WARNING: All domains on this website should be considered dangerous. If you do
not know what you are doing here, it is recommended you leave right away. This
website is a resource for security professionals and enthusiasts.
Search: Results to return: Include inactive sites

Date (UTC)DomainIPReverse LookupDescriptionASN
2017/12/04_18:50textspeier.de104.27.163.228-phishing/fraud13335US
2017/10/26_13:48photoscape.ch/Setup.exe31.148.219.11knigazdorovya.com.trojan14576CZ
2017/06/02_08:38sarahdaniella.com/swift/SWIFT%20$.pdf.ace63.247.140.224coriandertest.hmdnsgroup.com.trojan19271US
2017/05/01_16:22amazon-sicherheit.kunden-ueberpruefung.xyz185.61.138.74hosted-by.blazingfast.io.phishing49349UA
2017/03/20_10:13alegroup.info/ntnrrhst194.87.217.87mccfortwayne.org.Ransom, Fake.PCN, Malspam197695RU
2017/03/20_10:13fourthgate.org/Yryzvt104.200.67.194-Ransom, Fake.PCN, Malspam8100US
2017/03/20_10:13dieutribenhkhop.com/parking/84.200.4.125125.0-255.4.200.84.in-addr.arpa.Ransom, Fake.PCN, Malspam31400DE
2017/03/20_10:13dieutribenhkhop.com/parking/pay/rd.php?id=1084.200.4.125125.0-255.4.200.84.in-addr.arpa.Ransom, Fake.PCN, Malspam31400DE
2017/03/14_23:02ssl-6582datamanager.de/54.72.9.51ec2-54-72-9-51.eu-west-1.compute.amazonaws.com.redirects to Paypal phishing16509US
2017/03/14_23:02privatkunden.datapipe9271.com/104.31.75.147-Paypal phishing13335US
2017/03/06_21:09www.hjaoopoa.top/admin.php?f=1.gif52.207.234.89ec2-52-207-234-89.compute-1.amazonaws.com.Cerber ransomware14618US
2017/03/06_21:09up.mykings.pw:8888/update.txt60.250.76.5260-250-76-52.HINET-IP.hinet.net.related to a Mirai windows spreader trojan3462TW
2017/03/06_21:09down.mykings.pw:8888/ver.txt60.250.76.5260-250-76-52.HINET-IP.hinet.net.related to a Mirai windows spreader trojan3462TW
2017/03/06_21:09down.mykings.pw:8888/ups.rar60.250.76.5260-250-76-52.HINET-IP.hinet.net.related to a Mirai windows spreader trojan3462TW
2017/02/09_14:04fo5.a1-downloader.org/g2v9s1.php?id=yourname@yourdomain.com188.225.32.177vds-tibca.timeweb.ru.trojan download9123RU
2017/01/25_20:16falconsafe.com.sg/api/get.php?id=aW5mb0BzYXBjdXBncmFkZXMuY29t43.229.84.107-Trojan.Backdoor, Office.Word.Downloader38532SG
2017/01/25_20:15www.lifelabs.vn/api/get.php?id=aW5mb0BzYXBjdXBncmFkZXMuY29t118.69.196.199-Trojan.Backdoor, Office.Word.Downloader18403VN
2017/01/19_13:0561kx.uk-insolvencydirect.com/sending_data/in_cgi/bbwp/cases/Inquiry.php35.166.113.223ec2-35-166-113-223.us-west-2.compute.amazonaws.com.leads to ransomware16509US
2017/01/19_13:05daralasnan.com/wp-content/plugins/mkazaqbya/vmywyvz4.php166.62.12.1sg2nlhg800c1800.shr.prod.sin2.secureserver.net.leads to ransomware26496US
2017/01/19_13:05www.studiolegaleabbruzzese.com/wp-content/plugins/urxwhbnw3ez/flight_4832.pdf62.149.142.206webx440.aruba.it.ransomware31034IT
2017/01/19_13:05raneevahijab.id/adnin/box/workspace/103.24.13.91server3.e-cbncloud.co.id.phishing site132644ID
2016/10/30_01:52kingskillz.ru/~kingskil/Prince/Man/lucy/mine/shit.exe85.143.215.18362695.simplecloud.club.Trojan.FareIt201848RU
2016/10/13_14:03www.family-partners.fr/data.dpg95.142.169.132xvm-169-132.ghst.net.ransomware29169FR
2016/10/13_14:03elmissouri.fr/data.dpg213.186.33.50cluster017.ovh.net.ransomware16276FR
2016/09/21_12:12art-archiv.ru/images/animated-number/docum-arhiv.exe81.177.139.111-trojan8342RU
2016/09/15_10:06catjogger.win/ganel/gate.php213.145.225.170web02.chillydomains.com.pony loader c&c25575AT
2016/09/15_08:48tscl.com.bd/m/RI%20XIN%20QUOTATION%20LIST.zip209.99.16.206206.0/24.16.99.209.in-addr.arpa.trojan inside zip file394695US
2016/09/14_20:05ad.getfond.info83.217.26.203ru2.com.PlugX C&C200161RU
2016/09/06_12:42jessisjewels.com/disk/update/postmaster/en/?ar=yourname@yourdomain.com50.87.153.9650-87-153-96.unifiedlayer.com.phishing site46606US
2016/09/06_11:49structured.blackswanstore.com/plc/header.js5.200.55.91-leads to exploit kit48096RU
2016/09/05_10:07ross.starvingmillionaire.org/unveiled/dropdown.js?ver=496e05e1aea0a9c4655800e8a7b9ea285.200.55.58-leads to exploit kit48096RU
2016/09/05_09:37ad.9tv.co.il/serv4/www/delivery/ajs.php?zoneid=37&cb=54350405237&charset=utf-862.219.67.44bzq-67-44.red.bezeqint.net.iframe on compromised site leads to exploit kit8551IL
2016/09/05_09:37giants.yourzip.co/static/quotes.js?ver=d58072be2820e8682c0a27c0518e805e5.200.55.58-leads to exploit kit48096RU
2016/09/05_09:37evans.babajilab.in/specimen/1479491/tire-something-detect-five-what-knot-unknown-entertain-stiff85.143.219.18160567.simplecloud.club.exploit kit201848RU
2016/09/01_17:35tahit.wastech2016.in/xcqrsw3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/09/01_17:00pogruz.wanyizhao.net/ceqxwu3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/09/01_16:55livre.wasastation.fi/ceqxwu3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/09/01_14:55sanya.vipc2f.com/ceqxwu3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/09/01_11:55tanner.alicerosenmanmemorial.com/hggfgl3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/30_12:25wuvac.agwebdigital.com/dsgajo3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/30_12:20rufex.ajfingenieros.cl/dsgajo3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/29_15:40cqji.artidentalkurs.com/vdgqb3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/29_14:25unlink.altitude.lv/vdgqb3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/29_13:15vitaly.agricolacolhue.cl/rncbu3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/29_13:10geil.alon3.tk/rncbu3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/29_12:35honor.agitaattori.fi/rncbu3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/26_17:35gojnox.boxtomarket.com/yxmvr3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/26_16:55womsy.bobbutcher.net/rtuee3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/26_15:40bonjo.bmbsklep.pl/jvoxyj3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/26_15:05pybul.bestfrozenporn.nl/jvoxyj3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/26_12:35soxorok.ddospower.ro/lwwxx3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/26_12:00funkucck.bluerobot.cl/lwwxx3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/26_11:55wixx.caliptopis.cl/lwwxx3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/26_10:45mepra.blautechnology.cl/pwigd3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/26_10:10wopper.bioblitzgaming.ca/pwigd3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/23_18:45losas.cabanaslanina.com.ar/wkicrz3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/23_18:40losos.caliane.com.br/wkicrz3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/23_17:30pumpkin.brisik.net/rvgkm3.html93.190.140.162customer.worldstream.nl.gateway to EK49981NL
2016/08/22_18:45decorator.crabgrab.cl/rjavgx3.html93.190.140.163customer.worldstream.nl.gateway to EK49981NL
2016/08/22_16:35scanty.colormark.cl/rjavgx3.html93.190.140.163customer.worldstream.nl.gateway to EK49981NL
2016/08/13_10:47coffeol.com/fend/raw_server.exe208.112.30.120-Trojan.Backdoor20021US
2016/08/13_10:47www.pgathailand.com/which.exe128.199.127.7pyptech.net.Trojan.P0ny133165GB
2016/08/12_07:01euro-vertrieb.com/hosteurope/KIS-Login.htm217.31.81.101zaphod3-1.hostweb.de.Hosteurope phishing29140DE
2016/08/09_20:02www.jcmarcadolib.com/hbc/a.php82.221.129.16esja.orangewebsite.com.phishing50613IS
2016/07/21_16:35lexu.goggendorf.at/nukgfr2.html93.190.140.121customer.worldstream.nl.gateway to EK49981NL
2016/07/21_16:30victor.connectcloud.ch/nukgfr2.html93.190.140.121customer.worldstream.nl.gateway to EK49981NL
2016/07/21_15:20molla.gato1000.cl/edmiu2.html93.190.140.121customer.worldstream.nl.gateway to EK49981NL
2016/07/21_14:45hmora.fred-build.tk/odbsx2.html93.190.140.121customer.worldstream.nl.gateway to EK49981NL
2016/07/21_14:40peeg.fronterarq.cl/odbsx2.html93.190.140.121customer.worldstream.nl.gateway to EK49981NL
2016/07/21_13:20adv.riza.it/www/delivery/ajs.php?zoneid=51&cb=9602097806062.149.195.107host107-195-149-62.serverdedicati.aruba.it.iframe on compromised site leads to exploit kit31034IT
2016/07/21_12:15borat.elticket.com.ar/pkge2.html93.190.140.121customer.worldstream.nl.gateway to EK49981NL
2016/07/20_17:35lay.elticket.com.ar/tslwo2.html93.190.140.121customer.worldstream.nl.gateway to EK49981NL
2016/07/20_16:30plank.duplicolor.cl/zbtqvc2.html93.190.140.121customer.worldstream.nl.gateway to EK49981NL
2016/07/20_16:25pave.elisecries.com/zbtqvc2.html93.190.140.121customer.worldstream.nl.gateway to EK49981NL
2016/07/20_15:15spread.diadanoivabh.com.br/alvbh2.html93.190.140.121customer.worldstream.nl.gateway to EK49981NL
2016/07/20_14:05smilll.depozit.hr/bgaldb2.html93.190.140.121customer.worldstream.nl.gateway to EK49981NL
2016/07/18_18:30soros.departamentosejecutivos.cl/venak2.html93.190.140.118customer.worldstream.nl.gateway to EK49981NL
2016/07/18_17:15stock.daydreamfuze.com/rxdjna2.html93.190.140.118customer.worldstream.nl.gateway to EK49981NL
2016/07/18_16:40vdula.czystykod.pl/rxdjna2.html93.190.140.118customer.worldstream.nl.gateway to EK49981NL
2016/07/18_15:30produla.czatgg.pl/rxdjna2.html93.190.140.118customer.worldstream.nl.gateway to EK49981NL
2016/07/18_13:10aircraft.evote.cl/ybluq2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/14_17:25absurdity.flarelight.com/xdnkn2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/14_15:35pacan.gofreedom.info/omrjy2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/14_15:30pacman.gkgar.com/omrjy2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/14_14:20terem.eltransbt.ro/ysfmgl2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/14_14:15likes.gisnetwork.net/ysfmgl2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/14_13:10personal.editura-amsibiu.ro/rdxzmt2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/13_18:20above.e-rezerwacje24.pl/uzjuz2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/13_18:15headless.ebkfwd.com/uzjuz2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/13_17:05higher.dwebsi.tk/uzjuz2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/13_16:30crops.dunight.eu/uzjuz2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/13_12:50invention.festinolente.cl/ajuijm2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/13_12:45erupt.fernetmoretti.com.ar/ajuijm2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/13_12:15stork.escortfinder.cl/ajuijm2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/13_12:10vomit.facilitandosonhos.com.br/ajuijm2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/13_11:10trifle.ernstenco.be/ajuijm2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/12_13:19www.ywvcomputerprocess.info/errorreport/ty5ug6h4ndma4/103.224.212.222lb-212-222.above.com.fake alert page133618AU
2016/07/08_16:55cosmos.furnipict.com/gsvot2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/08_16:50milf.gabriola.cl/gsvot2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/08_16:15cosmos.felago.es/gsvot2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/08_15:45drank.fa779.com/gsvot2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/08_14:05boots.fotopyra.pl/gsvot2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/08_11:20concede.fmtlib.net/khoklj2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/07_13:30shoal.grahanusareadymix.com/arais2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/07_12:15exclaim.goldenteamacademy.cl/arais2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/07/07_10:05scream.garudamp3.com/arais2.html93.190.140.110customer.worldstream.nl.gateway to EK49981NL
