CLEAN MX realtime database    
public access query for virus URL statistics
Totally watched: 690288 As of 2013-05-24 05:32:03 CEST
Subscribe to the VirusWatch Mailing list, updated hourly

This database consists of Virus URI, collected and verified since Feb 2006
Tweet
If you detect URI'S concerning your netblock, already closed... you have made a good job, otherwise please close them as soon as possible.

to look at some nice charts, there are complete statisticsstatistics for this database
Attention: all URI'S are manually verified, but not cross-checked for real viruses function in this moment you make this query.(Sites may have been closed already..)
Our automatic Viruswalker process is scheduled every hour, so you may see now a incident and this one will be resolved later on.
So please keep on sending close-feedbacks to us...

if you have questions, criticism, wishes or ... do not hesitate to contact us at abuse@clean-mx.de
Our PBX is down you may reach us by cell phone +49 171 4802507 ...
Query as xml: Same query as xml output
TIMERS: Runtime Query: 9.1539 Seconds 10 hits
helpLine help#descendigascending helpDatedescendigascending helpCloseddescendigascending helphours helpcontributordescendigascending helpvirusnamedescendigascending helpURLdescendigascending helpip state helpresponsedescendigascending helpIp initialdescendigascending helpAS#descendigascending helpip reviewdescendigascending helpURLdescendigascending helpDomaindescendigascending helpcountrydescendigascending helpsourcedescendigascending helpemaildescendigascending helpinetnumdescendigascending helpnetnamedescendigascending helpdescrdescendigascending helpns1descendigascending helpns2descendigascending helpns3descendigascending helpns4descendigascending helpns5descendigascending helpURLdescendigascending
1 follow up this item(11394768) 11394768 Report false positive Report closed case make a suggestion 2013-05-24 05:00:55     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
lookup in virustotal.com (29a10d0281c0716205c57d37673277d1)follow up this md5sum(29a10d0281c0716205c57d37673277d1)follow up this itemfollow up this virusname (unknown_html) as RSS-Feedfollow up this malware(unknown_html) for scanner (undef) in md5 table0/43 (0.0%) unknown_html
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://ziphost.org/download/1e6cf5b5-bc7 ...  up No previous evidence recordedSaved evidence (1421 Bytes) of last contact as txt May 24 2013 05:12:33 CEST. aliveSaved log of last contact as txt May 24 2013 05:12:33 CEST. SenderBaselookup 5.149.248.134 at virustotallookup 5.149.248.134 at Rus CERT university stuttgart germanylookup 5.149.248.134 at Ripefollow up this item(ip) in same window 5.149.248.134 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS59711) in networks tablefollow up this itemfollow up this AS (AS59711) as RSS-Feed AS59711 SenderBaselookup 5.149.248.134 at virustotallookup 5.149.248.134 at Rus CERT university stuttgart germanylookup 5.149.248.134 at Ripefollow up this item(review) in same window 5.149.248.134 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://ziphost.org/download/1e6cf5b5-bc7 ... lookup ziphost.org at virustotalfollow up this domain(ziphost.org) ziphost.org follow up this itemfollow up this country (NL) as RSS-Feed NL follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE   follow up this itemfollow up this item 5.149.248.0 - 5.149.249.255 follow up this item FN-NA1 follow up this item FORTUNIX NETWORKS L.P.FortunixNetworks.NL follow up this item ns1.kind-dns.com follow up this item ns2.kind-dns.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://ziphost.org/download/1e6cf5b5-bc7 ...
