CLEAN MX realtime database    
public access query for virus URL statistics
Totally watched: 825273 As of 2013-06-20 05:31:32 CEST

you have also some phishing incidents open see: click here for these incidents (147)


you have also some portals incidents open see: click here for these incidents (2074)

Subscribe to the VirusWatch Mailing list, updated hourly

This database consists of Virus URI, collected and verified since Feb 2006
Tweet
If you detect URI'S concerning your netblock, already closed... you have made a good job, otherwise please close them as soon as possible.

to look at some nice charts, there are complete statisticsstatistics for this database
Attention: all URI'S are manually verified, but not cross-checked for real viruses function in this moment you make this query.(Sites may have been closed already..)
Our automatic Viruswalker process is scheduled every hour, so you may see now a incident and this one will be resolved later on.
So please keep on sending close-feedbacks to us...

if you have questions, criticism, wishes or ... do not hesitate to contact us at abuse@clean-mx.de
Our PBX is down you may reach us by cell phone +49 171 4802507 ...
malware impact on country PL
Query as xml: Same query as xml output
TIMERS: Runtime Query: 3.8086 Seconds 10 hits
helpLine help#descendigascending helpDatedescendigascending helpCloseddescendigascending helphours helpcontributordescendigascending helpvirusnamedescendigascending helpURLdescendigascending helpip state helpresponsedescendigascending helpIp initialdescendigascending helpAS#descendigascending helpip reviewdescendigascending helpURLdescendigascending helpDomaindescendigascending helpcountrydescendigascending helpsourcedescendigascending helpemaildescendigascending helpinetnumdescendigascending helpnetnamedescendigascending helpdescrdescendigascending helpns1descendigascending helpns2descendigascending helpns3descendigascending helpns4descendigascending helpns5descendigascending helpURLdescendigascending
1 follow up this item(12218225) 12218225 Report false positive Report closed case make a suggestion 2013-06-20 04:30:06     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
2/36 (5.6%) 
 
TrojWare.HTML.Agent.IM
HTML/IFrame.igmk 
 lookup in virustotal.com (50cd368ddf2fb8d70c3b031db12ac194)-->[http://www.virustotal.com/latest-report.html?resource=50cd368ddf2fb8d70c3b031db12ac194]follow up this md5sum(50cd368ddf2fb8d70c3b031db12ac194)follow up this itemfollow up this virusname (HTML%2FIFrame.igmk) as RSS-Feedfollow up this malware(HTML%2FIFrame.igmk) for scanner (AntiVir) in md5 table2/36 (5.6%) HTML/IFrame.igmk
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://gobucyvetiw.htw.pl/  up No previous evidence recordedSaved evidence (32338 Bytes) of last contact as txt June 20 2013 04:33:55 CEST. aliveSaved log of last contact as txt June 20 2013 04:33:55 CEST. SenderBaselookup 194.9.24.158 at virustotallookup 194.9.24.158 at Rus CERT university stuttgart germanylookup 194.9.24.158 at Ripefollow up this item(ip) in same window 194.9.24.158 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS41406) in networks tablefollow up this itemfollow up this AS (AS41406) as RSS-Feed AS41406 SenderBaselookup 194.9.24.158 at virustotallookup 194.9.24.158 at Rus CERT university stuttgart germanylookup 194.9.24.158 at Ripefollow up this item(review) in same window 194.9.24.158 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://gobucyvetiw.htw.pl/ lookup htw.pl at virustotalfollow up this domain(htw.pl) htw.pl follow up this itemfollow up this country (PL) as RSS-Feed PL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (noc@sabela.pl) as RSS-Feed noc@sabela.pl follow up this itemfollow up this item 194.9.24.0 - 194.9.25.255 follow up this item CRMedia follow up this item CR Media S.A.CRMediaCR Media S.A. follow up this item ns131.grupapino.pl follow up this item ns130.grupapino.pl follow up this item ns143.grupapino.pl follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://gobucyvetiw.htw.pl/
2 follow up this item(12217971) 12217971 Report false positive Report closed case make a suggestion 2013-06-20 04:10:10     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
19/47 (40.4%) 
 Gen:Variant.Kazy.181677
RDN/Generic
BackDoor!qo
WS.Reputation.1
TROJ_GEN.R0CBC0DFJ13
Trojan.MSIL.Disfa.atcc
Gen:Variant.Kazy.181677
Mal/Generic-S
UnclassifiedMalware
Gen:Variant.Kazy.181677
Trojan.Win32.Generic!BT
TR/MSIL.Disfa.atcc
TROJ_GEN.R0CBC0DFJ13
 
 lookup in virustotal.com (615dc48ef0ba3e2f90d83e6505fd7365)-->[http://www.virustotal.com/latest-report.html?resource=615dc48ef0ba3e2f90d83e6505fd7365]follow up this md5sum(615dc48ef0ba3e2f90d83e6505fd7365)follow up this itemfollow up this virusname (Trj%2FCI.A) as RSS-Feedfollow up this malware(Trj%2FCI.A) for scanner (undef) in md5 table19/47 (40.4%) Trj/CI.A
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://babyboo.pl/images/Metin2Hack.rar  up No previous evidence recordedSaved evidence (87287 Bytes) of last contact as txt June 17 2013 20:05:20 CEST. aliveSaved log of last contact as txt June 20 2013 04:33:21 CEST. SenderBaselookup 89.146.199.134 at virustotallookup 89.146.199.134 at Rus CERT university stuttgart germanylookup 89.146.199.134 at Ripefollow up this item(ip) in same window 89.146.199.134 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS8495) in networks tablefollow up this itemfollow up this AS (AS8495) as RSS-Feed AS8495 SenderBaselookup 89.146.199.134 at virustotallookup 89.146.199.134 at Rus CERT university stuttgart germanylookup 89.146.199.134 at Ripefollow up this item(review) in same window 89.146.199.134 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://babyboo.pl/images/Metin2Hack.rar lookup babyboo.pl at virustotalfollow up this domain(babyboo.pl) babyboo.pl follow up this itemfollow up this country (PL) as RSS-Feed PL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (admin@lh.pl) as RSS-Feed admin@lh.pl follow up this itemfollow up this item 89.146.199.128 - 89.146.199.255 follow up this item LH-NET follow up this item Light Hosting NETINTERNIC GmbH follow up this item ns2.lighthosting.net follow up this item ns.lh.pl follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://babyboo.pl/images/Metin2Hack.rar
3 follow up this item(12217822) 12217822 Report false positive Report closed case make a suggestion 2013-06-20 03:40:26     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
2/47 (4.3%) 
 TrojWare.HTML.Agent.IM
HTML/IFrame.igmk 
 lookup in virustotal.com (383a5bcc826d1d824f73350d465219ce)-->[http://www.virustotal.com/latest-report.html?resource=383a5bcc826d1d824f73350d465219ce]follow up this md5sum(383a5bcc826d1d824f73350d465219ce)follow up this itemfollow up this virusname (HTML%2FIFrame.igmk) as RSS-Feedfollow up this malware(HTML%2FIFrame.igmk) for scanner (undef) in md5 table2/47 (4.3%) HTML/IFrame.igmk
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://usuwewesojec.xlx.pl/  up No previous evidence recordedSaved evidence (54026 Bytes) of last contact as txt June 20 2013 04:06:59 CEST. aliveSaved log of last contact as txt June 20 2013 04:06:59 CEST. SenderBaselookup 194.9.24.158 at virustotallookup 194.9.24.158 at Rus CERT university stuttgart germanylookup 194.9.24.158 at Ripefollow up this item(ip) in same window 194.9.24.158 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS41406) in networks tablefollow up this itemfollow up this AS (AS41406) as RSS-Feed AS41406 SenderBaselookup 194.9.24.158 at virustotallookup 194.9.24.158 at Rus CERT university stuttgart germanylookup 194.9.24.158 at Ripefollow up this item(review) in same window 194.9.24.158 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://usuwewesojec.xlx.pl/ lookup xlx.pl at virustotalfollow up this domain(xlx.pl) xlx.pl follow up this itemfollow up this country (PL) as RSS-Feed PL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (noc@sabela.pl) as RSS-Feed noc@sabela.pl follow up this itemfollow up this item 194.9.24.0 - 194.9.25.255 follow up this item CRMedia follow up this item CR Media S.A.CRMediaCR Media S.A. follow up this item ns143.grupapino.pl follow up this item ns131.grupapino.pl follow up this item ns130.grupapino.pl follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://usuwewesojec.xlx.pl/
4 follow up this item(12217342) 12217342 Report false positive Report closed case make a suggestion 2013-06-20 03:40:08     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
19/36 (52.8%) 
 
Trojan.Script.BBO
JS/BlacoleRef.CZB
JS/Exploit-Blacole.le
IFrame.gen
BlacoleRef.BF
JS:Decode-AJU
Trj
Trojan.JS.Agent.cbn
Trojan.Script.BBO
Trojan.Script.BBO
(B)
TrojWare.JS.Agent.NB
Trojan.Script.BBO
JS.IFrame.454
JS/Agent.bbo.1
Heuristic.LooksLike.HTML 
 lookup in virustotal.com (8cb9890b135190d40bd346edd27581d4)-->[http://www.virustotal.com/latest-report.html?resource=8cb9890b135190d40bd346edd27581d4]follow up this md5sum(8cb9890b135190d40bd346edd27581d4)follow up this itemfollow up this virusname (HTML%2FInfected.WebPage.Gen3) as RSS-Feedlookup Virusname at avirafollow up this malware(HTML%2FInfected.WebPage.Gen3) for scanner (avira) in md5 table19/36 (52.8%) HTML/Infected.WebPage.Gen3
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://crohn.pl/  up No previous evidence recordedSaved evidence (11062 Bytes) of last contact as txt June 20 2013 04:17:52 CEST. aliveSaved log of last contact as txt June 20 2013 04:17:52 CEST. SenderBaselookup 89.146.199.134 at virustotallookup 89.146.199.134 at Rus CERT university stuttgart germanylookup 89.146.199.134 at Ripefollow up this item(ip) in same window 89.146.199.134 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS8495) in networks tablefollow up this itemfollow up this AS (AS8495) as RSS-Feed AS8495 SenderBaselookup 89.146.199.134 at virustotallookup 89.146.199.134 at Rus CERT university stuttgart germanylookup 89.146.199.134 at Ripefollow up this item(review) in same window 89.146.199.134 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://crohn.pl/ lookup crohn.pl at virustotalfollow up this domain(crohn.pl) crohn.pl follow up this itemfollow up this country (PL) as RSS-Feed PL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (admin@lh.pl) as RSS-Feed admin@lh.pl follow up this itemfollow up this item 89.146.199.128 - 89.146.199.255 follow up this item LH-NET follow up this item Light Hosting NETINTERNIC GmbH follow up this item ns.lh.pl follow up this item ns2.lighthosting.net follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://crohn.pl/
5 follow up this item(12216773) 12216773 Report false positive Report closed case make a suggestion 2013-06-20 02:40:42     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
22/46 (47.8%) 
 Trojan.JS.Redirector.VP
Riskware
Trojan.Script.Twetti.bbpkpt
JS/Crypted.PF
Iframe.RZ
JS:Twetti-C
[Trj]
Trojan-Downloader.JS.Twetti.s
Trojan.JS.Redirector.VP
Troj/Twetti-B
TrojWare.JS.Agent.S
JS.Twitter.4
Trojan-Downloader.JS.Twettir.t
(v)
JS/Twetti.S
Tro 
 lookup in virustotal.com (b25bbb923e38623bf2285e8c2311e677)-->[http://www.virustotal.com/latest-report.html?resource=b25bbb923e38623bf2285e8c2311e677]follow up this md5sum(b25bbb923e38623bf2285e8c2311e677)follow up this itemfollow up this virusname (JS%2FTwetti.S) as RSS-Feedlookup Virusname at avirafollow up this malware(JS%2FTwetti.S) for scanner (avira) in md5 table22/46 (47.8%) JS/Twetti.S
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://szotartstudio.com/ENG/index.html  up No previous evidence recordedSaved evidence (10548 Bytes) of last contact as txt January 15 2013 17:40:33 CET. aliveSaved log of last contact as txt June 20 2013 03:08:16 CEST. SenderBaselookup 194.169.227.130 at virustotallookup 194.169.227.130 at Rus CERT university stuttgart germanylookup 194.169.227.130 at Ripefollow up this item(ip) in same window 194.169.227.130 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS41079) in networks tablefollow up this itemfollow up this AS (AS41079) as RSS-Feed AS41079 SenderBaselookup 194.169.227.130 at virustotallookup 194.169.227.130 at Rus CERT university stuttgart germanylookup 194.169.227.130 at Ripefollow up this item(review) in same window 194.169.227.130 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://szotartstudio.com/ENG/index.html lookup szotartstudio.com at virustotalfollow up this domain(szotartstudio.com) szotartstudio.com follow up this itemfollow up this country (PL) as RSS-Feed PL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@superhost.pl) as RSS-Feed abuse@superhost.pl follow up this itemfollow up this item 194.169.227.0 - 194.169.227.255 follow up this item SUPERHOST-PL follow up this item SuperHost.pl sp. z o.o.! - ! - ! - ! - ! - ! - ! - ! - ! - ! - !Please send spam and abuse notificationonly to! - ! - ! - ! - ! - ! - ! - ! - ! - ! - ! follow up this item ns1.aidahosting.com follow up this item ns2.aidahosting.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://szotartstudio.com/ENG/index.html
6 follow up this item(12216305) 12216305 Report false positive Report closed case make a suggestion 2013-06-20 02:00:56     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
5/47 (10.6%) 
 W32/SmallTrojan.AR.gen!Eldorado
Suspicious_Gen4.EDRNN
TROJ_GEN.R47H1GP
Mal/Zbot-DY
W32/SmallTrojan.AR.gen!Eldorado 
 lookup in virustotal.com (e8fc0e305b5988e77eb3a3950258412e)-->[http://www.virustotal.com/latest-report.html?resource=e8fc0e305b5988e77eb3a3950258412e]lookup in threatexpert.comlookup the sha256(86e65cdcf923b74da1b0228cec4cd400351bccd6ba482383a43f91a680773f49) in comodo.comfollow up this md5sum(e8fc0e305b5988e77eb3a3950258412e)follow up this itemfollow up this virusname (Mal%2FZbot-DY) as RSS-Feedfollow up this malware(Mal%2FZbot-DY) for scanner (undef) in md5 table5/47 (10.6%) Mal/Zbot-DY
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://zambari.art.pl/inne/XviD-1.0-Beta ...  up No previous evidence recordedSaved evidence (378922 Bytes) of last contact as txt June 08 2006 00:21:06 CEST. aliveSaved log of last contact as txt June 20 2013 02:08:37 CEST. SenderBaselookup 194.169.227.130 at virustotallookup 194.169.227.130 at Rus CERT university stuttgart germanylookup 194.169.227.130 at Ripefollow up this item(ip) in same window 194.169.227.130 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS41079) in networks tablefollow up this itemfollow up this AS (AS41079) as RSS-Feed AS41079 SenderBaselookup 194.169.227.130 at virustotallookup 194.169.227.130 at Rus CERT university stuttgart germanylookup 194.169.227.130 at Ripefollow up this item(review) in same window 194.169.227.130 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://zambari.art.pl/inne/XviD-1.0-Beta ... lookup zambari.art.pl at virustotalfollow up this domain(zambari.art.pl) zambari.art.pl follow up this itemfollow up this country (PL) as RSS-Feed PL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@superhost.pl) as RSS-Feed abuse@superhost.pl follow up this itemfollow up this item 194.169.227.0 - 194.169.227.255 follow up this item SUPERHOST-PL follow up this item SuperHost.pl sp. z o.o.! - ! - ! - ! - ! - ! - ! - ! - ! - ! - !Please send spam and abuse notificationonly to! - ! - ! - ! - ! - ! - ! - ! - ! - ! - ! follow up this item fns2.42.pl follow up this item fns1.42.pl follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://zambari.art.pl/inne/XviD-1.0-Beta ...
7 follow up this item(12213232) 12213232 Report false positive Report closed case make a suggestion 2013-06-19 23:40:25     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
14/47 (29.8%) 
 Trojan.Iframe.BMY
Trojan.Html.Iframe.brfdrk
Iframe.gen
HTML:Iframe-ZG
[Trj]
Trojan.JS.Iframe.aeq
Trojan.Iframe.BMY
TrojWare.JS.Iframe.GJ
Trojan.Iframe.BMY
JS.IFrame.425
HTML/Infected.WebPage.Gen3
Heuristic.LooksLike.HTML.Infected.B
Trojan.Iframe.BMY
(B)
 
