<?xml version="1.0" encoding="iso-8859-15"?>
<output>
	<response>
		<error>0</error>
		<hits>32</hits>
	</response>
<entries>
<entry>
	<line>1</line>
	<id>10571074</id>
	<first>1367385622</first>
	<last>0</last>
	<md5>5077c5471197eeb0ae490177f65fbd86</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=5077c5471197eeb0ae490177f65fbd86</virustotal>
	<vt_score>1/46 (2.2%)</vt_score>
	<scanner>clamav</scanner>
	<virusname><![CDATA[JS.Redirect-4]]></virusname>
	<url><![CDATA[http://maildb.ftpserver.biz/in.cgi?16&amp;ad_type=st&amp;adsize=728x90&amp;log=6812&amp;ur=1&amp;HTTP_REFERER=http://www.123greetings.com/congratulations/promotion/]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>217.23.5.159</ip>
	<as>AS49981</as>
	<review>217.23.5.159</review>
	<domain>ftpserver.biz</domain>
	<country>NL</country>
	<source>RIPE</source>
	<email>abuse@customerpanel.nl</email>
	<inetnum>217.23.5.0 - 217.23.5.255</inetnum>
	<netname>WorldStream</netname>
	<descr><![CDATA[WorldStream IPv4.12CUSTOMERPANEL-BLK-217-23-0-0]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>2</line>
	<id>10544519</id>
	<first>1367316206</first>
	<last>0</last>
	<md5>3d04fe1ee8a41d46310a56071d076f75</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=3d04fe1ee8a41d46310a56071d076f75</virustotal>
	<vt_score>1/46 (2.2%)</vt_score>
	<scanner>clamav</scanner>
	<virusname><![CDATA[JS.Redirect-4]]></virusname>
	<url><![CDATA[http://maildb.ftpserver.biz/qkghw.cgi?16]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>217.23.5.159</ip>
	<as>AS49981</as>
	<review>217.23.5.159</review>
	<domain>ftpserver.biz</domain>
	<country>NL</country>
	<source>RIPE</source>
	<email>abuse@customerpanel.nl</email>
	<inetnum>217.23.5.0 - 217.23.5.255</inetnum>
	<netname>WorldStream</netname>
	<descr><![CDATA[WorldStream IPv4.12CUSTOMERPANEL-BLK-217-23-0-0]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>3</line>
	<id>10523804</id>
	<first>1367256682</first>
	<last>0</last>
	<md5>95a9077dceaebdcec3847ea6a6a695b3</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=95a9077dceaebdcec3847ea6a6a695b3</virustotal>
	<vt_score>1/46 (2.2%)</vt_score>
	<scanner>clamav</scanner>
	<virusname><![CDATA[JS.Redirect-4]]></virusname>
	<url><![CDATA[http://datastore.ftp1.biz/yjiti.cgi?18]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>217.23.5.159</ip>
	<as>AS49981</as>
	<review>217.23.5.159</review>
	<domain>ftp1.biz</domain>
	<country>NL</country>
	<source>RIPE</source>
	<email>abuse@customerpanel.nl</email>
	<inetnum>217.23.5.0 - 217.23.5.255</inetnum>
	<netname>WorldStream</netname>
	<descr><![CDATA[WorldStream IPv4.12CUSTOMERPANEL-BLK-217-23-0-0]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>4</line>
	<id>9170956</id>
	<first>1358836421</first>
	<last>0</last>
	<md5>d41d8cd98f00b204e9800998ecf8427e</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285</virustotal>
	<vt_score>26/36 (72.2%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[JS%2FRunForest.C.1]]></virusname>
	<url><![CDATA[http://uyj.jkub.com:66/1/36vaa0.htm]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>218.61.0.26</ip>
	<as>AS4837</as>
	<review>undef</review>
	<domain>jkub.com</domain>
	<country>CN</country>
	<source>ARIN</source>
	<email>abuse@online.ln.cn</email>
	<inetnum>218.60.0.0 - 218.61.255.255</inetnum>
	<netname>UNICOM-LN</netname>
