Asprox has awaken again.
I have not tried to follow it this time.
But a quick look gave me this one (from bfk.de):

The domain thingre.com lived happily side by side with other domains "attributed" to the newly wakened Asprox botnet.
(bannerdriven.ru, adsyndication.ru, adtcp.ru, adbnr.ru, siteanalitycs.ru, htmlads.ru, ads-t.ru, bannert.ru).
But if you do a quick search for thingre. com, this domain has been tied to Waledac.
Some of them, others do of course exist too.
I stumbled across two new ones registered today, 15infinput.com and binnet11.net.
One of the IPs that shows up in connection with those is 69.66.237.74.
Here is an example using bfk.de from 69.66.237.74 (all of those are not active):
First a screenshot from the phish site at
h||p://ww4.visa.com.82siddefault.com/creditcards/security/confirm
(Click on it for a bigger one)
And here is a screenshot of the location bar from the screenshot above:

Trend Micro mentioning a possible connection between Conficker and Waledac:
DOWNAD/Conficker Watch: New Variant in The Mix?
Quote:
Another interesting thing we also noticed was that the Downad/Conficker box was trying to access a known Waledac domain (goodnewsdigital(dot)com) and download yet another encrypted file.
Another one from the same article:
Just a quick one now, a list of some more domains on the Asprox botnet registered yesterday.
The "proactive" registrar is Directi. Not directly unusual.
32rundllfunc.biz, 50label-map.com, 59comm-cookie.biz, 76text-crypt.net, 7batchshare.biz, admin-batch97.biz, apidefault57.com, cfm-sid7.net, cmdidini32.biz, code-func42.biz, comm-cipher67.name, corebank98.biz, map-ref95.com, pool-org23.name, rdir-site81.name, tidport85.biz, win-pool21.biz,
Phish setup:
ww9.business.hsbc.com.win-pool21.biz
The Asprox domain:
debug-script40.biz. (Found on URIBL.COM).
Not serving the usual javascript files at the moment.
(There are probably more of them)
Some expected Downadup/Conficker domains, shows up on the Asprox botnet:
fmhxqutvccr.org, fmkopswuzhj.biz, fuougcdv.org, fvwugekf.info, fwkbt.info, gbxpxugx.org, ghtileh.biz, gnyluuxneo.com.
And highly possible several others.
An image illustrates one common IP:
Recent comments
40 weeks 5 days ago
41 weeks 1 day ago
41 weeks 5 days ago
41 weeks 5 days ago
43 weeks 16 hours ago
1 year 21 weeks ago
1 year 21 weeks ago
1 year 24 weeks ago
1 year 24 weeks ago
1 year 25 weeks ago