CLEAN MX realtime database
public access query for virus URL statistics
Totally watched: 20282, to down: 0, to up: 0, changed ip: 0
As of 2010-09-02 22:05:27 CEST
Subscribe to the VirusWatch Mailing list, updated hourly

This database consists of Virus URI, collected and verified since Feb 2006

If you detect URI'S concerning your netblock, already closed... you have made a good job, otherwise please close them as soon as possible.

to look at some nice charts, there are complete statisticsstatistics for this database
Attention: all URI'S are manually verified, but not cross-checked for real viruses function in this moment you make this query.(Sites may have been closed already..)
Our automatic Viruswalker process is scheduled every hour, so you may see now a incident and this one will be resolved later on.
So please keep on sending close-feedbacks to us...

if you have questions, criticism, wishes or ... do not hesitate to contact us at abuse@clean-mx.de
Our PBX is down you may reach us by cell phone +49 171 4802507 ...
Welcome back, would be fine to get some feedback from your site..
Query as xml: Same query as xml output
TIMERS: Runtime Query: 0.0058 Seconds
helpLine help#descendigascending helpDatedescendigascending helpCloseddescendigascending helphours helpcontributordescendigascending helpvirusnamedescendigascending helpURLdescendigascending helpip state helpresponsedescendigascending helpIp initialdescendigascending helpAS#descendigascending helpip reviewdescendigascending helpURLdescendigascending helpDomaindescendigascending helpcountrydescendigascending helpsourcedescendigascending helpemaildescendigascending helpinetnumdescendigascending helpnetnamedescendigascending helpdescrdescendigascending helpns1descendigascending helpns2descendigascending helpns3descendigascending helpns4descendigascending helpns5descendigascending helpURLdescendigascending
1 620133 2010-07-13 14:40:03 2010-07-13 15:14:30 0.6 follow up this itemfollow up this contributor (sub12) as RSS-Feed sub12possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://vu.purzmhsalf.co.cc/befothokesco. ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 13 2010 15:14:30 CEST. SenderBaselookup 94.76.205.177 at Rus CERT university stuttgart germanylookup 94.76.205.177 at Ripefollow up this item(ip) in same window 94.76.205.177 SenderBaselookup 94.76.205.177 at Rus CERT university stuttgart germanylookup 94.76.205.177 at Ripefollow up this item(review) in same window 94.76.205.177 Safe Virus-Viewer and Analyser may take a minute to complete http://vu.purzmhsalf.co.cc/befothokesco. ... follow up this domain(purzmhsalf.co.cc) purzmhsalf.co.cc follow up this itemfollow up this country (GB) as RSS-Feed GB follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@blueconnex.net) as RSS-Feed abuse@blueconnex.net follow up this itemfollow up this item 94.76.205.176 - 94.76.205.191 follow up this item Poundhost-3742 follow up this item Poundhost customer serverBlueconnex Networks Ltd follow up this item ns1.freepublicdns.com follow up this item ns2.freepublicdns.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://vu.purzmhsalf.co.cc/befothokesco. ...
2 620113 2010-07-13 13:40:03 2010-07-13 14:16:46 0.6 follow up this itemfollow up this contributor (sub12) as RSS-Feed sub12possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://hude.dymfqzejoi.co.cc/arere.html  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 13 2010 14:16:46 CEST. SenderBaselookup 94.76.205.183 at Rus CERT university stuttgart germanylookup 94.76.205.183 at Ripefollow up this item(ip) in same window 94.76.205.183 SenderBaselookup 94.76.205.183 at Rus CERT university stuttgart germanylookup 94.76.205.183 at Ripefollow up this item(review) in same window 94.76.205.183 Safe Virus-Viewer and Analyser may take a minute to complete http://hude.dymfqzejoi.co.cc/arere.html follow up this domain(dymfqzejoi.co.cc) dymfqzejoi.co.cc follow up this itemfollow up this country (GB) as RSS-Feed GB follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@blueconnex.net) as RSS-Feed abuse@blueconnex.net follow up this itemfollow up this item 94.76.205.176 - 94.76.205.191 follow up this item Poundhost-3742 follow up this item Poundhost customer serverBlueconnex Networks Ltd follow up this item ns1.freepublicdns.com follow up this item ns2.freepublicdns.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://hude.dymfqzejoi.co.cc/arere.html
3 620114 2010-07-13 13:40:03 2010-07-13 14:16:42 0.6 follow up this itemfollow up this contributor (sub12) as RSS-Feed sub12possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://hude.dymfqzejoi.co.cc/kinenfathen ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 13 2010 14:16:42 CEST. SenderBaselookup 94.76.205.183 at Rus CERT university stuttgart germanylookup 94.76.205.183 at Ripefollow up this item(ip) in same window 94.76.205.183 SenderBaselookup 94.76.205.183 at Rus CERT university stuttgart germanylookup 94.76.205.183 at Ripefollow up this item(review) in same window 94.76.205.183 Safe Virus-Viewer and Analyser may take a minute to complete http://hude.dymfqzejoi.co.cc/kinenfathen ... follow up this domain(dymfqzejoi.co.cc) dymfqzejoi.co.cc follow up this itemfollow up this country (GB) as RSS-Feed GB follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@blueconnex.net) as RSS-Feed abuse@blueconnex.net follow up this itemfollow up this item 94.76.205.176 - 94.76.205.191 follow up this item Poundhost-3742 follow up this item Poundhost customer serverBlueconnex Networks Ltd follow up this item ns1.freepublicdns.com follow up this item ns2.freepublicdns.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://hude.dymfqzejoi.co.cc/kinenfathen ...
