A method and system of detecting a malicious and/or botnet-related domain
name, comprising: reviewing a domain name used in Domain Name System
(DNS) traffic in a network; searching for information about the domain
name, the information related to: information about the domain name in a
domain name white list and/or a domain name suspicious list; and
information about the domain name using an Internet search engine,
wherein the Internet search engine determines if there are no search
results or search results with a link to at least one malware analysis
site; and designating the domain name as malicious and/or botnet-related
based on the information.