	<descr><![CDATA[China Unicom Liaoning province networkChina UnicomCNC Group CHINA169 Liaoning Province Network]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>5</line>
	<id>9170957</id>
	<first>1358836421</first>
	<last>0</last>
	<md5>d41d8cd98f00b204e9800998ecf8427e</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285</virustotal>
	<vt_score>26/36 (72.2%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[JS%2FRunForest.C.1]]></virusname>
	<url><![CDATA[http://uyn.jkub.com:66/1/36vaa0.htm]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>218.61.0.26</ip>
	<as>AS4837</as>
	<review>undef</review>
	<domain>jkub.com</domain>
	<country>CN</country>
	<source>ARIN</source>
	<email>abuse@online.ln.cn</email>
	<inetnum>218.60.0.0 - 218.61.255.255</inetnum>
	<netname>UNICOM-LN</netname>
	<descr><![CDATA[China Unicom Liaoning province networkChina UnicomCNC Group CHINA169 Liaoning Province Network]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>6</line>
	<id>9461532</id>
	<first>1360740888</first>
	<last>0</last>
	<md5>dd5a63741b8e5fe0b2913843faf3483e</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=dd5a63741b8e5fe0b2913843faf3483e</virustotal>
	<vt_score>18/35 (51.4%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[EXP%2FCVE-2012-1889.T]]></virusname>
	<url><![CDATA[http://vcd.jkub.com:66/1/36b0.htm]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>218.61.0.26</ip>
	<as>AS4837</as>
	<review>218.61.0.26</review>
	<domain>jkub.com</domain>
	<country>CN</country>
	<source>APNIC</source>
	<email>abuse@online.ln.cn</email>
	<inetnum>218.60.0.0 - 218.61.255.255</inetnum>
	<netname>UNICOM-LN</netname>
	<descr><![CDATA[China Unicom Liaoning province networkChina UnicomCNC Group CHINA169 Liaoning Province Network]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>7</line>
	<id>9613084</id>
	<first>1361982046</first>
	<last>0</last>
	<md5>ea24f9297d11023076d9b10de14d15ec</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=ea24f9297d11023076d9b10de14d15ec</virustotal>
	<vt_score>32/46 (69.6%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[TR%2FDropper.Gen]]></virusname>
	<url><![CDATA[http://ven.jkub.com:66/o/eh.exe]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>218.61.0.26</ip>
	<as>AS4837</as>
	<review>218.61.0.26</review>
	<domain>jkub.com</domain>
	<country>CN</country>
	<source>APNIC</source>
	<email>abuse@online.ln.cn</email>
	<inetnum>218.60.0.0 - 218.61.255.255</inetnum>
	<netname>UNICOM-LN</netname>
	<descr><![CDATA[China Unicom Liaoning province networkChina UnicomCNC Group CHINA169 Liaoning Province Network]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>8</line>
	<id>9425453</id>
	<first>1360510356</first>
	<last>0</last>
	<md5>9d466f19b02af0ecb9f2541d3b30ce52</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=9d466f19b02af0ecb9f2541d3b30ce52</virustotal>
	<vt_score>17/35 (48.6%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[EXP%2FCVE-2012-1889.T]]></virusname>
	<url><![CDATA[http://vbu.jkub.com:66/1/36b0.htm]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>218.61.0.26</ip>
	<as>AS4837</as>
	<review>218.61.0.26</review>
	<domain>jkub.com</domain>
	<country>CN</country>
	<source>APNIC</source>
	<email>abuse@online.ln.cn</email>
	<inetnum>218.60.0.0 - 218.61.255.255</inetnum>
	<netname>UNICOM-LN</netname>
