<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0" xmlns:media="http://search.yahoo.com/mrss/" xml:lang="en-US">
	<channel>
		<title>clean-mx realtime database</title>
		<link>http://support.clean-mx.de/clean-mx/rss?scope=viruses</link>
		<description><![CDATA[Live information from clean-mx.de 473 items in this issue]]></description>
		<item>
			<title><![CDATA[http://audpuu5b.zeqromoj.ru/rasta01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11102972</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11102972</guid>
			<pubDate>2013-05-17T19:40:03+02:00</pubDate>
			<description><![CDATA[id:	11102972<br />first:	1368812403<br />last:	0<br />md5:	398fad94657bdf663c58e82855939a2d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=398fad94657bdf663c58e82855939a2d<br />vt_score:	5/47 (10.6%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen2<br />url:	http://audpuu5b.zeqromoj.ru/rasta01.exe<br />recent:	up<br />response:	alive<br />ip:	89.28.117.143<br />as:	AS31252<br />review:	31.63.185.80<br />domain:	zeqromoj.ru<br />country:	PL<br />source:	RIPE<br />email:	abuse@centertel.pl<br />inetnum:	89.28.0.0 - 89.28.127.255<br />netname:	PL-IDEA-DSL<br />descr:	PTK CENTERTEL mobile data services<br />ns1:	ns5.zeqromoj.ru<br />ns2:	ns4.zeqromoj.ru<br />ns3:	ns3.zeqromoj.ru<br />ns4:	ns6.zeqromoj.ru<br />ns5:	ns2.zeqromoj.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://94.242.198.64/4/hh.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11102970</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Win32.Madon]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11102970</guid>
			<pubDate>2013-05-17T19:40:02+02:00</pubDate>
			<description><![CDATA[id:	11102970<br />first:	1368812402<br />last:	0<br />md5:	0256065b55d537283e6f9246abb80b51<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0256065b55d537283e6f9246abb80b51<br />vt_score:	2/35 (5.7%)<br />scanner:	Ikarus<br />virusname:	Trojan.Win32.Madon<br />url:	http://94.242.198.64/4/hh.exe<br />recent:	up<br />response:	alive<br />ip:	94.242.198.64<br />as:	AS5577<br />review:	94.242.198.64<br />domain:	94.242.198.64<br />country:	LU<br />source:	RIPE<br />email:	abuse@as5577.net<br />inetnum:	94.242.192.0 - 94.242.223.255<br />netname:	ROOT-NETWORK<br />descr:	root SA<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://46.118.212.108/traff01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11102143</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11102143</guid>
			<pubDate>2013-05-17T19:00:11+02:00</pubDate>
			<description><![CDATA[id:	11102143<br />first:	1368810011<br />last:	0<br />md5:	84103fd3c2de2fc3224404cc11192313<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=84103fd3c2de2fc3224404cc11192313<br />vt_score:	11/36 (30.6%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://46.118.212.108/traff01.exe<br />recent:	up<br />response:	alive<br />ip:	46.118.212.108<br />as:	AS12530<br />review:	46.118.212.108<br />domain:	46.118.212.108<br />country:	UA<br />source:	RIPE<br />email:	security@svitonline.com<br />inetnum:	46.118.0.0 - 46.119.255.255<br />netname:	UA-SVITONLINE-20100517<br />descr:	GoldenTelecom LLC<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://filesx.hi2.ro/uploads/geloyun.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11089578</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Scar]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11089578</guid>
			<pubDate>2013-05-17T09:40:43+02:00</pubDate>
			<description><![CDATA[id:	11089578<br />first:	1368776443<br />last:	0<br />md5:	442797fe7ddeb9e2e2e1457845cba395<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=442797fe7ddeb9e2e2e1457845cba395<br />vt_score:	16/36 (44.4%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Scar<br />url:	http://filesx.hi2.ro/uploads/geloyun.exe<br />recent:	up<br />response:	alive<br />ip:	89.40.156.12<br />as:	AS9050<br />review:	89.40.156.12<br />domain:	hi2.ro<br />country:	ro<br />source:	RIPE<br />email:	Honoriu.Lazar@telemobil.ro<br />inetnum:	89.40.128.0 - 89.40.191.255<br />netname:	TELEMOBIL-SA<br />descr:	Telemobil S.A.Calea Bucuresti, nr. 2B bis,Balotesti, Jud Ilfov, RomaniaTELEMOBIL S.A.Calea Bucuresti, nr. 2B bis, Balotesti, Ilfov, Romania<br />ns1:	ns2.hi2.ro<br />ns2:	ns3.hi2.ro<br />ns3:	ns4.hi2.ro<br />ns4:	ns1.hi2.ro<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vlcplayer.info/t/pri_s10_UPX.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11058971</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicious file]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11058971</guid>
			<pubDate>2013-05-16T18:00:05+02:00</pubDate>
			<description><![CDATA[id:	11058971<br />first:	1368720005<br />last:	0<br />md5:	f1f2d871dc81312c5bb017561a52e8cc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f1f2d871dc81312c5bb017561a52e8cc<br />vt_score:	11/46 (23.9%)<br />scanner:	undef<br />virusname:	Suspicious file<br />url:	http://vlcplayer.info/t/pri_s10_UPX.exe<br />recent:	up<br />response:	alive<br />ip:	141.101.117.179<br />as:	AS13335<br />review:	141.101.117.179<br />domain:	vlcplayer.info<br />country:	EU<br />source:	RIPE<br />email:	<br />inetnum:	141.101.64.0 - 141.101.127.255<br />netname:	<br />descr:	<br />ns1:	cody.ns.cloudflare.com<br />ns2:	lisa.ns.cloudflare.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sapobxap.ru/rasta01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=11042135</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Kryptik.AXUE!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=11042135</guid>
			<pubDate>2013-05-16T09:40:06+02:00</pubDate>
			<description><![CDATA[id:	11042135<br />first:	1368690006<br />last:	0<br />md5:	cdc2cb572de7982395d22e4449d2b281<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cdc2cb572de7982395d22e4449d2b281<br />vt_score:	8/45 (17.8%)<br />scanner:	undef<br />virusname:	W32/Kryptik.AXUE!tr<br />url:	http://sapobxap.ru/rasta01.exe<br />recent:	up<br />response:	alive<br />ip:	176.103.208.136<br />as:	AS44884<br />review:	175.182.70.33<br />domain:	sapobxap.ru<br />country:	TW<br />source:	APNIC<br />email:	jonaschou@fareastone.com.tw<br />inetnum:	176.103.208.0 - 176.103.215.255<br />netname:	NCICNET-NET<br />descr:	New Century InfoComm Tech. Co., Ltd.1F~11F, No. 218, Rueiguang RoadTaipei Taiwan 114<br />ns1:	ns3.sapobxap.ru<br />ns2:	ns4.sapobxap.ru<br />ns3:	ns6.sapobxap.ru<br />ns4:	ns5.sapobxap.ru<br />ns5:	ns1.sapobxap.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fff.gsgsfs.cn/play.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10965594</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Hosts.dropper]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10965594</guid>
			<pubDate>2013-05-14T18:40:02+02:00</pubDate>
			<description><![CDATA[id:	10965594<br />first:	1368549602<br />last:	0<br />md5:	e4993d4fef2255e742301640f9f51574<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e4993d4fef2255e742301640f9f51574<br />vt_score:	14/46 (30.4%)<br />scanner:	undef<br />virusname:	Hosts.dropper<br />url:	http://fff.gsgsfs.cn/play.exe<br />recent:	up<br />response:	alive<br />ip:	199.193.67.243<br />as:	AS53935<br />review:	199.193.67.243<br />domain:	gsgsfs.cn<br />country:	US<br />source:	ARIN<br />email:	zoujinhe@ehostingusa.com<br />inetnum:	199.193.64.0 - 199.193.71.255<br />netname:	VPS21004<br />descr:	VPS21 LTD VL-11 38958 S FREMONT BLVD FREMONT CA 94536<br />ns1:	f1g1ns1.dnspod.net<br />ns2:	f1g1ns2.dnspod.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hk.sz181.com/images/c4a.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10919078</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10919078</guid>
			<pubDate>2013-05-13T21:40:02+02:00</pubDate>
			<description><![CDATA[id:	10919078<br />first:	1368474002<br />last:	0<br />md5:	b0ef2ab86f160aa416184c09df8388fe<br />virustotal:	<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://hk.sz181.com/images/c4a.jpg<br />recent:	up<br />response:	alive<br />ip:	202.155.223.21<br />as:	AS9381<br />review:	202.155.223.21<br />domain:	sz181.com<br />country:	HK<br />source:	APNIC<br />email:	abuse@wharftt.com<br />inetnum:	202.155.192.0 - 202.155.223.255<br />netname:	IPC-NEWTT<br />descr:	Wharf T&T LimitedHarbour City, Hong Kong SAR<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kachsurf.servepics.com/wmiupd.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10896608</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BAT/Dldr.Agent.D]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10896608</guid>
			<pubDate>2013-05-13T12:30:37+02:00</pubDate>
			<description><![CDATA[id:	10896608<br />first:	1368441037<br />last:	0<br />md5:	24e708128b5bc22ee0a494017a5bc5ab<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=24e708128b5bc22ee0a494017a5bc5ab<br />vt_score:	14/46 (30.4%)<br />scanner:	avira<br />virusname:	BAT/Dldr.Agent.D<br />url:	http://kachsurf.servepics.com/wmiupd.exe<br />recent:	up<br />response:	alive<br />ip:	94.228.201.117<br />as:	AS48293<br />review:	94.228.201.117<br />domain:	servepics.com<br />country:	RU<br />source:	RIPE<br />email:	ncc@union-tel.ru<br />inetnum:	94.228.192.0 - 94.228.207.255<br />netname:	RU-UNION-TEL-20081105<br />descr:	Uniontel ZAOKalininec-net<br />ns1:	nf3.no-ip.com<br />ns2:	nf5.no-ip.com<br />ns3:	nf2.no-ip.com<br />ns4:	nf1.no-ip.com<br />ns5:	nf4.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kachsurf.servepics.com/ifupd.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10896606</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10896606</guid>
			<pubDate>2013-05-13T12:30:37+02:00</pubDate>
			<description><![CDATA[id:	10896606<br />first:	1368441037<br />last:	0<br />md5:	e69cbe453b1c10651161e9e38c568167<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e69cbe453b1c10651161e9e38c568167<br />vt_score:	7/46 (15.2%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://kachsurf.servepics.com/ifupd.exe<br />recent:	up<br />response:	alive<br />ip:	94.228.201.117<br />as:	AS48293<br />review:	94.228.201.117<br />domain:	servepics.com<br />country:	RU<br />source:	RIPE<br />email:	ncc@union-tel.ru<br />inetnum:	94.228.192.0 - 94.228.207.255<br />netname:	RU-UNION-TEL-20081105<br />descr:	Uniontel ZAOKalininec-net<br />ns1:	nf3.no-ip.com<br />ns2:	nf5.no-ip.com<br />ns3:	nf2.no-ip.com<br />ns4:	nf1.no-ip.com<br />ns5:	nf4.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://182.18.128.254:8090/get/b2f7e9141eb124ce3152352c5df520f7.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10842303</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicious file]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10842303</guid>
			<pubDate>2013-05-11T11:01:13+02:00</pubDate>
			<description><![CDATA[id:	10842303<br />first:	1368262873<br />last:	0<br />md5:	df8471168ca8b86df77cf569626ba0bf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=df8471168ca8b86df77cf569626ba0bf<br />vt_score:	6/46 (13%)<br />scanner:	undef<br />virusname:	Suspicious file<br />url:	http://182.18.128.254:8090/get/b2f7e9141eb124ce3152352c5df520f7.exe<br />recent:	up<br />response:	alive<br />ip:	182.18.128.254<br />as:	AS18229<br />review:	182.18.128.254<br />domain:	182.18.128.254<br />country:	IN<br />source:	APNIC<br />email:	psridharreddy@hotmail.com<br />inetnum:	182.18.128.0 - 182.18.191.255<br />netname:	PIONEER_ELABS<br />descr:	Pioneer Elabs Ltd.7th Floor, Pioneer Towers,Plot No.16, APIIC Software Units Layout,Madhapur,CtrlSCtrlS IP Pools<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://irojtumy.ru/traff01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10813508</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10813508</guid>
			<pubDate>2013-05-10T16:00:05+02:00</pubDate>
			<description><![CDATA[id:	10813508<br />first:	1368194405<br />last:	0<br />md5:	ea21c9b116abac680064c09a1e849fd1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ea21c9b116abac680064c09a1e849fd1<br />vt_score:	10/44 (22.7%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://irojtumy.ru/traff01.exe<br />recent:	up<br />response:	alive<br />ip:	178.150.178.48<br />as:	AS13188<br />review:	210.203.202.190<br />domain:	irojtumy.ru<br />country:	JP<br />source:	APNIC<br />email:	hm-changed@apnic.net<br />inetnum:	178.150.0.0 - 178.151.255.255<br />netname:	QTNet<br />descr:	Kyushu Telecommunication Network Co.,Inc.1-12-20, Tenjin, Chuo-ku, Fukuoka-shi,810-0001, JapanKyushu Telecommunication Network Co.,Inc.<br />ns1:	ns1.irojtumy.ru<br />ns2:	ns5.irojtumy.ru<br />ns3:	ns6.irojtumy.ru<br />ns4:	ns4.irojtumy.ru<br />ns5:	ns3.irojtumy.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://irojtumy.ru/shem001.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10811481</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Kryptik.X!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10811481</guid>
			<pubDate>2013-05-10T15:40:16+02:00</pubDate>
			<description><![CDATA[id:	10811481<br />first:	1368193216<br />last:	0<br />md5:	922c8f1110304f68469d3575131b8f13<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=922c8f1110304f68469d3575131b8f13<br />vt_score:	10/46 (21.7%)<br />scanner:	undef<br />virusname:	W32/Kryptik.X!tr<br />url:	http://irojtumy.ru/shem001.exe<br />recent:	up<br />response:	alive<br />ip:	46.118.239.52<br />as:	AS12530<br />review:	178.151.45.128<br />domain:	irojtumy.ru<br />country:	UA<br />source:	RIPE<br />email:	lir@triolan.kiev.ua<br />inetnum:	46.118.0.0 - 46.119.255.255<br />netname:	UA-EDUNETWORKS-20100415<br />descr:	DC&BITRIOLANTriple Play ServicesUkraine<br />ns1:	ns1.irojtumy.ru<br />ns2:	ns4.irojtumy.ru<br />ns3:	ns5.irojtumy.ru<br />ns4:	ns2.irojtumy.ru<br />ns5:	ns6.irojtumy.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yxwnst.best.lt.ua/dlimage11.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10774251</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10774251</guid>
			<pubDate>2013-05-09T16:00:03+02:00</pubDate>
			<description><![CDATA[id:	10774251<br />first:	1368108003<br />last:	0<br />md5:	afe39019be4bb13bc854668f03a48780<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=afe39019be4bb13bc854668f03a48780<br />vt_score:	4/31 (12.9%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen<br />url:	http://yxwnst.best.lt.ua/dlimage11.php<br />recent:	up<br />response:	alive<br />ip:	188.190.124.151<br />as:	AS197145<br />review:	188.190.124.151<br />domain:	lt.ua<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	188.190.96.0 - 188.190.127.255<br />netname:	INFIUM<br />descr:	Infium LTD<br />ns1:	nix.ns.ua<br />ns2:	ns.vizor.lutsk.ua<br />ns3:	ns.cv.ua<br />ns4:	ns2.4grad.in.ua<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yxwnst.best.lt.ua/dlimage4.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10774250</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10774250</guid>
			<pubDate>2013-05-09T16:00:02+02:00</pubDate>
			<description><![CDATA[id:	10774250<br />first:	1368108002<br />last:	0<br />md5:	f9c5d63b4f9943f39427dda5bbfa96c9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f9c5d63b4f9943f39427dda5bbfa96c9<br />vt_score:	3/46 (6.5%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen<br />url:	http://yxwnst.best.lt.ua/dlimage4.php<br />recent:	up<br />response:	alive<br />ip:	188.190.124.151<br />as:	AS197145<br />review:	188.190.124.151<br />domain:	lt.ua<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	188.190.96.0 - 188.190.127.255<br />netname:	INFIUM<br />descr:	Infium LTD<br />ns1:	nix.ns.ua<br />ns2:	ns.vizor.lutsk.ua<br />ns3:	ns.cv.ua<br />ns4:	ns2.4grad.in.ua<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://najobbar.ru/traff01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10772641</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10772641</guid>
			<pubDate>2013-05-09T15:00:02+02:00</pubDate>
			<description><![CDATA[id:	10772641<br />first:	1368104402<br />last:	0<br />md5:	402dc9182f03889ceb74e4f1b55fc314<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=402dc9182f03889ceb74e4f1b55fc314<br />vt_score:	12/46 (26.1%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://najobbar.ru/traff01.exe<br />recent:	up<br />response:	alive<br />ip:	195.128.231.18<br />as:	AS33657<br />review:	188.231.172.95<br />domain:	najobbar.ru<br />country:	UA<br />source:	RIPE<br />email:	ripe@o3.ua<br />inetnum:	195.128.230.0 - 195.128.231.255<br />netname:	FREENET<br />descr:	Fiber Optic IP NetworkFREENETFREENETFREENET<br />ns1:	ns3.najobbar.ru<br />ns2:	ns1.najobbar.ru<br />ns3:	ns6.najobbar.ru<br />ns4:	ns2.najobbar.ru<br />ns5:	ns5.najobbar.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yhbixpub.ru/traff01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10746634</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10746634</guid>
			<pubDate>2013-05-08T17:40:11+02:00</pubDate>
			<description><![CDATA[id:	10746634<br />first:	1368027611<br />last:	0<br />md5:	f223fa2b03a1815719767d5a42e06373<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f223fa2b03a1815719767d5a42e06373<br />vt_score:	9/46 (19.6%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://yhbixpub.ru/traff01.exe<br />recent:	up<br />response:	alive<br />ip:	109.254.51.237<br />as:	AS20590<br />review:	77.121.78.151<br />domain:	yhbixpub.ru<br />country:	UA<br />source:	RIPE<br />email:	abuse@volia.net<br />inetnum:	109.254.0.0 - 109.254.255.255<br />netname:	VOLIA<br />descr:	Volia SubnetVolia Network primary routeVolia more specific route<br />ns1:	ns5.yhbixpub.ru<br />ns2:	ns2.yhbixpub.ru<br />ns3:	ns3.yhbixpub.ru<br />ns4:	ns4.yhbixpub.ru<br />ns5:	ns1.yhbixpub.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://be-created.com/img/Pony.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10734758</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trj/CI.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10734758</guid>
			<pubDate>2013-05-08T12:00:05+02:00</pubDate>
			<description><![CDATA[id:	10734758<br />first:	1368007205<br />last:	0<br />md5:	ae8461594610add30a947dbff6c6952b<br />virustotal:	<br />vt_score:	23/46 (50%)<br />scanner:	undef<br />virusname:	Trj/CI.A<br />url:	http://be-created.com/img/Pony.exe<br />recent:	up<br />response:	alive<br />ip:	94.23.45.68<br />as:	AS16276<br />review:	94.23.45.68<br />domain:	be-created.com<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	94.23.0.0 - 94.23.63.255<br />netname:	OVH<br />descr:	OVH SASDedicated Servershttp<br />ns1:	dns1.e-clicking.in<br />ns2:	dns2.e-clicking.in<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://svses.cz/prenos/second.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10734757</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Symmi.18614]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10734757</guid>
			<pubDate>2013-05-08T12:00:03+02:00</pubDate>
			<description><![CDATA[id:	10734757<br />first:	1368007203<br />last:	0<br />md5:	020dfb3861516fbe2819c39f1b18919d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=020dfb3861516fbe2819c39f1b18919d<br />vt_score:	12/45 (26.7%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Symmi.18614<br />url:	http://svses.cz/prenos/second.exe<br />recent:	up<br />response:	alive<br />ip:	83.136.204.202<br />as:	AS39408<br />review:	83.136.204.202<br />domain:	svses.cz<br />country:	CZ<br />source:	RIPE<br />email:	register@avi.cz<br />inetnum:	83.136.200.0 - 83.136.207.255<br />netname:	CZ-ETHERNET-20040402<br />descr:	AVI druzstvoProvider Local RegistryAVI<br />ns1:	dns.ethernet.cz<br />ns2:	ns.ethernet.cz<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://209.190.56.26/41/movie1080p.mkv.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10734192</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.FakeAV]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10734192</guid>
			<pubDate>2013-05-08T11:00:04+02:00</pubDate>
			<description><![CDATA[id:	10734192<br />first:	1368003604<br />last:	0<br />md5:	946718d1dbd4f80af0d55153889bb1d7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=946718d1dbd4f80af0d55153889bb1d7<br />vt_score:	26/35 (74.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.FakeAV<br />url:	http://209.190.56.26/41/movie1080p.mkv.exe<br />recent:	up<br />response:	alive<br />ip:	209.190.56.26<br />as:	AS10297<br />review:	209.190.56.26<br />domain:	209.190.56.26<br />country:	US<br />source:	ARIN<br />email:	abuse@ee.net<br />inetnum:	209.190.0.0 - 209.190.127.255<br />netname:	ENET-XLHOST<br />descr:	eNET Inc. ENET 3000 East Dublin Granville Rd. Columbus OH 43231<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://209.190.56.26/40/movie1080p.mkv.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10734191</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Agent/Gen-MalPE]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10734191</guid>
			<pubDate>2013-05-08T11:00:04+02:00</pubDate>
			<description><![CDATA[id:	10734191<br />first:	1368003604<br />last:	0<br />md5:	df9a6f131f652174f55ccfd9e38ec105<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=df9a6f131f652174f55ccfd9e38ec105<br />vt_score:	6/46 (13%)<br />scanner:	undef<br />virusname:	Trojan.Agent/Gen-MalPE<br />url:	http://209.190.56.26/40/movie1080p.mkv.exe<br />recent:	up<br />response:	alive<br />ip:	209.190.56.26<br />as:	AS10297<br />review:	209.190.56.26<br />domain:	209.190.56.26<br />country:	US<br />source:	ARIN<br />email:	abuse@ee.net<br />inetnum:	209.190.0.0 - 209.190.127.255<br />netname:	ENET-XLHOST<br />descr:	eNET Inc. ENET 3000 East Dublin Granville Rd. Columbus OH 43231<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rashmm.best.volyn.ua/dlimage4.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10734035</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10734035</guid>
			<pubDate>2013-05-08T10:40:04+02:00</pubDate>
			<description><![CDATA[id:	10734035<br />first:	1368002404<br />last:	0<br />md5:	c7abe30931d7f2bb4f46952ebda516b3<br />virustotal:	<br />vt_score:	3/46 (6.5%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen<br />url:	http://rashmm.best.volyn.ua/dlimage4.php<br />recent:	up<br />response:	alive<br />ip:	188.190.124.151<br />as:	AS197145<br />review:	188.190.124.151<br />domain:	volyn.ua<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	188.190.96.0 - 188.190.127.255<br />netname:	INFIUM<br />descr:	Infium LTD<br />ns1:	ns2.4grad.in.ua<br />ns2:	ns.vizor.lutsk.ua<br />ns3:	nix.ns.ua<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://snakesforever.com/images/Pony.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10733162</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trj/CI.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10733162</guid>
			<pubDate>2013-05-08T08:50:04+02:00</pubDate>
			<description><![CDATA[id:	10733162<br />first:	1367995804<br />last:	0<br />md5:	ae8461594610add30a947dbff6c6952b<br />virustotal:	<br />vt_score:	23/46 (50%)<br />scanner:	undef<br />virusname:	Trj/CI.A<br />url:	http://snakesforever.com/images/Pony.exe<br />recent:	up<br />response:	alive<br />ip:	94.23.45.68<br />as:	AS16276<br />review:	94.23.45.68<br />domain:	snakesforever.com<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	94.23.0.0 - 94.23.63.255<br />netname:	OVH<br />descr:	OVH SASDedicated Servershttp<br />ns1:	dns2.e-clicking.in<br />ns2:	dns1.e-clicking.in<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.asc-360.com/zt6a71HZ.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10733161</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Kryptik.AGAJ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10733161</guid>
			<pubDate>2013-05-08T08:50:04+02:00</pubDate>
			<description><![CDATA[id:	10733161<br />first:	1367995804<br />last:	0<br />md5:	7fae49d5fbfea54c3468b1f2caf72ea8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7fae49d5fbfea54c3468b1f2caf72ea8<br />vt_score:	9/39 (23.1%)<br />scanner:	undef<br />virusname:	W32/Kryptik.AGAJ!tr<br />url:	http://www.asc-360.com/zt6a71HZ.exe<br />recent:	up<br />response:	alive<br />ip:	88.191.79.37<br />as:	AS12322<br />review:	88.191.79.37<br />domain:	asc-360.com<br />country:	FR<br />source:	RIPE<br />email:	abuse@support.dedibox.fr<br />inetnum:	88.191.3.0 - 88.191.129.255<br />netname:	FR-DEDIBOX<br />descr:	Dedibox SASCustomersParis, FranceNCC#2007023902ProXad network / Free SASParis, France<br />ns1:	ns2.directnom.com<br />ns2:	ns.directnom.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.vernaison.fr/media/media/images/Protesto.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10716575</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trj/Genetic.gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10716575</guid>
			<pubDate>2013-05-07T15:40:21+02:00</pubDate>
			<description><![CDATA[id:	10716575<br />first:	1367934021<br />last:	0<br />md5:	10a95ac129f619d858f419d670bc0bfe<br />virustotal:	<br />vt_score:	13/46 (28.3%)<br />scanner:	undef<br />virusname:	Trj/Genetic.gen<br />url:	http://www.vernaison.fr/media/media/images/Protesto.exe<br />recent:	up<br />response:	alive<br />ip:	46.105.38.50<br />as:	AS16276<br />review:	46.105.38.50<br />domain:	vernaison.fr<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	46.105.32.0 - 46.105.63.255<br />netname:	OVH<br />descr:	OVH SASdedicated servershttp<br />ns1:	ns1.axs-fr.net<br />ns2:	ns2.axs-fr.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://virginx.free.fr/Money_Attractor_Ultrate_pywaie.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10707858</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[SPR/Tool.899839]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10707858</guid>
			<pubDate>2013-05-06T23:40:55+02:00</pubDate>
			<description><![CDATA[id:	10707858<br />first:	1367876455<br />last:	0<br />md5:	3cace8e57d25a6a0b01c7b619b334697<br />virustotal:	<br />vt_score:	10/46 (21.7%)<br />scanner:	avira<br />virusname:	SPR/Tool.899839<br />url:	http://virginx.free.fr/Money_Attractor_Ultrate_pywaie.exe<br />recent:	up<br />response:	alive<br />ip:	212.27.63.111<br />as:	AS12322<br />review:	212.27.63.111<br />domain:	free.fr<br />country:	FR<br />source:	RIPE<br />email:	abuse@proxad.net<br />inetnum:	212.27.60.0 - 212.27.63.255<br />netname:	FR-PROXAD<br />descr:	Free SAS (ProXad)internal infrastructure (servers)Paris, FranceProXad network / Free SAParis, France<br />ns1:	freens1-g20.free.fr<br />ns2:	freens2-g20.free.fr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://betabros.com/c/Crypted.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10678068</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.GenericKDZ.16544]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10678068</guid>
			<pubDate>2013-05-05T17:00:03+02:00</pubDate>
			<description><![CDATA[id:	10678068<br />first:	1367766003<br />last:	0<br />md5:	13b55725de38fbe6647077fb8db914bf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=13b55725de38fbe6647077fb8db914bf<br />vt_score:	7/35 (20%)<br />scanner:	BitDefender<br />virusname:	Trojan.GenericKDZ.16544<br />url:	http://betabros.com/c/Crypted.exe<br />recent:	up<br />response:	alive<br />ip:	146.0.78.4<br />as:	AS57043<br />review:	146.0.78.4<br />domain:	betabros.com<br />country:	NL<br />source:	RIPE<br />email:	<br />inetnum:	146.0.72.0 - 146.0.79.255<br />netname:	<br />descr:	<br />ns1:	ns1.ipchina163.com<br />ns2:	ns2.ipchina163.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://betabros.com/c/disfiguredslush.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10678067</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicious file]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10678067</guid>
			<pubDate>2013-05-05T17:00:02+02:00</pubDate>
			<description><![CDATA[id:	10678067<br />first:	1367766002<br />last:	0<br />md5:	265e19300f007215ffbdde0f8f2c7245<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=265e19300f007215ffbdde0f8f2c7245<br />vt_score:	12/46 (26.1%)<br />scanner:	undef<br />virusname:	Suspicious file<br />url:	http://betabros.com/c/disfiguredslush.exe<br />recent:	up<br />response:	alive<br />ip:	146.0.78.4<br />as:	AS57043<br />review:	146.0.78.4<br />domain:	betabros.com<br />country:	NL<br />source:	RIPE<br />email:	<br />inetnum:	146.0.72.0 - 146.0.79.255<br />netname:	<br />descr:	<br />ns1:	ns1.ipchina163.com<br />ns2:	ns2.ipchina163.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gvdlqk.best.lt.ua/dlimage4.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10622257</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10622257</guid>
			<pubDate>2013-05-03T11:10:05+02:00</pubDate>
			<description><![CDATA[id:	10622257<br />first:	1367572205<br />last:	0<br />md5:	11ecc19500e80623e948a803a97d0550<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=11ecc19500e80623e948a803a97d0550<br />vt_score:	5/46 (10.9%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen2<br />url:	http://gvdlqk.best.lt.ua/dlimage4.php<br />recent:	up<br />response:	alive<br />ip:	188.190.124.151<br />as:	AS197145<br />review:	188.190.124.151<br />domain:	lt.ua<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	188.190.96.0 - 188.190.127.255<br />netname:	INFIUM<br />descr:	Infium LTD<br />ns1:	ns.vizor.lutsk.ua<br />ns2:	nix.ns.ua<br />ns3:	ns.cv.ua<br />ns4:	ns2.4grad.in.ua<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gvdlqk.best.lt.ua/dlimage11.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10622256</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10622256</guid>
			<pubDate>2013-05-03T11:10:05+02:00</pubDate>
			<description><![CDATA[id:	10622256<br />first:	1367572205<br />last:	0<br />md5:	0fe4fa36e7ce25e9cb7c227cf02960f9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0fe4fa36e7ce25e9cb7c227cf02960f9<br />vt_score:	5/46 (10.9%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen2<br />url:	http://gvdlqk.best.lt.ua/dlimage11.php<br />recent:	up<br />response:	alive<br />ip:	188.190.124.151<br />as:	AS197145<br />review:	188.190.124.151<br />domain:	lt.ua<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	188.190.96.0 - 188.190.127.255<br />netname:	INFIUM<br />descr:	Infium LTD<br />ns1:	ns.vizor.lutsk.ua<br />ns2:	nix.ns.ua<br />ns3:	ns.cv.ua<br />ns4:	ns2.4grad.in.ua<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://najobbar.ru/rasta01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10622254</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Kryptik.AGAJ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10622254</guid>
			<pubDate>2013-05-03T10:40:04+02:00</pubDate>
			<description><![CDATA[id:	10622254<br />first:	1367570404<br />last:	0<br />md5:	ff1317a44c9c3dd377c43dd47d300487<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ff1317a44c9c3dd377c43dd47d300487<br />vt_score:	20/46 (43.5%)<br />scanner:	undef<br />virusname:	W32/Kryptik.AGAJ!tr<br />url:	http://najobbar.ru/rasta01.exe<br />recent:	up<br />response:	alive<br />ip:	176.109.9.4<br />as:	AS57847<br />review:	89.28.117.143<br />domain:	najobbar.ru<br />country:	MD<br />source:	RIPE<br />email:	abuse@starnet.md<br />inetnum:	176.109.8.0 - 176.109.15.255<br />netname:	MD-STARNET-20060629<br />descr:	STARNET S.R.L<br />ns1:	ns5.najobbar.ru<br />ns2:	ns1.najobbar.ru<br />ns3:	ns4.najobbar.ru<br />ns4:	ns6.najobbar.ru<br />ns5:	ns2.najobbar.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://najobbar.ru/shem001.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10622252</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.FakeAV]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10622252</guid>
			<pubDate>2013-05-03T10:40:04+02:00</pubDate>
			<description><![CDATA[id:	10622252<br />first:	1367570404<br />last:	0<br />md5:	597ed2eddf14045b343c74bb55bb299a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=597ed2eddf14045b343c74bb55bb299a<br />vt_score:	14/35 (40%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.FakeAV<br />url:	http://najobbar.ru/shem001.exe<br />recent:	up<br />response:	alive<br />ip:	81.21.14.61<br />as:	AS24896<br />review:	178.137.182.204<br />domain:	najobbar.ru<br />country:	UA<br />source:	RIPE<br />email:	noc@kyivstar.net<br />inetnum:	81.21.8.0 - 81.21.15.255<br />netname:	KYIVSTAR-NET-8<br />descr:	Kyivstar GSMUkrainian mobile phone operatorKyivstar GSM, Kiev, UkraineKyivstar GSM, Kiev, Ukraine<br />ns1:	ns5.najobbar.ru<br />ns2:	ns1.najobbar.ru<br />ns3:	ns4.najobbar.ru<br />ns4:	ns6.najobbar.ru<br />ns5:	ns2.najobbar.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://looserbalance.com/40/movie1080p.mkv.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10617395</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Heur.Packed.Unknown]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10617395</guid>
			<pubDate>2013-05-02T19:02:56+02:00</pubDate>
			<description><![CDATA[id:	10617395<br />first:	1367514176<br />last:	0<br />md5:	3656ff526d8851810458271ee13ab990<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3656ff526d8851810458271ee13ab990<br />vt_score:	7/46 (15.2%)<br />scanner:	undef<br />virusname:	Heur.Packed.Unknown<br />url:	http://looserbalance.com/40/movie1080p.mkv.exe<br />recent:	up<br />response:	alive<br />ip:	209.190.56.26<br />as:	AS10297<br />review:	209.190.56.26<br />domain:	looserbalance.com<br />country:	US<br />source:	ARIN<br />email:	abuse@ee.net<br />inetnum:	209.190.0.0 - 209.190.127.255<br />netname:	ENET-XLHOST<br />descr:	eNET Inc. ENET 3000 East Dublin Granville Rd. Columbus OH 43231<br />ns1:	ns2.modesitsweets.com<br />ns2:	ns1.modesitsweets.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://buyersindex.com/neting/wsnilyxs.gif]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10616674</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.Banker.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10616674</guid>
			<pubDate>2013-05-02T18:05:02+02:00</pubDate>
			<description><![CDATA[id:	10616674<br />first:	1367510702<br />last:	0<br />md5:	74cb3764a4cbf5da23e8fca6be6b6663<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=74cb3764a4cbf5da23e8fca6be6b6663<br />vt_score:	8/35 (22.9%)<br />scanner:	AntiVir<br />virusname:	TR/Spy.Banker.Gen<br />url:	http://buyersindex.com/neting/wsnilyxs.gif<br />recent:	up<br />response:	alive<br />ip:	64.150.180.144<br />as:	AS10316<br />review:	64.150.180.144<br />domain:	buyersindex.com<br />country:	US<br />source:	ARIN<br />email:	abuse@codero.com<br />inetnum:	64.150.176.0 - 64.150.191.255<br />netname:	CODERO2008A<br />descr:	Codero APHIN 7500 W 110th St., Suite 400 Overland Park KS 66210<br />ns1:	ns51.1and1.com<br />ns2:	ns52.1and1.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.trucdefoupoto.com/AdobeFlashPlayer.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10604246</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Bck/IrcBrute.M]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10604246</guid>
			<pubDate>2013-05-02T11:00:09+02:00</pubDate>
			<description><![CDATA[id:	10604246<br />first:	1367485209<br />last:	0<br />md5:	77bd66cbeddc84bb9f6ef3f63244e865<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=77bd66cbeddc84bb9f6ef3f63244e865<br />vt_score:	30/45 (66.7%)<br />scanner:	undef<br />virusname:	Bck/IrcBrute.M<br />url:	http://www.trucdefoupoto.com/AdobeFlashPlayer.exe<br />recent:	up<br />response:	alive<br />ip:	212.1.212.8<br />as:	AS47583<br />review:	212.1.212.8<br />domain:	trucdefoupoto.com<br />country:	US<br />source:	RIPE<br />email:	abuse@main-hosting.com<br />inetnum:	212.1.212.0 - 212.1.215.255<br />netname:	HOSTING24<br />descr:	HOSTING24 Servers<br />ns1:	ns112.hosting24.com<br />ns2:	ns111.hosting24.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.trucdefoupoto.com/cam.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10604245</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Bck/IrcBrute.M]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10604245</guid>
			<pubDate>2013-05-02T11:00:09+02:00</pubDate>
			<description><![CDATA[id:	10604245<br />first:	1367485209<br />last:	0<br />md5:	77bd66cbeddc84bb9f6ef3f63244e865<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=77bd66cbeddc84bb9f6ef3f63244e865<br />vt_score:	30/45 (66.7%)<br />scanner:	undef<br />virusname:	Bck/IrcBrute.M<br />url:	http://www.trucdefoupoto.com/cam.exe<br />recent:	up<br />response:	alive<br />ip:	212.1.212.8<br />as:	AS47583<br />review:	212.1.212.8<br />domain:	trucdefoupoto.com<br />country:	US<br />source:	RIPE<br />email:	abuse@main-hosting.com<br />inetnum:	212.1.212.0 - 212.1.215.255<br />netname:	HOSTING24<br />descr:	HOSTING24 Servers<br />ns1:	ns112.hosting24.com<br />ns2:	ns111.hosting24.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://jahbob3.free.fr/server.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10579105</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Smal.axb.14]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10579105</guid>
			<pubDate>2013-05-01T14:40:10+02:00</pubDate>
			<description><![CDATA[id:	10579105<br />first:	1367412010<br />last:	0<br />md5:	1c26f23584064927010c45860f5bafa4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1c26f23584064927010c45860f5bafa4<br />vt_score:	42/46 (91.3%)<br />scanner:	avira<br />virusname:	TR/Dldr.Smal.axb.14<br />url:	http://jahbob3.free.fr/server.exe<br />recent:	up<br />response:	alive<br />ip:	212.27.63.171<br />as:	AS12322<br />review:	212.27.63.171<br />domain:	free.fr<br />country:	FR<br />source:	RIPE<br />email:	abuse@proxad.net<br />inetnum:	212.27.60.0 - 212.27.63.255<br />netname:	FR-PROXAD<br />descr:	Free SAS (ProXad)internal infrastructure (servers)Paris, FranceProXad network / Free SAParis, France<br />ns1:	freens1-g20.free.fr<br />ns2:	freens2-g20.free.fr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wienold.kilu.de/gXSXcV.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10576632</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trj/Tepfer.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10576632</guid>
			<pubDate>2013-05-01T12:00:04+02:00</pubDate>
			<description><![CDATA[id:	10576632<br />first:	1367402404<br />last:	0<br />md5:	aa4006ea7e8806e659d7220051935117<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=aa4006ea7e8806e659d7220051935117<br />vt_score:	25/46 (54.3%)<br />scanner:	undef<br />virusname:	Trj/Tepfer.B<br />url:	http://wienold.kilu.de/gXSXcV.exe<br />recent:	up<br />response:	alive<br />ip:	5.9.50.42<br />as:	AS24940<br />review:	5.9.50.42<br />domain:	kilu.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@hetzner.de<br />inetnum:	5.9.0.0 - 5.9.255.255<br />netname:	DE-HETZNER-20120425<br />descr:	Hetzner Online AG<br />ns1:	ns2.subdomain.com<br />ns2:	ns1.subdomain.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mbcwtg.best.volyn.ua/dlimage11.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10576631</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10576631</guid>
			<pubDate>2013-05-01T12:00:03+02:00</pubDate>
			<description><![CDATA[id:	10576631<br />first:	1367402403<br />last:	0<br />md5:	5c0f6a64881669aa2278269c8fbeb4bf<br />virustotal:	<br />vt_score:	5/45 (11.1%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen<br />url:	http://mbcwtg.best.volyn.ua/dlimage11.php<br />recent:	up<br />response:	alive<br />ip:	94.242.250.151<br />as:	AS5577<br />review:	94.242.250.151<br />domain:	volyn.ua<br />country:	LU<br />source:	RIPE<br />email:	abuse@as5577.net<br />inetnum:	94.242.224.0 - 94.242.255.255<br />netname:	SERVER-NETWORK<br />descr:	root SA<br />ns1:	ns.vizor.lutsk.ua<br />ns2:	ns2.4grad.in.ua<br />ns3:	nix.ns.ua<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mbcwtg.best.volyn.ua/dlimage4.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10576630</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan-Dropper.Win32.Dorifel.adhf]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10576630</guid>
			<pubDate>2013-05-01T12:00:03+02:00</pubDate>
			<description><![CDATA[id:	10576630<br />first:	1367402403<br />last:	0<br />md5:	66c100d465dc29d1ac99ee0637b4e764<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=66c100d465dc29d1ac99ee0637b4e764<br />vt_score:	16/46 (34.8%)<br />scanner:	Kaspersky<br />virusname:	Trojan-Dropper.Win32.Dorifel.adhf<br />url:	http://mbcwtg.best.volyn.ua/dlimage4.php<br />recent:	up<br />response:	alive<br />ip:	94.242.250.151<br />as:	AS5577<br />review:	94.242.250.151<br />domain:	volyn.ua<br />country:	LU<br />source:	RIPE<br />email:	abuse@as5577.net<br />inetnum:	94.242.224.0 - 94.242.255.255<br />netname:	SERVER-NETWORK<br />descr:	root SA<br />ns1:	ns.vizor.lutsk.ua<br />ns2:	ns2.4grad.in.ua<br />ns3:	nix.ns.ua<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yhbixpub.ru/shem001.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10573652</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Kazy.169324]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10573652</guid>
			<pubDate>2013-05-01T10:00:10+02:00</pubDate>
			<description><![CDATA[id:	10573652<br />first:	1367395210<br />last:	0<br />md5:	f81cc6c36c4336e3c8cccddb9bfec383<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f81cc6c36c4336e3c8cccddb9bfec383<br />vt_score:	9/35 (25.7%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Kazy.169324<br />url:	http://yhbixpub.ru/shem001.exe<br />recent:	up<br />response:	alive<br />ip:	79.139.2.99<br />as:	AS5617<br />review:	180.176.74.58<br />domain:	yhbixpub.ru<br />country:	TW<br />source:	APNIC<br />email:	ho.ch@kbro.com.tw<br />inetnum:	79.139.0.0 - 79.139.7.255<br />netname:	TUNGHO-NET<br />descr:	kbro CO. Ltd.Taipei City Taiwan<br />ns1:	ns4.yhbixpub.ru<br />ns2:	ns2.yhbixpub.ru<br />ns3:	ns1.yhbixpub.ru<br />ns4:	ns3.yhbixpub.ru<br />ns5:	ns6.yhbixpub.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yhbixpub.ru/rasta01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10573361</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.169324.104]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10573361</guid>
			<pubDate>2013-05-01T09:40:07+02:00</pubDate>
			<description><![CDATA[id:	10573361<br />first:	1367394007<br />last:	0<br />md5:	ce82a65ee948a4d0edbadf178ef0b26f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ce82a65ee948a4d0edbadf178ef0b26f<br />vt_score:	24/45 (53.3%)<br />scanner:	AntiVir<br />virusname:	TR/Kazy.169324.104<br />url:	http://yhbixpub.ru/rasta01.exe<br />recent:	up<br />response:	alive<br />ip:	109.87.28.162<br />as:	AS13188<br />review:	46.118.42.228<br />domain:	yhbixpub.ru<br />country:	UA<br />source:	RIPE<br />email:	security@svitonline.com<br />inetnum:	109.86.0.0 - 109.87.255.255<br />netname:	UA-SVITONLINE-20100517<br />descr:	GoldenTelecom LLC<br />ns1:	ns3.yhbixpub.ru<br />ns2:	ns2.yhbixpub.ru<br />ns3:	ns4.yhbixpub.ru<br />ns4:	ns1.yhbixpub.ru<br />ns5:	ns5.yhbixpub.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://200.98.200.112/Pluss/capst.png]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10557712</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicious file]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10557712</guid>
			<pubDate>2013-04-30T20:00:24+02:00</pubDate>
			<description><![CDATA[id:	10557712<br />first:	1367344824<br />last:	0<br />md5:	7df21215e49f638d90a53b84a2a670a3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7df21215e49f638d90a53b84a2a670a3<br />vt_score:	17/46 (37%)<br />scanner:	undef<br />virusname:	Suspicious file<br />url:	http://200.98.200.112/Pluss/capst.png<br />recent:	up<br />response:	alive<br />ip:	200.98.200.112<br />as:	AS15201<br />review:	200.98.200.112<br />domain:	200.98.200.112<br />country:	BR<br />source:	LACNIC<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	200.98.0.0 - 200.98.255.255<br />netname:	001.109.184/0001-95<br />descr:	Universo Online S.A.<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://200.98.200.112/Pluss/Plancton.png]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10557711</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trj/CI.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10557711</guid>
			<pubDate>2013-04-30T20:00:23+02:00</pubDate>
			<description><![CDATA[id:	10557711<br />first:	1367344823<br />last:	0<br />md5:	559ed2cbc8b196cf83cd041a8050e859<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=559ed2cbc8b196cf83cd041a8050e859<br />vt_score:	21/46 (45.7%)<br />scanner:	undef<br />virusname:	Trj/CI.A<br />url:	http://200.98.200.112/Pluss/Plancton.png<br />recent:	up<br />response:	alive<br />ip:	200.98.200.112<br />as:	AS15201<br />review:	200.98.200.112<br />domain:	200.98.200.112<br />country:	BR<br />source:	LACNIC<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	200.98.0.0 - 200.98.255.255<br />netname:	001.109.184/0001-95<br />descr:	Universo Online S.A.<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://94.242.198.64/sky.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10557367</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10557367</guid>
			<pubDate>2013-04-30T19:40:05+02:00</pubDate>
			<description><![CDATA[id:	10557367<br />first:	1367343605<br />last:	0<br />md5:	f793e43be6e4226c8d6bd1c2a2abbf1f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f793e43be6e4226c8d6bd1c2a2abbf1f<br />vt_score:	11/35 (31.4%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://94.242.198.64/sky.exe<br />recent:	up<br />response:	alive<br />ip:	94.242.198.64<br />as:	AS5577<br />review:	94.242.198.64<br />domain:	94.242.198.64<br />country:	LU<br />source:	RIPE<br />email:	abuse@as5577.net<br />inetnum:	94.242.192.0 - 94.242.223.255<br />netname:	ROOT-NETWORK<br />descr:	root SA<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://s02.cba.pl/supermario.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10549921</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.GenericKDZ.16085]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10549921</guid>
			<pubDate>2013-04-30T15:40:13+02:00</pubDate>
			<description><![CDATA[id:	10549921<br />first:	1367329213<br />last:	0<br />md5:	cbd6f7307faf71e0cd63a1ed57f89db9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cbd6f7307faf71e0cd63a1ed57f89db9<br />vt_score:	15/46 (32.6%)<br />scanner:	undef<br />virusname:	Trojan.GenericKDZ.16085<br />url:	http://s02.cba.pl/supermario.exe<br />recent:	up<br />response:	alive<br />ip:	95.211.144.87<br />as:	AS16265<br />review:	95.211.144.87<br />domain:	cba.pl<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.cba.pl<br />ns2:	ns2.cba.pl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://txpdna.best.lt.ua/image.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10548926</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10548926</guid>
			<pubDate>2013-04-30T15:00:49+02:00</pubDate>
			<description><![CDATA[id:	10548926<br />first:	1367326849<br />last:	0<br />md5:	5c0f6a64881669aa2278269c8fbeb4bf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5c0f6a64881669aa2278269c8fbeb4bf<br />vt_score:	5/45 (11.1%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen<br />url:	http://txpdna.best.lt.ua/image.php<br />recent:	up<br />response:	alive<br />ip:	94.242.250.150<br />as:	AS5577<br />review:	94.242.250.150<br />domain:	lt.ua<br />country:	LU<br />source:	RIPE<br />email:	abuse@as5577.net<br />inetnum:	94.242.224.0 - 94.242.255.255<br />netname:	SERVER-NETWORK<br />descr:	root SA<br />ns1:	ns2.4grad.in.ua<br />ns2:	nix.ns.ua<br />ns3:	ns.vizor.lutsk.ua<br />ns4:	ns.cv.ua<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://txpdna.best.lt.ua/com.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10548925</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10548925</guid>
			<pubDate>2013-04-30T15:00:49+02:00</pubDate>
			<description><![CDATA[id:	10548925<br />first:	1367326849<br />last:	0<br />md5:	3a41d9f9b4e108ab6098fb45780dc7d6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3a41d9f9b4e108ab6098fb45780dc7d6<br />vt_score:	5/46 (10.9%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen<br />url:	http://txpdna.best.lt.ua/com.php<br />recent:	up<br />response:	alive<br />ip:	94.242.250.150<br />as:	AS5577<br />review:	94.242.250.150<br />domain:	lt.ua<br />country:	LU<br />source:	RIPE<br />email:	abuse@as5577.net<br />inetnum:	94.242.224.0 - 94.242.255.255<br />netname:	SERVER-NETWORK<br />descr:	root SA<br />ns1:	ns2.4grad.in.ua<br />ns2:	nix.ns.ua<br />ns3:	ns.vizor.lutsk.ua<br />ns4:	ns.cv.ua<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://txpdna.best.lt.ua/dlimage11.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10548924</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10548924</guid>
			<pubDate>2013-04-30T15:00:49+02:00</pubDate>
			<description><![CDATA[id:	10548924<br />first:	1367326849<br />last:	0<br />md5:	5c0f6a64881669aa2278269c8fbeb4bf<br />virustotal:	<br />vt_score:	5/45 (11.1%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen<br />url:	http://txpdna.best.lt.ua/dlimage11.php<br />recent:	up<br />response:	alive<br />ip:	94.242.250.150<br />as:	AS5577<br />review:	94.242.250.150<br />domain:	lt.ua<br />country:	LU<br />source:	RIPE<br />email:	abuse@as5577.net<br />inetnum:	94.242.224.0 - 94.242.255.255<br />netname:	SERVER-NETWORK<br />descr:	root SA<br />ns1:	ns2.4grad.in.ua<br />ns2:	nix.ns.ua<br />ns3:	ns.vizor.lutsk.ua<br />ns4:	ns.cv.ua<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://zalil.ru/34419309/1bf9e2a4.51805a38/XboxLiveGTIP.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10548819</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.VB.Gen8]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10548819</guid>
			<pubDate>2013-04-30T14:40:44+02:00</pubDate>
			<description><![CDATA[id:	10548819<br />first:	1367325644<br />last:	0<br />md5:	0f83ef1279a454272f17508f8f77ec5e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0f83ef1279a454272f17508f8f77ec5e<br />vt_score:	16/35 (45.7%)<br />scanner:	AntiVir<br />virusname:	TR/Dropper.VB.Gen8<br />url:	http://zalil.ru/34419309/1bf9e2a4.51805a38/XboxLiveGTIP.exe<br />recent:	up<br />response:	alive<br />ip:	194.63.142.66<br />as:	AS21011<br />review:	194.63.142.66<br />domain:	zalil.ru<br />country:	RU<br />source:	RIPE<br />email:	tech@mirotel.net<br />inetnum:	194.63.140.0 - 194.63.143.255<br />netname:	MIROTEL2<br />descr:	ITS Mirotel<br />ns1:	ns8-l2.nic.ru<br />ns2:	ns4-cloud.nic.ru<br />ns3:	ns3-l2.nic.ru<br />ns4:	ns8-cloud.nic.ru<br />ns5:	ns4-l2.nic.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://txpdna.best.lt.ua/dlimage4.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10548818</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10548818</guid>
			<pubDate>2013-04-30T14:40:44+02:00</pubDate>
			<description><![CDATA[id:	10548818<br />first:	1367325644<br />last:	0<br />md5:	3a41d9f9b4e108ab6098fb45780dc7d6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3a41d9f9b4e108ab6098fb45780dc7d6<br />vt_score:	5/46 (10.9%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen<br />url:	http://txpdna.best.lt.ua/dlimage4.php<br />recent:	up<br />response:	alive<br />ip:	94.242.250.150<br />as:	AS5577<br />review:	94.242.250.150<br />domain:	lt.ua<br />country:	LU<br />source:	RIPE<br />email:	abuse@as5577.net<br />inetnum:	94.242.224.0 - 94.242.255.255<br />netname:	SERVER-NETWORK<br />descr:	root SA<br />ns1:	nix.ns.ua<br />ns2:	ns2.4grad.in.ua<br />ns3:	ns.vizor.lutsk.ua<br />ns4:	ns.cv.ua<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://centroandino.edu.co/images/svcnss.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10540979</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Symmi.kioem]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10540979</guid>
			<pubDate>2013-04-30T10:00:22+02:00</pubDate>
			<description><![CDATA[id:	10540979<br />first:	1367308822<br />last:	0<br />md5:	317d5e35380f213fdee9c498dc1bff9f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=317d5e35380f213fdee9c498dc1bff9f<br />vt_score:	14/45 (31.1%)<br />scanner:	AntiVir<br />virusname:	TR/Symmi.kioem<br />url:	http://centroandino.edu.co/images/svcnss.exe<br />recent:	up<br />response:	alive<br />ip:	216.172.187.16<br />as:	AS36351<br />review:	216.172.187.16<br />domain:	centroandino.edu.co<br />country:	US<br />source:	ARIN<br />email:	ipadmin@websitewelcome.com<br />inetnum:	216.172.160.0 - 216.172.191.255<br />netname:	HGBLOCK-2<br />descr:	WEBSITEWELCOME.COM BO 11251 Northwest Freeway Houston TX 77092<br />ns1:	ns1519.websitewelcome.com<br />ns2:	ns1520.websitewelcome.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://centroandino.edu.co/images/services.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10540978</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10540978</guid>
			<pubDate>2013-04-30T10:00:22+02:00</pubDate>
			<description><![CDATA[id:	10540978<br />first:	1367308822<br />last:	0<br />md5:	7d7091a13bac90f0e568e18898ebd462<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7d7091a13bac90f0e568e18898ebd462<br />vt_score:	9/46 (19.6%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://centroandino.edu.co/images/services.exe<br />recent:	up<br />response:	alive<br />ip:	216.172.187.16<br />as:	AS36351<br />review:	216.172.187.16<br />domain:	centroandino.edu.co<br />country:	US<br />source:	ARIN<br />email:	ipadmin@websitewelcome.com<br />inetnum:	216.172.160.0 - 216.172.191.255<br />netname:	HGBLOCK-2<br />descr:	WEBSITEWELCOME.COM BO 11251 Northwest Freeway Houston TX 77092<br />ns1:	ns1519.websitewelcome.com<br />ns2:	ns1520.websitewelcome.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://centroandino.edu.co/images/realsched.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10540977</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Injector.YFC!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10540977</guid>
			<pubDate>2013-04-30T10:00:22+02:00</pubDate>
			<description><![CDATA[id:	10540977<br />first:	1367308822<br />last:	0<br />md5:	58e60f18f9cc67586cd5231b8205cd8c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=58e60f18f9cc67586cd5231b8205cd8c<br />vt_score:	7/46 (15.2%)<br />scanner:	undef<br />virusname:	W32/Injector.YFC!tr<br />url:	http://centroandino.edu.co/images/realsched.exe<br />recent:	up<br />response:	alive<br />ip:	216.172.187.16<br />as:	AS36351<br />review:	216.172.187.16<br />domain:	centroandino.edu.co<br />country:	US<br />source:	ARIN<br />email:	ipadmin@websitewelcome.com<br />inetnum:	216.172.160.0 - 216.172.191.255<br />netname:	HGBLOCK-2<br />descr:	WEBSITEWELCOME.COM BO 11251 Northwest Freeway Houston TX 77092<br />ns1:	ns1519.websitewelcome.com<br />ns2:	ns1520.websitewelcome.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://centroandino.edu.co/images/perfect.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10540976</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10540976</guid>
