<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0" xmlns:media="http://search.yahoo.com/mrss/" xml:lang="en-US">
	<channel>
		<title>clean-mx realtime database</title>
		<link>http://support.clean-mx.de/clean-mx/rss?scope=viruses</link>
		<description><![CDATA[Live information from clean-mx.de 6 items in this issue]]></description>
		<item>
			<title><![CDATA[http://dumciej.fimrulyv.ru/calc.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9767715</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9767715</guid>
			<pubDate>2013-03-15T08:06:40+01:00</pubDate>
			<description><![CDATA[id:	9767715<br />first:	1363331200<br />last:	0<br />md5:	e44b17e8dc52fe4f2bd4e72d4d7824ee<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e44b17e8dc52fe4f2bd4e72d4d7824ee<br />vt_score:	33/46 (71.7%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen3<br />url:	http://dumciej.fimrulyv.ru/calc.exe<br />recent:	up<br />response:	alive<br />ip:	124.153.230.84<br />as:	AS9694<br />review:	188.213.89.152<br />domain:	fimrulyv.ru<br />country:	MD<br />source:	RIPE<br />email:	dudko_oleg@mail.ru<br />inetnum:	124.153.128.0 - 124.153.255.255<br />netname:	METICAL-SRL<br />descr:	Metical SRLstr. V. Mahu 137Orhei Republica MoldovaMetical SRL<br />ns1:	ns3.fimrulyv.ru<br />ns2:	ns4.fimrulyv.ru<br />ns3:	ns1.fimrulyv.ru<br />ns4:	ns6.fimrulyv.ru<br />ns5:	ns5.fimrulyv.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pds24.egloos.com/pds/201205/11/37/musim12.5.11.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8583073</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PUA.Win32.Packer.Asprotect-2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8583073</guid>
			<pubDate>2012-12-06T23:22:02+01:00</pubDate>
			<description><![CDATA[id:	8583073<br />first:	1354832522<br />last:	0<br />md5:	c4b5ac10680e6a06382b591694e30411<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c4b5ac10680e6a06382b591694e30411<br />vt_score:	6/36 (16.7%)<br />scanner:	clamav<br />virusname:	PUA.Win32.Packer.Asprotect-2<br />url:	http://pds24.egloos.com/pds/201205/11/37/musim12.5.11.exe<br />recent:	up<br />response:	alive<br />ip:	211.234.242.165<br />as:	AS9694<br />review:	58.229.125.101<br />domain:	egloos.com<br />country:	KR<br />source:	APNIC<br />email:	abuse@skbroadband.com<br />inetnum:	211.232.0.0 - 211.255.255.255<br />netname:	broadNnet-KR<br />descr:	SK Broadband Co Ltd<br />ns1:	ns3.skcommunications.com<br />ns2:	ns4.skcommunications.com<br />ns3:	ns1.skcommunications.com<br />ns4:	ns2.skcommunications.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pds21.egloos.com/pds/201206/19/37/flower12.6.19.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=4262065</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Hupigon-28552]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=4262065</guid>
			<pubDate>2012-11-14T11:41:18+01:00</pubDate>
			<description><![CDATA[id:	4262065<br />first:	1352889678<br />last:	0<br />md5:	87c27f4ddc5d0465378235e84b28f32d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=87c27f4ddc5d0465378235e84b28f32d<br />vt_score:	7/36 (19.4%)<br />scanner:	clamav<br />virusname:	Trojan.Hupigon-28552<br />url:	http://pds21.egloos.com/pds/201206/19/37/flower12.6.19.exe<br />recent:	up<br />response:	alive<br />ip:	211.234.242.162<br />as:	AS9694<br />review:	58.229.125.103<br />domain:	egloos.com<br />country:	KR<br />source:	APNIC<br />email:	abuse@skbroadband.com<br />inetnum:	211.232.0.0 - 211.255.255.255<br />netname:	broadNnet-KR<br />descr:	SK Broadband Co Ltd<br />ns1:	ns1.skcommunications.com<br />ns2:	ns3.skcommunications.com<br />ns3:	ns4.skcommunications.com<br />ns4:	ns2.skcommunications.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://nsi.or.kr/technote7/data/theme/itemm.txt]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3671858</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PHP/Pbot.A.6]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3671858</guid>