	<descr><![CDATA[China Unicom Liaoning province networkChina UnicomCNC Group CHINA169 Liaoning Province Network]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>9</line>
	<id>9441924</id>
	<first>1360615043</first>
	<last>0</last>
	<md5>1e1db6199f114e8cb29503a1559a5ddf</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=1e1db6199f114e8cb29503a1559a5ddf</virustotal>
	<vt_score>19/45 (42.2%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[EXP%2FCVE-2012-1889.T]]></virusname>
	<url><![CDATA[http://vcl.jkub.com:66/1/36b0.htm]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>218.61.0.26</ip>
	<as>AS4837</as>
	<review>218.61.0.26</review>
	<domain>jkub.com</domain>
	<country>CN</country>
	<source>APNIC</source>
	<email>abuse@online.ln.cn</email>
	<inetnum>218.60.0.0 - 218.61.255.255</inetnum>
	<netname>UNICOM-LN</netname>
	<descr><![CDATA[China Unicom Liaoning province networkChina UnicomCNC Group CHINA169 Liaoning Province Network]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>10</line>
	<id>9186701</id>
	<first>1358937863</first>
	<last>0</last>
	<md5></md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=626aaedb2fd3cbeabfdc5b8f7a6855c5</virustotal>
	<vt_score>17/40 (42.5%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[TR%2FPSW.37888.A]]></virusname>
	<url><![CDATA[http://uyj.jkub.com:66/o/eh.exe]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>218.61.0.26</ip>
	<as>AS4837</as>
	<review>undef</review>
	<domain>jkub.com</domain>
	<country>CN</country>
	<source>ARIN</source>
	<email>abuse@online.ln.cn</email>
	<inetnum>218.60.0.0 - 218.61.255.255</inetnum>
	<netname>UNICOM-LN</netname>
	<descr><![CDATA[China Unicom Liaoning province networkChina UnicomCNC Group CHINA169 Liaoning Province Network]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>11</line>
	<id>9588129</id>
	<first>1361761841</first>
	<last>0</last>
	<md5>ea24f9297d11023076d9b10de14d15ec</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=ea24f9297d11023076d9b10de14d15ec</virustotal>
	<vt_score>32/46 (69.6%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[TR%2FDropper.Gen]]></virusname>
	<url><![CDATA[http://veb.jkub.com:66/o/eh.exe]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>218.61.0.26</ip>
	<as>AS4837</as>
	<review>218.61.0.26</review>
	<domain>jkub.com</domain>
	<country>CN</country>
	<source>APNIC</source>
	<email>abuse@online.ln.cn</email>
	<inetnum>218.60.0.0 - 218.61.255.255</inetnum>
	<netname>UNICOM-LN</netname>
	<descr><![CDATA[China Unicom Liaoning province networkChina UnicomCNC Group CHINA169 Liaoning Province Network]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>12</line>
	<id>9539759</id>
	<first>1361365786</first>
	<last>0</last>
	<md5>ea24f9297d11023076d9b10de14d15ec</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=ea24f9297d11023076d9b10de14d15ec</virustotal>
	<vt_score>32/46 (69.6%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[TR%2FDropper.Gen]]></virusname>
	<url><![CDATA[http://vdm.jkub.com:66/o/eh.exe]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>218.61.0.26</ip>
	<as>AS4837</as>
	<review>218.61.0.26</review>
	<domain>jkub.com</domain>
	<country>CN</country>
	<source>APNIC</source>
	<email>abuse@online.ln.cn</email>
	<inetnum>218.60.0.0 - 218.61.255.255</inetnum>
	<netname>UNICOM-LN</netname>
	<descr><![CDATA[China Unicom Liaoning province networkChina UnicomCNC Group CHINA169 Liaoning Province Network]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>13</line>