2 follow up this item(11394767) 11394767 Report false positive Report closed case make a suggestion 2013-05-24 05:00:55     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
lookup in virustotal.com (504a5c0c5d7d824cce85fe273bd6733b)lookup in threatexpert.comlookup the sha256(fa9fb876e0eea0015d8634bf78e2ea0e9f1cd7f8a83706e52a5d67478baa617a) in comodo.comfollow up this md5sum(504a5c0c5d7d824cce85fe273bd6733b)follow up this itemfollow up this virusname (W32%2FDelf.I) as RSS-Feedlookup Virusname at avirafollow up this malware(W32%2FDelf.I) for scanner (avira) in md5 table40/45 (88.9%) W32/Delf.I
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://zalil.ru/34474617/7513c159.519f0d ...  up No previous evidence recordedSaved evidence (230400 Bytes) of last contact as txt April 29 2013 15:58:28 CEST. aliveSaved log of last contact as txt May 24 2013 05:13:07 CEST. SenderBaselookup 194.63.142.66 at virustotallookup 194.63.142.66 at Rus CERT university stuttgart germanylookup 194.63.142.66 at Ripefollow up this item(ip) in same window 194.63.142.66 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS21011) in networks tablefollow up this itemfollow up this AS (AS21011) as RSS-Feed AS21011 SenderBaselookup 194.63.142.66 at virustotallookup 194.63.142.66 at Rus CERT university stuttgart germanylookup 194.63.142.66 at Ripefollow up this item(review) in same window 194.63.142.66 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://zalil.ru/34474617/7513c159.519f0d ... lookup zalil.ru at virustotalfollow up this domain(zalil.ru) zalil.ru follow up this itemfollow up this country (RU) as RSS-Feed RU follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (tech@mirotel.net) as RSS-Feed tech@mirotel.net follow up this itemfollow up this item 194.63.140.0 - 194.63.143.255 follow up this item MIROTEL2 follow up this item ITS Mirotel follow up this item ns8-cloud.nic.ru follow up this item ns3-l2.nic.ru follow up this item ns4-cloud.nic.ru follow up this item ns8-l2.nic.ru follow up this item ns4-l2.nic.ru Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://zalil.ru/34474617/7513c159.519f0d ...
3 follow up this item(11394765) 11394765 Report false positive Report closed case make a suggestion 2013-05-24 05:00:55     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
18/35 (51.4%) 
 
Artemis!3CA319A7ACDB
Trojan/FakeAV.mozh
Trojan
WS.Reputation.1
W32/Suspicious_Gen4.BOPPU
TROJ_GEN.RFFH1FI
Gen:Variant.Zusy.7768
Trojan.Agent/Gen-Zusy
UnclassifiedMalware
TR/Rogue.kdv.629834
Heuristic.BehavesLike.Win32.ModifiedUPX.C
Gen:Variant.Zusy.7768 
 lookup in virustotal.com (3ca319a7acdbc6db55afed6ffaecf197)-->[http://www.virustotal.com/latest-report.html?resource=3ca319a7acdbc6db55afed6ffaecf197]lookup in threatexpert.comlookup the sha256(236628436843dc05e03544f70e3be20be9f5a59a56ffabba7f6f26a83326660f) in comodo.comfollow up this md5sum(3ca319a7acdbc6db55afed6ffaecf197)follow up this itemfollow up this virusname (TR%2FRogue.kdv.629834) as RSS-Feedlookup Virusname at avirafollow up this malware(TR%2FRogue.kdv.629834) for scanner (avira) in md5 table18/35 (51.4%) TR/Rogue.kdv.629834
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.un-jeu-par-jour.com/toolbar/t ...  up No previous evidence recordedSaved evidence (373429 Bytes) of last contact as txt May 24 2013 05:13:35 CEST. aliveSaved log of last contact as txt May 24 2013 05:13:35 CEST. SenderBaselookup 212.23.46.135 at virustotallookup 212.23.46.135 at Rus CERT university stuttgart germanylookup 212.23.46.135 at Ripefollow up this item(ip) in same window 212.23.46.135 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS8928) in networks tablefollow up this itemfollow up this AS (AS8928) as RSS-Feed AS8928 SenderBaselookup 212.23.46.135 at virustotallookup 212.23.46.135 at Rus CERT university stuttgart germanylookup 212.23.46.135 at Ripefollow up this item(review) in same window 212.23.46.135 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.un-jeu-par-jour.com/toolbar/t ... lookup un-jeu-par-jour.com at virustotalfollow up this domain(un-jeu-par-jour.com) un-jeu-par-jour.com follow up this itemfollow up this country (FR) as RSS-Feed FR follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (obouillaud@microapp.com) as RSS-Feed obouillaud@microapp.com follow up this itemfollow up this item 212.23.46.128 - 212.23.46.159 follow up this item MICROAPPLICATION-NETS follow up this item MICRO APPLICATIONInteroute Telecommunications (UK) Ltd follow up this item a.ns.zerigo.net follow up this item e.ns.zerigo.net follow up this item c.ns.zerigo.net follow up this item d.ns.zerigo.net follow up this item b.ns.zerigo.net Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.un-jeu-par-jour.com/toolbar/t ...