			<pubDate>2013-04-30T10:00:22+02:00</pubDate>
			<description><![CDATA[id:	10540976<br />first:	1367308822<br />last:	0<br />md5:	89dccf5500923adb3bf7841e6f0f42ee<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=89dccf5500923adb3bf7841e6f0f42ee<br />vt_score:	6/35 (17.1%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://centroandino.edu.co/images/perfect.exe<br />recent:	up<br />response:	alive<br />ip:	216.172.187.16<br />as:	AS36351<br />review:	216.172.187.16<br />domain:	centroandino.edu.co<br />country:	US<br />source:	ARIN<br />email:	ipadmin@websitewelcome.com<br />inetnum:	216.172.160.0 - 216.172.191.255<br />netname:	HGBLOCK-2<br />descr:	WEBSITEWELCOME.COM BO 11251 Northwest Freeway Houston TX 77092<br />ns1:	ns1519.websitewelcome.com<br />ns2:	ns1520.websitewelcome.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://centroandino.edu.co/images/iexplorer.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10540975</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10540975</guid>
			<pubDate>2013-04-30T10:00:22+02:00</pubDate>
			<description><![CDATA[id:	10540975<br />first:	1367308822<br />last:	0<br />md5:	80fc28c383ab7d021bd843064441f019<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=80fc28c383ab7d021bd843064441f019<br />vt_score:	9/46 (19.6%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://centroandino.edu.co/images/iexplorer.exe<br />recent:	up<br />response:	alive<br />ip:	216.172.187.16<br />as:	AS36351<br />review:	216.172.187.16<br />domain:	centroandino.edu.co<br />country:	US<br />source:	ARIN<br />email:	ipadmin@websitewelcome.com<br />inetnum:	216.172.160.0 - 216.172.191.255<br />netname:	HGBLOCK-2<br />descr:	WEBSITEWELCOME.COM BO 11251 Northwest Freeway Houston TX 77092<br />ns1:	ns1519.websitewelcome.com<br />ns2:	ns1520.websitewelcome.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://centroandino.edu.co/images/1resident.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10540974</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicious file]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10540974</guid>
			<pubDate>2013-04-30T10:00:22+02:00</pubDate>
			<description><![CDATA[id:	10540974<br />first:	1367308822<br />last:	0<br />md5:	f668516df4032f02ba2fe71b2643fd7a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f668516df4032f02ba2fe71b2643fd7a<br />vt_score:	9/45 (20%)<br />scanner:	undef<br />virusname:	Suspicious file<br />url:	http://centroandino.edu.co/images/1resident.exe<br />recent:	up<br />response:	alive<br />ip:	216.172.187.16<br />as:	AS36351<br />review:	216.172.187.16<br />domain:	centroandino.edu.co<br />country:	US<br />source:	ARIN<br />email:	ipadmin@websitewelcome.com<br />inetnum:	216.172.160.0 - 216.172.191.255<br />netname:	HGBLOCK-2<br />descr:	WEBSITEWELCOME.COM BO 11251 Northwest Freeway Houston TX 77092<br />ns1:	ns1519.websitewelcome.com<br />ns2:	ns1520.websitewelcome.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.naturacoiffure.com/images/mcces.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10540973</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10540973</guid>
			<pubDate>2013-04-30T10:00:22+02:00</pubDate>
			<description><![CDATA[id:	10540973<br />first:	1367308822<br />last:	0<br />md5:	5bc38a19d77294fffbd3f49228874f93<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5bc38a19d77294fffbd3f49228874f93<br />vt_score:	36/46 (78.3%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://www.naturacoiffure.com/images/mcces.exe<br />recent:	up<br />response:	alive<br />ip:	37.59.16.198<br />as:	AS16276<br />review:	37.59.16.198<br />domain:	naturacoiffure.com<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	37.59.0.0 - 37.59.63.255<br />netname:	OVH<br />descr:	OVH SASDedicated servershttp<br />ns1:	sdns2.ovh.net<br />ns2:	ns231403.ovh.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://heuro-vacances.fr/5nW.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10519659</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Strictor.27708]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10519659</guid>
			<pubDate>2013-04-29T16:40:35+02:00</pubDate>
			<description><![CDATA[id:	10519659<br />first:	1367246435<br />last:	0<br />md5:	3097f08b5b880d428e0948f7253e2d09<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3097f08b5b880d428e0948f7253e2d09<br />vt_score:	12/46 (26.1%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Strictor.27708<br />url:	http://heuro-vacances.fr/5nW.exe<br />recent:	up<br />response:	alive<br />ip:	62.73.4.10<br />as:	AS8999<br />review:	62.73.4.10<br />domain:	heuro-vacances.fr<br />country:	FR<br />source:	RIPE<br />email:	r.khadrouche@free.fr<br />inetnum:	62.73.4.0 - 62.73.5.255<br />netname:	NET-WORK-COMMUNICATION-NET<br />descr:	Net work CommunicationISP France, SwitzerlandNWC-BLK1NWC-Bv<br />ns1:	ns1.axinet.fr<br />ns2:	ns2.axinet.fr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wknqba.best.volyn.ua/dlimage11.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10399568</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10399568</guid>
			<pubDate>2013-04-25T10:40:09+02:00</pubDate>
			<description><![CDATA[id:	10399568<br />first:	1366879209<br />last:	0<br />md5:	be8341c9a569991e218e77e507c6a032<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=be8341c9a569991e218e77e507c6a032<br />vt_score:	10/46 (21.7%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://wknqba.best.volyn.ua/dlimage11.php<br />recent:	up<br />response:	alive<br />ip:	91.218.39.175<br />as:	AS197145<br />review:	91.218.39.175<br />domain:	volyn.ua<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	91.218.36.0 - 91.218.39.255<br />netname:	INFIUMHOST-NET<br />descr:	Infium Ltd.<br />ns1:	nix.ns.ua<br />ns2:	ns.vizor.lutsk.ua<br />ns3:	ns2.4grad.in.ua<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yyhflh.best.volyn.ua/dlimage11.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10399566</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10399566</guid>
			<pubDate>2013-04-25T10:40:09+02:00</pubDate>
			<description><![CDATA[id:	10399566<br />first:	1366879209<br />last:	0<br />md5:	be8341c9a569991e218e77e507c6a032<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=be8341c9a569991e218e77e507c6a032<br />vt_score:	10/46 (21.7%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://yyhflh.best.volyn.ua/dlimage11.php<br />recent:	up<br />response:	alive<br />ip:	91.218.39.175<br />as:	AS197145<br />review:	91.218.39.175<br />domain:	volyn.ua<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	91.218.36.0 - 91.218.39.255<br />netname:	INFIUMHOST-NET<br />descr:	Infium Ltd.<br />ns1:	ns2.4grad.in.ua<br />ns2:	ns.vizor.lutsk.ua<br />ns3:	nix.ns.ua<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lwqxam.best.lt.ua/dlimage4.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10399565</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10399565</guid>
			<pubDate>2013-04-25T10:40:09+02:00</pubDate>
			<description><![CDATA[id:	10399565<br />first:	1366879209<br />last:	0<br />md5:	099365e00f7ebe5a0c51db3176368f16<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=099365e00f7ebe5a0c51db3176368f16<br />vt_score:	4/46 (8.7%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://lwqxam.best.lt.ua/dlimage4.php<br />recent:	up<br />response:	alive<br />ip:	91.218.39.175<br />as:	AS197145<br />review:	91.218.39.175<br />domain:	lt.ua<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	91.218.36.0 - 91.218.39.255<br />netname:	INFIUMHOST-NET<br />descr:	Infium Ltd.<br />ns1:	ns2.4grad.in.ua<br />ns2:	ns.cv.ua<br />ns3:	ns.vizor.lutsk.ua<br />ns4:	nix.ns.ua<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://91.218.39.175/com.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10399564</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10399564</guid>
			<pubDate>2013-04-25T10:40:09+02:00</pubDate>
			<description><![CDATA[id:	10399564<br />first:	1366879209<br />last:	0<br />md5:	099365e00f7ebe5a0c51db3176368f16<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=099365e00f7ebe5a0c51db3176368f16<br />vt_score:	4/46 (8.7%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://91.218.39.175/com.php<br />recent:	up<br />response:	alive<br />ip:	91.218.39.175<br />as:	AS197145<br />review:	91.218.39.175<br />domain:	91.218.39.175<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	91.218.36.0 - 91.218.39.255<br />netname:	INFIUMHOST-NET<br />descr:	Infium Ltd.<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://91.218.39.175/image.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10399563</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10399563</guid>
			<pubDate>2013-04-25T10:40:09+02:00</pubDate>
			<description><![CDATA[id:	10399563<br />first:	1366879209<br />last:	0<br />md5:	be8341c9a569991e218e77e507c6a032<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=be8341c9a569991e218e77e507c6a032<br />vt_score:	10/46 (21.7%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://91.218.39.175/image.php<br />recent:	up<br />response:	alive<br />ip:	91.218.39.175<br />as:	AS197145<br />review:	91.218.39.175<br />domain:	91.218.39.175<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	91.218.36.0 - 91.218.39.255<br />netname:	INFIUMHOST-NET<br />descr:	Infium Ltd.<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sigkeqvi.ru/angrim2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10333486</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Tepfer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10333486</guid>
			<pubDate>2013-04-22T14:40:36+02:00</pubDate>
			<description><![CDATA[id:	10333486<br />first:	1366634436<br />last:	0<br />md5:	5b3575f6d24fa9d4ac17540db9bd2762<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5b3575f6d24fa9d4ac17540db9bd2762<br />vt_score:	8/35 (22.9%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Tepfer<br />url:	http://sigkeqvi.ru/angrim2.exe<br />recent:	up<br />response:	alive<br />ip:	58.153.8.105<br />as:	AS4760<br />review:	93.89.210.216<br />domain:	sigkeqvi.ru<br />country:	UA<br />source:	RIPE<br />email:	hostmaster@element.dn.ua<br />inetnum:	58.152.0.0 - 58.153.255.255<br />netname:	EDN-INFRA-NET<br />descr:	East Donbass NetworksSPD Chernyavskiy S.V.East Donbass NetworksEast Donbass Networks<br />ns1:	ns1.sigkeqvi.ru<br />ns2:	ns2.sigkeqvi.ru<br />ns3:	ns4.sigkeqvi.ru<br />ns4:	ns6.sigkeqvi.ru<br />ns5:	ns5.sigkeqvi.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/203841525/0d7fa04/f1897f4w8f4we1.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10315993</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.166402]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10315993</guid>
			<pubDate>2013-04-21T15:40:09+02:00</pubDate>
			<description><![CDATA[id:	10315993<br />first:	1366551609<br />last:	0<br />md5:	78caa5360d7971391f06509999236671<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=78caa5360d7971391f06509999236671<br />vt_score:	18/46 (39.1%)<br />scanner:	AntiVir<br />virusname:	TR/Kazy.166402<br />url:	http://hotfile.com/dl/203841525/0d7fa04/f1897f4w8f4we1.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.226<br />as:	AS7366<br />review:	199.7.177.216<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns1.hotfile.com<br />ns2:	ns2.easydns.com<br />ns3:	ns1.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://thedogbowlmorecambe.co.uk/main.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10282195</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.434688.35]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10282195</guid>
			<pubDate>2013-04-20T05:40:03+02:00</pubDate>
			<description><![CDATA[id:	10282195<br />first:	1366429203<br />last:	0<br />md5:	e418cc36b3c7a8ec5bd57fbc63cbecc2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e418cc36b3c7a8ec5bd57fbc63cbecc2<br />vt_score:	18/46 (39.1%)<br />scanner:	AntiVir<br />virusname:	TR/Spy.434688.35<br />url:	http://thedogbowlmorecambe.co.uk/main.exe<br />recent:	up<br />response:	alive<br />ip:	46.30.211.55<br />as:	AS51468<br />review:	46.30.211.55<br />domain:	thedogbowlmorecambe.co.uk<br />country:	DK<br />source:	RIPE<br />email:	abuse@one.com<br />inetnum:	46.30.211.32 - 46.30.211.63<br />netname:	ONE-COM<br />descr:	Webcluster services for One.com<br />ns1:	ns01.one.com<br />ns2:	ns02.one.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://you-tube.de.pl/AdobeUpdate.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10281301</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.KD.740321]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10281301</guid>
			<pubDate>2013-04-20T05:00:04+02:00</pubDate>
			<description><![CDATA[id:	10281301<br />first:	1366426804<br />last:	0<br />md5:	c2296f493fed89137e044db34807769d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c2296f493fed89137e044db34807769d<br />vt_score:	22/46 (47.8%)<br />scanner:	avira<br />virusname:	TR/Rogue.KD.740321<br />url:	http://you-tube.de.pl/AdobeUpdate.exe<br />recent:	up<br />response:	alive<br />ip:	78.46.86.242<br />as:	AS24940<br />review:	78.46.86.242<br />domain:	you-tube.de.pl<br />country:	DE<br />source:	RIPE<br />email:	abuse@hetzner.de<br />inetnum:	78.46.64.0 - 78.46.95.255<br />netname:	HETZNER-RZ-NBG-NET<br />descr:	Hetzner Online AG<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dj0k.kolasoeg.ru/m.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10260292</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Waledac.EB.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10260292</guid>
			<pubDate>2013-04-19T13:40:38+02:00</pubDate>
			<description><![CDATA[id:	10260292<br />first:	1366371638<br />last:	0<br />md5:	78934c5d5a04f96dedff9c54d2fcf31f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=78934c5d5a04f96dedff9c54d2fcf31f<br />vt_score:	20/46 (43.5%)<br />scanner:	AntiVir<br />virusname:	TR/Waledac.EB.2<br />url:	http://dj0k.kolasoeg.ru/m.exe<br />recent:	up<br />response:	alive<br />ip:	159.224.226.211<br />as:	AS13188<br />review:	93.79.118.22<br />domain:	kolasoeg.ru<br />country:	UA<br />source:	RIPE<br />email:	abuse@volia.net<br />inetnum:	159.224.0.0 - 159.224.255.255<br />netname:	UA-VOLIA-20080404<br />descr:	Kyivski Telekomunikatsiyni Merezhi LLC<br />ns1:	ns6.kolasoeg.ru<br />ns2:	ns2.kolasoeg.ru<br />ns3:	ns4.kolasoeg.ru<br />ns4:	ns5.kolasoeg.ru<br />ns5:	ns1.kolasoeg.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dj0k.kolasoeg.ru/ballsof.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10260291</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Kazy.165428]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10260291</guid>
			<pubDate>2013-04-19T13:40:38+02:00</pubDate>
			<description><![CDATA[id:	10260291<br />first:	1366371638<br />last:	0<br />md5:	49d4c5e3315b1cf3c939174f506bc54c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=49d4c5e3315b1cf3c939174f506bc54c<br />vt_score:	7/35 (20%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Kazy.165428<br />url:	http://dj0k.kolasoeg.ru/ballsof.exe<br />recent:	up<br />response:	alive<br />ip:	37.57.104.182<br />as:	AS13188<br />review:	189.53.42.157<br />domain:	kolasoeg.ru<br />country:	BR<br />source:	LACNIC<br />email:	abuse@embratel.net.br<br />inetnum:	37.57.104.0 - 37.57.104.255<br />netname:	033.530.486/0001-29<br />descr:	EMBRATEL-EMPRESA BRASILEIRA DE TELECOMUNICAÇÕES SA (10525)<br />ns1:	ns6.kolasoeg.ru<br />ns2:	ns2.kolasoeg.ru<br />ns3:	ns4.kolasoeg.ru<br />ns4:	ns5.kolasoeg.ru<br />ns5:	ns1.kolasoeg.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dj0k.kolasoeg.ru/keybex3.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10259666</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Kazy.165428]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10259666</guid>
			<pubDate>2013-04-19T13:00:03+02:00</pubDate>
			<description><![CDATA[id:	10259666<br />first:	1366369203<br />last:	0<br />md5:	e844d2c371c72bd0f4b2494aded264af<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e844d2c371c72bd0f4b2494aded264af<br />vt_score:	11/44 (25%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Kazy.165428<br />url:	http://dj0k.kolasoeg.ru/keybex3.exe<br />recent:	up<br />response:	alive<br />ip:	31.133.60.219<br />as:	AS52091<br />review:	46.119.167.149<br />domain:	kolasoeg.ru<br />country:	UA<br />source:	RIPE<br />email:	security@svitonline.com<br />inetnum:	31.133.32.0 - 31.133.63.255<br />netname:	UA-SVITONLINE-20100517<br />descr:	GoldenTelecom LLC<br />ns1:	ns3.kolasoeg.ru<br />ns2:	ns2.kolasoeg.ru<br />ns3:	ns4.kolasoeg.ru<br />ns4:	ns5.kolasoeg.ru<br />ns5:	ns1.kolasoeg.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://juqhasri.ru/angrim2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10259489</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_html]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10259489</guid>
			<pubDate>2013-04-19T12:40:13+02:00</pubDate>
			<description><![CDATA[id:	10259489<br />first:	1366368013<br />last:	0<br />md5:	2b73a5500bfe8da61c23ed04c85a959a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2b73a5500bfe8da61c23ed04c85a959a<br />vt_score:	0/35 (0.0%)<br />scanner:	undef<br />virusname:	unknown_html<br />url:	http://juqhasri.ru/angrim2.exe<br />recent:	up<br />response:	alive<br />ip:	91.149.167.38<br />as:	AS50155<br />review:	109.200.253.77<br />domain:	juqhasri.ru<br />country:	UA<br />source:	RIPE<br />email:	abuse@arm.in.ua<br />inetnum:	91.149.167.0 - 91.149.167.255<br />netname:	UA-BRIZ-20100210<br />descr:	TOV TRK "Briz"<br />ns1:	ns5.juqhasri.ru<br />ns2:	ns6.juqhasri.ru<br />ns3:	ns3.juqhasri.ru<br />ns4:	ns1.juqhasri.ru<br />ns5:	ns4.juqhasri.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dj0k.kolasoeg.ru/traff01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10258320</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Foreign]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10258320</guid>
			<pubDate>2013-04-19T10:40:16+02:00</pubDate>
			<description><![CDATA[id:	10258320<br />first:	1366360816<br />last:	0<br />md5:	f8f70118d06834de3e561c475a21f64b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f8f70118d06834de3e561c475a21f64b<br />vt_score:	10/35 (28.6%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Foreign<br />url:	http://dj0k.kolasoeg.ru/traff01.exe<br />recent:	up<br />response:	alive<br />ip:	98.156.69.198<br />as:	AS20231<br />review:	93.79.247.31<br />domain:	kolasoeg.ru<br />country:	UA<br />source:	RIPE<br />email:	abuse@volia.net<br />inetnum:	98.144.0.0 - 98.157.255.255<br />netname:	UA-VOLIA-20080404<br />descr:	Kyivski Telekomunikatsiyni Merezhi LLC<br />ns1:	ns1.kolasoeg.ru<br />ns2:	ns2.kolasoeg.ru<br />ns3:	ns3.kolasoeg.ru<br />ns4:	ns5.kolasoeg.ru<br />ns5:	ns4.kolasoeg.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dj0k.kolasoeg.ru/rasta01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10257610</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Foreign]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10257610</guid>
			<pubDate>2013-04-19T09:40:48+02:00</pubDate>
			<description><![CDATA[id:	10257610<br />first:	1366357248<br />last:	0<br />md5:	2a12e503178bcfb7a299e19af89a8c64<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2a12e503178bcfb7a299e19af89a8c64<br />vt_score:	10/46 (21.7%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Foreign<br />url:	http://dj0k.kolasoeg.ru/rasta01.exe<br />recent:	up<br />response:	alive<br />ip:	77.122.159.162<br />as:	AS25229<br />review:	46.150.69.173<br />domain:	kolasoeg.ru<br />country:	UA<br />source:	RIPE<br />email:	admin@melitopol.tv<br />inetnum:	77.122.128.0 - 77.122.207.255<br />netname:	VIVANET-NET1<br />descr:	Vivanet LtdVivanetVivanet Ltd<br />ns1:	ns6.kolasoeg.ru<br />ns2:	ns3.kolasoeg.ru<br />ns3:	ns2.kolasoeg.ru<br />ns4:	ns1.kolasoeg.ru<br />ns5:	ns5.kolasoeg.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://78.83.177.242/rasta01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10243754</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Foreign]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10243754</guid>
			<pubDate>2013-04-18T14:40:03+02:00</pubDate>
			<description><![CDATA[id:	10243754<br />first:	1366288803<br />last:	0<br />md5:	fcabd806d83c4b79c85bd1e9a466fe4f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fcabd806d83c4b79c85bd1e9a466fe4f<br />vt_score:	7/34 (20.6%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Foreign<br />url:	http://78.83.177.242/rasta01.exe<br />recent:	up<br />response:	alive<br />ip:	78.83.177.242<br />as:	AS29580<br />review:	78.83.177.242<br />domain:	78.83.177.242<br />country:	BG<br />source:	RIPE<br />email:	abuse@spnet.net<br />inetnum:	78.83.0.0 - 78.83.255.255<br />netname:	BG-SPNET-20071416<br />descr:	Spectrum NET Jsc<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vins-vinhos-wines-portugal.com/pictures/images/be.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10243753</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10243753</guid>
			<pubDate>2013-04-18T14:40:03+02:00</pubDate>
			<description><![CDATA[id:	10243753<br />first:	1366288803<br />last:	0<br />md5:	4637e85ee3430a74693753f4271e64f9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4637e85ee3430a74693753f4271e64f9<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://vins-vinhos-wines-portugal.com/pictures/images/be.exe<br />recent:	up<br />response:	alive<br />ip:	213.186.33.17<br />as:	AS16276<br />review:	213.186.33.17<br />domain:	vins-vinhos-wines-portugal.com<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	213.186.33.0 - 213.186.33.255<br />netname:	OVH<br />descr:	OVH SASShared Hosting ServershttpOVH ISPParis, France<br />ns1:	dns101.ovh.net<br />ns2:	ns101.ovh.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vins-vinhos-wines-portugal.com/pictures/img/Pony.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10243752</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10243752</guid>
			<pubDate>2013-04-18T14:40:03+02:00</pubDate>
			<description><![CDATA[id:	10243752<br />first:	1366288803<br />last:	0<br />md5:	72b94b74d92ed91540410e083c632e8b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=72b94b74d92ed91540410e083c632e8b<br />vt_score:	26/46 (56.5%)<br />scanner:	avira<br />virusname:	TR/Spy.Gen<br />url:	http://vins-vinhos-wines-portugal.com/pictures/img/Pony.exe<br />recent:	up<br />response:	alive<br />ip:	213.186.33.17<br />as:	AS16276<br />review:	213.186.33.17<br />domain:	vins-vinhos-wines-portugal.com<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	213.186.33.0 - 213.186.33.255<br />netname:	OVH<br />descr:	OVH SASShared Hosting ServershttpOVH ISPParis, France<br />ns1:	dns101.ovh.net<br />ns2:	ns101.ovh.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://78.83.177.242/calc.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10243751</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10243751</guid>
			<pubDate>2013-04-18T14:40:03+02:00</pubDate>
			<description><![CDATA[id:	10243751<br />first:	1366288803<br />last:	0<br />md5:	a487bf042ee4b00ebd3e8cc6aa0c19ea<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a487bf042ee4b00ebd3e8cc6aa0c19ea<br />vt_score:	20/46 (43.5%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://78.83.177.242/calc.exe<br />recent:	up<br />response:	alive<br />ip:	78.83.177.242<br />as:	AS29580<br />review:	78.83.177.242<br />domain:	78.83.177.242<br />country:	BG<br />source:	RIPE<br />email:	abuse@spnet.net<br />inetnum:	78.83.0.0 - 78.83.255.255<br />netname:	BG-SPNET-20071416<br />descr:	Spectrum NET Jsc<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://78.83.177.242/shem001.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10243750</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Foreign]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10243750</guid>
			<pubDate>2013-04-18T14:40:03+02:00</pubDate>
			<description><![CDATA[id:	10243750<br />first:	1366288803<br />last:	0<br />md5:	8417b517b46a3f3b7a5e5626f2aed3cd<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8417b517b46a3f3b7a5e5626f2aed3cd<br />vt_score:	13/46 (28.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Foreign<br />url:	http://78.83.177.242/shem001.exe<br />recent:	up<br />response:	alive<br />ip:	78.83.177.242<br />as:	AS29580<br />review:	78.83.177.242<br />domain:	78.83.177.242<br />country:	BG<br />source:	RIPE<br />email:	abuse@spnet.net<br />inetnum:	78.83.0.0 - 78.83.255.255<br />netname:	BG-SPNET-20071416<br />descr:	Spectrum NET Jsc<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://deborahgladstein.com/DEB88/STD87YH66.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10242689</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Symmi.18711]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10242689</guid>
			<pubDate>2013-04-18T13:41:13+02:00</pubDate>
			<description><![CDATA[id:	10242689<br />first:	1366285273<br />last:	0<br />md5:	25521ef657d786265e7db9b2396b1013<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=25521ef657d786265e7db9b2396b1013<br />vt_score:	9/46 (19.6%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Symmi.18711<br />url:	http://deborahgladstein.com/DEB88/STD87YH66.zip<br />recent:	up<br />response:	alive<br />ip:	66.240.144.68<br />as:	AS29925<br />review:	66.240.144.68<br />domain:	deborahgladstein.com<br />country:	US<br />source:	ARIN<br />email:	shu.lam@momentum.com<br />inetnum:	66.240.128.0 - 66.240.191.255<br />netname:	MASMEDIA-NET<br />descr:	Mas Media Inc. MASME 155 Commerce Valley Drive East Thornhill ON L3T-7T2<br />ns1:	ns3.mdnsservice.com<br />ns2:	ns1.mdnsservice.com<br />ns3:	ns2.mdnsservice.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ickyrjum.ru/traff01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10239822</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Foreign]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10239822</guid>
			<pubDate>2013-04-18T11:00:16+02:00</pubDate>
			<description><![CDATA[id:	10239822<br />first:	1366275616<br />last:	0<br />md5:	e97162613cfb8aa1ef7cc440adc67b0e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e97162613cfb8aa1ef7cc440adc67b0e<br />vt_score:	7/46 (15.2%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Foreign<br />url:	http://ickyrjum.ru/traff01.exe<br />recent:	up<br />response:	alive<br />ip:	94.240.165.164<br />as:	AS41232<br />review:	176.241.154.177<br />domain:	ickyrjum.ru<br />country:	UA<br />source:	RIPE<br />email:	abuse@ip.datagroup.ua<br />inetnum:	94.240.160.0 - 94.240.191.255<br />netname:	UA-DATACOM-20111206<br />descr:	PRIVATE JOINT STOCK COMPANY "DATAGROUP"<br />ns1:	ns2.ickyrjum.ru<br />ns2:	ns3.ickyrjum.ru<br />ns3:	ns6.ickyrjum.ru<br />ns4:	ns5.ickyrjum.ru<br />ns5:	ns1.ickyrjum.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kolasoeg.ru/newbos3.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10239412</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win32:Kryptik-LKV [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10239412</guid>
			<pubDate>2013-04-18T10:40:03+02:00</pubDate>
			<description><![CDATA[id:	10239412<br />first:	1366274403<br />last:	0<br />md5:	dc4b789acb1bd89959837ce4134e0273<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dc4b789acb1bd89959837ce4134e0273<br />vt_score:	12/46 (26.1%)<br />scanner:	Avast<br />virusname:	Win32:Kryptik-LKV [Trj]<br />url:	http://kolasoeg.ru/newbos3.exe<br />recent:	up<br />response:	alive<br />ip:	77.122.232.137<br />as:	AS25229<br />review:	31.192.175.6<br />domain:	kolasoeg.ru<br />country:	RU<br />source:	RIPE<br />email:	ripe@telenet.ru<br />inetnum:	77.122.128.0 - 77.122.255.255<br />netname:	RU-TELESET-20110421<br />descr:	Teleset-Servis Ltd.KABINET internet workspace<br />ns1:	ns2.kolasoeg.ru<br />ns2:	ns1.kolasoeg.ru<br />ns3:	ns4.kolasoeg.ru<br />ns4:	ns3.kolasoeg.ru<br />ns5:	ns6.kolasoeg.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fvdbzn.best.lt.ua/dlimage4.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10216147</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10216147</guid>
			<pubDate>2013-04-17T14:40:08+02:00</pubDate>
			<description><![CDATA[id:	10216147<br />first:	1366202408<br />last:	0<br />md5:	5506a72243dcfb29eea1dfd9096c9376<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5506a72243dcfb29eea1dfd9096c9376<br />vt_score:	7/46 (15.2%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen2<br />url:	http://fvdbzn.best.lt.ua/dlimage4.php<br />recent:	up<br />response:	alive<br />ip:	94.242.250.178<br />as:	AS5577<br />review:	94.242.250.178<br />domain:	lt.ua<br />country:	LU<br />source:	RIPE<br />email:	abuse@as5577.net<br />inetnum:	94.242.224.0 - 94.242.255.255<br />netname:	SERVER-NETWORK<br />descr:	root SA<br />ns1:	ns2.4grad.in.ua<br />ns2:	ns.cv.ua<br />ns3:	nix.ns.ua<br />ns4:	ns.vizor.lutsk.ua<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://omi.org.br/flash_player.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10214303</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10214303</guid>
			<pubDate>2013-04-17T12:40:18+02:00</pubDate>
			<description><![CDATA[id:	10214303<br />first:	1366195218<br />last:	0<br />md5:	8d5b9d70bc98f36c85a82c774960ee6d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8d5b9d70bc98f36c85a82c774960ee6d<br />vt_score:	24/34 (70.6%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Gen<br />url:	http://omi.org.br/flash_player.exe<br />recent:	up<br />response:	alive<br />ip:	187.45.240.50<br />as:	AS27715<br />review:	187.45.240.50<br />domain:	omi.org.br<br />country:	BR<br />source:	LACNIC<br />email:	regcom@locaweb.com.br<br />inetnum:	187.45.224.0 - 187.45.255.255<br />netname:	002.351.877/0001-52<br />descr:	Locaweb Serviços de Internet S/A<br />ns1:	ns3.locaweb.com.br<br />ns2:	ns1.locaweb.com.br<br />ns3:	ns2.locaweb.com.br<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://94.242.250.178:80/image.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10214302</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10214302</guid>
			<pubDate>2013-04-17T12:40:18+02:00</pubDate>
			<description><![CDATA[id:	10214302<br />first:	1366195218<br />last:	0<br />md5:	81410cd9e0e68e1a299c50770a7e5e3d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=81410cd9e0e68e1a299c50770a7e5e3d<br />vt_score:	4/35 (11.4%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen2<br />url:	http://94.242.250.178:80/image.php<br />recent:	up<br />response:	alive<br />ip:	94.242.250.178<br />as:	AS5577<br />review:	94.242.250.178<br />domain:	94.242.250.178<br />country:	LU<br />source:	RIPE<br />email:	abuse@as5577.net<br />inetnum:	94.242.224.0 - 94.242.255.255<br />netname:	SERVER-NETWORK<br />descr:	root SA<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://94.242.250.178:80/com.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10214301</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10214301</guid>
			<pubDate>2013-04-17T12:40:18+02:00</pubDate>
			<description><![CDATA[id:	10214301<br />first:	1366195218<br />last:	0<br />md5:	5506a72243dcfb29eea1dfd9096c9376<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5506a72243dcfb29eea1dfd9096c9376<br />vt_score:	7/46 (15.2%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen2<br />url:	http://94.242.250.178:80/com.php<br />recent:	up<br />response:	alive<br />ip:	94.242.250.178<br />as:	AS5577<br />review:	94.242.250.178<br />domain:	94.242.250.178<br />country:	LU<br />source:	RIPE<br />email:	abuse@as5577.net<br />inetnum:	94.242.224.0 - 94.242.255.255<br />netname:	SERVER-NETWORK<br />descr:	root SA<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.niloblog.com/files/images/2jcyn4vdrr8yyyfh3z30.png]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10214300</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Inject]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10214300</guid>
			<pubDate>2013-04-17T12:40:18+02:00</pubDate>
			<description><![CDATA[id:	10214300<br />first:	1366195218<br />last:	0<br />md5:	8e9c17b94f1e8602355a6880a2661766<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8e9c17b94f1e8602355a6880a2661766<br />vt_score:	23/44 (52.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Inject<br />url:	http://www.niloblog.com/files/images/2jcyn4vdrr8yyyfh3z30.png<br />recent:	up<br />response:	alive<br />ip:	176.9.38.7<br />as:	AS24940<br />review:	176.9.38.7<br />domain:	niloblog.com<br />country:	DE<br />source:	RIPE<br />email:	abuse@hetzner.de<br />inetnum:	176.9.0.0 - 176.9.255.255<br />netname:	DE-HETZNER-20110517<br />descr:	Hetzner Online AG<br />ns1:	ns2.niloblog.com<br />ns2:	ns1.niloblog.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://faithbibleweb.org/MsJZeLv6.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10214299</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[UDS:DangerousObject.Multi.Generic]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10214299</guid>
			<pubDate>2013-04-17T12:40:17+02:00</pubDate>
			<description><![CDATA[id:	10214299<br />first:	1366195217<br />last:	0<br />md5:	5fb8fe54ea814006ac7b3abd4541bb71<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5fb8fe54ea814006ac7b3abd4541bb71<br />vt_score:	1/45 (2.2%)<br />scanner:	Kaspersky<br />virusname:	UDS:DangerousObject.Multi.Generic<br />url:	http://faithbibleweb.org/MsJZeLv6.exe<br />recent:	up<br />response:	alive<br />ip:	67.210.111.20<br />as:	AS15244<br />review:	67.210.111.20<br />domain:	faithbibleweb.org<br />country:	US<br />source:	ARIN<br />email:	hostmaster@lunarpages.com<br />inetnum:	67.210.96.0 - 67.210.111.255<br />netname:	ADD2NET-DOT-COM<br />descr:	ADDD2NET COM INC DBA LUNARPAGES ACIDL Add2Net, Inc. Lunarpages Division 100 East La Habra Blvd. La Habra CA 90631<br />ns1:	ns1.lunarmania.com<br />ns2:	ns2.lunarmania.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dls.nicdls.com/p/151/flashplayer/1/1]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10171791</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicion: unknown virus]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10171791</guid>
			<pubDate>2013-04-15T20:40:10+02:00</pubDate>
			<description><![CDATA[id:	10171791<br />first:	1366051210<br />last:	0<br />md5:	e6d75c4addfeb70c29934350b48957e1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e6d75c4addfeb70c29934350b48957e1<br />vt_score:	6/45 (13.3%)<br />scanner:	AVG<br />virusname:	Suspicion: unknown virus<br />url:	http://dls.nicdls.com/p/151/flashplayer/1/1<br />recent:	up<br />response:	alive<br />ip:	178.33.233.113<br />as:	AS16276<br />review:	178.33.233.113<br />domain:	nicdls.com<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	178.32.0.0 - 178.33.255.255<br />netname:	FR-OVH-20100119<br />descr:	Ovh Systems<br />ns1:	ns1.nicdls.com<br />ns2:	ns2.nicdls.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/203006750/2822377/h98yoi.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10154524</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Worm/Dorkbot.AM.5]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10154524</guid>
			<pubDate>2013-04-15T10:40:52+02:00</pubDate>
			<description><![CDATA[id:	10154524<br />first:	1366015252<br />last:	0<br />md5:	eeff410a4bc62672f1163f0fd9bec3e5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=eeff410a4bc62672f1163f0fd9bec3e5<br />vt_score:	26/45 (57.8%)<br />scanner:	AntiVir<br />virusname:	Worm/Dorkbot.AM.5<br />url:	http://hotfile.com/dl/203006750/2822377/h98yoi.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.224<br />as:	AS7366<br />review:	199.7.177.230<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns2.easydns.com<br />ns2:	ns1.easydns.com<br />ns3:	ns1.hotfile.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dl.dropboxusercontent.com/s/km4sl43jvagiwqs/fifty.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=10074110</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=10074110</guid>
			<pubDate>2013-04-12T22:40:13+02:00</pubDate>
			<description><![CDATA[id:	10074110<br />first:	1365799213<br />last:	0<br />md5:	faa74648bac7931d48ca1cd19b5362de<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=faa74648bac7931d48ca1cd19b5362de<br />vt_score:	36/46 (78.3%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://dl.dropboxusercontent.com/s/km4sl43jvagiwqs/fifty.exe<br />recent:	up<br />response:	alive<br />ip:	54.225.136.76<br />as:	AS16509<br />review:	50.17.230.108<br />domain:	dropboxusercontent.com<br />country:	US<br />source:	ARIN<br />email:	ec2-abuse@amazon.com<br />inetnum:	54.224.0.0 - 54.225.255.255<br />netname:	AMAZON-EC2-8<br />descr:	Amazon.com, Inc. AMAZO-4 Amazon Web Services, Elastic Compute Cloud, EC2 1200 12th Avenue South Seattle WA 98144<br />ns1:	ns-1797.awsdns-32.co.uk<br />ns2:	ns-1525.awsdns-62.org<br />ns3:	ns-88.awsdns-11.com<br />ns4:	ns-649.awsdns-17.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bigdollarbills.com/sF2jEhs.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9965642</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Zusy.42478]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9965642</guid>
			<pubDate>2013-04-04T12:01:11+02:00</pubDate>
			<description><![CDATA[id:	9965642<br />first:	1365069671<br />last:	0<br />md5:	ed70e6d4ca5a1360b4917bc03153e5a3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ed70e6d4ca5a1360b4917bc03153e5a3<br />vt_score:	11/36 (30.6%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Zusy.42478<br />url:	http://bigdollarbills.com/sF2jEhs.exe<br />recent:	up<br />response:	alive<br />ip:	72.167.183.25<br />as:	AS26496<br />review:	72.167.183.25<br />domain:	bigdollarbills.com<br />country:	US<br />source:	ARIN<br />email:	noc@godaddy.com<br />inetnum:	72.167.0.0 - 72.167.255.255<br />netname:	GO-DADDY-COM-LLC<br />descr:	GoDaddy.com, LLC GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	ns76.domaincontrol.com<br />ns2:	ns75.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://flaglere.ipower.com/CBpDjd.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9965641</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Zusy.42478]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9965641</guid>
			<pubDate>2013-04-04T12:01:11+02:00</pubDate>
			<description><![CDATA[id:	9965641<br />first:	1365069671<br />last:	0<br />md5:	ed70e6d4ca5a1360b4917bc03153e5a3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ed70e6d4ca5a1360b4917bc03153e5a3<br />vt_score:	34/46 (73.9%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Zusy.42478<br />url:	http://flaglere.ipower.com/CBpDjd.exe<br />recent:	up<br />response:	alive<br />ip:	66.96.131.12<br />as:	AS29873<br />review:	66.96.131.12<br />domain:	ipower.com<br />country:	US<br />source:	ARIN<br />email:	bnbrock@maileig.com<br />inetnum:	66.96.128.0 - 66.96.191.255<br />netname:	BIZLAND-FC01<br />descr:	The Endurance International Group, Inc. EIG-12 70 Blanchard Road Burlington MA 01803<br />ns1:	ns2.ipowerweb.net<br />ns2:	ns2.ipowerdns.com<br />ns3:	ns1.ipowerweb.net<br />ns4:	ns1.ipowerdns.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.fortalezapremium.com.br/JgN.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9965640</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Zusy.42478]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9965640</guid>
			<pubDate>2013-04-04T12:01:11+02:00</pubDate>
			<description><![CDATA[id:	9965640<br />first:	1365069671<br />last:	0<br />md5:	ed70e6d4ca5a1360b4917bc03153e5a3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ed70e6d4ca5a1360b4917bc03153e5a3<br />vt_score:	34/46 (73.9%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Zusy.42478<br />url:	http://www.fortalezapremium.com.br/JgN.exe<br />recent:	up<br />response:	alive<br />ip:	200.58.111.69<br />as:	AS27823<br />review:	200.58.111.69<br />domain:	fortalezapremium.com.br<br />country:	AR<br />source:	LACNIC<br />email:	ipmaster@hostmar.com<br />inetnum:	200.58.96.0 - 200.58.111.255<br />netname:	AR-DATT-LACNIC<br />descr:	Dattatec.comCordoba, 3753,2000 - Rosario - SFCordoba, 3753,2000 - Rosario - SF<br />ns1:	ns3.hostmar.com<br />ns2:	ns4.hostmar.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yobbk.lskrmms.ignorelist.com/1.exe?ts=db8ad130816342eec9ab7e4c567b9bbbffd4fdec&affid=31212]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9964431</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9964431</guid>
			<pubDate>2013-04-04T10:00:09+02:00</pubDate>
			<description><![CDATA[id:	9964431<br />first:	1365062409<br />last:	0<br />md5:	2c440d6809db65ff58bc0fe86300608a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2c440d6809db65ff58bc0fe86300608a<br />vt_score:	29/45 (64.4%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://yobbk.lskrmms.ignorelist.com/1.exe?ts=db8ad130816342eec9ab7e4c567b9bbbffd4fdec&affid=31212<br />recent:	up<br />response:	alive<br />ip:	5.104.106.56<br />as:	AS24961<br />review:	5.104.106.56<br />domain:	ignorelist.com<br />country:	DE<br />source:	RIPE<br />email:	abuse@fibre1.net<br />inetnum:	5.104.104.0 - 5.104.111.255<br />netname:	DE-FASTIT-20120629<br />descr:	myLoc managed IT AG<br />ns1:	ns4.afraid.org<br />ns2:	ns2.afraid.org<br />ns3:	ns3.afraid.org<br />ns4:	ns1.afraid.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yobbk.lskrmms.ignorelist.com/get_soft_demo.php?ts=db8ad130816342eec9ab7e4c567b9bbbffd4fdec&affid=31212]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9964430</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9964430</guid>
			<pubDate>2013-04-04T10:00:09+02:00</pubDate>
			<description><![CDATA[id:	9964430<br />first:	1365062409<br />last:	0<br />md5:	0cc4f5eacd1ab6ebd99855b7ed77c651<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0cc4f5eacd1ab6ebd99855b7ed77c651<br />vt_score:	3/46 (6.5%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen2<br />url:	http://yobbk.lskrmms.ignorelist.com/get_soft_demo.php?ts=db8ad130816342eec9ab7e4c567b9bbbffd4fdec&affid=31212<br />recent:	up<br />response:	alive<br />ip:	5.104.106.56<br />as:	AS24961<br />review:	5.104.106.56<br />domain:	ignorelist.com<br />country:	DE<br />source:	RIPE<br />email:	abuse@fibre1.net<br />inetnum:	5.104.104.0 - 5.104.111.255<br />netname:	DE-FASTIT-20120629<br />descr:	myLoc managed IT AG<br />ns1:	ns4.afraid.org<br />ns2:	ns2.afraid.org<br />ns3:	ns3.afraid.org<br />ns4:	ns1.afraid.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://openminds.nazwa.pl/Y3EWoT.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9955554</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win32/Cryptor]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9955554</guid>
			<pubDate>2013-04-03T11:40:39+02:00</pubDate>
			<description><![CDATA[id:	9955554<br />first:	1364982039<br />last:	0<br />md5:	e30dd76330ab2df795efb978ae0ec7bf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e30dd76330ab2df795efb978ae0ec7bf<br />vt_score:	7/36 (19.4%)<br />scanner:	AVG<br />virusname:	Win32/Cryptor<br />url:	http://openminds.nazwa.pl/Y3EWoT.exe<br />recent:	up<br />response:	alive<br />ip:	85.128.198.179<br />as:	AS15967<br />review:	85.128.198.179<br />domain:	nazwa.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@netart.pl<br />inetnum:	85.128.168.0 - 85.128.199.255<br />netname:	NETART<br />descr:	NetArt webhosting servers<br />ns1:	ns1.netart.pl<br />ns2:	ns2.netart.pl<br />ns3:	ns3.netart.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://curtisgroup-inc.com/ZopzktR1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9955553</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicion: unknown virus]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9955553</guid>
			<pubDate>2013-04-03T11:40:39+02:00</pubDate>
			<description><![CDATA[id:	9955553<br />first:	1364982039<br />last:	0<br />md5:	24a2dbbcea4137e5a329c38cda32a07e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=24a2dbbcea4137e5a329c38cda32a07e<br />vt_score:	5/36 (13.9%)<br />scanner:	AVG<br />virusname:	Suspicion: unknown virus<br />url:	http://curtisgroup-inc.com/ZopzktR1.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.19.185<br />as:	AS8560<br />review:	74.208.19.185<br />domain:	curtisgroup-inc.com<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.79.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	ns58.1and1.com<br />ns2:	ns57.1and1.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/201095360/b8442e7/7f93h34t.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9954538</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9954538</guid>
			<pubDate>2013-04-03T09:40:46+02:00</pubDate>
			<description><![CDATA[id:	9954538<br />first:	1364974846<br />last:	0<br />md5:	b876c7653dac3cc259875172c6bd18aa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b876c7653dac3cc259875172c6bd18aa<br />vt_score:	34/45 (75.6%)<br />scanner:	avira<br />virusname:	TR/Crypt.ZPACK.Gen<br />url:	http://hotfile.com/dl/201095360/b8442e7/7f93h34t.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.232<br />as:	AS7366<br />review:	199.7.177.230<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns1.easydns.com<br />ns2:	ns1.hotfile.com<br />ns3:	ns2.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://satisotomatlari.com/images/atualizacao/ISB31670327.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9938718</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win.Trojan.Spy-70]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9938718</guid>
			<pubDate>2013-04-02T12:40:05+02:00</pubDate>
			<description><![CDATA[id:	9938718<br />first:	1364899205<br />last:	0<br />md5:	8fcb723a091ade0f133aca882f5b8cf2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8fcb723a091ade0f133aca882f5b8cf2<br />vt_score:	29/46 (63%)<br />scanner:	clamav<br />virusname:	Win.Trojan.Spy-70<br />url:	http://satisotomatlari.com/images/atualizacao/ISB31670327.rar<br />recent:	up<br />response:	alive<br />ip:	213.142.141.17<br />as:	AS16265<br />review:	213.142.141.17<br />domain:	satisotomatlari.com<br />country:	TR<br />source:	RIPE<br />email:	ipabuse@adeox.com<br />inetnum:	213.142.136.0 - 213.142.143.255<br />netname:	ADEOXNET<br />descr:	Adeox Hosting Network<br />ns1:	server-6e290821<br />ns2:	ns.satisotomatlari.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cristinaubatuba.com.br/images/stories/refce012/refce012_15.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9938717</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Chifrax.gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9938717</guid>
			<pubDate>2013-04-02T12:40:05+02:00</pubDate>
			<description><![CDATA[id:	9938717<br />first:	1364899205<br />last:	0<br />md5:	12b6c3aa5dab48afcdeb53a168d519ac<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=12b6c3aa5dab48afcdeb53a168d519ac<br />vt_score:	22/46 (47.8%)<br />scanner:	Antiy_AVL<br />virusname:	Trojan/Win32.Chifrax.gen<br />url:	http://cristinaubatuba.com.br/images/stories/refce012/refce012_15.jpg<br />recent:	up<br />response:	alive<br />ip:	187.108.192.52<br />as:	AS53107<br />review:	187.108.192.52<br />domain:	cristinaubatuba.com.br<br />country:	BR<br />source:	LACNIC<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	187.108.192.0 - 187.108.195.255<br />netname:	001.109.184/0004-38<br />descr:	Universo Online S.A.<br />ns1:	ns2.dravos.com<br />ns2:	ns1.dravos.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://f1axion.gr/LkEAg.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9938319</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KDZ.12764]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9938319</guid>
			<pubDate>2013-04-02T11:00:20+02:00</pubDate>
			<description><![CDATA[id:	9938319<br />first:	1364893220<br />last:	0<br />md5:	86bdb5e4a27a2318ccc95595864d6a58<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=86bdb5e4a27a2318ccc95595864d6a58<br />vt_score:	9/36 (25%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KDZ.12764<br />url:	http://f1axion.gr/LkEAg.exe<br />recent:	up<br />response:	alive<br />ip:	85.25.120.154<br />as:	AS8972<br />review:	85.25.120.154<br />domain:	f1axion.gr<br />country:	DE<br />source:	RIPE<br />email:	abuse@server4you.de<br />inetnum:	85.25.112.0 - 85.25.127.255<br />netname:	SERVER4YOU-DSL<br />descr:	SERVER4YOU-DSL Broadband DialinhttpThese IPs are dynamic-assigned broadband IPsInternet-Hosterintergenia AG<br />ns1:	ns1.winzone32.grserver.gr<br />ns2:	ns2.winzone32.grserver.gr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sebassmusic.com/favicon.ico]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9938318</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Dropper/Win32.Injector]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9938318</guid>
			<pubDate>2013-04-02T11:00:19+02:00</pubDate>
			<description><![CDATA[id:	9938318<br />first:	1364893219<br />last:	0<br />md5:	5d2fe09941645450dbc034d23de61eaa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5d2fe09941645450dbc034d23de61eaa<br />vt_score:	34/46 (73.9%)<br />scanner:	AhnLab_V3<br />virusname:	Dropper/Win32.Injector<br />url:	http://sebassmusic.com/favicon.ico<br />recent:	up<br />response:	alive<br />ip:	94.100.20.11<br />as:	AS35017<br />review:	94.100.20.11<br />domain:	sebassmusic.com<br />country:	NL<br />source:	RIPE<br />email:	support@e-dentify.nl<br />inetnum:	94.100.20.0 - 94.100.20.255<br />netname:	E-DENTIFY<br />descr:	E-dentify.nlNL-AS35017<br />ns1:	ns14.e-ns.nl<br />ns2:	ns13.e-ns.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://frecuencia1023.com/jRgkFG.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9938288</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KDZ.12764]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9938288</guid>
			<pubDate>2013-04-02T10:40:04+02:00</pubDate>
			<description><![CDATA[id:	9938288<br />first:	1364892004<br />last:	0<br />md5:	86bdb5e4a27a2318ccc95595864d6a58<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=86bdb5e4a27a2318ccc95595864d6a58<br />vt_score:	9/36 (25%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KDZ.12764<br />url:	http://frecuencia1023.com/jRgkFG.exe<br />recent:	up<br />response:	alive<br />ip:	200.58.114.17<br />as:	ASNA.200.58.112.0 - 200.58.127.255<br />review:	200.58.114.17<br />domain:	frecuencia1023.com<br />country:	AR<br />source:	LACNIC<br />email:	ipmaster@hostmar.com<br />inetnum:	200.58.112.0 - 200.58.127.255<br />netname:	AR-DATT-LACNIC<br />descr:	Dattatec.comCordoba, 3753,2000 - Rosario - SFCordoba, 3753,2000 - Rosario - SF<br />ns1:	ns3.hostmar.com<br />ns2:	ns4.hostmar.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/201058396/97cebd1/c378goqw34ty7i4.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9938053</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Symmi.17074]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9938053</guid>
			<pubDate>2013-04-02T09:41:06+02:00</pubDate>
			<description><![CDATA[id:	9938053<br />first:	1364888466<br />last:	0<br />md5:	6461b8847870fb809c7bcd9d1f5b6c4d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6461b8847870fb809c7bcd9d1f5b6c4d<br />vt_score:	4/36 (11.1%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Symmi.17074<br />url:	http://hotfile.com/dl/201058396/97cebd1/c378goqw34ty7i4.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.244<br />as:	AS7366<br />review:	199.7.177.236<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns1.easydns.com<br />ns2:	ns2.easydns.com<br />ns3:	ns1.hotfile.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ergoholding.ru/rev/gate.php?cmd=getexe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933659</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/ATRAPS.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933659</guid>
			<pubDate>2013-04-01T15:00:03+02:00</pubDate>
			<description><![CDATA[id:	9933659<br />first:	1364821203<br />last:	0<br />md5:	c9c6aeacee9f973ca0ca5da101a12a16<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c9c6aeacee9f973ca0ca5da101a12a16<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	TR/ATRAPS.Gen<br />url:	http://ergoholding.ru/rev/gate.php?cmd=getexe<br />recent:	up<br />response:	alive<br />ip:	62.109.5.151<br />as:	AS29182<br />review:	62.109.5.151<br />domain:	ergoholding.ru<br />country:	RU<br />source:	RIPE<br />email:	abuse@ispsystem.net<br />inetnum:	62.109.0.0 - 62.109.7.255<br />netname:	ISPSYSTEM<br />descr:	ISPsystem at MSM<br />ns1:	ns2.dollardns.net<br />ns2:	ns1.dollardns.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/c/tui.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933328</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Delphi.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933328</guid>
			<pubDate>2013-04-01T14:00:09+02:00</pubDate>
			<description><![CDATA[id:	9933328<br />first:	1364817609<br />last:	0<br />md5:	9ed393937fdde7c7d99238bcb5d47294<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9ed393937fdde7c7d99238bcb5d47294<br />vt_score:	16/36 (44.4%)<br />scanner:	avira<br />virusname:	TR/Dldr.Delphi.Gen<br />url:	http://SuperAdsDomain.ru/c/tui.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns1.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns2.freedns.ws<br />ns4:	ns4.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/bl/1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933206</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KD.921379]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933206</guid>
			<pubDate>2013-04-01T13:41:16+02:00</pubDate>
			<description><![CDATA[id:	9933206<br />first:	1364816476<br />last:	0<br />md5:	09abf42bc0782621124c5f3b1fa3c694<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=09abf42bc0782621124c5f3b1fa3c694<br />vt_score:	6/36 (16.7%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KD.921379<br />url:	http://SuperAdsDomain.ru/bl/1.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns4.freedns.ws<br />ns4:	ns1.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/bl/mail.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933205</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicious File]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933205</guid>
			<pubDate>2013-04-01T13:41:16+02:00</pubDate>