 lookup in virustotal.com (15ae0ce4e15ec2dcbfbcb23d88407af0)-->[http://www.virustotal.com/latest-report.html?resource=15ae0ce4e15ec2dcbfbcb23d88407af0]follow up this md5sum(15ae0ce4e15ec2dcbfbcb23d88407af0)follow up this itemfollow up this virusname (JS%2FIframe.BMY%21tr) as RSS-Feedfollow up this malware(JS%2FIframe.BMY%21tr) for scanner (undef) in md5 table14/47 (29.8%) JS/Iframe.BMY!tr
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://rafalpietrzyk.kei.pl/  up No previous evidence recordedSaved evidence (453 Bytes) of last contact as txt June 20 2013 00:17:58 CEST. aliveSaved log of last contact as txt June 20 2013 00:17:58 CEST. SenderBaselookup 94.152.8.37 at virustotallookup 94.152.8.37 at Rus CERT university stuttgart germanylookup 94.152.8.37 at Ripefollow up this item(ip) in same window 94.152.8.37 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29522) in networks tablefollow up this itemfollow up this AS (AS29522) as RSS-Feed AS29522 SenderBaselookup 94.152.8.37 at virustotallookup 94.152.8.37 at Rus CERT university stuttgart germanylookup 94.152.8.37 at Ripefollow up this item(review) in same window 94.152.8.37 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://rafalpietrzyk.kei.pl/ lookup kei.pl at virustotalfollow up this domain(kei.pl) kei.pl follow up this itemfollow up this country (PL) as RSS-Feed PL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@kei.pl) as RSS-Feed abuse@kei.pl follow up this itemfollow up this item 94.152.0.0 - 94.152.127.255 follow up this item KEI follow up this item Hosting Servers follow up this item ns1.kei.pl follow up this item ns2.kei.pl follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://rafalpietrzyk.kei.pl/
8 follow up this item(12212846) 12212846 Report false positive Report closed case make a suggestion 2013-06-19 23:40:04     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
13/47 (27.7%) 
 Trojan.Iframe.BMY
Trojan.Html.Iframer.bprxev
Iframe.gen
HTML:Iframe-ZG
[Trj]
Trojan.JS.Iframe.aeq
Trojan.Iframe.BMY
TrojWare.JS.Iframe.GJ
Trojan.Iframe.BMY
JS.IFrame.425
HTML/Infected.WebPage.Gen3
Trojan.Iframe.BMY
(B)
Trojan.Iframe.BMY
JS/Iframe.BMY!tr 
 lookup in virustotal.com (44778edb9391979e4b34fd52c6419025)-->[http://www.virustotal.com/latest-report.html?resource=44778edb9391979e4b34fd52c6419025]follow up this md5sum(44778edb9391979e4b34fd52c6419025)follow up this itemfollow up this virusname (JS%2FIframe.BMY%21tr) as RSS-Feedfollow up this malware(JS%2FIframe.BMY%21tr) for scanner (undef) in md5 table13/47 (27.7%) JS/Iframe.BMY!tr
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://ameba.be/  up No previous evidence recordedSaved evidence (218 Bytes) of last contact as txt June 20 2013 00:22:14 CEST. aliveSaved log of last contact as txt June 20 2013 00:22:14 CEST. SenderBaselookup 94.152.8.37 at virustotallookup 94.152.8.37 at Rus CERT university stuttgart germanylookup 94.152.8.37 at Ripefollow up this item(ip) in same window 94.152.8.37 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29522) in networks tablefollow up this itemfollow up this AS (AS29522) as RSS-Feed AS29522 SenderBaselookup 94.152.8.37 at virustotallookup 94.152.8.37 at Rus CERT university stuttgart germanylookup 94.152.8.37 at Ripefollow up this item(review) in same window 94.152.8.37 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://ameba.be/ lookup ameba.be at virustotalfollow up this domain(ameba.be) ameba.be follow up this itemfollow up this country (PL) as RSS-Feed PL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@kei.pl) as RSS-Feed abuse@kei.pl follow up this itemfollow up this item 94.152.0.0 - 94.152.127.255 follow up this item KEI follow up this item Hosting Servers follow up this item ns1.kei.pl follow up this item ns2.kei.pl follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://ameba.be/
9 follow up this item(12212123) 12212123 Report false positive Report closed case make a suggestion 2013-06-19 22:40:13     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
16/47 (34%) 
 Trojan.JS.Iframe.DDB
Trojan.Url.IframeB.brcedc
IFrame.gen
Iframe.XA
HTML:Iframe-AHZ
[Trj]
Trojan.JS.Iframe.DDB
TrojWare.JS.Iframe.HD
Trojan.JS.Iframe.DDB
JS/iFrame.ddb
Trojan.JS.Iframe.DDB
(B)
Exploit:HTML/IframeRef.EU
Trojan.JS.Iframe.DDB
IFrame.gen
