages infected (according to Google). Note that these numbers decay with time. Some of these domains were injected long ago and have been cleaned. At their height, their numbers may have been larger.

www.nihaorr1.com468,000
free.hostpinoy.info444,000
xprmn4u.info369,000
www.nmidahena.com140,000
winzipices.cn75,000
sb.5252.ws69,000
www.aspder.com62,000
www.11910.net47,000
bbs.jueduizuan.com44,000
www.bluell.cn44,000
www.2117966.net39,000
s.see9.us39,000
xvgaoke.cn33,000
1.hao929.cn20,000
www.414151.com17,000
cc.18dd.net15,000
yl18.net15,000
www.kisswow.com.cn13,000
urkb.net13,000
c.uc8010.com9500
rnmb.net7000
www.ririwow.cn6000
www.killwow1.cn4000
www.qiqigm.com3600
www.wowgm1.cn3500
www.wowyeye.cn2800
9i5t.cn2500
computershello.cn2300
www.z008.net1600
b15.3322.org1200
www.direct84.com1100
www.caocaowow.cn900
www.qiuxuegm.com800
firestnamestea.cn700
%61%2E%6B%61%34%37%2E%75%73 (a.ka47.us)600
%61%31%38%38%2E%77%73 (a188.ws)500
www.qiqi111.cn230
www.banner82.com90
smeisp.cn85
okey123.cn55
www.nihao112.com45
al.99.vc45
www.aidushu.net45
www.chliyi.com40
free.edivid.info40
52-o.cn40
www.fucksb.net40
www60.actualization.cn40
d39.6600.org40
h28.8800.org34
ucmal.com30
t.uc8010.com30
www.dota11.cn25
bc0.cn20
%33%2E%74%72%6F%6A%61%6E%38%2E%63%6F%6D (3.trojan8.com)20
www.adword71.com17
killpp.cn16
w11.6600.org13
usuc.us13
www.msshamof.com10
newasp.com.cn7
www.wowgm2.cn8
mm.jsjwh.com.cn8
17ge.cn4
www.adword72.com2
www.117275.cn1
vb008.cn?
www.wow112.cn?

www.nihaoel3.com
The list might not be that useful anymore but it gives a nice idea about the number of website affected. Since the attackers stay very dynamic and make us of fast flux dns, they have already moved to some new domains. Thanks to ddchanchev for providing them.
The botnet masters behind Asprox are converging tactics already, by fast-fluxing the SQL injected domains. Related URLs for this campaign :

banner82.com
dll64.com
aspx88.com
bank11.net

cookie68.com

exportpe.net


Read the complete assessment - Fast-Fluxing SQL Injection Attacks Executed from the Asprox Botnet, and go through previous posts related to the botnet as well - Phishing Emails Generating Botnet Scaling; Inside a Botnet's Phishing Activities; Fake Yahoo Greetings Malware Campaign Circulate
If you have some original Google search terms to keep track of 'security events', feel free to share them.

Previous articles:

0 comments: