Thursday, July 16, 2009

New Mebroot domains for the summer

The last variant of Mebroot's driver uses an obfuscated domain generation algorithm to connect to C&C servers. Here are the domains for this summer, you might want to block them for whatever reason.

The first domain, week-based, is used first (though, after the hardcoded domain in the driver itself); the second domain is day-based and used as a failsafe. On top of '.com', the TLDs '.net' and '.biz' are tried as well.


2009/07/17: bdcxduds.com xdjxekgt.com
2009/07/18: bdcxduds.com ejswwhvk.com
2009/07/19: swuvxcds.com khkciudw.com
2009/07/20: swuvxcds.com kxhwcceu.com
2009/07/21: swuvxcds.com xhxvdsck.com
2009/07/22: swuvxcds.com hkssvihg.com
2009/07/23: swuvxcds.com jwjchkci.com
2009/07/24: swuvxcds.com vkcvuksd.com
2009/07/25: swuvxcds.com ecjhdvue.com
2009/07/26: vxvtvhik.com kvcwhwgj.com
2009/07/27: vxvtvhik.com kvbdxjhc.com
2009/07/28: vxvtvhik.com uuvksskh.com
2009/07/29: vxvtvhik.com tkevtxue.com
2009/07/30: vxvtvhik.com vdkhsccs.com
2009/07/31: vxvtvhik.com feuufscg.com
2009/08/01: vxvtvhik.com gcuekdss.com
2009/08/02: wjbijxix.com ubhxghvt.com
2009/08/03: wjbijxix.com vcdgcseb.com
2009/08/04: wjbijxix.com ugfdvxck.com
2009/08/05: wjbijxix.com wdbbgwej.com
2009/08/06: wjbijxix.com fgugcijb.com
2009/08/07: wjbijxix.com twsssthu.com
2009/08/08: wjbijxix.com bfithbdd.com
2009/08/09: ufcsbgsg.com cgkgttfg.com
2009/08/10: ufcsbgsg.com fxxubvcg.com
2009/08/11: ufcsbgsg.com egihvgjf.com
2009/08/12: ufcsbgsg.com fkcxifec.com
2009/08/13: ufcsbgsg.com ukxsuvhw.com
2009/08/14: ufcsbgsg.com fxkihkfi.com