2016/06/29_08:48websitebuildersinfo.in166.62.28.83ip-166-62-28-83.ip.secureserver.net.fake infection page26496US
2016/06/28_20:52www.alphamedical02.fr/94.23.236.74ns308230.ip-94-23-236.eu.iframe on compromised site leads to EK16276FR
2016/06/27_12:33www.airbornehydrography.com/194.9.95.65s210.loopia.se.iframe on compromised site leads to EK39570SE
2016/06/27_08:07www.gennaroespositomilano.it/75.126.217.36web234.webfaction.com.iframe on compromised site leads to EK36351US
2016/06/23_15:01www.enchantier.com/176.31.73.196www.enchantier.com.iframe on compromised site leads to EK16276FR
2016/06/21_10:21www.fsm-europe.eu/79.96.162.106cloudserver092054.home.net.pl.iframe on compromised site leads to EK12824PL
2016/06/20_14:33www.salentoeasy.it/95.110.189.62host62-189-110-95.serverdedicati.aruba.it.iframe on compromised site leads to EK31034IT
2016/06/17_12:10www.nuvon.com/64.207.96.72-iframe on compromised site leads to EK11598US
2016/06/17_12:10ex.technor.com/index.php82.113.193.43web.alias.twt.it.iframe on compromised site leads to EK30848IT
2016/06/07_08:37www.vertourmer.com/81.31.147.91jmhlmd41.colt-engine.it.iframe on compromised site leads to EK47242IT
2016/05/30_16:31buildviet.info/servicer/fattura/123.30.240.66static.vdc.vn.redirects to trojan download at SugarSync45899VN
2016/05/30_11:34www.northpoleitalia.it/46.37.11.7host7-11-37-46.serverdedicati.aruba.it.iframe on compromised site leads to EK
2016/05/24_17:36www.ceisystems.it/178.212.142.108ceisystems.it.iframe on compromised site leads to EK47316IT
2016/05/23_09:06www.sieltre.it/79.58.246.237host237-246-static.58-79-b.business.telecomitalia.it.iframe on compromised site leads to EK3269IT
2016/05/12_08:36www.airsonett.se193.44.13.93193-44-13-93.net.tnm.se.iframe on compromised site leads to EK3301SE
2016/05/10_07:18www.outlinearray.com/85.235.130.71w461.widhost.net.iframe on compromised site leads to EK31034IT
2016/05/05_18:09www.roltek.com.tr/94.73.151.594-73-151-5.cizgi.net.tr.iframe on compromised site leads to EK34619TR
2016/05/02_10:23www.donneuropa.it/23.23.85.3ec2-23-23-85-3.compute-1.amazonaws.com.iframe on compromised site leads to EK14618US
2016/04/28_14:52www.del-marine.com/80.244.187.39mail.ebnserver1.com.iframe on compromised site leads to EK34934GB
2016/04/28_12:00kollagen4you.se/46.252.206.1n1nlhg198c1198.shr.prod.ams1.secureserver.net.iframe on compromised site leads to EK26496NL
2016/04/28_07:49www.dezuiderwaard.nl/195.238.74.87www53.totaalholding.nl.iframe on compromised site leads to EK50673NL
2016/03/31_13:34www.actiagroup.com/141.0.187.5-iframe on compromised site leads to EK30741FR
2016/03/31_10:01kassabravo.com/67.196.85.119israsky.com.iframe on compromised site leads to EK8001US
2016/03/29_20:56holishit.in/wp-content/plugins/wpclef/assets/src/sass/neat/grid/binarystings.php160.153.63.4ip-160-153-63-4.ip.secureserver.net.Teslacrypt c&c26496US
2016/03/29_20:56grosirkecantikan.com/wp-content/plugins/contact-form-7/includes/js/jquery-ui/themes/smoothness/images/binarystings.php192.185.51.87-Teslacrypt c&c20013US
2016/03/18_14:13marialorena.com.br/wp-content/plugins/hello123/8888ytc6r.exe200.219.253.2323.0-127.253.219.200.in-addr.arpa.trojan16397BR
2016/03/18_09:37-104.245.239.7/~earlysym/vr.phpinfra23.imacomsolucoes.com.br.WellsFargo phishing destination62638US
2016/03/18_06:58zt.tim-taxi.com/login.php198.12.67.179179.67.12.198.host.nwnx.net.MasterCard phishing36352US
2016/03/15_11:48legendsdtv.com/lmzjH7XQY/67.212.178.106m2304.sgded.com.leads to CryptoLocker32475US
2016/03/15_07:55www.schuh-zentgraf.de/81.169.145.160wa0.rzone.de.iframe on compromised site leads to EK6724DE
2016/03/13_14:23-81.169.219.64/security_check.htmlh2543039.stratoserver.net.PayPal phishing6724DE
2016/03/13_14:23-185.11.146.198/nginx1.vosuites.cl.PayPal phishing49349NL
2016/03/08_10:58stopmeagency.free.fr/9uj8n76b5.exe212.27.63.112perso112-g5.free.fr.trojan12322FR
2016/03/08_10:58reclamus.com/9uj8n76b5.exe198.63.208.35vserv.cifnet.com.trojan14585US
2016/03/08_10:58lhs-mhs.org/9uj8n76b5.exe208.131.141.2rageresearch.com.trojan29854US
2016/03/08_10:51izzy-cars.nl/9uj8n76b5.exe46.235.47.134srv047134.webreus.nl.trojan34233NL
2016/03/04_13:55nevergreen.net/6ob107.180.26.77ip-107-180-26-77.ip.secureserver.net.Bot26496US
2016/03/03_10:17www.inevo.co.il/212.199.114.168mx.standingdesk.co.il.iframe on compromised site leads to EK9116IL
2016/03/01_07:20-188.138.68.160/sdt/skodls/dp.exestatic-ip-188-138-68-160.inaddr.ip-pool.com.trojan8972DE
2016/02/29_13:00www.gold-city.it/image/_vti_cnf/app/psi.exe31.11.33.82websn2s072.aruba.it.trojan31034IT
2016/02/29_13:00www.cerquasas.it/wp-admin/user/UPS_INVOICE.rar109.168.123.112srv-hs2-112.netsons.net.trojan5602IT
2016/02/29_13:00-91.224.161.116/ftz/z64.bin-malware calls home50673NL
2016/02/29_13:00-91.224.161.116/ftz/z32.bin-malware calls home50673NL
2016/02/29_07:14www.icybrand.eu/pathway/created/accelerated/mailuserlg/savealife/trwrwbejtw.zip192.185.194.21ns387.websitewelcome.com.Phishing20013US
2016/02/29_07:14www.icybrand.eu/pathway/created/accelerated/mailuserlg/savealife/trwrwbejtw/viewer.php192.185.194.21ns387.websitewelcome.com.Phishing20013US
2016/02/01_13:14www.pieiron.co.uk/146.185.29.100www6.grakka.net.iframe on compromised site leads to EK29302GB
2016/01/29_07:39deleondeos.com/img/script.php?tup1.jpg95.105.27.1195.105.27.11.dynamic.oktgs.ufanet.ru.trojan24955RU
2016/01/29_07:39deleondeos.com/img/script.php?tup2.jpg176.106.31.227-trojan52043RU
2016/01/29_07:39deleondeos.com/img/script.php?tup3.jpg176.104.18.152s-176-104-18-152.under.net.ua.trojan41435UA
2016/01/27_11:21wonchangvacuum.com.my/libraries/pear/mandate.htm103.6.196.156datousaurus.mschosting.com.Phishing46015MY
2016/01/27_11:21gosciniec-paproc.pl/lib/excel/kamp.php85.128.248.56aon56.rev.netart.pl.Phishing15967PL
2016/01/23_00:46www.proascolcolombia.com/portal/modules/mod_banners/Imprimir_IntimacaoCTI2015-03698541.rar?cli=Cliente&/yRpBKPujKU/nNqRc6QsuO.php190.8.176.235bartolome.colombiahosting.com.co.Trojan.Banload52335CO
2016/01/23_00:46www.proascolcolombia.com/portal/modules/mod_banners/Imprimir_IntimacaoCTI2015-03698541.rar?cli=Cliente&/yRpBKPujKU/nNqRc6QsuO.php190.8.176.235bartolome.colombiahosting.com.co.Trojan.Banload52335CO
2016/01/21_13:06www.cifor.com/213.186.33.84basic-cdn-01.cluster003.ovh.net.iframe on compromised site leads to EK16276FR
2016/01/20_12:33www.areadiprova.eu/gardani/80.247.79.174mail.360at.net.compromised site leads to exploit kit12850IT
2016/01/19_11:30www.profill-smd.com/77.55.57.113acf113.rev.netart.pl.compromised site leads to exploit kit15967PL
2016/01/19_09:50pradakomechanicals.com/203.124.103.1sg2nlhg500c1500.shr.prod.sin2.secureserver.net.compromised site leads to exploit kit26496SG
2016/01/19_09:03blog.replacemycontacts.com/50.62.235.1p3nlhg498c1498.shr.prod.phx3.secureserver.net.compromised site leads to exploit kit26496US
2016/01/19_07:37avppet.com/wp-includes/js/tinymce/plugins/media/Oracle_32.zip173.254.37.144173-254-37-144.unifiedlayer.com.Java installation abused for installing Java malware46606US
2016/01/19_07:37avppet.com/wp-includes/js/tinymce/plugins/media/Oracle_64.zip173.254.37.144173-254-37-144.unifiedlayer.com.Java installation abused for installing Java malware46606US
2016/01/18_14:18www.gasthofpost-ebs.de/81.169.251.136h2402507.stratoserver.net.iframe on compromised site leads to EK6724DE
2016/01/13_15:10inclusivediversity.co.uk/wp-content/upgrade/217.199.187.192web192.extendcp.co.uk.Paypal Phishing (Redirect)20738GB
2016/01/12_10:08www.ostsee-schnack.de/80.67.28.137dgws10s3-1-5db.ispgateway.de.compromised site leads to exploit kit34011DE
2016/01/12_09:58szinhaz.hu/185.43.205.98szinhaz.hu.compromised site leads to exploit kit62214HU
2016/01/12_08:53www.technix.it/217.194.6.34vchicken.oval.it.compromised site leads to exploit kit12637IT
2016/01/12_08:49www.scantanzania.com/bin/img/make.html64.202.115.199twiga-ip5.tanzaniawebhosting.com.phishing23352US
2016/01/06_15:19-46.30.45.39/yyo.wvz110372.eurodir.ru.Cryptowall ransomware35415RU
2016/01/06_15:19-46.30.45.39/Statement.jpgvz110372.eurodir.ru.Cryptowall download script35415RU
2015/12/30_19:54healthybloodpressure.info/2uOioq.php50.63.56.47ip-50-63-56-47.ip.secureserver.net.Cryptowall ransomware C&C26496US
2015/12/28_20:16betterhomeandgardenideas.com/dbsys.php192.185.52.247-Teslacrypt ransomware c&c20013US
2015/12/28_20:16yigitakcali.com/dbsys.php160.153.16.29ip-160-153-16-29.ip.secureserver.net.Teslacrypt ransomware c&c26496US
2015/12/26_15:34www.hitekshop.vn/login.php112.78.2.101mb2d101.vdrs.net.Keybase keylogger web panel45538VN
2015/12/20_11:16eeps.me/208.67.23.26h155.cpanellogin.net.ESET phishing3257US
2015/12/14_22:05www.drteachme.com/wp-content/plugins/theme-check/misc.php198.154.254.250glulife.glulife.com.trojan46606US
2015/11/03_08:24earthcontrolsys.com/abuse_report.php?issviews.com69.50.210.69-Trojan.Backdoor18866US
2015/10/24_03:50-155.133.18.117/121fjrgoneXyeia1c3v1e3e1e2w4c3e1a3j7a3z4a1f2a1a2z1a3a4e1a2ba2a1w3.exeptr-155.133.18.117.vmline.pl.Trojan.Andromeda197226DE
2015/10/24_03:50-155.133.18.117/goldenbet403.exeptr-155.133.18.117.vmline.pl.Trojan.Andromeda197226DE
2015/10/24_03:50-155.133.18.117/235fjrgoneXyeia1c3v1e3e1e2w4c3e1a3j7a3z4a1f2a1a2z1a3a4e1a2ba2a1w3.exeptr-155.133.18.117.vmline.pl.Trojan.Andromeda197226DE
2015/10/24_03:50-155.133.18.117/nut50a403.exeptr-155.133.18.117.vmline.pl.Trojan.Andromeda197226DE
2015/10/24_03:50-155.133.18.117/38yes3.exeptr-155.133.18.117.vmline.pl.Trojan.Andromeda197226DE
2015/10/16_07:41lunaticjazz.com69.163.200.161apache2-bongo.koechlin.dreamhost.com.Trojan.Ramnit26347US
2015/10/16_07:33www.smartscan.ro85.9.27.130s13v.webindex.ro.compromised site leads to exploit kit5588RO
2015/09/26_14:56skidki-yuga.ru/files/17448.jpg5.101.152.85m2.yoda.beget.ru.PHP.RFI198610RU
2015/09/26_14:56kfc.i.illuminationes.com/snitch?default_keyword=&referrer=&se_referrer=&source=91.226.33.54d6828.core-vps.lv.Script.iFrame.TDS (via compromised sites)56617LV
2015/09/17_22:431866809.securefastserver.com/~keycodes777/x1/login.php86.105.227.125-Bot.C249335EU
2015/09/06_00:08fondazioneciampi.org/nuovo/blogs/media/ap2.php66.36.163.207gasco.com.sa.Trojan.CryptoLocker.CallBack14265US
2015/09/06_00:08europe-academy.net/wp-admin/user/ap2.php192.232.249.212-Trojan.CryptoLocker.CallBack46606US
2015/09/03_21:21ab.usageload32.com/zz/kudhg87s7882bi/mmerrorx.html?tid=x4v&os=Windows&osv=7&isp=Comcast%20Cable&browser=Firefox&ip=Firefox184.50.238.184a184-50-238-184.deploy.static.akamaitechnologies.com.Browlock, Fake.TechSupport20940US
2015/09/03_05:16krsa2gno.internet-security-alert.com/0H4RuV82F4sgUoM42smmqB4doKnVprIJ/52.10.128.168ec2-52-10-128-168.us-west-2.compute.amazonaws.com.Browlock.Fake.TechSupport16509US
2015/09/03_05:16krsa2gno.todays-sweepstakes-winner.com/0H4RuV82F4sgUoM42smmqB4doKnVprIJ/52.10.128.168ec2-52-10-128-168.us-west-2.compute.amazonaws.com.Browlock.Fake.TechSupport16509US
2015/09/03_05:16krsa2gno.congrats-sweepstakes-winner.com/0H4RuV82F4sgUoM42smmqB4doKnVprIJ/52.10.128.168ec2-52-10-128-168.us-west-2.compute.amazonaws.com.Browlock.Fake.TechSupport16509US
