A forum for reverse engineering, OS internals and malware analysis 

Forum for announcements and questions about tools and software.
 #16984  by Peter Kleissner
 Mon Dec 03, 2012 1:10 am
Latest updates:
- added Conficker A and B domains to the blackklist
- Pimped the blocklist a little (added for example latest UrlZone domains)
- Now monitoring of Sinowal!

Data sharing (e.g. for nex, but also other 3rd parties) should also be avl soon. Just had no one yet for writing a script to export the data.
 #17011  by hanan
 Tue Dec 04, 2012 9:39 am
how does you know the amount of infections? is it by collecting DNS queries or by registering for yourself one of the domains from the DGA ?
 #17013  by Peter Kleissner
 Tue Dec 04, 2012 10:12 am
Yup I have a shitloads of domains, classical sinkholing. But there's more behind the entire Virus Tracker system, I am also monitoring all the C&Cs, generating automatically the blocklist etc.

Right now I am starting to implement at least some protocols of the banking trojans in order to get the latest stuff out of the real C&Cs and provide it to the security industry.
 #17014  by Buster_BSA
 Tue Dec 04, 2012 10:32 am
Nice work, Peter!

If you do not mind I would like to use your list in Buster Sandbox Analyzer.
 #17022  by Peter Kleissner
 Tue Dec 04, 2012 10:39 pm
Buster_BSA wrote:Nice work, Peter!

If you do not mind I would like to use your list in Buster Sandbox Analyzer.
Sure, feel free to use it!
 #17023  by Buster_BSA
 Tue Dec 04, 2012 10:50 pm
Peter Kleissner wrote:Sure, feel free to use it!
Thank you very much!

Next release will be using it.
 #18317  by Peter Kleissner
 Sat Feb 23, 2013 1:40 pm
There have been some new features introduced on Virus Tracker. One is now a free domain classifying service, it allows you to check domains (if they are parked/expired, suspended, sinkhole, active and so on) and outputs the result as CSV. You can find more information here http://blog.virustracker.info/?p=47

Other changes were:
- adding more botnets to both showing infection statistics
- adding more botnets to the blocklist
- catching all mails being sent to @rbnnetwork.com, generating a summary xlsx