			<description><![CDATA[id:	9933205<br />first:	1364816476<br />last:	0<br />md5:	e60df17001a3cb3c309908ad992a4575<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e60df17001a3cb3c309908ad992a4575<br />vt_score:	5/36 (13.9%)<br />scanner:	eSafe<br />virusname:	Suspicious File<br />url:	http://SuperAdsDomain.ru/bl/mail.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns4.freedns.ws<br />ns4:	ns1.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/bl/111.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933204</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933204</guid>
			<pubDate>2013-04-01T13:41:16+02:00</pubDate>
			<description><![CDATA[id:	9933204<br />first:	1364816476<br />last:	0<br />md5:	f2fbef6378d7429fce3358b77892cfae<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f2fbef6378d7429fce3358b77892cfae<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://SuperAdsDomain.ru/bl/111.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns4.freedns.ws<br />ns4:	ns1.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/bl/setup.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933203</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/ATRAPS.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933203</guid>
			<pubDate>2013-04-01T13:41:16+02:00</pubDate>
			<description><![CDATA[id:	9933203<br />first:	1364816476<br />last:	0<br />md5:	26327ff85959d80cf6680e1e8f4f221b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=26327ff85959d80cf6680e1e8f4f221b<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	TR/ATRAPS.Gen2<br />url:	http://SuperAdsDomain.ru/bl/setup.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns4.freedns.ws<br />ns4:	ns1.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/bl/mailer.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933202</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Worm/Gamarue.I.1066]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933202</guid>
			<pubDate>2013-04-01T13:41:16+02:00</pubDate>
			<description><![CDATA[id:	9933202<br />first:	1364816476<br />last:	0<br />md5:	9f4e6b59505df462af59b94b22354015<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9f4e6b59505df462af59b94b22354015<br />vt_score:	15/36 (41.7%)<br />scanner:	AntiVir<br />virusname:	Worm/Gamarue.I.1066<br />url:	http://SuperAdsDomain.ru/bl/mailer.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns4.freedns.ws<br />ns4:	ns1.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/bl/output.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933201</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.kdz.12397.10]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933201</guid>
			<pubDate>2013-04-01T13:41:16+02:00</pubDate>
			<description><![CDATA[id:	9933201<br />first:	1364816476<br />last:	0<br />md5:	e071f310a1ee4b391d044e2aaf6ebb99<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e071f310a1ee4b391d044e2aaf6ebb99<br />vt_score:	18/36 (50%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.kdz.12397.10<br />url:	http://SuperAdsDomain.ru/bl/output.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns4.freedns.ws<br />ns4:	ns1.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/bl/generator.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933200</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Inject]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933200</guid>
			<pubDate>2013-04-01T13:41:16+02:00</pubDate>
			<description><![CDATA[id:	9933200<br />first:	1364816476<br />last:	0<br />md5:	608e29ecb5fe90744886c9094ecc4aa7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=608e29ecb5fe90744886c9094ecc4aa7<br />vt_score:	29/36 (80.6%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Inject<br />url:	http://SuperAdsDomain.ru/bl/generator.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns4.freedns.ws<br />ns4:	ns1.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/bl/firenze.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933199</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Spyware/Win32.Zbot]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933199</guid>
			<pubDate>2013-04-01T13:41:16+02:00</pubDate>
			<description><![CDATA[id:	9933199<br />first:	1364816476<br />last:	0<br />md5:	63a0f2dd9a9841fa7710ea6d65b46377<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=63a0f2dd9a9841fa7710ea6d65b46377<br />vt_score:	21/36 (58.3%)<br />scanner:	AhnLab_V3<br />virusname:	Spyware/Win32.Zbot<br />url:	http://SuperAdsDomain.ru/bl/firenze.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns4.freedns.ws<br />ns4:	ns1.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/bl/svchost.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933198</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/ATRAPS.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933198</guid>
			<pubDate>2013-04-01T13:41:16+02:00</pubDate>
			<description><![CDATA[id:	9933198<br />first:	1364816476<br />last:	0<br />md5:	ea78eb273f0c633b8a0a86f386f2310b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ea78eb273f0c633b8a0a86f386f2310b<br />vt_score:	41/45 (91.1%)<br />scanner:	avira<br />virusname:	TR/ATRAPS.Gen<br />url:	http://SuperAdsDomain.ru/bl/svchost.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns4.freedns.ws<br />ns4:	ns1.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/sv/bot.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933197</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Delphi.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933197</guid>
			<pubDate>2013-04-01T13:41:16+02:00</pubDate>
			<description><![CDATA[id:	9933197<br />first:	1364816476<br />last:	0<br />md5:	0a47ba384a192c635af8bbf7de806573<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0a47ba384a192c635af8bbf7de806573<br />vt_score:	30/36 (83.3%)<br />scanner:	avira<br />virusname:	TR/Dldr.Delphi.Gen<br />url:	http://SuperAdsDomain.ru/sv/bot.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns4.freedns.ws<br />ns4:	ns1.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/c/1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933196</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[WORM/Rbot.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933196</guid>
			<pubDate>2013-04-01T13:41:15+02:00</pubDate>
			<description><![CDATA[id:	9933196<br />first:	1364816475<br />last:	0<br />md5:	97fe565d2160dd4e834f897b77cabf8f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=97fe565d2160dd4e834f897b77cabf8f<br />vt_score:	33/36 (91.7%)<br />scanner:	avira<br />virusname:	WORM/Rbot.Gen<br />url:	http://SuperAdsDomain.ru/c/1.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns4.freedns.ws<br />ns4:	ns1.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/p/bin.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933194</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Delphi.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933194</guid>
			<pubDate>2013-04-01T13:41:15+02:00</pubDate>
			<description><![CDATA[id:	9933194<br />first:	1364816475<br />last:	0<br />md5:	08054e3b719ea9cc24cf54bcd9ba5722<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=08054e3b719ea9cc24cf54bcd9ba5722<br />vt_score:	31/36 (86.1%)<br />scanner:	avira<br />virusname:	TR/Dldr.Delphi.Gen<br />url:	http://SuperAdsDomain.ru/p/bin.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns4.freedns.ws<br />ns4:	ns1.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/p/u.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933193</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933193</guid>
			<pubDate>2013-04-01T13:41:15+02:00</pubDate>
			<description><![CDATA[id:	9933193<br />first:	1364816475<br />last:	0<br />md5:	5cd1807d8a2aa57058bd4d77988a6b5b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5cd1807d8a2aa57058bd4d77988a6b5b<br />vt_score:	25/36 (69.4%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Gen<br />url:	http://SuperAdsDomain.ru/p/u.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns4.freedns.ws<br />ns2:	ns2.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/p/test.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933192</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.VBKrypt]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933192</guid>
			<pubDate>2013-04-01T13:41:15+02:00</pubDate>
			<description><![CDATA[id:	9933192<br />first:	1364816475<br />last:	0<br />md5:	6ea245bcef11cd07b0bf8c68a1fc79ee<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6ea245bcef11cd07b0bf8c68a1fc79ee<br />vt_score:	20/36 (55.6%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.VBKrypt<br />url:	http://SuperAdsDomain.ru/p/test.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns4.freedns.ws<br />ns2:	ns2.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/c/123.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933191</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Downloader.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933191</guid>
			<pubDate>2013-04-01T13:41:15+02:00</pubDate>
			<description><![CDATA[id:	9933191<br />first:	1364816475<br />last:	0<br />md5:	9122cf2a819f037f679b1c43955bd3a7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9122cf2a819f037f679b1c43955bd3a7<br />vt_score:	33/36 (91.7%)<br />scanner:	avira<br />virusname:	TR/Downloader.Gen<br />url:	http://SuperAdsDomain.ru/c/123.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns4.freedns.ws<br />ns2:	ns2.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/c/456.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933190</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win.Trojan.Agent-221710]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933190</guid>
			<pubDate>2013-04-01T13:41:15+02:00</pubDate>
			<description><![CDATA[id:	9933190<br />first:	1364816475<br />last:	0<br />md5:	bbeb7b39b45dfdf8261fce8900b7145f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bbeb7b39b45dfdf8261fce8900b7145f<br />vt_score:	27/36 (75%)<br />scanner:	clamav<br />virusname:	Win.Trojan.Agent-221710<br />url:	http://SuperAdsDomain.ru/c/456.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns4.freedns.ws<br />ns2:	ns2.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/p/bot.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933189</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.VB]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933189</guid>
			<pubDate>2013-04-01T13:41:15+02:00</pubDate>
			<description><![CDATA[id:	9933189<br />first:	1364816475<br />last:	0<br />md5:	919a620511472063cb9d1383f8af839e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=919a620511472063cb9d1383f8af839e<br />vt_score:	22/29 (75.9%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.VB<br />url:	http://SuperAdsDomain.ru/p/bot.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns4.freedns.ws<br />ns2:	ns2.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/p/777.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933188</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933188</guid>
			<pubDate>2013-04-01T13:41:15+02:00</pubDate>
			<description><![CDATA[id:	9933188<br />first:	1364816475<br />last:	0<br />md5:	ec0034740461f874f24959040e181875<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ec0034740461f874f24959040e181875<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://SuperAdsDomain.ru/p/777.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns4.freedns.ws<br />ns2:	ns2.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/p/still.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933187</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Gimemo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933187</guid>
			<pubDate>2013-04-01T13:41:14+02:00</pubDate>
			<description><![CDATA[id:	9933187<br />first:	1364816474<br />last:	0<br />md5:	87c63eac1ec76a733141ff33b7d93af3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=87c63eac1ec76a733141ff33b7d93af3<br />vt_score:	25/36 (69.4%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Gimemo<br />url:	http://SuperAdsDomain.ru/p/still.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns4.freedns.ws<br />ns2:	ns2.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/c/bot2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933186</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Delphi.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933186</guid>
			<pubDate>2013-04-01T13:41:14+02:00</pubDate>
			<description><![CDATA[id:	9933186<br />first:	1364816474<br />last:	0<br />md5:	fc7ae14084c949ddbb858e1b411d9bab<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fc7ae14084c949ddbb858e1b411d9bab<br />vt_score:	25/36 (69.4%)<br />scanner:	avira<br />virusname:	TR/Dldr.Delphi.Gen<br />url:	http://SuperAdsDomain.ru/c/bot2.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns4.freedns.ws<br />ns2:	ns2.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/p/finished.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933185</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[WIN.Ransom.Blocker-4]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933185</guid>
			<pubDate>2013-04-01T13:41:13+02:00</pubDate>
			<description><![CDATA[id:	9933185<br />first:	1364816473<br />last:	0<br />md5:	898a1f06085f1d1d3f0c50fa90aae3df<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=898a1f06085f1d1d3f0c50fa90aae3df<br />vt_score:	29/36 (80.6%)<br />scanner:	clamav<br />virusname:	WIN.Ransom.Blocker-4<br />url:	http://SuperAdsDomain.ru/p/finished.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns4.freedns.ws<br />ns2:	ns2.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/c/bot1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933184</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Delphi.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933184</guid>
			<pubDate>2013-04-01T13:41:13+02:00</pubDate>
			<description><![CDATA[id:	9933184<br />first:	1364816473<br />last:	0<br />md5:	876d5acc323a705597c58e520d3c5a53<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=876d5acc323a705597c58e520d3c5a53<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	TR/Dldr.Delphi.Gen<br />url:	http://SuperAdsDomain.ru/c/bot1.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns4.freedns.ws<br />ns2:	ns2.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/c/svchost.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933183</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/ATRAPS.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933183</guid>
			<pubDate>2013-04-01T13:41:13+02:00</pubDate>
			<description><![CDATA[id:	9933183<br />first:	1364816473<br />last:	0<br />md5:	79b21e07cf2bf741275f7191ec7f33f2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=79b21e07cf2bf741275f7191ec7f33f2<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	TR/ATRAPS.Gen<br />url:	http://SuperAdsDomain.ru/c/svchost.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns4.freedns.ws<br />ns2:	ns2.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://zalil.ru/34400011/46b9426d.5159bf68/222.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933098</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/ATRAPS.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933098</guid>
			<pubDate>2013-04-01T12:40:03+02:00</pubDate>
			<description><![CDATA[id:	9933098<br />first:	1364812803<br />last:	0<br />md5:	f762a150b70cef908a0f411e2d8f817c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f762a150b70cef908a0f411e2d8f817c<br />vt_score:	43/46 (93.5%)<br />scanner:	avira<br />virusname:	TR/ATRAPS.Gen<br />url:	http://zalil.ru/34400011/46b9426d.5159bf68/222.exe<br />recent:	up<br />response:	alive<br />ip:	194.63.142.66<br />as:	AS21011<br />review:	194.63.142.66<br />domain:	zalil.ru<br />country:	RU<br />source:	RIPE<br />email:	tech@mirotel.net<br />inetnum:	194.63.140.0 - 194.63.143.255<br />netname:	MIROTEL2<br />descr:	ITS Mirotel<br />ns1:	ns3-l2.nic.ru<br />ns2:	ns4-l2.nic.ru<br />ns3:	ns8-l2.nic.ru<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/bl/soft262.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933097</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KD.923455]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933097</guid>
			<pubDate>2013-04-01T12:40:03+02:00</pubDate>
			<description><![CDATA[id:	9933097<br />first:	1364812803<br />last:	0<br />md5:	23c04698f358e7883d74cbb3fe3dabed<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=23c04698f358e7883d74cbb3fe3dabed<br />vt_score:	8/36 (22.2%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KD.923455<br />url:	http://SuperAdsDomain.ru/bl/soft262.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns4.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/bl/zcry.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933096</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.kdz.12576.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933096</guid>
			<pubDate>2013-04-01T12:40:03+02:00</pubDate>
			<description><![CDATA[id:	9933096<br />first:	1364812803<br />last:	0<br />md5:	bfd802c3a484c8184ab437d10e9b0583<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bfd802c3a484c8184ab437d10e9b0583<br />vt_score:	30/46 (65.2%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.kdz.12576.1<br />url:	http://SuperAdsDomain.ru/bl/zcry.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns4.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/bl/done.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933095</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933095</guid>
			<pubDate>2013-04-01T12:40:03+02:00</pubDate>
			<description><![CDATA[id:	9933095<br />first:	1364812803<br />last:	0<br />md5:	19ffd9ea2d42dfb75c6ef31d776cfd22<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=19ffd9ea2d42dfb75c6ef31d776cfd22<br />vt_score:	5/36 (13.9%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://SuperAdsDomain.ru/bl/done.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns4.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://zalil.ru/34289404/16be599b.5159f230/bin.exe.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933094</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Delphi.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933094</guid>
			<pubDate>2013-04-01T12:40:03+02:00</pubDate>
			<description><![CDATA[id:	9933094<br />first:	1364812803<br />last:	0<br />md5:	dc77ce4eacaaafb2cb1711e9e6181325<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dc77ce4eacaaafb2cb1711e9e6181325<br />vt_score:	33/36 (91.7%)<br />scanner:	avira<br />virusname:	TR/Dldr.Delphi.Gen<br />url:	http://zalil.ru/34289404/16be599b.5159f230/bin.exe.exe<br />recent:	up<br />response:	alive<br />ip:	194.63.142.66<br />as:	AS21011<br />review:	194.63.142.66<br />domain:	zalil.ru<br />country:	RU<br />source:	RIPE<br />email:	tech@mirotel.net<br />inetnum:	194.63.140.0 - 194.63.143.255<br />netname:	MIROTEL2<br />descr:	ITS Mirotel<br />ns1:	ns8-l2.nic.ru<br />ns2:	ns3-l2.nic.ru<br />ns3:	ns4-l2.nic.ru<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/c/bot.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9933093</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Delphi.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9933093</guid>
			<pubDate>2013-04-01T12:40:03+02:00</pubDate>
			<description><![CDATA[id:	9933093<br />first:	1364812803<br />last:	0<br />md5:	1dd5756ed018f341dbd970933e5eadd1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1dd5756ed018f341dbd970933e5eadd1<br />vt_score:	31/46 (67.4%)<br />scanner:	avira<br />virusname:	TR/Dldr.Delphi.Gen<br />url:	http://SuperAdsDomain.ru/c/bot.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns4.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns3.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://SuperAdsDomain.ru/p/r.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9932691</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Blocker]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9932691</guid>
			<pubDate>2013-04-01T11:40:09+02:00</pubDate>
			<description><![CDATA[id:	9932691<br />first:	1364809209<br />last:	0<br />md5:	f0009b10c7f25818c16760f64c1ec13d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f0009b10c7f25818c16760f64c1ec13d<br />vt_score:	33/46 (71.7%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Blocker<br />url:	http://SuperAdsDomain.ru/p/r.exe<br />recent:	up<br />response:	alive<br />ip:	91.217.90.237<br />as:	AS21098<br />review:	91.217.90.237<br />domain:	SuperAdsDomain.ru<br />country:	UA<br />source:	RIPE<br />email:	vitaliy@xserver.com.ua<br />inetnum:	91.217.90.0 - 91.217.91.255<br />netname:	IVANOV-IP2<br />descr:	PE Ivanov Vitaliy SergeevichMhost Data Center<br />ns1:	ns2.freedns.ws<br />ns2:	ns3.freedns.ws<br />ns3:	ns1.freedns.ws<br />ns4:	ns4.freedns.ws<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://94.242.198.67/sget.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9927278</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9927278</guid>
			<pubDate>2013-03-31T16:40:20+02:00</pubDate>
			<description><![CDATA[id:	9927278<br />first:	1364740820<br />last:	0<br />md5:	7b114dec4cdfaabb940551b6aa9ef992<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7b114dec4cdfaabb940551b6aa9ef992<br />vt_score:	39/45 (86.7%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://94.242.198.67/sget.exe<br />recent:	up<br />response:	alive<br />ip:	94.242.198.67<br />as:	AS5577<br />review:	94.242.198.67<br />domain:	94.242.198.67<br />country:	LU<br />source:	RIPE<br />email:	abuse@as5577.net<br />inetnum:	94.242.192.0 - 94.242.223.255<br />netname:	ROOT-NETWORK<br />descr:	root SA<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/200478058/ab1db01/flowerito.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9921253</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Backdoor/Win32.Ruskill]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9921253</guid>
			<pubDate>2013-03-30T18:00:05+01:00</pubDate>
			<description><![CDATA[id:	9921253<br />first:	1364662805<br />last:	0<br />md5:	306fbe600befa7f7852b01d1ae0c32c9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=306fbe600befa7f7852b01d1ae0c32c9<br />vt_score:	9/36 (25%)<br />scanner:	AhnLab_V3<br />virusname:	Backdoor/Win32.Ruskill<br />url:	http://hotfile.com/dl/200478058/ab1db01/flowerito.exe<br />recent:	up<br />response:	alive<br />ip:	199.7.177.226<br />as:	AS7366<br />review:	199.7.177.224<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns2.easydns.com<br />ns2:	ns1.easydns.com<br />ns3:	ns1.hotfile.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/200478063/5870b38/ard.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9921252</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Xema]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9921252</guid>
			<pubDate>2013-03-30T18:00:05+01:00</pubDate>
			<description><![CDATA[id:	9921252<br />first:	1364662805<br />last:	0<br />md5:	adfb4b5f4249a1881d6f431253260b90<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=adfb4b5f4249a1881d6f431253260b90<br />vt_score:	8/36 (22.2%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Xema<br />url:	http://hotfile.com/dl/200478063/5870b38/ard.exe<br />recent:	up<br />response:	alive<br />ip:	199.7.177.228<br />as:	AS7366<br />review:	199.7.177.218<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns2.easydns.com<br />ns2:	ns1.easydns.com<br />ns3:	ns1.hotfile.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/200478072/ebdeb60/fgd.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9921251</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win32:Malware-gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9921251</guid>
			<pubDate>2013-03-30T18:00:05+01:00</pubDate>
			<description><![CDATA[id:	9921251<br />first:	1364662805<br />last:	0<br />md5:	6437dd923e3a4e514b3e5ffa930d7f7f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6437dd923e3a4e514b3e5ffa930d7f7f<br />vt_score:	9/35 (25.7%)<br />scanner:	Avast<br />virusname:	Win32:Malware-gen<br />url:	http://hotfile.com/dl/200478072/ebdeb60/fgd.exe<br />recent:	up<br />response:	alive<br />ip:	199.7.177.230<br />as:	AS7366<br />review:	199.7.177.242<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns2.easydns.com<br />ns2:	ns1.easydns.com<br />ns3:	ns1.hotfile.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pxedesign.com/9281.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9920670</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.SelfDel]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9920670</guid>
			<pubDate>2013-03-30T15:40:09+01:00</pubDate>
			<description><![CDATA[id:	9920670<br />first:	1364654409<br />last:	0<br />md5:	aec5644825a9442c5ab608fbf78b2565<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=aec5644825a9442c5ab608fbf78b2565<br />vt_score:	24/36 (66.7%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.SelfDel<br />url:	http://pxedesign.com/9281.exe<br />recent:	up<br />response:	alive<br />ip:	65.98.87.114<br />as:	AS25653<br />review:	65.98.87.114<br />domain:	pxedesign.com<br />country:	US<br />source:	ARIN<br />email:	abuse@fortressitx.com<br />inetnum:	65.98.0.0 - 65.98.127.255<br />netname:	FORTRESSITX<br />descr:	FortressITX FORTR-5 100 Delawanna Ave Clifton NJ 07014<br />ns1:	ns2.kumcsfla.org<br />ns2:	ns1.kumcsfla.org<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://72.167.59.210/8ong.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9915858</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.KD.917544]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9915858</guid>
			<pubDate>2013-03-29T17:40:06+01:00</pubDate>
			<description><![CDATA[id:	9915858<br />first:	1364575206<br />last:	0<br />md5:	77274d5d7878ed64a1d6c50191bd0544<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=77274d5d7878ed64a1d6c50191bd0544<br />vt_score:	36/46 (78.3%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.KD.917544<br />url:	http://72.167.59.210/8ong.exe<br />recent:	up<br />response:	alive<br />ip:	72.167.59.210<br />as:	AS26496<br />review:	72.167.59.210<br />domain:	72.167.59.210<br />country:	US<br />source:	ARIN<br />email:	abuse@godaddy.com<br />inetnum:	72.167.0.0 - 72.167.127.255<br />netname:	GO-DADDY-SOFTWARE-INC<br />descr:	GoDaddy.com, Inc. GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://000023p.rcomhost.com/EJjgELq.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9915857</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.KD.917544]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9915857</guid>
			<pubDate>2013-03-29T17:40:06+01:00</pubDate>
			<description><![CDATA[id:	9915857<br />first:	1364575206<br />last:	0<br />md5:	77274d5d7878ed64a1d6c50191bd0544<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=77274d5d7878ed64a1d6c50191bd0544<br />vt_score:	36/46 (78.3%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.KD.917544<br />url:	http://000023p.rcomhost.com/EJjgELq.exe<br />recent:	up<br />response:	alive<br />ip:	205.178.145.65<br />as:	AS14441, AS19871, AS6245<br />review:	205.178.145.65<br />domain:	rcomhost.com<br />country:	US<br />source:	ARIN<br />email:	noc@networksolutions.com<br />inetnum:	205.178.128.0 - 205.178.191.255<br />netname:	NTSL-01<br />descr:	Network Solutions, LLC NETWO-59 13861 Sunrise Valley Dr Suite 300 Herndon VA 20171<br />ns1:	ns45.worldnic.com<br />ns2:	ns46.worldnic.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://beauty-hair1.home.pl/fwANujLa.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9915856</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.KD.917544]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9915856</guid>
			<pubDate>2013-03-29T17:40:06+01:00</pubDate>
			<description><![CDATA[id:	9915856<br />first:	1364575206<br />last:	0<br />md5:	77274d5d7878ed64a1d6c50191bd0544<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=77274d5d7878ed64a1d6c50191bd0544<br />vt_score:	15/36 (41.7%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.KD.917544<br />url:	http://beauty-hair1.home.pl/fwANujLa.exe<br />recent:	up<br />response:	alive<br />ip:	79.96.177.244<br />as:	AS12824<br />review:	79.96.177.244<br />domain:	home.pl<br />country:	PL<br />source:	RIPE<br />email:	abuse@home.pl<br />inetnum:	79.96.128.0 - 79.96.255.255<br />netname:	HOMEPL<br />descr:	home.pl webhosting farm - static allocation<br />ns1:	dns2.home.pl<br />ns2:	dns3.home.pl<br />ns3:	dns.home.pl<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gvcustomsoftware.com.au/NXuoTn.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9915854</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.KD.917544]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9915854</guid>
			<pubDate>2013-03-29T17:40:06+01:00</pubDate>
			<description><![CDATA[id:	9915854<br />first:	1364575206<br />last:	0<br />md5:	77274d5d7878ed64a1d6c50191bd0544<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=77274d5d7878ed64a1d6c50191bd0544<br />vt_score:	36/46 (78.3%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.KD.917544<br />url:	http://gvcustomsoftware.com.au/NXuoTn.exe<br />recent:	up<br />response:	alive<br />ip:	111.223.234.21<br />as:	AS38880<br />review:	111.223.234.21<br />domain:	gvcustomsoftware.com.au<br />country:	AU<br />source:	APNIC<br />email:	abuse@micron21.com<br />inetnum:	111.223.224.0 - 111.223.239.254<br />netname:	Micron21-Melbourne-Datacentre<br />descr:	Micron21 Melbourne Datacentre Co-Location Dedicated Servers Web HostingColocation and Fully managed servicesColocation, Webhosting etc<br />ns1:	ns2.gvcustomsoftware.com.au<br />ns2:	ns1.gvcustomsoftware.com.au<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://192.211.54.156/Programs/Master/wmdc.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9903763</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win-Trojan/Agent.43008.QN]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9903763</guid>
			<pubDate>2013-03-27T14:41:46+01:00</pubDate>
			<description><![CDATA[id:	9903763<br />first:	1364391706<br />last:	0<br />md5:	14c7d45549321ffc0dcaf474c7025623<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=14c7d45549321ffc0dcaf474c7025623<br />vt_score:	33/46 (71.7%)<br />scanner:	AhnLab_V3<br />virusname:	Win-Trojan/Agent.43008.QN<br />url:	http://192.211.54.156/Programs/Master/wmdc.exe<br />recent:	up<br />response:	alive<br />ip:	192.211.54.156<br />as:	AS174, AS13354<br />review:	192.211.54.156<br />domain:	192.211.54.156<br />country:	US<br />source:	ARIN<br />email:	arincontact@incero.com<br />inetnum:	192.211.48.0 - 192.211.63.255<br />netname:	INCERO-LLC<br />descr:	Incero LLC IL-38 5555 N LAMAR, STE L-121 AUSTIN TX 78751<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vusypxaw.ru/newbos4.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9842474</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Tepfer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9842474</guid>
			<pubDate>2013-03-21T18:40:02+01:00</pubDate>
			<description><![CDATA[id:	9842474<br />first:	1363887602<br />last:	0<br />md5:	53b2d4d0bd39805766dd10ac622078cf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=53b2d4d0bd39805766dd10ac622078cf<br />vt_score:	36/46 (78.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Tepfer<br />url:	http://vusypxaw.ru/newbos4.exe<br />recent:	up<br />response:	alive<br />ip:	93.79.247.31<br />as:	AS25229<br />review:	93.95.189.176<br />domain:	vusypxaw.ru<br />country:	UA<br />source:	RIPE<br />email:	noc@triolan.com<br />inetnum:	93.72.0.0 - 93.79.255.255<br />netname:	LAN_B77<br />descr:	Kiev TroeshinaTriolan, Khakov<br />ns1:	ns4.vusypxaw.ru<br />ns2:	ns5.vusypxaw.ru<br />ns3:	ns3.vusypxaw.ru<br />ns4:	ns6.vusypxaw.ru<br />ns5:	ns1.vusypxaw.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://prix-comparateur.org/annuaire/licence/download/Setup.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9842473</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9842473</guid>
			<pubDate>2013-03-21T18:40:02+01:00</pubDate>
			<description><![CDATA[id:	9842473<br />first:	1363887602<br />last:	0<br />md5:	08bc0f08cbe773666ae684ed81c1763c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=08bc0f08cbe773666ae684ed81c1763c<br />vt_score:	43/46 (93.5%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://prix-comparateur.org/annuaire/licence/download/Setup.exe<br />recent:	up<br />response:	alive<br />ip:	213.186.33.87<br />as:	AS16276<br />review:	213.186.33.87<br />domain:	prix-comparateur.org<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	213.186.33.0 - 213.186.33.255<br />netname:	OVH<br />descr:	OVH SASShared Hosting ServershttpOVH ISPParis, France<br />ns1:	dns13.ovh.net<br />ns2:	ns13.ovh.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://gettrial.store-apps.org/d/conh10.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9842472</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Heuristic.BehavesLike.Win32.ModifiedUPX.C]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9842472</guid>
			<pubDate>2013-03-21T18:40:02+01:00</pubDate>
			<description><![CDATA[id:	9842472<br />first:	1363887602<br />last:	0<br />md5:	12e1dacb0bcea447237fad65acb1e0cc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=12e1dacb0bcea447237fad65acb1e0cc<br />vt_score:	5/35 (14.3%)<br />scanner:	McAfee_GW_Editio<br />virusname:	Heuristic.BehavesLike.Win32.ModifiedUPX.C<br />url:	http://gettrial.store-apps.org/d/conh10.jpg<br />recent:	up<br />response:	alive<br />ip:	95.163.104.94<br />as:	AS12695<br />review:	95.163.104.94<br />domain:	store-apps.org<br />country:	RU<br />source:	RIPE<br />email:	lir@di-net.ru<br />inetnum:	95.163.0.0 - 95.163.255.255<br />netname:	RU-DINET-20081230<br />descr:	Digital Networks CJSCDigital Network JSCMoscow, Russiahttpaggregate prefixDigital Network JSCMoscow, Russiahttpaggregate prefix<br />ns1:	ns2.store-apps.org<br />ns2:	ns1.store-apps.org<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://us-marshals.org/123//download_file.php?e=JavaSignedApplet]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9842471</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Vague]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9842471</guid>
			<pubDate>2013-03-21T18:40:02+01:00</pubDate>
			<description><![CDATA[id:	9842471<br />first:	1363887602<br />last:	0<br />md5:	e737d79910866ba025c8ce642e652ee6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e737d79910866ba025c8ce642e652ee6<br />vt_score:	19/35 (54.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Vague<br />url:	http://us-marshals.org/123//download_file.php?e=JavaSignedApplet<br />recent:	up<br />response:	alive<br />ip:	82.146.60.121<br />as:	AS29182<br />review:	82.146.60.121<br />domain:	us-marshals.org<br />country:	RU<br />source:	RIPE<br />email:	abuse@ispsystem.net<br />inetnum:	82.146.56.0 - 82.146.63.255<br />netname:	ISPSYSTEM<br />descr:	ISPsystem MSK<br />ns1:	dns1.yandex.net<br />ns2:	dns2.yandex.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fanwink.com/dutch/mi/svv.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9830963</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Androm.EB.66]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9830963</guid>
			<pubDate>2013-03-20T10:20:04+01:00</pubDate>
			<description><![CDATA[id:	9830963<br />first:	1363771204<br />last:	0<br />md5:	d91954a5925485ac24c264e14306be5b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d91954a5925485ac24c264e14306be5b<br />vt_score:	6/35 (17.1%)<br />scanner:	AntiVir<br />virusname:	BDS/Androm.EB.66<br />url:	http://fanwink.com/dutch/mi/svv.exe<br />recent:	up<br />response:	alive<br />ip:	178.18.85.175<br />as:	AS35470<br />review:	178.18.85.175<br />domain:	fanwink.com<br />country:	NL<br />source:	RIPE<br />email:	abuse@xl-is.net<br />inetnum:	178.18.80.0 - 178.18.95.255<br />netname:	NL-XLIS-20100412<br />descr:	XL Internet Services B.V.<br />ns1:	ns2.trimp.nl<br />ns2:	ns1.trimp.nl<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://myplanet.su/favicon.ico]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9830962</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.ShipUp]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9830962</guid>
			<pubDate>2013-03-20T10:20:03+01:00</pubDate>
			<description><![CDATA[id:	9830962<br />first:	1363771203<br />last:	0<br />md5:	1ad543ade32cfdb90bc8868871bebe8c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1ad543ade32cfdb90bc8868871bebe8c<br />vt_score:	20/35 (57.1%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.ShipUp<br />url:	http://myplanet.su/favicon.ico<br />recent:	up<br />response:	alive<br />ip:	217.29.51.172<br />as:	AS29053<br />review:	217.29.51.172<br />domain:	myplanet.su<br />country:	RU<br />source:	RIPE<br />email:	<br />inetnum:	217.29.51.168 - 217.29.51.175<br />netname:	TREVEL-NET<br />descr:	Moscow, Russian FederationTelenet Route<br />ns1:	ns1.lightsoft.ru<br />ns2:	ns2.lightsoft.ru<br />ns3:	ns3.lightsoft.ru<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://yurtdisirehber.com/Sinops/tudo.rar]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9830961</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Banker]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9830961</guid>
			<pubDate>2013-03-20T10:20:03+01:00</pubDate>
			<description><![CDATA[id:	9830961<br />first:	1363771203<br />last:	0<br />md5:	c9caffb84b6b00cb150d09e6f448f6a6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c9caffb84b6b00cb150d09e6f448f6a6<br />vt_score:	22/36 (61.1%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Banker<br />url:	http://yurtdisirehber.com/Sinops/tudo.rar<br />recent:	up<br />response:	alive<br />ip:	159.253.37.220<br />as:	AS51559<br />review:	159.253.37.220<br />domain:	yurtdisirehber.com<br />country:	TR<br />source:	RIPE<br />email:	abuse@ni.net.tr<br />inetnum:	159.253.37.0 - 159.253.37.255<br />netname:	NETINTERNET<br />descr:	Netinternet Bilgisayar Telekomunikasyon San. ve Tic. Ltd. Sti.Netinternet Datacenter<br />ns1:	ns1.onaranbilisim.com<br />ns2:	ns2.onaranbilisim.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://picturesofdeath.net/kill/long_fills.php?rsbyo=30:2v:1f:1j:30&lvb=1g:1k:2v:1n:32:1o:1i:1i:32:31&yvehhvt=1i&qabyk=rarokeg&pxrq=xgzaazv]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9828310</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Jorik]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9828310</guid>
			<pubDate>2013-03-19T18:40:18+01:00</pubDate>
			<description><![CDATA[id:	9828310<br />first:	1363714818<br />last:	0<br />md5:	a372939c7134e95f39566dabaede4204<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a372939c7134e95f39566dabaede4204<br />vt_score:	5/35 (14.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Jorik<br />url:	http://picturesofdeath.net/kill/long_fills.php?rsbyo=30:2v:1f:1j:30&lvb=1g:1k:2v:1n:32:1o:1i:1i:32:31&yvehhvt=1i&qabyk=rarokeg&pxrq=xgzaazv<br />recent:	up<br />response:	alive<br />ip:	109.74.61.59<br />as:	AS50261<br />review:	24.111.157.113<br />domain:	picturesofdeath.net<br />country:	US<br />source:	ARIN<br />email:	abuse@midco.net<br />inetnum:	109.74.48.0 - 109.74.63.255<br />netname:	MIDCO<br />descr:	Midcontinent Media, Inc. MIDC 410 S Phillips Ave Sioux Falls SD 57104<br />ns1:	ns1.streetcry.net<br />ns2:	ns2.streetcry.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://raufdn.able.yt/dlimage4.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9823922</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KD.904587]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9823922</guid>
			<pubDate>2013-03-19T04:28:54+01:00</pubDate>
			<description><![CDATA[id:	9823922<br />first:	1363663734<br />last:	0<br />md5:	7ab1e9953686027fefe5361ac3bde65e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7ab1e9953686027fefe5361ac3bde65e<br />vt_score:	12/45 (26.7%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KD.904587<br />url:	http://raufdn.able.yt/dlimage4.php<br />recent:	up<br />response:	alive<br />ip:	91.218.39.245<br />as:	AS197145<br />review:	91.218.39.245<br />domain:	able.yt<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	91.218.36.0 - 91.218.39.255<br />netname:	INFIUMHOST-NET<br />descr:	Infium Ltd.<br />ns1:	ns-usa.topdns.com<br />ns2:	ns-canada.topdns.com<br />ns3:	ns-uk.topdns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://justfruit.gr/KRUbYMps/pXAY7Ja.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9817003</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.ZBot.ald]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9817003</guid>
			<pubDate>2013-03-18T14:00:05+01:00</pubDate>
			<description><![CDATA[id:	9817003<br />first:	1363611605<br />last:	0<br />md5:	096358e65c2a411e89020b7ad1eda2bc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=096358e65c2a411e89020b7ad1eda2bc<br />vt_score:	38/44 (86.4%)<br />scanner:	AntiVir<br />virusname:	TR/Spy.ZBot.ald<br />url:	http://justfruit.gr/KRUbYMps/pXAY7Ja.exe<br />recent:	up<br />response:	alive<br />ip:	85.25.147.8<br />as:	AS8972<br />review:	85.25.147.8<br />domain:	justfruit.gr<br />country:	DE<br />source:	RIPE<br />email:	abuse@server4you.de<br />inetnum:	85.25.129.0 - 85.25.148.255<br />netname:	SERVER4YOU-1<br />descr:	SERVER4YOU Dedicated Server HostinghttpInternet-Hosterintergenia AG<br />ns1:	ns1.nameserverservice.de<br />ns2:	ns2.nameserverservice.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bazeley-architects.co.uk/D2rfJsLM.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9817002</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Spyware/Win32.Zbot]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9817002</guid>
			<pubDate>2013-03-18T14:00:05+01:00</pubDate>
			<description><![CDATA[id:	9817002<br />first:	1363611605<br />last:	0<br />md5:	d3839f02fcc434180d6db875e8f875bc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d3839f02fcc434180d6db875e8f875bc<br />vt_score:	35/46 (76.1%)<br />scanner:	AhnLab_V3<br />virusname:	Spyware/Win32.Zbot<br />url:	http://bazeley-architects.co.uk/D2rfJsLM.exe<br />recent:	up<br />response:	alive<br />ip:	212.227.159.88<br />as:	AS8560<br />review:	212.227.159.88<br />domain:	bazeley-architects.co.uk<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	212.227.144.0 - 212.227.159.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AGNCC#1999110113<br />ns1:	ns3.orakle.co.uk<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.tw4r.com/data/thecoon/b.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9814705</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win-Trojan/Blocker.151552]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9814705</guid>
			<pubDate>2013-03-18T11:41:05+01:00</pubDate>
			<description><![CDATA[id:	9814705<br />first:	1363603265<br />last:	0<br />md5:	e4cee6b8bdc9b87b5eee1aabb02f44f9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e4cee6b8bdc9b87b5eee1aabb02f44f9<br />vt_score:	33/46 (71.7%)<br />scanner:	AhnLab_V3<br />virusname:	Win-Trojan/Blocker.151552<br />url:	http://www.tw4r.com/data/thecoon/b.exe<br />recent:	up<br />response:	alive<br />ip:	37.59.13.112<br />as:	AS16276<br />review:	37.59.13.112<br />domain:	tw4r.com<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	37.59.0.0 - 37.59.63.255<br />netname:	OVH<br />descr:	OVH SASDedicated servershttp<br />ns1:	ns1.hostmonster.com<br />ns2:	ns2.hostmonster.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://twilighteclipse.us/download/sharp/svchost.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9814704</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.FKM.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9814704</guid>
			<pubDate>2013-03-18T11:41:05+01:00</pubDate>
			<description><![CDATA[id:	9814704<br />first:	1363603265<br />last:	0<br />md5:	cccef14296890550891084e3c1577a3b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cccef14296890550891084e3c1577a3b<br />vt_score:	35/46 (76.1%)<br />scanner:	avira<br />virusname:	TR/Crypt.FKM.Gen<br />url:	http://twilighteclipse.us/download/sharp/svchost.exe<br />recent:	up<br />response:	alive<br />ip:	94.102.48.101<br />as:	AS29073<br />review:	94.102.48.101<br />domain:	twilighteclipse.us<br />country:	NL<br />source:	RIPE<br />email:	abuse@ecatel.net<br />inetnum:	94.102.48.0 - 94.102.48.255<br />netname:	NL-ECATEL<br />descr:	ECATEL LTDDedicated servershttp<br />ns1:	ns2.offshore-dns.net<br />ns2:	ns1.offshore-dns.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://turbo-tax.org/sharpjacker/bot.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9814703</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.MK]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9814703</guid>
			<pubDate>2013-03-18T11:41:04+01:00</pubDate>
			<description><![CDATA[id:	9814703<br />first:	1363603264<br />last:	0<br />md5:	7d5edc07877b3654390632c60720762f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7d5edc07877b3654390632c60720762f<br />vt_score:	32/35 (91.4%)<br />scanner:	avira<br />virusname:	TR/Kazy.MK<br />url:	http://turbo-tax.org/sharpjacker/bot.exe<br />recent:	up<br />response:	alive<br />ip:	94.102.48.101<br />as:	AS29073<br />review:	94.102.48.101<br />domain:	turbo-tax.org<br />country:	NL<br />source:	RIPE<br />email:	abuse@ecatel.net<br />inetnum:	94.102.48.0 - 94.102.48.255<br />netname:	NL-ECATEL<br />descr:	ECATEL LTDDedicated servershttp<br />ns1:	ns2.offshore-dns.net<br />ns2:	ns1.offshore-dns.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://picturesofdeath.net/kill/long_fills.php?hkezfs=1n:2w:2w:31:2v&pvgssu=1g:1k:2v:1n:32:1o:1i:1i:32:31&ukz=1i&mhjrkco=hbwqnvv&ztmtkihp=gspls]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9773806</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Jorik]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9773806</guid>
			<pubDate>2013-03-15T18:20:12+01:00</pubDate>
			<description><![CDATA[id:	9773806<br />first:	1363368012<br />last:	0<br />md5:	a372939c7134e95f39566dabaede4204<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a372939c7134e95f39566dabaede4204<br />vt_score:	5/35 (14.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Jorik<br />url:	http://picturesofdeath.net/kill/long_fills.php?hkezfs=1n:2w:2w:31:2v&pvgssu=1g:1k:2v:1n:32:1o:1i:1i:32:31&ukz=1i&mhjrkco=hbwqnvv&ztmtkihp=gspls<br />recent:	up<br />response:	alive<br />ip:	155.239.247.247<br />as:	AS5713<br />review:	58.26.233.175<br />domain:	picturesofdeath.net<br />country:	MY<br />source:	APNIC<br />email:	pieter@saix.net<br />inetnum:	155.239.0.0 - 155.239.255.255<br />netname:	TELKOM<br />descr:	7500<br />ns1:	ns1.streetcry.net<br />ns2:	ns2.streetcry.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/198303412/e054426/cx.exe.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9770117</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[UnclassifiedMalware]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9770117</guid>
			<pubDate>2013-03-15T11:40:11+01:00</pubDate>
			<description><![CDATA[id:	9770117<br />first:	1363344011<br />last:	0<br />md5:	b29921383a05c43fcb685f592e55af7a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b29921383a05c43fcb685f592e55af7a<br />vt_score:	6/35 (17.1%)<br />scanner:	Comodo<br />virusname:	UnclassifiedMalware<br />url:	http://hotfile.com/dl/198303412/e054426/cx.exe.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.236<br />as:	AS7366<br />review:	199.7.177.234<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns2.easydns.com<br />ns2:	ns1.hotfile.com<br />ns3:	ns1.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://176.31.53.137/updt/nfs.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9768897</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Bublik]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9768897</guid>
			<pubDate>2013-03-15T10:00:03+01:00</pubDate>
			<description><![CDATA[id:	9768897<br />first:	1363338003<br />last:	0<br />md5:	10a9b08640b2019f11b83e4fb8a2478a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=10a9b08640b2019f11b83e4fb8a2478a<br />vt_score:	36/46 (78.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Bublik<br />url:	http://176.31.53.137/updt/nfs.exe<br />recent:	up<br />response:	alive<br />ip:	176.31.53.137<br />as:	AS16276<br />review:	176.31.53.137<br />domain:	176.31.53.137<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	176.31.0.0 - 176.31.255.255<br />netname:	FR-OVH-20110520<br />descr:	Ovh Systems<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://max.ick.su/about/library/movie.php?id=3D126793214]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9757421</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9757421</guid>
			<pubDate>2013-03-14T13:40:05+01:00</pubDate>
			<description><![CDATA[id:	9757421<br />first:	1363264805<br />last:	0<br />md5:	2fbe95e22614d8f9e5e1c0545ec780de<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2fbe95e22614d8f9e5e1c0545ec780de<br />vt_score:	6/35 (17.1%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen2<br />url:	http://max.ick.su/about/library/movie.php?id=3D126793214<br />recent:	up<br />response:	alive<br />ip:	92.53.106.185<br />as:	AS20597<br />review:	92.53.106.185<br />domain:	ick.su<br />country:	RU<br />source:	RIPE<br />email:	noc@twnet.ru<br />inetnum:	92.53.104.0 - 92.53.107.255<br />netname:	RZT-TWNetSol<br />descr:	TW Network SolutionRZT-TIMEWEB<br />ns1:	ns3.timeweb.org<br />ns2:	ns1.timeweb.ru<br />ns3:	ns2.timeweb.ru<br />ns4:	ns4.timeweb.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://iramaferreira.hospedagemdesites.ws/dllgood.pdf]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9755758</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win-Trojan/Siggen.1916928]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9755758</guid>
			<pubDate>2013-03-14T10:40:13+01:00</pubDate>
			<description><![CDATA[id:	9755758<br />first:	1363254013<br />last:	0<br />md5:	b558616dfa40cae7e6b7b17057203495<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b558616dfa40cae7e6b7b17057203495<br />vt_score:	33/46 (71.7%)<br />scanner:	AhnLab_V3<br />virusname:	Win-Trojan/Siggen.1916928<br />url:	http://iramaferreira.hospedagemdesites.ws/dllgood.pdf<br />recent:	up<br />response:	alive<br />ip:	186.202.153.105<br />as:	AS27715<br />review:	186.202.153.105<br />domain:	hospedagemdesites.ws<br />country:	BR<br />source:	LACNIC<br />email:	regcom@locaweb.com.br<br />inetnum:	186.202.0.0 - 186.202.255.255<br />netname:	002.351.877/0001-52<br />descr:	Locaweb Serviços de Internet S/A<br />ns1:	ns1.hospedagemdesites.ws<br />ns2:	ns2.hospedagemdesites.ws<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/198093236/e93b3de/tet.exe.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9742080</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Scarsi]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9742080</guid>
			<pubDate>2013-03-13T14:40:16+01:00</pubDate>
			<description><![CDATA[id:	9742080<br />first:	1363182016<br />last:	0<br />md5:	df9dd1ce6ed8bda05ac723fe8c71bf87<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=df9dd1ce6ed8bda05ac723fe8c71bf87<br />vt_score:	33/46 (71.7%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Scarsi<br />url:	http://hotfile.com/dl/198093236/e93b3de/tet.exe.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.232<br />as:	AS7366<br />review:	199.7.177.230<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns1.easydns.com<br />ns2:	ns2.easydns.com<br />ns3:	ns1.hotfile.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lachimieszd.com/colischronoposthtmlcolischronoposthtmlcolischronoposthtmlcolischronoposthtml]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9724574</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Backdoor/Win32.DarkKomet]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9724574</guid>
			<pubDate>2013-03-12T12:40:03+01:00</pubDate>
			<description><![CDATA[id:	9724574<br />first:	1363088403<br />last:	0<br />md5:	01ec03319966ca96eee4ce20485a48b2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=01ec03319966ca96eee4ce20485a48b2<br />vt_score:	17/36 (47.2%)<br />scanner:	AhnLab_V3<br />virusname:	Backdoor/Win32.DarkKomet<br />url:	http://lachimieszd.com/colischronoposthtmlcolischronoposthtmlcolischronoposthtmlcolischronoposthtml<br />recent:	up<br />response:	alive<br />ip:	213.186.33.3<br />as:	AS16276<br />review:	213.186.33.3<br />domain:	lachimieszd.com<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	213.186.33.0 - 213.186.33.255<br />netname:	OVH<br />descr:	OVH SASShared Hosting ServershttpOVH ISPParis, France<br />ns1:	ns104.ovh.net<br />ns2:	dns104.ovh.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://museum-synt-isap.gr/ZkN.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9724573</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Spyware/Win32.Zbot]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9724573</guid>
			<pubDate>2013-03-12T12:40:03+01:00</pubDate>
			<description><![CDATA[id:	9724573<br />first:	1363088403<br />last:	0<br />md5:	2a384e16a39dd0b3d0596f6deb9cf3d1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2a384e16a39dd0b3d0596f6deb9cf3d1<br />vt_score:	29/36 (80.6%)<br />scanner:	AhnLab_V3<br />virusname:	Spyware/Win32.Zbot<br />url:	http://museum-synt-isap.gr/ZkN.exe<br />recent:	up<br />response:	alive<br />ip:	188.165.252.160<br />as:	AS16276<br />review:	188.165.252.160<br />domain:	museum-synt-isap.gr<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	188.165.192.0 - 188.165.255.255<br />netname:	OVH<br />descr:	OVH SASDedicated Servershttp<br />ns1:	ns2.artime-adv.com<br />ns2:	ns1.artime-adv.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/197958699/2ea412a/po.exe.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9724570</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Scarsi]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9724570</guid>
			<pubDate>2013-03-12T12:40:03+01:00</pubDate>