4 620105 2010-07-13 13:00:15 2010-07-13 13:12:07 0.2 follow up this itemfollow up this contributor (sub12) as RSS-Feed sub12possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://vu.purzmhsalf.co.cc/zdoterozli.ht ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 13 2010 13:12:07 CEST. SenderBaselookup 94.76.205.177 at Rus CERT university stuttgart germanylookup 94.76.205.177 at Ripefollow up this item(ip) in same window 94.76.205.177 SenderBaselookup 94.76.205.177 at Rus CERT university stuttgart germanylookup 94.76.205.177 at Ripefollow up this item(review) in same window 94.76.205.177 Safe Virus-Viewer and Analyser may take a minute to complete http://vu.purzmhsalf.co.cc/zdoterozli.ht ... follow up this domain(purzmhsalf.co.cc) purzmhsalf.co.cc follow up this itemfollow up this country (GB) as RSS-Feed GB follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@blueconnex.net) as RSS-Feed abuse@blueconnex.net follow up this itemfollow up this item 94.76.205.176 - 94.76.205.191 follow up this item Poundhost-3742 follow up this item Poundhost customer serverBlueconnex Networks Ltd follow up this item ns1.freepublicdns.com follow up this item ns2.freepublicdns.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://vu.purzmhsalf.co.cc/zdoterozli.ht ...
5 620107 2010-07-13 13:00:15 2010-07-13 13:11:58 0.2 follow up this itemfollow up this contributor (sub12) as RSS-Feed sub12possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://yo.purzmhsalf.co.cc/dedasendrsh.h ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 13 2010 13:11:58 CEST. SenderBaselookup 94.76.205.177 at Rus CERT university stuttgart germanylookup 94.76.205.177 at Ripefollow up this item(ip) in same window 94.76.205.177 SenderBaselookup 94.76.205.177 at Rus CERT university stuttgart germanylookup 94.76.205.177 at Ripefollow up this item(review) in same window 94.76.205.177 Safe Virus-Viewer and Analyser may take a minute to complete http://yo.purzmhsalf.co.cc/dedasendrsh.h ... follow up this domain(purzmhsalf.co.cc) purzmhsalf.co.cc follow up this itemfollow up this country (GB) as RSS-Feed GB follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@blueconnex.net) as RSS-Feed abuse@blueconnex.net follow up this itemfollow up this item 94.76.205.176 - 94.76.205.191 follow up this item Poundhost-3742 follow up this item Poundhost customer serverBlueconnex Networks Ltd follow up this item ns1.freepublicdns.com follow up this item ns2.freepublicdns.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://yo.purzmhsalf.co.cc/dedasendrsh.h ...
