CLEAN MX realtime database
public access query for virus URL statistics
Totally watched: 20282, to down: 0, to up: 0, changed ip: 0
As of 2010-09-02 22:05:27 CEST
Subscribe to the VirusWatch Mailing list, updated hourly

This database consists of Virus URI, collected and verified since Feb 2006

If you detect URI'S concerning your netblock, already closed... you have made a good job, otherwise please close them as soon as possible.

to look at some nice charts, there are complete statisticsstatistics for this database
Attention: all URI'S are manually verified, but not cross-checked for real viruses function in this moment you make this query.(Sites may have been closed already..)
Our automatic Viruswalker process is scheduled every hour, so you may see now a incident and this one will be resolved later on.
So please keep on sending close-feedbacks to us...

if you have questions, criticism, wishes or ... do not hesitate to contact us at abuse@clean-mx.de
Our PBX is down you may reach us by cell phone +49 171 4802507 ...
Query as xml: Same query as xml output
TIMERS: Runtime Query: 0.0180 Seconds
helpLine help#descendigascending helpDatedescendigascending helpCloseddescendigascending helphours helpcontributordescendigascending helpvirusnamedescendigascending helpURLdescendigascending helpip state helpresponsedescendigascending helpIp initialdescendigascending helpAS#descendigascending helpip reviewdescendigascending helpURLdescendigascending helpDomaindescendigascending helpcountrydescendigascending helpsourcedescendigascending helpemaildescendigascending helpinetnumdescendigascending helpnetnamedescendigascending helpdescrdescendigascending helpns1descendigascending helpns2descendigascending helpns3descendigascending helpns4descendigascending helpns5descendigascending helpURLdescendigascending
1 321254 2009-12-11 00:00:00 2009-12-13 05:34:30 53.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Trojan) as RSS-Feedfollow up this malware(malwareurl_Trojan) for scanner () in md5 table malwareurl_Trojan
Safe Virus-Viewer and Analyser may take a minute to complete http://dozvonic.cn/edF8Y.exe  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt December 13 2009 05:34:30 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://dozvonic.cn/edF8Y.exe follow up this domain(dozvonic.cn) dozvonic.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://dozvonic.cn/edF8Y.exe
2 304443 2009-12-10 19:07:21 2009-12-10 20:13:54 1.1 follow up this itemfollow up this contributor (sub8) as RSS-Feed sub8possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (Backdoor.Win32.Bredavi.bia) as RSS-Feedfollow up this malware(Backdoor.Win32.Bredavi.bia) for scanner () in md5 table Backdoor.Win32.Bredavi.bia
Safe Virus-Viewer and Analyser may take a minute to complete http://www.zyablik.cn/  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt December 10 2009 20:13:54 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://www.zyablik.cn/ follow up this domain(zyablik.cn) zyablik.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://www.zyablik.cn/
3 304434 2009-12-10 16:00:00 2009-12-18 05:55:45 181.9 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
Saved local log of anubis as txt December 10 2009 22:07:12 CET.5/41 (12.20%) 
 Virustotal.
MD5:
d2c785da0480e6bee70410f9d6b9d43c
Backdoor.Win32.Bredavi!IK
Trojan.Siggen.31413
Backdoor.Win32.Bredavi
 
 lookup in virustotal.com (d2c785da0480e6bee70410f9d6b9d43c)-->[http://www.virustotal.com/analisis/be04ae2c9a504909ae40424348757e040217d2d6a36b765c62a6cfadd485897a-1260515221]lookup in threatexpert.comlookup the sha256(be04ae2c9a504909ae40424348757e040217d2d6a36b765c62a6cfadd485897a) in comodo.comfollow up this md5sum(d2c785da0480e6bee70410f9d6b9d43c)follow up this itemfollow up this virusname (Backdoor.Win32.Bredavi%21IK) as RSS-Feedfollow up this malware(Backdoor.Win32.Bredavi%21IK) for scanner (a_squared) in md5 table5/41 (12.20%) Backdoor.Win32.Bredavi!IK
Safe Virus-Viewer and Analyser may take a minute to complete http://www.dozvonic.cn/04-Hcurd.exe  up Saved evidence (44032 Bytes) of first contact as txt December 09 2009 20:21:51 CET.No evidence recorded closedSaved log of last contact as txt December 18 2009 05:55:44 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://www.dozvonic.cn/04-Hcurd.exe follow up this domain(dozvonic.cn) dozvonic.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://www.dozvonic.cn/04-Hcurd.exe
4 303678 2009-12-10 00:47:00 2009-12-18 06:30:51 197.7 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
Saved local log of anubis as txt December 10 2009 05:06:11 CET.0/41 (0.00%) 
 Virustotal.
MD5:
1888032359fb7405657411e90ea91aa1
 
 lookup in virustotal.com (1888032359fb7405657411e90ea91aa1)-->[no evidence available]lookup in threatexpert.comlookup the sha256(da92bb0735ba889a27fa1c66fbf1d0770d9132f6296ba43cac0be4809358f388) in comodo.comfollow up this md5sum(1888032359fb7405657411e90ea91aa1)follow up this itemfollow up this virusname (mdl_bot) as RSS-Feedfollow up this malware(mdl_bot) for scanner (undef) in md5 table0/41 (0.00%) mdl_bot
Safe Virus-Viewer and Analyser may take a minute to complete http://www.dozvonic.cn/edF8Y.exe  up Saved evidence (58880 Bytes) of first contact as txt December 09 2009 20:23:36 CET.No evidence recorded closedSaved log of last contact as txt December 18 2009 06:30:49 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://www.dozvonic.cn/edF8Y.exe follow up this domain(dozvonic.cn) dozvonic.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://www.dozvonic.cn/edF8Y.exe
5 303679 2009-12-10 00:47:00 2009-12-15 00:47:00 120 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
Saved local log of anubis as txt December 10 2009 05:06:23 CET.0/41 (0.00%) 
 Virustotal.
MD5:
54e796c09781aeb3d69291efeb43c489
 