4 follow up this item(11394764) 11394764 Report false positive Report closed case make a suggestion 2013-05-24 05:00:55     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
18/35 (51.4%) 
 
Artemis!3CA319A7ACDB
Trojan/FakeAV.mozh
Trojan
WS.Reputation.1
W32/Suspicious_Gen4.BOPPU
TROJ_GEN.RFFH1FI
Gen:Variant.Zusy.7768
Trojan.Agent/Gen-Zusy
UnclassifiedMalware
TR/Rogue.kdv.629834
Heuristic.BehavesLike.Win32.ModifiedUPX.C
Gen:Variant.Zusy.7768 
 lookup in virustotal.com (3ca319a7acdbc6db55afed6ffaecf197)-->[http://www.virustotal.com/latest-report.html?resource=3ca319a7acdbc6db55afed6ffaecf197]lookup in threatexpert.comlookup the sha256(236628436843dc05e03544f70e3be20be9f5a59a56ffabba7f6f26a83326660f) in comodo.comfollow up this md5sum(3ca319a7acdbc6db55afed6ffaecf197)follow up this itemfollow up this virusname (TR%2FRogue.kdv.629834) as RSS-Feedlookup Virusname at avirafollow up this malware(TR%2FRogue.kdv.629834) for scanner (avira) in md5 table18/35 (51.4%) TR/Rogue.kdv.629834
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.un-jeu-par-jour.com/toolbar/t ...  up No previous evidence recordedSaved evidence (373429 Bytes) of last contact as txt May 24 2013 05:13:45 CEST. aliveSaved log of last contact as txt May 24 2013 05:13:45 CEST. SenderBaselookup 212.23.46.135 at virustotallookup 212.23.46.135 at Rus CERT university stuttgart germanylookup 212.23.46.135 at Ripefollow up this item(ip) in same window 212.23.46.135 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS8928) in networks tablefollow up this itemfollow up this AS (AS8928) as RSS-Feed AS8928 SenderBaselookup 212.23.46.135 at virustotallookup 212.23.46.135 at Rus CERT university stuttgart germanylookup 212.23.46.135 at Ripefollow up this item(review) in same window 212.23.46.135 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.un-jeu-par-jour.com/toolbar/t ... lookup un-jeu-par-jour.com at virustotalfollow up this domain(un-jeu-par-jour.com) un-jeu-par-jour.com follow up this itemfollow up this country (FR) as RSS-Feed FR follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (obouillaud@microapp.com) as RSS-Feed obouillaud@microapp.com follow up this itemfollow up this item 212.23.46.128 - 212.23.46.159 follow up this item MICROAPPLICATION-NETS follow up this item MICRO APPLICATIONInteroute Telecommunications (UK) Ltd follow up this item a.ns.zerigo.net follow up this item e.ns.zerigo.net follow up this item c.ns.zerigo.net follow up this item d.ns.zerigo.net follow up this item b.ns.zerigo.net Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.un-jeu-par-jour.com/toolbar/t ...