6 620098 2010-07-13 12:40:06 2010-07-13 13:12:20 0.5 follow up this itemfollow up this contributor (sub12) as RSS-Feed sub12possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (NA) as RSS-Feedfollow up this malware(NA) for scanner (undef) in md5 table NA
Safe Virus-Viewer and Analyser may take a minute to complete http://qi.nfabepiyqh.co.cc/  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt July 13 2010 13:12:20 CEST. SenderBaselookup 94.76.205.180 at Rus CERT university stuttgart germanylookup 94.76.205.180 at Ripefollow up this item(ip) in same window 94.76.205.180 SenderBaselookup 94.76.205.180 at Rus CERT university stuttgart germanylookup 94.76.205.180 at Ripefollow up this item(review) in same window 94.76.205.180 Safe Virus-Viewer and Analyser may take a minute to complete http://qi.nfabepiyqh.co.cc/ follow up this domain(nfabepiyqh.co.cc) nfabepiyqh.co.cc follow up this itemfollow up this country (GB) as RSS-Feed GB follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@blueconnex.net) as RSS-Feed abuse@blueconnex.net follow up this itemfollow up this item 94.76.205.176 - 94.76.205.191 follow up this item Poundhost-3742 follow up this item Poundhost customer serverBlueconnex Networks Ltd follow up this item ns2.freepublicdns.com follow up this item ns1.freepublicdns.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://qi.nfabepiyqh.co.cc/
7 233030 2009-10-18 00:00:00 2010-04-01 15:39:12 3975.7 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
0/40 (0.00%) 
 Virustotal.
MD5:
ff388291c25da438339766d4782c695e
 
 lookup in virustotal.com (47b53815408e0af8a913f334abcb5091)-->[http://www.virustotal.com/analisis/e147086224bcead2259e05b5df80e598f83b3c9fdc38570a5fe0846ade3d5a11-1255926928]follow up this md5sum(47b53815408e0af8a913f334abcb5091)follow up this itemfollow up this virusname (malwareurl_Directs+to+Rogue+Antivirus) as RSS-Feedfollow up this malware(malwareurl_Directs+to+Rogue+Antivirus) for scanner (undef) in md5 table0/40 (0.00%) malwareurl_Directs to Rogue Antivirus
Safe Virus-Viewer and Analyser may take a minute to complete http://mixxquery.com/559932.js?sid=c2l1d ...  up Saved evidence (159 Bytes) of first contact as txt October 19 2009 06:33:32 CEST.No evidence recorded deadSaved log of last contact as txt April 01 2010 15:39:12 CEST. SenderBaselookup 94.76.205.181 at Rus CERT university stuttgart germanylookup 94.76.205.181 at Ripefollow up this item(ip) in same window 94.76.205.181 SenderBaselookup 94.76.205.181 at Rus CERT university stuttgart germanylookup 94.76.205.181 at Ripefollow up this item(review) in same window 94.76.205.181 Safe Virus-Viewer and Analyser may take a minute to complete http://mixxquery.com/559932.js?sid=c2l1d ... follow up this domain(mixxquery.com) mixxquery.com follow up this itemfollow up this country (GB) as RSS-Feed GB follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@blueconnex.net) as RSS-Feed abuse@blueconnex.net follow up this itemfollow up this item 94.76.205.176 - 94.76.205.191 follow up this item Poundhost-3742 follow up this item Poundhost customer serverBlueconnex Networks Ltd follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://mixxquery.com/559932.js?sid=c2l1d ...
8 233031 2009-10-18 00:00:00 2009-10-21 01:18:59 73.3 follow up this itemfollow up this contributor (sub6) as RSS-Feed sub6lookup Evidence at malwareurl.com
0/41 (0.00%) 
 Virustotal.