			<description><![CDATA[id:	9724570<br />first:	1363088403<br />last:	0<br />md5:	887af94471e793e9cf741c320b4ff087<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=887af94471e793e9cf741c320b4ff087<br />vt_score:	26/36 (72.2%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Scarsi<br />url:	http://hotfile.com/dl/197958699/2ea412a/po.exe.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.240<br />as:	AS7366<br />review:	199.7.177.238<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns1.easydns.com<br />ns2:	ns2.easydns.com<br />ns3:	ns1.hotfile.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bvyus.badauyeu.tk/plugin.php?fname=flashplayer]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9724272</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Backdoor/Win32.Cidox]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9724272</guid>
			<pubDate>2013-03-12T12:00:11+01:00</pubDate>
			<description><![CDATA[id:	9724272<br />first:	1363086011<br />last:	0<br />md5:	8192e93545fbedf5df21b8cf589e5946<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8192e93545fbedf5df21b8cf589e5946<br />vt_score:	29/36 (80.6%)<br />scanner:	AhnLab_V3<br />virusname:	Backdoor/Win32.Cidox<br />url:	http://bvyus.badauyeu.tk/plugin.php?fname=flashplayer<br />recent:	up<br />response:	alive<br />ip:	46.4.194.146<br />as:	AS24940<br />review:	46.4.194.146<br />domain:	badauyeu.tk<br />country:	DE<br />source:	RIPE<br />email:	abuse@hetzner.de<br />inetnum:	46.4.0.0 - 46.4.255.255<br />netname:	DE-HETZNER-20100819<br />descr:	Hetzner Online AG<br />ns1:	ns4.afraid.org<br />ns2:	ns3.afraid.org<br />ns3:	ns2.afraid.org<br />ns4:	ns1.afraid.org<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://palmaturismo.com/templates/herbstv1/lo.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9724271</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win.Trojan.Zbot-10645]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9724271</guid>
			<pubDate>2013-03-12T12:00:11+01:00</pubDate>
			<description><![CDATA[id:	9724271<br />first:	1363086011<br />last:	0<br />md5:	3e54d11b94d7fe4f9c53cc3b71a9693d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3e54d11b94d7fe4f9c53cc3b71a9693d<br />vt_score:	35/46 (76.1%)<br />scanner:	clamav<br />virusname:	Win.Trojan.Zbot-10645<br />url:	http://palmaturismo.com/templates/herbstv1/lo.exe<br />recent:	up<br />response:	alive<br />ip:	87.106.193.179<br />as:	AS8560<br />review:	87.106.193.179<br />domain:	palmaturismo.com<br />country:	ES<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	87.106.192.0 - 87.106.195.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGSCHLUND-PA-5<br />ns1:	ns63.1and1.es<br />ns2:	ns64.1and1.es<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://simplysuperbiketickets.com/sp0n.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9724270</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Scarsi]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9724270</guid>
			<pubDate>2013-03-12T12:00:10+01:00</pubDate>
			<description><![CDATA[id:	9724270<br />first:	1363086010<br />last:	0<br />md5:	a9a14b8e3b5adbfd5738906bba087a67<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a9a14b8e3b5adbfd5738906bba087a67<br />vt_score:	35/46 (76.1%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Scarsi<br />url:	http://simplysuperbiketickets.com/sp0n.exe<br />recent:	up<br />response:	alive<br />ip:	82.165.140.9<br />as:	AS8560<br />review:	82.165.140.9<br />domain:	simplysuperbiketickets.com<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.128.0 - 82.165.143.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AG<br />ns1:	ns67.1and1.co.uk<br />ns2:	ns68.1and1.co.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.neyrou.fr/xwc/upload/g.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9714611</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Backdoor.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9714611</guid>
			<pubDate>2013-03-11T22:40:23+01:00</pubDate>
			<description><![CDATA[id:	9714611<br />first:	1363038023<br />last:	0<br />md5:	7f00e5a36b363af36b187fdd5beb981f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7f00e5a36b363af36b187fdd5beb981f<br />vt_score:	31/45 (68.9%)<br />scanner:	avira<br />virusname:	BDS/Backdoor.Gen<br />url:	http://www.neyrou.fr/xwc/upload/g.exe<br />recent:	up<br />response:	alive<br />ip:	109.234.161.32<br />as:	AS50474<br />review:	109.234.161.32<br />domain:	neyrou.fr<br />country:	FR<br />source:	RIPE<br />email:	ripe@o2switch.fr<br />inetnum:	109.234.161.0 - 109.234.161.255<br />netname:	O2SWITCH<br />descr:	o2switch Datacenter Ip-Range-2<br />ns1:	ns1.o2switch.net<br />ns2:	ns2.o2switch.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://kanmay.cafe24.com/xxx.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9712514</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win-Adware/Urelas.107041]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9712514</guid>
			<pubDate>2013-03-11T17:00:07+01:00</pubDate>
			<description><![CDATA[id:	9712514<br />first:	1363017607<br />last:	0<br />md5:	9e1125979be7ec801afab6ee356adba8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9e1125979be7ec801afab6ee356adba8<br />vt_score:	29/46 (63%)<br />scanner:	AhnLab_V3<br />virusname:	Win-Adware/Urelas.107041<br />url:	http://kanmay.cafe24.com/xxx.exe<br />recent:	up<br />response:	alive<br />ip:	112.175.50.185<br />as:	AS132524<br />review:	112.175.50.185<br />domain:	cafe24.com<br />country:	KR<br />source:	APNIC<br />email:	<br />inetnum:	112.160.0.0 - 112.175.255.255<br />netname:	<br />descr:	<br />ns1:	nc4.cafe24.com<br />ns2:	nc3.cafe24.com<br />ns3:	ns3.cafe24.com<br />ns4:	ns4.cafe24.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://217.160.213.35/pula.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9712513</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Scarsi]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9712513</guid>
			<pubDate>2013-03-11T17:00:07+01:00</pubDate>
			<description><![CDATA[id:	9712513<br />first:	1363017607<br />last:	0<br />md5:	beadf499343a0aa53fbe5a129d449373<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=beadf499343a0aa53fbe5a129d449373<br />vt_score:	34/46 (73.9%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Scarsi<br />url:	http://217.160.213.35/pula.exe<br />recent:	up<br />response:	alive<br />ip:	217.160.213.35<br />as:	AS209<br />review:	217.160.213.35<br />domain:	217.160.213.35<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	217.160.208.0 - 217.160.223.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AGNCC#1999110113<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://salmonesriopuelo.cl/PGg.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9712512</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Spyware/Win32.Zbot]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9712512</guid>
			<pubDate>2013-03-11T17:00:07+01:00</pubDate>
			<description><![CDATA[id:	9712512<br />first:	1363017607<br />last:	0<br />md5:	cebd54146d22f5f88e09c40e61808e50<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cebd54146d22f5f88e09c40e61808e50<br />vt_score:	6/35 (17.1%)<br />scanner:	AhnLab_V3<br />virusname:	Spyware/Win32.Zbot<br />url:	http://salmonesriopuelo.cl/PGg.exe<br />recent:	up<br />response:	alive<br />ip:	184.173.197.198<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	184.173.197.198<br />domain:	salmonesriopuelo.cl<br />country:	US<br />source:	ARIN<br />email:	noc@theplanet.com<br />inetnum:	184.172.0.0 - 184.173.255.255<br />netname:	NETBLK-THEPLANET-BLK-17<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns401.hostgator.com<br />ns2:	ns402.hostgator.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://giftmarketing.net/qAuX3EL.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9712511</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Spyware/Win32.Zbot]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9712511</guid>
			<pubDate>2013-03-11T17:00:07+01:00</pubDate>
			<description><![CDATA[id:	9712511<br />first:	1363017607<br />last:	0<br />md5:	6254a1d9b7c80fba0d48744cca9f65fa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6254a1d9b7c80fba0d48744cca9f65fa<br />vt_score:	36/46 (78.3%)<br />scanner:	AhnLab_V3<br />virusname:	Spyware/Win32.Zbot<br />url:	http://giftmarketing.net/qAuX3EL.exe<br />recent:	up<br />response:	alive<br />ip:	64.29.145.9<br />as:	AS30447<br />review:	64.29.145.9<br />domain:	giftmarketing.net<br />country:	US<br />source:	ARIN<br />email:	admin@internetnamesforbusiness.com<br />inetnum:	64.29.144.0 - 64.29.159.255<br />netname:	MEGA-2<br />descr:	InternetNamesForBusiness.com INFB 500 East Broward Boulevard Suite 1700 Fort Lauderdale FL 33394<br />ns1:	ns1.carrierzone.com<br />ns2:	ns3.carrierzone.com<br />ns3:	ns2.carrierzone.com<br />ns4:	ns4.carrierzone.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.lypto.ch/K2d98Z.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9712510</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Spyware/Win32.Zbot]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9712510</guid>
			<pubDate>2013-03-11T17:00:07+01:00</pubDate>
			<description><![CDATA[id:	9712510<br />first:	1363017607<br />last:	0<br />md5:	6254a1d9b7c80fba0d48744cca9f65fa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6254a1d9b7c80fba0d48744cca9f65fa<br />vt_score:	36/46 (78.3%)<br />scanner:	AhnLab_V3<br />virusname:	Spyware/Win32.Zbot<br />url:	http://www.lypto.ch/K2d98Z.exe<br />recent:	up<br />response:	alive<br />ip:	194.124.233.172<br />as:	AS3303<br />review:	194.124.233.172<br />domain:	lypto.ch<br />country:	CH<br />source:	RIPE<br />email:	mzuercher@epc.ch<br />inetnum:	194.124.233.0 - 194.124.233.255<br />netname:	EDVPC<br />descr:	EDV-Perform ConsultingNetwork Consulting and SupportKirchbergUitikon GIB Solution<br />ns1:	specter.mva-n.net<br />ns2:	web01.opentag.ch<br />ns3:	ns.lypto.ch<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/197865129/fc04997/truck.exe.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9712463</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[UnclassifiedMalware]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9712463</guid>
			<pubDate>2013-03-11T16:10:04+01:00</pubDate>
			<description><![CDATA[id:	9712463<br />first:	1363014604<br />last:	0<br />md5:	23ae2559fb71dacd7e6d63b6183ffaaf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=23ae2559fb71dacd7e6d63b6183ffaaf<br />vt_score:	8/32 (25%)<br />scanner:	Comodo<br />virusname:	UnclassifiedMalware<br />url:	http://hotfile.com/dl/197865129/fc04997/truck.exe.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.240<br />as:	AS7366<br />review:	199.7.177.238<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns2.easydns.com<br />ns2:	ns1.easydns.com<br />ns3:	ns1.hotfile.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://217.160.213.35/upppa.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9712233</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.585728.266]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9712233</guid>
			<pubDate>2013-03-11T12:10:05+01:00</pubDate>
			<description><![CDATA[id:	9712233<br />first:	1363000205<br />last:	0<br />md5:	02e2db1413f738a4d65047e60ba6cca0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=02e2db1413f738a4d65047e60ba6cca0<br />vt_score:	33/46 (71.7%)<br />scanner:	AntiVir<br />virusname:	TR/Agent.585728.266<br />url:	http://217.160.213.35/upppa.exe<br />recent:	up<br />response:	alive<br />ip:	217.160.213.35<br />as:	AS209<br />review:	217.160.213.35<br />domain:	217.160.213.35<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	217.160.208.0 - 217.160.223.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AGNCC#1999110113<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://uploaded.net/file/b43z440t]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9712232</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.585728.266]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9712232</guid>
			<pubDate>2013-03-11T12:10:05+01:00</pubDate>
			<description><![CDATA[id:	9712232<br />first:	1363000205<br />last:	0<br />md5:	02e2db1413f738a4d65047e60ba6cca0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=02e2db1413f738a4d65047e60ba6cca0<br />vt_score:	11/32 (34.4%)<br />scanner:	AntiVir<br />virusname:	TR/Agent.585728.266<br />url:	http://uploaded.net/file/b43z440t<br />recent:	up<br />response:	alive<br />ip:	95.211.143.200<br />as:	AS16265<br />review:	95.211.143.200<br />domain:	uploaded.net<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.uploaded.net<br />ns2:	ns3.uploaded.net<br />ns3:	ns4.uploaded.net<br />ns4:	ns2.uploaded.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://royclub.fr/51dvPk.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9712175</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Tepfer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9712175</guid>
			<pubDate>2013-03-11T11:10:02+01:00</pubDate>
			<description><![CDATA[id:	9712175<br />first:	1362996602<br />last:	0<br />md5:	cc0be13e7bb53dd4b18e8656532c8862<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cc0be13e7bb53dd4b18e8656532c8862<br />vt_score:	39/46 (84.8%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Tepfer<br />url:	http://royclub.fr/51dvPk.exe<br />recent:	up<br />response:	alive<br />ip:	82.165.218.118<br />as:	AS8560<br />review:	82.165.218.118<br />domain:	royclub.fr<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.0.0 - 82.165.255.255<br />netname:	DE-SCHLUND-20030806<br />descr:	1&1 Internet AGSCHLUND-PA-4<br />ns1:	ns62.1and1.fr<br />ns2:	ns61.1and1.fr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/197728243/0d80b65/ObgFMxy.exe.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9712139</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KD.892516]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9712139</guid>
			<pubDate>2013-03-11T09:10:04+01:00</pubDate>
			<description><![CDATA[id:	9712139<br />first:	1362989404<br />last:	0<br />md5:	630daae93fb3e8b7bc13e0aa3e8f7963<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=630daae93fb3e8b7bc13e0aa3e8f7963<br />vt_score:	6/17 (35.3%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KD.892516<br />url:	http://hotfile.com/dl/197728243/0d80b65/ObgFMxy.exe.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.242<br />as:	AS7366<br />review:	199.7.177.232<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns1.hotfile.com<br />ns2:	ns2.easydns.com<br />ns3:	ns1.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fotografiewilcodevilee.nl/wp-content/plugins/Radar-Earth-Fungus/form_2012_9534259207.pdf.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9626652</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen8]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9626652</guid>
			<pubDate>2013-03-01T14:50:01+01:00</pubDate>
			<description><![CDATA[id:	9626652<br />first:	1362145801<br />last:	0<br />md5:	10337ebf7f457fb73685426dd3c18e61<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=10337ebf7f457fb73685426dd3c18e61<br />vt_score:	36/45 (80%)<br />scanner:	AntiVir<br />virusname:	TR/Crypt.ZPACK.Gen8<br />url:	http://fotografiewilcodevilee.nl/wp-content/plugins/Radar-Earth-Fungus/form_2012_9534259207.pdf.exe<br />recent:	up<br />response:	alive<br />ip:	81.169.145.147<br />as:	AS6724<br />review:	81.169.145.147<br />domain:	fotografiewilcodevilee.nl<br />country:	DE<br />source:	RIPE<br />email:	abuse@strato.de<br />inetnum:	81.169.144.0 - 81.169.156.255<br />netname:	STRATO-RZG-KA<br />descr:	Strato Rechenzentrum, BerlinStrato Rechenzentrum<br />ns1:	shades12.rzone.de<br />ns2:	docks19.rzone.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://78.83.177.250/m.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9613749</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen8]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9613749</guid>
			<pubDate>2013-02-27T20:50:02+01:00</pubDate>
			<description><![CDATA[id:	9613749<br />first:	1361994602<br />last:	0<br />md5:	26be87936563ca147a47a5eb087d1908<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=26be87936563ca147a47a5eb087d1908<br />vt_score:	15/36 (41.7%)<br />scanner:	AntiVir<br />virusname:	TR/Crypt.XPACK.Gen8<br />url:	http://78.83.177.250/m.exe<br />recent:	up<br />response:	alive<br />ip:	78.83.177.250<br />as:	AS29580<br />review:	78.83.177.250<br />domain:	78.83.177.250<br />country:	BG<br />source:	RIPE<br />email:	abuse@spnet.net<br />inetnum:	78.83.0.0 - 78.83.255.255<br />netname:	BG-SPNET-20071416<br />descr:	Spectrum NET Jsc<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://serumx.com.tr/g3Asmrw.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9606344</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win32:Malware-gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9606344</guid>
			<pubDate>2013-02-26T17:00:06+01:00</pubDate>
			<description><![CDATA[id:	9606344<br />first:	1361894406<br />last:	0<br />md5:	23c160500d0e456655b2ec0615fed0ff<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=23c160500d0e456655b2ec0615fed0ff<br />vt_score:	17/35 (48.6%)<br />scanner:	Avast<br />virusname:	Win32:Malware-gen<br />url:	http://serumx.com.tr/g3Asmrw.exe<br />recent:	up<br />response:	alive<br />ip:	85.153.46.40<br />as:	AS31365<br />review:	85.153.46.40<br />domain:	serumx.com.tr<br />country:	TR<br />source:	RIPE<br />email:	ripe@sgstelecom.com<br />inetnum:	85.153.32.0 - 85.153.47.255<br />netname:	MECIDIYEKOY-POP3<br />descr:	Profilo Telekom A.S.Profilo Telekom # 1<br />ns1:	win8.turkishost.com<br />ns2:	win7.turkishost.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://onlinestreams.zapto.org/videos/skydl2.php?cid=b265d7ad427bcccd&id=B265D7AD427BCCCD%21107&file=Setup.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9603872</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Agent.giuu]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9603872</guid>
			<pubDate>2013-02-26T10:40:03+01:00</pubDate>
			<description><![CDATA[id:	9603872<br />first:	1361871603<br />last:	0<br />md5:	ac3129819faa20a776239f48e57d2b35<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6dc142083bb58cb8219b92fc6dbb7336<br />vt_score:	1/38 (2.6%)<br />scanner:	Jiangmin<br />virusname:	Trojan/Agent.giuu<br />url:	http://onlinestreams.zapto.org/videos/skydl2.php?cid=b265d7ad427bcccd&id=B265D7AD427BCCCD%21107&file=Setup.exe<br />recent:	up<br />response:	alive<br />ip:	188.120.254.152<br />as:	AS29182<br />review:	188.120.254.152<br />domain:	zapto.org<br />country:	US<br />source:	RIPE<br />email:	abuse@ispserver.com<br />inetnum:	188.120.254.0 - 188.120.255.255<br />netname:	CLOUD-NET<br />descr:	CLOUD NAC collocationCLOUD, NAC site allocation<br />ns1:	nf5.no-ip.com<br />ns2:	nf2.no-ip.com<br />ns3:	nf1.no-ip.com<br />ns4:	nf3.no-ip.com<br />ns5:	nf4.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://igallery.php-dev.in/hW4e.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9539639</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win.Trojan.8145]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9539639</guid>
			<pubDate>2013-02-20T14:40:09+01:00</pubDate>
			<description><![CDATA[id:	9539639<br />first:	1361367609<br />last:	0<br />md5:	af9488c667c91eb894df1681e4d4d9f7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=af9488c667c91eb894df1681e4d4d9f7<br />vt_score:	24/35 (68.6%)<br />scanner:	clamav<br />virusname:	Win.Trojan.8145<br />url:	http://igallery.php-dev.in/hW4e.exe<br />recent:	up<br />response:	alive<br />ip:	180.149.243.31<br />as:	AS33480<br />review:	180.149.243.31<br />domain:	php-dev.in<br />country:	IN<br />source:	APNIC<br />email:	abuse@webwerks.com<br />inetnum:	180.149.240.0 - 180.149.245.255<br />netname:	WEBWERKS1-AP<br />descr:	Web Werks India Pvt. Ltd.<br />ns1:	ns1.rapidns.com<br />ns2:	ns2.rapidns.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://elmascarodelmundo.com/wpe.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9537698</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Dropper]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9537698</guid>
			<pubDate>2013-02-20T09:00:06+01:00</pubDate>
			<description><![CDATA[id:	9537698<br />first:	1361347206<br />last:	0<br />md5:	69276ede41fd243dba3bcaa86fd8f5d8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=69276ede41fd243dba3bcaa86fd8f5d8<br />vt_score:	34/46 (73.9%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Dropper<br />url:	http://elmascarodelmundo.com/wpe.exe<br />recent:	up<br />response:	alive<br />ip:	54.245.224.72<br />as:	AS16509<br />review:	54.245.224.72<br />domain:	elmascarodelmundo.com<br />country:	US<br />source:	ARIN<br />email:	aes-noc@amazon.com<br />inetnum:	54.245.0.0 - 54.245.255.255<br />netname:	AMAZO-ZPDX1<br />descr:	Amazon.com, Inc. AMAZO-47 EC2, EC2 1200 12th Ave South Seattle WA 98144<br />ns1:	ns2.slicehost.net<br />ns2:	ns1.slicehost.net<br />ns3:	ns3.slicehost.net<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://193.105.134.189/newbos3.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9537667</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9537667</guid>
			<pubDate>2013-02-20T08:40:03+01:00</pubDate>
			<description><![CDATA[id:	9537667<br />first:	1361346003<br />last:	0<br />md5:	682828b7f449584edcaba14d3875144a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=682828b7f449584edcaba14d3875144a<br />vt_score:	36/46 (78.3%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen3<br />url:	http://193.105.134.189/newbos3.exe<br />recent:	up<br />response:	alive<br />ip:	193.105.134.189<br />as:	AS42708<br />review:	193.105.134.189<br />domain:	193.105.134.189<br />country:	SE<br />source:	RIPE<br />email:	info@swedendedicated.com<br />inetnum:	193.105.134.0 - 193.105.134.255<br />netname:	SWEDENDEDICATED-NET<br />descr:	Christian Maurice Sebastiaan Hein<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://193.105.134.189/newbos1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9537666</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9537666</guid>
			<pubDate>2013-02-20T08:40:03+01:00</pubDate>
			<description><![CDATA[id:	9537666<br />first:	1361346003<br />last:	0<br />md5:	5003285cd373fbeafdc675327e61f3c4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5003285cd373fbeafdc675327e61f3c4<br />vt_score:	27/37 (73%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen3<br />url:	http://193.105.134.189/newbos1.exe<br />recent:	up<br />response:	alive<br />ip:	193.105.134.189<br />as:	AS42708<br />review:	193.105.134.189<br />domain:	193.105.134.189<br />country:	SE<br />source:	RIPE<br />email:	info@swedendedicated.com<br />inetnum:	193.105.134.0 - 193.105.134.255<br />netname:	SWEDENDEDICATED-NET<br />descr:	Christian Maurice Sebastiaan Hein<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://193.105.134.189/calc.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9537665</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9537665</guid>
			<pubDate>2013-02-20T08:40:03+01:00</pubDate>
			<description><![CDATA[id:	9537665<br />first:	1361346003<br />last:	0<br />md5:	dea2ed6b8fa67121668335c54307c5b3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dea2ed6b8fa67121668335c54307c5b3<br />vt_score:	7/35 (20%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://193.105.134.189/calc.exe<br />recent:	up<br />response:	alive<br />ip:	193.105.134.189<br />as:	AS42708<br />review:	193.105.134.189<br />domain:	193.105.134.189<br />country:	SE<br />source:	RIPE<br />email:	info@swedendedicated.com<br />inetnum:	193.105.134.0 - 193.105.134.255<br />netname:	SWEDENDEDICATED-NET<br />descr:	Christian Maurice Sebastiaan Hein<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://193.105.134.189/rasta01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9537664</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9537664</guid>
			<pubDate>2013-02-20T08:40:03+01:00</pubDate>
			<description><![CDATA[id:	9537664<br />first:	1361346003<br />last:	0<br />md5:	5b56714c939319d851af781a753be529<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5b56714c939319d851af781a753be529<br />vt_score:	36/46 (78.3%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen3<br />url:	http://193.105.134.189/rasta01.exe<br />recent:	up<br />response:	alive<br />ip:	193.105.134.189<br />as:	AS42708<br />review:	193.105.134.189<br />domain:	193.105.134.189<br />country:	SE<br />source:	RIPE<br />email:	info@swedendedicated.com<br />inetnum:	193.105.134.0 - 193.105.134.255<br />netname:	SWEDENDEDICATED-NET<br />descr:	Christian Maurice Sebastiaan Hein<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://193.105.134.189/instcod.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9537663</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9537663</guid>
			<pubDate>2013-02-20T08:40:03+01:00</pubDate>
			<description><![CDATA[id:	9537663<br />first:	1361346003<br />last:	0<br />md5:	a917db7312de4a2edc823ab9873199f8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a917db7312de4a2edc823ab9873199f8<br />vt_score:	8/36 (22.2%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen3<br />url:	http://193.105.134.189/instcod.exe<br />recent:	up<br />response:	alive<br />ip:	193.105.134.189<br />as:	AS42708<br />review:	193.105.134.189<br />domain:	193.105.134.189<br />country:	SE<br />source:	RIPE<br />email:	info@swedendedicated.com<br />inetnum:	193.105.134.0 - 193.105.134.255<br />netname:	SWEDENDEDICATED-NET<br />descr:	Christian Maurice Sebastiaan Hein<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://193.105.134.189/madload.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9537662</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9537662</guid>
			<pubDate>2013-02-20T08:40:03+01:00</pubDate>
			<description><![CDATA[id:	9537662<br />first:	1361346003<br />last:	0<br />md5:	6a636f6ea2ea48376f99d962abdb74f2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6a636f6ea2ea48376f99d962abdb74f2<br />vt_score:	8/36 (22.2%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen3<br />url:	http://193.105.134.189/madload.exe<br />recent:	up<br />response:	alive<br />ip:	193.105.134.189<br />as:	AS42708<br />review:	193.105.134.189<br />domain:	193.105.134.189<br />country:	SE<br />source:	RIPE<br />email:	info@swedendedicated.com<br />inetnum:	193.105.134.0 - 193.105.134.255<br />netname:	SWEDENDEDICATED-NET<br />descr:	Christian Maurice Sebastiaan Hein<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cuatrofm.es/img/load50.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9537661</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9537661</guid>
			<pubDate>2013-02-20T08:40:03+01:00</pubDate>
			<description><![CDATA[id:	9537661<br />first:	1361346003<br />last:	0<br />md5:	428580c7ad6620c884121738e4b453f1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=428580c7ad6620c884121738e4b453f1<br />vt_score:	13/36 (36.1%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://cuatrofm.es/img/load50.exe<br />recent:	up<br />response:	alive<br />ip:	85.214.110.148<br />as:	AS6724<br />review:	85.214.110.148<br />domain:	cuatrofm.es<br />country:	DE<br />source:	RIPE<br />email:	abuse-server@strato.de<br />inetnum:	85.214.16.0 - 85.214.139.255<br />netname:	STRATO-RZG-DED2<br />descr:	Strato Rechenzentrum, Berlin<br />ns1:	ns9.piensasolutions.com<br />ns2:	ns10.piensasolutions.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ceregypt.com/images/load50.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9537660</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9537660</guid>
			<pubDate>2013-02-20T08:40:03+01:00</pubDate>
			<description><![CDATA[id:	9537660<br />first:	1361346003<br />last:	0<br />md5:	428580c7ad6620c884121738e4b453f1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=428580c7ad6620c884121738e4b453f1<br />vt_score:	13/36 (36.1%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://ceregypt.com/images/load50.exe<br />recent:	up<br />response:	alive<br />ip:	174.36.114.32<br />as:	AS36351<br />review:	174.36.114.32<br />domain:	ceregypt.com<br />country:	US<br />source:	ARIN<br />email:	abuse@softlayer.com<br />inetnum:	174.36.0.0 - 174.37.255.255<br />netname:	SOFTLAYER-4-7<br />descr:	SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207<br />ns1:	ns2.echomicrosystems.com<br />ns2:	ns1.echomicrosystems.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ceregypt.com/images/load57.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9537659</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9537659</guid>
			<pubDate>2013-02-20T08:40:03+01:00</pubDate>
			<description><![CDATA[id:	9537659<br />first:	1361346003<br />last:	0<br />md5:	c7b985b2b178407d99e148fc3408f150<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c7b985b2b178407d99e148fc3408f150<br />vt_score:	14/36 (38.9%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://ceregypt.com/images/load57.exe<br />recent:	up<br />response:	alive<br />ip:	174.36.114.32<br />as:	AS36351<br />review:	174.36.114.32<br />domain:	ceregypt.com<br />country:	US<br />source:	ARIN<br />email:	abuse@softlayer.com<br />inetnum:	174.36.0.0 - 174.37.255.255<br />netname:	SOFTLAYER-4-7<br />descr:	SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207<br />ns1:	ns2.echomicrosystems.com<br />ns2:	ns1.echomicrosystems.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ceregypt.com/images/load2008.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9537658</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[UnclassifiedMalware]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9537658</guid>
			<pubDate>2013-02-20T08:40:03+01:00</pubDate>
			<description><![CDATA[id:	9537658<br />first:	1361346003<br />last:	0<br />md5:	9fa3b642e665eadc7de46c6ad00d88b9<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9fa3b642e665eadc7de46c6ad00d88b9<br />vt_score:	4/36 (11.1%)<br />scanner:	Comodo<br />virusname:	UnclassifiedMalware<br />url:	http://ceregypt.com/images/load2008.exe<br />recent:	up<br />response:	alive<br />ip:	174.36.114.32<br />as:	AS36351<br />review:	174.36.114.32<br />domain:	ceregypt.com<br />country:	US<br />source:	ARIN<br />email:	abuse@softlayer.com<br />inetnum:	174.36.0.0 - 174.37.255.255<br />netname:	SOFTLAYER-4-7<br />descr:	SoftLayer Technologies Inc. SOFTL 1950 N Stemmons Freeway Dallas TX 75207<br />ns1:	ns2.echomicrosystems.com<br />ns2:	ns1.echomicrosystems.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://incumzyr.ru/rasta01.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9535483</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9535483</guid>
			<pubDate>2013-02-20T00:00:05+01:00</pubDate>
			<description><![CDATA[id:	9535483<br />first:	1361314805<br />last:	0<br />md5:	a4777e8e9b10493ee486667e39f1be47<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a4777e8e9b10493ee486667e39f1be47<br />vt_score:	10/46 (21.7%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen3<br />url:	http://incumzyr.ru/rasta01.exe<br />recent:	up<br />response:	alive<br />ip:	46.109.168.3<br />as:	AS12578<br />review:	79.135.211.227<br />domain:	incumzyr.ru<br />country:	UA<br />source:	RIPE<br />email:	rias@skyline.od.ua<br />inetnum:	46.109.0.0 - 46.109.255.255<br />netname:	ICN-IP-ADDRESSING<br />descr:	ICN Ltd.ICN Ltd.<br />ns1:	ns6.incumzyr.ru<br />ns2:	ns1.incumzyr.ru<br />ns3:	ns2.incumzyr.ru<br />ns4:	ns4.incumzyr.ru<br />ns5:	ns3.incumzyr.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/195157652/7a6c311/ckAw8xV.exe.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9531105</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.VBKrypt]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9531105</guid>
			<pubDate>2013-02-19T17:40:08+01:00</pubDate>
			<description><![CDATA[id:	9531105<br />first:	1361292008<br />last:	0<br />md5:	dbb6a761b670a25175870cc4b29e2c25<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dbb6a761b670a25175870cc4b29e2c25<br />vt_score:	35/46 (76.1%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.VBKrypt<br />url:	http://hotfile.com/dl/195157652/7a6c311/ckAw8xV.exe.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.236<br />as:	AS7366<br />review:	199.7.177.234<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns2.easydns.com<br />ns2:	ns1.hotfile.com<br />ns3:	ns1.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://130.0.238.184/file.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9529446</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9529446</guid>
			<pubDate>2013-02-19T11:00:04+01:00</pubDate>
			<description><![CDATA[id:	9529446<br />first:	1361268004<br />last:	0<br />md5:	046c70a6583d4218e2d677abf5fb30f5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=046c70a6583d4218e2d677abf5fb30f5<br />vt_score:	36/42 (85.7%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://130.0.238.184/file.exe<br />recent:	up<br />response:	alive<br />ip:	130.0.238.184<br />as:	AS15626<br />review:	130.0.238.184<br />domain:	130.0.238.184<br />country:	UA<br />source:	RIPE<br />email:	info@3nt.com<br />inetnum:	130.0.238.0 - 130.0.239.255<br />netname:	UK-3NT-NET2<br />descr:	VPS/VDS servicesUK-3NT-NET<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://130.0.238.184/file1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9529445</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.117248.56]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9529445</guid>
			<pubDate>2013-02-19T11:00:04+01:00</pubDate>
			<description><![CDATA[id:	9529445<br />first:	1361268004<br />last:	0<br />md5:	0af577450d03e90d4886006e3492def3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0af577450d03e90d4886006e3492def3<br />vt_score:	33/46 (71.7%)<br />scanner:	AntiVir<br />virusname:	TR/Agent.117248.56<br />url:	http://130.0.238.184/file1.exe<br />recent:	up<br />response:	alive<br />ip:	130.0.238.184<br />as:	AS15626<br />review:	130.0.238.184<br />domain:	130.0.238.184<br />country:	UA<br />source:	RIPE<br />email:	info@3nt.com<br />inetnum:	130.0.238.0 - 130.0.239.255<br />netname:	UK-3NT-NET2<br />descr:	VPS/VDS servicesUK-3NT-NET<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bluegrassornamentaliron.com/5AUPnx.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9529444</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Agent]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9529444</guid>
			<pubDate>2013-02-19T11:00:04+01:00</pubDate>
			<description><![CDATA[id:	9529444<br />first:	1361268004<br />last:	0<br />md5:	72db7ec179ec0d5785f20abc3fad8b45<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=72db7ec179ec0d5785f20abc3fad8b45<br />vt_score:	32/46 (69.6%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Agent<br />url:	http://bluegrassornamentaliron.com/5AUPnx.exe<br />recent:	up<br />response:	alive<br />ip:	66.147.240.153<br />as:	AS11798<br />review:	66.147.240.153<br />domain:	bluegrassornamentaliron.com<br />country:	US<br />source:	ARIN<br />email:	abuse@bluehost.com<br />inetnum:	66.147.240.0 - 66.147.255.255<br />netname:	BLUEHOST-NETWORK-4<br />descr:	Bluehost Inc. BLUEH-2 1958 South 950 East Provo UT 84606<br />ns1:	ns2.hostmonster.com<br />ns2:	ns1.hostmonster.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mariefredbk.se/TE2ECpWp.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9529443</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Agent]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9529443</guid>
			<pubDate>2013-02-19T11:00:03+01:00</pubDate>
			<description><![CDATA[id:	9529443<br />first:	1361268003<br />last:	0<br />md5:	72db7ec179ec0d5785f20abc3fad8b45<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=72db7ec179ec0d5785f20abc3fad8b45<br />vt_score:	32/46 (69.6%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Agent<br />url:	http://mariefredbk.se/TE2ECpWp.exe<br />recent:	up<br />response:	alive<br />ip:	91.201.60.24<br />as:	AS44136<br />review:	91.201.60.24<br />domain:	mariefredbk.se<br />country:	SE<br />source:	RIPE<br />email:	abuse@oderland.se<br />inetnum:	91.201.60.0 - 91.201.63.255<br />netname:	ODERLAND-NET<br />descr:	ODERLAND Webbhotell AB<br />ns1:	dns2.oderland.com<br />ns2:	dns1.oderland.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://stefan-auerswald.de/jPA.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9529442</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Agent]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9529442</guid>
			<pubDate>2013-02-19T11:00:03+01:00</pubDate>
			<description><![CDATA[id:	9529442<br />first:	1361268003<br />last:	0<br />md5:	72db7ec179ec0d5785f20abc3fad8b45<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=72db7ec179ec0d5785f20abc3fad8b45<br />vt_score:	6/36 (16.7%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Agent<br />url:	http://stefan-auerswald.de/jPA.exe<br />recent:	up<br />response:	alive<br />ip:	80.67.28.170<br />as:	AS34011<br />review:	80.67.28.170<br />domain:	stefan-auerswald.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@ispgateway.de<br />inetnum:	80.67.28.0 - 80.67.28.255<br />netname:	DOMAINFACTORY-20070518<br />descr:	SHARED WEBHOSTINGDOMAINFACTORY<br />ns1:	ns.namespace4you.de<br />ns2:	ns2.namespace4you.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://19.danielherr.org/adobe/update_flash_player.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9528546</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.Fareit.IJ.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9528546</guid>
			<pubDate>2013-02-19T08:00:03+01:00</pubDate>
			<description><![CDATA[id:	9528546<br />first:	1361257203<br />last:	0<br />md5:	ada8d1204a74b9889052e8c9bdfa4b1c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ada8d1204a74b9889052e8c9bdfa4b1c<br />vt_score:	5/34 (14.7%)<br />scanner:	AntiVir<br />virusname:	TR/PSW.Fareit.IJ.1<br />url:	http://19.danielherr.org/adobe/update_flash_player.exe<br />recent:	up<br />response:	alive<br />ip:	173.246.103.232<br />as:	AS29169<br />review:	173.246.103.232<br />domain:	danielherr.org<br />country:	US<br />source:	ARIN<br />email:	noc@gandi.net<br />inetnum:	173.246.96.0 - 173.246.111.255<br />netname:	GANDI-NET-DC1-1<br />descr:	Gandi US Inc. GANDI-2 Gandi US Inc. PO Box 32863 Baltimore MD 21282<br />ns1:	ns19.domaincontrol.com<br />ns2:	ns20.domaincontrol.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://industriac5.dominiotemporario.com/17-02/Xp/aples.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9521080</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Graftor.CE]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9521080</guid>
			<pubDate>2013-02-18T14:00:23+01:00</pubDate>
			<description><![CDATA[id:	9521080<br />first:	1361192423<br />last:	0<br />md5:	9adc33f72643f961c15cdb71a0e9892a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9adc33f72643f961c15cdb71a0e9892a<br />vt_score:	36/46 (78.3%)<br />scanner:	avira<br />virusname:	TR/Graftor.CE<br />url:	http://industriac5.dominiotemporario.com/17-02/Xp/aples.exe<br />recent:	up<br />response:	alive<br />ip:	200.98.196.10<br />as:	AS15201<br />review:	200.98.196.10<br />domain:	dominiotemporario.com<br />country:	BR<br />source:	LACNIC<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	200.98.0.0 - 200.98.255.255<br />netname:	001.109.184/0001-95<br />descr:	Universo Online S.A.<br />ns1:	ns1.host.uol.com.br<br />ns2:	ns3.host.uol.com.br<br />ns3:	ns2.host.uol.com.br<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://industriac5.dominiotemporario.com/17-02/Xp/gerente.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9521079</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.Banker.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9521079</guid>
			<pubDate>2013-02-18T14:00:23+01:00</pubDate>
			<description><![CDATA[id:	9521079<br />first:	1361192423<br />last:	0<br />md5:	cd4c476f88176b958a10b218f01616a0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cd4c476f88176b958a10b218f01616a0<br />vt_score:	31/45 (68.9%)<br />scanner:	avira<br />virusname:	TR/Spy.Banker.Gen<br />url:	http://industriac5.dominiotemporario.com/17-02/Xp/gerente.exe<br />recent:	up<br />response:	alive<br />ip:	200.98.196.10<br />as:	AS15201<br />review:	200.98.196.10<br />domain:	dominiotemporario.com<br />country:	BR<br />source:	LACNIC<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	200.98.0.0 - 200.98.255.255<br />netname:	001.109.184/0001-95<br />descr:	Universo Online S.A.<br />ns1:	ns1.host.uol.com.br<br />ns2:	ns3.host.uol.com.br<br />ns3:	ns2.host.uol.com.br<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://industriac5.dominiotemporario.com/17-02/Xp/service.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9520975</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.CFI.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9520975</guid>
			<pubDate>2013-02-18T13:40:06+01:00</pubDate>
			<description><![CDATA[id:	9520975<br />first:	1361191206<br />last:	0<br />md5:	158ee1b9a3edca9e1392de9c8097e0c3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=158ee1b9a3edca9e1392de9c8097e0c3<br />vt_score:	31/46 (67.4%)<br />scanner:	avira<br />virusname:	TR/Crypt.CFI.Gen<br />url:	http://industriac5.dominiotemporario.com/17-02/Xp/service.exe<br />recent:	up<br />response:	alive<br />ip:	200.98.196.10<br />as:	AS15201<br />review:	200.98.196.10<br />domain:	dominiotemporario.com<br />country:	BR<br />source:	LACNIC<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	200.98.0.0 - 200.98.255.255<br />netname:	001.109.184/0001-95<br />descr:	Universo Online S.A.<br />ns1:	ns2.host.uol.com.br<br />ns2:	ns1.host.uol.com.br<br />ns3:	ns3.host.uol.com.br<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://95.140.203.241:8080/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9485829</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.FakeAV]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9485829</guid>
			<pubDate>2013-02-15T23:42:53+01:00</pubDate>
			<description><![CDATA[id:	9485829<br />first:	1360968173<br />last:	0<br />md5:	f57ea9cf86020c86e95be4fd7403e0ef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f57ea9cf86020c86e95be4fd7403e0ef<br />vt_score:	36/46 (78.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.FakeAV<br />url:	http://95.140.203.241:8080/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe<br />recent:	up<br />response:	alive<br />ip:	95.140.203.241<br />as:	AS42109<br />review:	95.140.203.241<br />domain:	95.140.203.241<br />country:	AM<br />source:	RIPE<br />email:	abuse@adc.am<br />inetnum:	95.140.192.0 - 95.140.207.255<br />netname:	AM-ADC-20090320<br />descr:	Armenian Datacom Company<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://94.23.193.229:8080/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9485827</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.FakeAV]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9485827</guid>
			<pubDate>2013-02-15T23:42:53+01:00</pubDate>
			<description><![CDATA[id:	9485827<br />first:	1360968173<br />last:	0<br />md5:	f57ea9cf86020c86e95be4fd7403e0ef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f57ea9cf86020c86e95be4fd7403e0ef<br />vt_score:	36/46 (78.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.FakeAV<br />url:	http://94.23.193.229:8080/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe<br />recent:	up<br />response:	alive<br />ip:	94.23.193.229<br />as:	AS16276<br />review:	94.23.193.229<br />domain:	94.23.193.229<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	94.23.192.0 - 94.23.255.255<br />netname:	OVH<br />descr:	OVH SASDedicated Servershttp<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://87.118.122.19:8080/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9485826</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.FakeAV]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9485826</guid>
			<pubDate>2013-02-15T23:42:53+01:00</pubDate>
			<description><![CDATA[id:	9485826<br />first:	1360968173<br />last:	0<br />md5:	f57ea9cf86020c86e95be4fd7403e0ef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f57ea9cf86020c86e95be4fd7403e0ef<br />vt_score:	36/46 (78.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.FakeAV<br />url:	http://87.118.122.19:8080/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe<br />recent:	up<br />response:	alive<br />ip:	87.118.122.19<br />as:	AS31103<br />review:	87.118.122.19<br />domain:	87.118.122.19<br />country:	DE<br />source:	RIPE<br />email:	abuse@keyweb.de<br />inetnum:	87.118.96.0 - 87.118.127.255<br />netname:	DE-KEYWEB-III<br />descr:	Keyweb AG IP Network<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://213.229.106.32:8088/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9485825</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.FakeAV]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9485825</guid>
			<pubDate>2013-02-15T23:42:53+01:00</pubDate>
			<description><![CDATA[id:	9485825<br />first:	1360968173<br />last:	0<br />md5:	f57ea9cf86020c86e95be4fd7403e0ef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f57ea9cf86020c86e95be4fd7403e0ef<br />vt_score:	36/46 (78.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.FakeAV<br />url:	http://213.229.106.32:8088/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe<br />recent:	up<br />response:	alive<br />ip:	213.229.106.32<br />as:	AS29550<br />review:	213.229.106.32<br />domain:	213.229.106.32<br />country:	NL<br />source:	RIPE<br />email:	n_alblas@saturnus.nl<br />inetnum:	213.229.88.0 - 213.229.119.255<br />netname:	DEKOOI<br />descr:	Kooi SysteemHuis B.V.Provider Local Registry<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://91.121.28.146:8080/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9485824</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.FakeAV]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9485824</guid>
			<pubDate>2013-02-15T23:42:53+01:00</pubDate>
			<description><![CDATA[id:	9485824<br />first:	1360968173<br />last:	0<br />md5:	f57ea9cf86020c86e95be4fd7403e0ef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f57ea9cf86020c86e95be4fd7403e0ef<br />vt_score:	36/46 (78.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.FakeAV<br />url:	http://91.121.28.146:8080/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe<br />recent:	up<br />response:	alive<br />ip:	91.121.28.146<br />as:	AS16276<br />review:	91.121.28.146<br />domain:	91.121.28.146<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	91.121.0.0 - 91.121.31.255<br />netname:	OVH<br />descr:	OVH SASDedicated Servershttp<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://149.62.168.76:8080/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9485823</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.FakeAV]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9485823</guid>
			<pubDate>2013-02-15T23:42:53+01:00</pubDate>
			<description><![CDATA[id:	9485823<br />first:	1360968173<br />last:	0<br />md5:	f57ea9cf86020c86e95be4fd7403e0ef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f57ea9cf86020c86e95be4fd7403e0ef<br />vt_score:	36/46 (78.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.FakeAV<br />url:	http://149.62.168.76:8080/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe<br />recent:	up<br />response:	alive<br />ip:	149.62.168.76<br />as:	AS3356<br />review:	149.62.168.76<br />domain:	149.62.168.76<br />country:	ES<br />source:	RIPE<br />email:	<br />inetnum:	149.62.168.0 - 149.62.175.255<br />netname:	<br />descr:	<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://50.115.116.201:8088/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9485821</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.FakeAV]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9485821</guid>
			<pubDate>2013-02-15T23:42:53+01:00</pubDate>
			<description><![CDATA[id:	9485821<br />first:	1360968173<br />last:	0<br />md5:	f57ea9cf86020c86e95be4fd7403e0ef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f57ea9cf86020c86e95be4fd7403e0ef<br />vt_score:	36/46 (78.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.FakeAV<br />url:	http://50.115.116.201:8088/get/67ad970fbbc4f9b29bfeca40b0b4a54f.exe<br />recent:	up<br />response:	alive<br />ip:	50.115.116.201<br />as:	AS29854, AS32780<br />review:	50.115.116.201<br />domain:	50.115.116.201<br />country:	US<br />source:	ARIN<br />email:	abuse@hostingservicesinc.net<br />inetnum:	50.115.112.0 - 50.115.127.255<br />netname:	HOSTINGSERVICES-INC<br />descr:	Hosting Services, Inc. HOSTI-20 164 N Gateway Drive Providence UT 84332<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tspcncmachinetools.com/aiXJ8.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9480837</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Spyware/Win32.Zbot]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9480837</guid>
			<pubDate>2013-02-15T14:00:10+01:00</pubDate>
			<description><![CDATA[id:	9480837<br />first:	1360933210<br />last:	0<br />md5:	de676198f8d7025e915b08042a977291<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=de676198f8d7025e915b08042a977291<br />vt_score:	14/36 (38.9%)<br />scanner:	AhnLab_V3<br />virusname:	Spyware/Win32.Zbot<br />url:	http://tspcncmachinetools.com/aiXJ8.exe<br />recent:	up<br />response:	alive<br />ip:	64.130.220.90<br />as:	AS23136<br />review:	64.130.220.90<br />domain:	tspcncmachinetools.com<br />country:	CA<br />source:	ARIN<br />email:	roozbeh@ravand.com<br />inetnum:	64.130.208.0 - 64.130.223.255<br />netname:	ONX-BLK2<br />descr:	OnX Enterprise Solutions Inc. OES-15 155 Commerce Valley Drive East Thornhill ON L3T-7T2Ravand Cybertech Inc. RAVAN 255 Duncan Mill Rd. Suite 205 Toronto ON M3B-3H9<br />ns1:	ns1.nedahosting.com<br />ns2:	ns2.nedahosting.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://itforever.hu/FBo8creG.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9480836</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[WIN.Spy.Zbot-2928]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9480836</guid>
			<pubDate>2013-02-15T14:00:09+01:00</pubDate>
			<description><![CDATA[id:	9480836<br />first:	1360933209<br />last:	0<br />md5:	af43b86ce00115630eb766ca908037fa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=af43b86ce00115630eb766ca908037fa<br />vt_score:	35/46 (76.1%)<br />scanner:	clamav<br />virusname:	WIN.Spy.Zbot-2928<br />url:	http://itforever.hu/FBo8creG.exe<br />recent:	up<br />response:	alive<br />ip:	195.228.86.48<br />as:	AS5483<br />review:	195.228.86.48<br />domain:	itforever.hu<br />country:	HU<br />source:	RIPE<br />email:	abuse@t-online.hu<br />inetnum:	195.228.86.0 - 195.228.87.255<br />netname:	ADATPARK<br />descr:	Magyar Telekom, GyorHungarian Telecom, AxeleroPublic Internet Access ProviderBudapest, HungaryHU<br />ns1:	ns2.webtar.hu<br />ns2:	ns1.webtar.hu<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.northerncyprusweddings.com/FKsyKnXA.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9480834</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Spyware/Win32.Zbot]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9480834</guid>
			<pubDate>2013-02-15T14:00:09+01:00</pubDate>
			<description><![CDATA[id:	9480834<br />first:	1360933209<br />last:	0<br />md5:	de676198f8d7025e915b08042a977291<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=de676198f8d7025e915b08042a977291<br />vt_score:	14/36 (38.9%)<br />scanner:	AhnLab_V3<br />virusname:	Spyware/Win32.Zbot<br />url:	http://www.northerncyprusweddings.com/FKsyKnXA.exe<br />recent:	up<br />response:	alive<br />ip:	212.85.249.130<br />as:	AS8401<br />review:	212.85.249.130<br />domain:	northerncyprusweddings.com<br />country:	GB<br />source:	RIPE<br />email:	abuse@minx.net.uk<br />inetnum:	212.85.224.0 - 212.85.249.255<br />netname:	EliteISP<br />descr:	Internet service provider==========================================================To report abuse and spam send email to==========================================================<br />ns1:	d.ns.as8401.net<br />ns2:	c.ns.as8401.net<br />ns3:	b.ns.186k.co.uk<br />ns4:	a.ns.186k.co.uk<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://speedpoker1.info/antivirusblock.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9480833</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.KD.859964]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9480833</guid>
			<pubDate>2013-02-15T14:00:09+01:00</pubDate>
			<description><![CDATA[id:	9480833<br />first:	1360933209<br />last:	0<br />md5:	3e31f575b2a5a722eb2d1f2a06ac12c5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3e31f575b2a5a722eb2d1f2a06ac12c5<br />vt_score:	18/36 (50%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.KD.859964<br />url:	http://speedpoker1.info/antivirusblock.exe<br />recent:	up<br />response:	alive<br />ip:	213.5.176.20<br />as:	as33970<br />review:	213.5.176.20<br />domain:	speedpoker1.info<br />country:	GB<br />source:	RIPE<br />email:	abuse@racksrv.com<br />inetnum:	213.5.176.0 - 213.5.183.255<br />netname:	Racksrv<br />descr:	RackSRV Communications Ltd<br />ns1:	ns1.thewebhostserver.com<br />ns2:	ns4.thewebhostserver.com<br />ns3:	ns2.thewebhostserver.com<br />ns4:	ns3.thewebhostserver.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.ipu-ce.com/admin/pics/emoticons/Gbplugin.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9480832</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9480832</guid>
			<pubDate>2013-02-15T14:00:09+01:00</pubDate>
			<description><![CDATA[id:	9480832<br />first:	1360933209<br />last:	0<br />md5:	7c97e5ecfbb3f5805552cfb11f864341<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7c97e5ecfbb3f5805552cfb11f864341<br />vt_score:	30/46 (65.2%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen2<br />url:	http://www.ipu-ce.com/admin/pics/emoticons/Gbplugin.exe<br />recent:	up<br />response:	alive<br />ip:	187.17.98.44<br />as:	AS15201<br />review:	187.17.98.44<br />domain:	ipu-ce.com<br />country:	BR<br />source:	LACNIC<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	187.17.64.0 - 187.17.127.255<br />netname:	001.109.184/0001-95<br />descr:	Universo Online S.A.<br />ns1:	ns2.dominios.uol.com.br<br />ns2:	ns1.dominios.uol.com.br<br />ns3:	ns3.dominios.uol.com.br<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://izolenta.info/tmp/xx.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9479050</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9479050</guid>
			<pubDate>2013-02-15T11:00:06+01:00</pubDate>
