CLEAN MX realtime database    
public access query for virus URL statistics
Totally watched: 3640373 As of 2014-04-21 10:19:01 CEST
Subscribe to the VirusWatch Mailing list, updated hourly

This database consists of Virus URI, collected and verified since Feb 2006
Tweet
If you detect URI'S concerning your netblock, already closed... you have made a good job, otherwise please close them as soon as possible.

to look at some nice charts, there are complete statisticsstatistics for this database
Attention: all URI'S are manually verified, but not cross-checked for real viruses function in this moment you make this query.(Sites may have been closed already..)
Our automatic Viruswalker process is scheduled every hour, so you may see now a incident and this one will be resolved later on.
So please keep on sending close-feedbacks to us...

if you have questions, criticism, wishes or ... do not hesitate to contact us at abuse@clean-mx.de
Our PBX is down you may reach us by cell phone +49 171 4802507 ...
Query as xml: Same query as xml output
TIMERS: Runtime Query: 0.0036 Seconds 7 hits
helpLine help#descendigascending helpDatedescendigascending helpCloseddescendigascending helphours helpcontributordescendigascending helpvirusnamedescendigascending helpURLdescendigascending helpip state helpresponsedescendigascending helpIp initialdescendigascending helpAS#descendigascending helpip reviewdescendigascending helpURLdescendigascending helpDomaindescendigascending helpcountrydescendigascending helpsourcedescendigascending helpemaildescendigascending helpinetnumdescendigascending helpnetnamedescendigascending helpdescrdescendigascending helpns1descendigascending helpns2descendigascending helpns3descendigascending helpns4descendigascending helpns5descendigascending helpURLdescendigascending
1 follow up this item(22836829) 22836829 Report false positive Report closed case make a suggestion 2014-03-16 12:50:26 OVERDUE! Overdue!860.5 follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
1/49 (2%) 
 
Heuristic-31 
 lookup in virustotal.com (d0e20c64b2a5fb140723a6f27c89cbad)-->[http://www.virustotal.com/latest-report.html?resource=d0e20c64b2a5fb140723a6f27c89cbad]follow up this md5sum(d0e20c64b2a5fb140723a6f27c89cbad)follow up this itemfollow up this virusname (Heuristic-31) as RSS-Feedfollow up this malware(Heuristic-31) for scanner (F_Prot) in md5 table1/49 (2%) Heuristic-31
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://nikunjp.wordpress.com/  up No previous evidence recordedSaved evidence (98988 Bytes) of last contact as txt March 16 2014 13:04:51 CET. aliveSaved log of last contact as txt March 16 2014 13:04:51 CET. follow up this ip (ip=66.155.9.238) as RSS-FeedSenderBaselookup 66.155.9.238 at virustotallookup 66.155.9.238 at Rus CERT university stuttgart germanylookup 66.155.9.238 at ARINfollow up this item(ip) in same window 66.155.9.238 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS13768) in networks tablefollow up this itemfollow up this AS (AS13768) as RSS-Feed AS13768 follow up this ip (review=192.0.81.250) as RSS-FeedSenderBaselookup 192.0.81.250 at virustotallookup 192.0.81.250 at Rus CERT university stuttgart germanylookup 192.0.81.250 at ARINfollow up this item(review) in same window 192.0.81.250 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://nikunjp.wordpress.com/ follow up this domain (wordpress.com) as RSS-Feedlookup wordpress.com at virustotalfollow up this domain(wordpress.com) wordpress.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (ipadmin@automattic.com) as RSS-Feed ipadmin@automattic.com follow up this itemfollow up this item 66.155.0.0 - 66.155.127.255 follow up this item AUTOMATTIC follow up this item Automattic, Inc AUTOM-93 60 29th Street #343 San Francisco CA 94110 follow up this item ns4.wordpress.com follow up this item ns5.wordpress.com follow up this item ns3.wordpress.com follow up this item ns2.wordpress.com follow up this item ns6.wordpress.com Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://nikunjp.wordpress.com/
2 follow up this item(16051531) 16051531  2013-10-13 15:40:22 2013-10-13 17:23:31 1.7 follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
0/48 (0.0%) 
  