2015/09/03_05:16krsa2gno.important-security-brower-alert.com/0H4RuV82F4sgUoM42smmqB4doKnVprIJ/52.10.128.168ec2-52-10-128-168.us-west-2.compute.amazonaws.com.Browlock.Fake.TechSupport16509US
2015/09/03_05:16krsa2gno.youre-todays-lucky-sweeps-winner.com/0H4RuV82F4sgUoM42smmqB4doKnVprIJ/52.10.128.168ec2-52-10-128-168.us-west-2.compute.amazonaws.com.Browlock.Fake.TechSupport16509US
2015/07/20_18:46atlcourier.com/wp-content/plugins/cached_data/k1.exe72.52.170.149host.betterwphosting.com.Trojan.P0ny32244US
2015/07/20_18:46www.mondoperaio.net/wp-content/plugins/cached_data/k1.exe62.149.144.66webx544.aruba.it.Trojan.P0ny31034IT
2015/06/29_16:20lifescience.sysu.edu.cn/filees/guuu16pesche.asp202.116.65.35lifescience.sysu.edu.cn.Leads to exploit4538CN
2015/06/02_07:16www.volleyball-doppeldorf.de/templates/blau_weiss/n8jh3wbr.php?id=6071616337.218.254.115c15.webspace-verkauf.de.iframe on compromised site leads to exploit kit45031DE
2015/06/02_07:16winsetupcostotome.easthamvacations.info/answered-polynomial-eccentricity-unserviceable/02928771821861481494.242.198.222ip-static-94-242-198-222.server.lu.exploit kit5577LU
2015/05/12_19:41executivecoaching.co.il/IsKgVrtvQ/109.226.10.37-trojan50463IL
2015/05/11_10:05www.motivacionyrelajacion.com/Z0H24k7E6A/50.62.31.207ip-50-62-31-207.ip.secureserver.net.trojan26496US
2015/05/11_09:30sgs.us.com/sU3P6pqaWwkJ/23.253.130.80server1.www.mc-solutions.com.trojan27357US
2015/04/24_19:11www.thesparkmachine.com/Antivirus.zip208.113.197.192apache2-emu.paulding.dreamhost.com.FakeAV26347US
2015/04/22_15:17gurde.tourstogo.us/leefoohopt/ezussoadyz/utufegheer/files/GO49776M.vbs176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17-185.91.175.183/sas/evzxce.exe-Trojan.Backdoor42632RU
2015/04/22_15:17web-sensations.com/js/jquery-1.40.15.js192.186.238.40ip-192-186-238-40.ip.secureserver.net.JS.Exploit26496US
2015/04/22_15:17jstaikos.com/51i70l/chbpy.html192.186.209.131ip-192-186-209-131.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17agsteier.com/HSBC_BANK_STORAGE-DATA/new-payment.html173.254.28.44just44.justhost.com.Script.Exploit46606US
2015/04/22_15:17broadtech.co/HSBC_BANK-STORAGE_DATA/new-payment.html23.229.160.136ip-23-229-160-136.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17bilbaopisos.es/HSBC_BANK.STORAGE-DATA/secure.html216.119.143.194ssr1.supercp.com.Script.Exploit55293US
2015/04/22_15:17ajewishgift.com/HSBC_BANK_STORAGE_DATA/payment_document.html192.186.223.196ip-192-186-223-196.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:172amsports.com/HSBC-BANK_STORAGE_DATA/new-payment-document.html69.89.21.71box71.bluehost.com.Script.Exploit46606US
2015/04/22_15:17bilbaopisos.es/BANK.STORAGE-DATA/secure_payment_document.html216.119.143.194ssr1.supercp.com.Script.Exploit55293US
2015/04/22_15:17agsteier.com/HSBC.BANK-STORAGE.DATA/new_secure-document.html173.254.28.44just44.justhost.com.Script.Exploit46606US
2015/04/22_15:17hinsib.com/HSBC_BANK.STORAGE.DATA/secure_payment.document.html198.38.82.23mocha6001.mochahost.com.Script.Exploit23352US
2015/04/22_15:17impressoras-cartoes.com.pt/HSBC.STORAGE.DATA/new.payment.html109.71.43.41idonic.com.Script.Exploit24768PT
2015/04/22_15:17cacl.fr/HSBC-BANK_STORAGE_DATA/secure.payment.html174.127.110.239slan-550-81.anhosting.com.Script.Exploit29854US
2015/04/22_15:17wv-law.com/HSBC-BANK-DATA/secure_payment.html160.153.48.70ip-160-153-48-70.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17aminev.com/HSBC.BANK-STORAGE-DATA/new.payment_document.html69.89.22.122box122.bluehost.com.Script.Exploit46606US
2015/04/22_15:17hydraulicpowerpack.com/HSBC-BANK.STORAGE_DATA/new_secure.html119.18.61.133-Script.Exploit33480IN
2015/04/22_15:17hydraulicpowerpack.com/BANK-STORAGE-DATA/new-document.html119.18.61.133-Script.Exploit33480IN
2015/04/22_15:17aminev.com/HSBC.BANK.DATA/new-secure.html69.89.22.122box122.bluehost.com.Script.Exploit46606US
2015/04/22_15:17aminev.com/HSBC.STORAGE-DATA/new.payment-document.html69.89.22.122box122.bluehost.com.Script.Exploit46606US
2015/04/22_15:17agsteier.com/HSBC_BANK.STORAGE-DATA/new.html173.254.28.44just44.justhost.com.Script.Exploit46606US
2015/04/22_15:17broadtech.co/HSBC_BANK_STORAGE/payment-document.html23.229.160.136ip-23-229-160-136.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17hydraulicpowerpack.com/HSBC.BANK_STORAGE.DATA/new_payment.document.html119.18.61.133-Script.Exploit33480IN
2015/04/22_15:17teprom.it/HSBC.BANK.STORAGE/document.html213.205.38.23client-sh-3.hosting.tiscali.it.Script.Exploit8612IT
2015/04/22_15:17broadtech.co/HSBC-BANK.STORAGE_DATA/new_secure.html23.229.160.136ip-23-229-160-136.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17hydraulicpowerpack.com/HSBC.BANK_STORAGE/payment-document.html119.18.61.133-Script.Exploit33480IN
2015/04/22_15:17bilbaopisos.es/HSBC_BANK_STORAGE_DATA/secure.payment_document.html216.119.143.194ssr1.supercp.com.Script.Exploit55293US
2015/04/22_15:17broadtech.co/HSBC.BANK.STORAGE.DATA/payment.document.html23.229.160.136ip-23-229-160-136.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17wv-law.com/HSBC_BANK_STORAGE/new-payment.document.html160.153.48.70ip-160-153-48-70.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17teprom.it/BANK.STORAGE-DATA/secure_document.html213.205.38.23client-sh-3.hosting.tiscali.it.Script.Exploit8612IT
2015/04/22_15:17hydraulicpowerpack.com/HSBC.BANK.STORAGE/secure_payment.document.html119.18.61.133-Script.Exploit33480IN
2015/04/22_15:17bilbaopisos.es/HSBC_BANK-STORAGE.DATA/new_payment.html216.119.143.194ssr1.supercp.com.Script.Exploit55293US
2015/04/22_15:17bilbaopisos.es/HSBC.BANK_STORAGE/secure.payment_document.html216.119.143.194ssr1.supercp.com.Script.Exploit55293US
2015/04/22_15:17abcdespanol.com/HSBC.BANK_STORAGE/secure.document.html173.254.28.143just143.justhost.com.Script.Exploit46606US
2015/04/22_15:17ajewishgift.com/HSBC_BANK_DATA/payment-document.html192.186.223.196ip-192-186-223-196.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17ajewishgift.com/HSBC_BANK-STORAGE_DATA/new_secure-document.html192.186.223.196ip-192-186-223-196.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17hydraulicpowerpack.com/HSBC_BANK_DATA/payment_document.html119.18.61.133-Script.Exploit33480IN
2015/04/22_15:17undefined.it/HSBC-BANK_DATA/secure.payment.document.html174.127.110.143slan-550-59.anhosting.com.Script.Exploit29854US
2015/04/22_15:172amsports.com/BANK-STORAGE_DATA/secure.html69.89.21.71box71.bluehost.com.Script.Exploit46606US
2015/04/22_15:17teprom.it/HSBC-BANK_STORAGE-DATA/new_secure_payment.html213.205.38.23client-sh-3.hosting.tiscali.it.Script.Exploit8612IT
2015/04/22_15:17hydraulicpowerpack.com/BANK.STORAGE.DATA/payment-document.html119.18.61.133-Script.Exploit33480IN
2015/04/22_15:17abcdespanol.com/HSBC-STORAGE-DATA/payment.document.html173.254.28.143just143.justhost.com.Script.Exploit46606US
2015/04/22_15:17ajewishgift.com/HSBC_STORAGE.DATA/secure_payment.html192.186.223.196ip-192-186-223-196.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:172amsports.com/HSBC.STORAGE-DATA/secure.payment.html69.89.21.71box71.bluehost.com.Script.Exploit46606US
2015/04/22_15:17broadtech.co/BANK-STORAGE.DATA/new_payment.html23.229.160.136ip-23-229-160-136.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17999fitness.com/HSBC.BANK_STORAGE.DATA/new.html69.89.31.242box442.bluehost.com.Script.Exploit46606US
2015/04/22_15:17agsteier.com/HSBC-STORAGE-DATA/payment.document.html173.254.28.44just44.justhost.com.Script.Exploit46606US
2015/04/22_15:172amsports.com/HSBC-BANK_STORAGE.DATA/secure-payment-document.html69.89.21.71box71.bluehost.com.Script.Exploit46606US
2015/04/22_15:17abcdespanol.com/BANK_STORAGE.DATA/new.payment.html173.254.28.143just143.justhost.com.Script.Exploit46606US
2015/04/22_15:17aminev.com/HSBC.BANK_STORAGE-DATA/secure_document.html69.89.22.122box122.bluehost.com.Script.Exploit46606US
2015/04/22_15:17broadtech.co/HSBC-STORAGE_DATA/payment.document.html23.229.160.136ip-23-229-160-136.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17cacl.fr/HSBC.BANK_STORAGE_DATA/document.html174.127.110.239slan-550-81.anhosting.com.Script.Exploit29854US
2015/04/22_15:17999fitness.com/HSBC_BANK-STORAGE-DATA/new_payment.html69.89.31.242box442.bluehost.com.Script.Exploit46606US
2015/04/22_15:17cacl.fr/HSBC-STORAGE_DATA/new.secure.html174.127.110.239slan-550-81.anhosting.com.Script.Exploit29854US
2015/04/22_15:17wv-law.com/HSBC.BANK_STORAGE.DATA/secure_payment.html160.153.48.70ip-160-153-48-70.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17cacl.fr/HSBC.BANK_STORAGE-DATA/payment.html174.127.110.239slan-550-81.anhosting.com.Script.Exploit29854US
2015/04/22_15:17hinsib.com/HSBC.BANK_DATA/new-payment.document.html198.38.82.23mocha6001.mochahost.com.Script.Exploit23352US
2015/04/22_15:17abcdespanol.com/BANK_STORAGE_DATA/new.secure-document.html173.254.28.143just143.justhost.com.Script.Exploit46606US
2015/04/22_15:17impressoras-cartoes.com.pt/BANK_STORAGE-DATA/new.payment.html109.71.43.41idonic.com.Script.Exploit24768PT
2015/04/22_15:17broadtech.co/BANK_STORAGE.DATA/secure_payment_document.html23.229.160.136ip-23-229-160-136.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17bilbaopisos.es/BANK-STORAGE.DATA/secure_payment-document.html216.119.143.194ssr1.supercp.com.Script.Exploit55293US
2015/04/22_15:17teprom.it/HSBC_BANK_STORAGE_DATA/secure-document.html213.205.38.23client-sh-3.hosting.tiscali.it.Script.Exploit8612IT
2015/04/22_15:172amsports.com/HSBC_BANK-STORAGE_DATA/secure.html69.89.21.71box71.bluehost.com.Script.Exploit46606US
2015/04/22_15:17impressoras-cartoes.com.pt/HSBC.BANK.STORAGE/payment.html109.71.43.41idonic.com.Script.Exploit24768PT
2015/04/22_15:17aminev.com/HSBC_BANK-STORAGE.DATA/new_payment-document.html69.89.22.122box122.bluehost.com.Script.Exploit46606US
2015/04/22_15:172amsports.com/HSBC-BANK.DATA/new_payment.html69.89.21.71box71.bluehost.com.Script.Exploit46606US
2015/04/22_15:17wv-law.com/HSBC_STORAGE-DATA/new-secure.payment.html160.153.48.70ip-160-153-48-70.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17undefined.it/BANK-STORAGE-DATA/new-payment.document.html174.127.110.143slan-550-59.anhosting.com.Script.Exploit29854US
2015/04/22_15:17abcdespanol.com/HSBC_BANK-STORAGE-DATA/secure-payment.document.html173.254.28.143just143.justhost.com.Script.Exploit46606US
2015/04/22_15:17abcdespanol.com/HSBC-BANK_STORAGE.DATA/new.payment.html173.254.28.143just143.justhost.com.Script.Exploit46606US
2015/04/22_15:17cacl.fr/HSBC_BANK-STORAGE-DATA/secure_payment_document.html174.127.110.239slan-550-81.anhosting.com.Script.Exploit29854US
2015/04/22_15:17hinsib.com/BANK-STORAGE.DATA/secure.document.html198.38.82.23mocha6001.mochahost.com.Script.Exploit23352US
2015/04/22_15:17abcdespanol.com/HSBC.STORAGE_DATA/new_payment_document.html173.254.28.143just143.justhost.com.Script.Exploit46606US
2015/04/22_15:17broadtech.co/HSBC_BANK.STORAGE-DATA/secure.document.html23.229.160.136ip-23-229-160-136.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17ajewishgift.com/HSBC.BANK.STORAGE_DATA/new_secure.payment.html192.186.223.196ip-192-186-223-196.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17wv-law.com/HSBC-BANK-STORAGE.DATA/payment_document.html160.153.48.70ip-160-153-48-70.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17undefined.it/HSBC_BANK.STORAGE.DATA/new-secure.document.html174.127.110.143slan-550-59.anhosting.com.Script.Exploit29854US