			<description><![CDATA[id:	9479050<br />first:	1360922406<br />last:	0<br />md5:	89f55866ce438720f6b62e9ffc6e2da5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=89f55866ce438720f6b62e9ffc6e2da5<br />vt_score:	20/36 (55.6%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://izolenta.info/tmp/xx.exe<br />recent:	up<br />response:	alive<br />ip:	178.91.94.6<br />as:	AS9198<br />review:	178.91.94.6<br />domain:	izolenta.info<br />country:	KZ<br />source:	RIPE<br />email:	nic@online.kz<br />inetnum:	178.88.0.0 - 178.91.255.255<br />netname:	KZ-KAZAKTELECOM-20091126<br />descr:	JSC KazakhtelecomKazakhtelecom Data Network AdministrationKazakhtelecom Data Network AdministrationKazakhtelecom Data Network Administration<br />ns1:	ns2.hosthouse.kz<br />ns2:	ns1.hosthouse.kz<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://izolenta.info/tmp/z.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9479049</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.Zbot.5123]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9479049</guid>
			<pubDate>2013-02-15T11:00:06+01:00</pubDate>
			<description><![CDATA[id:	9479049<br />first:	1360922406<br />last:	0<br />md5:	aad8918fa8cfb520c29c1c0e72839626<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=aad8918fa8cfb520c29c1c0e72839626<br />vt_score:	10/32 (31.3%)<br />scanner:	AntiVir<br />virusname:	TR/PSW.Zbot.5123<br />url:	http://izolenta.info/tmp/z.exe<br />recent:	up<br />response:	alive<br />ip:	178.91.94.6<br />as:	AS9198<br />review:	178.91.94.6<br />domain:	izolenta.info<br />country:	KZ<br />source:	RIPE<br />email:	nic@online.kz<br />inetnum:	178.88.0.0 - 178.91.255.255<br />netname:	KZ-KAZAKTELECOM-20091126<br />descr:	JSC KazakhtelecomKazakhtelecom Data Network AdministrationKazakhtelecom Data Network AdministrationKazakhtelecom Data Network Administration<br />ns1:	ns2.hosthouse.kz<br />ns2:	ns1.hosthouse.kz<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://brimka.ru/download/?id=913]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9478478</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9478478</guid>
			<pubDate>2013-02-15T10:40:03+01:00</pubDate>
			<description><![CDATA[id:	9478478<br />first:	1360921203<br />last:	0<br />md5:	531f3f0d6d2d474a36ff185942998cab<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=531f3f0d6d2d474a36ff185942998cab<br />vt_score:	4/36 (11.1%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://brimka.ru/download/?id=913<br />recent:	up<br />response:	alive<br />ip:	88.198.206.120<br />as:	AS24940<br />review:	88.198.206.120<br />domain:	brimka.ru<br />country:	DE<br />source:	RIPE<br />email:	abuse@hetzner.de<br />inetnum:	88.198.0.0 - 88.198.255.255<br />netname:	DE-HETZNER-20051227<br />descr:	Hetzner Online AG<br />ns1:	ns1.brimka.ru<br />ns2:	ns2.brimka.ru<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://astexisnew.net/ngen/controlling/doddresc.php?jbbyrark=2w:32:32:2v:1k&jhr=1i:2v:1l:1n:1m:1f:33:1m:1g:1n&oud=1i&qjnwi=ezttvwl&ply=reczxk]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9477872</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Caphaw.I!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9477872</guid>
			<pubDate>2013-02-15T09:40:06+01:00</pubDate>
			<description><![CDATA[id:	9477872<br />first:	1360917606<br />last:	0<br />md5:	709bc9fe8418590315500b36800e50d8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=709bc9fe8418590315500b36800e50d8<br />vt_score:	2/36 (5.6%)<br />scanner:	Fortinet<br />virusname:	W32/Caphaw.I!tr<br />url:	http://astexisnew.net/ngen/controlling/doddresc.php?jbbyrark=2w:32:32:2v:1k&jhr=1i:2v:1l:1n:1m:1f:33:1m:1g:1n&oud=1i&qjnwi=ezttvwl&ply=reczxk<br />recent:	up<br />response:	alive<br />ip:	63.90.228.36<br />as:	AS46940<br />review:	63.90.228.36<br />domain:	astexisnew.net<br />country:	US<br />source:	ARIN<br />email:	abuse-mail@verizonbusiness.com<br />inetnum:	63.64.0.0 - 63.127.255.255<br />netname:	UUNET63<br />descr:	MCI Communications Services, Inc. d/b/a Verizon Business MCICS 22001 Loudoun County Pkwy Ashburn VA 20147<br />ns1:	ns3.cnmsn.com<br />ns2:	ns4.cnmsn.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://194.242.59.32/instcod.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9468796</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Zbot]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9468796</guid>
			<pubDate>2013-02-14T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	9468796<br />first:	1360853404<br />last:	0<br />md5:	06fc381df0d167a389c8607c926c5b80<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=06fc381df0d167a389c8607c926c5b80<br />vt_score:	37/46 (80.4%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Zbot<br />url:	http://194.242.59.32/instcod.exe<br />recent:	up<br />response:	alive<br />ip:	194.242.59.32<br />as:	AS20785<br />review:	194.242.59.32<br />domain:	194.242.59.32<br />country:	UA<br />source:	RIPE<br />email:	abuse@uct.ua<br />inetnum:	194.242.59.0 - 194.242.59.255<br />netname:	UCT-NET<br />descr:	ISP UCT<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://194.242.59.34/newbos3.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9468795</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Zbot]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9468795</guid>
			<pubDate>2013-02-14T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	9468795<br />first:	1360853404<br />last:	0<br />md5:	272052e02e57cd6eebca51e7a68e4189<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=272052e02e57cd6eebca51e7a68e4189<br />vt_score:	37/46 (80.4%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Zbot<br />url:	http://194.242.59.34/newbos3.exe<br />recent:	up<br />response:	alive<br />ip:	194.242.59.34<br />as:	AS20785<br />review:	194.242.59.34<br />domain:	194.242.59.34<br />country:	UA<br />source:	RIPE<br />email:	abuse@uct.ua<br />inetnum:	194.242.59.0 - 194.242.59.255<br />netname:	UCT-NET<br />descr:	ISP UCT<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://217.11.63.194:8080/get/b2f7e9141eb124ce3152352c5df520f7.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9468794</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Agent]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9468794</guid>
			<pubDate>2013-02-14T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	9468794<br />first:	1360853404<br />last:	0<br />md5:	3dff532cbfa42fb2173e9cf3cf98923d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3dff532cbfa42fb2173e9cf3cf98923d<br />vt_score:	21/35 (60%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Agent<br />url:	http://217.11.63.194:8080/get/b2f7e9141eb124ce3152352c5df520f7.exe<br />recent:	up<br />response:	alive<br />ip:	217.11.63.194<br />as:	AS9063<br />review:	217.11.63.194<br />domain:	217.11.63.194<br />country:	DE<br />source:	RIPE<br />email:	og@goekal-it.de<br />inetnum:	217.11.63.0 - 217.11.63.255<br />netname:	GOEKAL-IT<br />descr:	Goekal-IT NetworkKilianstraße 10433098 PaderbornmanituWelvertstrasse 266606 St. WendelGermany<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://193.105.134.89/madload.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9468793</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Winwebsec.401926]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9468793</guid>
			<pubDate>2013-02-14T15:50:04+01:00</pubDate>
			<description><![CDATA[id:	9468793<br />first:	1360853404<br />last:	0<br />md5:	961b30fd067a6fd6e71d6cdb0ba16d20<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=961b30fd067a6fd6e71d6cdb0ba16d20<br />vt_score:	32/43 (74.4%)<br />scanner:	AntiVir<br />virusname:	TR/Winwebsec.401926<br />url:	http://193.105.134.89/madload.exe<br />recent:	up<br />response:	alive<br />ip:	193.105.134.89<br />as:	AS42708<br />review:	193.105.134.89<br />domain:	193.105.134.89<br />country:	SE<br />source:	RIPE<br />email:	info@swedendedicated.com<br />inetnum:	193.105.134.0 - 193.105.134.255<br />netname:	SWEDENDEDICATED-NET<br />descr:	Christian Maurice Sebastiaan Hein<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://188.190.98.74/madload.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9468558</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Zbot]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9468558</guid>
			<pubDate>2013-02-14T14:50:05+01:00</pubDate>
			<description><![CDATA[id:	9468558<br />first:	1360849805<br />last:	0<br />md5:	9ebdf532a1f95fd37fa3b4b3a099539d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9ebdf532a1f95fd37fa3b4b3a099539d<br />vt_score:	24/35 (68.6%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Zbot<br />url:	http://188.190.98.74/madload.exe<br />recent:	up<br />response:	alive<br />ip:	188.190.98.74<br />as:	AS197145<br />review:	188.190.98.74<br />domain:	188.190.98.74<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	188.190.96.0 - 188.190.127.255<br />netname:	INFIUM<br />descr:	Infium LTD<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://188.190.98.74/newbos3.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9468557</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Crypt_s.AJO]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9468557</guid>
			<pubDate>2013-02-14T14:50:05+01:00</pubDate>
			<description><![CDATA[id:	9468557<br />first:	1360849805<br />last:	0<br />md5:	ac7293642a7afba68429257b05d4d5e1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ac7293642a7afba68429257b05d4d5e1<br />vt_score:	11/36 (30.6%)<br />scanner:	AVG<br />virusname:	Crypt_s.AJO<br />url:	http://188.190.98.74/newbos3.exe<br />recent:	up<br />response:	alive<br />ip:	188.190.98.74<br />as:	AS197145<br />review:	188.190.98.74<br />domain:	188.190.98.74<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	188.190.96.0 - 188.190.127.255<br />netname:	INFIUM<br />descr:	Infium LTD<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://194.242.59.34/calc.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9468408</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9468408</guid>
			<pubDate>2013-02-14T13:40:08+01:00</pubDate>
			<description><![CDATA[id:	9468408<br />first:	1360845608<br />last:	0<br />md5:	3ef56e3e99bc9780bdc33242716cf141<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3ef56e3e99bc9780bdc33242716cf141<br />vt_score:	10/36 (27.8%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://194.242.59.34/calc.exe<br />recent:	up<br />response:	alive<br />ip:	194.242.59.34<br />as:	AS20785<br />review:	194.242.59.34<br />domain:	194.242.59.34<br />country:	UA<br />source:	RIPE<br />email:	abuse@uct.ua<br />inetnum:	194.242.59.0 - 194.242.59.255<br />netname:	UCT-NET<br />descr:	ISP UCT<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://194.242.59.34/madload.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9468308</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Crypt_s.AJO]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9468308</guid>
			<pubDate>2013-02-14T13:00:11+01:00</pubDate>
			<description><![CDATA[id:	9468308<br />first:	1360843211<br />last:	0<br />md5:	5683d35b6e26f98654b28d8830285a69<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5683d35b6e26f98654b28d8830285a69<br />vt_score:	12/36 (33.3%)<br />scanner:	AVG<br />virusname:	Crypt_s.AJO<br />url:	http://194.242.59.34/madload.exe<br />recent:	up<br />response:	alive<br />ip:	194.242.59.34<br />as:	AS20785<br />review:	194.242.59.34<br />domain:	194.242.59.34<br />country:	UA<br />source:	RIPE<br />email:	abuse@uct.ua<br />inetnum:	194.242.59.0 - 194.242.59.255<br />netname:	UCT-NET<br />descr:	ISP UCT<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://194.242.59.34/newbos2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9468307</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Crypt_s.AJO]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9468307</guid>
			<pubDate>2013-02-14T13:00:11+01:00</pubDate>
			<description><![CDATA[id:	9468307<br />first:	1360843211<br />last:	0<br />md5:	2c0dcedefcd94d0bb7e71605347f7e6a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2c0dcedefcd94d0bb7e71605347f7e6a<br />vt_score:	6/19 (31.6%)<br />scanner:	AVG<br />virusname:	Crypt_s.AJO<br />url:	http://194.242.59.34/newbos2.exe<br />recent:	up<br />response:	alive<br />ip:	194.242.59.34<br />as:	AS20785<br />review:	194.242.59.34<br />domain:	194.242.59.34<br />country:	UA<br />source:	RIPE<br />email:	abuse@uct.ua<br />inetnum:	194.242.59.0 - 194.242.59.255<br />netname:	UCT-NET<br />descr:	ISP UCT<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://91.121.57.231:8080/forum/links/column.php?zyz=1k:33:1m:1m:1n&cljoq=1j:33:32:1l:1g:1i:1o:1n:1o:1i&voow=1i&zdaji=zzjnh&tgibgll=jlv]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9468306</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.kdz.7940.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9468306</guid>
			<pubDate>2013-02-14T13:00:11+01:00</pubDate>
			<description><![CDATA[id:	9468306<br />first:	1360843211<br />last:	0<br />md5:	04e9d4167c9a1b82e622e04ad85f8e99<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=04e9d4167c9a1b82e622e04ad85f8e99<br />vt_score:	23/35 (65.7%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.kdz.7940.1<br />url:	http://91.121.57.231:8080/forum/links/column.php?zyz=1k:33:1m:1m:1n&cljoq=1j:33:32:1l:1g:1i:1o:1n:1o:1i&voow=1i&zdaji=zzjnh&tgibgll=jlv<br />recent:	up<br />response:	alive<br />ip:	91.121.57.231<br />as:	AS16276<br />review:	91.121.57.231<br />domain:	91.121.57.231<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	91.121.32.0 - 91.121.63.255<br />netname:	OVH<br />descr:	OVH SASDedicated Servershttp<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://194.242.59.34/m.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9468305</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Crypt_s.AJO]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9468305</guid>
			<pubDate>2013-02-14T13:00:11+01:00</pubDate>
			<description><![CDATA[id:	9468305<br />first:	1360843211<br />last:	0<br />md5:	3ea1dce36633f8623a64bcbe12f11929<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3ea1dce36633f8623a64bcbe12f11929<br />vt_score:	11/35 (31.4%)<br />scanner:	AVG<br />virusname:	Crypt_s.AJO<br />url:	http://194.242.59.34/m.exe<br />recent:	up<br />response:	alive<br />ip:	194.242.59.34<br />as:	AS20785<br />review:	194.242.59.34<br />domain:	194.242.59.34<br />country:	UA<br />source:	RIPE<br />email:	abuse@uct.ua<br />inetnum:	194.242.59.0 - 194.242.59.255<br />netname:	UCT-NET<br />descr:	ISP UCT<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cuxystaf.ru/status/electronics-emphasis_significantly.php?ffxymafx=1k:33:1m:1m:1n&cged=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&fgpqvbd=1i&rmlyon=wgkp&aiggtnlz=rweyvnr]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9468171</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Spyware/Win32.Zbot]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9468171</guid>
			<pubDate>2013-02-14T12:00:11+01:00</pubDate>
			<description><![CDATA[id:	9468171<br />first:	1360839611<br />last:	0<br />md5:	32f7e7d8bba6e5a64bb8644f2ee58462<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=32f7e7d8bba6e5a64bb8644f2ee58462<br />vt_score:	35/46 (76.1%)<br />scanner:	AhnLab_V3<br />virusname:	Spyware/Win32.Zbot<br />url:	http://cuxystaf.ru/status/electronics-emphasis_significantly.php?ffxymafx=1k:33:1m:1m:1n&cged=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&fgpqvbd=1i&rmlyon=wgkp&aiggtnlz=rweyvnr<br />recent:	up<br />response:	alive<br />ip:	142.0.45.27<br />as:	AS46664<br />review:	142.0.45.27<br />domain:	cuxystaf.ru<br />country:	US<br />source:	ARIN<br />email:	info@volumedrive.com<br />inetnum:	142.0.32.0 - 142.0.47.255<br />netname:	VOLUM-ARIN<br />descr:	VolumeDrive VOLUM-2 1143 Northern Blvd Clarks Summit PA 18411<br />ns1:	ns2.cuxystaf.ru<br />ns2:	ns6.cuxystaf.ru<br />ns3:	ns4.cuxystaf.ru<br />ns4:	ns3.cuxystaf.ru<br />ns5:	ns1.cuxystaf.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://mypicture.de-info.de/DCIM_2112-004.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9464246</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Worm/Win32.Palevo]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9464246</guid>
			<pubDate>2013-02-13T17:40:03+01:00</pubDate>
			<description><![CDATA[id:	9464246<br />first:	1360773603<br />last:	0<br />md5:	f05bf3edb697f5f3fde30f2502789c60<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f05bf3edb697f5f3fde30f2502789c60<br />vt_score:	12/35 (34.3%)<br />scanner:	AhnLab_V3<br />virusname:	Worm/Win32.Palevo<br />url:	http://mypicture.de-info.de/DCIM_2112-004.exe<br />recent:	up<br />response:	alive<br />ip:	88.198.21.241<br />as:	AS24940<br />review:	88.198.21.241<br />domain:	de-info.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@hetzner.de<br />inetnum:	88.198.16.0 - 88.198.31.255<br />netname:	HETZNER-RZ-NBG-NET<br />descr:	Hetzner Online AGDatacenter NuernbergHETZNER-RZ-NBG-BLK4<br />ns1:	ns1.subdomain.com<br />ns2:	ns2.subdomain.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wir-in-moers.de/sj4wF5oH.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9464245</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.FakeAV]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9464245</guid>
			<pubDate>2013-02-13T17:40:02+01:00</pubDate>
			<description><![CDATA[id:	9464245<br />first:	1360773602<br />last:	0<br />md5:	a2fab835c7d050030e9f241913fb6c28<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a2fab835c7d050030e9f241913fb6c28<br />vt_score:	25/46 (54.3%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.FakeAV<br />url:	http://wir-in-moers.de/sj4wF5oH.exe<br />recent:	up<br />response:	alive<br />ip:	82.165.84.183<br />as:	AS8560<br />review:	82.165.84.183<br />domain:	wir-in-moers.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.64.0 - 82.165.127.255<br />netname:	SCHLUND-SHARED<br />descr:	1&1 Internet AGNCC#2004115007SCHLUND-PA-4<br />ns1:	ns65.1und1.de<br />ns2:	ns66.1und1.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rolex30.serverthuis.nl/file/1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9452856</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Yakes.B!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9452856</guid>
			<pubDate>2013-02-12T17:40:05+01:00</pubDate>
			<description><![CDATA[id:	9452856<br />first:	1360687205<br />last:	0<br />md5:	01c0a2a73af6df556ddb616dae708ed0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=01c0a2a73af6df556ddb616dae708ed0<br />vt_score:	3/35 (8.6%)<br />scanner:	Fortinet<br />virusname:	W32/Yakes.B!tr<br />url:	http://rolex30.serverthuis.nl/file/1.exe<br />recent:	up<br />response:	alive<br />ip:	31.148.219.6<br />as:	AS44546<br />review:	31.148.219.6<br />domain:	serverthuis.nl<br />country:	GB<br />source:	RIPE<br />email:	abuse@alfatelecom.cz<br />inetnum:	31.148.219.0 - 31.148.219.255<br />netname:	SVSERVERS-NET<br />descr:	INTERNET IT TECHNOLOGY LTD<br />ns1:	ns4.serverthuis.com<br />ns2:	ns2.serverthuis.com<br />ns3:	ns1.serverthuis.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rolex30.serverthuis.nl/file/2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9452855</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9452855</guid>
			<pubDate>2013-02-12T17:40:04+01:00</pubDate>
			<description><![CDATA[id:	9452855<br />first:	1360687204<br />last:	0<br />md5:	3ac6c5f9e686e04bf5a6ac212cd18f41<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3ac6c5f9e686e04bf5a6ac212cd18f41<br />vt_score:	14/45 (31.1%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://rolex30.serverthuis.nl/file/2.exe<br />recent:	up<br />response:	alive<br />ip:	31.148.219.6<br />as:	AS44546<br />review:	31.148.219.6<br />domain:	serverthuis.nl<br />country:	GB<br />source:	RIPE<br />email:	abuse@alfatelecom.cz<br />inetnum:	31.148.219.0 - 31.148.219.255<br />netname:	SVSERVERS-NET<br />descr:	INTERNET IT TECHNOLOGY LTD<br />ns1:	ns4.serverthuis.com<br />ns2:	ns2.serverthuis.com<br />ns3:	ns1.serverthuis.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://seunig.de/L5Fvb.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9452182</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Graftor.68095]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9452182</guid>
			<pubDate>2013-02-12T15:40:24+01:00</pubDate>
			<description><![CDATA[id:	9452182<br />first:	1360680024<br />last:	0<br />md5:	11d7125355766144527db272c584714b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=11d7125355766144527db272c584714b<br />vt_score:	6/35 (17.1%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Graftor.68095<br />url:	http://seunig.de/L5Fvb.exe<br />recent:	up<br />response:	alive<br />ip:	81.169.145.162<br />as:	AS6724<br />review:	81.169.145.162<br />domain:	seunig.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@strato.de<br />inetnum:	81.169.144.0 - 81.169.156.255<br />netname:	STRATO-RZG-KA<br />descr:	Strato Rechenzentrum, BerlinStrato Rechenzentrum<br />ns1:	shades06.rzone.de<br />ns2:	docks11.rzone.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://limitedltd.be/CtSfQca3.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9452181</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Graftor.68095]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9452181</guid>
			<pubDate>2013-02-12T15:40:24+01:00</pubDate>
			<description><![CDATA[id:	9452181<br />first:	1360680024<br />last:	0<br />md5:	11d7125355766144527db272c584714b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=11d7125355766144527db272c584714b<br />vt_score:	8/45 (17.8%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Graftor.68095<br />url:	http://limitedltd.be/CtSfQca3.exe<br />recent:	up<br />response:	alive<br />ip:	81.95.123.12<br />as:	AS42160<br />review:	81.95.123.12<br />domain:	limitedltd.be<br />country:	BE<br />source:	RIPE<br />email:	<br />inetnum:	81.95.112.0 - 81.95.127.255<br />netname:	<br />descr:	<br />ns1:	ns1.belgon-dns05.be<br />ns2:	ns2.belgon-dns05.be<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://visiterlareunion.fr/3gyrJ8B8.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9452180</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Graftor.68095]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9452180</guid>
			<pubDate>2013-02-12T15:40:24+01:00</pubDate>
			<description><![CDATA[id:	9452180<br />first:	1360680024<br />last:	0<br />md5:	11d7125355766144527db272c584714b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=11d7125355766144527db272c584714b<br />vt_score:	6/35 (17.1%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Graftor.68095<br />url:	http://visiterlareunion.fr/3gyrJ8B8.exe<br />recent:	up<br />response:	alive<br />ip:	174.142.212.165<br />as:	AS32613<br />review:	174.142.212.165<br />domain:	visiterlareunion.fr<br />country:	CA<br />source:	ARIN<br />email:	abuse@noc.privatedns.com<br />inetnum:	174.142.0.0 - 174.142.255.255<br />netname:	IWEB-BLK-06<br />descr:	iWeb Technologies Inc. GIT-20 20, place du Commerce Montreal QC H3E-1Z6<br />ns1:	ns2.capigroupe7.net<br />ns2:	ns4.capigroupe7.net<br />ns3:	ns3.capigroupe7.net<br />ns4:	ns1.capigroupe7.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://amxylkap.ru/calc.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9452179</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9452179</guid>
			<pubDate>2013-02-12T15:40:24+01:00</pubDate>
			<description><![CDATA[id:	9452179<br />first:	1360680024<br />last:	0<br />md5:	2943a9569a77c97641b0ab7129496736<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2943a9569a77c97641b0ab7129496736<br />vt_score:	16/44 (36.4%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen2<br />url:	http://amxylkap.ru/calc.exe<br />recent:	up<br />response:	alive<br />ip:	14.99.100.119<br />as:	AS55740<br />review:	95.104.85.31<br />domain:	amxylkap.ru<br />country:	GE<br />source:	RIPE<br />email:	ib@caucasus.net<br />inetnum:	14.96.0.0 - 14.99.255.255<br />netname:	CAUCASUS-BROADBAND-4<br />descr:	Caucasus Online Broadband networkCaucasus OnlineCAUCASUS-BROADBAND-4<br />ns1:	ns5.amxylkap.ru<br />ns2:	ns6.amxylkap.ru<br />ns3:	ns4.amxylkap.ru<br />ns4:	ns2.amxylkap.ru<br />ns5:	ns1.amxylkap.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/193972185/c755590/uozUt9K.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9448459</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/VBKrypt.DAB!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9448459</guid>
			<pubDate>2013-02-12T10:00:04+01:00</pubDate>
			<description><![CDATA[id:	9448459<br />first:	1360659604<br />last:	0<br />md5:	702ebc67e49c160b37376bc15f42efed<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=702ebc67e49c160b37376bc15f42efed<br />vt_score:	4/35 (11.4%)<br />scanner:	Fortinet<br />virusname:	W32/VBKrypt.DAB!tr<br />url:	http://hotfile.com/dl/193972185/c755590/uozUt9K.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.218<br />as:	AS7366<br />review:	199.7.177.216<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns2.easydns.com<br />ns2:	ns1.hotfile.com<br />ns3:	ns1.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/193931805/fcb69f8/PnsaXgc.exe.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9437822</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Agent.90112.366]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9437822</guid>
			<pubDate>2013-02-11T18:00:11+01:00</pubDate>
			<description><![CDATA[id:	9437822<br />first:	1360602011<br />last:	0<br />md5:	36588c8f29e23f645cde30187432ae6d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=36588c8f29e23f645cde30187432ae6d<br />vt_score:	39/45 (86.7%)<br />scanner:	AntiVir<br />virusname:	TR/Agent.90112.366<br />url:	http://hotfile.com/dl/193931805/fcb69f8/PnsaXgc.exe.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.226<br />as:	AS7366<br />review:	199.7.177.224<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns1.hotfile.com<br />ns2:	ns1.easydns.com<br />ns3:	ns2.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/193930317/46b1b0d/2doiO9k.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9437821</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win-Trojan/Vbcrypt.86016]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9437821</guid>
			<pubDate>2013-02-11T18:00:11+01:00</pubDate>
			<description><![CDATA[id:	9437821<br />first:	1360602011<br />last:	0<br />md5:	beb3b506e1384f9196564adf94745b97<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=beb3b506e1384f9196564adf94745b97<br />vt_score:	40/46 (87%)<br />scanner:	AhnLab_V3<br />virusname:	Win-Trojan/Vbcrypt.86016<br />url:	http://hotfile.com/dl/193930317/46b1b0d/2doiO9k.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.228<br />as:	AS7366<br />review:	199.7.177.220<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns1.hotfile.com<br />ns2:	ns1.easydns.com<br />ns3:	ns2.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/193879235/2d844bf/wtYSllF.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9436549</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/VBKrypt.DAB!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9436549</guid>
			<pubDate>2013-02-11T14:00:33+01:00</pubDate>
			<description><![CDATA[id:	9436549<br />first:	1360587633<br />last:	0<br />md5:	dd485bac9d16f2162b9a3e611761d0ce<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dd485bac9d16f2162b9a3e611761d0ce<br />vt_score:	4/46 (8.7%)<br />scanner:	Fortinet<br />virusname:	W32/VBKrypt.DAB!tr<br />url:	http://hotfile.com/dl/193879235/2d844bf/wtYSllF.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.234<br />as:	AS7366<br />review:	199.7.177.232<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns2.easydns.com<br />ns2:	ns1.hotfile.com<br />ns3:	ns1.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://lisybsij.ru/status/electronics-emphasis_significantly.php?ffxymafx=1k:33:1m:1m:1n&cged=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&fgpqvbd=1i&rmlyon=wgkp&aiggtnlz=rweyvnr]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9424736</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KDZ.7696]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9424736</guid>
			<pubDate>2013-02-10T13:50:03+01:00</pubDate>
			<description><![CDATA[id:	9424736<br />first:	1360500603<br />last:	0<br />md5:	85c58237735fb92dfb174e56bc05f12e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=85c58237735fb92dfb174e56bc05f12e<br />vt_score:	7/35 (20%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KDZ.7696<br />url:	http://lisybsij.ru/status/electronics-emphasis_significantly.php?ffxymafx=1k:33:1m:1m:1n&cged=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&fgpqvbd=1i&rmlyon=wgkp&aiggtnlz=rweyvnr<br />recent:	up<br />response:	alive<br />ip:	192.210.142.237<br />as:	AS36352<br />review:	192.210.142.237<br />domain:	lisybsij.ru<br />country:	BG<br />source:	ARIN<br />email:	abarakov94@gmail.com<br />inetnum:	192.210.142.192 - 192.210.142.255<br />netname:	CC-192-210-142-192-26<br />descr:	LiquidSolutions LIQUI-52 Mladost, block.3, vhod B, ap.10 Troyan NA 5600<br />ns1:	ns4.lisybsij.ru<br />ns2:	ns1.lisybsij.ru<br />ns3:	ns3.lisybsij.ru<br />ns4:	ns6.lisybsij.ru<br />ns5:	ns2.lisybsij.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.kamizoku.com/foto43.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9423777</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9423777</guid>
			<pubDate>2013-02-10T11:00:13+01:00</pubDate>
			<description><![CDATA[id:	9423777<br />first:	1360490413<br />last:	0<br />md5:	34d386e6be8d11ecd09aa507c824a368<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=34d386e6be8d11ecd09aa507c824a368<br />vt_score:	14/34 (41.2%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://www.kamizoku.com/foto43.exe<br />recent:	up<br />response:	alive<br />ip:	69.89.31.70<br />as:	AS11798<br />review:	69.89.31.70<br />domain:	kamizoku.com<br />country:	US<br />source:	ARIN<br />email:	abuse@bluehost.com<br />inetnum:	69.89.16.0 - 69.89.31.255<br />netname:	BLUEHOST-NETWORK-1<br />descr:	Bluehost Inc. BLUEH-2 1958 South 950 East Provo UT 84606<br />ns1:	ns1.bluehost.com<br />ns2:	ns2.bluehost.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sspmrwli.jkub.com/xlawr/next/acquires-board.php?dwwsvqih=1k:33:1m:1m:1n&plsmltdq=1f:30:2w:1k:31:1i:2v:1f:2v:32&zrbup=1i&gmfbj=wcvevwn&axvmdmns=ncbchrha]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9416612</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KD.854227]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9416612</guid>
			<pubDate>2013-02-09T20:50:10+01:00</pubDate>
			<description><![CDATA[id:	9416612<br />first:	1360439410<br />last:	0<br />md5:	58fff1751a0d362b777ad15464f08c69<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=58fff1751a0d362b777ad15464f08c69<br />vt_score:	6/35 (17.1%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KD.854227<br />url:	http://sspmrwli.jkub.com/xlawr/next/acquires-board.php?dwwsvqih=1k:33:1m:1m:1n&plsmltdq=1f:30:2w:1k:31:1i:2v:1f:2v:32&zrbup=1i&gmfbj=wcvevwn&axvmdmns=ncbchrha<br />recent:	up<br />response:	alive<br />ip:	92.63.105.23<br />as:	AS29182<br />review:	92.63.105.23<br />domain:	jkub.com<br />country:	RU<br />source:	RIPE<br />email:	abuse@ispsystem.net<br />inetnum:	92.63.104.0 - 92.63.107.255<br />netname:	ISPSYSTEM<br />descr:	ISPsystem MSK<br />ns1:	ns2.changeip.org<br />ns2:	ns3.changeip.org<br />ns3:	ns1.changeip.org<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ul.to/t1dk6o7l]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9406548</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Injector.YMS!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9406548</guid>
			<pubDate>2013-02-08T22:40:09+01:00</pubDate>
			<description><![CDATA[id:	9406548<br />first:	1360359609<br />last:	0<br />md5:	c8eade12c00203451f485d12259ab93e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c8eade12c00203451f485d12259ab93e<br />vt_score:	1/36 (2.8%)<br />scanner:	Fortinet<br />virusname:	W32/Injector.YMS!tr<br />url:	http://ul.to/t1dk6o7l<br />recent:	up<br />response:	alive<br />ip:	95.211.143.200<br />as:	AS16265<br />review:	95.211.143.200<br />domain:	ul.to<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.ul.to<br />ns2:	ns3.ul.to<br />ns3:	ns4.ul.to<br />ns4:	ns2.ul.to<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.gebiet-nord.de/pics/coconutsp2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9406547</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANM!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9406547</guid>
			<pubDate>2013-02-08T22:40:09+01:00</pubDate>
			<description><![CDATA[id:	9406547<br />first:	1360359609<br />last:	0<br />md5:	5d7ac5e2662513c8a93ca5fceac73e12<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5d7ac5e2662513c8a93ca5fceac73e12<br />vt_score:	2/35 (5.7%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANM!tr<br />url:	http://www.gebiet-nord.de/pics/coconutsp2.exe<br />recent:	up<br />response:	alive<br />ip:	81.169.145.156<br />as:	AS6724<br />review:	81.169.145.156<br />domain:	gebiet-nord.de<br />country:	DE<br />source:	RIPE<br />email:	abuse@strato.de<br />inetnum:	81.169.144.0 - 81.169.156.255<br />netname:	STRATO-RZG-KA<br />descr:	Strato Rechenzentrum, BerlinStrato Rechenzentrum<br />ns1:	docks13.rzone.de<br />ns2:	shades01.rzone.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ul.to/5qs9kvxe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9397841</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9397841</guid>
			<pubDate>2013-02-08T10:40:28+01:00</pubDate>
			<description><![CDATA[id:	9397841<br />first:	1360316428<br />last:	0<br />md5:	b610a6a02b51c0b37bbb0b62752594c5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b610a6a02b51c0b37bbb0b62752594c5<br />vt_score:	23/45 (51.1%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://ul.to/5qs9kvxe<br />recent:	up<br />response:	alive<br />ip:	95.211.143.200<br />as:	AS16265<br />review:	95.211.143.200<br />domain:	ul.to<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.ul.to<br />ns2:	ns4.ul.to<br />ns3:	ns3.ul.to<br />ns4:	ns1.ul.to<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ul.to/j6hmerd3]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9396923</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Injector.YMS!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9396923</guid>
			<pubDate>2013-02-08T09:40:15+01:00</pubDate>
			<description><![CDATA[id:	9396923<br />first:	1360312815<br />last:	0<br />md5:	9420fa6921691a2735d1e180328f13e1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9420fa6921691a2735d1e180328f13e1<br />vt_score:	2/36 (5.6%)<br />scanner:	Fortinet<br />virusname:	W32/Injector.YMS!tr<br />url:	http://ul.to/j6hmerd3<br />recent:	up<br />response:	alive<br />ip:	95.211.143.200<br />as:	AS16265<br />review:	95.211.143.200<br />domain:	ul.to<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns4.ul.to<br />ns2:	ns3.ul.to<br />ns3:	ns2.ul.to<br />ns4:	ns1.ul.to<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://egygumlo.ru/madload.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9395635</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Generic_s.ALE]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9395635</guid>
			<pubDate>2013-02-08T08:00:11+01:00</pubDate>
			<description><![CDATA[id:	9395635<br />first:	1360306811<br />last:	0<br />md5:	18585dfc6c5c3a1cfda4e9d390df3fd7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=18585dfc6c5c3a1cfda4e9d390df3fd7<br />vt_score:	11/46 (23.9%)<br />scanner:	AVG<br />virusname:	Generic_s.ALE<br />url:	http://egygumlo.ru/madload.exe<br />recent:	up<br />response:	alive<br />ip:	62.84.44.120<br />as:	AS39824<br />review:	90.130.146.98<br />domain:	egygumlo.ru<br />country:	LT<br />source:	RIPE<br />email:	abuse@swip.net<br />inetnum:	62.84.40.0 - 62.84.47.255<br />netname:	BALTICS-MBB<br />descr:	Tele2 Internet ProviderMobile InternetLithuania####################################<br />ns1:	ns3.egygumlo.ru<br />ns2:	ns4.egygumlo.ru<br />ns3:	ns5.egygumlo.ru<br />ns4:	ns1.egygumlo.ru<br />ns5:	ns6.egygumlo.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://egygumlo.ru/calc.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9395149</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9395149</guid>
			<pubDate>2013-02-08T07:40:02+01:00</pubDate>
			<description><![CDATA[id:	9395149<br />first:	1360305602<br />last:	0<br />md5:	5a515092f8685ba95869a519eea9fbcf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5a515092f8685ba95869a519eea9fbcf<br />vt_score:	15/45 (33.3%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://egygumlo.ru/calc.exe<br />recent:	up<br />response:	alive<br />ip:	81.30.190.24<br />as:	AS24955<br />review:	93.116.247.79<br />domain:	egygumlo.ru<br />country:	md<br />source:	RIPE<br />email:	suprunov@moldtelecom.md<br />inetnum:	81.30.184.0 - 81.30.191.255<br />netname:	JSC-MOLDTELECOM-SA<br />descr:	JSC MOLDTELECOM SAB-ul Stefan cel Mare si Sfant 10Chisinau, Republica Moldova MD-2001JSC MOLDTELECOM SAJSC MOLDTELECOM SA<br />ns1:	ns5.egygumlo.ru<br />ns2:	ns2.egygumlo.ru<br />ns3:	ns6.egygumlo.ru<br />ns4:	ns1.egygumlo.ru<br />ns5:	ns4.egygumlo.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ylgoaxle.ru/status/electronics-emphasis_significantly.php?ffxymafx=1k:33:1m:1m:1n&cged=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&fgpqvbd=1i&rmlyon=wgkp&aiggtnlz=rweyvnr]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9394063</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Kelihos.MI]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9394063</guid>
			<pubDate>2013-02-08T06:00:18+01:00</pubDate>
			<description><![CDATA[id:	9394063<br />first:	1360299618<br />last:	0<br />md5:	8a599b62dcf63789e554e1b4a93a1a2e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8a599b62dcf63789e554e1b4a93a1a2e<br />vt_score:	9/36 (25%)<br />scanner:	AntiVir<br />virusname:	BDS/Kelihos.MI<br />url:	http://ylgoaxle.ru/status/electronics-emphasis_significantly.php?ffxymafx=1k:33:1m:1m:1n&cged=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&fgpqvbd=1i&rmlyon=wgkp&aiggtnlz=rweyvnr<br />recent:	up<br />response:	alive<br />ip:	69.197.177.14<br />as:	AS32097<br />review:	69.197.177.14<br />domain:	ylgoaxle.ru<br />country:	US<br />source:	ARIN<br />email:	abuse@wholesaleinternet.net<br />inetnum:	69.197.128.0 - 69.197.191.255<br />netname:	WHOLESALEINTERNET-2<br />descr:	WholeSale Internet, Inc. WHOLE-125 324 E. 11th St. Suite 1000 Kansas City MO 64106<br />ns1:	ns2.ylgoaxle.ru<br />ns2:	ns3.ylgoaxle.ru<br />ns3:	ns1.ylgoaxle.ru<br />ns4:	ns6.ylgoaxle.ru<br />ns5:	ns4.ylgoaxle.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://heartbeat.scoundrelly.eu/load/dlimage4.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9386140</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Spambot.11176]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9386140</guid>
			<pubDate>2013-02-07T19:00:16+01:00</pubDate>
			<description><![CDATA[id:	9386140<br />first:	1360260016<br />last:	0<br />md5:	1ea59c237ff7aa80513f5798d91cc358<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1ea59c237ff7aa80513f5798d91cc358<br />vt_score:	11/46 (23.9%)<br />scanner:	DrWeb<br />virusname:	Trojan.Spambot.11176<br />url:	http://heartbeat.scoundrelly.eu/load/dlimage4.php<br />recent:	up<br />response:	alive<br />ip:	188.190.99.252<br />as:	AS197145<br />review:	188.190.99.252<br />domain:	scoundrelly.eu<br />country:	UA<br />source:	RIPE<br />email:	abusemail@infiumhost.com<br />inetnum:	188.190.96.0 - 188.190.127.255<br />netname:	INFIUM<br />descr:	Infium LTD<br />ns1:	ns-canada.topdns.com<br />ns2:	ns-uk.topdns.com<br />ns3:	ns-usa.topdns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ykmeffyw.ru/status/electronics-emphasis_significantly.php?glozmr=1k:33:1m:1m:1n&cfwln=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&vjaazu=1i&idski=mkbrav&dyesynr=cpowz]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9385628</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Generic_s.ALD]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9385628</guid>
			<pubDate>2013-02-07T17:40:11+01:00</pubDate>
			<description><![CDATA[id:	9385628<br />first:	1360255211<br />last:	0<br />md5:	3079427e1b2dca78b6e7447e00015a7e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3079427e1b2dca78b6e7447e00015a7e<br />vt_score:	10/46 (21.7%)<br />scanner:	AVG<br />virusname:	Generic_s.ALD<br />url:	http://ykmeffyw.ru/status/electronics-emphasis_significantly.php?glozmr=1k:33:1m:1m:1n&cfwln=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&vjaazu=1i&idski=mkbrav&dyesynr=cpowz<br />recent:	up<br />response:	alive<br />ip:	69.197.177.14<br />as:	AS32097<br />review:	69.197.177.14<br />domain:	ykmeffyw.ru<br />country:	US<br />source:	ARIN<br />email:	abuse@wholesaleinternet.net<br />inetnum:	69.197.128.0 - 69.197.191.255<br />netname:	WHOLESALEINTERNET-2<br />descr:	WholeSale Internet, Inc. WHOLE-125 324 E. 11th St. Suite 1000 Kansas City MO 64106<br />ns1:	ns6.ykmeffyw.ru<br />ns2:	ns4.ykmeffyw.ru<br />ns3:	ns1.ykmeffyw.ru<br />ns4:	ns5.ykmeffyw.ru<br />ns5:	ns2.ykmeffyw.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wevwubhy.ru/links/1.php?ldxiuu=33:32:2w:32:1k&uuvmia=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&urmqzgod=1i&wtwnibft=abmp&oqscdel=xyboqm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9379918</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Generic_s.ALD]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9379918</guid>
			<pubDate>2013-02-07T03:00:07+01:00</pubDate>
			<description><![CDATA[id:	9379918<br />first:	1360202407<br />last:	0<br />md5:	872789b19b28a0983cb2a87d6767c229<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=872789b19b28a0983cb2a87d6767c229<br />vt_score:	11/36 (30.6%)<br />scanner:	AVG<br />virusname:	Generic_s.ALD<br />url:	http://wevwubhy.ru/links/1.php?ldxiuu=33:32:2w:32:1k&uuvmia=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&urmqzgod=1i&wtwnibft=abmp&oqscdel=xyboqm<br />recent:	up<br />response:	alive<br />ip:	199.188.102.62<br />as:	AS393253<br />review:	199.188.102.62<br />domain:	wevwubhy.ru<br />country:	US<br />source:	ARIN<br />email:	<br />inetnum:	199.188.100.0 - 199.188.103.255<br />netname:	<br />descr:	<br />ns1:	ns2.wevwubhy.ru<br />ns2:	ns5.wevwubhy.ru<br />ns3:	ns4.wevwubhy.ru<br />ns4:	ns1.wevwubhy.ru<br />ns5:	ns3.wevwubhy.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://goldcoin.su/b.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9376328</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[UDS:DangerousObject.Multi.Generic]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9376328</guid>
			<pubDate>2013-02-06T17:40:28+01:00</pubDate>
			<description><![CDATA[id:	9376328<br />first:	1360168828<br />last:	0<br />md5:	242e7e8ee6970b73169a64d687fb1d61<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=242e7e8ee6970b73169a64d687fb1d61<br />vt_score:	3/46 (6.5%)<br />scanner:	Kaspersky<br />virusname:	UDS:DangerousObject.Multi.Generic<br />url:	http://goldcoin.su/b.exe<br />recent:	up<br />response:	alive<br />ip:	92.114.82.140<br />as:	AS39758<br />review:	92.114.82.140<br />domain:	goldcoin.su<br />country:	ro<br />source:	RIPE<br />email:	9e52afcbaeed67d5b08c2d0809e1e15a@protected-email.eu<br />inetnum:	92.114.82.0 - 92.114.82.255<br />netname:	SC-TATAL-DOMINATION-SRL<br />descr:	SC Tatal Domination SRLBld. Republici  Nr. 26alba-iulia albaSC Tatal Domination SRL<br />ns1:	ns1.freedns.ws<br />ns2:	ns2.freedns.ws<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bkua.su/l/3580c.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9375739</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Jorik]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9375739</guid>
			<pubDate>2013-02-06T15:40:28+01:00</pubDate>
			<description><![CDATA[id:	9375739<br />first:	1360161628<br />last:	0<br />md5:	3b88f1150828dc477353d415db5bdd3a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3b88f1150828dc477353d415db5bdd3a<br />vt_score:	6/35 (17.1%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Jorik<br />url:	http://bkua.su/l/3580c.exe<br />recent:	up<br />response:	alive<br />ip:	5.187.4.204<br />as:	AS44066<br />review:	5.187.4.204<br />domain:	bkua.su<br />country:	ES<br />source:	RIPE<br />email:	<br />inetnum:	5.187.0.0 - 5.187.7.255<br />netname:	<br />descr:	<br />ns1:	ns2.cloudns.net<br />ns2:	ns3.cloudns.net<br />ns3:	pns3.cloudns.net<br />ns4:	pns2.cloudns.net<br />ns5:	ns4.cloudns.net<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://touchthesky.net.in/88u5a6.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9375525</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win-Trojan/Zbot.306176.E]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9375525</guid>
			<pubDate>2013-02-06T15:00:14+01:00</pubDate>
			<description><![CDATA[id:	9375525<br />first:	1360159214<br />last:	0<br />md5:	71ed487f4c1ffc051cb115118f743f2a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=71ed487f4c1ffc051cb115118f743f2a<br />vt_score:	13/36 (36.1%)<br />scanner:	AhnLab_V3<br />virusname:	Win-Trojan/Zbot.306176.E<br />url:	http://touchthesky.net.in/88u5a6.exe<br />recent:	up<br />response:	alive<br />ip:	69.167.154.157<br />as:	AS32244<br />review:	69.167.154.157<br />domain:	touchthesky.net.in<br />country:	US<br />source:	ARIN<br />email:	abuse@liquidweb.com<br />inetnum:	69.167.128.0 - 69.167.191.255<br />netname:	LIQUIDWEB-9<br />descr:	Liquid Web, Inc. LQWB 4210 Creyts Rd. Lansing MI 48917<br />ns1:	ns1-alaknanda.ewebguru.com<br />ns2:	ns2-alaknanda.ewebguru.com<br />ns3:	ns.touchthesky.net.in<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ul.to/f93juw8u/images.php?image=]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9372931</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.PWS.Stealer.1932]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9372931</guid>
			<pubDate>2013-02-06T09:00:15+01:00</pubDate>
			<description><![CDATA[id:	9372931<br />first:	1360137615<br />last:	0<br />md5:	70f0784b4c1d3a3d8d09fce3ab11c48d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=70f0784b4c1d3a3d8d09fce3ab11c48d<br />vt_score:	4/46 (8.7%)<br />scanner:	DrWeb<br />virusname:	Trojan.PWS.Stealer.1932<br />url:	http://ul.to/f93juw8u/images.php?image=<br />recent:	up<br />response:	alive<br />ip:	95.211.143.200<br />as:	AS16265<br />review:	95.211.143.200<br />domain:	ul.to<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns3.ul.to<br />ns2:	ns4.ul.to<br />ns3:	ns1.ul.to<br />ns4:	ns2.ul.to<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://uploaded.net/file/r28gfu3p]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9372930</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/ZAccess.EB.22]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9372930</guid>
			<pubDate>2013-02-06T09:00:15+01:00</pubDate>
			<description><![CDATA[id:	9372930<br />first:	1360137615<br />last:	0<br />md5:	1ceed94af1b12adec55c376b84300988<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1ceed94af1b12adec55c376b84300988<br />vt_score:	15/46 (32.6%)<br />scanner:	AntiVir<br />virusname:	TR/ZAccess.EB.22<br />url:	http://uploaded.net/file/r28gfu3p<br />recent:	up<br />response:	alive<br />ip:	95.211.143.200<br />as:	AS16265<br />review:	95.211.143.200<br />domain:	uploaded.net<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.uploaded.net<br />ns2:	ns3.uploaded.net<br />ns3:	ns2.uploaded.net<br />ns4:	ns4.uploaded.net<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bl4kjj.zapto.org/dj.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9365948</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.140145]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9365948</guid>
			<pubDate>2013-02-05T18:00:21+01:00</pubDate>
			<description><![CDATA[id:	9365948<br />first:	1360083621<br />last:	0<br />md5:	56419bfceab588eb762c49f7abf6239e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=56419bfceab588eb762c49f7abf6239e<br />vt_score:	21/46 (45.7%)<br />scanner:	AntiVir<br />virusname:	TR/Kazy.140145<br />url:	http://bl4kjj.zapto.org/dj.exe<br />recent:	up<br />response:	alive<br />ip:	188.138.0.169<br />as:	AS8972<br />review:	188.138.0.169<br />domain:	zapto.org<br />country:	DE<br />source:	RIPE<br />email:	abuse@plusserver.de<br />inetnum:	188.138.0.0 - 188.138.3.255<br />netname:	SERVERLOFT-1<br />descr:	BSB-Service GmbHhttp<br />ns1:	nf3.no-ip.com<br />ns2:	nf4.no-ip.com<br />ns3:	nf2.no-ip.com<br />ns4:	nf5.no-ip.com<br />ns5:	nf1.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bl4kjj.zapto.org/d/dj.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9365947</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.140145]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9365947</guid>
			<pubDate>2013-02-05T18:00:21+01:00</pubDate>
			<description><![CDATA[id:	9365947<br />first:	1360083621<br />last:	0<br />md5:	56419bfceab588eb762c49f7abf6239e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=56419bfceab588eb762c49f7abf6239e<br />vt_score:	17/36 (47.2%)<br />scanner:	AntiVir<br />virusname:	TR/Kazy.140145<br />url:	http://bl4kjj.zapto.org/d/dj.exe<br />recent:	up<br />response:	alive<br />ip:	188.138.0.169<br />as:	AS8972<br />review:	188.138.0.169<br />domain:	zapto.org<br />country:	DE<br />source:	RIPE<br />email:	abuse@plusserver.de<br />inetnum:	188.138.0.0 - 188.138.3.255<br />netname:	SERVERLOFT-1<br />descr:	BSB-Service GmbHhttp<br />ns1:	nf3.no-ip.com<br />ns2:	nf4.no-ip.com<br />ns3:	nf2.no-ip.com<br />ns4:	nf5.no-ip.com<br />ns5:	nf1.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://loft3066.serverloft.eu/dj.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9365946</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.140145]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9365946</guid>
			<pubDate>2013-02-05T18:00:21+01:00</pubDate>
			<description><![CDATA[id:	9365946<br />first:	1360083621<br />last:	0<br />md5:	56419bfceab588eb762c49f7abf6239e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=56419bfceab588eb762c49f7abf6239e<br />vt_score:	42/46 (91.3%)<br />scanner:	AntiVir<br />virusname:	TR/Kazy.140145<br />url:	http://loft3066.serverloft.eu/dj.exe<br />recent:	up<br />response:	alive<br />ip:	188.138.0.169<br />as:	AS8972<br />review:	188.138.0.169<br />domain:	serverloft.eu<br />country:	DE<br />source:	RIPE<br />email:	abuse@plusserver.de<br />inetnum:	188.138.0.0 - 188.138.3.255<br />netname:	SERVERLOFT-1<br />descr:	BSB-Service GmbHhttp<br />ns1:	ns10.nameserverservice.de<br />ns2:	ns9.nameserverservice.de<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://109.163.233.44/video_syria.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9365264</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win.Trojan.Agent-158384]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9365264</guid>
			<pubDate>2013-02-05T16:00:31+01:00</pubDate>
			<description><![CDATA[id:	9365264<br />first:	1360076431<br />last:	0<br />md5:	b52c70f8cbfec87ef09b7880de9e84d1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b52c70f8cbfec87ef09b7880de9e84d1<br />vt_score:	18/35 (51.4%)<br />scanner:	clamav<br />virusname:	Win.Trojan.Agent-158384<br />url:	http://109.163.233.44/video_syria.exe<br />recent:	up<br />response:	alive<br />ip:	109.163.233.44<br />as:	AS39743<br />review:	109.163.233.44<br />domain:	109.163.233.44<br />country:	RO<br />source:	RIPE<br />email:	abuse@srsvps.com<br />inetnum:	109.163.233.0 - 109.163.233.63<br />netname:	SrsVPS1<br />descr:	SrsVPS<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dl-b.uni.me/i_FR]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9364714</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Banload-1361]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9364714</guid>
			<pubDate>2013-02-05T14:40:22+01:00</pubDate>
			<description><![CDATA[id:	9364714<br />first:	1360071622<br />last:	0<br />md5:	cbcbe447db4684791abb206dba0555c4<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cbcbe447db4684791abb206dba0555c4<br />vt_score:	19/45 (42.2%)<br />scanner:	clamav<br />virusname:	Trojan.Banload-1361<br />url:	http://dl-b.uni.me/i_FR<br />recent:	up<br />response:	alive<br />ip:	198.23.141.103<br />as:	AS36352<br />review:	198.23.141.103<br />domain:	uni.me<br />country:	US<br />source:	ARIN<br />email:	abuse@colocrossing.com<br />inetnum:	198.23.128.0 - 198.23.255.255<br />netname:	CC-10<br />descr:	ColoCrossing VGS-9 8469 Sheridan Drive ATTN Williamsville NY 14221<br />ns1:	ns2.dns-domainserver.com<br />ns2:	ns1.dns-domainserver.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://q.45rwf24r.ru/Rabies6%281%29_crypt_qr30Y50d9fd13abaa9.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9364522</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Malex.E.1453]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9364522</guid>
			<pubDate>2013-02-05T14:00:25+01:00</pubDate>
			<description><![CDATA[id:	9364522<br />first:	1360069225<br />last:	0<br />md5:	0a61a16f8725e34328f10fbf54835790<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0a61a16f8725e34328f10fbf54835790<br />vt_score:	35/46 (76.1%)<br />scanner:	avira<br />virusname:	TR/Malex.E.1453<br />url:	http://q.45rwf24r.ru/Rabies6%281%29_crypt_qr30Y50d9fd13abaa9.exe<br />recent:	up<br />response:	alive<br />ip:	193.169.188.27<br />as:	AS21219<br />review:	193.169.188.27<br />domain:	45rwf24r.ru<br />country:	UA<br />source:	RIPE<br />email:	abuse@hostpro.ua<br />inetnum:	193.169.188.0 - 193.169.189.255<br />netname:	HOSTPRO-NET2<br />descr:	HostPro<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/smokeldr/sellers/bl4kj.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9362010</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9362010</guid>
			<pubDate>2013-02-05T10:00:15+01:00</pubDate>
			<description><![CDATA[id:	9362010<br />first:	1360054815<br />last:	0<br />md5:	f69f3ea44f4120d22636d5e42d16db19<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f69f3ea44f4120d22636d5e42d16db19<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://64.85.233.8/smokeldr/sellers/bl4kj.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/smokeldr/sellers/boo.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9362009</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9362009</guid>
			<pubDate>2013-02-05T10:00:15+01:00</pubDate>
			<description><![CDATA[id:	9362009<br />first:	1360054815<br />last:	0<br />md5:	e76814e104ac157ebfffde5c6982cb7d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e76814e104ac157ebfffde5c6982cb7d<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://64.85.233.8/smokeldr/sellers/boo.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/smokeldr/sellers/poop.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9362008</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9362008</guid>