	<id>9724613</id>
	<first>1363088409</first>
	<last>0</last>
	<md5>ea24f9297d11023076d9b10de14d15ec</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=ea24f9297d11023076d9b10de14d15ec</virustotal>
	<vt_score>32/46 (69.6%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[TR%2FDropper.Gen]]></virusname>
	<url><![CDATA[http://vgd.jkub.com:66/o/eh.exe]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>218.61.0.26</ip>
	<as>AS4837</as>
	<review>218.61.0.26</review>
	<domain>jkub.com</domain>
	<country>CN</country>
	<source>APNIC</source>
	<email>abuse@online.ln.cn</email>
	<inetnum>218.60.0.0 - 218.61.255.255</inetnum>
	<netname>UNICOM-LN</netname>
	<descr><![CDATA[China Unicom Liaoning province networkChina UnicomCNC Group CHINA169 Liaoning Province Network]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>14</line>
	<id>10401240</id>
	<first>1366886453</first>
	<last>0</last>
	<md5>24267fa84be4f2c240c3523f0c445cb7</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=24267fa84be4f2c240c3523f0c445cb7</virustotal>
	<vt_score>3/46 (6.5%)</vt_score>
	<scanner>Comodo</scanner>
	<virusname><![CDATA[UnclassifiedMalware]]></virusname>
	<url><![CDATA[http://www.tsm.25u.com/]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>94.228.201.117</ip>
	<as>AS48293</as>
	<review>94.228.201.117</review>
	<domain>25u.com</domain>
	<country>RU</country>
	<source>RIPE</source>
	<email>ncc@union-tel.ru</email>
	<inetnum>94.228.192.0 - 94.228.207.255</inetnum>
	<netname>RU-UNION-TEL-20081105</netname>
	<descr><![CDATA[Uniontel ZAOKalininec-net]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>15</line>
	<id>9441322</id>
	<first>1360617060</first>
	<last>0</last>
	<md5>9dfdad3931b134d2331721b5c28984f7</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=9dfdad3931b134d2331721b5c28984f7</virustotal>
	<vt_score>2/35 (5.7%)</vt_score>
	<scanner>McAfee</scanner>
	<virusname><![CDATA[JS%2FExploit-Blacole.gq]]></virusname>
	<url><![CDATA[http://7slkhgwjghkj.qhigh.com/closest/209tuj2dsljdglsgjwrigslgkjskga.php]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>89.253.230.132</ip>
	<as>AS41535</as>
	<review>89.253.230.132</review>
	<domain>qhigh.com</domain>
	<country>RU</country>
	<source>RIPE</source>
	<email>abuse@rusonyx.ru</email>
	<inetnum>89.253.192.0 - 89.253.255.255</inetnum>
	<netname>RU-RUSONYX-20060829</netname>
	<descr><![CDATA[Rusonyx, Ltd.]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>16</line>
	<id>9340357</id>
	<first>1359985188</first>
	<last>0</last>
	<md5>79744fddfc843a99dcdc3d3fd1fa0707</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=79744fddfc843a99dcdc3d3fd1fa0707</virustotal>
	<vt_score>20/36 (55.6%)</vt_score>
	<scanner>AhnLab_V3</scanner>
	<virusname><![CDATA[Trojan%2FWin32.Bublik]]></virusname>
	<url><![CDATA[http://3rtyjjdxgn.ns02.us/closest/black_dragon.php?khxht=1f:1o:31:1o:1n&qoryow=1n:32:1i:2w:1m:1g:33:31:1h:31&fipamjwl=1i&obbsp=wja&jvtmehpa=uvyq]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>89.253.232.149</ip>
	<as>AS41535</as>
	<review>89.253.232.149</review>
	<domain>ns02.us</domain>
	<country>RU</country>
	<source>RIPE</source>
	<email>abuse@rusonyx.ru</email>
	<inetnum>89.253.192.0 - 89.253.255.255</inetnum>
	<netname>RU-RUSONYX-20060829</netname>
	<descr><![CDATA[Rusonyx, Ltd.]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>17</line>
