The domain Yahoo550.com was recently found to be hosting malicious files. Not related in any way to Yahoo!, the domain was obviously created to trick users into thinking that it is a valid domain in the fashion of Yahoo! 360°, Yahoo’s version of a social networking site.
Based on DNS information, Yahoo550 was registered by someone named Bill Adward, whose email address is from Yahoo! competitor Hotmail.
Currently, four subdomains of Yahoo550 are found to be serving malware:
There are no available Web pages for the domains and the malicious file needs have to be accessed directly. It is not known yet if the exact malicious URLs were spammed or linked from compromised Web pages.
The malware file served from this site is detected by Trend Micro as TROJ_FARFLI.EY.