 lookup in virustotal.com (4f0e6a459909c613a55c9b9757a1935c)-->[http://www.virustotal.com/latest-report.html?resource=4f0e6a459909c613a55c9b9757a1935c]lookup in threatexpert.comlookup the sha256(c7e5d9600c1177a4d213a2c3c7887617407921d7c191952e567b8f00b3818d14) in comodo.comfollow up this md5sum(4f0e6a459909c613a55c9b9757a1935c)follow up this itemfollow up this virusname (Heuristic-31) as RSS-Feedfollow up this malware(Heuristic-31) for scanner (undef) in md5 table0/48 (0.0%) Heuristic-31
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://s3.trbonet.com/download/enterpris ...  up No previous evidence recordedSaved evidence (13460769 Bytes) of last contact as txt October 13 2013 16:52:43 CEST. closedSaved log of last contact as txt October 13 2013 16:52:43 CEST. follow up this ip (ip=176.32.101.148) as RSS-FeedSenderBaselookup 176.32.101.148 at virustotallookup 176.32.101.148 at Rus CERT university stuttgart germanylookup 176.32.101.148 at ARINfollow up this item(ip) in same window 176.32.101.148 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS16509) in networks tablefollow up this itemfollow up this AS (AS16509) as RSS-Feed AS16509 follow up this ip (review=205.251.243.60) as RSS-FeedSenderBaselookup 205.251.243.60 at virustotallookup 205.251.243.60 at Rus CERT university stuttgart germanylookup 205.251.243.60 at ARINfollow up this item(review) in same window 205.251.243.60 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://s3.trbonet.com/download/enterpris ... follow up this domain (trbonet.com) as RSS-Feedlookup trbonet.com at virustotalfollow up this domain(trbonet.com) trbonet.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (noc@amazon.com) as RSS-Feed noc@amazon.com follow up this itemfollow up this item 176.32.96.0 - 176.32.103.255 follow up this item AMAZON-05 follow up this item Amazon.com, Inc. AMAZON-4 605 5th Ave S SEATTLE WA 98104 follow up this item ns2.1gb.ru follow up this item ns1.1gb.ru follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://s3.trbonet.com/download/enterpris ...
3 follow up this item(14997488) 14997488 Report false positive Report closed case make a suggestion 2013-09-13 01:44:49 OVERDUE! Overdue!5288.6 follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
lookup in virustotal.com (36af5fdcd8bfdba87ad2ea5d9a8116ef)lookup in threatexpert.comlookup the sha256(a54d703a40155892411fcb6208c075a5c7b13e937d7d3a8c5469b94e10c2f512) in comodo.comfollow up this md5sum(36af5fdcd8bfdba87ad2ea5d9a8116ef)follow up this itemfollow up this virusname (Heuristic-31) as RSS-Feedfollow up this malware(Heuristic-31) for scanner (undef) in md5 table1/45 (2.2%) Heuristic-31
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://trbonet.com/download/latest/4.0.1 ...  up No previous evidence recordedSaved evidence (30191428 Bytes) of last contact as txt August 27 2013 17:55:31 CEST. aliveSaved log of last contact as txt September 13 2013 05:51:23 CEST. follow up this ip (ip=81.176.226.28) as RSS-FeedSenderBaselookup 81.176.226.28 at virustotallookup 81.176.226.28 at Rus CERT university stuttgart germanylookup 81.176.226.28 at Ripefollow up this item(ip) in same window 81.176.226.28 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS8342) in networks tablefollow up this itemfollow up this AS (AS8342) as RSS-Feed AS8342 follow up this ip (review=81.176.226.28) as RSS-FeedSenderBaselookup 81.176.226.28 at virustotallookup 81.176.226.28 at Rus CERT university stuttgart germanylookup 81.176.226.28 at Ripefollow up this item(review) in same window 81.176.226.28 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://trbonet.com/download/latest/4.0.1 ... follow up this domain (trbonet.com) as RSS-Feedlookup trbonet.com at virustotalfollow up this domain(trbonet.com) trbonet.com follow up this itemfollow up this country (RU) as RSS-Feed RU follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (noc@in-solve.ru) as RSS-Feed noc@in-solve.ru follow up this itemfollow up this item 81.176.226.0 - 81.176.226.255 follow up this item INSOLVERTC2 follow up this item In-Solve/1Gb.ru hosting services provider107078, Russia, MoscowRTCOMM-RU follow up this item ns1.1gb.ru follow up this item ns2.1gb.ru follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://trbonet.com/download/latest/4.0.1 ...