MD5:
bca59de10a89e53ee13e8e6f34576083
 
 lookup in virustotal.com (bca59de10a89e53ee13e8e6f34576083)-->[http://www.virustotal.com/analisis/1efde892972ea1271638c561d3b69dc0e449ff32589a6cdfc3cac84e22c1cd42-1255927019]follow up this md5sum(bca59de10a89e53ee13e8e6f34576083)follow up this itemfollow up this virusname (malwareurl_Directs+to+Rogue+Antivirus+%28Referer+must+be+a+Google+query%3A+google.com%2Fsearch%3Fq%3D%29) as RSS-Feedfollow up this malware(malwareurl_Directs+to+Rogue+Antivirus+%28Referer+must+be+a+Google+query%3A+google.com%2Fsearch%3Fq%3D%29) for scanner (undef) in md5 table0/41 (0.00%) malwareurl_Directs to Rogue Antivirus (Referer must be a Google query: google.com/search?q=)
Safe Virus-Viewer and Analyser may take a minute to complete http://siutor_preschoo6c.mixxquery.com/i ...  up Saved evidence (9021 Bytes) of first contact as txt October 19 2009 06:33:30 CEST.No evidence recorded deadSaved log of last contact as txt October 21 2009 01:18:59 CEST. SenderBaselookup 94.76.205.181 at Rus CERT university stuttgart germanylookup 94.76.205.181 at Ripefollow up this item(ip) in same window 94.76.205.181 SenderBaselookup 94.76.205.181 at Rus CERT university stuttgart germanylookup 94.76.205.181 at Ripefollow up this item(review) in same window 94.76.205.181 Safe Virus-Viewer and Analyser may take a minute to complete http://siutor_preschoo6c.mixxquery.com/i ... follow up this domain(mixxquery.com) mixxquery.com follow up this itemfollow up this country (GB) as RSS-Feed GB follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@blueconnex.net) as RSS-Feed abuse@blueconnex.net follow up this itemfollow up this item 94.76.205.176 - 94.76.205.191 follow up this item Poundhost-3742 follow up this item Poundhost customer serverBlueconnex Networks Ltd follow up this item ns1.everydns.net follow up this item ns2.everydns.net follow up this item ns3.everydns.net follow up this item ns4.everydns.net follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://siutor_preschoo6c.mixxquery.com/i ...
9 43851 2009-06-03 00:00:00 2009-06-08 00:00:00 120 follow up this itemfollow up this contributor (sub4) as RSS-Feed sub4lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (unknown_html) as RSS-Feedfollow up this malware(unknown_html) for scanner (undef) in md5 table unknown_html
Safe Virus-Viewer and Analyser may take a minute to complete http://differentart.net/1/1410/  up No previous evidence recordedNo evidence recorded closedSaved log of last contact as txt July 05 2009 23:01:49 CEST. SenderBaselookup 94.76.205.160 at Rus CERT university stuttgart germanylookup 94.76.205.160 at Ripefollow up this item(ip) in same window 94.76.205.160 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS29550) in networks tablefollow up this itemfollow up this AS (AS29550) as RSS-Feed AS29550 SenderBaselookup 94.76.205.160 at Rus CERT university stuttgart germanylookup 94.76.205.160 at Ripefollow up this item(review) in same window 94.76.205.160 Safe Virus-Viewer and Analyser may take a minute to complete http://differentart.net/1/1410/ follow up this domain(differentart.net) differentart.net follow up this itemfollow up this country (GB) as RSS-Feed GB follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@blueconnex.net) as RSS-Feed abuse@blueconnex.net follow up this itemfollow up this item 94.76.192.0 - 94.76.255.255 follow up this item UK-POUNDHOST-20080807 follow up this item BlueConnex MK LtdBlueconnex Networks Ltd follow up this item ns29.domaincontrol.com follow up this item ns30.domaincontrol.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://differentart.net/1/1410/
10 22039 2009-02-23 20:55:26 2009-02-28 20:55:26 120 follow up this itemfollow up this contributor (sub1) as RSS-Feed sub1possible lookup Evidence at malwareurl.compossible lookup Evidence at malwaredomainlist.com
follow up this itemfollow up this virusname (unknown_html) as RSS-Feedfollow up this malware(unknown_html) for scanner (undef) in md5 table unknown_html
Safe Virus-Viewer and Analyser may take a minute to complete http://hot.mupe.xorg.pl/alereas.html  up No previous evidence recordedNo evidence recorded closedSaved log of last contact as txt February 24 2009 06:57:08 CET. SenderBaselookup 94.76.205.178 at Rus CERT university stuttgart germanylookup 94.76.205.178 at Ripefollow up this item(ip) in same window 94.76.205.178 SenderBaselookup 94.76.205.178 at Rus CERT university stuttgart germanylookup 94.76.205.178 at Ripefollow up this item(review) in same window 94.76.205.178 Safe Virus-Viewer and Analyser may take a minute to complete http://hot.mupe.xorg.pl/alereas.html follow up this domain(xorg.pl) xorg.pl follow up this itemfollow up this country (GB) as RSS-Feed GB follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (abuse@blueconnex.net) as RSS-Feed abuse@blueconnex.net follow up this itemfollow up this item 94.76.205.176 - 94.76.205.191 follow up this item Poundhost-3742 follow up this item Poundhost customer serverBlueconnex Networks Ltd follow up this item dns.xorg.pl follow up this item dns3.gery.pl follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to complete http://hot.mupe.xorg.pl/alereas.html
Click here for other vital incidents