5 follow up this item(11394763) 11394763 Report false positive Report closed case make a suggestion 2013-05-24 05:00:55     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
18/35 (51.4%) 
 
Artemis!3CA319A7ACDB
Trojan/FakeAV.mozh
Trojan
WS.Reputation.1
W32/Suspicious_Gen4.BOPPU
TROJ_GEN.RFFH1FI
Gen:Variant.Zusy.7768
Trojan.Agent/Gen-Zusy
UnclassifiedMalware
TR/Rogue.kdv.629834
Heuristic.BehavesLike.Win32.ModifiedUPX.C
Gen:Variant.Zusy.7768 
 lookup in virustotal.com (3ca319a7acdbc6db55afed6ffaecf197)-->[http://www.virustotal.com/latest-report.html?resource=3ca319a7acdbc6db55afed6ffaecf197]lookup in threatexpert.comlookup the sha256(236628436843dc05e03544f70e3be20be9f5a59a56ffabba7f6f26a83326660f) in comodo.comfollow up this md5sum(3ca319a7acdbc6db55afed6ffaecf197)follow up this itemfollow up this virusname (TR%2FRogue.kdv.629834) as RSS-Feedlookup Virusname at avirafollow up this malware(TR%2FRogue.kdv.629834) for scanner (avira) in md5 table18/35 (51.4%) TR/Rogue.kdv.629834
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.un-jeu-par-jour.com/toolbar/t ...  up No previous evidence recordedSaved evidence (373429 Bytes) of last contact as txt May 24 2013 05:13:59 CEST. aliveSaved log of last contact as txt May 24 2013 05:13:59 CEST. SenderBaselookup 212.23.46.135 at virustotallookup 212.23.46.135 at Rus CERT university stuttgart germanylookup 212.23.46.135 at Ripefollow up this item(ip) in same window 212.23.46.135 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS8928) in networks tablefollow up this itemfollow up this AS (AS8928) as RSS-Feed AS8928 SenderBaselookup 212.23.46.135 at virustotallookup 212.23.46.135 at Rus CERT university stuttgart germanylookup 212.23.46.135 at Ripefollow up this item(review) in same window 212.23.46.135 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.un-jeu-par-jour.com/toolbar/t ... lookup un-jeu-par-jour.com at virustotalfollow up this domain(un-jeu-par-jour.com) un-jeu-par-jour.com follow up this itemfollow up this country (FR) as RSS-Feed FR follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (obouillaud@microapp.com) as RSS-Feed obouillaud@microapp.com follow up this itemfollow up this item 212.23.46.128 - 212.23.46.159 follow up this item MICROAPPLICATION-NETS follow up this item MICRO APPLICATIONInteroute Telecommunications (UK) Ltd follow up this item a.ns.zerigo.net follow up this item e.ns.zerigo.net follow up this item c.ns.zerigo.net follow up this item d.ns.zerigo.net follow up this item b.ns.zerigo.net Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.un-jeu-par-jour.com/toolbar/t ...
6 follow up this item(11394761) 11394761 Report false positive Report closed case make a suggestion 2013-05-24 05:00:55     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
18/35 (51.4%) 
 
Artemis!3CA319A7ACDB
Trojan/FakeAV.mozh
Trojan
WS.Reputation.1
W32/Suspicious_Gen4.BOPPU
TROJ_GEN.RFFH1FI
Gen:Variant.Zusy.7768
Trojan.Agent/Gen-Zusy
UnclassifiedMalware
TR/Rogue.kdv.629834
Heuristic.BehavesLike.Win32.ModifiedUPX.C
Gen:Variant.Zusy.7768 
 lookup in virustotal.com (3ca319a7acdbc6db55afed6ffaecf197)-->[http://www.virustotal.com/latest-report.html?resource=3ca319a7acdbc6db55afed6ffaecf197]lookup in threatexpert.comlookup the sha256(236628436843dc05e03544f70e3be20be9f5a59a56ffabba7f6f26a83326660f) in comodo.comfollow up this md5sum(3ca319a7acdbc6db55afed6ffaecf197)follow up this itemfollow up this virusname (TR%2FRogue.kdv.629834) as RSS-Feedlookup Virusname at avirafollow up this malware(TR%2FRogue.kdv.629834) for scanner (avira) in md5 table18/35 (51.4%) TR/Rogue.kdv.629834