4 follow up this item(13782617) 13782617 Report false positive Report closed case make a suggestion 2013-08-05 00:08:11 OVERDUE! Overdue!6226.2 follow up this itemfollow up this contributor (csirt) as RSS-Feed sub31possible lookup Evidence at malwaredomainlist.com
1/34 (2.9%) 
 
Heuristic-31 
 lookup in virustotal.com (ff1516b58dc37f8cf49d2a308d38a434)-->[http://www.virustotal.com/latest-report.html?resource=ff1516b58dc37f8cf49d2a308d38a434]follow up this md5sum(ff1516b58dc37f8cf49d2a308d38a434)follow up this itemfollow up this virusname (Heuristic-31) as RSS-Feedfollow up this malware(Heuristic-31) for scanner (F_Prot) in md5 table1/34 (2.9%) Heuristic-31
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://auto.mail.ru/opinions/volkswagen/ ...  up No previous evidence recordedSaved evidence (132809 Bytes) of last contact as txt August 05 2013 04:31:24 CEST. aliveSaved log of last contact as txt August 05 2013 04:31:24 CEST. follow up this ip (ip=217.69.134.40) as RSS-FeedSenderBaselookup 217.69.134.40 at virustotallookup 217.69.134.40 at Rus CERT university stuttgart germanylookup 217.69.134.40 at Ripefollow up this item(ip) in same window 217.69.134.40 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS47764) in networks tablefollow up this itemfollow up this AS (AS47764) as RSS-Feed AS47764 follow up this ip (review=217.69.134.40) as RSS-FeedSenderBaselookup 217.69.134.40 at virustotallookup 217.69.134.40 at Rus CERT university stuttgart germanylookup 217.69.134.40 at Ripefollow up this item(review) in same window 217.69.134.40 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://auto.mail.ru/opinions/volkswagen/ ... follow up this domain (mail.ru) as RSS-Feedlookup mail.ru at virustotalfollow up this domain(mail.ru) mail.ru follow up this itemfollow up this country (RU) as RSS-Feed RU follow up this itemfollow up this region (RIPE) as RSS-Feed RIPE follow up this itemfollow up this enail (gabrelyan@corp.mail.ru) as RSS-Feed gabrelyan@corp.mail.ru follow up this itemfollow up this item 217.69.128.0 - 217.69.135.255 follow up this item MAILRU-NET follow up this item MAILRU-NETLLC netBridge ServicesMAILRU-MAIL follow up this item ns2.mail.ru follow up this item ns.mail.ru follow up this item ns5.mail.ru follow up this item ns3.mail.ru follow up this item ns1.mail.ru Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://auto.mail.ru/opinions/volkswagen/ ...