 lookup in virustotal.com (54e796c09781aeb3d69291efeb43c489)-->[no evidence available]lookup in threatexpert.comlookup the sha256(355cdecfbbbd99702f4526457a8ce7d630a23e7e5c3101e9d6452a580b28ec8a) in comodo.comfollow up this md5sum(54e796c09781aeb3d69291efeb43c489)follow up this itemfollow up this virusname (mdl_trojan+downloader) as RSS-Feedfollow up this malware(mdl_trojan+downloader) for scanner (undef) in md5 table0/41 (0.00%) mdl_trojan downloader
Safe Virus-Viewer and Analyser may take a minute to complete http://www.zyablik.cn/socks5.exe  up Saved evidence (105472 Bytes) of first contact as txt December 09 2009 20:21:38 CET.No evidence recorded deadSaved log of last contact as txt December 18 2009 06:30:45 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://www.zyablik.cn/socks5.exe follow up this domain(zyablik.cn) zyablik.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://www.zyablik.cn/socks5.exe
6 303507 2009-12-09 17:08:00 2009-12-09 20:22:51 3.2 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (mdl_trojan+Oficla) as RSS-Feedfollow up this malware(mdl_trojan+Oficla) for scanner () in md5 table mdl_trojan Oficla
Safe Virus-Viewer and Analyser may take a minute to complete http://www.dostuplcb.cn/04-aT2Sq.exe  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt December 09 2009 20:22:51 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://www.dostuplcb.cn/04-aT2Sq.exe follow up this domain(dostuplcb.cn) dostuplcb.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://www.dostuplcb.cn/04-aT2Sq.exe
7 303508 2009-12-09 17:08:00 2009-12-09 20:22:50 3.2 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (mdl_bot) as RSS-Feedfollow up this malware(mdl_bot) for scanner () in md5 table mdl_bot
Safe Virus-Viewer and Analyser may take a minute to complete http://www.dostuplcb.cn/8c_LM.exe  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt December 09 2009 20:22:50 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://www.dostuplcb.cn/8c_LM.exe follow up this domain(dostuplcb.cn) dostuplcb.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://www.dostuplcb.cn/8c_LM.exe
8 296983 2009-12-03 00:00:00 2009-12-03 10:21:21 10.4 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Trojan+Inject) as RSS-Feedfollow up this malware(malwareurl_Trojan+Inject) for scanner () in md5 table malwareurl_Trojan Inject
Safe Virus-Viewer and Analyser may take a minute to complete http://brendbar.cn/n-bss.exe  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt December 03 2009 10:21:21 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://brendbar.cn/n-bss.exe follow up this domain(brendbar.cn) brendbar.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://brendbar.cn/n-bss.exe
9 297197 2009-12-03 00:00:00 2009-12-03 15:44:05 15.7 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Malware+URLs) as RSS-Feedfollow up this malware(malwareurl_Malware+URLs) for scanner () in md5 table malwareurl_Malware URLs
Safe Virus-Viewer and Analyser may take a minute to complete http://smyslovaya.cn  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt December 03 2009 15:44:05 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://smyslovaya.cn follow up this domain(smyslovaya.cn) smyslovaya.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://smyslovaya.cn
10 296494 2009-12-02 20:32:00 2009-12-02 22:31:15 2 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (mdl_bot) as RSS-Feedfollow up this malware(mdl_bot) for scanner () in md5 table mdl_bot
Safe Virus-Viewer and Analyser may take a minute to complete http://antibalk.cn/n-file111.exe  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt December 02 2009 22:31:15 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://antibalk.cn/n-file111.exe follow up this domain(antibalk.cn) antibalk.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://antibalk.cn/n-file111.exe
11 292498 2009-11-29 00:00:00 2009-11-30 19:38:58 43.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
2/41 (4.88%) 
 Virustotal.
MD5:
39687c596d2a53237334159b16fdd6c8
Scareware:HTML:FakeAV!IK
Scareware:HTML:FakeAV
 
 lookup in virustotal.com (39687c596d2a53237334159b16fdd6c8)-->[http://www.virustotal.com/analisis/9e57007b15edab321b71b57c500e3d677eeb54fb37017527dae0a5e52358eb69-1255927867]follow up this md5sum(39687c596d2a53237334159b16fdd6c8)follow up this itemfollow up this virusname (Scareware%3AHTML%3AFakeAV%21IK) as RSS-Feedfollow up this malware(Scareware%3AHTML%3AFakeAV%21IK) for scanner (a_squared) in md5 table2/41 (4.88%) Scareware:HTML:FakeAV!IK
Safe Virus-Viewer and Analyser may take a minute to complete http://vvvgz.cn  up No previous evidence recordedSaved evidence (44 Bytes) of last contact as txt August 25 2009 12:44:29 CEST. deadSaved log of last contact as txt November 30 2009 19:38:58 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://vvvgz.cn follow up this domain(vvvgz.cn) vvvgz.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://vvvgz.cn
12 283020 2009-11-21 20:57:00 2009-11-26 20:57:00 120 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
Saved local log of anubis as txt November 22 2009 00:23:09 CET.1/41 (2.44%) 
 Virustotal.
MD5:
727345e2af5535bc3327a38c5315972e
Medium
Risk
Malware
 