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.un-jeu-par-jour.com/toolbar/t ...  up No previous evidence recordedSaved evidence (373429 Bytes) of last contact as txt May 24 2013 05:14:53 CEST. aliveSaved log of last contact as txt May 24 2013 05:14:53 CEST. SenderBaselookup 212.23.46.135 at virustotallookup 212.23.46.135 at Rus CERT university stuttgart germanylookup 212.23.46.135 at Ripefollow up this item(ip) in same window 212.23.46.135 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS8928) in networks tablefollow up this itemfollow up this AS (AS8928) as RSS-Feed AS8928 SenderBaselookup 212.23.46.135 at virustotallookup 212.23.46.135 at Rus CERT university stuttgart germanylookup 212.23.46.135 at Ripefollow up this item(review) in same window 212.23.46.135 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.un-jeu-par-jour.com/toolbar/t ... lookup un-jeu-par-jour.com at virustotalfollow up this domain(un-jeu-par-jour.com) un-jeu-par-jour.com follow up this itemfollow up this country (FR) as RSS-Feed FR follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (obouillaud@microapp.com) as RSS-Feed obouillaud@microapp.com follow up this itemfollow up this item 212.23.46.128 - 212.23.46.159 follow up this item MICROAPPLICATION-NETS follow up this item MICRO APPLICATIONInteroute Telecommunications (UK) Ltd follow up this item a.ns.zerigo.net follow up this item e.ns.zerigo.net follow up this item c.ns.zerigo.net follow up this item d.ns.zerigo.net follow up this item b.ns.zerigo.net Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.un-jeu-par-jour.com/toolbar/t ...
7 follow up this item(11394753) 11394753 Report false positive Report closed case make a suggestion 2013-05-24 05:00:54     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
lookup in virustotal.com (5657801dc34e052942a824212f1eb148)lookup in threatexpert.comlookup the sha256(faafd7b1761fa7242c66ffec5fef41836f3cd365cede9c95001dc45b99f84db9) in comodo.comfollow up this md5sum(5657801dc34e052942a824212f1eb148)follow up this itemfollow up this virusname (unknown_exe) as RSS-Feedfollow up this malware(unknown_exe) for scanner (undef) in md5 table0/43 (0.0%) unknown_exe
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.startmenu8.com/StartMenu8_Set ...  up No previous evidence recordedSaved evidence (4882088 Bytes) of last contact as txt May 03 2013 16:08:01 CEST. aliveSaved log of last contact as txt May 24 2013 05:17:23 CEST. SenderBaselookup 70.86.134.123 at virustotallookup 70.86.134.123 at Rus CERT university stuttgart germanylookup 70.86.134.123 at ARINfollow up this item(ip) in same window 70.86.134.123 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS36420, AS30315, AS13749, AS21844) in networks tablefollow up this itemfollow up this AS (AS36420, AS30315, AS13749, AS21844) as RSS-Feed AS36420, AS30315, AS13749, AS21844 SenderBaselookup 70.86.134.123 at virustotallookup 70.86.134.123 at Rus CERT university stuttgart germanylookup 70.86.134.123 at ARINfollow up this item(review) in same window 70.86.134.123 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.startmenu8.com/StartMenu8_Set ... lookup startmenu8.com at virustotalfollow up this domain(startmenu8.com) startmenu8.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (abuse@theplanet.com) as RSS-Feed abuse@theplanet.com follow up this itemfollow up this item 70.84.0.0 - 70.87.255.255 follow up this item NETBLK-THEPLANET-BLK-13 follow up this item ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002 follow up this item dns2.registrar-servers.com follow up this item dns3.registrar-servers.com follow up this item dns4.registrar-servers.com follow up this item dns1.registrar-servers.com follow up this item dns5.registrar-servers.com Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.startmenu8.com/StartMenu8_Set ...
