CLEAN MX realtime database
safe Virus viewer
try this https://199.27.76.133/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe
start tracing target: 199.27.76.133 (The specified type of tracerouting is allowed for superuser only)
/usr/bin/lft: Option '-T' is not implemented in this wrapper
/usr/bin/lft: Option '-E' is not implemented in this wrapper
The specified type of tracerouting is allowed for superuser only

end tracing target 199.27.76.133
start whois lasthop for (199.27.76.133)

#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


#
# Query terms are ambiguous.  The query is assumed to be:
#     "n 199.27.76.133"
#
# Use "?" to get help.
#

#
# The following results may also be obtained via:
# http://whois.arin.net/rest/nets;q=199.27.76.133?showDetails=true&showARIN=false&ext=netref2
#

NetRange:       199.27.72.0 - 199.27.79.255
CIDR:           199.27.72.0/21
OriginAS:       AS54113
NetName:        FASTLY
NetHandle:      NET-199-27-72-0-1
Parent:         NET-199-0-0-0-0
NetType:        Direct Assignment
RegDate:        2011-10-17
Updated:        2012-03-02
Ref:            http://whois.arin.net/rest/net/NET-199-27-72-0-1

OrgName:        Fastly
OrgId:          SKYCA-3
Address:        346 1st street #301
City:           San Francisco
StateProv:      CA
PostalCode:     94105
Country:        US
RegDate:        2011-09-16
Updated:        2013-01-25
Ref:            http://whois.arin.net/rest/org/SKYCA-3

OrgTechHandle: VUKSA-ARIN
OrgTechName:   Vuksan, Vladimir
OrgTechPhone:  +1-415-525-3481
OrgTechEmail:  vladimir@fastly.com
OrgTechRef:    http://whois.arin.net/rest/poc/VUKSA-ARIN

OrgAbuseHandle: ABE87-ARIN
OrgAbuseName:   Bergman, Artur
OrgAbusePhone:  +1-415-568-8829
OrgAbuseEmail:  sky+arin@crucially.net
OrgAbuseRef:    http://whois.arin.net/rest/poc/ABE87-ARIN

OrgTechHandle: HENDR43-ARIN
OrgTechName:   Hendrie, Chris
OrgTechPhone:  +1-410-703-8240
OrgTechEmail:  chris@fastly.com
OrgTechRef:    http://whois.arin.net/rest/poc/HENDR43-ARIN

OrgAbuseHandle: VUKSA-ARIN
OrgAbuseName:   Vuksan, Vladimir
OrgAbusePhone:  +1-415-525-3481
OrgAbuseEmail:  vladimir@fastly.com
OrgAbuseRef:    http://whois.arin.net/rest/poc/VUKSA-ARIN

OrgTechHandle: ABE87-ARIN
OrgTechName:   Bergman, Artur
OrgTechPhone:  +1-415-568-8829
OrgTechEmail:  sky+arin@crucially.net
OrgTechRef:    http://whois.arin.net/rest/poc/ABE87-ARIN

OrgAbuseHandle: HENDR43-ARIN
OrgAbuseName:   Hendrie, Chris
OrgAbusePhone:  +1-410-703-8240
OrgAbuseEmail:  chris@fastly.com
OrgAbuseRef:    http://whois.arin.net/rest/poc/HENDR43-ARIN


#
# ARIN WHOIS data and services are subject to the Terms of Use
# available at: https://www.arin.net/whois_tou.html
#


end whois lasthop for (199.27.76.133)
start list of email contacts:
vladimir@fastly.com
sky+arin@crucially.net
chris@fastly.com
vladimir@fastly.com
sky+arin@crucially.net
chris@fastly.com

end list of email contacts:
start transcript of session:
DEBUG output created by Wget 1.12 on linux-gnu.

--2013-06-20 13:39:53-- 
https://raw.github.com/inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe
Resolving raw.github.com... 199.27.76.133
Caching raw.github.com => 199.27.76.133
Connecting to raw.github.com|199.27.76.133|:443... connected.
Created socket 5.
Releasing 0x00000000025eab80 (new refcount 1).
Initiating SSL handshake.
Handshake successful; connected socket 5 to SSL handle 0x00000000025ead00
certificate:
  subject: /C=US/ST=California/L=San Francisco/O=Github, Inc./CN=*.github.com
  issuer:  /C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High Assurance CA-3
X509 certificate successfully verified and matches host raw.github.com

---request begin---
GET /inquisb/shellcodeexec/master/windows/shellcodeexec.x32.exe HTTP/1.0
Pragma: no-cache
User-Agent: Mozilla/5.0 (compatible; en-US)
Accept: */*
Host: raw.github.com