 lookup in virustotal.com (727345e2af5535bc3327a38c5315972e)-->[http://www.virustotal.com/analisis/e6fd34cf667cbdbcc8c87e2a96f58cff810cc09424e51389b7bc615dceb8574a-1258843173]lookup in threatexpert.comlookup the sha256(e6fd34cf667cbdbcc8c87e2a96f58cff810cc09424e51389b7bc615dceb8574a) in comodo.comfollow up this md5sum(727345e2af5535bc3327a38c5315972e)follow up this itemfollow up this virusname (Medium+Risk+Malware) as RSS-Feedfollow up this malware(Medium+Risk+Malware) for scanner (Prevx) in md5 table1/41 (2.44%) Medium Risk Malware
Safe Virus-Viewer and Analyser may take a minute to complete http://antipolicai.cn/n-file.exe  up Saved evidence (55808 Bytes) of first contact as txt November 21 2009 12:29:31 CET.No evidence recorded deadSaved log of last contact as txt November 29 2009 12:02:11 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanyfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanyfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://antipolicai.cn/n-file.exe follow up this domain(antipolicai.cn) antipolicai.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (ripe) as RSS-Feed ripe follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://antipolicai.cn/n-file.exe
13 271631 2009-11-15 00:00:00 2009-11-16 12:53:50 36.9 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack+%28use+Sina+DLoader%29+%2F+Unknown+Trojan) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack+%28use+Sina+DLoader%29+%2F+Unknown+Trojan) for scanner () in md5 table malwareurl_Eleonore Exploit Pack (use Sina DLoader) / Unknown Trojan
Safe Virus-Viewer and Analyser may take a minute to complete http://serafimzz.cn/sv/pdf.php  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 16 2009 12:53:50 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://serafimzz.cn/sv/pdf.php follow up this domain(serafimzz.cn) serafimzz.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://serafimzz.cn/sv/pdf.php
14 271682 2009-11-15 00:00:00 2009-11-16 12:46:48 36.8 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack+%28use+Sina+DLoader%29+%2F+Unknown+Trojan) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack+%28use+Sina+DLoader%29+%2F+Unknown+Trojan) for scanner () in md5 table malwareurl_Eleonore Exploit Pack (use Sina DLoader) / Unknown Trojan
Safe Virus-Viewer and Analyser may take a minute to complete http://serafimzz.cn/sv/index.php?s=ec445 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 16 2009 12:46:48 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://serafimzz.cn/sv/index.php?s=ec445 ... follow up this domain(serafimzz.cn) serafimzz.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://serafimzz.cn/sv/index.php?s=ec445 ...
15 269756 2009-11-13 00:00:00 2009-11-22 15:08:10 231.1 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
Saved local log of anubis as txt November 14 2009 13:13:35 CET.0/41 (0.00%) 
 Virustotal.
MD5:
1cc4491fca7cc1dd69c272645c142c7d
 
 lookup in virustotal.com (1cc4491fca7cc1dd69c272645c142c7d)-->[http://www.virustotal.com/analisis/a106ef1e4434b8fd9a84fa89ae98a6e252ad58d9a5c6e77c1572d7405f78dc6e-1258173492]lookup in threatexpert.comlookup the sha256(a106ef1e4434b8fd9a84fa89ae98a6e252ad58d9a5c6e77c1572d7405f78dc6e) in comodo.comfollow up this md5sum(1cc4491fca7cc1dd69c272645c142c7d)follow up this itemfollow up this virusname (unknown_exe) as RSS-Feedfollow up this malware(unknown_exe) for scanner (undef) in md5 table0/41 (0.00%) unknown_exe
Safe Virus-Viewer and Analyser may take a minute to complete http://antipolicai.cn/dib-file.exe  up Saved evidence (70144 Bytes) of first contact as txt November 13 2009 20:17:50 CET.Saved evidence (71680 Bytes) of last contact as txt November 22 2009 08:07:46 CET. closed1536Saved log of last contact as txt November 22 2009 15:08:06 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://antipolicai.cn/dib-file.exe follow up this domain(antipolicai.cn) antipolicai.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://antipolicai.cn/dib-file.exe
16 267661 2009-11-11 12:22:22 2009-11-11 13:43:20 1.3 follow up this itemfollow up this contributor (sub9) as RSS-Feed sub9possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://tolzcoolz.cn/sv/load.php?spl=mdac ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 11 2009 13:43:20 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://tolzcoolz.cn/sv/load.php?spl=mdac ... follow up this domain(tolzcoolz.cn) tolzcoolz.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://tolzcoolz.cn/sv/load.php?spl=mdac ...
17 267026 2009-11-10 15:49:20 2009-11-10 16:17:50 0.5 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://seyzones.cn/n-bss.exe  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 10 2009 16:17:50 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://seyzones.cn/n-bss.exe follow up this domain(seyzones.cn) seyzones.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://seyzones.cn/n-bss.exe
18 268564 2009-11-10 00:00:00 2009-11-12 03:11:36 51.2 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Trojan) as RSS-Feedfollow up this malware(malwareurl_Trojan) for scanner () in md5 table malwareurl_Trojan
Safe Virus-Viewer and Analyser may take a minute to complete http://seyzones.cn/dib-file.exe  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 12 2009 03:11:36 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://seyzones.cn/dib-file.exe follow up this domain(seyzones.cn) seyzones.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://seyzones.cn/dib-file.exe
19 267082 2009-11-09 13:34:32 2009-11-15 05:59:22 136.4 follow up this itemfollow up this contributor (sub8) as RSS-Feed sub8possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
0/41 (0.00%) 
 Virustotal.
MD5:
bc3da186da1e060d2a7916ce236565d7
 
 lookup in virustotal.com (bc3da186da1e060d2a7916ce236565d7)-->[http://www.virustotal.com/analisis/b45fec595d9e799c5e27845f7117b8552988b4ccb0d3d632023e9a0ca34e4bb9-1256599447]follow up this md5sum(bc3da186da1e060d2a7916ce236565d7)follow up this itemfollow up this virusname (Trojan-Banker.Win32.Banker.apgt) as RSS-Feedfollow up this malware(Trojan-Banker.Win32.Banker.apgt) for scanner (undef) in md5 table0/41 (0.00%) Trojan-Banker.Win32.Banker.apgt
Safe Virus-Viewer and Analyser may take a minute to complete http://gamerszons.cn/  up Saved evidence (25 Bytes) of first contact as txt October 11 2009 16:50:52 CEST.Saved evidence (44 Bytes) of last contact as txt August 25 2009 12:44:29 CEST. dead19Saved log of last contact as txt November 15 2009 05:59:22 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://gamerszons.cn/ follow up this domain(gamerszons.cn) gamerszons.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns4.everydns.net follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://gamerszons.cn/
20 264783 2009-11-09 08:22:00 2009-11-22 19:06:54 322.7 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
Saved local log of anubis as txt November 10 2009 09:10:24 CET.2/40 (5.00%) 
 Virustotal.
MD5:
b2bb5d9b83622809f004f0a78e7c0815
Suspicious:W32/Malware!Online
Trojan-Dropper.Win32.Agent.bhnf
 