2015/04/22_15:17ajewishgift.com/HSBC-BANK-STORAGE-DATA/secure.html192.186.223.196ip-192-186-223-196.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:172amsports.com/HSBC.BANK_STORAGE-DATA/new_secure.document.html69.89.21.71box71.bluehost.com.Script.Exploit46606US
2015/04/22_15:17broadtech.co/HSBC.BANK_STORAGE_DATA/secure-document.html23.229.160.136ip-23-229-160-136.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17mtldesigns.ca/HSBC-BANK-DATA/new-secure-document.html23.229.153.132ip-23-229-153-132.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17ajewishgift.com/HSBC_BANK-STORAGE-DATA/secure.html192.186.223.196ip-192-186-223-196.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17impressoras-cartoes.com.pt/HSBC_BANK-STORAGE/new_document.html109.71.43.41idonic.com.Script.Exploit24768PT
2015/04/22_15:17mtldesigns.ca/HSBC-BANK.STORAGE/new_secure.document.html23.229.153.132ip-23-229-153-132.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17bilbaopisos.es/HSBC_BANK.STORAGE_DATA/secure.payment.html216.119.143.194ssr1.supercp.com.Script.Exploit55293US
2015/04/22_15:17wv-law.com/HSBC_BANK_DATA/secure_payment.html160.153.48.70ip-160-153-48-70.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17cacl.fr/HSBC-BANK_DATA/secure.html174.127.110.239slan-550-81.anhosting.com.Script.Exploit29854US
2015/04/22_15:17wv-law.com/HSBC.BANK_STORAGE_DATA/new_payment_document.html160.153.48.70ip-160-153-48-70.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17hydraulicpowerpack.com/HSBC.BANK_DATA/payment-document.html119.18.61.133-Script.Exploit33480IN
2015/04/22_15:17aminev.com/HSBC-BANK-STORAGE-DATA/new-secure.html69.89.22.122box122.bluehost.com.Script.Exploit46606US
2015/04/22_15:17broadtech.co/HSBC.BANK.STORAGE/new-document.html23.229.160.136ip-23-229-160-136.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17agsteier.com/HSBC.BANK.DATA/new_secure-document.html173.254.28.44just44.justhost.com.Script.Exploit46606US
2015/04/22_15:17aminev.com/HSBC-STORAGE_DATA/secure_document.html69.89.22.122box122.bluehost.com.Script.Exploit46606US
2015/04/22_15:17undefined.it/HSBC_BANK-STORAGE.DATA/new_payment_document.html174.127.110.143slan-550-59.anhosting.com.Script.Exploit29854US
2015/04/22_15:17agsteier.com/BANK_STORAGE-DATA/new.payment-document.html173.254.28.44just44.justhost.com.Script.Exploit46606US
2015/04/22_15:17broadtech.co/HSBC_STORAGE_DATA/payment.html23.229.160.136ip-23-229-160-136.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17cacl.fr/HSBC_BANK_DATA/new.secure.html174.127.110.239slan-550-81.anhosting.com.Script.Exploit29854US
2015/04/22_15:17ajewishgift.com/HSBC_BANK_STORAGE.DATA/secure.payment-document.html192.186.223.196ip-192-186-223-196.ip.secureserver.net.Script.Exploit26496US
2015/04/22_15:17eekro.cruisingsmallship.com/oaglotogoa/pusoathuth/okexithejo/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17ptuph.barginginfrance.net/ytooglesyw/evymoftoph/leewhigroo/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17emits.iptvdeals.com/pigneglogl/psoomporso/whulsynsee/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17shovi.frost-electric-supply.com/ychoomusha/uptejawhee/eegelengic/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17iptoo.cruisingsmallship.com/cocmeepsee/nikagnypsi/hoaboogrol/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17uchyz.cruisingsmallship.com/vootukigli/shacmiwhoa/zipevelrid/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17eecky.butlerelectricsupply.com/oalseebypt/hidowodruf/phaptyrsoa/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17zyrdu.cruisingsmallship.com/vyglachaph/choawoatch/glocoaphoo/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17ixoox.csheaven.com/ytoocmefta/ythyreejyk/eeshoomoar/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17gylra.cruisingsmallship.com/talsoohaha/icoagroapt/oglaheeglo/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17oshoo.iptvdeals.com/oachudydri/theshasicm/chyshyngee/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17coaha.frenchgerlemanelectric.com/atydymulra/psoaptylty/ywhopaptyl/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17echoa.randbinternationaltravel.com/wheekresip/lesorgysoj/oasemteefu/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17ooksu.frost-electric-supply.com/sebossoode/itylseehyh/grykrostad/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17efugl.iptvdeals.com/avoamsyrga/ujecketird/fudsoonsep/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17ptool.barginginfrance.net/wadostomot/oophosagli/tipsosteen/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17ocick.frost-electric-supply.com/nasaghytho/whofydroon/glotchypiv/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17xotsa.frenchgerlemanelectric.com/apsestooxo/iwheewhosh/keckalrees/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17veksi.barginginfrance.net/oassemsoci/psolsoapsi/netsoorgaw/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17ukugl.tourstogo.us/shudsoangu/whooglagoz/isestipsep/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17greev.randbinternationaltravel.com/sheptighut/groadratoa/omedryglol/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17simpi.tourstogo.us/vodopsoopu/dumseessee/viphadeeph/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17iwhab.randbinternationaltravel.com/etuwotsols/phydretack/psyveshool/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17whabi.csheaven.com/ehetsusywh/yglegrehee/jitypsewhy/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17nonsi.csheaven.com/udoartorsa/oathampoat/uzostecmew/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17namso.butlerelectricsupply.com/yfuksajozi/phidampoas/ufykampoap/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17eroov.iptvdeals.com/wheedessyh/uptoowhooj/urognotchy/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17rawoo.barginginfrance.net/deethevoaz/upsachoaju/poastycith/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17hoawy.frost-electric-supply.com/synestyfoo/oampansoam/fetuksessu/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17wetyt.tourstogo.us/shissashee/abekekurdi/oagrusteel/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17uvidu.butlerelectricsupply.com/ephuhoawud/fodrejymta/pugnovesho/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17asham.tourstogo.us/oadirteeph/eeroaghyss/evoarsoshi/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17oakso.tourstogo.us/pheekseeku/kirystobul/exeedsoots/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17dujur.barginginfrance.net/oampimsika/foowimupho/thampoperd/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17keemy.butlerelectricsupply.com/zyrsoltoah/duftuxoxyz/epheenyzug/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17ithyk.frenchgerlemanelectric.com/cywhamsoaj/thamtampee/oodsardoon/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17vitha.csheaven.com/awygludoav/ooghooksek/puptywoamt/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17esoad.frost-electric-supply.com/psutsoshup/phastupsim/tigrystolt/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17gurde.tourstogo.us/leefoohopt/ezussoadyz/utufegheer/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17oampa.csheaven.com/ovoamegloa/ishoodooho/whetcheeng/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17acool.csheaven.com/okoassetch/buweegnogr/ereedrimtu/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17phoaz.cruisingsmallship.com/thymuksate/ysigorguru/stogroaryf/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17oshoa.iptvdeals.com/whoagrofta/shaphygyft/oomtyrtogl/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17psooz.tourstogo.us/joacumupty/yduhoalrow/ooksyfoogl/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17oolsi.frost-electric-supply.com/eerutsuleh/oamteejigl/shogrodroo/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17kulro.csheaven.com/dersyphalr/kyjorsoalt/rywoarsoaz/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17eeroo.frost-electric-supply.com/phoagnonga/oshuzoathu/anunserogy/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17gyboo.cruisingsmallship.com/phyckyhert/oaltesteef/ptoneewhis/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17rumog.frost-electric-supply.com/ooxyphuxoa/oodrirolta/javyphepti/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17veevu.tourstogo.us/yxampoavoo/psopansoom/ithexoakib/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17eetho.cruisingsmallship.com/fustochoox/areltussen/hoogroxuga/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17oojee.barginginfrance.net/poovajywhi/ooghovelee/madroompob/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17igoby.frost-electric-supply.com/eesefteeps/ookeestool/meefeleezu/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17upsoj.iptvdeals.com/doaryruptu/uroassulah/foomosoglo/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17oosee.barginginfrance.net/buksyngems/boofoostiw/orignujonu/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17oawoo.frenchgerlemanelectric.com/utyfatheex/nurirsoaja/rojingaroo/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17whave.iptvdeals.com/panoowyxoz/oazicmitov/ptampordap/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17kyrsu.frost-electric-supply.com/wowoathept/grishamesa/weemoseevo/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17mocka.frost-electric-supply.com/zarseehetu/igaksuxals/kyroalopsa/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17pulso.butlerelectricsupply.com/uthoachugr/uceerdyhap/ochadikist/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17nefib.tourstogo.us/shoampakre/igoawootsi/greengeeku/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17oapsa.tourstogo.us/looreeneps/yshoobeeje/syshyshogo/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17azoos.csheaven.com/eechoawoap/rissupsuns/bigleeptuf/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17ptush.iptvdeals.com/oapsoadoov/vooglebopo/oasoardexy/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17zibup.csheaven.com/ypsoophoov/ptycmympub/teezukedoo/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17atyss.barginginfrance.net/aseerteert/ootoorezav/olaweersyb/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17ptewh.iptvdeals.com/foogloajuc/eeshedyfon/yvookrynso/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17igroo.barginginfrance.net/ogroatashy/osynoonsax/ydumtixivy/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17oofuv.cruisingsmallship.com/oozughoars/psoakraghi/oawygroors/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17pigra.csheaven.com/eveebichoa/xygyrtoolt/ooholtoaka/files/46.30.42.74veronikalife.ru.VBS.Trojan.Downloader35415RU