---request end---
HTTP request sent, awaiting response... 
---response begin---
HTTP/1.1 200 OK
Date: Thu, 20 Jun 2013 11:39:53 GMT
Server: GitHub.com
Content-Type: application/octet-stream
Status: 200 OK
X-RateLimit-Limit: 100
X-RateLimit-Remaining: 100
X-Frame-Options: deny
Access-Control-Allow-Origin: https://render.github.com
X-Content-Type-Options: nosniff
Content-Disposition: attachment; filename=shellcodeexec.x32.exe
Content-Transfer-Encoding: binary
X-Runtime: 12
ETag: "6635db0651061b0669bd8c1c524bfde5"
Content-Length: 5632
Accept-Ranges: bytes
Via: 1.1 varnish
Age: 0
X-Served-By: cache-a16-AMS
X-Cache: MISS
X-Cache-Hits: 0
Vary: Accept-Encoding
Cache-Control: private
Connection: close

---response end---

  HTTP/1.1 200 OK
  Date: Thu, 20 Jun 2013 11:39:53 GMT
  Server: GitHub.com
  Content-Type: application/octet-stream
  Status: 200 OK
  X-RateLimit-Limit: 100
  X-RateLimit-Remaining: 100
  X-Frame-Options: deny
  Access-Control-Allow-Origin: https://render.github.com
  X-Content-Type-Options: nosniff
  Content-Disposition: attachment; filename=shellcodeexec.x32.exe
  Content-Transfer-Encoding: binary
  X-Runtime: 12
  ETag: "6635db0651061b0669bd8c1c524bfde5"
  Content-Length: 5632
  Accept-Ranges: bytes
  Via: 1.1 varnish
  Age: 0
  X-Served-By: cache-a16-AMS
  X-Cache: MISS
  X-Cache-Hits: 0
  Vary: Accept-Encoding
  Cache-Control: private
  Connection: close
Length: ignored [application/octet-stream]
Saving to: `/tmp/BARR2TeFR'

     0K .....                                                   151K=0.04s

Closed 5/SSL 0x00000000025ead00
2013-06-20 13:39:53 (151 KB/s) - `/tmp/BARR2TeFR' saved [5632]


end transcript of session
start of offending raw content:
MZÿÿ¸@ິ	Í!¸LÍ!This program cannot be run in DOS mode.