 lookup in virustotal.com (b2bb5d9b83622809f004f0a78e7c0815)-->[http://www.virustotal.com/analisis/d97ed982267fcf984fc200116258145c62dc0eb8f1ed5caa7a5e943ae8a02751-1257835139]lookup in threatexpert.comlookup the sha256(d97ed982267fcf984fc200116258145c62dc0eb8f1ed5caa7a5e943ae8a02751) in comodo.comfollow up this md5sum(b2bb5d9b83622809f004f0a78e7c0815)follow up this itemfollow up this virusname (Suspicious%3AW32%2FMalware%21Online) as RSS-Feedfollow up this malware(Suspicious%3AW32%2FMalware%21Online) for scanner (F_Secure) in md5 table2/40 (5.00%) Suspicious:W32/Malware!Online
Safe Virus-Viewer and Analyser may take a minute to complete http://gamerszons.cn/dd-file.exe  up Saved evidence (95744 Bytes) of first contact as txt November 09 2009 20:27:48 CET.No evidence recorded deadSaved log of last contact as txt November 22 2009 19:06:54 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://gamerszons.cn/dd-file.exe follow up this domain(gamerszons.cn) gamerszons.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://gamerszons.cn/dd-file.exe
21 265578 2009-11-09 00:00:00 2009-11-10 06:34:38 30.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
2/41 (4.88%) 
 Virustotal.
MD5:
39687c596d2a53237334159b16fdd6c8
Scareware:HTML:FakeAV!IK
Scareware:HTML:FakeAV
 
 lookup in virustotal.com (39687c596d2a53237334159b16fdd6c8)-->[http://www.virustotal.com/analisis/9e57007b15edab321b71b57c500e3d677eeb54fb37017527dae0a5e52358eb69-1255927867]follow up this md5sum(39687c596d2a53237334159b16fdd6c8)follow up this itemfollow up this virusname (Scareware%3AHTML%3AFakeAV%21IK) as RSS-Feedfollow up this malware(Scareware%3AHTML%3AFakeAV%21IK) for scanner (a_squared) in md5 table2/41 (4.88%) Scareware:HTML:FakeAV!IK
Safe Virus-Viewer and Analyser may take a minute to complete http://mypinch.cn  up No previous evidence recordedSaved evidence (44 Bytes) of last contact as txt August 25 2009 12:44:29 CEST. deadSaved log of last contact as txt November 10 2009 06:34:37 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://mypinch.cn follow up this domain(mypinch.cn) mypinch.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mypinch.cn
22 265579 2009-11-09 00:00:00 2009-11-10 06:34:36 30.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack) for scanner () in md5 table malwareurl_Eleonore Exploit Pack
Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/index.php?s=ec44 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 10 2009 06:34:36 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/index.php?s=ec44 ... follow up this domain(barracuder.cn) barracuder.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/index.php?s=ec44 ...
23 265580 2009-11-09 00:00:00 2009-11-22 18:35:39 330.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
0/40 (0.00%) 
 Virustotal.
MD5:
0518c1bfe38aabf2ef99ce9d2b800f82
 
 lookup in virustotal.com (0518c1bfe38aabf2ef99ce9d2b800f82)-->[http://www.virustotal.com/analisis/b843826da9b4d816e4c6023106b94ea8f4aab18136647f6c81c63d2564105211-1257831371]follow up this md5sum(0518c1bfe38aabf2ef99ce9d2b800f82)follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack) for scanner (undef) in md5 table0/40 (0.00%) malwareurl_Eleonore Exploit Pack
Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/x.x  up Saved evidence (100 Bytes) of first contact as txt November 06 2009 19:41:53 CET.No evidence recorded deadSaved log of last contact as txt November 22 2009 18:35:39 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/x.x follow up this domain(barracuder.cn) barracuder.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/x.x
24 265581 2009-11-09 00:00:00 2009-11-22 18:35:38 330.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
2/40 (5.00%) 
 Virustotal.
MD5:
2a70457cdb5220c762e228caa489fb84
JS:Pdfka-SP
JS:Pdfka-SP

 
 lookup in virustotal.com (2a70457cdb5220c762e228caa489fb84)-->[http://www.virustotal.com/analisis/744ba577393e1c31f38be28b58e25e6eebb4a1f77ada5da1bf2f6e9c209d2d01-1257831317]follow up this md5sum(2a70457cdb5220c762e228caa489fb84)follow up this itemfollow up this virusname (JS%3APdfka-SP) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(JS%3APdfka-SP) for scanner (Avast) in md5 table2/40 (5.00%) JS:Pdfka-SP
Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/pdf.php  up Saved evidence (4013 Bytes) of first contact as txt November 10 2009 06:34:19 CET.No evidence recorded deadSaved log of last contact as txt November 22 2009 18:35:38 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/pdf.php follow up this domain(barracuder.cn) barracuder.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/pdf.php
25 265582 2009-11-09 00:00:00 2009-11-22 18:35:35 330.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
0/40 (0.00%) 
 Virustotal.
MD5:
a60b908d3afa91c708a1a9edd0681a0f
 
 lookup in virustotal.com (a60b908d3afa91c708a1a9edd0681a0f)-->[http://www.virustotal.com/analisis/1f7bd8bac7cbf536dfbdddd4f3f062efc148cdbdc19574d3dbbfa5cfb46d18db-1257831351]lookup in threatexpert.comlookup the sha256(1f7bd8bac7cbf536dfbdddd4f3f062efc148cdbdc19574d3dbbfa5cfb46d18db) in comodo.comfollow up this md5sum(a60b908d3afa91c708a1a9edd0681a0f)follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack) for scanner (undef) in md5 table0/40 (0.00%) malwareurl_Eleonore Exploit Pack
Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/Client2.jar  up Saved evidence (4819 Bytes) of first contact as txt November 09 2009 11:13:31 CET.No evidence recorded deadSaved log of last contact as txt November 22 2009 18:35:35 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/Client2.jar follow up this domain(barracuder.cn) barracuder.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/Client2.jar
helpLine help#descendigascending helpDatedescendigascending helpCloseddescendigascending helphours helpcontributordescendigascending helpvirusnamedescendigascending helpURLdescendigascending helpip state helpresponsedescendigascending helpIp initialdescendigascending helpAS#descendigascending helpip reviewdescendigascending helpURLdescendigascending helpDomaindescendigascending helpcountrydescendigascending helpsourcedescendigascending helpemaildescendigascending helpinetnumdescendigascending helpnetnamedescendigascending helpdescrdescendigascending helpns1descendigascending helpns2descendigascending helpns3descendigascending helpns4descendigascending helpns5descendigascending helpURLdescendigascending
26 265583 2009-11-09 00:00:00 2009-11-22 18:35:33 330.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
Saved local log of anubis as txt November 10 2009 09:15:09 CET.2/40 (5.00%) 
 Virustotal.
MD5:
75cabc66395667834dea92f4b042d244
Trojan.Win32.Agent
Trojan.Win32.Agent.dbtl
 