	<id>9446871</id>
	<first>1360647662</first>
	<last>0</last>
	<md5>eeda9bc7459c3bee9c70b22c19953a3c</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=eeda9bc7459c3bee9c70b22c19953a3c</virustotal>
	<vt_score>13/44 (29.5%)</vt_score>
	<scanner>BitDefender</scanner>
	<virusname><![CDATA[Trojan.Generic.KD.856452]]></virusname>
	<url><![CDATA[http://7wfjkwnjnwek.ikwb.com/closest/98yf8913fjipgjialhg8239jgighnjh4i6k5o.php?mdvkjge=1m:30:2v:33:31&hyv=1k:1f:2w:1m:31:1o:1l:1l:30:31&ddruey=1i&pebzrwke=apuxr&kfibtmt=sjpdggn]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>89.253.230.132</ip>
	<as>AS41535</as>
	<review>89.253.230.132</review>
	<domain>ikwb.com</domain>
	<country>RU</country>
	<source>RIPE</source>
	<email>abuse@rusonyx.ru</email>
	<inetnum>89.253.192.0 - 89.253.255.255</inetnum>
	<netname>RU-RUSONYX-20060829</netname>
	<descr><![CDATA[Rusonyx, Ltd.]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>18</line>
	<id>9208108</id>
	<first>1359178299</first>
	<last>0</last>
	<md5>d41d8cd98f00b204e9800998ecf8427e</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285</virustotal>
	<vt_score>26/36 (72.2%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[JS%2FRunForest.C.1]]></virusname>
	<url><![CDATA[http://qtans.wikaba.com/airyoleg.php?boutfage=322835]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>78.110.62.93</ip>
	<as>AS31240</as>
	<review>undef</review>
	<domain>wikaba.com</domain>
	<country>RU</country>
	<source>ARIN</source>
	<email>abuse@ht-systems.ru</email>
	<inetnum>78.110.56.0 - 78.110.63.255</inetnum>
	<netname>RU-HT-SYSTEMS-BIS</netname>
	<descr><![CDATA[Hosting Telesystems network]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>19</line>
	<id>10457736</id>
	<first>1367012422</first>
	<last>0</last>
	<md5>b575685ae916c143943daf7193f6c420</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=b575685ae916c143943daf7193f6c420</virustotal>
	<vt_score>2/46 (4.3%)</vt_score>
	<scanner>Avast</scanner>
	<virusname><![CDATA[JS%3AScriptIP-inf+%5BTrj%5D]]></virusname>
	<url><![CDATA[http://rilvudxrvop.my03.com/]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>207.200.111.13</ip>
	<as>AS1668</as>
	<review>207.200.111.13</review>
	<domain>my03.com</domain>
	<country>US</country>
	<source>ARIN</source>
	<email>domains@aol.net</email>
	<inetnum>207.200.64.0 - 207.200.127.255</inetnum>
	<netname>NETSCAPE-CIDR</netname>
	<descr><![CDATA[Netscape Communications Corp. NSCP 501 E. Middlefield Mountain View CA 94043]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>20</line>
	<id>10722035</id>
	<first>1367953252</first>
	<last>0</last>
	<md5>2e1d841e67baf41626772682c021be1e</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=2e1d841e67baf41626772682c021be1e</virustotal>
	<vt_score>1/46 (2.2%)</vt_score>
	<scanner>undef</scanner>
	<virusname><![CDATA[Redir.IG]]></virusname>
	<url><![CDATA[http://www.0f2.gaaa.jetos.com/?0rb]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>147.255.106.145</ip>
	<as>AS15003</as>
	<review>147.255.106.145</review>
	<domain>jetos.com</domain>
	<country>US</country>
	<source>ARIN</source>
	<email>abuse@nobistech.net</email>
	<inetnum>147.255.96.0 - 147.255.111.255</inetnum>
	<netname>NETBLK-UBIQUITY-147-255-96-0</netname>
	<descr><![CDATA[Ubiquity Server Solutions Los Angeles NTGL-4 530 West 6th Street Los Angeles CA 90014]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>21</line>