2015/04/22_15:17dofeb.frenchgerlemanelectric.com/iglejimoar/upsudypooz/leepeegrah/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17igagh.tourstogo.us/chogoajeep/uhozyngako/iphoasteer/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17estoa.frost-electric-supply.com/ukoatiptyv/upseeboapo/ufekyckaft/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17ubike.tourstogo.us/lussoaglee/raxadsunyx/oatchingoa/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17boogu.barginginfrance.net/peehejoaty/avugnemtee/hibygnoars/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/22_15:17oowhe.frost-electric-supply.com/ejisoozach/esisseeloo/oajilitsof/files/93.170.123.186programmerworld.ru.VBS.Trojan.Downloader29182CZ
2015/04/22_15:17nugly.barginginfrance.net/oogamtoafo/eestathici/athiphisik/files/176.31.28.226-VBS.Trojan.Downloader16276FR
2015/04/21_10:28eternitymobiles.com/25/144.exe203.170.86.89server-2h-r34.ipv4.au.syrahost.com.Trojan.Dridex38719AU
2015/04/21_10:28e-matelco.com/25/144.exe200.58.114.51libia.dattaweb.com.Trojan.Dridex27823AR
2015/04/21_10:28TRIANGLESERVICESLTD.COM/25/144.exe113.21.229.2-Trojan.Dridex45766BD
2015/04/21_10:28hobby-hangar.net/25/144.exe94.76.212.176swindon.eukhost.com.Trojan.Dridex29550GB
2015/04/21_10:28creditbootcamp.com/25/144.exe192.185.48.205-Trojan.Dridex20013US
2015/04/20_23:15thewinesteward.com/css/Document1704.exe192.254.249.180-Trojan.Dyre46606US
2015/04/11_14:50securitywebservices.com/aEubV1l8Cu.js217.23.5.57-P2PZeus.WebInject49981NL
2015/04/11_14:50securitywebservices.com/an4XpPvL6p.js217.23.5.57-P2PZeus.WebInject49981NL
2015/04/11_14:50securitywebservices.com/bQR3XpCbGj.js217.23.5.57-P2PZeus.WebInject49981NL
2015/04/11_14:50securitywebservices.com/hD08940x9A.js217.23.5.57-P2PZeus.WebInject49981NL
2015/04/11_14:50securitywebservices.com/HNXZAxrMNC.js217.23.5.57-P2PZeus.WebInject49981NL
2015/04/11_14:50securitywebservices.com/JPPj4HhWXH.js217.23.5.57-P2PZeus.WebInject49981NL
2015/04/11_14:50securitywebservices.com/nuLwjhUDt4.js217.23.5.57-P2PZeus.WebInject49981NL
2015/04/11_14:50securitywebservices.com/pbMes3AKl2.js217.23.5.57-P2PZeus.WebInject49981NL
2015/04/11_14:50securitywebservices.com/s4haYynZvs.js217.23.5.57-P2PZeus.WebInject49981NL
2015/04/11_14:50securitywebservices.com/WQLzrpnA7D.js217.23.5.57-P2PZeus.WebInject49981NL
2015/04/11_14:50securitywebservices.com/WrQBcRn4E3.js217.23.5.57-P2PZeus.WebInject49981NL
2015/04/11_14:34theweatherspace.com185.53.177.20-Malvertising61969DE
2015/03/28_05:29-46.160.125.167/p2603us21.pdf46.160.125.167.format-tv.net.Trojan.Upatre6712UA
2015/03/28_05:29-46.160.125.167/2603uk11.pdf46.160.125.167.format-tv.net.Trojan.Upatre6712UA
2015/03/28_05:29-46.160.125.167/2603uk12.pdf46.160.125.167.format-tv.net.Trojan.Upatre6712UA
2015/03/28_05:29-46.160.125.167/p2603us11.pdf46.160.125.167.format-tv.net.Trojan.Upatre6712UA
2015/03/28_05:29-46.160.125.167/p2603us12.pdf46.160.125.167.format-tv.net.Trojan.Upatre6712UA
2015/03/28_05:29-46.249.3.66/winbox/winbox.exe-Trojan.Upatre34456RU
2015/03/20_11:35b.nevadaprivateoffice.com:8085/phpmyadm/modelsearch/help/after.php?before=346.254.17.233hosted-by.ihc.ru.Sweet Orange exploit kit42244RU
2015/03/11_12:26hujii.qplanner.cf:8181/2006/movies/html/christmas.php?online=160755&paper=124&what=109448&promos=206723&exchange=309188&edit=135400&common=21695646.254.17.30hosted-by.ihc.ru.exploit kit42244RU
2015/03/09_13:46-64.37.52.84/~ibnking1/latino/smart.host-care.com.trojans33182US
2015/03/07_07:57dimarsbg.com/images/portfolio/vtutmcireturxeitritxirete/rcturtncuyretycrutycreu.exe95.141.37.183cphost04.qhoster.net.Trojan.Backdoor49367IT
2015/03/07_07:57dimarsbg.com/images/prettyPhoto/light_rounded/jicmtritucirutmucr.exe95.141.37.183cphost04.qhoster.net.Trojan.Backdoor49367IT
2015/03/07_07:57dimarsbg.com/images/social_media/vuiutcimrieiurxiexerexrexrerex/vrituiruixtuieruxtireuit.exe95.141.37.183cphost04.qhoster.net.Trojan.Backdoor49367IT
2015/02/28_14:36www.vipcpms.com/watch?key=e722a8eea048590dd97760d8b657327b&scrWidth=1680&scrHeight=1050&tz=0209.200.44.228trgdbtest.webair.com.Malvertising, Android.FakeAV27257US
2015/02/28_14:36app.pho8.com/click.php?c=246&key=l8s861364oq1y6w08t9kjkq1&pl_id=1286198.58.103.202li553-202.members.linode.com.Malvertising, Android.FakeAV36351US
2015/02/28_14:36app.pho8.com/lp/sd/en/lp4/index.php?c=300&l=524&subid=21841780391198.58.103.202li553-202.members.linode.com.Malvertising, Android.FakeAV36351US
2015/02/28_14:36app.pho8.com/lp/sd/en/lp4/files/bootstrap.css198.58.103.202li553-202.members.linode.com.Malvertising, Android.FakeAV36351US
2015/02/28_14:36app.pho8.com/lp/sd/en/lp4/files/bootstrap-responsive.css198.58.103.202li553-202.members.linode.com.Malvertising, Android.FakeAV36351US
2015/02/28_14:36app.pho8.com/go.php?c=255&l=387&subid=21843049645198.58.103.202li553-202.members.linode.com.Malvertising, Android.FakeAV36351US
2015/02/28_14:36app.pho8.com/jump/?jl=66968484198.58.103.202li553-202.members.linode.com.Malvertising, Android.FakeAV36351US
2015/02/28_14:36app.pho8.com/go.php?c=246&l=509&subid=21388413584?198.58.103.202li553-202.members.linode.com.Malvertising, Fake.Cleaner36351US
2015/02/28_14:36www.officialrdr.com/b012dd3a-0871-4fc2-a5d8-8f6e6e30c33454.236.134.245ec2-54-236-134-245.compute-1.amazonaws.com.Malvertising, Android.FakeAV14618US
2015/02/28_14:36www.scanmyphones.com/fatalvirus/mx/101/index.php?countryname=United%20Kingdom&brand=&model=&isp=PlusNet%20Technologies%20Ltd&voluumdata=vid..00000008-5d87-4a50-8000-000000000000__vpid..15af7000-bf52-11e4-8afe-28ca782357aa__caid..b012dd3a-0871-4fc2-a5d8-8f6e6e30c334__lid..281f1d6a-3f5c-4aef-b00d-8178c6d9f00f__rt..D__oid1..14fdf5b9-f153-4ad7-9aec-c61b2432d31e54.209.159.227ec2-54-209-159-227.compute-1.amazonaws.com.Malvertising, Android.FakeAV14618US
2015/02/28_14:36mobile.bitterstrawberry.org/?id=131985.17.137.41-Malvertising, Android.FakeAV60781NL
2015/02/25_07:37static.retirementcommunitiesfyi.com/k?tstmp=3472398450.87.151.14650-87-151-146.unifiedlayer.com.Gateway for Sweet Orange EK46606US
2015/02/17_01:15ad-beast.com/ads.js5.61.39.14-Browlock, Malvertising16265GB
2015/02/17_01:15njtgsd.attackthethrone.com/public-justice/64XPKZldWDM_/R4efelSvf_/I1OdCoSKw2r1epqivQsiUvi9Pb1pHroRToqggbsG5oYAuB_/fSiunpQPK/_/lE3aXgQ~~/MTQ2N2I5OThlNWVjOWFmMWQ2OTE0ZjBh/governing-institution.mhtml94.242.203.247ip-static-94-242-203-247.server.lu.Browlock.Malvertising5577LU
2015/02/04_13:35ads.wikipartes.com/all/test.php31.192.210.88server.yakanaydinlatma.com.tr.redirects to exploit kit51559TR
2015/01/14_20:48d4.cumshots.ws:25707/history/t/movies.php?timeline=2146.254.18.236hosted-by.ihc.ru.exploit kit42244RU
2015/01/13_14:47rubiks.ca/js/jquery-1.14.94.js50.87.18.12750-87-18-127.unifiedlayer.com.Compromised site, leads to exploit46606US
2015/01/13_14:47mysmallcock.com/taxadmin/get_doc.html64.6.105.24164-6-105-241.phatservers.com.Compromised site, leads to exploit30266US
2015/01/13_14:47monarchslo.com/taxadmin/get_doc.html69.163.242.27apache2-dap.mafdet.dreamhost.com.Compromised site, leads to exploit26347US
2015/01/13_14:47myshopmarketim.com/taxadmin/get_doc.html94.73.148.14094-73-148-140.cizgi.net.tr.Compromised site, leads to exploit34619TR
2015/01/13_14:47mindstormstudio.ro/taxadmin/get_doc.html85.10.205.164ns.gorilahosting.ro.Compromised site, leads to exploit24940DE
2015/01/13_14:47semiyun.com/taxadmin/get_doc.html95.173.170.227227rfszma.guzel.net.tr.Compromised site, leads to exploit51559TR
2015/01/13_14:47maxisoft.co.uk/taxadmin/get_doc.html192.185.111.220ns539.websitewelcome.com.Compromised site, leads to exploit20013US
2015/01/13_14:47omrdatacapture.com/taxadmin/get_doc.html213.171.218.18server213-171-218-18.livedns.org.uk.Compromised site, leads to exploit8560GB
2015/01/13_12:55fgtkmcby02.eu:9633/file/help.php?state=36185.16.40.228-exploit kit199456GB
2015/01/08_08:12-109.87.242.9/pod2/beo1bw3.exe9.242.87.109.triolan.net.Trojan.Downloader13188UA
2015/01/08_08:12-37.221.162.57/pod1/sdhfjkl.exelh20471.voxility.net.Trojan.Downloader39743RO
2015/01/08_08:12-37.221.162.57/pod2/beo1bw3.exelh20471.voxility.net.Trojan.Downloader39743RO
2015/01/08_08:12-37.221.162.57/pod2/sdfbfhj.exelh20471.voxility.net.Trojan.Downloader39743RO
2015/01/08_08:12-5.254.98.54/pod2/sdhfjkl.exelh20471.voxility.net.Trojan.Downloader39743RO
2015/01/08_08:12-93.77.231.193/pod2/sdhfjkl.exedynamic.te.volia.net.Trojan.Injector.HNNP25229UA
2015/01/08_08:12-93.79.189.119/pod1/gavr001.exe-Trojan.Downloader25229UA
2014/12/17_21:01whitehorsetechnologies.net/images/clients/x/mail.php208.91.199.150bh-7.webhostbox.net.Destination of banking phishing19905VG
2014/12/03_08:50loft2126.dedicatedpanel.com/cra/s.exe85.25.176.113loft2126.serverloft.com.Trojan.Agent8972DE
2014/12/03_08:50loft2126.dedicatedpanel.com/vvv.exe85.25.176.113loft2126.serverloft.com.Trojan.Agent8972DE
2014/12/03_08:50chaveiro.bio.br/tmp/AcbtReader.exe177.12.163.81web943.uni5.net.Trojan.Agent.AI28299BR
2014/12/03_08:50campamento.queenscamp.com/yuppie/staying74.91.220.22.webhosting.ecommerce.com.Trojan.Agent.CRV32392US
2014/12/03_08:50ftp.flyfishusa.com/lords/vanishings184.168.240.101ip-184-168-240-101.ip.secureserver.net.Trojan.Agent.CRV26496US
2014/12/03_08:50optimization-methods.com/Bilder/calc.exe212.218.192.28plesk3.nbg1.nethinks.com.Trojan.Backdoor8319DE
2014/12/03_08:50paraskov.com/err.exe66.154.48.2adulttgpgallery.com.Trojan.Backdoor22653US
2014/12/03_08:50tatschke.net/hbc.exe190.228.29.82mx2982.godns.net.Trojan.Backdoor7303AR
2014/12/03_08:50wt10.haote.com/jywgxrjzd.exe218.75.155.41-Trojan.Backdoor4134CN
2014/12/03_08:50www.fiduciariobajio.com.mx/plugins/content/hltv.exe200.76.36.93static-200-76-36-93.alestra.net.mx.Trojan.Backdoor11172MX
2014/12/03_08:50cmicapui.ce.gov.br/components/com_phocadownload/helpers/modu.exe54.228.191.94ec2-54-228-191-94.eu-west-1.compute.amazonaws.com.Trojan.Banker16509US
2014/12/03_08:50harshwhispers.com/img/dunptty.gif66.240.144.68noreverse.broadspire.com.Trojan.Banker23136US
2014/12/03_08:50harshwhispers.com/img/wxynts.gif66.240.144.68noreverse.broadspire.com.Trojan.Banker23136US
2014/12/03_08:50prorodeosportmed.com/templates/atomic/html/mod_custom/default.xx184.168.16.1p3nlhg716c1716.shr.prod.phx3.secureserver.net.Trojan.Banker26496US
2014/12/03_08:50xicaxique.com.br/catalog/view/theme/default/image/image102.jpg200.219.249.162static.200.219.249.162.datacenter1.com.br.Trojan.Banker.DE16397BR
2014/12/03_08:50iybasketball.info/wp-content/themes/twentytwelve/lo.exe192.186.233.104ip-192-186-233-104.ip.secureserver.net.Trojan.Downloader26496US
2014/12/03_08:50loft2126.dedicatedpanel.com/pnn/1.txt85.25.176.113loft2126.serverloft.com.Trojan.Downloader8972DE
2014/12/03_08:50loft2126.dedicatedpanel.com/pnn/12.exe85.25.176.113loft2126.serverloft.com.Trojan.Downloader8972DE
2014/12/03_08:50loft2126.dedicatedpanel.com/pnn/20.exe85.25.176.113loft2126.serverloft.com.Trojan.Downloader8972DE
2014/12/03_08:50hexadl.line55.net/FLV_Media_Player.exe104.28.15.104-Trojan.Downloader.Agent13335US
2014/12/03_08:50hexadl.line55.net/FLV-HD.exe104.28.14.104-Trojan.Downloader.Agent13335US
2014/12/03_08:50fbku.com/yeni/Porno-HD.exe94.23.169.208-Trojan.Dropper16276FR
2014/12/03_08:50getdatanetukscan.info/sp32_64_10044639319006172375.exe85.17.73.28-Trojan.FakeMS16265NL
2014/12/03_08:50getdatanetukscan.info/sp32_64_3491943367355003623.exe85.17.73.28-Trojan.FakeMS16265NL
2014/12/03_08:50extreembilisim.com/themes/blue/Cure.exe188.132.231.74cpanel2.webadam.com.Trojan.MSIL.Injector42910TR
2014/12/03_08:50extreembilisim.com/themes/blue/panelServerCrypted.exe188.132.231.74cpanel2.webadam.com.Trojan.MSIL.Injector42910TR