 lookup in virustotal.com (75cabc66395667834dea92f4b042d244)-->[http://www.virustotal.com/analisis/3ed2cba1479d627927bc2e4b97859fda3612eed8e1b7a3fd08faef83c0ddded3-1257840049]lookup in threatexpert.comlookup the sha256(3ed2cba1479d627927bc2e4b97859fda3612eed8e1b7a3fd08faef83c0ddded3) in comodo.comfollow up this md5sum(75cabc66395667834dea92f4b042d244)follow up this itemfollow up this virusname (Trojan.Win32.Agent) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(Trojan.Win32.Agent) for scanner (Ikarus) in md5 table2/40 (5.00%) Trojan.Win32.Agent
Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/load.php?spl=Act ...  up Saved evidence (33280 Bytes) of first contact as txt November 10 2009 06:34:09 CET.No evidence recorded deadSaved log of last contact as txt November 22 2009 18:35:32 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/load.php?spl=Act ... follow up this domain(barracuder.cn) barracuder.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/load.php?spl=Act ...
27 265584 2009-11-09 00:00:00 2009-11-22 18:35:29 330.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
0/40 (0.00%) 
 Virustotal.
MD5:
fd7b694331ee4648c733fc2ec304856b
 
 lookup in virustotal.com (fd7b694331ee4648c733fc2ec304856b)-->[http://www.virustotal.com/analisis/883552ea91386e115c1a07f9ba6c64d8f538f2251ca4d328add2435bf7f1c8b6-1257831351]follow up this md5sum(fd7b694331ee4648c733fc2ec304856b)follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack) for scanner (undef) in md5 table0/40 (0.00%) malwareurl_Eleonore Exploit Pack
Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/stat.php  up Saved evidence (2132 Bytes) of first contact as txt November 10 2009 06:34:06 CET.No evidence recorded deadSaved log of last contact as txt November 22 2009 18:35:29 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/stat.php follow up this domain(barracuder.cn) barracuder.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://barracuder.cn/sv/stat.php
28 265585 2009-11-09 00:00:00 2009-11-10 06:34:03 30.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack) for scanner () in md5 table malwareurl_Eleonore Exploit Pack
Safe Virus-Viewer and Analyser may take a minute to complete http://vvvcr.cn/sv/index.php?s=ec445bc54 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 10 2009 06:34:03 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://vvvcr.cn/sv/index.php?s=ec445bc54 ... follow up this domain(vvvcr.cn) vvvcr.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://vvvcr.cn/sv/index.php?s=ec445bc54 ...
29 265616 2009-11-09 00:00:00 2009-11-10 06:28:09 30.5 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
0/40 (0.00%) 
 Virustotal.
MD5:
ea42b07f69f1433f24e0e2c5a505deb0
 
 lookup in virustotal.com (ea42b07f69f1433f24e0e2c5a505deb0)-->[http://www.virustotal.com/analisis/af9d08514e9f86d1e7bb1a397826fee0b7d2048fb1050e5f3d2087b2d3d42315-1257843974]follow up this md5sum(ea42b07f69f1433f24e0e2c5a505deb0)follow up this itemfollow up this virusname (malwareurl_Malware+URLs) as RSS-Feedfollow up this malware(malwareurl_Malware+URLs) for scanner () in md5 table0/40 (0.00%) malwareurl_Malware URLs
Safe Virus-Viewer and Analyser may take a minute to complete http://zyablik.cn  up No previous evidence recordedSaved evidence (608 Bytes) of last contact as txt September 26 2009 20:50:42 CEST. deadSaved log of last contact as txt November 10 2009 06:28:09 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://zyablik.cn follow up this domain(zyablik.cn) zyablik.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://zyablik.cn
30 303811 2009-11-09 00:00:00 2009-12-23 09:50:01 1065.8 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
Saved local log of anubis as txt December 10 2009 08:10:46 CET.0/41 (0.00%) 
 Virustotal.
MD5:
54e796c09781aeb3d69291efeb43c489
 
 lookup in virustotal.com (54e796c09781aeb3d69291efeb43c489)-->[no evidence available]lookup in threatexpert.comlookup the sha256(355cdecfbbbd99702f4526457a8ce7d630a23e7e5c3101e9d6452a580b28ec8a) in comodo.comfollow up this md5sum(54e796c09781aeb3d69291efeb43c489)follow up this itemfollow up this virusname (malwareurl_Trojan) as RSS-Feedfollow up this malware(malwareurl_Trojan) for scanner (undef) in md5 table0/41 (0.00%) malwareurl_Trojan
Safe Virus-Viewer and Analyser may take a minute to complete http://zyablik.cn/socks5.exe  up Saved evidence (105472 Bytes) of first contact as txt December 09 2009 20:21:38 CET.No evidence recorded deadSaved log of last contact as txt December 23 2009 09:50:01 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://zyablik.cn/socks5.exe follow up this domain(zyablik.cn) zyablik.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://zyablik.cn/socks5.exe
31 253800 2009-11-05 11:03:51 2009-11-05 11:21:34 0.3 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://gamerszons.cn/dib-file.exe  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 05 2009 11:21:34 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://gamerszons.cn/dib-file.exe follow up this domain(gamerszons.cn) gamerszons.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://gamerszons.cn/dib-file.exe
32 252780 2009-11-03 17:37:00 2009-11-03 20:38:53 3 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (mdl_Eleonore+exploit+pack) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(mdl_Eleonore+exploit+pack) for scanner () in md5 table mdl_Eleonore exploit pack
Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 03 2009 20:38:52 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/ follow up this domain(somstan.cn) somstan.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/
33 252781 2009-11-03 17:37:00 2009-11-03 20:38:48 3 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (mdl_Eleonore+exploit+pack) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(mdl_Eleonore+exploit+pack) for scanner () in md5 table mdl_Eleonore exploit pack
Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 03 2009 20:38:48 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/ follow up this domain(zaders.cn) zaders.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns4.everydns.net follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/
34 252564 2009-11-03 15:02:44 2009-11-15 11:24:32 284.4 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
0/41 (0.00%) 
 Virustotal.
MD5:
50ac484d4775b783d70d87a21bbfaa36
 