	<id>9385483</id>
	<first>1360253462</first>
	<last>0</last>
	<md5>a4c59a5d7503242aac28413f9e711cdb</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=a4c59a5d7503242aac28413f9e711cdb</virustotal>
	<vt_score>3/35 (8.6%)</vt_score>
	<scanner>McAfee</scanner>
	<virusname><![CDATA[JS%2FExploit-Blacole.gq]]></virusname>
	<url><![CDATA[http://6rhjrtjejfgfd.ddns.us/closest/df7guhoijewpgkegwegko.php]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>188.93.211.195</ip>
	<as>AS49352</as>
	<review>188.93.211.195</review>
	<domain>ddns.us</domain>
	<country>RU</country>
	<source>RIPE</source>
	<email>noc@logol.ru</email>
	<inetnum>188.93.208.0 - 188.93.213.255</inetnum>
	<netname>LOGOL-NET</netname>
	<descr><![CDATA[LTD Hosting ServiceLTD Hosting Service IPv4 routeLTD Hosting Service IPv4 host route]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>22</line>
	<id>9537613</id>
	<first>1361343935</first>
	<last>0</last>
	<md5>90685fdf80ec8bfd33a1e95275ec5afd</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=90685fdf80ec8bfd33a1e95275ec5afd</virustotal>
	<vt_score>2/36 (5.6%)</vt_score>
	<scanner>McAfee</scanner>
	<virusname><![CDATA[JS%2FExploit-Blacole.kf]]></virusname>
	<url><![CDATA[http://8rghwigwe.qhigh.com/closest/df7guhoijewpgkegwegko.php]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>188.93.210.77</ip>
	<as>AS49352</as>
	<review>188.93.210.77</review>
	<domain>qhigh.com</domain>
	<country>RU</country>
	<source>RIPE</source>
	<email>noc@logol.ru</email>
	<inetnum>188.93.208.0 - 188.93.213.255</inetnum>
	<netname>LOGOL-NET</netname>
	<descr><![CDATA[LTD Hosting ServiceLTD Hosting Service IPv4 routeLTD Hosting Service IPv4 host route]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>23</line>
	<id>10288195</id>
	<first>1366449032</first>
	<last>0</last>
	<md5>eb51585b962c6ceeee9b74b4de6dc5d6</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=eb51585b962c6ceeee9b74b4de6dc5d6</virustotal>
	<vt_score>19/46 (41.3%)</vt_score>
	<scanner>AntiVir</scanner>
	<virusname><![CDATA[JS%2FiFrame.dbr]]></virusname>
	<url><![CDATA[http://bablorub.dnset.com/pop.js]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>78.24.217.166</ip>
	<as>AS29182</as>
	<review>78.24.217.166</review>
	<domain>dnset.com</domain>
	<country>RU</country>
	<source>RIPE</source>
	<email>abuse@ispsystem.net</email>
	<inetnum>78.24.216.0 - 78.24.219.255</inetnum>
	<netname>ISPSYSTEM</netname>
	<descr><![CDATA[ISPsystem at MSM]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>24</line>
	<id>10961615</id>
	<first>1368540565</first>
	<last>0</last>
	<md5>587bdae503aa61ebebc4115a5bcb1f55</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=587bdae503aa61ebebc4115a5bcb1f55</virustotal>
	<vt_score>2/35 (5.7%)</vt_score>
	<scanner>McAfee</scanner>
	<virusname><![CDATA[JS%2FExploit%21JNLP]]></virusname>
	<url><![CDATA[http://ejrnpy.lflinkup.net/xlawr/next/requirements_anonymous_ordinary.php?jnlp=f5646a1]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>62.109.7.127</ip>
	<as>AS29182</as>
	<review>62.109.7.127</review>
	<domain>lflinkup.net</domain>
	<country>RU</country>
	<source>RIPE</source>
	<email>abuse@ispsystem.net</email>
	<inetnum>62.109.0.0 - 62.109.7.255</inetnum>
	<netname>ISPSYSTEM</netname>
	<descr><![CDATA[ISPsystem at MSM]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>25</line>