			<pubDate>2013-02-05T10:00:15+01:00</pubDate>
			<description><![CDATA[id:	9362008<br />first:	1360054815<br />last:	0<br />md5:	bdcceabcfbef06df669774e7a4c1d801<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bdcceabcfbef06df669774e7a4c1d801<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://64.85.233.8/smokeldr/sellers/poop.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/smokeldr/sellers/sel1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9362007</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9362007</guid>
			<pubDate>2013-02-05T10:00:14+01:00</pubDate>
			<description><![CDATA[id:	9362007<br />first:	1360054814<br />last:	0<br />md5:	231c019cb04275828a48d348121b17eb<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=231c019cb04275828a48d348121b17eb<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://64.85.233.8/smokeldr/sellers/sel1.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/smokeldr/sellers/t0h.bak]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9362006</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Dofoil.R.403]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9362006</guid>
			<pubDate>2013-02-05T10:00:14+01:00</pubDate>
			<description><![CDATA[id:	9362006<br />first:	1360054814<br />last:	0<br />md5:	472c51ab55aaeac6e1b7cbfebe49aeda<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=472c51ab55aaeac6e1b7cbfebe49aeda<br />vt_score:	23/43 (53.5%)<br />scanner:	AntiVir<br />virusname:	TR/Dldr.Dofoil.R.403<br />url:	http://64.85.233.8/smokeldr/sellers/t0h.bak<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/192581454/012c2e7/go.exe.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9346026</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9346026</guid>
			<pubDate>2013-02-04T20:43:18+01:00</pubDate>
			<description><![CDATA[id:	9346026<br />first:	1360006998<br />last:	0<br />md5:	d74df528f5cbc07f1e73ae99e6991291<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d74df528f5cbc07f1e73ae99e6991291<br />vt_score:	5/45 (11.1%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://hotfile.com/dl/192581454/012c2e7/go.exe.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.216<br />as:	AS7366<br />review:	199.7.177.244<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns1.easydns.com<br />ns2:	ns1.hotfile.com<br />ns3:	ns2.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/192572400/5dc1a80/4.exe.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9346025</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9346025</guid>
			<pubDate>2013-02-04T20:43:17+01:00</pubDate>
			<description><![CDATA[id:	9346025<br />first:	1360006997<br />last:	0<br />md5:	48c81d978db164f0db68cd6f6c28c673<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=48c81d978db164f0db68cd6f6c28c673<br />vt_score:	5/46 (10.9%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://hotfile.com/dl/192572400/5dc1a80/4.exe.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.218<br />as:	AS7366<br />review:	199.7.177.238<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns1.easydns.com<br />ns2:	ns1.hotfile.com<br />ns3:	ns2.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/192563295/26e3025/lol.exe.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9346024</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.PornoAsset]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9346024</guid>
			<pubDate>2013-02-04T20:43:17+01:00</pubDate>
			<description><![CDATA[id:	9346024<br />first:	1360006997<br />last:	0<br />md5:	0e2ed8e3910b2f644668ae38382728ed<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0e2ed8e3910b2f644668ae38382728ed<br />vt_score:	6/46 (13%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.PornoAsset<br />url:	http://hotfile.com/dl/192563295/26e3025/lol.exe.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.220<br />as:	AS7366<br />review:	199.7.177.232<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns1.easydns.com<br />ns2:	ns1.hotfile.com<br />ns3:	ns2.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/192562755/1d80e0a/IMG0530250.JPG]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9343179</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicious file]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9343179</guid>
			<pubDate>2013-02-04T18:40:02+01:00</pubDate>
			<description><![CDATA[id:	9343179<br />first:	1359999602<br />last:	0<br />md5:	7c215df4e7718aefa2210825eee95144<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7c215df4e7718aefa2210825eee95144<br />vt_score:	2/46 (4.3%)<br />scanner:	Panda<br />virusname:	Suspicious file<br />url:	http://hotfile.com/dl/192562755/1d80e0a/IMG0530250.JPG<br />recent:	up<br />response:	alive<br />ip:	199.7.177.234<br />as:	AS7366<br />review:	199.7.177.232<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns2.easydns.com<br />ns2:	ns1.hotfile.com<br />ns3:	ns1.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://hotfile.com/dl/192563628/4e7a427/st.exe.html]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9343178</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KDZ.7027]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9343178</guid>
			<pubDate>2013-02-04T18:40:02+01:00</pubDate>
			<description><![CDATA[id:	9343178<br />first:	1359999602<br />last:	0<br />md5:	4d75cf82f4e1c4de23ce59a2fbd4e629<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4d75cf82f4e1c4de23ce59a2fbd4e629<br />vt_score:	9/36 (25%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KDZ.7027<br />url:	http://hotfile.com/dl/192563628/4e7a427/st.exe.html<br />recent:	up<br />response:	alive<br />ip:	199.7.177.236<br />as:	AS7366<br />review:	199.7.177.226<br />domain:	hotfile.com<br />country:	US<br />source:	ARIN<br />email:	abuse@lemuriaco.com<br />inetnum:	199.7.176.0 - 199.7.183.255<br />netname:	LEMURIA-COMMUNICATIONS<br />descr:	Lemuria Communications Inc. LEMUR 110 E BROWARD BLVD STE 1736 FORT LAUDERDALE FL 33301<br />ns1:	ns2.easydns.com<br />ns2:	ns1.hotfile.com<br />ns3:	ns1.easydns.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://track.www-myups.net/WebTracking/hi.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9342646</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9342646</guid>
			<pubDate>2013-02-04T17:40:03+01:00</pubDate>
			<description><![CDATA[id:	9342646<br />first:	1359996003<br />last:	0<br />md5:	dbe45c0e9b2412cc17116c667809895e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dbe45c0e9b2412cc17116c667809895e<br />vt_score:	13/46 (28.3%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://track.www-myups.net/WebTracking/hi.exe<br />recent:	up<br />response:	alive<br />ip:	122.155.13.130<br />as:	AS9931<br />review:	122.155.13.130<br />domain:	www-myups.net<br />country:	TH<br />source:	APNIC<br />email:	support@idc.cattelecom.com<br />inetnum:	122.155.0.0 - 122.155.15.255<br />netname:	CAT-IDC-Service<br />descr:	CAT TELECOM Data Comm. Dept, IDC Office***send spam abuse to support@idc.cattelecom.com***<br />ns1:	ns13.dns.com.cn<br />ns2:	ns14.dns.com.cn<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://track.www-myups.net/WebTracking/javaupdate.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9342645</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9342645</guid>
			<pubDate>2013-02-04T17:40:03+01:00</pubDate>
			<description><![CDATA[id:	9342645<br />first:	1359996003<br />last:	0<br />md5:	dbe45c0e9b2412cc17116c667809895e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dbe45c0e9b2412cc17116c667809895e<br />vt_score:	13/46 (28.3%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://track.www-myups.net/WebTracking/javaupdate.exe<br />recent:	up<br />response:	alive<br />ip:	122.155.13.130<br />as:	AS9931<br />review:	122.155.13.130<br />domain:	www-myups.net<br />country:	TH<br />source:	APNIC<br />email:	support@idc.cattelecom.com<br />inetnum:	122.155.0.0 - 122.155.15.255<br />netname:	CAT-IDC-Service<br />descr:	CAT TELECOM Data Comm. Dept, IDC Office***send spam abuse to support@idc.cattelecom.com***<br />ns1:	ns13.dns.com.cn<br />ns2:	ns14.dns.com.cn<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://track.www-myups.net/WebTracking/JavaJREInstaller.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9342644</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9342644</guid>
			<pubDate>2013-02-04T17:40:03+01:00</pubDate>
			<description><![CDATA[id:	9342644<br />first:	1359996003<br />last:	0<br />md5:	dbe45c0e9b2412cc17116c667809895e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dbe45c0e9b2412cc17116c667809895e<br />vt_score:	12/36 (33.3%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://track.www-myups.net/WebTracking/JavaJREInstaller.exe<br />recent:	up<br />response:	alive<br />ip:	122.155.13.130<br />as:	AS9931<br />review:	122.155.13.130<br />domain:	www-myups.net<br />country:	TH<br />source:	APNIC<br />email:	support@idc.cattelecom.com<br />inetnum:	122.155.0.0 - 122.155.15.255<br />netname:	CAT-IDC-Service<br />descr:	CAT TELECOM Data Comm. Dept, IDC Office***send spam abuse to support@idc.cattelecom.com***<br />ns1:	ns13.dns.com.cn<br />ns2:	ns14.dns.com.cn<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://advert.www-myups.net/brackets/advert01.php?smk=30:2v:1f:1j:30&hqnp=30:1m:30:32:1g:1o:31:1l:33:1o&xxepo=1i&reotkodm=kkeuon&dfag=klticin]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9342643</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9342643</guid>
			<pubDate>2013-02-04T17:40:03+01:00</pubDate>
			<description><![CDATA[id:	9342643<br />first:	1359996003<br />last:	0<br />md5:	dbe45c0e9b2412cc17116c667809895e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dbe45c0e9b2412cc17116c667809895e<br />vt_score:	12/36 (33.3%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://advert.www-myups.net/brackets/advert01.php?smk=30:2v:1f:1j:30&hqnp=30:1m:30:32:1g:1o:31:1l:33:1o&xxepo=1i&reotkodm=kkeuon&dfag=klticin<br />recent:	up<br />response:	alive<br />ip:	192.210.134.213<br />as:	AS36352<br />review:	192.210.134.213<br />domain:	www-myups.net<br />country:	US<br />source:	ARIN<br />email:	<br />inetnum:	192.210.128.0 - 192.210.255.255<br />netname:	<br />descr:	<br />ns1:	ns13.dns.com.cn<br />ns2:	ns14.dns.com.cn<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/r55.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9341422</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9341422</guid>
			<pubDate>2013-02-04T16:40:32+01:00</pubDate>
			<description><![CDATA[id:	9341422<br />first:	1359992432<br />last:	0<br />md5:	ed693494bf143bb7f13c6e812d393dd0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ed693494bf143bb7f13c6e812d393dd0<br />vt_score:	10/36 (27.8%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://74.208.195.229/r55.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ul.to/1zs3acqr/IMG0539204492.JPG]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9341421</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicion: unknown virus]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9341421</guid>
			<pubDate>2013-02-04T16:40:32+01:00</pubDate>
			<description><![CDATA[id:	9341421<br />first:	1359992432<br />last:	0<br />md5:	55152cb9c7a924e04a0e26546a6faf18<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=55152cb9c7a924e04a0e26546a6faf18<br />vt_score:	16/46 (34.8%)<br />scanner:	AVG<br />virusname:	Suspicion: unknown virus<br />url:	http://ul.to/1zs3acqr/IMG0539204492.JPG<br />recent:	up<br />response:	alive<br />ip:	95.211.143.200<br />as:	AS16265<br />review:	95.211.143.200<br />domain:	ul.to<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	95.211.0.0 - 95.211.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns1.ul.to<br />ns2:	ns4.ul.to<br />ns3:	ns3.ul.to<br />ns4:	ns2.ul.to<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/bget.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9337314</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KDZ.7043]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9337314</guid>
			<pubDate>2013-02-04T12:40:16+01:00</pubDate>
			<description><![CDATA[id:	9337314<br />first:	1359978016<br />last:	0<br />md5:	3cf756a86657de51d9dc7b9a99665ecf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3cf756a86657de51d9dc7b9a99665ecf<br />vt_score:	11/35 (31.4%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KDZ.7043<br />url:	http://74.208.195.229/bget.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/dun.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9337054</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9337054</guid>
			<pubDate>2013-02-04T11:40:31+01:00</pubDate>
			<description><![CDATA[id:	9337054<br />first:	1359974431<br />last:	0<br />md5:	8f2dd905f108760bf57c03a4f2f4aeb2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8f2dd905f108760bf57c03a4f2f4aeb2<br />vt_score:	14/36 (38.9%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://74.208.195.229/dun.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/server.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9336776</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Bifrose.aec.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9336776</guid>
			<pubDate>2013-02-04T11:00:11+01:00</pubDate>
			<description><![CDATA[id:	9336776<br />first:	1359972011<br />last:	0<br />md5:	617850e63ab6ee8b94c479ed44b087b3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=617850e63ab6ee8b94c479ed44b087b3<br />vt_score:	42/45 (93.3%)<br />scanner:	avira<br />virusname:	BDS/Bifrose.aec.1<br />url:	http://74.208.195.229/server.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229:80/22.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9336775</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KD.847463]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9336775</guid>
			<pubDate>2013-02-04T11:00:11+01:00</pubDate>
			<description><![CDATA[id:	9336775<br />first:	1359972011<br />last:	0<br />md5:	749996f4f59cd46d535a47c5b725facc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=749996f4f59cd46d535a47c5b725facc<br />vt_score:	9/36 (25%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KD.847463<br />url:	http://74.208.195.229:80/22.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/zy.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9336774</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9336774</guid>
			<pubDate>2013-02-04T11:00:11+01:00</pubDate>
			<description><![CDATA[id:	9336774<br />first:	1359972011<br />last:	0<br />md5:	4196afe96f5ba774a0a207b099c3436e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4196afe96f5ba774a0a207b099c3436e<br />vt_score:	3/46 (6.5%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://74.208.195.229/zy.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://royjamesinsurance.com/images/TcpAdaptorService_b3.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9336582</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Locotout.A.26]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9336582</guid>
			<pubDate>2013-02-04T10:00:26+01:00</pubDate>
			<description><![CDATA[id:	9336582<br />first:	1359968426<br />last:	0<br />md5:	c09ae408db653ba612ac7e8d3055c52b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c09ae408db653ba612ac7e8d3055c52b<br />vt_score:	11/46 (23.9%)<br />scanner:	AntiVir<br />virusname:	TR/Locotout.A.26<br />url:	http://royjamesinsurance.com/images/TcpAdaptorService_b3.exe<br />recent:	up<br />response:	alive<br />ip:	66.59.64.114<br />as:	AS11551<br />review:	66.59.64.114<br />domain:	royjamesinsurance.com<br />country:	US<br />source:	ARIN<br />email:	abuse@frontline.net<br />inetnum:	66.59.64.0 - 66.59.95.255<br />netname:	SINEP-BLOCK-2<br />descr:	Sinep Corporation SINEP-1 PO Box 98 Orangeburg NY 10962<br />ns1:	dns01.frontline.net<br />ns2:	dns02.frontline.net<br />ns3:	dns03.frontline.net<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/upi.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9336514</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KDZ.7043]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9336514</guid>
			<pubDate>2013-02-04T09:40:03+01:00</pubDate>
			<description><![CDATA[id:	9336514<br />first:	1359967203<br />last:	0<br />md5:	812353ba068edd07469ac41710aac1c7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=812353ba068edd07469ac41710aac1c7<br />vt_score:	11/36 (30.6%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KDZ.7043<br />url:	http://74.208.195.229/upi.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://62.2.109.236/server.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9334472</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Downloader.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9334472</guid>
			<pubDate>2013-02-04T02:40:04+01:00</pubDate>
			<description><![CDATA[id:	9334472<br />first:	1359942004<br />last:	0<br />md5:	a41f5b63d0c23c77810e731b2e707478<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a41f5b63d0c23c77810e731b2e707478<br />vt_score:	41/45 (91.1%)<br />scanner:	avira<br />virusname:	TR/Downloader.Gen<br />url:	http://62.2.109.236/server.exe<br />recent:	up<br />response:	alive<br />ip:	62.2.109.236<br />as:	AS8404<br />review:	62.2.109.236<br />domain:	62.2.109.236<br />country:	CH<br />source:	RIPE<br />email:	abuse@cablecom.ch<br />inetnum:	62.2.0.0 - 62.2.255.255<br />netname:	CH-CABLECOM-981211<br />descr:	Cablecom GmbH<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/boss.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9333255</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.kdz.6893.18]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9333255</guid>
			<pubDate>2013-02-03T21:50:04+01:00</pubDate>
			<description><![CDATA[id:	9333255<br />first:	1359924604<br />last:	0<br />md5:	5d5795d0149d0cfc1b6aab7f09d8e953<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5d5795d0149d0cfc1b6aab7f09d8e953<br />vt_score:	22/45 (48.9%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.kdz.6893.18<br />url:	http://74.208.195.229/boss.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/stget.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9333254</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.KD.848159.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9333254</guid>
			<pubDate>2013-02-03T21:50:04+01:00</pubDate>
			<description><![CDATA[id:	9333254<br />first:	1359924604<br />last:	0<br />md5:	91a87e9b26c68d37b2327c8963f8cd14<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=91a87e9b26c68d37b2327c8963f8cd14<br />vt_score:	13/36 (36.1%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.KD.848159.1<br />url:	http://74.208.195.229/stget.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/bat.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9331530</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9331530</guid>
			<pubDate>2013-02-03T20:00:09+01:00</pubDate>
			<description><![CDATA[id:	9331530<br />first:	1359918009<br />last:	0<br />md5:	de5697ed5bff38c98f3ae7b80a8e3387<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=de5697ed5bff38c98f3ae7b80a8e3387<br />vt_score:	3/46 (6.5%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://74.208.195.229/bat.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.silviasgalerie.com/b.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9331500</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KDZ.6945]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9331500</guid>
			<pubDate>2013-02-03T19:40:06+01:00</pubDate>
			<description><![CDATA[id:	9331500<br />first:	1359916806<br />last:	0<br />md5:	c01c0c6d26eb003b4410f11adb95abfa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c01c0c6d26eb003b4410f11adb95abfa<br />vt_score:	8/45 (17.8%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KDZ.6945<br />url:	http://www.silviasgalerie.com/b.exe<br />recent:	up<br />response:	alive<br />ip:	212.227.92.29<br />as:	AS8560<br />review:	212.227.92.29<br />domain:	silviasgalerie.com<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	212.227.68.0 - 212.227.108.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AGNCC#1999110113<br />ns1:	dns122.b.register.com<br />ns2:	dns174.a.register.com<br />ns3:	dns016.c.register.com<br />ns4:	dns010.d.register.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/skaa.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9331499</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9331499</guid>
			<pubDate>2013-02-03T19:40:06+01:00</pubDate>
			<description><![CDATA[id:	9331499<br />first:	1359916806<br />last:	0<br />md5:	90a61c26183fcc3f3806fff96fbf8a36<br />virustotal:	<br />vt_score:	4/46 (8.7%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://74.208.195.229/skaa.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.gssmail.net/images.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9331498</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9331498</guid>
			<pubDate>2013-02-03T19:40:06+01:00</pubDate>
			<description><![CDATA[id:	9331498<br />first:	1359916806<br />last:	0<br />md5:	de5697ed5bff38c98f3ae7b80a8e3387<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=de5697ed5bff38c98f3ae7b80a8e3387<br />vt_score:	3/36 (8.3%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://www.gssmail.net/images.php<br />recent:	up<br />response:	alive<br />ip:	212.227.92.29<br />as:	AS8560<br />review:	212.227.92.29<br />domain:	gssmail.net<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	212.227.68.0 - 212.227.108.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AGNCC#1999110113<br />ns1:	dns023.c.register.com<br />ns2:	dns085.a.register.com<br />ns3:	dns010.d.register.com<br />ns4:	dns046.b.register.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.gssmail.net/b.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9331497</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9331497</guid>
			<pubDate>2013-02-03T19:40:05+01:00</pubDate>
			<description><![CDATA[id:	9331497<br />first:	1359916805<br />last:	0<br />md5:	4196afe96f5ba774a0a207b099c3436e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4196afe96f5ba774a0a207b099c3436e<br />vt_score:	3/36 (8.3%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://www.gssmail.net/b.exe<br />recent:	up<br />response:	alive<br />ip:	212.227.92.29<br />as:	AS8560<br />review:	212.227.92.29<br />domain:	gssmail.net<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	212.227.68.0 - 212.227.108.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AGNCC#1999110113<br />ns1:	dns023.c.register.com<br />ns2:	dns085.a.register.com<br />ns3:	dns010.d.register.com<br />ns4:	dns046.b.register.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.silviasgalerie.com/images.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9331259</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9331259</guid>
			<pubDate>2013-02-03T19:00:16+01:00</pubDate>
			<description><![CDATA[id:	9331259<br />first:	1359914416<br />last:	0<br />md5:	c8e11e3fa99b1535eab473c3ea53adf3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c8e11e3fa99b1535eab473c3ea53adf3<br />vt_score:	4/46 (8.7%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://www.silviasgalerie.com/images.php<br />recent:	up<br />response:	alive<br />ip:	212.227.92.29<br />as:	AS8560<br />review:	212.227.92.29<br />domain:	silviasgalerie.com<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	212.227.68.0 - 212.227.108.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AGNCC#1999110113<br />ns1:	dns016.c.register.com<br />ns2:	dns174.a.register.com<br />ns3:	dns010.d.register.com<br />ns4:	dns122.b.register.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/get.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9330061</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KDZ.6930]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9330061</guid>
			<pubDate>2013-02-03T15:00:23+01:00</pubDate>
			<description><![CDATA[id:	9330061<br />first:	1359900023<br />last:	0<br />md5:	48c9b2233aeff848a157ce9123f2a457<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=48c9b2233aeff848a157ce9123f2a457<br />vt_score:	8/36 (22.2%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KDZ.6930<br />url:	http://74.208.195.229/get.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/a.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9330002</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KDZ.6945]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9330002</guid>
			<pubDate>2013-02-03T14:40:21+01:00</pubDate>
			<description><![CDATA[id:	9330002<br />first:	1359898821<br />last:	0<br />md5:	c01c0c6d26eb003b4410f11adb95abfa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c01c0c6d26eb003b4410f11adb95abfa<br />vt_score:	17/46 (37%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KDZ.6945<br />url:	http://74.208.195.229/a.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/aa.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9330001</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9330001</guid>
			<pubDate>2013-02-03T14:40:21+01:00</pubDate>
			<description><![CDATA[id:	9330001<br />first:	1359898821<br />last:	0<br />md5:	c8e11e3fa99b1535eab473c3ea53adf3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c8e11e3fa99b1535eab473c3ea53adf3<br />vt_score:	4/46 (8.7%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://74.208.195.229/aa.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/fr.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9330000</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win32:VBInject-M [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9330000</guid>
			<pubDate>2013-02-03T14:40:20+01:00</pubDate>
			<description><![CDATA[id:	9330000<br />first:	1359898820<br />last:	0<br />md5:	cccb9e29c396a0fb6487efd07c384493<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cccb9e29c396a0fb6487efd07c384493<br />vt_score:	10/36 (27.8%)<br />scanner:	Avast<br />virusname:	Win32:VBInject-M [Trj]<br />url:	http://74.208.195.229/fr.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/sk.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9329999</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.kdz.6852.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9329999</guid>
			<pubDate>2013-02-03T14:40:20+01:00</pubDate>
			<description><![CDATA[id:	9329999<br />first:	1359898820<br />last:	0<br />md5:	5b4d54ae95a8d71728fd51a39e7c5cc1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5b4d54ae95a8d71728fd51a39e7c5cc1<br />vt_score:	13/35 (37.1%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.kdz.6852.2<br />url:	http://74.208.195.229/sk.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/rew.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9329998</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9329998</guid>
			<pubDate>2013-02-03T14:40:20+01:00</pubDate>
			<description><![CDATA[id:	9329998<br />first:	1359898820<br />last:	0<br />md5:	6060c8e04411d6f61395cc3e4a3bfda5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6060c8e04411d6f61395cc3e4a3bfda5<br />vt_score:	6/36 (16.7%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://74.208.195.229/rew.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/21.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9329997</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KDZ.6930]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9329997</guid>
			<pubDate>2013-02-03T14:40:20+01:00</pubDate>
			<description><![CDATA[id:	9329997<br />first:	1359898820<br />last:	0<br />md5:	360d976d6508fadd4585dcc5f48a2786<br />virustotal:	<br />vt_score:	8/46 (17.4%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KDZ.6930<br />url:	http://74.208.195.229/21.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/22.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9329996</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KD.847463]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9329996</guid>
			<pubDate>2013-02-03T14:40:20+01:00</pubDate>
			<description><![CDATA[id:	9329996<br />first:	1359898820<br />last:	0<br />md5:	749996f4f59cd46d535a47c5b725facc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=749996f4f59cd46d535a47c5b725facc<br />vt_score:	9/36 (25%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KD.847463<br />url:	http://74.208.195.229/22.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.silviasgalerie.com/images.php?img=IMG0540255.JPG]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9329681</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9329681</guid>
			<pubDate>2013-02-03T13:50:07+01:00</pubDate>
			<description><![CDATA[id:	9329681<br />first:	1359895807<br />last:	0<br />md5:	c8e11e3fa99b1535eab473c3ea53adf3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c8e11e3fa99b1535eab473c3ea53adf3<br />vt_score:	4/46 (8.7%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://www.silviasgalerie.com/images.php?img=IMG0540255.JPG<br />recent:	up<br />response:	alive<br />ip:	212.227.92.29<br />as:	AS8560<br />review:	212.227.92.29<br />domain:	silviasgalerie.com<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	212.227.68.0 - 212.227.108.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AGNCC#1999110113<br />ns1:	dns010.d.register.com<br />ns2:	dns174.a.register.com<br />ns3:	dns016.c.register.com<br />ns4:	dns122.b.register.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/23.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9328822</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KDZ.6930]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9328822</guid>
			<pubDate>2013-02-03T11:50:03+01:00</pubDate>
			<description><![CDATA[id:	9328822<br />first:	1359888603<br />last:	0<br />md5:	3db47e913d48330150eefea639b422ce<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3db47e913d48330150eefea639b422ce<br />vt_score:	9/36 (25%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KDZ.6930<br />url:	http://74.208.195.229/23.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/vv.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9325108</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Kazy.140468]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9325108</guid>
			<pubDate>2013-02-03T02:40:04+01:00</pubDate>
			<description><![CDATA[id:	9325108<br />first:	1359855604<br />last:	0<br />md5:	6726109db64f743d56801cc06a71fb03<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6726109db64f743d56801cc06a71fb03<br />vt_score:	5/46 (10.9%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Kazy.140468<br />url:	http://74.208.195.229/vv.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/r.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9324341</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9324341</guid>
			<pubDate>2013-02-03T01:50:03+01:00</pubDate>
			<description><![CDATA[id:	9324341<br />first:	1359852603<br />last:	0<br />md5:	d0954a2da4f94ed2fda0abd8caf87140<br />virustotal:	<br />vt_score:	22/46 (47.8%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://74.208.195.229/r.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/4.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9324340</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.kdz.6852.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9324340</guid>
			<pubDate>2013-02-03T01:50:03+01:00</pubDate>
			<description><![CDATA[id:	9324340<br />first:	1359852603<br />last:	0<br />md5:	eb92b538a25c13cec6374f7c02415201<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=eb92b538a25c13cec6374f7c02415201<br />vt_score:	21/46 (45.7%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.kdz.6852.1<br />url:	http://74.208.195.229/4.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/g.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9323517</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KD.846374]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9323517</guid>
			<pubDate>2013-02-03T00:19:38+01:00</pubDate>
			<description><![CDATA[id:	9323517<br />first:	1359847178<br />last:	0<br />md5:	881cd0118e63c983ed19283ec308264c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=881cd0118e63c983ed19283ec308264c<br />vt_score:	10/46 (21.7%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KD.846374<br />url:	http://74.208.195.229/g.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://192.34.58.99/WinDefender.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9323451</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9323451</guid>
			<pubDate>2013-02-02T23:40:07+01:00</pubDate>
			<description><![CDATA[id:	9323451<br />first:	1359844807<br />last:	0<br />md5:	d9bbbbf6f5190d8760fa64c0960b4e62<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d9bbbbf6f5190d8760fa64c0960b4e62<br />vt_score:	13/36 (36.1%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://192.34.58.99/WinDefender.exe<br />recent:	up<br />response:	alive<br />ip:	192.34.58.99<br />as:	AS14061<br />review:	192.34.58.99<br />domain:	192.34.58.99<br />country:	US<br />source:	ARIN<br />email:	abuse@digitalocean.com<br />inetnum:	192.34.56.0 - 192.34.63.255<br />netname:	DIGITALOCEAN-2<br />descr:	Digital Ocean, Inc. DO-13 270 Lafayette St Suite 1206 New York NY 10012<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://egygumlo.ru/newbos2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9322377</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Generic_s.AKA]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9322377</guid>
			<pubDate>2013-02-02T20:41:25+01:00</pubDate>
			<description><![CDATA[id:	9322377<br />first:	1359834085<br />last:	0<br />md5:	5db858b8f4e7798d86a8cadc3a5f836d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5db858b8f4e7798d86a8cadc3a5f836d<br />vt_score:	9/36 (25%)<br />scanner:	AVG<br />virusname:	Generic_s.AKA<br />url:	http://egygumlo.ru/newbos2.exe<br />recent:	up<br />response:	alive<br />ip:	31.185.119.205<br />as:	AS197687<br />review:	24.211.130.19<br />domain:	egygumlo.ru<br />country:	US<br />source:	ARIN<br />email:	abuse@rr.com<br />inetnum:	31.185.112.0 - 31.185.119.255<br />netname:	RR-CENTRAL-3BLK<br />descr:	Road Runner HoldCo LLC RRMA 13241 Woodland Park Road Herndon VA 20171<br />ns1:	ns3.egygumlo.ru<br />ns2:	ns4.egygumlo.ru<br />ns3:	ns1.egygumlo.ru<br />ns4:	ns6.egygumlo.ru<br />ns5:	ns2.egygumlo.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://goldcoin.so/prime/connect-vary-conventions_upper.php?fbw=1k:33:1m:1m:1n&ilammsg=32:33:33:1h:1i:1n:30:2w:33:1j&ldd=1i&dwcdyt=oudbp&kjxidf=gzlzi]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9321120</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Ransom.Blocker.btbw.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9321120</guid>
			<pubDate>2013-02-02T19:40:07+01:00</pubDate>
			<description><![CDATA[id:	9321120<br />first:	1359830407<br />last:	0<br />md5:	bc2b1e85e21703e62110950816659714<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bc2b1e85e21703e62110950816659714<br />vt_score:	9/36 (25%)<br />scanner:	AntiVir<br />virusname:	TR/Ransom.Blocker.btbw.1<br />url:	http://goldcoin.so/prime/connect-vary-conventions_upper.php?fbw=1k:33:1m:1m:1n&ilammsg=32:33:33:1h:1i:1n:30:2w:33:1j&ldd=1i&dwcdyt=oudbp&kjxidf=gzlzi<br />recent:	up<br />response:	alive<br />ip:	198.23.248.138<br />as:	AS36352<br />review:	198.23.248.138<br />domain:	goldcoin.so<br />country:	US<br />source:	ARIN<br />email:	abuse@colocrossing.com<br />inetnum:	198.23.128.0 - 198.23.255.255<br />netname:	CC-10<br />descr:	ColoCrossing VGS-9 8469 Sheridan Drive ATTN Williamsville NY 14221<br />ns1:	ns2.freedns.ws<br />ns2:	ns1.freedns.ws<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/st.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9319453</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Generic.KDZ.6591]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9319453</guid>
			<pubDate>2013-02-02T13:40:04+01:00</pubDate>
			<description><![CDATA[id:	9319453<br />first:	1359808804<br />last:	0<br />md5:	3666d06de6e83129ce802facb8bf872f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3666d06de6e83129ce802facb8bf872f<br />vt_score:	11/36 (30.6%)<br />scanner:	BitDefender<br />virusname:	Trojan.Generic.KDZ.6591<br />url:	http://74.208.195.229/st.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/l.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9311725</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win32:VBInject-L [Trj]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9311725</guid>
			<pubDate>2013-02-01T19:40:46+01:00</pubDate>
			<description><![CDATA[id:	9311725<br />first:	1359744046<br />last:	0<br />md5:	96c9051e4a221f7edc217f7bb644770f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=96c9051e4a221f7edc217f7bb644770f<br />vt_score:	11/36 (30.6%)<br />scanner:	Avast<br />virusname:	Win32:VBInject-L [Trj]<br />url:	http://74.208.195.229/l.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.195.229/b.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9311724</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[WORM/Gamarue.itza]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9311724</guid>
			<pubDate>2013-02-01T19:40:46+01:00</pubDate>
			<description><![CDATA[id:	9311724<br />first:	1359744046<br />last:	0<br />md5:	4d3d99f4941a3f2ce648ee382253c58c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=4d3d99f4941a3f2ce648ee382253c58c<br />vt_score:	28/35 (80%)<br />scanner:	avira<br />virusname:	WORM/Gamarue.itza<br />url:	http://74.208.195.229/b.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.195.229<br />as:	AS8560<br />review:	74.208.195.229<br />domain:	74.208.195.229<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://pusycqyz.ru/links/1.php?ldxiuu=35:32:2w:32:1k&uuvmia=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&urmqzgod=1i&wtwnibft=abmp&oqscdel=xyboqm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9311723</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Heur.Packed.Unknown]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9311723</guid>
			<pubDate>2013-02-01T19:40:12+01:00</pubDate>
			<description><![CDATA[id:	9311723<br />first:	1359744012<br />last:	0<br />md5:	c0e875c05dbb018cc0342c6899e4510c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c0e875c05dbb018cc0342c6899e4510c<br />vt_score:	5/36 (13.9%)<br />scanner:	Comodo<br />virusname:	Heur.Packed.Unknown<br />url:	http://pusycqyz.ru/links/1.php?ldxiuu=35:32:2w:32:1k&uuvmia=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&urmqzgod=1i&wtwnibft=abmp&oqscdel=xyboqm<br />recent:	up<br />response:	alive<br />ip:	198.23.248.138<br />as:	AS36352<br />review:	198.23.248.138<br />domain:	pusycqyz.ru<br />country:	US<br />source:	ARIN<br />email:	abuse@colocrossing.com<br />inetnum:	198.23.128.0 - 198.23.255.255<br />netname:	CC-10<br />descr:	ColoCrossing VGS-9 8469 Sheridan Drive ATTN Williamsville NY 14221<br />ns1:	ns5.pusycqyz.ru<br />ns2:	ns6.pusycqyz.ru<br />ns3:	ns3.pusycqyz.ru<br />ns4:	ns4.pusycqyz.ru<br />ns5:	ns1.pusycqyz.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://37.221.170.244/cbcs.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9311143</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Cryp_Xin1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9311143</guid>
			<pubDate>2013-02-01T17:40:18+01:00</pubDate>
			<description><![CDATA[id:	9311143<br />first:	1359736818<br />last:	0<br />md5:	50a59e805eeb228d44f6c08e4b786d1e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=50a59e805eeb228d44f6c08e4b786d1e<br />vt_score:	22/46 (47.8%)<br />scanner:	trendmicro<br />virusname:	Cryp_Xin1<br />url:	http://37.221.170.244/cbcs.exe<br />recent:	up<br />response:	alive<br />ip:	37.221.170.244<br />as:	AS39743<br />review:	37.221.170.244<br />domain:	37.221.170.244<br />country:	RO<br />source:	RIPE<br />email:	noc@voxility.com<br />inetnum:	37.221.160.0 - 37.221.175.255<br />netname:	RO-VOXILITY-20120405<br />descr:	Voxility S.R.L.<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vybakcov.ru/links/1.php?ldxiuu=33:32:2w:32:1k&uuvmia=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&urmqzgod=1i&wtwnibft=abmp&oqscdel=xyboqm]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9311038</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Heur.Packed.Unknown]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9311038</guid>
			<pubDate>2013-02-01T17:20:17+01:00</pubDate>
			<description><![CDATA[id:	9311038<br />first:	1359735617<br />last:	0<br />md5:	f342d3c772186ec7bea986f67abc09a8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f342d3c772186ec7bea986f67abc09a8<br />vt_score:	6/46 (13%)<br />scanner:	Comodo<br />virusname:	Heur.Packed.Unknown<br />url:	http://vybakcov.ru/links/1.php?ldxiuu=33:32:2w:32:1k&uuvmia=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&urmqzgod=1i&wtwnibft=abmp&oqscdel=xyboqm<br />recent:	up<br />response:	alive<br />ip:	198.23.248.138<br />as:	AS36352<br />review:	198.23.248.138<br />domain:	vybakcov.ru<br />country:	US<br />source:	ARIN<br />email:	abuse@colocrossing.com<br />inetnum:	198.23.128.0 - 198.23.255.255<br />netname:	CC-10<br />descr:	ColoCrossing VGS-9 8469 Sheridan Drive ATTN Williamsville NY 14221<br />ns1:	ns6.vybakcov.ru<br />ns2:	ns2.vybakcov.ru<br />ns3:	ns3.vybakcov.ru<br />ns4:	ns4.vybakcov.ru<br />ns5:	ns1.vybakcov.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://astound-64-85-233-8.ca.astound.net/bleed/rrt.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9307560</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.64267.16]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9307560</guid>
			<pubDate>2013-02-01T11:42:28+01:00</pubDate>
			<description><![CDATA[id:	9307560<br />first:	1359715348<br />last:	0<br />md5:	d40f65bf66b840f3672a062e1c0edfc3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d40f65bf66b840f3672a062e1c0edfc3<br />vt_score:	28/45 (62.2%)<br />scanner:	avira<br />virusname:	TR/Kazy.64267.16<br />url:	http://astound-64-85-233-8.ca.astound.net/bleed/rrt.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	astound.net<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	ns1.wavecable.com<br />ns2:	ns2.wavecable.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://astound-64-85-233-8.ca.astound.net/eliteloader/Binary/result.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9307559</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Downloader.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9307559</guid>
			<pubDate>2013-02-01T11:42:28+01:00</pubDate>
			<description><![CDATA[id:	9307559<br />first:	1359715348<br />last:	0<br />md5:	2a9797c722fe6678a721d89ccd469c85<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2a9797c722fe6678a721d89ccd469c85<br />vt_score:	29/36 (80.6%)<br />scanner:	avira<br />virusname:	TR/Downloader.Gen<br />url:	http://astound-64-85-233-8.ca.astound.net/eliteloader/Binary/result.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	astound.net<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	ns1.wavecable.com<br />ns2:	ns2.wavecable.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://89.249.55.163/g.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9306500</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Gen:Variant.Symmi.10241]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9306500</guid>
			<pubDate>2013-02-01T09:50:04+01:00</pubDate>
			<description><![CDATA[id:	9306500<br />first:	1359708604<br />last:	0<br />md5:	d6f4f3915cb93e628e36f8cdc53c870e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d6f4f3915cb93e628e36f8cdc53c870e<br />vt_score:	11/36 (30.6%)<br />scanner:	BitDefender<br />virusname:	Gen:Variant.Symmi.10241<br />url:	http://89.249.55.163/g.exe<br />recent:	up<br />response:	alive<br />ip:	89.249.55.163<br />as:	AS41310<br />review:	89.249.55.163<br />domain:	89.249.55.163<br />country:	RU<br />source:	RIPE<br />email:	krem@ipct.ru<br />inetnum:	89.249.48.0 - 89.249.55.255<br />netname:	IPCT<br />descr:	ISP Komputer technology Ltd.Bryansk citySofya Perovskoy st. 83(4832)674-674Ltd "Kompyuternie Tehnologii".<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://89.249.55.163/b.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9306499</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win32.HLLW.Phorpiex.54]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9306499</guid>
			<pubDate>2013-02-01T09:50:04+01:00</pubDate>
			<description><![CDATA[id:	9306499<br />first:	1359708604<br />last:	0<br />md5:	8469641a51159f7986b297652a2290c3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8469641a51159f7986b297652a2290c3<br />vt_score:	6/36 (16.7%)<br />scanner:	DrWeb<br />virusname:	Win32.HLLW.Phorpiex.54<br />url:	http://89.249.55.163/b.exe<br />recent:	up<br />response:	alive<br />ip:	89.249.55.163<br />as:	AS41310<br />review:	89.249.55.163<br />domain:	89.249.55.163<br />country:	RU<br />source:	RIPE<br />email:	krem@ipct.ru<br />inetnum:	89.249.48.0 - 89.249.55.255<br />netname:	IPCT<br />descr:	ISP Komputer technology Ltd.Bryansk citySofya Perovskoy st. 83(4832)674-674Ltd "Kompyuternie Tehnologii".<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://89.249.55.163/l.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9306498</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9306498</guid>
			<pubDate>2013-02-01T09:50:04+01:00</pubDate>
			<description><![CDATA[id:	9306498<br />first:	1359708604<br />last:	0<br />md5:	4efac350da363727994646cbe530ed54<br />virustotal:	<br />vt_score:	20/46 (43.5%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://89.249.55.163/l.exe<br />recent:	up<br />response:	alive<br />ip:	89.249.55.163<br />as:	AS41310<br />review:	89.249.55.163<br />domain:	89.249.55.163<br />country:	RU<br />source:	RIPE<br />email:	krem@ipct.ru<br />inetnum:	89.249.48.0 - 89.249.55.255<br />netname:	IPCT<br />descr:	ISP Komputer technology Ltd.Bryansk citySofya Perovskoy st. 83(4832)674-674Ltd "Kompyuternie Tehnologii".<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://46.38.63.119/bck/udateq.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9304763</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Backdoor/Win32.DarkKomet]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9304763</guid>
			<pubDate>2013-02-01T06:41:30+01:00</pubDate>
			<description><![CDATA[id:	9304763<br />first:	1359697290<br />last:	0<br />md5:	dffcdbe44ebfe40064e4f035579ddfba<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=dffcdbe44ebfe40064e4f035579ddfba<br />vt_score:	23/46 (50%)<br />scanner:	AhnLab_V3<br />virusname:	Backdoor/Win32.DarkKomet<br />url:	http://46.38.63.119/bck/udateq.exe<br />recent:	up<br />response:	alive<br />ip:	46.38.63.119<br />as:	AS52201<br />review:	46.38.63.119<br />domain:	46.38.63.119<br />country:	RU<br />source:	RIPE<br />email:	alexander.kondrat@tel.ru<br />inetnum:	46.38.56.0 - 46.38.63.255<br />netname:	TCTEL<br />descr:	TC TEL hostingTCTEL-NET<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://200.170.219.25/v2/kkras/up.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9304762</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win-Trojan/Downloader.239104.AG]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9304762</guid>
			<pubDate>2013-02-01T06:41:30+01:00</pubDate>
			<description><![CDATA[id:	9304762<br />first:	1359697290<br />last:	0<br />md5:	098e6f0259e9d8428b29337de5879d3b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=098e6f0259e9d8428b29337de5879d3b<br />vt_score:	32/46 (69.6%)<br />scanner:	AhnLab_V3<br />virusname:	Win-Trojan/Downloader.239104.AG<br />url:	http://200.170.219.25/v2/kkras/up.jpg<br />recent:	up<br />response:	alive<br />ip:	200.170.219.25<br />as:	AS11432<br />review:	200.170.219.25<br />domain:	200.170.219.25<br />country:	BR<br />source:	LACNIC<br />email:	goldsuporte@telium.com.br<br />inetnum:	200.170.192.0 - 200.170.255.255<br />netname:	007.272.054/0001-55<br />descr:	Telium Telecomunicações Ltda<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://200.170.219.25/v2/negao/up.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9304761</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win-Trojan/Downloader.239104.AG]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9304761</guid>
			<pubDate>2013-02-01T06:41:30+01:00</pubDate>
			<description><![CDATA[id:	9304761<br />first:	1359697290<br />last:	0<br />md5:	098e6f0259e9d8428b29337de5879d3b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=098e6f0259e9d8428b29337de5879d3b<br />vt_score:	32/46 (69.6%)<br />scanner:	AhnLab_V3<br />virusname:	Win-Trojan/Downloader.239104.AG<br />url:	http://200.170.219.25/v2/negao/up.jpg<br />recent:	up<br />response:	alive<br />ip:	200.170.219.25<br />as:	AS11432<br />review:	200.170.219.25<br />domain:	200.170.219.25<br />country:	BR<br />source:	LACNIC<br />email:	goldsuporte@telium.com.br<br />inetnum:	200.170.192.0 - 200.170.255.255<br />netname:	007.272.054/0001-55<br />descr:	Telium Telecomunicações Ltda<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://200.170.219.25/v2/negao/evx.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9304759</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PSW.Banker6.APFI]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9304759</guid>
			<pubDate>2013-02-01T06:41:30+01:00</pubDate>
			<description><![CDATA[id:	9304759<br />first:	1359697290<br />last:	0<br />md5:	e18fd6d7241b0d693f04481c91701a39<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e18fd6d7241b0d693f04481c91701a39<br />vt_score:	7/46 (15.2%)<br />scanner:	AVG<br />virusname:	PSW.Banker6.APFI<br />url:	http://200.170.219.25/v2/negao/evx.jpg<br />recent:	up<br />response:	alive<br />ip:	200.170.219.25<br />as:	AS11432<br />review:	200.170.219.25<br />domain:	200.170.219.25<br />country:	BR<br />source:	LACNIC<br />email:	goldsuporte@telium.com.br<br />inetnum:	200.170.192.0 - 200.170.255.255<br />netname:	007.272.054/0001-55<br />descr:	Telium Telecomunicações Ltda<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://xizzawvu.ru/links/1.php?ayq=32:2v:1h:2w:1m&mntt=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&eghf=1i&uodoskx=padzflh&knrezehi=vkyuabri]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9304757</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Tepfer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9304757</guid>
			<pubDate>2013-02-01T06:41:30+01:00</pubDate>
			<description><![CDATA[id:	9304757<br />first:	1359697290<br />last:	0<br />md5:	7d58eaa00f5615b784b67647e5b613ae<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c497d0c2f9942819038a84cef50a3221<br />vt_score:	8/36 (22.2%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Tepfer<br />url:	http://xizzawvu.ru/links/1.php?ayq=32:2v:1h:2w:1m&mntt=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&eghf=1i&uodoskx=padzflh&knrezehi=vkyuabri<br />recent:	up<br />response:	alive<br />ip:	198.23.248.138<br />as:	AS36352<br />review:	198.23.248.138<br />domain:	xizzawvu.ru<br />country:	US<br />source:	ARIN<br />email:	abuse@colocrossing.com<br />inetnum:	198.23.128.0 - 198.23.255.255<br />netname:	CC-10<br />descr:	ColoCrossing VGS-9 8469 Sheridan Drive ATTN Williamsville NY 14221<br />ns1:	ns4.xizzawvu.ru<br />ns2:	ns5.xizzawvu.ru<br />ns3:	ns1.xizzawvu.ru<br />ns4:	ns3.xizzawvu.ru<br />ns5:	ns2.xizzawvu.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/dj.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303584</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/ATRAPS.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303584</guid>
			<pubDate>2013-02-01T03:40:20+01:00</pubDate>
			<description><![CDATA[id:	9303584<br />first:	1359686420<br />last:	0<br />md5:	2a4419024f501d168864771a38f85b8d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2a4419024f501d168864771a38f85b8d<br />vt_score:	42/46 (91.3%)<br />scanner:	avira<br />virusname:	TR/ATRAPS.Gen<br />url:	http://64.85.233.8/dj.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/c22.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303330</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.MSIL.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303330</guid>
			<pubDate>2013-02-01T03:01:31+01:00</pubDate>
			<description><![CDATA[id:	9303330<br />first:	1359684091<br />last:	0<br />md5:	eb61239931f7158d7e814e270406ba6e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=eb61239931f7158d7e814e270406ba6e<br />vt_score:	7/36 (19.4%)<br />scanner:	avira<br />virusname:	TR/Dropper.MSIL.Gen<br />url:	http://64.85.233.8/c22.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/Bot_Builder_-_cracked!.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303329</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Backdoor.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303329</guid>
			<pubDate>2013-02-01T03:01:31+01:00</pubDate>
			<description><![CDATA[id:	9303329<br />first:	1359684091<br />last:	0<br />md5:	7fdbf6b561f69dd9ed3be3269100af78<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=7fdbf6b561f69dd9ed3be3269100af78<br />vt_score:	21/46 (45.7%)<br />scanner:	avira<br />virusname:	BDS/Backdoor.Gen<br />url:	http://64.85.233.8/Bot_Builder_-_cracked!.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/CythBuilder.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303328</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Drop.Agent.46592.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303328</guid>
			<pubDate>2013-02-01T03:01:31+01:00</pubDate>
			<description><![CDATA[id:	9303328<br />first:	1359684091<br />last:	0<br />md5:	60252b0565a60abfef9dec2e20dd9629<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=60252b0565a60abfef9dec2e20dd9629<br />vt_score:	22/44 (50%)<br />scanner:	avira<br />virusname:	TR/Drop.Agent.46592.2<br />url:	http://64.85.233.8/CythBuilder.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/Loader.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303327</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303327</guid>
			<pubDate>2013-02-01T03:01:31+01:00</pubDate>