 lookup in virustotal.com (50ac484d4775b783d70d87a21bbfaa36)-->[http://www.virustotal.com/analisis/50fc08ed123d724fa41da19510e615fc28fc96288a65fd1fd18b876f16d2ca4b-1257266150]lookup in threatexpert.comlookup the sha256(50fc08ed123d724fa41da19510e615fc28fc96288a65fd1fd18b876f16d2ca4b) in comodo.comfollow up this md5sum(50ac484d4775b783d70d87a21bbfaa36)follow up this itemfollow up this virusname (unknown_html_google_malware) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(unknown_html_google_malware) for scanner (undef) in md5 table0/41 (0.00%) unknown_html_google_malware
Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/load.php?spl=MS09-0 ...  up Saved evidence (33792 Bytes) of first contact as txt November 03 2009 15:47:53 CET.No evidence recorded deadSaved log of last contact as txt November 15 2009 11:24:32 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/load.php?spl=MS09-0 ... follow up this domain(somstan.cn) somstan.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/load.php?spl=MS09-0 ...
35 252565 2009-11-03 15:02:44 2009-11-15 11:24:31 284.4 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
0/41 (0.00%) 
 Virustotal.
MD5:
50ac484d4775b783d70d87a21bbfaa36
 
 lookup in virustotal.com (50ac484d4775b783d70d87a21bbfaa36)-->[http://www.virustotal.com/analisis/50fc08ed123d724fa41da19510e615fc28fc96288a65fd1fd18b876f16d2ca4b-1257266150]lookup in threatexpert.comlookup the sha256(50fc08ed123d724fa41da19510e615fc28fc96288a65fd1fd18b876f16d2ca4b) in comodo.comfollow up this md5sum(50ac484d4775b783d70d87a21bbfaa36)follow up this itemfollow up this virusname (unknown_html_google_malware) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(unknown_html_google_malware) for scanner (undef) in md5 table0/41 (0.00%) unknown_html_google_malware
Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/load.php?spl=MS09-00 ...  up Saved evidence (33792 Bytes) of first contact as txt November 03 2009 15:47:28 CET.No evidence recorded deadSaved log of last contact as txt November 15 2009 11:24:31 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/load.php?spl=MS09-00 ... follow up this domain(zaders.cn) zaders.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item ns1.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/load.php?spl=MS09-00 ...
36 252184 2009-11-02 00:00:00 2009-11-03 05:05:57 29.1 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack) for scanner () in md5 table malwareurl_Eleonore Exploit Pack
Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/index.php?s=4017985 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 03 2009 05:05:57 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/index.php?s=4017985 ... follow up this domain(somstan.cn) somstan.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/index.php?s=4017985 ...
37 252185 2009-11-02 00:00:00 2009-11-03 05:05:53 29.1 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack) for scanner () in md5 table malwareurl_Eleonore Exploit Pack
Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/x.x  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 03 2009 05:05:53 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/x.x follow up this domain(somstan.cn) somstan.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/x.x
38 252186 2009-11-02 00:00:00 2009-11-22 21:55:37 501.9 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
lookup in anubis0/41 (0.00%) 
 Virustotal.
MD5:
40026391df8450b9b6e7802bc65ff9a4
 
 lookup in virustotal.com (40026391df8450b9b6e7802bc65ff9a4)-->[http://www.virustotal.com/analisis/14a84ab310b9a2b321388b590e764c8f79c8dee36078841b70fd768227a204f5-1257221303]lookup in threatexpert.comlookup the sha256(14a84ab310b9a2b321388b590e764c8f79c8dee36078841b70fd768227a204f5) in comodo.comfollow up this md5sum(40026391df8450b9b6e7802bc65ff9a4)follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack) for scanner (undef) in md5 table0/41 (0.00%) malwareurl_Eleonore Exploit Pack
Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/Client2.jar  up Saved evidence (5010 Bytes) of first contact as txt October 30 2009 19:23:34 CET.No evidence recorded deadSaved log of last contact as txt November 22 2009 21:55:37 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/Client2.jar follow up this domain(somstan.cn) somstan.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/Client2.jar
39 252187 2009-11-02 00:00:00 2009-11-22 21:55:36 501.9 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
1/41 (2.44%) 
 Virustotal.
MD5:
801b2f3a527b71faaa1809074bf8cf50
Exploit.Win32.Pidief.cux
 
 lookup in virustotal.com (801b2f3a527b71faaa1809074bf8cf50)-->[http://www.virustotal.com/analisis/5ebd6a16fdd88c95b01219060f94cf04eb93657258adec2a400e5d863520bdf3-1257221252]follow up this md5sum(801b2f3a527b71faaa1809074bf8cf50)follow up this itemfollow up this virusname (Exploit.Win32.Pidief.cux) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(Exploit.Win32.Pidief.cux) for scanner (Kaspersky) in md5 table1/41 (2.44%) Exploit.Win32.Pidief.cux
Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/pdf.php  up Saved evidence (3593 Bytes) of first contact as txt November 03 2009 05:05:41 CET.No evidence recorded deadSaved log of last contact as txt November 22 2009 21:55:36 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/pdf.php follow up this domain(somstan.cn) somstan.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/pdf.php
40 252188 2009-11-02 00:00:00 2009-11-09 06:54:27 174.9 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
0/41 (0.00%) 
 Virustotal.
MD5:
4fa0397d64f5cfcf2d8932f8a0cafa82
 