	<id>10946308</id>
	<first>1368516041</first>
	<last>0</last>
	<md5>a88473c3e916fea00f8d4c0e8f6f8403</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=01999a7cb3d65c1cc4383408c297ba32</virustotal>
	<vt_score>3/46 (6.5%)</vt_score>
	<scanner>Avast</scanner>
	<virusname><![CDATA[HTML%3AIframe-inf]]></virusname>
	<url><![CDATA[http://vzdqgxkj.ftpserver.biz/]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>97.74.180.128</ip>
	<as>AS26496</as>
	<review>97.74.180.128</review>
	<domain>ftpserver.biz</domain>
	<country>US</country>
	<source>ARIN</source>
	<email>noc@godaddy.com</email>
	<inetnum>97.74.0.0 - 97.74.255.255</inetnum>
	<netname>GO-DADDY-COM-LLC</netname>
	<descr><![CDATA[GoDaddy.com, LLC GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>26</line>
	<id>10307424</id>
	<first>1366510817</first>
	<last>0</last>
	<md5>a88473c3e916fea00f8d4c0e8f6f8403</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=01999a7cb3d65c1cc4383408c297ba32</virustotal>
	<vt_score>3/46 (6.5%)</vt_score>
	<scanner>Avast</scanner>
	<virusname><![CDATA[HTML%3AIframe-inf]]></virusname>
	<url><![CDATA[http://zwmxyfnyvm.jetos.com/]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>97.74.180.128</ip>
	<as>AS26496</as>
	<review>97.74.180.128</review>
	<domain>jetos.com</domain>
	<country>US</country>
	<source>ARIN</source>
	<email>noc@godaddy.com</email>
	<inetnum>97.74.0.0 - 97.74.255.255</inetnum>
	<netname>GO-DADDY-COM-LLC</netname>
	<descr><![CDATA[GoDaddy.com, LLC GODAD 14455 N Hayden Road Suite 226 Scottsdale AZ 85260]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>27</line>
	<id>9793216</id>
	<first>1363478462</first>
	<last>0</last>
	<md5>83cea86aa11c48019328f697da8e2367</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=83cea86aa11c48019328f697da8e2367</virustotal>
	<vt_score>1/46 (2.2%)</vt_score>
	<scanner>Jiangmin</scanner>
	<virusname><![CDATA[Trojan%2FScript.Gen]]></virusname>
	<url><![CDATA[http://rir2013.dns05.com/ssl.php]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>5.135.160.42</ip>
	<as>AS16276</as>
	<review>5.135.160.42</review>
	<domain>dns05.com</domain>
	<country>FR</country>
	<source>RIPE</source>
	<email>abuse@ovh.net</email>
	<inetnum>5.135.0.0 - 5.135.255.255</inetnum>
	<netname>FR-OVH-20120706</netname>
	<descr><![CDATA[Ovh Systems]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>28</line>
	<id>9287985</id>
	<first>1359592537</first>
	<last>0</last>
	<md5>d41d8cd98f00b204e9800998ecf8427e</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285</virustotal>
	<vt_score>26/36 (72.2%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[JS%2FRunForest.C.1]]></virusname>
	<url><![CDATA[http://1ewgthytj.mymom.info/closest/98y7y432ufh49gj23sldkkqowpsskfnv.php]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>91.218.121.86</ip>
	<as>AS50669</as>
	<review>1.0.0.0</review>
	<domain>mymom.info</domain>
	<country>AU</country>
	<source>APNIC</source>
	<email>research@apnic.net</email>
	<inetnum>91.218.120.0 - 91.218.123.255</inetnum>
	<netname>Debogon-prefix</netname>
	<descr><![CDATA[APNIC Debogon ProjectAPNIC Pty Ltd]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>29</line>
	<id>9281110</id>
	<first>1359553560</first>
	<last>0</last>
	<md5>d41d8cd98f00b204e9800998ecf8427e</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=bb89f0c48c36d04380c9c3ba24efd285</virustotal>