5 follow up this item(13782418) 13782418 Report false positive Report closed case make a suggestion 2013-08-05 00:41:32 OVERDUE! Overdue!6225.7 follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
1/46 (2.2%) 
 Heuristic-31 
 lookup in virustotal.com (f1af6e26f8866e1cf3bca510e9b76f7f)-->[http://www.virustotal.com/latest-report.html?resource=f1af6e26f8866e1cf3bca510e9b76f7f]lookup in threatexpert.comlookup the sha256(c984c1fa52b7c79df23de51ea4822f981dc681eae1e757c83fd7d734a8205173) in comodo.comfollow up this md5sum(f1af6e26f8866e1cf3bca510e9b76f7f)follow up this itemfollow up this virusname (Heuristic-31) as RSS-Feedfollow up this malware(Heuristic-31) for scanner (undef) in md5 table1/46 (2.2%) Heuristic-31
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.ultraedit.com/files/wf/xbasic ...  up No previous evidence recordedSaved evidence (431416 Bytes) of last contact as txt April 17 2009 23:07:52 CEST. aliveSaved log of last contact as txt August 05 2013 04:04:51 CEST. follow up this ip (ip=174.121.177.30) as RSS-FeedSenderBaselookup 174.121.177.30 at virustotallookup 174.121.177.30 at Rus CERT university stuttgart germanylookup 174.121.177.30 at ARINfollow up this item(ip) in same window 174.121.177.30 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS36420, AS30315, AS13749, AS21844) in networks tablefollow up this itemfollow up this AS (AS36420, AS30315, AS13749, AS21844) as RSS-Feed AS36420, AS30315, AS13749, AS21844 follow up this ip (review=174.121.177.30) as RSS-FeedSenderBaselookup 174.121.177.30 at virustotallookup 174.121.177.30 at Rus CERT university stuttgart germanylookup 174.121.177.30 at ARINfollow up this item(review) in same window 174.121.177.30 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.ultraedit.com/files/wf/xbasic ... follow up this domain (ultraedit.com) as RSS-Feedlookup ultraedit.com at virustotalfollow up this domain(ultraedit.com) ultraedit.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (noc@theplanet.com) as RSS-Feed noc@theplanet.com follow up this itemfollow up this item 174.120.0.0 - 174.123.255.255 follow up this item NETBLK-THEPLANET-BLK-16 follow up this item ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002 follow up this item ns2.theplanet.com follow up this item ns1.theplanet.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.ultraedit.com/files/wf/xbasic ...
6 follow up this item(10835109) 10835109 Report false positive Report closed case make a suggestion 2013-05-11 02:46:26 OVERDUE! Overdue!8287.6 follow up this itemfollow up this contributor (test) as RSS-Feed sub16possible lookup Evidence at malwaredomainlist.com
1/46 (2.2%) 
 Heuristic-31 
 lookup in virustotal.com (dadd2c63bbc8014706feb29777153e5f)-->[http://www.virustotal.com/latest-report.html?resource=dadd2c63bbc8014706feb29777153e5f]follow up this md5sum(dadd2c63bbc8014706feb29777153e5f)follow up this itemfollow up this virusname (Heuristic-31) as RSS-Feedfollow up this malware(Heuristic-31) for scanner (undef) in md5 table1/46 (2.2%) Heuristic-31
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.wardom.org/en-tehlikeli-virus ...  up No previous evidence recordedSaved evidence (60714 Bytes) of last contact as txt May 11 2013 11:46:36 CEST. aliveSaved log of last contact as txt May 11 2013 11:46:36 CEST. follow up this ip (ip=198.204.228.186) as RSS-FeedSenderBaselookup 198.204.228.186 at virustotallookup 198.204.228.186 at Rus CERT university stuttgart germanylookup 198.204.228.186 at ARINfollow up this item(ip) in same window 198.204.228.186 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS33387) in networks tablefollow up this itemfollow up this AS (AS33387) as RSS-Feed AS33387 follow up this ip (review=198.204.228.186) as RSS-FeedSenderBaselookup 198.204.228.186 at virustotallookup 198.204.228.186 at Rus CERT university stuttgart germanylookup 198.204.228.186 at ARINfollow up this item(review) in same window 198.204.228.186 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.wardom.org/en-tehlikeli-virus ... follow up this domain (wardom.org) as RSS-Feedlookup wardom.org at virustotalfollow up this domain(wardom.org) wardom.org follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (security@datashack.net) as RSS-Feed security@datashack.net follow up this itemfollow up this item 198.204.224.0 - 198.204.255.255 follow up this item DSV4-6 follow up this item DataShack, LC DL-9 1321 Burlington Suite 501 North Kansas City MO 64116 follow up this item ns2.turkbox.net follow up this item ns1.turkbox.net follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.wardom.org/en-tehlikeli-virus ...