			<pubDate>2012-11-13T08:20:35+01:00</pubDate>
			<description><![CDATA[id:	3671858<br />first:	1352791235<br />last:	0<br />md5:	c9b1621ed101ca12c7f05d013b700ad9<br />virustotal:	http://www.virustotal.com/analisis/918276f49308de8feea351ce081ef52814466bf5a47f84e046273b0ab5574906-1271515629<br />vt_score:	22/40 (55.00%)<br />scanner:	avira<br />virusname:	PHP/Pbot.A.6<br />url:	http://nsi.or.kr/technote7/data/theme/itemm.txt<br />recent:	up<br />response:	alive<br />ip:	211.255.32.154<br />as:	AS9694<br />review:	211.255.32.154<br />domain:	nsi.or.kr<br />country:	KR<br />source:	APNIC<br />email:	noc@hilineisp.net<br />inetnum:	211.232.0.0 - 211.255.255.255<br />netname:	HLINEISP_redmous1<br />descr:	KRNICKorea Network Information CenterLG DACOM KIDC<br />ns1:	ns1.hilineisp.net<br />ns2:	ns2.hilineisp.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://nsi.or.kr/technote7/data/theme/itemm.txt?&modez=botz]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=3574500</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PHP/Pbot.A.6]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=3574500</guid>
			<pubDate>2012-11-12T20:50:31+01:00</pubDate>
			<description><![CDATA[id:	3574500<br />first:	1352749831<br />last:	0<br />md5:	c9b1621ed101ca12c7f05d013b700ad9<br />virustotal:	http://www.virustotal.com/analisis/918276f49308de8feea351ce081ef52814466bf5a47f84e046273b0ab5574906-1271515629<br />vt_score:	22/40 (55.00%)<br />scanner:	avira<br />virusname:	PHP/Pbot.A.6<br />url:	http://nsi.or.kr/technote7/data/theme/itemm.txt?&modez=botz<br />recent:	up<br />response:	alive<br />ip:	211.255.32.154<br />as:	AS9694<br />review:	211.255.32.154<br />domain:	nsi.or.kr<br />country:	KR<br />source:	APNIC<br />email:	noc@hilineisp.net<br />inetnum:	211.232.0.0 - 211.255.255.255<br />netname:	HLINEISP_redmous1<br />descr:	KRNICKorea Network Information CenterLG DACOM KIDC<br />ns1:	ns1.hilineisp.net<br />ns2:	ns2.hilineisp.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pds11.egloos.com/pds/200901/27/86/shiftspace-himalia.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=2553092</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Gendal.1748068]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=2553092</guid>
			<pubDate>2012-11-08T09:11:12+01:00</pubDate>
			<description><![CDATA[id:	2553092<br />first:	1352362272<br />last:	0<br />md5:	a06762db9d8b9c416cd1b5e8f951baef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a06762db9d8b9c416cd1b5e8f951baef<br />vt_score:	20/43 (46.5%)<br />scanner:	avira<br />virusname:	TR/Gendal.1748068<br />url:	http://pds11.egloos.com/pds/200901/27/86/shiftspace-himalia.exe<br />recent:	up<br />response:	alive<br />ip:	211.234.242.184<br />as:	AS9694<br />review:	58.229.125.101<br />domain:	egloos.com<br />country:	KR<br />source:	APNIC<br />email:	abuse@skbroadband.com<br />inetnum:	211.232.0.0 - 211.255.255.255<br />netname:	broadNnet-KR<br />descr:	SK Broadband Co Ltd<br />ns1:	ns3.skcommunications.com<br />ns2:	ns4.skcommunications.com<br />ns3:	ns1.skcommunications.com<br />ns4:	ns2.skcommunications.com<br />ns5:	<br />]]></description>
		</item>
	</channel>
</rss>