 lookup in virustotal.com (4fa0397d64f5cfcf2d8932f8a0cafa82)-->[http://www.virustotal.com/analisis/b6e66bc37eea8a270647d1f14f842297ff455d326b3a5c5a92961b5d7736dd48-1257221094]follow up this md5sum(4fa0397d64f5cfcf2d8932f8a0cafa82)follow up this itemfollow up this virusname (unknown_html_RFI_eval) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(unknown_html_RFI_eval) for scanner (undef) in md5 table0/41 (0.00%) unknown_html_RFI_eval
Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/?spl=2&br=MSIE&vers ...  up Saved evidence (47920 Bytes) of first contact as txt January 01 2000 01:00:00 CET.Saved evidence (34437 Bytes) of last contact as txt January 01 2000 01:00:00 CET. closed-13483Saved log of last contact as txt November 09 2009 06:54:26 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/?spl=2&br=MSIE&vers ... follow up this domain(somstan.cn) somstan.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/?spl=2&br=MSIE&vers ...
41 252189 2009-11-02 00:00:00 2009-11-15 11:36:50 323.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
0/41 (0.00%) 
 Virustotal.
MD5:
19e72ed69fa7815574f0c43c2329cc15
 
 lookup in virustotal.com (19e72ed69fa7815574f0c43c2329cc15)-->[http://www.virustotal.com/analisis/4c9ddfb8218b9e5ea436282d30540461dbebd74635f25e4ec81e150feb755221-1257221235]follow up this md5sum(19e72ed69fa7815574f0c43c2329cc15)follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack) for scanner (undef) in md5 table0/41 (0.00%) malwareurl_Eleonore Exploit Pack
Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/?spl=3&br=MSIE&vers ...  up Saved evidence (1655 Bytes) of first contact as txt January 01 2000 01:00:00 CET.No evidence recorded deadSaved log of last contact as txt November 15 2009 11:36:50 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/?spl=3&br=MSIE&vers ... follow up this domain(somstan.cn) somstan.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/?spl=3&br=MSIE&vers ...
42 252190 2009-11-02 00:00:00 2009-11-22 21:55:35 501.9 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
Saved local log of anubis as txt November 03 2009 06:03:37 CET.1/41 (2.44%) 
 Virustotal.
MD5:
2e82f77c8d231b3aa974637b762de216
Win32/Oficla.AP
 
 lookup in virustotal.com (2e82f77c8d231b3aa974637b762de216)-->[http://www.virustotal.com/analisis/742200ade84bd278d1d67428009ab0d1c1a757f211dc2a5b2e7a68b80c7c90a0-1257221246]lookup in threatexpert.comlookup the sha256(742200ade84bd278d1d67428009ab0d1c1a757f211dc2a5b2e7a68b80c7c90a0) in comodo.comfollow up this md5sum(2e82f77c8d231b3aa974637b762de216)follow up this itemfollow up this virusname (Win32%2FOficla.AP) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(Win32%2FOficla.AP) for scanner (NOD32) in md5 table1/41 (2.44%) Win32/Oficla.AP
Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/load.php?spl=Active ...  up Saved evidence (32256 Bytes) of first contact as txt November 03 2009 05:05:23 CET.No evidence recorded deadSaved log of last contact as txt November 22 2009 21:55:35 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/load.php?spl=Active ... follow up this domain(somstan.cn) somstan.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/load.php?spl=Active ...
43 252191 2009-11-02 00:00:00 2009-11-22 21:55:34 501.9 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
0/41 (0.00%) 
 Virustotal.
MD5:
fd7b694331ee4648c733fc2ec304856b
 
 lookup in virustotal.com (fd7b694331ee4648c733fc2ec304856b)-->[http://www.virustotal.com/analisis/883552ea91386e115c1a07f9ba6c64d8f538f2251ca4d328add2435bf7f1c8b6-1257221303]follow up this md5sum(fd7b694331ee4648c733fc2ec304856b)follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack) for scanner (undef) in md5 table0/41 (0.00%) malwareurl_Eleonore Exploit Pack
Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/stat.php  up Saved evidence (2132 Bytes) of first contact as txt November 03 2009 05:05:18 CET.No evidence recorded deadSaved log of last contact as txt November 22 2009 21:55:34 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/stat.php follow up this domain(somstan.cn) somstan.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://somstan.cn/sv/stat.php
44 252192 2009-11-02 00:00:00 2009-11-03 05:05:16 29.1 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack+%2F+Trojan+Oficla) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack+%2F+Trojan+Oficla) for scanner () in md5 table malwareurl_Eleonore Exploit Pack / Trojan Oficla
Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/index.php?s=40179851 ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt November 03 2009 05:05:16 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/index.php?s=40179851 ... follow up this domain(zaders.cn) zaders.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/index.php?s=40179851 ...
45 252193 2009-11-02 00:00:00 2009-11-15 11:36:39 323.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
0/41 (0.00%) 
 Virustotal.
MD5:
e8a81446d23ba14299a02de43d11a1ab
 
 lookup in virustotal.com (e8a81446d23ba14299a02de43d11a1ab)-->[http://www.virustotal.com/analisis/ecd85b6b23b39f0747488367c79e04855c4783a1cf7f2981a421e17996bf64c5-1257221160]follow up this md5sum(e8a81446d23ba14299a02de43d11a1ab)follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack+%2F+Trojan+Oficla) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack+%2F+Trojan+Oficla) for scanner (undef) in md5 table0/41 (0.00%) malwareurl_Eleonore Exploit Pack / Trojan Oficla
Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/x.x  up Saved evidence (104 Bytes) of first contact as txt October 28 2009 20:03:56 CET.No evidence recorded deadSaved log of last contact as txt November 15 2009 11:36:39 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/x.x follow up this domain(zaders.cn) zaders.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/x.x
46 252194 2009-11-02 00:00:00 2009-11-15 11:36:38 323.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
lookup in anubis0/41 (0.00%) 
 Virustotal.
MD5:
40026391df8450b9b6e7802bc65ff9a4
 