			<description><![CDATA[id:	9303327<br />first:	1359684091<br />last:	0<br />md5:	9afe25e93d9118975fb849864b13b332<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9afe25e93d9118975fb849864b13b332<br />vt_score:	29/46 (63%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://64.85.233.8/Loader.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/androbot.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303326</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[WORM/Gamarue.itza]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303326</guid>
			<pubDate>2013-02-01T03:01:31+01:00</pubDate>
			<description><![CDATA[id:	9303326<br />first:	1359684091<br />last:	0<br />md5:	beec20b0093e341b12889ebfe06c6c30<br />virustotal:	<br />vt_score:	41/46 (89.1%)<br />scanner:	avira<br />virusname:	WORM/Gamarue.itza<br />url:	http://64.85.233.8/androbot.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/andronew.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303325</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[WORM/Gamarue.itza]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303325</guid>
			<pubDate>2013-02-01T03:01:31+01:00</pubDate>
			<description><![CDATA[id:	9303325<br />first:	1359684091<br />last:	0<br />md5:	8da240f8b9ae8f85913d31027afa5b2c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8da240f8b9ae8f85913d31027afa5b2c<br />vt_score:	29/36 (80.6%)<br />scanner:	avira<br />virusname:	WORM/Gamarue.itza<br />url:	http://64.85.233.8/andronew.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/mocat_win.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303324</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[SPR/Tool.NetCat.B]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303324</guid>
			<pubDate>2013-02-01T03:01:31+01:00</pubDate>
			<description><![CDATA[id:	9303324<br />first:	1359684091<br />last:	0<br />md5:	2fb74a511bdd6bb4c18a9c340f52785e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2fb74a511bdd6bb4c18a9c340f52785e<br />vt_score:	24/36 (66.7%)<br />scanner:	avira<br />virusname:	SPR/Tool.NetCat.B<br />url:	http://64.85.233.8/mocat_win.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/x2ImSD03.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303323</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[WORM/Autorun.hum.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303323</guid>
			<pubDate>2013-02-01T03:01:31+01:00</pubDate>
			<description><![CDATA[id:	9303323<br />first:	1359684091<br />last:	0<br />md5:	d2061c62e21dda589996355825f03f89<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d2061c62e21dda589996355825f03f89<br />vt_score:	36/46 (78.3%)<br />scanner:	avira<br />virusname:	WORM/Autorun.hum.1<br />url:	http://64.85.233.8/x2ImSD03.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/adobe-v10_08.20.2_2012_3.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303322</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Barys.2217.148]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303322</guid>
			<pubDate>2013-02-01T03:01:31+01:00</pubDate>
			<description><![CDATA[id:	9303322<br />first:	1359684091<br />last:	0<br />md5:	e5d076d725476014c2e6d1fde6c904e7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e5d076d725476014c2e6d1fde6c904e7<br />vt_score:	29/46 (63%)<br />scanner:	avira<br />virusname:	TR/Barys.2217.148<br />url:	http://64.85.233.8/adobe-v10_08.20.2_2012_3.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/dhell.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303321</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.78275.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303321</guid>
			<pubDate>2013-02-01T03:01:02+01:00</pubDate>
			<description><![CDATA[id:	9303321<br />first:	1359684062<br />last:	0<br />md5:	36042088f59bd84cd4e29e2bd17efd5a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=36042088f59bd84cd4e29e2bd17efd5a<br />vt_score:	26/44 (59.1%)<br />scanner:	avira<br />virusname:	TR/Kazy.78275.1<br />url:	http://64.85.233.8/dhell.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/setup.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303038</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Backdoor.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303038</guid>
			<pubDate>2013-02-01T02:43:12+01:00</pubDate>
			<description><![CDATA[id:	9303038<br />first:	1359682992<br />last:	0<br />md5:	8506f62ffe4a7bb780f9a0c127f97f80<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8506f62ffe4a7bb780f9a0c127f97f80<br />vt_score:	32/35 (91.4%)<br />scanner:	avira<br />virusname:	BDS/Backdoor.Gen<br />url:	http://64.85.233.8/setup.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/server.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303037</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303037</guid>
			<pubDate>2013-02-01T02:43:12+01:00</pubDate>
			<description><![CDATA[id:	9303037<br />first:	1359682992<br />last:	0<br />md5:	2f1c92f53575a1e43b5fb7f58778dc85<br />virustotal:	<br />vt_score:	36/46 (78.3%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://64.85.233.8/server.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/rrt.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303035</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.64267.16]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303035</guid>
			<pubDate>2013-02-01T02:43:12+01:00</pubDate>
			<description><![CDATA[id:	9303035<br />first:	1359682992<br />last:	0<br />md5:	d40f65bf66b840f3672a062e1c0edfc3<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d40f65bf66b840f3672a062e1c0edfc3<br />vt_score:	23/36 (63.9%)<br />scanner:	avira<br />virusname:	TR/Kazy.64267.16<br />url:	http://64.85.233.8/rrt.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/priv.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303034</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen7]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303034</guid>
			<pubDate>2013-02-01T02:43:12+01:00</pubDate>
			<description><![CDATA[id:	9303034<br />first:	1359682992<br />last:	0<br />md5:	168730e13b3689c926761e37fb39424c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=168730e13b3689c926761e37fb39424c<br />vt_score:	2/46 (4.3%)<br />scanner:	AntiVir<br />virusname:	TR/Crypt.ZPACK.Gen7<br />url:	http://64.85.233.8/priv.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/dual.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303031</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/ATRAPS.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303031</guid>
			<pubDate>2013-02-01T02:43:12+01:00</pubDate>
			<description><![CDATA[id:	9303031<br />first:	1359682992<br />last:	0<br />md5:	f255b0f0605dc1fe5103bcff911f9851<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f255b0f0605dc1fe5103bcff911f9851<br />vt_score:	40/46 (87%)<br />scanner:	avira<br />virusname:	TR/ATRAPS.Gen<br />url:	http://64.85.233.8/dual.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/combo.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303029</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[ILCrypt]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303029</guid>
			<pubDate>2013-02-01T02:43:12+01:00</pubDate>
			<description><![CDATA[id:	9303029<br />first:	1359682992<br />last:	0<br />md5:	5a8e905adcbb49bfa8f7f141371199b5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5a8e905adcbb49bfa8f7f141371199b5<br />vt_score:	9/36 (25%)<br />scanner:	AVG<br />virusname:	ILCrypt<br />url:	http://64.85.233.8/combo.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/QP69IUGD7Y.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9303019</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BDS/Backdoor.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9303019</guid>
			<pubDate>2013-02-01T02:40:54+01:00</pubDate>
			<description><![CDATA[id:	9303019<br />first:	1359682854<br />last:	0<br />md5:	ff089fe65535dbde885dc67b0148c5cc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ff089fe65535dbde885dc67b0148c5cc<br />vt_score:	37/45 (82.2%)<br />scanner:	avira<br />virusname:	BDS/Backdoor.Gen<br />url:	http://64.85.233.8/QP69IUGD7Y.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/go2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9302656</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.EPACK.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9302656</guid>
			<pubDate>2013-02-01T02:00:21+01:00</pubDate>
			<description><![CDATA[id:	9302656<br />first:	1359680421<br />last:	0<br />md5:	9e2951861c6b6b7e2d318c8d5f314de5<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9e2951861c6b6b7e2d318c8d5f314de5<br />vt_score:	18/45 (40%)<br />scanner:	avira<br />virusname:	TR/Crypt.EPACK.Gen2<br />url:	http://64.85.233.8/go2.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/result.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9302402</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Downloader.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9302402</guid>
			<pubDate>2013-02-01T01:40:06+01:00</pubDate>
			<description><![CDATA[id:	9302402<br />first:	1359679206<br />last:	0<br />md5:	b3a29aed50df89d306f751e697b1318e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b3a29aed50df89d306f751e697b1318e<br />vt_score:	36/46 (78.3%)<br />scanner:	avira<br />virusname:	TR/Downloader.Gen<br />url:	http://64.85.233.8/result.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/out.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9302401</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9302401</guid>
			<pubDate>2013-02-01T01:40:06+01:00</pubDate>
			<description><![CDATA[id:	9302401<br />first:	1359679206<br />last:	0<br />md5:	0001ef634043fe2347fa6314bff903ef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0001ef634043fe2347fa6314bff903ef<br />vt_score:	27/46 (58.7%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://64.85.233.8/out.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/evil.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9302400</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/ATRAPS.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9302400</guid>
			<pubDate>2013-02-01T01:40:06+01:00</pubDate>
			<description><![CDATA[id:	9302400<br />first:	1359679206<br />last:	0<br />md5:	2c810db5062de9956fef88b88e11ed27<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2c810db5062de9956fef88b88e11ed27<br />vt_score:	27/36 (75%)<br />scanner:	avira<br />virusname:	TR/ATRAPS.Gen<br />url:	http://64.85.233.8/evil.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/build.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9302399</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/ATRAPS.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9302399</guid>
			<pubDate>2013-02-01T01:40:06+01:00</pubDate>
			<description><![CDATA[id:	9302399<br />first:	1359679206<br />last:	0<br />md5:	2a4419024f501d168864771a38f85b8d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2a4419024f501d168864771a38f85b8d<br />vt_score:	42/46 (91.3%)<br />scanner:	avira<br />virusname:	TR/ATRAPS.Gen<br />url:	http://64.85.233.8/build.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/update.zip]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9302184</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[WORM/Gamarue.itza]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9302184</guid>
			<pubDate>2013-02-01T00:40:25+01:00</pubDate>
			<description><![CDATA[id:	9302184<br />first:	1359675625<br />last:	0<br />md5:	beec20b0093e341b12889ebfe06c6c30<br />virustotal:	<br />vt_score:	41/46 (89.1%)<br />scanner:	avira<br />virusname:	WORM/Gamarue.itza<br />url:	http://64.85.233.8/update.zip<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/as.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9302183</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen7]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9302183</guid>
			<pubDate>2013-02-01T00:40:25+01:00</pubDate>
			<description><![CDATA[id:	9302183<br />first:	1359675625<br />last:	0<br />md5:	8c90a114fb10e44c36c8734a815c2503<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8c90a114fb10e44c36c8734a815c2503<br />vt_score:	2/46 (4.3%)<br />scanner:	AntiVir<br />virusname:	TR/Crypt.ZPACK.Gen7<br />url:	http://64.85.233.8/as.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/po.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9302182</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen3]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9302182</guid>
			<pubDate>2013-02-01T00:40:25+01:00</pubDate>
			<description><![CDATA[id:	9302182<br />first:	1359675625<br />last:	0<br />md5:	d24ab17f5a7e4c0d622666039592da46<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d24ab17f5a7e4c0d622666039592da46<br />vt_score:	27/46 (58.7%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen3<br />url:	http://64.85.233.8/po.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/msf.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301915</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.EPACK.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301915</guid>
			<pubDate>2013-02-01T00:29:33+01:00</pubDate>
			<description><![CDATA[id:	9301915<br />first:	1359674973<br />last:	0<br />md5:	6284c548cd67533d96576f390de28a89<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6284c548cd67533d96576f390de28a89<br />vt_score:	35/45 (77.8%)<br />scanner:	avira<br />virusname:	TR/Crypt.EPACK.Gen2<br />url:	http://64.85.233.8/msf.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/backdoor.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301914</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301914</guid>
			<pubDate>2013-02-01T00:29:32+01:00</pubDate>
			<description><![CDATA[id:	9301914<br />first:	1359674972<br />last:	0<br />md5:	3f5aa952d29326268f6985cd9734a128<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=3f5aa952d29326268f6985cd9734a128<br />vt_score:	2/44 (4.5%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://64.85.233.8/backdoor.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/dl.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301913</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Barys.2831.130]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301913</guid>
			<pubDate>2013-02-01T00:29:32+01:00</pubDate>
			<description><![CDATA[id:	9301913<br />first:	1359674972<br />last:	0<br />md5:	c56ca809052066dcb6ad08ff491e2b7c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=c56ca809052066dcb6ad08ff491e2b7c<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	TR/Barys.2831.130<br />url:	http://64.85.233.8/dl.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/red/update.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301912</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301912</guid>
			<pubDate>2013-02-01T00:29:32+01:00</pubDate>
			<description><![CDATA[id:	9301912<br />first:	1359674972<br />last:	0<br />md5:	2f1c92f53575a1e43b5fb7f58778dc85<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=2f1c92f53575a1e43b5fb7f58778dc85<br />vt_score:	37/46 (80.4%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://64.85.233.8/red/update.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/p2/exe.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301711</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.mkc.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301711</guid>
			<pubDate>2013-01-31T23:40:21+01:00</pubDate>
			<description><![CDATA[id:	9301711<br />first:	1359672021<br />last:	0<br />md5:	a1b69b95c093115b81e79d0f04d84085<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a1b69b95c093115b81e79d0f04d84085<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	TR/Kazy.mkc.1<br />url:	http://64.85.233.8/p2/exe.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://212.227.141.241/l.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301708</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301708</guid>
			<pubDate>2013-01-31T23:40:21+01:00</pubDate>
			<description><![CDATA[id:	9301708<br />first:	1359672021<br />last:	0<br />md5:	4efac350da363727994646cbe530ed54<br />virustotal:	<br />vt_score:	20/46 (43.5%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://212.227.141.241/l.exe<br />recent:	up<br />response:	alive<br />ip:	212.227.141.241<br />as:	AS8560<br />review:	212.227.141.241<br />domain:	212.227.141.241<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	212.227.134.0 - 212.227.143.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 InternetSCHLUND-PA-2<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/h.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301706</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Dofoil.R.403]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301706</guid>
			<pubDate>2013-01-31T23:40:21+01:00</pubDate>
			<description><![CDATA[id:	9301706<br />first:	1359672021<br />last:	0<br />md5:	472c51ab55aaeac6e1b7cbfebe49aeda<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=472c51ab55aaeac6e1b7cbfebe49aeda<br />vt_score:	23/43 (53.5%)<br />scanner:	AntiVir<br />virusname:	TR/Dldr.Dofoil.R.403<br />url:	http://64.85.233.8/h.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/i.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301704</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Blocker]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301704</guid>
			<pubDate>2013-01-31T23:40:21+01:00</pubDate>
			<description><![CDATA[id:	9301704<br />first:	1359672021<br />last:	0<br />md5:	69bd6213a093db08e77e2990537fd022<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=69bd6213a093db08e77e2990537fd022<br />vt_score:	22/36 (61.1%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Blocker<br />url:	http://64.85.233.8/i.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/j.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301701</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Dropper/Win32.Agent]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301701</guid>
			<pubDate>2013-01-31T23:40:20+01:00</pubDate>
			<description><![CDATA[id:	9301701<br />first:	1359672020<br />last:	0<br />md5:	1a43cf22b43d2801ca6a2f51ac8ef1cf<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=1a43cf22b43d2801ca6a2f51ac8ef1cf<br />vt_score:	24/46 (52.2%)<br />scanner:	AhnLab_V3<br />virusname:	Dropper/Win32.Agent<br />url:	http://64.85.233.8/j.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/m.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301699</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.78275.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301699</guid>
			<pubDate>2013-01-31T23:40:20+01:00</pubDate>
			<description><![CDATA[id:	9301699<br />first:	1359672020<br />last:	0<br />md5:	36042088f59bd84cd4e29e2bd17efd5a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=36042088f59bd84cd4e29e2bd17efd5a<br />vt_score:	22/36 (61.1%)<br />scanner:	avira<br />virusname:	TR/Kazy.78275.1<br />url:	http://64.85.233.8/m.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/t.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301696</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.78275.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301696</guid>
			<pubDate>2013-01-31T23:40:20+01:00</pubDate>
			<description><![CDATA[id:	9301696<br />first:	1359672020<br />last:	0<br />md5:	36042088f59bd84cd4e29e2bd17efd5a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=36042088f59bd84cd4e29e2bd17efd5a<br />vt_score:	26/44 (59.1%)<br />scanner:	avira<br />virusname:	TR/Kazy.78275.1<br />url:	http://64.85.233.8/t.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/u.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301695</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301695</guid>
			<pubDate>2013-01-31T23:40:20+01:00</pubDate>
			<description><![CDATA[id:	9301695<br />first:	1359672020<br />last:	0<br />md5:	2f1c92f53575a1e43b5fb7f58778dc85<br />virustotal:	<br />vt_score:	36/46 (78.3%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://64.85.233.8/u.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/x.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301693</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.EPACK.Gen2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301693</guid>
			<pubDate>2013-01-31T23:40:20+01:00</pubDate>
			<description><![CDATA[id:	9301693<br />first:	1359672020<br />last:	0<br />md5:	fff700002c3e2b11ed62ad89c1f6739c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fff700002c3e2b11ed62ad89c1f6739c<br />vt_score:	28/35 (80%)<br />scanner:	avira<br />virusname:	TR/Crypt.EPACK.Gen2<br />url:	http://64.85.233.8/x.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/x]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301691</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Rogue.KD.843772.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301691</guid>
			<pubDate>2013-01-31T23:40:20+01:00</pubDate>
			<description><![CDATA[id:	9301691<br />first:	1359672020<br />last:	0<br />md5:	6dd7804597d6d37123448cd64381b4b0<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=6dd7804597d6d37123448cd64381b4b0<br />vt_score:	9/46 (19.6%)<br />scanner:	AntiVir<br />virusname:	TR/Rogue.KD.843772.1<br />url:	http://64.85.233.8/x<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/wa]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301689</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[KIT/Buildy.57]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301689</guid>
			<pubDate>2013-01-31T23:40:20+01:00</pubDate>
			<description><![CDATA[id:	9301689<br />first:	1359672020<br />last:	0<br />md5:	da1aba4a05e4045f3cfe1bdd26fafe85<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=da1aba4a05e4045f3cfe1bdd26fafe85<br />vt_score:	22/42 (52.4%)<br />scanner:	avira<br />virusname:	KIT/Buildy.57<br />url:	http://64.85.233.8/wa<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/up.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301687</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Kazy.mkc.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301687</guid>
			<pubDate>2013-01-31T23:40:20+01:00</pubDate>
			<description><![CDATA[id:	9301687<br />first:	1359672020<br />last:	0<br />md5:	a1b69b95c093115b81e79d0f04d84085<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a1b69b95c093115b81e79d0f04d84085<br />vt_score:	24/46 (52.2%)<br />scanner:	avira<br />virusname:	TR/Kazy.mkc.1<br />url:	http://64.85.233.8/up.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/win.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301686</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen7]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301686</guid>
			<pubDate>2013-01-31T23:40:20+01:00</pubDate>
			<description><![CDATA[id:	9301686<br />first:	1359672020<br />last:	0<br />md5:	9ac3b1df5a64c6fb3c92e8826d8b0cf6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9ac3b1df5a64c6fb3c92e8826d8b0cf6<br />vt_score:	3/36 (8.3%)<br />scanner:	AntiVir<br />virusname:	TR/Crypt.ZPACK.Gen7<br />url:	http://64.85.233.8/win.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/bot.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301636</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Barys.2217.148]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301636</guid>
			<pubDate>2013-01-31T23:00:24+01:00</pubDate>
			<description><![CDATA[id:	9301636<br />first:	1359669624<br />last:	0<br />md5:	e5d076d725476014c2e6d1fde6c904e7<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e5d076d725476014c2e6d1fde6c904e7<br />vt_score:	29/46 (63%)<br />scanner:	avira<br />virusname:	TR/Barys.2217.148<br />url:	http://64.85.233.8/bot.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/xxx/x-pack/load/load.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301635</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Dofoil.R.403]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301635</guid>
			<pubDate>2013-01-31T23:00:24+01:00</pubDate>
			<description><![CDATA[id:	9301635<br />first:	1359669624<br />last:	0<br />md5:	472c51ab55aaeac6e1b7cbfebe49aeda<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=472c51ab55aaeac6e1b7cbfebe49aeda<br />vt_score:	23/43 (53.5%)<br />scanner:	AntiVir<br />virusname:	TR/Dldr.Dofoil.R.403<br />url:	http://64.85.233.8/xxx/x-pack/load/load.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/xxx/x-pack/load/server.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301634</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301634</guid>
			<pubDate>2013-01-31T23:00:24+01:00</pubDate>
			<description><![CDATA[id:	9301634<br />first:	1359669624<br />last:	0<br />md5:	0001ef634043fe2347fa6314bff903ef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0001ef634043fe2347fa6314bff903ef<br />vt_score:	27/46 (58.7%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://64.85.233.8/xxx/x-pack/load/server.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/xxx/x-pack/load/UpdateAdobe.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301633</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/ATRAPS.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301633</guid>
			<pubDate>2013-01-31T23:00:24+01:00</pubDate>
			<description><![CDATA[id:	9301633<br />first:	1359669624<br />last:	0<br />md5:	f255b0f0605dc1fe5103bcff911f9851<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f255b0f0605dc1fe5103bcff911f9851<br />vt_score:	33/36 (91.7%)<br />scanner:	avira<br />virusname:	TR/ATRAPS.Gen<br />url:	http://64.85.233.8/xxx/x-pack/load/UpdateAdobe.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/smokeldr/update.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301632</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Dofoil.R.403]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301632</guid>
			<pubDate>2013-01-31T23:00:24+01:00</pubDate>
			<description><![CDATA[id:	9301632<br />first:	1359669624<br />last:	0<br />md5:	472c51ab55aaeac6e1b7cbfebe49aeda<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=472c51ab55aaeac6e1b7cbfebe49aeda<br />vt_score:	23/43 (53.5%)<br />scanner:	AntiVir<br />virusname:	TR/Dldr.Dofoil.R.403<br />url:	http://64.85.233.8/smokeldr/update.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/uniq/1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9301631</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[WORM/Gamarue.itza]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9301631</guid>
			<pubDate>2013-01-31T23:00:22+01:00</pubDate>
			<description><![CDATA[id:	9301631<br />first:	1359669622<br />last:	0<br />md5:	beec20b0093e341b12889ebfe06c6c30<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=beec20b0093e341b12889ebfe06c6c30<br />vt_score:	33/36 (91.7%)<br />scanner:	avira<br />virusname:	WORM/Gamarue.itza<br />url:	http://64.85.233.8/uniq/1.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://copapjid.ru/newbos2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9299746</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.ZPACK.Gen6]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9299746</guid>
			<pubDate>2013-01-31T21:00:19+01:00</pubDate>
			<description><![CDATA[id:	9299746<br />first:	1359662419<br />last:	0<br />md5:	64fc45d06a6f7e6004c6252b28925bb8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=64fc45d06a6f7e6004c6252b28925bb8<br />vt_score:	10/46 (21.7%)<br />scanner:	AntiVir<br />virusname:	TR/Crypt.ZPACK.Gen6<br />url:	http://copapjid.ru/newbos2.exe<br />recent:	up<br />response:	alive<br />ip:	109.185.226.78<br />as:	AS8926<br />review:	62.221.136.215<br />domain:	copapjid.ru<br />country:	BG<br />source:	RIPE<br />email:	hostmaster@interbgc.com<br />inetnum:	109.185.0.0 - 109.185.255.255<br />netname:	BG-IBGC-20081010<br />descr:	Eurocom Cable Management Bulgaria LtdCableTEL AD Bulgaria Address Space 2008<br />ns1:	ns2.copapjid.ru<br />ns2:	ns5.copapjid.ru<br />ns3:	ns3.copapjid.ru<br />ns4:	ns4.copapjid.ru<br />ns5:	ns6.copapjid.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://64.85.233.8/index.htm.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9299745</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Dofoil.R.403]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9299745</guid>
			<pubDate>2013-01-31T21:00:18+01:00</pubDate>
			<description><![CDATA[id:	9299745<br />first:	1359662418<br />last:	0<br />md5:	472c51ab55aaeac6e1b7cbfebe49aeda<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=472c51ab55aaeac6e1b7cbfebe49aeda<br />vt_score:	23/43 (53.5%)<br />scanner:	AntiVir<br />virusname:	TR/Dldr.Dofoil.R.403<br />url:	http://64.85.233.8/index.htm.exe<br />recent:	up<br />response:	alive<br />ip:	64.85.233.8<br />as:	AS22759<br />review:	64.85.233.8<br />domain:	64.85.233.8<br />country:	US<br />source:	ARIN<br />email:	wavecable@wavecable.com<br />inetnum:	64.85.224.0 - 64.85.255.255<br />netname:	WAVE-ASTOUND-1<br />descr:	Private Residence Concord CA 94520<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vacrajak.ru/calc.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9297670</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9297670</guid>
			<pubDate>2013-01-31T19:43:01+01:00</pubDate>
			<description><![CDATA[id:	9297670<br />first:	1359657781<br />last:	0<br />md5:	901fe4766ecd49c718869b621bf4aa08<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=901fe4766ecd49c718869b621bf4aa08<br />vt_score:	12/46 (26.1%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://vacrajak.ru/calc.exe<br />recent:	up<br />response:	alive<br />ip:	76.126.100.34<br />as:	AS33651<br />review:	37.229.47.218<br />domain:	vacrajak.ru<br />country:	UA<br />source:	RIPE<br />email:	abuse@colocall.net<br />inetnum:	76.126.0.0 - 76.126.255.255<br />netname:	KYIVSTAR-NET-15<br />descr:	Kyivstar GSMUkrainian mobile phone operatorKyivstar GSM, Kiev, Ukraine<br />ns1:	ns6.vacrajak.ru<br />ns2:	ns5.vacrajak.ru<br />ns3:	ns4.vacrajak.ru<br />ns4:	ns1.vacrajak.ru<br />ns5:	ns2.vacrajak.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vybakcov.ru/links/1.php?ayq=33:2v:1h:2w:1m&mntt=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&eghf=1i&uodoskx=padzflh&knrezehi=vkyuabri]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9297669</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Tepfer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9297669</guid>
			<pubDate>2013-01-31T19:43:01+01:00</pubDate>
			<description><![CDATA[id:	9297669<br />first:	1359657781<br />last:	0<br />md5:	fee2e9671fdf861958596e5197ad8fba<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fee2e9671fdf861958596e5197ad8fba<br />vt_score:	8/36 (22.2%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Tepfer<br />url:	http://vybakcov.ru/links/1.php?ayq=33:2v:1h:2w:1m&mntt=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&eghf=1i&uodoskx=padzflh&knrezehi=vkyuabri<br />recent:	up<br />response:	alive<br />ip:	198.23.248.138<br />as:	AS36352<br />review:	198.23.248.138<br />domain:	vybakcov.ru<br />country:	US<br />source:	ARIN<br />email:	abuse@colocrossing.com<br />inetnum:	198.23.128.0 - 198.23.255.255<br />netname:	CC-10<br />descr:	ColoCrossing VGS-9 8469 Sheridan Drive ATTN Williamsville NY 14221<br />ns1:	ns4.vybakcov.ru<br />ns2:	ns1.vybakcov.ru<br />ns3:	ns3.vybakcov.ru<br />ns4:	ns5.vybakcov.ru<br />ns5:	ns2.vybakcov.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://shayankarimi.com/media/nnsdiew.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9297174</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Tepfer]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9297174</guid>
			<pubDate>2013-01-31T18:40:02+01:00</pubDate>
			<description><![CDATA[id:	9297174<br />first:	1359654002<br />last:	0<br />md5:	61b0c810ee8ba4b5ad1d98f65fb8f907<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=61b0c810ee8ba4b5ad1d98f65fb8f907<br />vt_score:	12/45 (26.7%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Tepfer<br />url:	http://shayankarimi.com/media/nnsdiew.exe<br />recent:	up<br />response:	alive<br />ip:	174.133.83.82<br />as:	AS36420, AS30315, AS13749, AS21844<br />review:	174.133.83.82<br />domain:	shayankarimi.com<br />country:	US<br />source:	ARIN<br />email:	abuse@theplanet.com<br />inetnum:	174.132.0.0 - 174.133.255.255<br />netname:	NETBLK-THEPLANET-BLK-15<br />descr:	ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002<br />ns1:	ns5.mehravaran.net<br />ns2:	ns6.mehravaran.net<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://vacrajak.ru/madload.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9297173</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9297173</guid>
			<pubDate>2013-01-31T18:40:02+01:00</pubDate>
			<description><![CDATA[id:	9297173<br />first:	1359654002<br />last:	0<br />md5:	59ca9e956c004fe63ded1a1489741d1b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=59ca9e956c004fe63ded1a1489741d1b<br />vt_score:	13/36 (36.1%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://vacrajak.ru/madload.exe<br />recent:	up<br />response:	alive<br />ip:	77.122.164.175<br />as:	AS25229<br />review:	5.105.62.233<br />domain:	vacrajak.ru<br />country:	UA<br />source:	RIPE<br />email:	abuse@volia.net<br />inetnum:	77.122.128.0 - 77.122.207.255<br />netname:	UA-CDS-UA-RIPE-20120628<br />descr:	Cifrovye Dispetcherskie SistemyUA-CDS-UA-RIPE-20120628<br />ns1:	ns1.vacrajak.ru<br />ns2:	ns5.vacrajak.ru<br />ns3:	ns2.vacrajak.ru<br />ns4:	ns6.vacrajak.ru<br />ns5:	ns3.vacrajak.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.185.227/nn.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9295218</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/VB.Inject.JD.515]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9295218</guid>
			<pubDate>2013-01-31T15:40:11+01:00</pubDate>
			<description><![CDATA[id:	9295218<br />first:	1359643211<br />last:	0<br />md5:	24260d5f3d75cc9491afa794102627f6<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=24260d5f3d75cc9491afa794102627f6<br />vt_score:	26/46 (56.5%)<br />scanner:	AntiVir<br />virusname:	TR/VB.Inject.JD.515<br />url:	http://74.208.185.227/nn.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.185.227<br />as:	AS8560<br />review:	74.208.185.227<br />domain:	74.208.185.227<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://atlantacatering.us/images.php?image=IMG0540255.JPG]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9295217</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicion: unknown virus]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9295217</guid>
			<pubDate>2013-01-31T15:40:11+01:00</pubDate>
			<description><![CDATA[id:	9295217<br />first:	1359643211<br />last:	0<br />md5:	0cf44976e8f749941cfcef8be0239e54<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=0cf44976e8f749941cfcef8be0239e54<br />vt_score:	10/46 (21.7%)<br />scanner:	AVG<br />virusname:	Suspicion: unknown virus<br />url:	http://atlantacatering.us/images.php?image=IMG0540255.JPG<br />recent:	up<br />response:	alive<br />ip:	74.208.185.227<br />as:	AS8560<br />review:	74.208.185.227<br />domain:	atlantacatering.us<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	ns51.1and1.com<br />ns2:	ns52.1and1.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.185.227/5.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9294494</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Injector.YMS!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9294494</guid>
			<pubDate>2013-01-31T14:00:14+01:00</pubDate>
			<description><![CDATA[id:	9294494<br />first:	1359637214<br />last:	0<br />md5:	78f94cab5598dc7bbbfb97b1722928aa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=78f94cab5598dc7bbbfb97b1722928aa<br />vt_score:	4/36 (11.1%)<br />scanner:	Fortinet<br />virusname:	W32/Injector.YMS!tr<br />url:	http://74.208.185.227/5.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.185.227<br />as:	AS8560<br />review:	74.208.185.227<br />domain:	74.208.185.227<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fr-dl.uni.me/i_FR]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9293693</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Banload-1361]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9293693</guid>
			<pubDate>2013-01-31T12:50:06+01:00</pubDate>
			<description><![CDATA[id:	9293693<br />first:	1359633006<br />last:	0<br />md5:	75fed216c551543b8ba2e49f0d5b6468<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=75fed216c551543b8ba2e49f0d5b6468<br />vt_score:	7/36 (19.4%)<br />scanner:	clamav<br />virusname:	Trojan.Banload-1361<br />url:	http://fr-dl.uni.me/i_FR<br />recent:	up<br />response:	alive<br />ip:	199.231.227.149<br />as:	AS3800<br />review:	199.231.227.149<br />domain:	uni.me<br />country:	US<br />source:	ARIN<br />email:	network.tech@ionity.com<br />inetnum:	199.231.224.0 - 199.231.227.255<br />netname:	ION-DAL01<br />descr:	Ionity Corporation IC-47 13505 S. Mur-Len Suite 105-202 Olathe KS 66062<br />ns1:	ns1.dns-domainserver.com<br />ns2:	ns2.dns-domainserver.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://46.38.63.119/bck/iexplored.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9292327</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[(Suspicious) - DNAScan]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9292327</guid>
			<pubDate>2013-01-31T10:00:18+01:00</pubDate>
			<description><![CDATA[id:	9292327<br />first:	1359622818<br />last:	0<br />md5:	d00e455b65975ab903d7ecfcaecb8c3f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=d00e455b65975ab903d7ecfcaecb8c3f<br />vt_score:	7/46 (15.2%)<br />scanner:	CAT_QuickHeal<br />virusname:	(Suspicious) - DNAScan<br />url:	http://46.38.63.119/bck/iexplored.exe<br />recent:	up<br />response:	alive<br />ip:	46.38.63.119<br />as:	AS52201<br />review:	46.38.63.119<br />domain:	46.38.63.119<br />country:	RU<br />source:	RIPE<br />email:	alexander.kondrat@tel.ru<br />inetnum:	46.38.56.0 - 46.38.63.255<br />netname:	TCTEL<br />descr:	TC TEL hostingTCTEL-NET<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://soduvnec.ru/shem001.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9288238</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9288238</guid>
			<pubDate>2013-01-31T02:01:21+01:00</pubDate>
			<description><![CDATA[id:	9288238<br />first:	1359594081<br />last:	0<br />md5:	f7de8002f5ed377afe891fd03c41483b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=f7de8002f5ed377afe891fd03c41483b<br />vt_score:	12/36 (33.3%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://soduvnec.ru/shem001.exe<br />recent:	up<br />response:	alive<br />ip:	195.222.83.66<br />as:	AS12358<br />review:	66.168.236.219<br />domain:	soduvnec.ru<br />country:	US<br />source:	ARIN<br />email:	abuse@charter.net<br />inetnum:	195.222.64.0 - 195.222.87.255<br />netname:	ALCBN-66-168-232-0-21<br />descr:	12405 Powerscourt Dr. Use as many Customer Address lines as needed to specify St. Louis MO 63122<br />ns1:	ns5.soduvnec.ru<br />ns2:	ns2.soduvnec.ru<br />ns3:	ns4.soduvnec.ru<br />ns4:	ns6.soduvnec.ru<br />ns5:	ns3.soduvnec.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://img.pa-bandung.go.id/inc/1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9288026</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Yakes.B!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9288026</guid>
			<pubDate>2013-01-31T01:40:01+01:00</pubDate>
			<description><![CDATA[id:	9288026<br />first:	1359592801<br />last:	0<br />md5:	cb8c53a0d3f68100674cdd0dfd0fa122<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=cb8c53a0d3f68100674cdd0dfd0fa122<br />vt_score:	5/46 (10.9%)<br />scanner:	Fortinet<br />virusname:	W32/Yakes.B!tr<br />url:	http://img.pa-bandung.go.id/inc/1.exe<br />recent:	up<br />response:	alive<br />ip:	207.45.187.10<br />as:	AS36444, AS2828<br />review:	207.45.187.10<br />domain:	go.id<br />country:	US<br />source:	ARIN<br />email:	abuse@acenet-inc.net<br />inetnum:	207.45.176.0 - 207.45.191.255<br />netname:	ACENETMI<br />descr:	ACENET, INC. ACENE 22005 Outer Drive Dearborn MI 48124<br />ns1:	e.dns.id<br />ns2:	d.dns.id<br />ns3:	b.dns.id<br />ns4:	f.dns.id<br />ns5:	a.dns.id<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://img.pa-bandung.go.id/inc/2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9288025</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win32:Rootkit-gen [Rtk]]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9288025</guid>
			<pubDate>2013-01-31T01:40:01+01:00</pubDate>
			<description><![CDATA[id:	9288025<br />first:	1359592801<br />last:	0<br />md5:	9ff48a1523a0e0e5f9d7f355e7058e7e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9ff48a1523a0e0e5f9d7f355e7058e7e<br />vt_score:	16/36 (44.4%)<br />scanner:	Avast<br />virusname:	Win32:Rootkit-gen [Rtk]<br />url:	http://img.pa-bandung.go.id/inc/2.exe<br />recent:	up<br />response:	alive<br />ip:	207.45.187.10<br />as:	AS36444, AS2828<br />review:	207.45.187.10<br />domain:	go.id<br />country:	US<br />source:	ARIN<br />email:	abuse@acenet-inc.net<br />inetnum:	207.45.176.0 - 207.45.191.255<br />netname:	ACENETMI<br />descr:	ACENET, INC. ACENE 22005 Outer Drive Dearborn MI 48124<br />ns1:	e.dns.id<br />ns2:	d.dns.id<br />ns3:	b.dns.id<br />ns4:	f.dns.id<br />ns5:	a.dns.id<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://74.208.185.227/ev.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9286225</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Injector.YMS!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9286225</guid>
			<pubDate>2013-01-30T22:40:05+01:00</pubDate>
			<description><![CDATA[id:	9286225<br />first:	1359582005<br />last:	0<br />md5:	669afcf28dbc3097ccd3f35b70df243f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=669afcf28dbc3097ccd3f35b70df243f<br />vt_score:	3/35 (8.6%)<br />scanner:	Fortinet<br />virusname:	W32/Injector.YMS!tr<br />url:	http://74.208.185.227/ev.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.185.227<br />as:	AS8560<br />review:	74.208.185.227<br />domain:	74.208.185.227<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cateringatlanta.org/images.php?image=IMG0540255.JPG]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9286224</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicion: unknown virus]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9286224</guid>
			<pubDate>2013-01-30T22:40:05+01:00</pubDate>
			<description><![CDATA[id:	9286224<br />first:	1359582005<br />last:	0<br />md5:	36638585a0844fd7bbb0ef08436aa499<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=36638585a0844fd7bbb0ef08436aa499<br />vt_score:	5/36 (13.9%)<br />scanner:	AVG<br />virusname:	Suspicion: unknown virus<br />url:	http://cateringatlanta.org/images.php?image=IMG0540255.JPG<br />recent:	up<br />response:	alive<br />ip:	74.208.185.227<br />as:	AS8560<br />review:	74.208.185.227<br />domain:	cateringatlanta.org<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	ns51.1and1.com<br />ns2:	ns52.1and1.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cateringatlanta.org/b.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9286223</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9286223</guid>
			<pubDate>2013-01-30T22:40:05+01:00</pubDate>
			<description><![CDATA[id:	9286223<br />first:	1359582005<br />last:	0<br />md5:	e72381515f60d9a50682daf717c6c096<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e72381515f60d9a50682daf717c6c096<br />vt_score:	3/36 (8.3%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://cateringatlanta.org/b.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.185.227<br />as:	AS8560<br />review:	74.208.185.227<br />domain:	cateringatlanta.org<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	ns51.1and1.com<br />ns2:	ns52.1and1.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.fancy-dress-party.co.uk/b.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9278883</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9278883</guid>
			<pubDate>2013-01-30T13:40:14+01:00</pubDate>
			<description><![CDATA[id:	9278883<br />first:	1359549614<br />last:	0<br />md5:	212ed115e3880dd24329894e9829547b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=212ed115e3880dd24329894e9829547b<br />vt_score:	3/46 (6.5%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://www.fancy-dress-party.co.uk/b.exe<br />recent:	up<br />response:	alive<br />ip:	212.227.158.179<br />as:	AS8560<br />review:	212.227.158.179<br />domain:	fancy-dress-party.co.uk<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	212.227.144.0 - 212.227.159.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AGNCC#1999110113<br />ns1:	ns67.1and1.co.uk<br />ns2:	ns68.1and1.co.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.fancy-dress-party.co.uk/IMG0540255-JPG.scr]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9278882</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9278882</guid>
			<pubDate>2013-01-30T13:40:14+01:00</pubDate>
			<description><![CDATA[id:	9278882<br />first:	1359549614<br />last:	0<br />md5:	46395459a99bdaa95d69761f5d131ca8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=46395459a99bdaa95d69761f5d131ca8<br />vt_score:	2/36 (5.6%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://www.fancy-dress-party.co.uk/IMG0540255-JPG.scr<br />recent:	up<br />response:	alive<br />ip:	212.227.158.179<br />as:	AS8560<br />review:	212.227.158.179<br />domain:	fancy-dress-party.co.uk<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	212.227.144.0 - 212.227.159.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AGNCC#1999110113<br />ns1:	ns67.1and1.co.uk<br />ns2:	ns68.1and1.co.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.fancy-dress-party.co.uk/s.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9278881</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9278881</guid>
			<pubDate>2013-01-30T13:40:14+01:00</pubDate>
			<description><![CDATA[id:	9278881<br />first:	1359549614<br />last:	0<br />md5:	15349a4988b35130b2e7ee711c2da87a<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=15349a4988b35130b2e7ee711c2da87a<br />vt_score:	2/36 (5.6%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://www.fancy-dress-party.co.uk/s.exe<br />recent:	up<br />response:	alive<br />ip:	212.227.158.179<br />as:	AS8560<br />review:	212.227.158.179<br />domain:	fancy-dress-party.co.uk<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	212.227.144.0 - 212.227.159.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AGNCC#1999110113<br />ns1:	ns67.1and1.co.uk<br />ns2:	ns68.1and1.co.uk<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://dawkins.sexyi.am/xxxx.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9278801</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Lyposit]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9278801</guid>
			<pubDate>2013-01-30T09:43:11+01:00</pubDate>
			<description><![CDATA[id:	9278801<br />first:	1359535391<br />last:	0<br />md5:	357a498235180ff5edadff2cfc645328<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=357a498235180ff5edadff2cfc645328<br />vt_score:	33/46 (71.7%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Lyposit<br />url:	http://dawkins.sexyi.am/xxxx.exe<br />recent:	up<br />response:	alive<br />ip:	31.170.166.183<br />as:	AS47583<br />review:	31.170.166.183<br />domain:	sexyi.am<br />country:	US<br />source:	RIPE<br />email:	abuse@main-hosting.com<br />inetnum:	31.170.166.0 - 31.170.167.255<br />netname:	MAIN-HOSTING-SERVERS<br />descr:	Main Hosting ServersMAIN HOSTING US<br />ns1:	ns4.1freehosting.com<br />ns2:	ns1.1freehosting.com<br />ns3:	ns2.1freehosting.com<br />ns4:	ns3.1freehosting.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://aggeymin.ru/links/1.php?ayq=33:2v:1h:2w:1m&mntt=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&eghf=1i&uodoskx=padzflh&knrezehi=vkyuabri]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9274083</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Downloader.Gen8]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9274083</guid>
			<pubDate>2013-01-30T01:40:08+01:00</pubDate>
			<description><![CDATA[id:	9274083<br />first:	1359506408<br />last:	0<br />md5:	aced22676098abac610167a543bf5369<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=aced22676098abac610167a543bf5369<br />vt_score:	7/46 (15.2%)<br />scanner:	AntiVir<br />virusname:	TR/Downloader.Gen8<br />url:	http://aggeymin.ru/links/1.php?ayq=33:2v:1h:2w:1m&mntt=1j:1n:1m:1l:1m:2w:31:1j:1m:1g&eghf=1i&uodoskx=padzflh&knrezehi=vkyuabri<br />recent:	up<br />response:	alive<br />ip:	82.221.96.225<br />as:	AS30818<br />review:	82.221.96.225<br />domain:	aggeymin.ru<br />country:	IS<br />source:	RIPE<br />email:	abuse@skyrr.is<br />inetnum:	82.221.0.0 - 82.221.255.255<br />netname:	IS-SKYRR-20031211<br />descr:	PROVIDER Local RegistrySkyrr hfIS-SKYRR-NET<br />ns1:	ns1.aggeymin.ru<br />ns2:	ns4.aggeymin.ru<br />ns3:	ns5.aggeymin.ru<br />ns4:	ns6.aggeymin.ru<br />ns5:	ns3.aggeymin.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://soduvnec.ru/madload.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9273223</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dropper.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9273223</guid>
			<pubDate>2013-01-30T00:40:25+01:00</pubDate>
			<description><![CDATA[id:	9273223<br />first:	1359502825<br />last:	0<br />md5:	df1c359c9e1e578a0c924cc3718f4de2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=df1c359c9e1e578a0c924cc3718f4de2<br />vt_score:	13/46 (28.3%)<br />scanner:	avira<br />virusname:	TR/Dropper.Gen<br />url:	http://soduvnec.ru/madload.exe<br />recent:	up<br />response:	alive<br />ip:	31.223.211.119<br />as:	AS21107<br />review:	89.176.152.165<br />domain:	soduvnec.ru<br />country:	CZ<br />source:	RIPE<br />email:	abuse@mistral.cz<br />inetnum:	31.223.208.0 - 31.223.223.255<br />netname:	UPC-BRNO-XI<br />descr:	UPC Ceska republika, a.s.<br />ns1:	ns1.soduvnec.ru<br />ns2:	ns4.soduvnec.ru<br />ns3:	ns2.soduvnec.ru<br />ns4:	ns6.soduvnec.ru<br />ns5:	ns5.soduvnec.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ziarul-obiectiv.ro/idfsuwer.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9273222</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Crypt.XPACK.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9273222</guid>
			<pubDate>2013-01-30T00:40:25+01:00</pubDate>
			<description><![CDATA[id:	9273222<br />first:	1359502825<br />last:	0<br />md5:	e7baa39d480a2859ca6257a09fce23ab<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=e7baa39d480a2859ca6257a09fce23ab<br />vt_score:	11/46 (23.9%)<br />scanner:	avira<br />virusname:	TR/Crypt.XPACK.Gen<br />url:	http://ziarul-obiectiv.ro/idfsuwer.exe<br />recent:	up<br />response:	alive<br />ip:	89.42.217.243<br />as:	AS5606<br />review:	89.42.217.243<br />domain:	ziarul-obiectiv.ro<br />country:	ro<br />source:	RIPE<br />email:	abuse@romarg.com<br />inetnum:	89.42.216.0 - 89.42.223.255<br />netname:	SC-ROMARG-SRL<br />descr:	ROMARG SRL-----------------------------ROMARG | The Hosting Provider-----------------------------Str. Transilvaniei, nr. 28Brasov Brasov Romania<br />ns1:	ns3.whmpanels.ro<br />ns2:	ns2.whmpanels.ro<br />ns3:	ns1.whmpanels.ro<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://img.pa-bandung.go.id/inc/22.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9272187</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Win.Trojan.5600]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9272187</guid>
			<pubDate>2013-01-29T23:40:13+01:00</pubDate>
			<description><![CDATA[id:	9272187<br />first:	1359499213<br />last:	0<br />md5:	88cf8e9c36ea8fcb3eb9c1fb76f87cdc<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=88cf8e9c36ea8fcb3eb9c1fb76f87cdc<br />vt_score:	21/36 (58.3%)<br />scanner:	clamav<br />virusname:	Win.Trojan.5600<br />url:	http://img.pa-bandung.go.id/inc/22.exe<br />recent:	up<br />response:	alive<br />ip:	207.45.187.10<br />as:	AS36444, AS2828<br />review:	207.45.187.10<br />domain:	go.id<br />country:	US<br />source:	ARIN<br />email:	abuse@acenet-inc.net<br />inetnum:	207.45.176.0 - 207.45.191.255<br />netname:	ACENETMI<br />descr:	ACENET, INC. ACENE 22005 Outer Drive Dearborn MI 48124<br />ns1:	b.dns.id<br />ns2:	f.dns.id<br />ns3:	d.dns.id<br />ns4:	g.dns.id<br />ns5:	c.dns.id<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://img.pa-bandung.go.id/inc/33.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9272186</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BackDoor.Generic16.BDRE]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9272186</guid>
			<pubDate>2013-01-29T23:40:13+01:00</pubDate>
			<description><![CDATA[id:	9272186<br />first:	1359499213<br />last:	0<br />md5:	05a698a5f1c865619538fdc4e6e53852<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=05a698a5f1c865619538fdc4e6e53852<br />vt_score:	16/36 (44.4%)<br />scanner:	AVG<br />virusname:	BackDoor.Generic16.BDRE<br />url:	http://img.pa-bandung.go.id/inc/33.exe<br />recent:	up<br />response:	alive<br />ip:	207.45.187.10<br />as:	AS36444, AS2828<br />review:	207.45.187.10<br />domain:	go.id<br />country:	US<br />source:	ARIN<br />email:	abuse@acenet-inc.net<br />inetnum:	207.45.176.0 - 207.45.191.255<br />netname:	ACENETMI<br />descr:	ACENET, INC. ACENE 22005 Outer Drive Dearborn MI 48124<br />ns1:	b.dns.id<br />ns2:	f.dns.id<br />ns3:	d.dns.id<br />ns4:	g.dns.id<br />ns5:	c.dns.id<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://205.196.120.91/b5vf53qq95sg/ekl6ol34qwym3km/s.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9265405</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9265405</guid>
			<pubDate>2013-01-29T16:40:08+01:00</pubDate>
			<description><![CDATA[id:	9265405<br />first:	1359474008<br />last:	0<br />md5:	840c55a041c7f5abbf26925d72144060<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=840c55a041c7f5abbf26925d72144060<br />vt_score:	6/45 (13.3%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://205.196.120.91/b5vf53qq95sg/ekl6ol34qwym3km/s.exe<br />recent:	up<br />response:	alive<br />ip:	205.196.120.91<br />as:	AS174<br />review:	205.196.120.91<br />domain:	205.196.120.91<br />country:	US<br />source:	ARIN<br />email:	derek@linkrightllc.com<br />inetnum:	205.196.120.0 - 205.196.123.255<br />netname:	LINKRIGHT-HOU-1<br />descr:	Link Right, LLC LINKR-7 21175 State Highway 249 Suite 199 Houston TX 77070<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://myfantasyroom.gr/4Uam7t.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9264258</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Clicker.LOL!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9264258</guid>