2014/12/03_08:50nailbytes1.com/test/86lkL2Xpxa.exe208.109.216.59ip-208-109-216-59.ip.secureserver.net.Trojan.PWS26496US
2014/12/03_08:50hoerbird.net/galerie/w4f3f4.exe85.13.132.183dd8432.kasserver.com.Trojan.Zbot34788DE
2014/12/03_08:50josip-stadler.org/11192.185.78.65ns105.websitewelcome.com.Trojan.Zbot20013US
2014/12/03_08:50loft2126.dedicatedpanel.com/b.exe85.25.176.113loft2126.serverloft.com.Trojan.Zbot8972DE
2014/12/03_08:50chsplantsales.co.uk/werwre5689.238.188.22http.apache1.cp247.net.Trojan.Zeus.GO9009GB
2014/12/03_08:50cudacorp.com/shqgowox192.185.235.74-Trojan.Zeus.GO46606US
2014/12/03_08:50jdfabrication.com/ihfipiex64.78.28.201intermedia.net.Trojan.Zeus.GO16406US
2014/12/03_08:50mueller-holz-bau.com/v28nyn2781.169.145.161wa1.rzone.de.Trojan.Zeus.GO6724DE
2014/12/03_08:50perfectionautorepairs.com/jkcokunrh66.147.244.51box751.bluehost.com.Trojan.Zeus.GO46606US
2014/12/03_08:50pharmadeal.gr/nfqnaanl64.71.131.228228.224-28.131.71.64.in-addr.arpa.Trojan.Zeus.GO6939US
2014/12/03_08:50testtralala.xorg.pl/s6i8yn193.203.99.114ip-99-114.redefine.pl.Trojan.Zeus.GO47303PL
2014/12/03_08:50www.super8service.de/zf0yx81.169.145.164wa4.rzone.de.Trojan.Zeus.GO6724DE
2014/11/27_18:24systemscheckusa.com/208.94.229.238-Browlock.FakeInfection19710US
2014/11/27_18:24www.email-login-support.com/index-10.html192.186.249.4ip-192-186-249-4.ip.secureserver.net.Browlock.FakeInfection26496US
2014/11/27_18:2497b1c56132dfcdd90f93-0c5c8388c0a5897e648f883e2c86dc72.r54.cf5.rackcdn.com/67.135.105.184-Browlock.FakeInfection209US
2014/11/27_18:24immediateresponseforcomputer.com/index112.htm23.229.170.164ip-23-229-170-164.ip.secureserver.net.Browlock.FakeInfection26496US
2014/11/27_18:24www.consumeralternatives.org/anti-virus-check.html64.235.60.164lasvegas-nv-datacenter.com.Browlock.FakeInfection26277US
2014/11/25_08:30-104.152.215.90/1.html90-215-152-104-static.reverse.queryfoundry.net.CVE-2014-6332 exploit62638US
2014/10/09_13:05www.sasenergia.pt/images/highslide/highslide-with-gallery.js176.221.32.120pplc32120.ciberserver.com.Compromised site leading to exploit8426PT
2014/09/16_09:59optilogus.com/twmfizdfmu/lteqwxftti.html192.185.17.123-Compromised site (Sage malspam campaign), leads to Upatre20013US
2014/09/16_09:59flashsavant.com/cqavunntfg/kuldytebws.html74.91.152.22.webhosting.ecommerce.com.Compromised site (Sage malspam campaign), leads to Upatre32392US
2014/09/16_09:59becomedebtfree.com.au/ttlnlmwbox/ctinpfgeob.html198.57.194.65198-57-194-65.unifiedlayer.com.Compromised site (Sage malspam campaign), leads to Upatre46606US
2014/09/16_09:59unitex.home.pl/bbhdskxelc/wlqcwttani.html79.96.42.136v061604.home.net.pl.Compromised site (Natwest malspam campaign), leads to Upatre12824PL
2014/09/16_09:59becomedebtfree.com.au/zscczqbncu/nrrwalnlba.html198.57.194.65198-57-194-65.unifiedlayer.com.Compromised site (Sage malspam campaign), leads to Upatre46606US
2014/09/16_09:59hobbytotaalservice.nl/dspbhbslyt/twzokdiymd.html85.17.155.23hosted-by.leaseweb.com.Compromised site (Natwest malspam campaign), leads to Upatre16265NL
2014/09/16_09:59bnsoutlaws.co.uk/xzvltaqahm/hrbturjzuh.html87.249.106.3rev-3.106.249.87.virtu.nl.Compromised site (Natwest malspam campaign), leads to Upatre16243NL
2014/09/16_09:59bnsoutlaws.co.uk/vhwqpjheft/nlxclwfmym.html87.249.106.3rev-3.106.249.87.virtu.nl.Compromised site (Natwest malspam campaign), leads to Upatre16243NL
2014/09/16_09:59bnsoutlaws.co.uk/sadpwzhoww/durnmjxqyj.html87.249.106.3rev-3.106.249.87.virtu.nl.Compromised site (Natwest malspam campaign), leads to Upatre16243NL
2014/09/16_09:59artsconsortium.org/znquvoclmr/bamgrmqmgb.html72.47.194.241gumey.com.Compromised site (Natwest malspam campaign), leads to Upatre31815US
2014/09/16_09:59artsconsortium.org/wkqcisrgap/ahqjkywlsx.html72.47.194.241gumey.com.Compromised site (Natwest malspam campaign), leads to Upatre31815US
2014/09/16_09:59artsconsortium.org/lcrplilcal/irzdmndcby.html72.47.194.241gumey.com.Compromised site (Natwest malspam campaign), leads to Upatre31815US
2014/09/16_09:59-162.210.70.17/uemfjtpigt/dgnkhubxnc.html162.210.70-17.confluence-networks.com.Compromised site (Natwest malspam campaign), leads to Upatre40034VG
2014/09/16_09:59ambulanciaslazaro.com/nqwkgtzemx/yjfqpocron.html149.62.168.210inetworking.vservers.es.Compromised site (Natwest malspam campaign), leads to Upatre12860ES
2014/09/16_09:59luchtenbergdecor.com.br/cythsfonuj/sijnkzotme.js186.202.56.110CPROHWIN0190.locaweb.com.br.Compromised site (Natwest malspam campaign), leads to Upatre27715BR
2014/09/16_09:59ciclismovalenciano.com/wcxpcflvbj/ymkmcvpnkh.js46.29.49.1cloud1.hospedajeydominios.com.Compromised site (Natwest malspam campaign), leads to Upatre51718ES
2014/09/16_09:59pix360.co.nf/lgdjojxwuo/fofrkxuhgc.html83.125.22.199-Compromised site (DHL malspam campaign), leads to Upatre13237EU
2014/09/16_09:59isonomia.com.ar/mkyejphtxc/nsjkdqsmto.html200.58.123.153x094vm14.isonomia.com.ar.Compromised site (DHL malspam campaign), leads to Upatre27823AR
2014/09/16_09:59interactivearea.ru/kuxqihgvye/dbjyaszqcq.html37.140.192.82server51.hosting.reg.ru.Compromised site (DHL malspam campaign), leads to Upatre197695RU
2014/09/16_09:59okeanbg.com/lwpxofmvqz/jeslvdvjrt.html91.215.216.21hook.icnhost.net.Compromised site (DHL malspam campaign), leads to Upatre49699BG
2014/09/16_09:59okeanbg.com/jfydaalego/mimaefuenh.html91.215.216.21hook.icnhost.net.Compromised site (DHL malspam campaign), leads to Upatre49699BG
2014/09/16_09:59interactivearea.ru/tjnmfqjver/tswcsbafys.html37.140.192.82server51.hosting.reg.ru.Compromised site (DHL malspam campaign), leads to Upatre197695RU
2014/09/16_09:59www.advancesrl.eu/ryubfrytqb/dkdorvskxe.html62.149.142.94webx328.aruba.it.Compromised site (DHL malspam campaign), leads to Upatre31034IT
2014/09/16_09:59dimensionnail.ro/jfcwzdbvzq/ovgjelahsu.html85.10.205.164ns.gorilahosting.ro.Compromised site (DHL malspam campaign), leads to Upatre24940DE
2014/09/16_09:59okeanbg.com/vcvzwsaybm/agptgouxot.html91.215.216.21hook.icnhost.net.Compromised site (DHL malspam campaign), leads to Upatre49699BG
2014/09/16_09:59www.advancesrl.eu/tjjyeqyfjz/gmiuxfhgsb.html62.149.142.94webx328.aruba.it.Compromised site (DHL malspam campaign), leads to Upatre31034IT
2014/09/16_09:59www.advancesrl.eu/ukhclcatkr/brcybmsute.html62.149.142.94webx328.aruba.it.Compromised site (DHL malspam campaign), leads to Upatre31034IT
2014/09/16_09:59dimensionnail.ro/qydmsiazxq/fdoyqfddox.html85.10.205.164ns.gorilahosting.ro.Compromised site (DHL malspam campaign), leads to Upatre24940DE
2014/09/16_09:59dimensionnail.ro/ijaiqwgdcr/nxcubmnbyu.html85.10.205.164ns.gorilahosting.ro.Compromised site (DHL malspam campaign), leads to Upatre24940DE
2014/09/16_09:59interactivearea.ru/rcaxfhtfnu/wghvxslkiv.html37.140.192.82server51.hosting.reg.ru.Compromised site (DHL malspam campaign), leads to Upatre197695RU
2014/09/16_09:59dimensionnail.ro/zgzjgmytap/jnreistghg.html85.10.205.164ns.gorilahosting.ro.Compromised site (DHL malspam campaign), leads to Upatre24940DE
2014/09/16_09:59okeanbg.com/rjanequlla/nyxliupxyf.html91.215.216.21hook.icnhost.net.Compromised site (DHL malspam campaign), leads to Upatre49699BG
2014/09/16_09:59cosmetice-farduri.ro/puhmivlnki/gvddofpfpv.html144.76.194.178ns.icetechcopycenter.ro.Compromised site (DHL malspam campaign), leads to Upatre24940DE
2014/09/16_09:59pix360.co.nf/wisnyrdqou/ltbwattpww.html83.125.22.199-Compromised site (DHL malspam campaign), leads to Upatre13237EU
2014/09/16_09:59interactivearea.ru/qbwfmjfuui/fbtvmwobxx.html37.140.192.82server51.hosting.reg.ru.Compromised site (DHL malspam campaign), leads to Upatre197695RU
2014/09/16_09:59isonomia.com.ar/vwyryztlkn/nsxiquronl.html200.58.123.153x094vm14.isonomia.com.ar.Compromised site (DHL malspam campaign), leads to Upatre27823AR
2014/09/16_09:59cosmetice-farduri.ro/modidoogrt/gjdotmqgzx.html144.76.194.178ns.icetechcopycenter.ro.Compromised site (DHL malspam campaign), leads to Upatre24940DE
2014/09/16_09:59okeanbg.com/sshbuycplb/hbkfnidlfx.html91.215.216.21hook.icnhost.net.Compromised site (DHL malspam campaign), leads to Upatre49699BG
2014/09/16_09:59dimensionnail.ro/aqbfyipgkh/hjyxeiamcp.html85.10.205.164ns.gorilahosting.ro.Compromised site (DHL malspam campaign), leads to Upatre24940DE
2014/09/16_09:59luchtenbergdecor.com.br/gcbelfuqbk/ygjbemlcsd.js186.202.56.110CPROHWIN0190.locaweb.com.br.Compromised site (DHL malspam campaign), leads to Upatre27715BR
2014/09/10_10:42pepelacer.computingservices123.com/7b828d9fbn1vw/1/9ffbf35e4190fbba62f70c8477fa3964.html176.58.111.253li489-253.members.linode.com.exploit kit15830GB
2014/09/02_09:11alsoknowsit.com/wp-files/config.bin80.250.114.239kvm.arconet.ee.Zeus config file39038EE
2014/08/03_18:10-46.183.221.58/we/bot.exeip-221-58.dataclub.biz.Trojan.Zbot52048LV
2014/08/03_18:10-46.183.221.58/snow/bot.exeip-221-58.dataclub.biz.Trojan.Zbot52048LV
2014/07/30_23:56coalimpex.com/web/boleto2.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/boleto.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/bg-02.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/hot-venda/receita-cliente1.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/hot-venda/receita-cliente.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/hot-venda/advocacia.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/bo_03.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/pe/advocacia.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/bo_02.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/bo_01.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/hot-venda/hven_04.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/ch_01.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/hot-venda/hven_03.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/hot-venda/hven_02.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/hot-venda/hven_01.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/pe/pe_02.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/re_02.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/pe/pe_01.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/pe/ad_04.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/pe/ad_02.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/pe/ad_03.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/pe/ad_01.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/serasa/serasa_02.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56coalimpex.com/web/serasa/serasa_01.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/boleto2.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/boleto.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/bg-02.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/hot-venda/receita-cliente1.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/hot-venda/receita-cliente.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/hot-venda/advocacia.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/pe/advocacia.jpg192.3.1.250-Used by malspam to lead victims to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/bo_03.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/bo_01.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/bo_02.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/ch_01.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/hot-venda/hven_04.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/hot-venda/hven_03.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/hot-venda/hven_02.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/hot-venda/hven_01.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/re_02.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/pe/pe_02.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/pe/ad_04.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/pe/pe_01.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/pe/ad_03.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/pe/ad_02.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/pe/ad_01.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/serasa/serasa_02.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/30_23:56ministerio-publi.info/web/serasa/serasa_01.php192.3.1.250-Leads to Trojan.Banload36352US