$­c+¨éEûéEûéEûÎÄ>ûëEûÎÄ+ûèEûÎÄ8ûèEûÎÄ(ûýEû*
ûêEûéDûÂEûÎÄ4ûèEûÎÄ=ûèEûRichéEûPEL±¬©Mà
l
@Pô!<@¬!@.textÒ
`.rdataà
@@.data„0@À.rsrc¬@@@ƒ|$}hØ
@ÿ¤ @Yjÿÿ  @‹D$ÿpèYjëéU‹ìQ‹EPŠ@„ÉuùVW+Âj@‹ðhFPjÿ @Vÿu‹øWÿ¨ @ƒÄjÿEüPjWh‹@jjÿ @Pÿ
@_3À^ÉÃjhØ!@èÕƒeü‹EÿÐë3À@ËeèÇEüþÿÿÿ3ÀèúÂ;
0@uóÃé­hU@èL¡`3@Ç$,0@ÿ5\3@£,0@h0@h
0@h0@ÿ˜ @ƒÄ…À£(0@}jèhYÃjhx!@èL3ۉ]üd¡‹p‰]ä¿t3@SVWÿ0 @;Ãt;Æu3öF‰uäëhèÿ4 @ëÚ3öF¡p3@;Æu
jèYë;¡p3@…Àu,‰5p3@hÈ @hÀ @èÔYY…ÀtÇEüþÿÿÿ¸ÿé݉540@¡p3@;Æuh¼ @h´ @è™YYÇp3@9]äuSWÿ8
@9€3@th€3@èY…Àt
SjSÿ€3@¡0@‹
ˆ @‰ÿ50@ÿ5 0@ÿ50@èÝýÿÿƒÄ£00@9$0@u7Pÿ  @‹Eì‹‹	‰MàPQè/YYËeè‹Eà£00@3Û9$0@uPÿ
@940@uÿ”
@ÇEüþÿÿÿ¡00@è(Ãf=@MZt3ÀëQ¡<@¸@PEuë·ˆ@ùtùuԃ¸„@vË3É9ˆø@냸t@v¸3É9ˆè@•Á‹Áj£$0@ÿT
@jÿÿP @YY£x3@£|3@ÿL @‹
h3@‰ÿH @‹
d3@‰¡D @‹£l3@èùèÔƒ=0@uh@ÿX @Y葃=0@ÿu	jÿÿ|
@Y3ÀÃè£éžýÿÿU‹ìì(£@1@‰
<1@‰81@‰41@‰501@‰=,1@fŒX1@fŒ
L1@fŒ(1@fŒ$1@fŒ%
1@fŒ-1@œP1@‹E£D1@‹E£H1@E£T1@‹…àüÿÿǐ0@¡H1@£D0@Ç80@	ÀÇ<0@¡0@‰…Øüÿÿ¡0@‰…Üüÿÿÿ
@£ˆ0@jègYjÿ  @hÐ @ÿ$ @ƒ=ˆ0@ujèCYh	Àÿ( @Pÿ, @ÉÃÿ%œ @jh˜!@èàÿ5|3@‹5l @ÿÖY‰E䃸ÿuÿuÿh
@YëajèYƒeüÿ5|3@ÿ։Eäÿ5x3@ÿ։EàEàPEäPÿuèÓ‰EÜÿuä‹5P
@ÿÖ£|3@ÿuàÿփÄ£x3@ÇEüþÿÿÿè	‹EÜèœÃjè‘YÃÿt$èXÿÿÿ÷ØÀ÷ØYHÃVW¸h!@¿h!@;Njðs‹…ÀtÿЃÆ;÷rñ_^ÃVW¸p!@¿p!@;Njðs‹…ÀtÿЃÆ;÷rñ_^ÃÌÿ%Œ
@‹L$f9MZt3ÀËA<Á8PEuð3Éfx”Á‹ÁÃÌÌÌÌÌÌ̋D$‹H<È·ASV·q3҅öWDv‹|$‹H;ùr	‹XÙ;ûrƒÂƒÀ(;Öræ3À_^[Ãjh¸!@ènƒeüº@RèsÿÿÿY…Àt=‹E+ÂPRè’ÿÿÿYY…Àt+‹@$Áè÷ЃàÇEüþÿÿÿë
‹E싋3É=À”Á‹ÁËeèÇEüþÿÿÿ3ÀèTÃÿ%„ @ÿ%€
@ÌÌhÅ@dÿ5‹D$‰l$l$+àSVW¡0@1Eü3ÅP‰eèÿuø‹EüÇEüþÿÿÿ‰EøEðd£Ã‹Mðd‰
Y__^[‹å]QÃÿt$ÿt$ÿt$ÿt$hº@h0@è܃ÄÃVhh3öVèуÄ…Àt
VVVVV躃Ä^Ã3ÀÃU‹ìƒì¡0@ƒeøƒeüSW¿Næ@»;Ç»ÿÿt
…Ãt	÷У0@ë`VEøPÿ<
@‹uü3uøÿ @3ðÿ @3ðÿ @3ðEðPÿ @‹Eô3Eð3ð;÷u¾Oæ@»ë…óu‹ÆÁàð‰50@÷։50@^_[ÉÃÿ%¬ @ÿ%\ @ÿ%` @ÿ%d @ÿ%p
@ÿ%t @ÿ%x
@þ"#"#0#F#Z#h#‚#–#´#Î#â#ô#$$.$H$V$d$p$‚$’$¤$®$¼$Ä$Î$à$ú$
%%.%<%H%T%b%j%r%‚%Ž%”%œ%¦%É@Š@80@0@Run:
	shellcodeexec <alphanumeric-encoded shellcode>
H0@`!@ÅþÿÿÿÐÿÿÿþÿÿÿ:@N@þÿÿÿÌÿÿÿþÿÿÿ@þÿÿÿØÿÿÿþÿÿÿ8@L@þÿÿÿØÿÿÿþÿÿÿ¢@¦@ä"
ñ"D
KERNEL32.DLLMSVCR80.dllWaitForSingleObjectVirtualAllocCreateThreadGetCurrentProcessIdGetCurrentThreadIdGetTickCountQueryPerformanceCounterIsDebuggerPresentSetUnhandledExceptionFilterUnhandledExceptionFilterGetCurrentProcessTerminateProcessInterlockedCompareExchangeSleepInterlockedExchangeGetSystemTimeAsFileTime_adjust_fdiv__p__commode__p__fmode_encode_pointer__set_app_type__setusermatherr_unlock__dllonexit_lock_onexit_decode_pointer_except_handler4_common_invoke_watson_controlfp_s_configthreadlocale_initterm_e_initterm__initenv_XcptFilter_exit_cexit__getmainargs_amsg_exitexitprintfstrncpy_crt_debugger_hookNæ@»±¿Dÿÿÿÿÿÿÿÿþÿÿÿ€0€	HX@Rä<assembly
xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
  <dependency>
    <dependentAssembly>
      <assemblyIdentity type="win32" name="Microsoft.VC80.CRT" version="8.0.50608.0" processorArchitecture="x86"
publicKeyToken="1fc8b3b9a1e18e3b"></assemblyIdentity>
    </dependentAssembly>
  </dependency>
</assembly>PA
end of offending raw content