 lookup in virustotal.com (40026391df8450b9b6e7802bc65ff9a4)-->[http://www.virustotal.com/analisis/14a84ab310b9a2b321388b590e764c8f79c8dee36078841b70fd768227a204f5-1257221303]lookup in threatexpert.comlookup the sha256(14a84ab310b9a2b321388b590e764c8f79c8dee36078841b70fd768227a204f5) in comodo.comfollow up this md5sum(40026391df8450b9b6e7802bc65ff9a4)follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack+%2F+Trojan+Oficla) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack+%2F+Trojan+Oficla) for scanner (undef) in md5 table0/41 (0.00%) malwareurl_Eleonore Exploit Pack / Trojan Oficla
Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/Client2.jar  up Saved evidence (5010 Bytes) of first contact as txt October 30 2009 19:23:34 CET.No evidence recorded deadSaved log of last contact as txt November 15 2009 11:36:38 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/Client2.jar follow up this domain(zaders.cn) zaders.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/Client2.jar
47 252195 2009-11-02 00:00:00 2009-11-15 11:36:37 323.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
1/41 (2.44%) 
 Virustotal.
MD5:
45e79f0cdbc6116254784402a605f046
Exploit.Win32.Pidief.cux
 
 lookup in virustotal.com (45e79f0cdbc6116254784402a605f046)-->[http://www.virustotal.com/analisis/399262572eb35716e3a7b4dc09af79952ae5608d882a9a6f3705b941d950618a-1257221234]follow up this md5sum(45e79f0cdbc6116254784402a605f046)follow up this itemfollow up this virusname (Exploit.Win32.Pidief.cux) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(Exploit.Win32.Pidief.cux) for scanner (Kaspersky) in md5 table1/41 (2.44%) Exploit.Win32.Pidief.cux
Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/pdf.php  up Saved evidence (3596 Bytes) of first contact as txt November 03 2009 05:04:41 CET.No evidence recorded deadSaved log of last contact as txt November 15 2009 11:36:37 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/pdf.php follow up this domain(zaders.cn) zaders.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/pdf.php
48 252196 2009-11-02 00:00:00 2009-11-15 11:36:33 323.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
0/41 (0.00%) 
 Virustotal.
MD5:
f2792c4009b4756cbe521da563ad467c
 
 lookup in virustotal.com (f2792c4009b4756cbe521da563ad467c)-->[http://www.virustotal.com/analisis/019b9939573a6f28bd408bab78c758063506d7912cf90b944a01cf7e998fbfae-1257221174]follow up this md5sum(f2792c4009b4756cbe521da563ad467c)follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack+%2F+Trojan+Oficla) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack+%2F+Trojan+Oficla) for scanner (undef) in md5 table0/41 (0.00%) malwareurl_Eleonore Exploit Pack / Trojan Oficla
Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/?spl=2&br=MSIE&vers= ...  up Saved evidence (45232 Bytes) of first contact as txt January 01 2000 01:00:00 CET.No evidence recorded deadSaved log of last contact as txt November 15 2009 11:36:33 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/?spl=2&br=MSIE&vers= ... follow up this domain(zaders.cn) zaders.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/?spl=2&br=MSIE&vers= ...
49 252197 2009-11-02 00:00:00 2009-11-15 11:36:32 323.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
0/41 (0.00%) 
 Virustotal.
MD5:
215cc4b2441bbafc83f008fe2700c6bb
 
 lookup in virustotal.com (215cc4b2441bbafc83f008fe2700c6bb)-->[http://www.virustotal.com/analisis/563e5aab800566a70533465939172dc4b515e6047e5fa821220bc11f2e140aa9-1257221116]follow up this md5sum(215cc4b2441bbafc83f008fe2700c6bb)follow up this itemfollow up this virusname (malwareurl_Eleonore+Exploit+Pack+%2F+Trojan+Oficla) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(malwareurl_Eleonore+Exploit+Pack+%2F+Trojan+Oficla) for scanner (undef) in md5 table0/41 (0.00%) malwareurl_Eleonore Exploit Pack / Trojan Oficla
Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/?spl=3&br=MSIE&vers= ...  up Saved evidence (1646 Bytes) of first contact as txt January 01 2000 01:00:00 CET.No evidence recorded deadSaved log of last contact as txt November 15 2009 11:36:32 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/?spl=3&br=MSIE&vers= ... follow up this domain(zaders.cn) zaders.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/?spl=3&br=MSIE&vers= ...
50 252198 2009-11-02 00:00:00 2009-11-15 11:36:31 323.6 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
Saved local log of anubis as txt November 03 2009 06:03:38 CET.1/41 (2.44%) 
 Virustotal.
MD5:
2e82f77c8d231b3aa974637b762de216
Win32/Oficla.AP
 
 lookup in virustotal.com (2e82f77c8d231b3aa974637b762de216)-->[http://www.virustotal.com/analisis/742200ade84bd278d1d67428009ab0d1c1a757f211dc2a5b2e7a68b80c7c90a0-1257221246]lookup in threatexpert.comlookup the sha256(742200ade84bd278d1d67428009ab0d1c1a757f211dc2a5b2e7a68b80c7c90a0) in comodo.comfollow up this md5sum(2e82f77c8d231b3aa974637b762de216)follow up this itemfollow up this virusname (Win32%2FOficla.AP) as RSS-FeedBlocked by google safebrowsing malwarelist click for analyse pagefollow up this malware(Win32%2FOficla.AP) for scanner (NOD32) in md5 table1/41 (2.44%) Win32/Oficla.AP
Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/load.php?spl=ActiveX ...  up Saved evidence (32256 Bytes) of first contact as txt November 03 2009 05:03:57 CET.No evidence recorded deadSaved log of last contact as txt November 15 2009 11:36:31 CET. SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(ip) in same window 210.51.166.247 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS9929) in networks tablefollow up this itemfollow up this AS (AS9929) as RSS-Feed AS9929 SenderBaselookup 210.51.166.247 at Rus CERT university stuttgart germanylookup 210.51.166.247 at apnicfollow up this item(review) in same window 210.51.166.247 Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/load.php?spl=ActiveX ... follow up this domain(zaders.cn) zaders.cn follow up this itemfollow up this country (CN) as RSS-Feed CN follow up this itemfollow up this region (APNIC) as RSS-Feed APNIC follow up this itemfollow up this enail (abuse@cnc-noc.net) as RSS-Feed abuse@cnc-noc.net follow up this itemfollow up this item 210.51.160.0 - 210.51.175.255 follow up this item CNC-BJ-IDC2 follow up this item Beijing YiZhuang IDC of China NetcomCNC Group CncNet follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://zaders.cn/sv/load.php?spl=ActiveX ...
Click here for other vital incidents