			<pubDate>2013-01-29T16:00:06+01:00</pubDate>
			<description><![CDATA[id:	9264258<br />first:	1359471606<br />last:	0<br />md5:	b993c2f150e23e83fe73412a465146a2<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b993c2f150e23e83fe73412a465146a2<br />vt_score:	6/46 (13%)<br />scanner:	Fortinet<br />virusname:	W32/Clicker.LOL!tr<br />url:	http://myfantasyroom.gr/4Uam7t.exe<br />recent:	up<br />response:	alive<br />ip:	209.172.50.105<br />as:	AS32613<br />review:	209.172.50.105<br />domain:	myfantasyroom.gr<br />country:	CA<br />source:	ARIN<br />email:	abuse@noc.privatedns.com<br />inetnum:	209.172.32.0 - 209.172.63.255<br />netname:	IWEB-BLK-01<br />descr:	iWeb Technologies Inc. GIT-20 20, place du Commerce Montreal QC H3E-1Z6<br />ns1:	ns305.superweb.gr<br />ns2:	ns304.superweb.gr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://213.251.187.162/~kift/gbss.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9264141</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Spy.Banker.1952256.2]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9264141</guid>
			<pubDate>2013-01-29T15:40:03+01:00</pubDate>
			<description><![CDATA[id:	9264141<br />first:	1359470403<br />last:	0<br />md5:	ab87c5a22a237f25038cd3eb2f503976<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=ab87c5a22a237f25038cd3eb2f503976<br />vt_score:	14/46 (30.4%)<br />scanner:	AntiVir<br />virusname:	TR/Spy.Banker.1952256.2<br />url:	http://213.251.187.162/~kift/gbss.jpg<br />recent:	up<br />response:	alive<br />ip:	213.251.187.162<br />as:	AS16276<br />review:	213.251.187.162<br />domain:	213.251.187.162<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	213.251.184.0 - 213.251.187.255<br />netname:	OVH<br />descr:	OVH SASDedicated Servers (2006)http<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://213.251.187.162/~kift/neo.jpg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9264140</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PCK/UltraProt]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9264140</guid>
			<pubDate>2013-01-29T15:40:03+01:00</pubDate>
			<description><![CDATA[id:	9264140<br />first:	1359470403<br />last:	0<br />md5:	fe446c3364c6708c3301a97a08bc9356<br />virustotal:	<br />vt_score:	18/46 (39.1%)<br />scanner:	AntiVir<br />virusname:	PCK/UltraProt<br />url:	http://213.251.187.162/~kift/neo.jpg<br />recent:	up<br />response:	alive<br />ip:	213.251.187.162<br />as:	AS16276<br />review:	213.251.187.162<br />domain:	213.251.187.162<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	213.251.184.0 - 213.251.187.255<br />netname:	OVH<br />descr:	OVH SASDedicated Servers (2006)http<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://213.251.187.162/~kift/Comprovante_Do_Deposito.cpl]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9263913</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Delphi.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9263913</guid>
			<pubDate>2013-01-29T14:50:15+01:00</pubDate>
			<description><![CDATA[id:	9263913<br />first:	1359467415<br />last:	0<br />md5:	9b7428713d01d3bdecf2dc4a127745fa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9b7428713d01d3bdecf2dc4a127745fa<br />vt_score:	20/45 (44.4%)<br />scanner:	avira<br />virusname:	TR/Dldr.Delphi.Gen<br />url:	http://213.251.187.162/~kift/Comprovante_Do_Deposito.cpl<br />recent:	up<br />response:	alive<br />ip:	213.251.187.162<br />as:	AS16276<br />review:	213.251.187.162<br />domain:	213.251.187.162<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	213.251.184.0 - 213.251.187.255<br />netname:	OVH<br />descr:	OVH SASDedicated Servers (2006)http<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://213.251.187.162/~kift/Instalador_Modulo_de_seguranca_BB.cpl]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9263912</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/Dldr.Delphi.Gen]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9263912</guid>
			<pubDate>2013-01-29T14:50:14+01:00</pubDate>
			<description><![CDATA[id:	9263912<br />first:	1359467414<br />last:	0<br />md5:	9b7428713d01d3bdecf2dc4a127745fa<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9b7428713d01d3bdecf2dc4a127745fa<br />vt_score:	39/46 (84.8%)<br />scanner:	avira<br />virusname:	TR/Dldr.Delphi.Gen<br />url:	http://213.251.187.162/~kift/Instalador_Modulo_de_seguranca_BB.cpl<br />recent:	up<br />response:	alive<br />ip:	213.251.187.162<br />as:	AS16276<br />review:	213.251.187.162<br />domain:	213.251.187.162<br />country:	FR<br />source:	RIPE<br />email:	abuse@ovh.net<br />inetnum:	213.251.184.0 - 213.251.187.255<br />netname:	OVH<br />descr:	OVH SASDedicated Servers (2006)http<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://royjamesinsurance.com/images/TcpAdaptorService_b2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9260794</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan.Win32.Locotout]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9260794</guid>
			<pubDate>2013-01-29T11:00:12+01:00</pubDate>
			<description><![CDATA[id:	9260794<br />first:	1359453612<br />last:	0<br />md5:	969c3997f40eb5fe6c4c0fb65dfabaef<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=969c3997f40eb5fe6c4c0fb65dfabaef<br />vt_score:	4/45 (8.9%)<br />scanner:	Ikarus<br />virusname:	Trojan.Win32.Locotout<br />url:	http://royjamesinsurance.com/images/TcpAdaptorService_b2.exe<br />recent:	up<br />response:	alive<br />ip:	66.59.64.114<br />as:	AS11551<br />review:	66.59.64.114<br />domain:	royjamesinsurance.com<br />country:	US<br />source:	ARIN<br />email:	abuse@frontline.net<br />inetnum:	66.59.64.0 - 66.59.95.255<br />netname:	SINEP-BLOCK-2<br />descr:	Sinep Corporation SINEP-1 PO Box 98 Orangeburg NY 10962<br />ns1:	dns02.frontline.net<br />ns2:	dns03.frontline.net<br />ns3:	dns01.frontline.net<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://84.32.116.143/mag]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9257125</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9257125</guid>
			<pubDate>2013-01-29T01:40:04+01:00</pubDate>
			<description><![CDATA[id:	9257125<br />first:	1359420004<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://84.32.116.143/mag<br />recent:	up<br />response:	alive<br />ip:	84.32.116.143<br />as:	AS33922<br />review:	84.32.116.143<br />domain:	84.32.116.143<br />country:	LT<br />source:	RIPE<br />email:	admin@ntt.lt<br />inetnum:	84.32.116.0 - 84.32.119.255<br />netname:	NTT_DATA_ROVENTA_NET<br />descr:	NTT DATA Service for Roventa partner<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://84.32.116.144/mag]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9257124</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[BackDoor.Generic16.BDIP]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9257124</guid>
			<pubDate>2013-01-29T01:40:04+01:00</pubDate>
			<description><![CDATA[id:	9257124<br />first:	1359420004<br />last:	0<br />md5:	0bf2101859e0d4e58383850f7d4149a7<br />virustotal:	<br />vt_score:	12/45 (26.7%)<br />scanner:	AVG<br />virusname:	BackDoor.Generic16.BDIP<br />url:	http://84.32.116.144/mag<br />recent:	up<br />response:	alive<br />ip:	84.32.116.144<br />as:	AS33922<br />review:	84.32.116.144<br />domain:	84.32.116.144<br />country:	LT<br />source:	RIPE<br />email:	admin@ntt.lt<br />inetnum:	84.32.116.0 - 84.32.119.255<br />netname:	NTT_DATA_ROVENTA_NET<br />descr:	NTT DATA Service for Roventa partner<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://abacaboffice.com/de.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9254858</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Crypt_s.AFQ]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9254858</guid>
			<pubDate>2013-01-28T23:40:18+01:00</pubDate>
			<description><![CDATA[id:	9254858<br />first:	1359412818<br />last:	0<br />md5:	309884d6d51f4f9c6c48cb95d5538db1<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=309884d6d51f4f9c6c48cb95d5538db1<br />vt_score:	12/36 (33.3%)<br />scanner:	AVG<br />virusname:	Crypt_s.AFQ<br />url:	http://abacaboffice.com/de.exe<br />recent:	up<br />response:	alive<br />ip:	203.170.82.97<br />as:	AS38719<br />review:	203.170.82.97<br />domain:	abacaboffice.com<br />country:	AU<br />source:	APNIC<br />email:	admin@syra.com.au<br />inetnum:	203.170.80.0 - 203.170.87.255<br />netname:	Syra Networks<br />descr:	Internet Services NetworkGlobal Telecommunications<br />ns1:	ns4.syra.net.au<br />ns2:	ns5.syra.net.au<br />ns3:	ns6.syra.net.au<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://help-mastera.ru/wp-content/themes/delicate/cache/VideoXXXKarinaB.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9244278</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicious File]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9244278</guid>
			<pubDate>2013-01-28T12:40:03+01:00</pubDate>
			<description><![CDATA[id:	9244278<br />first:	1359373203<br />last:	0<br />md5:	eb9d8f7574b70c208ac285e9012c7f27<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=eb9d8f7574b70c208ac285e9012c7f27<br />vt_score:	10/36 (27.8%)<br />scanner:	eSafe<br />virusname:	Suspicious File<br />url:	http://help-mastera.ru/wp-content/themes/delicate/cache/VideoXXXKarinaB.exe<br />recent:	up<br />response:	alive<br />ip:	94.75.212.209<br />as:	AS16265<br />review:	94.75.212.209<br />domain:	help-mastera.ru<br />country:	NL<br />source:	RIPE<br />email:	abuse@leaseweb.com<br />inetnum:	94.75.192.0 - 94.75.255.255<br />netname:	NL-LEASEWEB-20080724<br />descr:	LeaseWeb B.V.<br />ns1:	ns2.m-hoster-4.ru<br />ns2:	ns1.m-hoster-4.ru<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://205.196.121.197/98zy56a6qzlg/kf2lhk53bpfem63/go.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9243312</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[W32/Zbot.ANQ!tr]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9243312</guid>
			<pubDate>2013-01-28T10:50:04+01:00</pubDate>
			<description><![CDATA[id:	9243312<br />first:	1359366604<br />last:	0<br />md5:	5f0a638f69bb9b5b0d7010d2e1a3bf1e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5f0a638f69bb9b5b0d7010d2e1a3bf1e<br />vt_score:	2/36 (5.6%)<br />scanner:	Fortinet<br />virusname:	W32/Zbot.ANQ!tr<br />url:	http://205.196.121.197/98zy56a6qzlg/kf2lhk53bpfem63/go.exe<br />recent:	up<br />response:	alive<br />ip:	205.196.121.197<br />as:	AS174<br />review:	205.196.121.197<br />domain:	205.196.121.197<br />country:	US<br />source:	ARIN<br />email:	derek@linkrightllc.com<br />inetnum:	205.196.120.0 - 205.196.123.255<br />netname:	LINKRIGHT-HOU-1<br />descr:	Link Right, LLC LINKR-7 21175 State Highway 249 Suite 199 Houston TX 77070<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://205.196.123.64/ky3v1afdsftg/cnxj7rnqzz6ljhk/go.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9226985</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_html]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9226985</guid>
			<pubDate>2013-01-27T13:00:08+01:00</pubDate>
			<description><![CDATA[id:	9226985<br />first:	1359288008<br />last:	0<br />md5:	0c959e946329574b1aa256d773a1164d<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b19f4261eb8ac80b3fa30545da134ef8<br />vt_score:	10/46 (21.7%)<br />scanner:	undef<br />virusname:	unknown_html<br />url:	http://205.196.123.64/ky3v1afdsftg/cnxj7rnqzz6ljhk/go.exe<br />recent:	up<br />response:	alive<br />ip:	205.196.123.64<br />as:	AS174<br />review:	205.196.123.64<br />domain:	205.196.123.64<br />country:	US<br />source:	ARIN<br />email:	derek@linkrightllc.com<br />inetnum:	205.196.120.0 - 205.196.123.255<br />netname:	LINKRIGHT-HOU-1<br />descr:	Link Right, LLC LINKR-7 21175 State Highway 249 Suite 199 Houston TX 77070<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://205.196.121.6/d1tyzieqk6vg/grtxads9xsopnx2/ff.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9226658</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_html]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9226658</guid>
			<pubDate>2013-01-27T12:40:55+01:00</pubDate>
			<description><![CDATA[id:	9226658<br />first:	1359286855<br />last:	0<br />md5:	281f822210e49ffb1bcd30f48f34812f<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b0bcd05455b7f331ad2e9a6855aad7fe<br />vt_score:	6/36 (16.7%)<br />scanner:	undef<br />virusname:	unknown_html<br />url:	http://205.196.121.6/d1tyzieqk6vg/grtxads9xsopnx2/ff.exe<br />recent:	up<br />response:	alive<br />ip:	205.196.121.6<br />as:	AS174<br />review:	205.196.121.6<br />domain:	205.196.121.6<br />country:	US<br />source:	ARIN<br />email:	derek@linkrightllc.com<br />inetnum:	205.196.120.0 - 205.196.123.255<br />netname:	LINKRIGHT-HOU-1<br />descr:	Link Right, LLC LINKR-7 21175 State Highway 249 Suite 199 Houston TX 77070<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://webcombo.ru/wp-content/uploads/soft.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9224337</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_html]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9224337</guid>
			<pubDate>2013-01-27T09:40:03+01:00</pubDate>
			<description><![CDATA[id:	9224337<br />first:	1359276003<br />last:	0<br />md5:	9769de70ffa1a8eafef224b1ac3e41c8<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=a3cea3392b8b5c8cc664f740494a7321<br />vt_score:	6/35 (17.1%)<br />scanner:	undef<br />virusname:	unknown_html<br />url:	http://webcombo.ru/wp-content/uploads/soft.exe<br />recent:	up<br />response:	alive<br />ip:	5.9.112.221<br />as:	AS24940<br />review:	5.9.112.221<br />domain:	webcombo.ru<br />country:	DE<br />source:	RIPE<br />email:	abuse@hetzner.de<br />inetnum:	5.9.0.0 - 5.9.255.255<br />netname:	DE-HETZNER-20120425<br />descr:	Hetzner Online AG<br />ns1:	ns3.fastvps.ru<br />ns2:	ns4.fastvps.ru<br />ns3:	ns1.fastvps.ru<br />ns4:	ns2.fastvps.ru<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://199.91.152.190/bl7gg3829gdg/cnxj7rnqzz6ljhk/go.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9218721</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_html]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9218721</guid>
			<pubDate>2013-01-27T03:00:03+01:00</pubDate>
			<description><![CDATA[id:	9218721<br />first:	1359252003<br />last:	0<br />md5:	2e05f8e6819ec3376c3569cd6f8fec5c<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=b19f4261eb8ac80b3fa30545da134ef8<br />vt_score:	10/36 (27.8%)<br />scanner:	undef<br />virusname:	unknown_html<br />url:	http://199.91.152.190/bl7gg3829gdg/cnxj7rnqzz6ljhk/go.exe<br />recent:	up<br />response:	alive<br />ip:	199.91.152.190<br />as:	AS46179<br />review:	199.91.152.190<br />domain:	199.91.152.190<br />country:	US<br />source:	ARIN<br />email:	noc@mediafire.com<br />inetnum:	199.91.152.0 - 199.91.159.255<br />netname:	MEDIAFIRE-IP-DFW-01<br />descr:	MediaFire, LLC ML-4 330 Rayford Rd. #157 Spring TX 77386<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://84.32.116.144/gig]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9217893</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9217893</guid>
			<pubDate>2013-01-27T01:40:02+01:00</pubDate>
			<description><![CDATA[id:	9217893<br />first:	1359247202<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://84.32.116.144/gig<br />recent:	up<br />response:	alive<br />ip:	84.32.116.144<br />as:	AS33922<br />review:	84.32.116.144<br />domain:	84.32.116.144<br />country:	LT<br />source:	RIPE<br />email:	admin@ntt.lt<br />inetnum:	84.32.116.0 - 84.32.119.255<br />netname:	NTT_DATA_ROVENTA_NET<br />descr:	NTT DATA Service for Roventa partner<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://84.32.116.144/sma]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9217892</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9217892</guid>
			<pubDate>2013-01-27T01:40:02+01:00</pubDate>
			<description><![CDATA[id:	9217892<br />first:	1359247202<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://84.32.116.144/sma<br />recent:	up<br />response:	alive<br />ip:	84.32.116.144<br />as:	AS33922<br />review:	84.32.116.144<br />domain:	84.32.116.144<br />country:	LT<br />source:	RIPE<br />email:	admin@ntt.lt<br />inetnum:	84.32.116.0 - 84.32.119.255<br />netname:	NTT_DATA_ROVENTA_NET<br />descr:	NTT DATA Service for Roventa partner<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://199.91.154.82/rk5hhtdop6wg/klg5k1gp9v7sdsc/b.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9216476</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_html]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9216476</guid>
			<pubDate>2013-01-26T23:40:06+01:00</pubDate>
			<description><![CDATA[id:	9216476<br />first:	1359240006<br />last:	0<br />md5:	d6d0c73d619af7b8cd3590cc84933592<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=22541fb5cf79c2dd7cbbdc90b82a25d7<br />vt_score:	5/36 (13.9%)<br />scanner:	undef<br />virusname:	unknown_html<br />url:	http://199.91.154.82/rk5hhtdop6wg/klg5k1gp9v7sdsc/b.exe<br />recent:	up<br />response:	alive<br />ip:	199.91.154.82<br />as:	AS46179<br />review:	199.91.154.82<br />domain:	199.91.154.82<br />country:	US<br />source:	ARIN<br />email:	noc@mediafire.com<br />inetnum:	199.91.152.0 - 199.91.159.255<br />netname:	MEDIAFIRE-IP-DFW-01<br />descr:	MediaFire, LLC ML-4 330 Rayford Rd. #157 Spring TX 77386<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://wowrizep.ru/shem001.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9213002</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9213002</guid>
			<pubDate>2013-01-26T19:40:06+01:00</pubDate>
			<description><![CDATA[id:	9213002<br />first:	1359225606<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://wowrizep.ru/shem001.exe<br />recent:	up<br />response:	alive<br />ip:	212.28.83.102<br />as:	AS15836<br />review:	undef<br />domain:	wowrizep.ru<br />country:	MD<br />source:	ARIN<br />email:	cert.mtc@moldtelecom.md<br />inetnum:	212.28.64.0 - 212.28.95.255<br />netname:	MOLDTELECOM-NET<br />descr:	JSC "Moldtelecom" S.A.Chisinau, Moldova<br />ns1:	ns2.wowrizep.ru<br />ns2:	ns1.wowrizep.ru<br />ns3:	ns4.wowrizep.ru<br />ns4:	ns5.wowrizep.ru<br />ns5:	ns6.wowrizep.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://tsunami-rt.com/images/stories/backup.php?ncrnd=EyTKTQgHDc]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9209092</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/StartPage.bim]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9209092</guid>
			<pubDate>2013-01-26T14:40:02+01:00</pubDate>
			<description><![CDATA[id:	9209092<br />first:	1359207602<br />last:	0<br />md5:	c3b15db374d0fd41adbbc9c8137d5168<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=55f1a33b5115c07f77155fbc3650d29a<br />vt_score:	5/42 (11.9%)<br />scanner:	Jiangmin<br />virusname:	Trojan/StartPage.bim<br />url:	http://tsunami-rt.com/images/stories/backup.php?ncrnd=EyTKTQgHDc<br />recent:	up<br />response:	alive<br />ip:	91.200.112.85<br />as:	AS43864<br />review:	91.200.112.85<br />domain:	tsunami-rt.com<br />country:	UA<br />source:	RIPE<br />email:	contact@integra-media.com<br />inetnum:	91.200.112.0 - 91.200.115.255<br />netname:	INTEGRA-MEDIA-NET<br />descr:	Integra-Media LtdIntegra-Media LtdIntegra-Media LtdIntegra-Media Ltd<br />ns1:	ns1.h07.hvosting.ua<br />ns2:	ns2.h07.hvosting.ua<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://bbs.xiaojuren.net/source/language/chess.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9206735</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9206735</guid>
			<pubDate>2013-01-25T19:50:03+01:00</pubDate>
			<description><![CDATA[id:	9206735<br />first:	1359139803<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://bbs.xiaojuren.net/source/language/chess.exe<br />recent:	up<br />response:	alive<br />ip:	210.51.161.165<br />as:	AS9929<br />review:	undef<br />domain:	xiaojuren.net<br />country:	CN<br />source:	ARIN<br />email:	abuse@cnc-noc.net<br />inetnum:	210.51.160.0 - 210.51.175.255<br />netname:	CNC-BJ-IDC2<br />descr:	Beijing YiZhuang IDC of China NetcomCNC Group CncNet<br />ns1:	dns1.iidns.com<br />ns2:	dns5.iidns.com<br />ns3:	dns6.iidns.com<br />ns4:	dns2.iidns.com<br />ns5:	dns3.iidns.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.lytess.com/nnn.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9198706</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9198706</guid>
			<pubDate>2013-01-24T18:40:18+01:00</pubDate>
			<description><![CDATA[id:	9198706<br />first:	1359049218<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://www.lytess.com/nnn.exe<br />recent:	up<br />response:	alive<br />ip:	212.227.134.53<br />as:	AS8560<br />review:	82.165.162.55<br />domain:	lytess.com<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	212.227.134.0 - 212.227.143.255<br />netname:	DE-SCHLUND-20030806<br />descr:	1&1 Internet AGSCHLUND-PA-4<br />ns1:	ns62.1and1.fr<br />ns2:	ns61.1and1.fr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://sonhodoseu.dominiotemporario.com/ze/Instal.teaz]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9186142</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9186142</guid>
			<pubDate>2013-01-23T10:40:18+01:00</pubDate>
			<description><![CDATA[id:	9186142<br />first:	1358934018<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://sonhodoseu.dominiotemporario.com/ze/Instal.teaz<br />recent:	up<br />response:	alive<br />ip:	187.17.98.153<br />as:	AS15201<br />review:	undef<br />domain:	dominiotemporario.com<br />country:	BR<br />source:	ARIN<br />email:	l-registrobr-uol@corp.uol.com.br<br />inetnum:	187.17.64.0 - 187.17.127.255<br />netname:	001.109.184/0001-95<br />descr:	Universo Online S.A.<br />ns1:	ns2.host.uol.com.br<br />ns2:	ns1.host.uol.com.br<br />ns3:	ns3.host.uol.com.br<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ablap.com.br/wp-content/uploads/2011/03/mensagem.com]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9186141</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9186141</guid>
			<pubDate>2013-01-23T10:40:18+01:00</pubDate>
			<description><![CDATA[id:	9186141<br />first:	1358934018<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://ablap.com.br/wp-content/uploads/2011/03/mensagem.com<br />recent:	up<br />response:	alive<br />ip:	187.45.241.55<br />as:	AS27715<br />review:	187.45.241.55<br />domain:	ablap.com.br<br />country:	BR<br />source:	LACNIC<br />email:	regcom@locaweb.com.br<br />inetnum:	187.45.224.0 - 187.45.255.255<br />netname:	002.351.877/0001-52<br />descr:	Locaweb Serviços de Internet S/A<br />ns1:	ns3.locaweb.com.br<br />ns2:	ns2.locaweb.com.br<br />ns3:	ns1.locaweb.com.br<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cheapsunday.ru/wp-content/plugins/akismet/soft.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9159702</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[unknown_exe]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9159702</guid>
			<pubDate>2013-01-21T14:40:06+01:00</pubDate>
			<description><![CDATA[id:	9159702<br />first:	1358775606<br />last:	0<br />md5:	c52a073c01299e4cef0e641959360224<br />virustotal:	<br />vt_score:	9/36 (25%)<br />scanner:	undef<br />virusname:	unknown_exe<br />url:	http://cheapsunday.ru/wp-content/plugins/akismet/soft.exe<br />recent:	up<br />response:	alive<br />ip:	37.140.192.17<br />as:	AS39134<br />review:	37.140.192.17<br />domain:	cheapsunday.ru<br />country:	RU<br />source:	RIPE<br />email:	abuse@reg.ru<br />inetnum:	37.140.192.0 - 37.140.195.255<br />netname:	REGRU-NETWORK<br />descr:	Reg.Ru Hosting<br />ns1:	ns1.hosting.reg.ru<br />ns2:	ns2.hosting.reg.ru<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://208.131.138.133/links/came_broadcasting_taking-various.php?zrlqf=1k:33:1m:1m:1n&jnk=1m:2w:1n:1k:1l:1n:33:1g:1m:1o&uhbrip=1i&illk=saoiw&xocxbwqv=rhx]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9157982</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9157982</guid>
			<pubDate>2013-01-21T12:00:12+01:00</pubDate>
			<description><![CDATA[id:	9157982<br />first:	1358766012<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://208.131.138.133/links/came_broadcasting_taking-various.php?zrlqf=1k:33:1m:1m:1n&jnk=1m:2w:1n:1k:1l:1n:33:1g:1m:1o&uhbrip=1i&illk=saoiw&xocxbwqv=rhx<br />recent:	up<br />response:	alive<br />ip:	208.131.138.133<br />as:	AS29854<br />review:	208.131.138.133<br />domain:	208.131.138.133<br />country:	US<br />source:	ARIN<br />email:	noc@westhost.com<br />inetnum:	208.131.128.0 - 208.131.159.255<br />netname:	WESTHOST-NOC<br />descr:	WestHost, Inc. WESTHO 164 N Spring Creek Pkwy Providence UT 84332<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://208.131.138.133/links/came_broadcasting_taking-various.php?zfsrkp=1k:33:1m:1m:1n&bjtzmb=33:1n:1h:1f:1j:1h:1i:1n:1j:1h&rgpevb=1i&jgp=ljaof&soloi=siwlg]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9157981</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9157981</guid>
			<pubDate>2013-01-21T12:00:11+01:00</pubDate>
			<description><![CDATA[id:	9157981<br />first:	1358766011<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://208.131.138.133/links/came_broadcasting_taking-various.php?zfsrkp=1k:33:1m:1m:1n&bjtzmb=33:1n:1h:1f:1j:1h:1i:1n:1j:1h&rgpevb=1i&jgp=ljaof&soloi=siwlg<br />recent:	up<br />response:	alive<br />ip:	208.131.138.133<br />as:	AS29854<br />review:	208.131.138.133<br />domain:	208.131.138.133<br />country:	US<br />source:	ARIN<br />email:	noc@westhost.com<br />inetnum:	208.131.128.0 - 208.131.159.255<br />netname:	WESTHOST-NOC<br />descr:	WestHost, Inc. WESTHO 164 N Spring Creek Pkwy Providence UT 84332<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ald-facebook.co.uk/operations/outer_band_remote.php?ahsnjiy=33:2v:1h:2w:1m&fimh=2v:1h:1m:1g:1o:32:1i:30:2w:30&mztqf=1i&ito=ptk&umih=twljw]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9157435</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9157435</guid>
			<pubDate>2013-01-21T10:40:09+01:00</pubDate>
			<description><![CDATA[id:	9157435<br />first:	1358761209<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://ald-facebook.co.uk/operations/outer_band_remote.php?ahsnjiy=33:2v:1h:2w:1m&fimh=2v:1h:1m:1g:1o:32:1i:30:2w:30&mztqf=1i&ito=ptk&umih=twljw<br />recent:	up<br />response:	alive<br />ip:	192.210.142.20<br />as:	AS36352<br />review:	undef<br />domain:	ald-facebook.co.uk<br />country:	BG<br />source:	ARIN<br />email:	abarakov94@gmail.com<br />inetnum:	192.210.142.0 - 192.210.142.63<br />netname:	CC-192-210-142-0-26<br />descr:	LiquidSolutions LIQUI-50 Mladost, block.3, vhod B, ap.10 Troyan NA 5600<br />ns1:	ns0.lcn.com<br />ns2:	ns1.lcn.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cheapsunday.ru/wp-content/plugins/akismet/akismeet.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9154735</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Qhost]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9154735</guid>
			<pubDate>2013-01-21T00:40:03+01:00</pubDate>
			<description><![CDATA[id:	9154735<br />first:	1358725203<br />last:	0<br />md5:	890be8c33498693e813285dc063df399<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fabfcd33ffc4ab7ce6e50ed7e3aa504f<br />vt_score:	26/36 (72.2%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Qhost<br />url:	http://cheapsunday.ru/wp-content/plugins/akismet/akismeet.php<br />recent:	up<br />response:	alive<br />ip:	37.140.192.17<br />as:	AS39134<br />review:	37.140.192.17<br />domain:	cheapsunday.ru<br />country:	RU<br />source:	RIPE<br />email:	abuse@reg.ru<br />inetnum:	37.140.192.0 - 37.140.195.255<br />netname:	REGRU-NETWORK<br />descr:	Reg.Ru Hosting<br />ns1:	ns2.hosting.reg.ru<br />ns2:	ns1.hosting.reg.ru<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://connecttome1.sytes.net/zpanel/bot.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9149891</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9149891</guid>
			<pubDate>2013-01-20T12:40:09+01:00</pubDate>
			<description><![CDATA[id:	9149891<br />first:	1358682009<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://connecttome1.sytes.net/zpanel/bot.exe<br />recent:	up<br />response:	alive<br />ip:	5.135.179.88<br />as:	AS16276<br />review:	195.22.26.231<br />domain:	sytes.net<br />country:	PT<br />source:	RIPE<br />email:	abuse@pt.clara.net<br />inetnum:	5.135.0.0 - 5.135.255.255<br />netname:	ESOTERICA<br />descr:	VIA NET.WORKS Portugal -  Tecnologias de Informa,cao, SA(formerly Esoterica, SA)Lisboa, Portugal<br />ns1:	nf1.no-ip.com<br />ns2:	nf3.no-ip.com<br />ns3:	nf2.no-ip.com<br />ns4:	nf4.no-ip.com<br />ns5:	nf5.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://javadownload.sytes.net/new/bot.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9149890</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9149890</guid>
			<pubDate>2013-01-20T12:40:09+01:00</pubDate>
			<description><![CDATA[id:	9149890<br />first:	1358682009<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://javadownload.sytes.net/new/bot.exe<br />recent:	up<br />response:	alive<br />ip:	5.135.179.88<br />as:	AS16276<br />review:	undef<br />domain:	sytes.net<br />country:	FR<br />source:	ARIN<br />email:	abuse@ovh.net<br />inetnum:	5.135.0.0 - 5.135.255.255<br />netname:	FR-OVH-20120706<br />descr:	Ovh Systems<br />ns1:	nf1.no-ip.com<br />ns2:	nf3.no-ip.com<br />ns3:	nf2.no-ip.com<br />ns4:	nf4.no-ip.com<br />ns5:	nf5.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://testpanel.sytes.net/scanner/uploads/3460.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9149358</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9149358</guid>
			<pubDate>2013-01-20T11:40:06+01:00</pubDate>
			<description><![CDATA[id:	9149358<br />first:	1358678406<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://testpanel.sytes.net/scanner/uploads/3460.exe<br />recent:	up<br />response:	alive<br />ip:	5.135.179.88<br />as:	AS16276<br />review:	195.22.26.231<br />domain:	sytes.net<br />country:	PT<br />source:	RIPE<br />email:	abuse@pt.clara.net<br />inetnum:	5.135.0.0 - 5.135.255.255<br />netname:	ESOTERICA<br />descr:	VIA NET.WORKS Portugal -  Tecnologias de Informa,cao, SA(formerly Esoterica, SA)Lisboa, Portugal<br />ns1:	nf2.no-ip.com<br />ns2:	nf4.no-ip.com<br />ns3:	nf3.no-ip.com<br />ns4:	nf1.no-ip.com<br />ns5:	nf5.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://testpanel.sytes.net/scanner/uploads/Stub.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9149357</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9149357</guid>
			<pubDate>2013-01-20T11:40:05+01:00</pubDate>
			<description><![CDATA[id:	9149357<br />first:	1358678405<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://testpanel.sytes.net/scanner/uploads/Stub.exe<br />recent:	up<br />response:	alive<br />ip:	5.135.179.88<br />as:	AS16276<br />review:	195.22.26.231<br />domain:	sytes.net<br />country:	PT<br />source:	RIPE<br />email:	abuse@pt.clara.net<br />inetnum:	5.135.0.0 - 5.135.255.255<br />netname:	ESOTERICA<br />descr:	VIA NET.WORKS Portugal -  Tecnologias de Informa,cao, SA(formerly Esoterica, SA)Lisboa, Portugal<br />ns1:	nf2.no-ip.com<br />ns2:	nf4.no-ip.com<br />ns3:	nf3.no-ip.com<br />ns4:	nf1.no-ip.com<br />ns5:	nf5.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://testpanel.sytes.net/a.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9149356</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9149356</guid>
			<pubDate>2013-01-20T11:40:05+01:00</pubDate>
			<description><![CDATA[id:	9149356<br />first:	1358678405<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://testpanel.sytes.net/a.exe<br />recent:	up<br />response:	alive<br />ip:	5.135.179.88<br />as:	AS16276<br />review:	195.22.26.231<br />domain:	sytes.net<br />country:	PT<br />source:	RIPE<br />email:	abuse@pt.clara.net<br />inetnum:	5.135.0.0 - 5.135.255.255<br />netname:	ESOTERICA<br />descr:	VIA NET.WORKS Portugal -  Tecnologias de Informa,cao, SA(formerly Esoterica, SA)Lisboa, Portugal<br />ns1:	nf2.no-ip.com<br />ns2:	nf4.no-ip.com<br />ns3:	nf3.no-ip.com<br />ns4:	nf1.no-ip.com<br />ns5:	nf5.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://testpanel.sytes.net/pi.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9149355</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9149355</guid>
			<pubDate>2013-01-20T11:40:05+01:00</pubDate>
			<description><![CDATA[id:	9149355<br />first:	1358678405<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://testpanel.sytes.net/pi.exe<br />recent:	up<br />response:	alive<br />ip:	5.135.179.88<br />as:	AS16276<br />review:	195.22.26.231<br />domain:	sytes.net<br />country:	PT<br />source:	RIPE<br />email:	abuse@pt.clara.net<br />inetnum:	5.135.0.0 - 5.135.255.255<br />netname:	ESOTERICA<br />descr:	VIA NET.WORKS Portugal -  Tecnologias de Informa,cao, SA(formerly Esoterica, SA)Lisboa, Portugal<br />ns1:	nf2.no-ip.com<br />ns2:	nf4.no-ip.com<br />ns3:	nf3.no-ip.com<br />ns4:	nf1.no-ip.com<br />ns5:	nf5.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://testpanel.sytes.net/v.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9149354</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9149354</guid>
			<pubDate>2013-01-20T11:40:05+01:00</pubDate>
			<description><![CDATA[id:	9149354<br />first:	1358678405<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://testpanel.sytes.net/v.exe<br />recent:	up<br />response:	alive<br />ip:	5.135.179.88<br />as:	AS16276<br />review:	195.22.26.231<br />domain:	sytes.net<br />country:	PT<br />source:	RIPE<br />email:	abuse@pt.clara.net<br />inetnum:	5.135.0.0 - 5.135.255.255<br />netname:	ESOTERICA<br />descr:	VIA NET.WORKS Portugal -  Tecnologias de Informa,cao, SA(formerly Esoterica, SA)Lisboa, Portugal<br />ns1:	nf2.no-ip.com<br />ns2:	nf4.no-ip.com<br />ns3:	nf3.no-ip.com<br />ns4:	nf1.no-ip.com<br />ns5:	nf5.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://testpanel.sytes.net/xxx.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9149353</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9149353</guid>
			<pubDate>2013-01-20T11:40:05+01:00</pubDate>
			<description><![CDATA[id:	9149353<br />first:	1358678405<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://testpanel.sytes.net/xxx.exe<br />recent:	up<br />response:	alive<br />ip:	5.135.179.88<br />as:	AS16276<br />review:	195.22.26.231<br />domain:	sytes.net<br />country:	PT<br />source:	RIPE<br />email:	abuse@pt.clara.net<br />inetnum:	5.135.0.0 - 5.135.255.255<br />netname:	ESOTERICA<br />descr:	VIA NET.WORKS Portugal -  Tecnologias de Informa,cao, SA(formerly Esoterica, SA)Lisboa, Portugal<br />ns1:	nf2.no-ip.com<br />ns2:	nf4.no-ip.com<br />ns3:	nf3.no-ip.com<br />ns4:	nf1.no-ip.com<br />ns5:	nf5.no-ip.com<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rolex1.serverthuis.nl/file/files/1.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9146038</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9146038</guid>
			<pubDate>2013-01-19T22:50:02+01:00</pubDate>
			<description><![CDATA[id:	9146038<br />first:	1358632202<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://rolex1.serverthuis.nl/file/files/1.exe<br />recent:	up<br />response:	alive<br />ip:	178.63.123.217<br />as:	AS24940<br />review:	undef<br />domain:	serverthuis.nl<br />country:	DE<br />source:	ARIN<br />email:	abuse@hetzner.de<br />inetnum:	178.63.0.0 - 178.63.255.255<br />netname:	DE-HETZNER-20100302<br />descr:	Hetzner Online AG<br />ns1:	ns1.serverthuis.com<br />ns2:	ns4.serverthuis.com<br />ns3:	ns2.serverthuis.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://rolex1.serverthuis.nl/file/files/2.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9146037</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9146037</guid>
			<pubDate>2013-01-19T22:50:02+01:00</pubDate>
			<description><![CDATA[id:	9146037<br />first:	1358632202<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://rolex1.serverthuis.nl/file/files/2.exe<br />recent:	up<br />response:	alive<br />ip:	178.63.123.217<br />as:	AS24940<br />review:	undef<br />domain:	serverthuis.nl<br />country:	DE<br />source:	ARIN<br />email:	abuse@hetzner.de<br />inetnum:	178.63.0.0 - 178.63.255.255<br />netname:	DE-HETZNER-20100302<br />descr:	Hetzner Online AG<br />ns1:	ns1.serverthuis.com<br />ns2:	ns4.serverthuis.com<br />ns3:	ns2.serverthuis.com<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://fetolbus.ru/calc.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9144605</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9144605</guid>
			<pubDate>2013-01-19T18:40:03+01:00</pubDate>
			<description><![CDATA[id:	9144605<br />first:	1358617203<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://fetolbus.ru/calc.exe<br />recent:	up<br />response:	alive<br />ip:	76.85.185.136<br />as:	AS7757<br />review:	undef<br />domain:	fetolbus.ru<br />country:	BY<br />source:	ARIN<br />email:	head@belsonet.net<br />inetnum:	76.80.0.0 - 76.89.63.255<br />netname:	SOLO-BY<br />descr:	JSC Solo, Belarus<br />ns1:	ns3.fetolbus.ru<br />ns2:	ns2.fetolbus.ru<br />ns3:	ns5.fetolbus.ru<br />ns4:	ns1.fetolbus.ru<br />ns5:	ns6.fetolbus.ru<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://data.filehouse.biz/download3.php?n=Window_7_Flash.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9144201</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PUA.Win32.Packer.SetupExeSection]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9144201</guid>
			<pubDate>2013-01-19T17:40:05+01:00</pubDate>
			<description><![CDATA[id:	9144201<br />first:	1358613605<br />last:	0<br />md5:	588022e5be1c6fad7e4492529dc4b95b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5fc8f7ce54fd74e0a6ee092771fb482f<br />vt_score:	11/39 (28.2%)<br />scanner:	clamav<br />virusname:	PUA.Win32.Packer.SetupExeSection<br />url:	http://data.filehouse.biz/download3.php?n=Window_7_Flash.exe<br />recent:	up<br />response:	alive<br />ip:	211.115.80.56<br />as:	AS3786<br />review:	211.115.80.56<br />domain:	filehouse.biz<br />country:	KR<br />source:	APNIC<br />email:	ip@kidc.net<br />inetnum:	211.115.64.0 - 211.115.127.255<br />netname:	KIDC-KR<br />descr:	LG DACOM KIDC<br />ns1:	ns1.smartlist.co.kr<br />ns2:	ns2.smartlist.co.kr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://qualidade-developerxe2.com/DA-16/Xp/service.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9143874</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9143874</guid>
			<pubDate>2013-01-19T15:00:07+01:00</pubDate>
			<description><![CDATA[id:	9143874<br />first:	1358604007<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://qualidade-developerxe2.com/DA-16/Xp/service.exe<br />recent:	up<br />response:	alive<br />ip:	200.98.255.186<br />as:	AS15201<br />review:	109.123.82.172<br />domain:	qualidade-developerxe2.com<br />country:	GB<br />source:	RIPE<br />email:	ripe@uk2.net<br />inetnum:	200.98.0.0 - 200.98.255.255<br />netname:	UK-UK2NET-20091012<br />descr:	UK2 - LtdUK2.NET announcement<br />ns1:	ns1.dominios.uol.com.br<br />ns2:	ns3.dominios.uol.com.br<br />ns3:	ns2.dominios.uol.com.br<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://agixo.com/wp-content/plugins/zexiouiamuu/dir/Core999.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9142986</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9142986</guid>
			<pubDate>2013-01-19T11:00:06+01:00</pubDate>
			<description><![CDATA[id:	9142986<br />first:	1358589606<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://agixo.com/wp-content/plugins/zexiouiamuu/dir/Core999.exe<br />recent:	up<br />response:	alive<br />ip:	198.136.48.142<br />as:	AS33182<br />review:	198.136.48.142<br />domain:	agixo.com<br />country:	US<br />source:	ARIN<br />email:	abuse@dimenoc.com<br />inetnum:	198.136.48.0 - 198.136.63.255<br />netname:	DIMENOC<br />descr:	HostDime.com, Inc. DIMEN-6 189 South Orange Avenue Suite 1500S Orlando FL 32801<br />ns1:	ns2.whois.com<br />ns2:	ns4.whois.com<br />ns3:	ns3.whois.com<br />ns4:	ns1.whois.com<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://www.habbio.es/java.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9142726</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9142726</guid>
			<pubDate>2013-01-19T10:40:03+01:00</pubDate>
			<description><![CDATA[id:	9142726<br />first:	1358588403<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://www.habbio.es/java.exe<br />recent:	up<br />response:	alive<br />ip:	37.152.88.18<br />as:	AS57910<br />review:	undef<br />domain:	habbio.es<br />country:	ES<br />source:	ARIN<br />email:	abuse@scip.es<br />inetnum:	37.152.88.0 - 37.152.88.255<br />netname:	DONDOMINIO-HOSTING<br />descr:	DonDominio.com / MrDomain.comShared Hosting ServicesSoluciones Corporativas IP (SCIP)<br />ns1:	ns3.dondominio.com<br />ns2:	ns2.dondominio.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://strotegartners.com/ngen/controlling/topgearspecial.php?vdp=1k:33:1m:1m:1n&aidzlds=1g:32:1j:31:1k:2w:32:1h:31:1k&nazxcs=1i&qbj=sufqfyap&adyogup=blods]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9142516</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9142516</guid>
			<pubDate>2013-01-19T10:00:07+01:00</pubDate>
			<description><![CDATA[id:	9142516<br />first:	1358586007<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://strotegartners.com/ngen/controlling/topgearspecial.php?vdp=1k:33:1m:1m:1n&aidzlds=1g:32:1j:31:1k:2w:32:1h:31:1k&nazxcs=1i&qbj=sufqfyap&adyogup=blods<br />recent:	up<br />response:	alive<br />ip:	63.90.228.36<br />as:	AS46940<br />review:	63.90.228.36<br />domain:	strotegartners.com<br />country:	US<br />source:	ARIN<br />email:	abuse-mail@verizonbusiness.com<br />inetnum:	63.64.0.0 - 63.127.255.255<br />netname:	UUNET63<br />descr:	MCI Communications Services, Inc. d/b/a Verizon Business MCICS 22001 Loudoun County Pkwy Ashburn VA 20147<br />ns1:	ns4.cnmsn.com<br />ns2:	ns3.cnmsn.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://strotegartners.com/ngen/controlling/topgearspecial.php?iqjh=1k:33:1m:1m:1n&otjxbo=31:1o:32:1h:1n:1o:2v:1o:2v:1i&tqatfqe=1i&beqfinr=clgubiim&utezzsw=uwkigrz]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9142515</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9142515</guid>
			<pubDate>2013-01-19T10:00:07+01:00</pubDate>
			<description><![CDATA[id:	9142515<br />first:	1358586007<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://strotegartners.com/ngen/controlling/topgearspecial.php?iqjh=1k:33:1m:1m:1n&otjxbo=31:1o:32:1h:1n:1o:2v:1o:2v:1i&tqatfqe=1i&beqfinr=clgubiim&utezzsw=uwkigrz<br />recent:	up<br />response:	alive<br />ip:	63.90.228.36<br />as:	AS46940<br />review:	63.90.228.36<br />domain:	strotegartners.com<br />country:	US<br />source:	ARIN<br />email:	abuse-mail@verizonbusiness.com<br />inetnum:	63.64.0.0 - 63.127.255.255<br />netname:	UUNET63<br />descr:	MCI Communications Services, Inc. d/b/a Verizon Business MCICS 22001 Loudoun County Pkwy Ashburn VA 20147<br />ns1:	ns4.cnmsn.com<br />ns2:	ns3.cnmsn.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://soberthingingmonrom.com/ngen/controlling/thirdpartyone.php?vdp=1k:33:1m:1m:1n&aidzlds=1g:32:1j:31:1k:2w:32:1h:31:1k&nazxcs=1i&qbj=sufqfyap&adyogup=blods]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9142508</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9142508</guid>
			<pubDate>2013-01-19T09:50:03+01:00</pubDate>
			<description><![CDATA[id:	9142508<br />first:	1358585403<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://soberthingingmonrom.com/ngen/controlling/thirdpartyone.php?vdp=1k:33:1m:1m:1n&aidzlds=1g:32:1j:31:1k:2w:32:1h:31:1k&nazxcs=1i&qbj=sufqfyap&adyogup=blods<br />recent:	up<br />response:	alive<br />ip:	63.90.228.36<br />as:	AS46940<br />review:	63.90.228.36<br />domain:	soberthingingmonrom.com<br />country:	US<br />source:	ARIN<br />email:	abuse-mail@verizonbusiness.com<br />inetnum:	63.64.0.0 - 63.127.255.255<br />netname:	UUNET63<br />descr:	MCI Communications Services, Inc. d/b/a Verizon Business MCICS 22001 Loudoun County Pkwy Ashburn VA 20147<br />ns1:	ns3.cnmsn.com<br />ns2:	ns4.cnmsn.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://soberthingingmonrom.com/ngen/controlling/thirdpartyone.php?iqjh=1k:33:1m:1m:1n&otjxbo=31:1o:32:1h:1n:1o:2v:1o:2v:1i&tqatfqe=1i&beqfinr=clgubiim&utezzsw=uwkigrz]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9142507</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9142507</guid>
			<pubDate>2013-01-19T09:50:02+01:00</pubDate>
			<description><![CDATA[id:	9142507<br />first:	1358585402<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://soberthingingmonrom.com/ngen/controlling/thirdpartyone.php?iqjh=1k:33:1m:1m:1n&otjxbo=31:1o:32:1h:1n:1o:2v:1o:2v:1i&tqatfqe=1i&beqfinr=clgubiim&utezzsw=uwkigrz<br />recent:	up<br />response:	alive<br />ip:	63.90.228.36<br />as:	AS46940<br />review:	63.90.228.36<br />domain:	soberthingingmonrom.com<br />country:	US<br />source:	ARIN<br />email:	abuse-mail@verizonbusiness.com<br />inetnum:	63.64.0.0 - 63.127.255.255<br />netname:	UUNET63<br />descr:	MCI Communications Services, Inc. d/b/a Verizon Business MCICS 22001 Loudoun County Pkwy Ashburn VA 20147<br />ns1:	ns3.cnmsn.com<br />ns2:	ns4.cnmsn.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://cheapsunday.ru/wp-content/plugins/akismet/update.php]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9142375</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Trojan/Win32.Qhost]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9142375</guid>
			<pubDate>2013-01-19T08:40:02+01:00</pubDate>
			<description><![CDATA[id:	9142375<br />first:	1358581202<br />last:	0<br />md5:	890be8c33498693e813285dc063df399<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=fabfcd33ffc4ab7ce6e50ed7e3aa504f<br />vt_score:	26/36 (72.2%)<br />scanner:	AhnLab_V3<br />virusname:	Trojan/Win32.Qhost<br />url:	http://cheapsunday.ru/wp-content/plugins/akismet/update.php<br />recent:	up<br />response:	alive<br />ip:	37.140.192.17<br />as:	AS39134<br />review:	37.140.192.17<br />domain:	cheapsunday.ru<br />country:	RU<br />source:	RIPE<br />email:	abuse@reg.ru<br />inetnum:	37.140.192.0 - 37.140.195.255<br />netname:	REGRU-NETWORK<br />descr:	Reg.Ru Hosting<br />ns1:	ns2.hosting.reg.ru<br />ns2:	ns1.hosting.reg.ru<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://192.155.83.208/read/intention_same.php?rut=1k:33:1m:1m:1n&pzqgsql=32:1n:2v:1i:1h:1h:1o:1l:1m:1m&jfuikd=1i&xawb=fkz&nvsuncck=equ]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9139976</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9139976</guid>
			<pubDate>2013-01-19T02:40:03+01:00</pubDate>
			<description><![CDATA[id:	9139976<br />first:	1358559603<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://192.155.83.208/read/intention_same.php?rut=1k:33:1m:1m:1n&pzqgsql=32:1n:2v:1i:1h:1h:1o:1l:1m:1m&jfuikd=1i&xawb=fkz&nvsuncck=equ<br />recent:	up<br />response:	alive<br />ip:	192.155.83.208<br />as:	AS6939<br />review:	192.155.83.208<br />domain:	192.155.83.208<br />country:	US<br />source:	ARIN<br />email:	abuse@linode.com<br />inetnum:	192.155.80.0 - 192.155.95.255<br />netname:	LINODE-US<br />descr:	Linode LINOD 329 E. Jimmie Leeds Road Suite A Galloway NJ 08205<br />ns1:	<br />ns2:	<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://usethenews.com/b.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9132359</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9132359</guid>
			<pubDate>2013-01-18T09:40:02+01:00</pubDate>
			<description><![CDATA[id:	9132359<br />first:	1358498402<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://usethenews.com/b.exe<br />recent:	up<br />response:	alive<br />ip:	74.208.223.26<br />as:	AS8560<br />review:	undef<br />domain:	usethenews.com<br />country:	US<br />source:	ARIN<br />email:	abuse@1and1.com<br />inetnum:	74.208.0.0 - 74.208.255.255<br />netname:	1AN1-NETWORK<br />descr:	1&1 Internet Inc. 11INT 701 Lee Rd Suite 300 Chesterbrook PA 19087<br />ns1:	ns58.1and1.com<br />ns2:	ns57.1and1.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ritus.by/outputs.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9130114</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[cleanmx_generic]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9130114</guid>
			<pubDate>2013-01-18T02:40:02+01:00</pubDate>
			<description><![CDATA[id:	9130114<br />first:	1358473202<br />last:	0<br />md5:	1c319fd8154cdef04ddc22e16aaf7601<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=9d9f17c80ec377609caa08e85c4b7a44<br />vt_score:	18/36 (50%)<br />scanner:	undef<br />virusname:	cleanmx_generic<br />url:	http://ritus.by/outputs.exe<br />recent:	up<br />response:	alive<br />ip:	93.125.99.16<br />as:	AS6697<br />review:	93.125.99.16<br />domain:	ritus.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	93.125.99.0 - 93.125.99.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns1.tutby.com<br />ns2:	ns2.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ritus.by/564.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9130113</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[cleanmx_generic]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9130113</guid>
			<pubDate>2013-01-18T02:40:02+01:00</pubDate>
			<description><![CDATA[id:	9130113<br />first:	1358473202<br />last:	0<br />md5:	1c319fd8154cdef04ddc22e16aaf7601<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=8acbac046a1965551604274ca41e6fff<br />vt_score:	24/46 (52.2%)<br />scanner:	undef<br />virusname:	cleanmx_generic<br />url:	http://ritus.by/564.exe<br />recent:	up<br />response:	alive<br />ip:	93.125.99.16<br />as:	AS6697<br />review:	93.125.99.16<br />domain:	ritus.by<br />country:	BY<br />source:	RIPE<br />email:	dis@tutby.com<br />inetnum:	93.125.99.0 - 93.125.99.255<br />netname:	TUTBY<br />descr:	HOSTER.BYReliable Software, Inc.DELEGATED FROM BELPAK<br />ns1:	ns1.tutby.com<br />ns2:	ns2.tutby.com<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://ald-facebook.me.uk/operations/lead-achieves-fishes.php?ahsnjiy=33:2v:1h:2w:1m&fimh=2v:1h:1m:1g:1o:32:1i:30:2w:30&mztqf=1i&ito=ptk&umih=twljw]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9127801</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[JS/RunForest.C.1]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9127801</guid>
			<pubDate>2013-01-17T21:50:04+01:00</pubDate>
			<description><![CDATA[id:	9127801<br />first:	1358455804<br />last:	0<br />md5:	d41d8cd98f00b204e9800998ecf8427e<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285<br />vt_score:	26/36 (72.2%)<br />scanner:	avira<br />virusname:	JS/RunForest.C.1<br />url:	http://ald-facebook.me.uk/operations/lead-achieves-fishes.php?ahsnjiy=33:2v:1h:2w:1m&fimh=2v:1h:1m:1g:1o:32:1i:30:2w:30&mztqf=1i&ito=ptk&umih=twljw<br />recent:	up<br />response:	alive<br />ip:	75.127.0.27<br />as:	AS36352<br />review:	undef<br />domain:	me.uk<br />country:	US<br />source:	ARIN<br />email:	abuse@colocrossing.com<br />inetnum:	75.127.0.0 - 75.127.15.255<br />netname:	CC-07<br />descr:	ColoCrossing VGS-9 8469 Sheridan Drive ATTN Williamsville NY 14221<br />ns1:	ns2.nic.uk<br />ns2:	nsc.nic.uk<br />ns3:	nsa.nic.uk<br />ns4:	nsd.nic.uk<br />ns5:	ns1.nic.uk<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://boti.astria-serv.com/network.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=9018227</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[TR/PSW.37888.A]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=9018227</guid>
			<pubDate>2013-01-09T14:40:05+01:00</pubDate>
			<description><![CDATA[id:	9018227<br />first:	1357738805<br />last:	0<br />md5:	<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5<br />vt_score:	17/40 (42.5%)<br />scanner:	avira<br />virusname:	TR/PSW.37888.A<br />url:	http://boti.astria-serv.com/network.exe<br />recent:	up<br />response:	alive<br />ip:	82.165.157.212<br />as:	AS8560<br />review:	82.165.157.212<br />domain:	astria-serv.com<br />country:	DE<br />source:	RIPE<br />email:	abuse@1and1.com<br />inetnum:	82.165.144.0 - 82.165.159.255<br />netname:	SCHLUND-CUSTOMERS<br />descr:	1&1 Internet AG<br />ns1:	ns61.1and1.fr<br />ns2:	ns62.1and1.fr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://alyackorea.com/download3.php?n=window_7_keygen.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8910245</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[PUA.Win32.Packer.SetupExeSection]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8910245</guid>
			<pubDate>2012-12-31T12:00:07+01:00</pubDate>
			<description><![CDATA[id:	8910245<br />first:	1356951607<br />last:	0<br />md5:	588022e5be1c6fad7e4492529dc4b95b<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5fc8f7ce54fd74e0a6ee092771fb482f<br />vt_score:	11/39 (28.2%)<br />scanner:	clamav<br />virusname:	PUA.Win32.Packer.SetupExeSection<br />url:	http://alyackorea.com/download3.php?n=window_7_keygen.exe<br />recent:	up<br />response:	alive<br />ip:	211.115.80.56<br />as:	AS3786<br />review:	211.115.80.56<br />domain:	alyackorea.com<br />country:	KR<br />source:	APNIC<br />email:	ip@kidc.net<br />inetnum:	211.115.64.0 - 211.115.127.255<br />netname:	KIDC-KR<br />descr:	LG DACOM KIDC<br />ns1:	ns2.smartlist.co.kr<br />ns2:	ns1.smartlist.co.kr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
		<item>
			<title><![CDATA[http://setup.lnimarketing.co.kr/WkipSetup_203_Hide.exe]]></title>
			<link>http://support.clean-mx.de/clean-mx/viruses?id=8910243</link>
			<author>abuse@clean-mx.de</author>
			<category><![CDATA[Suspicion: unknown virus]]></category>
			<guid>http://support.clean-mx.de/clean-mx/viruses?id=8910243</guid>
			<pubDate>2012-12-31T12:00:07+01:00</pubDate>
			<description><![CDATA[id:	8910243<br />first:	1356951607<br />last:	0<br />md5:	5d659605263259615e05313c7551f7ac<br />virustotal:	http://www.virustotal.com/latest-report.html?resource=5d659605263259615e05313c7551f7ac<br />vt_score:	6/35 (17.1%)<br />scanner:	AVG<br />virusname:	Suspicion: unknown virus<br />url:	http://setup.lnimarketing.co.kr/WkipSetup_203_Hide.exe<br />recent:	up<br />response:	alive<br />ip:	114.203.87.199<br />as:	AS9318<br />review:	114.203.87.199<br />domain:	lnimarketing.co.kr<br />country:	KR<br />source:	APNIC<br />email:	abuse@skbroadband.com<br />inetnum:	114.200.0.0 - 114.207.255.255<br />netname:	broadNnet-KR<br />descr:	SK Broadband Co Ltd<br />ns1:	ns1.kshosting.co.kr<br />ns2:	ns2.kshosting.co.kr<br />ns3:	<br />ns4:	<br />ns5:	<br />]]></description>
		</item>
	</channel>
</rss>