7 follow up this item(769019) 769019  2011-03-05 00:54:47 2011-06-10 04:28:38 2330.6 follow up this itemfollow up this contributor (Paretologic.com) as RSS-Feed sub10possible lookup Evidence at malwaredomainlist.com
2/40 (5%) 
 
Heuristic-31
EmailWorm 
 lookup in virustotal.com (1405cbe000e90dbbe7c8447a23625511)-->[http://www.virustotal.com/latest-report.html?resource=1405cbe000e90dbbe7c8447a23625511]lookup in threatexpert.comlookup the sha256(e78c076f084e7b7bf8a00f2b45bfdd8e607aa34f227c6b93e66ad30719bdfdfd) in comodo.comfollow up this md5sum(1405cbe000e90dbbe7c8447a23625511)follow up this itemfollow up this virusname (Heuristic-31) as RSS-Feedfollow up this malware(Heuristic-31) for scanner (F_Prot) in md5 table2/40 (5%) Heuristic-31
Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.ultraedit.com/files/wf/wf.zip ...  up No previous evidence recordedNo evidence recorded deadSaved log of last contact as txt June 10 2011 04:28:38 CEST. follow up this ip (ip=174.121.177.30) as RSS-FeedSenderBaselookup 174.121.177.30 at virustotallookup 174.121.177.30 at Rus CERT university stuttgart germanylookup 174.121.177.30 at ARINfollow up this item(ip) in same window 174.121.177.30 possible lookup  in maliciousnetworks.org (FIRE: FInding RoguE Networks) pagepossible lookup in google safebrowsing pagefollow up this AS (AS36420, AS30315, AS13749, AS21844) in networks tablefollow up this itemfollow up this AS (AS36420, AS30315, AS13749, AS21844) as RSS-Feed AS36420, AS30315, AS13749, AS21844 follow up this ip (review=174.121.177.30) as RSS-FeedSenderBaselookup 174.121.177.30 at virustotallookup 174.121.177.30 at Rus CERT university stuttgart germanylookup 174.121.177.30 at ARINfollow up this item(review) in same window 174.121.177.30 Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.ultraedit.com/files/wf/wf.zip ... follow up this domain (ultraedit.com) as RSS-Feedlookup ultraedit.com at virustotalfollow up this domain(ultraedit.com) ultraedit.com follow up this itemfollow up this country (US) as RSS-Feed US follow up this itemfollow up this region (ARIN) as RSS-Feed ARIN follow up this itemfollow up this enail (noc@theplanet.com) as RSS-Feed noc@theplanet.com follow up this itemfollow up this item 174.120.0.0 - 174.123.255.255 follow up this item NETBLK-THEPLANET-BLK-16 follow up this item ThePlanet.com Internet Services, Inc. TPCM 315 Capitol Suite 205 Houston TX 77002 follow up this item ns1.theplanet.com follow up this item ns2.theplanet.com follow up this item  follow up this item  follow up this item  Safe Virus-Viewer and Analyser may take a minute to completelookup in virustotal http://www.ultraedit.com/files/wf/wf.zip ...
Click here for other vital incidents



Protected by clean MX [Valid RSS] Valid HTML 4.01 Transitional CSS ist valide!
Access is provided for free and subject to these Terms and Conditions.