	<vt_score>26/36 (72.2%)</vt_score>
	<scanner>avira</scanner>
	<virusname><![CDATA[JS%2FRunForest.C.1]]></virusname>
	<url><![CDATA[http://1wstdfgh.organiccrap.com/closest/984y3fh8u3hfu3jcihei.php]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>91.218.121.86</ip>
	<as>AS50669</as>
	<review>1.0.0.0</review>
	<domain>organiccrap.com</domain>
	<country>AU</country>
	<source>APNIC</source>
	<email>research@apnic.net</email>
	<inetnum>91.218.120.0 - 91.218.123.255</inetnum>
	<netname>Debogon-prefix</netname>
	<descr><![CDATA[APNIC Debogon ProjectAPNIC Pty Ltd]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>30</line>
	<id>10034578</id>
	<first>1365643203</first>
	<last>0</last>
	<md5>1a09fae577bca43fd426aa3198ae61c1</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=1a09fae577bca43fd426aa3198ae61c1</virustotal>
	<vt_score>2/36 (5.6%)</vt_score>
	<scanner>AVG</scanner>
	<virusname><![CDATA[Script%2FExploit.Kit.AI]]></virusname>
	<url><![CDATA[http://2dfgyhjkm.ikwb.com/closest/f2ihoiwegjowiejf230hfaj.php]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>46.4.150.117</ip>
	<as>AS24940</as>
	<review>46.4.150.117</review>
	<domain>ikwb.com</domain>
	<country>DE</country>
	<source>RIPE</source>
	<email>abuse@hetzner.de</email>
	<inetnum>46.4.0.0 - 46.4.255.255</inetnum>
	<netname>DE-HETZNER-20100819</netname>
	<descr><![CDATA[Hetzner Online AG]]></descr>
	<ns1>ns1.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns3.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>31</line>
	<id>10081926</id>
	<first>1365819212</first>
	<last>0</last>
	<md5>01a2c159dbbabdcf8e5247da38071e02</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=01a2c159dbbabdcf8e5247da38071e02</virustotal>
	<vt_score>2/46 (4.3%)</vt_score>
	<scanner>clamav</scanner>
	<virusname><![CDATA[JS.Redirect-4]]></virusname>
	<url><![CDATA[http://media.www1.biz/in.cgi?18&amp;ad_type=static&amp;ad_size=728x90&amp;log=6812&amp;ur=1&amp;HTTP_REFERER=http://ad.yieldmanager.com/st?ad_type=iframe]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>5.199.175.172</ip>
	<as>AS16125</as>
	<review>5.199.175.172</review>
	<domain>www1.biz</domain>
	<country>LT</country>
	<source>RIPE</source>
	<email></email>
	<inetnum>5.199.160.0 - 5.199.175.255</inetnum>
	<netname></netname>
	<descr><![CDATA[]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
<entry>
	<line>32</line>
	<id>10993862</id>
	<first>1368586294</first>
	<last>0</last>
	<md5>453024ccd5283973b8f87ba889cc8861</md5>
	<virustotal>http://www.virustotal.com/latest-report.html?resource=453024ccd5283973b8f87ba889cc8861</virustotal>
	<vt_score>4/46 (8.7%)</vt_score>
	<scanner>clamav</scanner>
	<virusname><![CDATA[JS.Redirect-4]]></virusname>
	<url><![CDATA[http://webmailer.jungleheart.com/in.cgi?9&amp;ad_type=static&amp;ad_size=728x90&amp;log=72611&amp;ur=1&amp;HTTP_REFERER=http://ad.doubleclick.net/adi/locm.sp/attorney_11180200]]></url>
	<recent>up</recent>
	<response>alive</response>
	<ip>5.199.175.173</ip>
	<as>AS16125</as>
	<review>5.199.175.173</review>
	<domain>jungleheart.com</domain>
	<country>LT</country>
	<source>RIPE</source>
	<email></email>
	<inetnum>5.199.160.0 - 5.199.175.255</inetnum>
	<netname></netname>
	<descr><![CDATA[]]></descr>
	<ns1>ns3.changeip.org</ns1>
	<ns2>ns2.changeip.org</ns2>
	<ns3>ns1.changeip.org</ns3>
	<ns4></ns4>
	<ns5></ns5>
</entry>
</entries>
</output>