2014/07/28_09:24-94.249.192.105/index.html-leads to ransom trojan message page12586DE
2014/07/24_12:58dentairemalin.com/images/report934875438jdfg8i45jg_07242014.exe217.16.10.2clweb01.hosteur.com.Trojan.Banker48809FR
2014/07/24_12:53mathenea.com/css/report934875438jdfg8i45jg_07242014.exe91.199.120.78mazer.h3m.com.Trojan.Banker15699ES
2014/07/24_09:31-117.21.191.47/ng15.exe-Win32/Cryptor4134CN
2014/07/24_09:31-117.21.191.47/bet15.exe-Win32/Cryptor4134CN
2014/07/24_09:31-117.21.191.47/ng.exe-W32/Slenfbot.B.gen!Eldorado4134CN
2014/07/24_09:31-117.21.191.47/beta.exe-Trojan.Ageny.ED4134CN
2014/07/24_09:31-117.21.191.47/betr7.exe-Win32/Cryptor4134CN
2014/07/24_09:31-117.21.191.47/ng2.exe-Win32/Injector.BHYG trojan4134CN
2014/07/24_09:31-117.21.191.47/ng1.exe-W32/Slenfbot.B.gen!Eldorado4134CN
2014/07/24_09:31-31.6.71.85/bet/ngr7.exehosted-by.slaskdatacenter.pl.Trojan.Krypt59491PL
2014/07/24_09:31-117.21.191.47/andr7.exe-Win32/Cryptor4134CN
2014/07/24_09:31-31.6.71.85/bet/andr7.exehosted-by.slaskdatacenter.pl.Trojan.Krypt59491PL
2014/07/24_09:31-31.6.71.85/bet/betr7.exehosted-by.slaskdatacenter.pl.Trojan.Krypt59491PL
2014/07/24_09:31-31.6.71.85/bet/zpmr7.exehosted-by.slaskdatacenter.pl.Trojan.Krypt59491PL
2014/07/23_09:27adobeflashupdate14.com/version/install_flashplayer14.0.0.145_ie.exe37.187.149.210o1.i-whost.com.fake Flash player16276FR
2014/07/15_08:58jue0jc.lukodorsai.info/dpta5n0tp2192.200.105.135192-200-105-135.static.gorillaservers.com.exploit kit53850US
2014/07/15_07:26www.m-barati.de/contao/count.php?id=421324594.101.38.14three.rr1.revido.de.leads to exploit kit16097DE
2014/07/15_07:26ylpzt.juzojossai.net/9aywse7eva192.200.105.135192-200-105-135.static.gorillaservers.com.exploit kit53850US
2014/07/11_08:26directxex.com/uploads/1738599339.ms1.exe?dl=11738599339.ms1.exe5.135.127.68-Trojan.Backdoor.Androm.Ar16276FR
2014/07/11_08:26directxex.com/uploads/2126787896.lol.exe5.135.127.68-RAR/Agent.AF16276FR
2014/07/11_03:506b8a953b2bf7788063d5-6e453f33ecbb90f11a62a5c376375af3.r71.cf5.rackcdn.com/Videos%20Player.mp4.exe64.210.100.99-Trojan.FakeAdobe3549US
2014/06/26_14:27www.cellularbeton.it/js/jquery.js213.205.40.169web-vip-it.eu.tiscali.it.JS.Exploit8612IT
2014/06/26_14:27www.frosinonewesternshow.it/fws2006/3tappa.htm213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.archigate.it/213.205.40.169web-vip-it.eu.tiscali.it.JS.Exploit8612IT
2014/06/26_14:27www.galileounaluna.com/213.205.40.169web-vip-it.eu.tiscali.it.JS.Exploit8612IT
2014/06/26_14:27www.vivaimontina.com/213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.elisaart.it/213.205.40.169web-vip-it.eu.tiscali.it.JS.Exploit8612IT
2014/06/26_14:27www.poesiadelsud.it/rende_16_05_07_saggese.htm213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.frosinonewesternshow.it/fws2013/calendario.htm213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.poesiadelsud.it/mostra_internazionale_artecont_1.htm213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.poesiadelsud.it/rende_16_05_07_napolillo.htm213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.anticarredodolomiti.com/index.html213.205.40.169web-vip-it.eu.tiscali.it.JS.Exploit8612IT
2014/06/26_14:27www.gliamicidellunicef.it/skiantos_in_concerto.htm213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.frosinonewesternshow.it/fws2011213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.frosinonewesternshow.it/fws2011/7tappa.htm213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.fotoidea.com/sport/4x4_san_ponso/slides/IMG_0068.html213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.fotoidea.com/sport/4x4_san_ponso/slides/IMG_0138.html213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.fotoidea.com/sport/4x4_san_ponso/slides/IMG_9540.html213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.fotoidea.com/sport/4x4_san_ponso/slides/IMG_0119.html213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.fotoidea.com/sport/4x4_san_ponso/slides/IMG_9597.html213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.fotoidea.com/sport/4x4_san_ponso/slides/IMG_9551.html213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.fotoidea.com/sport/4x4_san_ponso/slides/IMG_9378.html213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.fotoidea.com/sport/4x4_san_ponso/slides/IMG_9445.html213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.milardi.it/corteconti.htm213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.milardi.it/213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.frosinonewesternshow.it/fws2011/213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.bcservice.it/213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.unicaitaly.it/213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.montacarichi.it/213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.assculturaleincontri.it/213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.ristoromontebasso.it/scripts/menu.js213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.3difx.com213.205.40.169web-vip-it.eu.tiscali.it.JS.Exploit8612IT
2014/06/26_14:27www.3difx.com/serv010.html213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.chiaperottipaolo.it/213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.marinoderosas.com/213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.riccardochinnici.it/213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.eivamos.com/rimessaggio/carrelliconver.htm213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.catgallery.com/email.htm213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.vinyljazzrecords.com/japan.html213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.racingandclassic.com/pagineit/race.html213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit8612IT
2014/06/26_14:27www.sbo.it/babylon.html213.205.40.169web-vip-it.eu.tiscali.it.Script.Exploit, Embedded links leading to illegal pharma8612IT
2014/06/26_14:27nmsbaseball.com/post.php?id=14484096.0.115.64rev.opentransfer.com.64.115.0.96.in-addr.arpa.Exploit32392US
2014/06/26_14:27www.aerreravasi.com/filmestensibile/filmestensibile.htm213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.aerreravasi.com/differenziata/differenziata.html213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.aerreravasi.com/chisiamo/chisiamo.htm213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.aerreravasi.com/comeraggiungerci/comeraggiungerci.htm213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.aerreravasi.com/bolle/bolle.html213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/26_14:27www.aerreravasi.com213.205.40.169web-vip-it.eu.tiscali.it.iFrame.Exploit8612IT
2014/06/22_16:25-198.15.67.177/D63A5E3246A.jpg-Trojan.Zbot20454US
2014/06/22_16:25-95.154.228.163/1/bot.exe-Trojan.Zbot20860GB
2014/05/27_04:02www.sankyo.gr.jp/Pagamento.zip?mscfopoysckwdh202.224.60.77www.sankyo.gr.jp.Trojan.Zbot4685JP
2014/05/27_04:02www.sankyo.gr.jp/Pagamento.zip202.224.60.77www.sankyo.gr.jp.Trojan.Extension.Exploit4685JP
2014/05/27_04:02www.sankyo.gr.jp/Pagamento.zip?IIFEhTaalZlzYipWok202.224.60.77www.sankyo.gr.jp.Trojan.Zbot4685JP
2014/05/27_04:02www.rokus-tgy.hu/Pagamento.zip?IdjJzMrNmz195.70.32.145virtweb2.interware.hu.Trojan.Zbot5588HU
2014/05/27_04:02www.rokus-tgy.hu/Pagamento.zip195.70.32.145virtweb2.interware.hu.Trojan.Extension.Exploit5588HU
2014/05/27_04:02www.flowtec.com.br/vcard/Informazioni.zip200.195.192.45jurere.onda.com.br.Trojan.Zbot12140BR
2014/05/27_04:02www.flowtec.com.br/vcard/Informazioni.zip200.195.192.45jurere.onda.com.br.Trojan.Extension.Exploit12140BR
2014/05/27_04:02www.fabioalbini.com/Pay.zip195.110.150.4net150-004.mclink.it.Trojan.Extension.Exploit5396IT
2014/05/27_04:02www.fabioalbini.com/Order.zip195.110.150.4net150-004.mclink.it.Trojan.Extension.Exploit5396IT
2014/05/27_04:02www.fabioalbini.com/Pay.zip?2bMxG=heidi.kostic@aon.at195.110.150.4net150-004.mclink.it.Trojan.Zbot5396IT
2014/05/27_04:02www.fabioalbini.com/Pay.zip?2bMxG=heidi.kostic195.110.150.4net150-004.mclink.it.Trojan.Zbot5396IT
2014/05/27_04:02www.fabioalbini.com/Order.zip?YIjoBgGhCBbs195.110.150.4net150-004.mclink.it.Trojan.Zbot5396IT
2014/05/27_04:02www.fabioalbini.com/Order.zip?snaVs8Hxk1UBauZlc5pQcGW7195.110.150.4net150-004.mclink.it.Trojan.Zbot5396IT
2014/05/27_04:02www.emrlogistics.com/fr/to2.exe103.14.120.121103.14.120.121-static-reverse.gooddomainregistry.com.Trojan.Inject132322IN
2014/05/27_04:02www.cortesidesign.com/Avviso.zip213.205.40.169web-vip-it.eu.tiscali.it.Trojan.Zbot8612IT
2014/05/27_04:02www.cortesidesign.com/Avviso.zip213.205.40.169web-vip-it.eu.tiscali.it.Trojan.Inject8612IT
2014/05/27_04:02www.atousoft.com/img/2.exe88.190.253.247pf7-web.online.net.Spyware.Zbot.VXGen12322FR
2014/05/27_04:02www.arkinsoftware.in/images/aveksynkens.exe216.151.164.53shared-hosting.njtech.com.Spyware.Zbot.ED7393US
2014/05/27_04:02writingassociates.com/img/lks.exe205.186.183.232ekiaioocio.gs07.gridserver.com.Trojan.Agent.ED31815US
2014/05/27_04:02vmay.com/wordpress/wp-content/themes/twentytwelve/foot/185.exe175.182.230.91175-182-230-91.adsl.dynamic.seed.net.tw.Spyware.Password4780TW
2014/05/27_04:02troytempest.com/DHLDocument.zip217.160.115.88kundenserver.de.Trojan.Email.Gen8560DE
2014/05/27_04:02villalecchi.com/images/min/b41.exe209.51.141.123www.villalecchi.com.Trojan.Inject3595US
2014/05/27_04:02troytempest.com/DHLDocument.zip217.160.115.88kundenserver.de.Trojan.Zbot8560DE
2014/05/27_04:02sasson-cpa.co.il/Progetto.zip?iWPpEOb194.90.8.20as.netvision.net.il.Trojan.Zbot1680IL
2014/05/27_04:02sasson-cpa.co.il/Progetto.zip194.90.8.20as.netvision.net.il.Trojan.Extension.Exploit1680IL
2014/05/27_04:02rainbowcolours.me.uk/z14.exe46.30.212.183-Trojan.Zbot51468DK
2014/05/27_04:02rainbowcolours.me.uk/hp.exe46.30.212.183-Spyware.Zbot51468DK
2014/05/27_04:02rainbowcolours.me.uk/g17.exe46.30.212.183-Trojan.Zbot.RPE51468DK
2014/05/27_04:02optiker-michelmann.de/eoewdksna81.169.145.155w9b.rzone.de.Spyware.ZeuS.GO6724DE
2014/05/27_04:02progettocrea.org/wp-content/themes/telekom/telekom_deutschland_gmbh109.168.109.228board02.windows.kolst.it.Trojan.Email.FakeDoc5602IT
2014/05/27_04:02ns1.the-sinner.net/modules/webstat/vodafone_service_d289.169.174.218-Trojan.Email.FakeDoc31514RU
2014/05/27_04:02nkgamers.com/swazi/banalities.exe173.254.28.89just89.justhost.com.Spyware.ZeuS.GO46606US