HTM 
 lookup in virustotal.com (02de50b95ae83410f5b8cd5a74752523)-->[http://www.virustotal.com/latest-report.html?resource=02de50b95ae83410f5b8cd5a74752523]follow up this md5sum(02de50b95ae83410f5b8cd5a74752523)follow up this itemfollow up this virusname (cleanmx_generic) as RSS-Feedfollow up this malware(cleanmx_generic) for scanner (undef) in md5 table16/47 (34%) cleanmx_generic
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://prosprzatanie.pl/  up No previous evidence recordedSaved evidence (208 Bytes) of last contact as txt April 12 2013 00:54:33 CEST. aliveSaved log of last contact as txt June 19 2013 23:08:34 CEST. SenderBaselookup 195.242.92.3 at virustotallookup 195.242.92.3 at Rus CERT university stuttgart germanylookup 195.242.92.3 at Ripefollow up this item(ip) in same window 195.242.92.3 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS34324) in networks tablefollow up this itemfollow up this AS (AS34324) as RSS-Feed AS34324 SenderBaselookup 195.242.92.3 at virustotallookup 195.242.92.3 at Rus CERT university stuttgart germanylookup 195.242.92.3 at Ripefollow up this item(review) in same window 195.242.92.3 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://prosprzatanie.pl/ lookup prosprzatanie.pl at virustotalfollow up this domain(prosprzatanie.pl) prosprzatanie.pl follow up this itemfollow up this country (PL) as RSS-Feed PL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@nq.pl) as RSS-Feed abuse@nq.pl follow up this itemfollow up this item 195.242.92.0 - 195.242.93.255 follow up this item NETLINK-NET follow up this item NetLink sp. z o. o. follow up this item ns1.netlink.com.pl follow up this item ns2.netlink.com.pl follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://prosprzatanie.pl/
10 follow up this item(12212020) 12212020 Report false positive Report closed case make a suggestion 2013-06-19 22:40:09     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
19/46 (41.3%) 
 Trojan.Iframe.CEG
JS/IFrame.gen.j
Trojan.Html.TwitScroll.bklyhq
Trojan.Malscript!JS
Iframe.UW
JS:Iframe-AMJ
[Trj]
HEUR:Trojan.Script.Generic
Trojan.Iframe.CEG
TrojWare.HTML.Iframe.G
Exploit.HTML.Iframe.dm
(v)
HTML/TwitScroll.B
JS/IFrame.gen.j
Trojan.Ifra 
 lookup in virustotal.com (c823415f1a5e200003bb4fcde0cb6feb)-->[http://www.virustotal.com/latest-report.html?resource=c823415f1a5e200003bb4fcde0cb6feb]follow up this md5sum(c823415f1a5e200003bb4fcde0cb6feb)follow up this itemfollow up this virusname (HTML%2FFramer) as RSS-Feedfollow up this malware(HTML%2FFramer) for scanner (undef) in md5 table19/46 (41.3%) HTML/Framer
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://gmtechnics.pl/  up No previous evidence recordedSaved evidence (253 Bytes) of last contact as txt November 09 2012 00:57:42 CET. aliveSaved log of last contact as txt June 19 2013 23:09:18 CEST. SenderBaselookup 178.255.45.108 at virustotallookup 178.255.45.108 at Rus CERT university stuttgart germanylookup 178.255.45.108 at Ripefollow up this item(ip) in same window 178.255.45.108 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS197155) in networks tablefollow up this itemfollow up this AS (AS197155) as RSS-Feed AS197155 SenderBaselookup 178.255.45.108 at virustotallookup 178.255.45.108 at Rus CERT university stuttgart germanylookup 178.255.45.108 at Ripefollow up this item(review) in same window 178.255.45.108 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://gmtechnics.pl/ lookup gmtechnics.pl at virustotalfollow up this domain(gmtechnics.pl) gmtechnics.pl follow up this itemfollow up this country (PL) as RSS-Feed PL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (piotr@artnet.pl) as RSS-Feed piotr@artnet.pl follow up this itemfollow up this item 178.255.40.0 - 178.255.47.255 follow up this item PL-ARTNET-20100701 follow up this item Artnet Spolka z ograniczona odpowiedzialnosciaArtnet Sp. z o.o. follow up this item ns1.vipower.pl follow up this item ns2.vipower.pl follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://gmtechnics.pl/
Click here for other already closed incidents for your country (PL)

Click here for other vital incidents



Protected by clean MX [Valid RSS] Valid HTML 4.01 Transitional CSS ist valide!
Access is provided for free and subject to these Terms and Conditions.