8 follow up this item(11394749) 11394749 Report false positive Report closed case make a suggestion 2013-05-24 05:00:54     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
31/45 (68.9%) 
 Gen:Variant.Symmi.1507
Worm.SlenfBot.Gen
Trojan.Agent
Riskware
W32/ProxyAgent.C.gen!Eldorado
Trojan.Smowbot
Scar.HF
a
variant
of
Win32/ProxBot.B
TROJ_GEN.R2SCDEE
Win32:Rootkit-gen
[Rtk]
Trojan-Downloader.Win32.Karagany.asx
Gen:Variant.Symmi.1507
Packed/E 
 lookup in virustotal.com (befd44b3b8d0bfde5dc2405c2347e5cb)-->[http://www.virustotal.com/latest-report.html?resource=befd44b3b8d0bfde5dc2405c2347e5cb]lookup in threatexpert.comlookup the sha256(9ecb4d79863db914524652a2db2bc267c544afbbbcd83e988b87e5f0dceaa3a5) in comodo.comfollow up this md5sum(befd44b3b8d0bfde5dc2405c2347e5cb)follow up this itemfollow up this virusname (Trj%2FGenetic.gen) as RSS-Feedfollow up this malware(Trj%2FGenetic.gen) for scanner (undef) in md5 table31/45 (68.9%) Trj/Genetic.gen
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.leccrin.com/hermes/wp-content ...  up No previous evidence recordedSaved evidence (297472 Bytes) of last contact as txt May 14 2013 10:41:08 CEST. aliveSaved log of last contact as txt May 24 2013 05:22:28 CEST. SenderBaselookup 142.0.129.25 at virustotallookup 142.0.129.25 at Rus CERT university stuttgart germanylookup 142.0.129.25 at ARINfollow up this item(ip) in same window 142.0.129.25 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS54600) in networks tablefollow up this itemfollow up this AS (AS54600) as RSS-Feed AS54600 SenderBaselookup 142.0.129.25 at virustotallookup 142.0.129.25 at Rus CERT university stuttgart germanylookup 142.0.129.25 at ARINfollow up this item(review) in same window 142.0.129.25 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.leccrin.com/hermes/wp-content ... lookup leccrin.com at virustotalfollow up this domain(leccrin.com) leccrin.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (abuse@petaexpress.com) as RSS-Feed abuse@petaexpress.com follow up this itemfollow up this item 142.0.128.0 - 142.0.143.255 follow up this item PT-82-3 follow up this item PEG TECH INC PT-82 440 North Wolfe Road Sunnyvalle CA 94085 follow up this item ns29.domaincontrol.com follow up this item ns30.domaincontrol.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.leccrin.com/hermes/wp-content ...
9 follow up this item(11394748) 11394748 Report false positive Report closed case make a suggestion 2013-05-24 05:00:54     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
6/45 (13.3%) 
 Win32/Agent.BTW
Artemis!11E3901E7E57
Trojan/PSW.Agent.mns
WS.Reputation.1
TROJ_GEN.F47V0822
Artemis!11E3901E7E57 
 lookup in virustotal.com (11e3901e7e5755423aaa56127a556699)-->[http://www.virustotal.com/latest-report.html?resource=11e3901e7e5755423aaa56127a556699]lookup in threatexpert.comlookup the sha256(bfc2f37570ebbbe203ff67c7b5dc75648930553ba56c5edcac59961b487b421c) in comodo.comfollow up this md5sum(11e3901e7e5755423aaa56127a556699)follow up this itemfollow up this virusname (Artemis%2111E3901E7E57) as RSS-Feedfollow up this malware(Artemis%2111E3901E7E57) for scanner (undef) in md5 table6/45 (13.3%) Artemis!11E3901E7E57
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.igetmyexboyfriendback.com/chm ...  up No previous evidence recordedSaved evidence (424162 Bytes) of last contact as txt January 05 2010 22:21:28 CET. aliveSaved log of last contact as txt May 24 2013 05:22:37 CEST. SenderBaselookup 8.29.158.48 at virustotallookup 8.29.158.48 at Rus CERT university stuttgart germanylookup 8.29.158.48 at ARINfollow up this item(ip) in same window 8.29.158.48 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS14112) in networks tablefollow up this itemfollow up this AS (AS14112) as RSS-Feed AS14112 SenderBaselookup 8.29.158.48 at virustotallookup 8.29.158.48 at Rus CERT university stuttgart germanylookup 8.29.158.48 at ARINfollow up this item(review) in same window 8.29.158.48 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.igetmyexboyfriendback.com/chm ... lookup igetmyexboyfriendback.com at virustotalfollow up this domain(igetmyexboyfriendback.com) igetmyexboyfriendback.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (abuse@level3.com) as RSS-Feed abuse@level3.com follow up this itemfollow up this item 8.0.0.0 - 8.255.255.255 follow up this item LVLT-ORG-8-8 follow up this item Level 3 Communications, Inc. LVLT 1025 Eldorado Blvd. Broomfield CO 80021 follow up this item hns2.beyondhosting.net follow up this item hns1.beyondhosting.net follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.igetmyexboyfriendback.com/chm ...
10 follow up this item(11394745) 11394745 Report false positive Report closed case make a suggestion 2013-05-24 05:00:54     follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
21/46 (45.7%) 
 Adware.Relevant.BH
Adware.Relevant.BH
PUP.Adware.RelevantKnowledge
WS.Reputation.1
TROJ_GEN.RCBH1B1
Win32:PUP-gen
[PUP]
Win32.ADSPYNaviPromo
Adware.Relevant.BH
Adware.MarketScore!zitxnvecDX8
RelevantKnowledge
ApplicUnwnt.Win32.AdWare.RK.~E
Adware.Relevan 
 lookup in virustotal.com (677ccb1d7002682dcc715d88b20a1651)-->[http://www.virustotal.com/latest-report.html?resource=677ccb1d7002682dcc715d88b20a1651]lookup in threatexpert.comlookup the sha256(adeef51dc63b1db9bc3a2c0386a033f8322fde3ab53f3694efcef75f83e5a1e0) in comodo.comfollow up this md5sum(677ccb1d7002682dcc715d88b20a1651)follow up this itemfollow up this virusname (ADSPY%2FNaviPromo.J) as RSS-Feedlookup Virusname at avirafollow up this malware(ADSPY%2FNaviPromo.J) for scanner (avira) in md5 table21/46 (45.7%) ADSPY/NaviPromo.J
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://wrapapp.net/Temp/TriviaSetup_9861 ...  up No previous evidence recordedSaved evidence (484624 Bytes) of last contact as txt December 17 2012 15:53:25 CET. aliveSaved log of last contact as txt May 24 2013 05:23:05 CEST. SenderBaselookup 209.135.141.122 at virustotallookup 209.135.141.122 at Rus CERT university stuttgart germanylookup 209.135.141.122 at ARINfollow up this item(ip) in same window 209.135.141.122 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS32468) in networks tablefollow up this itemfollow up this AS (AS32468) as RSS-Feed AS32468 SenderBaselookup 209.135.141.122 at virustotallookup 209.135.141.122 at Rus CERT university stuttgart germanylookup 209.135.141.122 at ARINfollow up this item(review) in same window 209.135.141.122 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://wrapapp.net/Temp/TriviaSetup_9861 ... lookup wrapapp.net at virustotalfollow up this domain(wrapapp.net) wrapapp.net follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (ipadmin@primary.net) as RSS-Feed ipadmin@primary.net follow up this itemfollow up this item 209.135.128.0 - 209.135.159.255 follow up this item INLINK97 follow up this item InLink Communications Company INLK P.O. Box 410890 St. Louis MO 63141 follow up this item ns73.domaincontrol.com follow up this item ns74.domaincontrol.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://wrapapp.net/Temp/TriviaSetup_9861 ...
Click here for other vital incidents



Protected by clean MX [Valid RSS] Valid HTML 4.01 Transitional CSS ist valide!
Access is provided for free and subject to these Terms and Conditions.