2014/05/27_04:02neumashop.cl/bmfbnoou190.98.227.154gtd154.dch.cl.Spyware.ZeuS.GO14259CL
2014/05/27_04:02nctbonline.co.uk/InvoiceCopy.scr37.9.169.15lb-proxy-13.websupport.sk.Trojan.Zbot51013SK
2014/05/27_04:02ms11.net/%7Ecarmine/DHL%20Document.zip108.168.210.189ms11.net.Trojan.Zbot36351US
2014/05/27_04:02mediatrade.h19.ru/Our89.108.91.183double6.holm.ru.Produce Items.scr Trojan.Email.FakeDoc43146RU
2014/05/27_04:02mahindrainsurance.com/Informazioni/risposta_info_1103.zip203.123.178.30piin178030.pacific.net.in.Trojan.Extension.Exploit9625IN
2014/05/27_04:02mahindrainsurance.com/Informazioni/mail_info_11032014.zip203.123.178.30piin178030.pacific.net.in.Trojan.Extension.Exploit9625IN
2014/05/27_04:02mahindrainsurance.com/Informazioni/Conferma.zip203.123.178.30piin178030.pacific.net.in.Trojan.Extension.Exploit9625IN
2014/05/27_04:02mahindrainsurance.com/info/Mail_Info_11032014.zip203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/info/conferma.zip203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/Download_Risposta/Risposta.zip203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/Download_Risposta/Mail_Info_11032014.zip203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/download_doc/Risposta_Info_1103.zip203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/download_doc/risposta.zip203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/informazioni/risposta_info_1103.zip?david.cozens+at+martindale.com_rdynpk7uwzi203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/informazioni/risposta_info_1103.zip?david.cozens%20at%20martindale.com_rdynpk7uwzi203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/informazioni/risposta_info_1103.zip?david.cozens203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/informazioni/risposta_info_1103.zip?abstracts%20at%20ages.com.au_yzoxmlfe0f203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/informazioni/mail_info_11032014.zip?selene-68b%20at%20libero.it203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/Informazioni/Conferma.zip?aannuzzo574@libero.it203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/info/mail_info_11032014.zip?lerchc@kliniken-koeln.de_yex86uhg203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/info/mail_info_11032014.zip?itas00@virgilio.it_skwsq203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/info/mail_info_11032014.zip?itas00203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/Info/Mail_Info_11032014.zip?58311xaNf5r7s203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/info/mail_info_11032014.zip?2472316zzqa1knqcgu203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/Info/Mail_Info_11032014.zip?11870953rILDR203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/Info/Mail_Info_11032014.zip?02127pOiaw5LoQ203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/info/conferma.zip?michele.armaniniatlibero.it_uubafwuh203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/Download_Risposta/Risposta.zip?9949971rMqgj20wKB203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/download_risposta/mail_info_11032014.zip?90460199329lkggbup0203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/Download_Risposta/Mail_Info_11032014.zip?15844470966vrURcZ203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/download_doc/risposta_info_1103.zip?dbspa3@actaliscertymail.it_i8dqtqvi203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/Download_Doc/Risposta_Info_1103.zip?dbspa3@actaliscertymail.it_I8d203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/Download_Doc/Risposta_Info_1103.zip?cinziofarinelli@libero.it_7pzc6tde203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/download_doc/risposta_info_1103.zip?cinziofarinelli@libero.it203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/download_doc/risposta.zip?fernando.zellettaatalice.it_ftowwc203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/download_doc/risposta.zip?fernando.zelletta@alice.it_ftowwc203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02mahindrainsurance.com/download_doc/risposta.zip?fernando.zelletta@alice.it203.123.178.30piin178030.pacific.net.in.Trojan.Zbot9625IN
2014/05/27_04:02innatek.com/ListinoPrezzi.zip63.111.67.9ns3.actwd.net.Trojan.Extension.Exploit11486US
2014/05/27_04:02innatek.com/ListinoPrezzi.zip?SEmfjmWrPDXEz63.111.67.9ns3.actwd.net.Trojan.Zbot11486US
2014/05/27_04:02hobbat.fvds.ru/DHL%20Document.zip82.146.42.130hobbat.fvds.ru.Trojan.Zbot29182RU
2014/05/27_04:02hobbat.fvds.ru/DHL82.146.42.130hobbat.fvds.ru.Document.zip Trojan.Email.Gen29182RU
2014/05/27_04:02hnskorea.co.kr/alberta/dingo.exe203.242.210.105exp1.ecplaza.net.Trojan.Agent.ED7557KR
2014/05/27_04:02grendizer.biz/statistiche/fattura05032014.zip85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02gulf-industrial.com/images/2103USa.qta91.103.216.110secure.dfsv66.com.Trojan.Downloader29550GB
2014/05/27_04:02grendizer.biz/ordine/info.zip85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/ordine/fattura05032014.zip85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/Informazioni/statistiche.zip85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/Informazioni/ordine4582923332.zip85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/Informazioni/Fattura05032014.zip85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/Informazioni/Info.zip85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/fattura/statistiche.zip85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/fattura/ordine4582923332.zip85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/fattura/fattura05032014.zip85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/statistiche/fattura05032014.zip?qgbaprb3jqghxxof85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/ordine/info.zip?phmtllqsewlgejrea3r_emanuele.monfriniatfastwebnet.it85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/ordine/info.zip?phmtllqsewlgejrea3r_emanuele.monfrini+at+fastwebnet.it85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/ordine/info.zip?phmtllqsewlgejrea3r_emanuele.monfrini%20at%20fastwebnet.it85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/ordine/info.zip?phmtllqsewlgejre=85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/ordine/fattura05032014.zip?xx0frhnydqgzvzfzugbs5xm85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/ordine/fattura05032014.zip?uiukcav35d85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/informazioni/statistiche.zip?vfw=85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/informazioni/statistiche.zip?vfww8lyfaiccpr_elke.staiger+at+fdp.landtag-bw.de85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/informazioni/ordine4582923332.zip?boweipzoa374cr_info@bikesplaza.nl85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/Informazioni/Info.zip?17kDYCBNi6t85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/Informazioni/Fattura05032014.zip?zav6BNgeGvW89WPVOQlRX85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/fattura/statistiche.zip?l7ucqay9bgq6i6sk85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/fattura/ordine4582923332.zip?vybhzpsoxzapz0xdt85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/fattura/fattura05032014.zip?jwui91zljfn85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/fattura/fattura05032014.zip?dzmooxysgf3yt6ju2ehhm85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02grendizer.biz/fattura/fattura05032014.zip?9hq3vacty6ggvex85.235.154.18mwin05.masterweb.it.Trojan.Zbot31034IT
2014/05/27_04:02go-quicky.com/admin_old_dev/css/1504USd.exe162.210.70.39162.210.70-39.confluence-networks.com.Spyware.Zbot40034VG
2014/05/27_04:02dougmlee.com/DHL50.21.187.135s15569399.onlinehome-server.com.Document.zip Trojan.Email.Gen8560US
2014/05/27_04:02directxex.com/uploads/919691940.p-update.exe5.135.127.68-Spyware.Zbot16276FR
2014/05/27_04:02dougmlee.com/DHL%20Document.zip50.21.187.135s15569399.onlinehome-server.com.Trojan.Zbot8560US
2014/05/27_04:02directxex.com/uploads/610411940.save.exe5.135.127.68-Spyware.Zbot16276FR
2014/05/27_04:02directxex.com/uploads/535825339.androm.exe5.135.127.68-Spyware.Zbot16276FR
2014/05/27_04:02directxex.com/uploads/2139980916.S4_Crack.exe5.135.127.68-Spyware.Zbot16276FR
2014/05/27_04:02directxex.com/uploads/42238721.Amazon5.135.127.68-Rechnungs Tool.exe Backdoor.Bot16276FR
2014/05/27_04:02directxex.com/uploads/2050276296.scan0001.exe5.135.127.68-Spyware.Zbot16276FR
2014/05/27_04:02directxex.com/uploads/1627320498.runerr.exe5.135.127.68-Spyware.Zbot16276FR
2014/05/27_04:02directxex.com/uploads/164923136.cpu.exe5.135.127.68-Spyware.Zbot16276FR
2014/05/27_04:02directxex.com/uploads/1257844607.encrcyper.exe5.135.127.68-Spyware.Zbot16276FR
2014/05/27_04:02directxex.com/uploads/1149332910.Host2_crypter_05.exe5.135.127.68-Spyware.Zbot16276FR
2014/05/27_04:02destre45.com/p/svhost.exe193.203.50.51-Trojan.Agent.ED48031UA
2014/05/27_04:02directxex.com/uploads/100312839.CryptocurrencyTradingBotV1.4.exe5.135.127.68-Spyware.Zbot16276FR
2014/05/27_04:02destre45.com/p/f.exe193.203.50.51-Trojan.Agent.ED48031UA
2014/05/27_04:02demo.vertexinfo.in/conclusione/dettagli.zip109.203.112.170-Trojan.Extension.Exploit29550GB
2014/05/27_04:02demo.vertexinfo.in/conclusione/dettagli.zip?formazione@feldenkrais.it109.203.112.170-Trojan.Zbot29550GB
2014/05/27_04:02demo.vertexinfo.in/conclusione/dettagli.zip?formazione%20at%20feldenkrais.it109.203.112.170-Trojan.Zbot29550GB
2014/05/27_04:02decrolyschool.be/backup/1_1_777.exe217.21.184.230linweb003.webhosting.be.Trojan.Agent.ED34762BE
2014/05/27_04:02decografix.com/wp-content/uploads/2014/03/b41.exe184.172.57.26184.172.57.26-static.reverse.softlayer.com.Trojan.Inject36351US
2014/05/27_04:02csmail.iggcn.com/temp/service_mail/attachments/2014/03/11/2014031105343091111.zip66.171.200.210-Trojan.Downloader.RRE55034US
2014/05/27_04:02cope.it/templates/webstat/finanzgruppe_volksbanken_ne/index65.98.23.91-at cope.it-templates-webstat-finanzgruppe_volksbanken_ne.htm Trojan.Email.FakeDoc25653US
2014/05/27_04:02csmail.iggcn.com/temp/service_mail/attachments/2014/03/11/2014031105343091111.zip66.171.200.210-Trojan.Zbot55034US
2014/05/27_04:02classicspeedway.com/ff.exe116.0.23.229hiruko.instanthosting.com.au.Trojan.Zbot9280AU
2014/05/27_04:02centralwestwater.com.au/Estratto/Dati.zip103.4.16.91whs.clientdns.com.Trojan.Extension.Exploit58940AU
2014/05/27_04:02centralwestwater.com.au/Dettagli_Fatture.zip103.4.16.91whs.clientdns.com.Trojan.Extension.Exploit58940AU
2014/05/27_04:02centralwestwater.com.au/Conto.zip103.4.16.91whs.clientdns.com.Trojan.Extension.Exploit58940AU
2014/05/27_04:02centralwestwater.com.au/Estratto/Dati.zip103.4.16.91whs.clientdns.com.Trojan.Zbot58940AU
2014/05/27_04:02centralwestwater.com.au/Dettagli_Fatture.zip?aladinodepaulis@uniadriatica.it103.4.16.91whs.clientdns.com.Trojan.Zbot58940AU
2014/05/27_04:02centralwestwater.com.au/Conto.zip?gZ5lXOdeRY7y103.4.16.91whs.clientdns.com.Trojan.Zbot58940AU
2014/05/27_04:02americancareconcept.com/modules/webstat/rechnungonline_telekom_rt/2014_05_rechnungonline_8290155236sign.zip198.98.102.215215.0-24.102.98.198.in-addr.arpa.Trojan.Email.FakeDoc18978US
2014/05/27_04:02americancareconcept.com/modules/webstat/rechnungonline_telekom_rt/2014_05_rechnungonline_8290155236sign.zip198.98.102.215215.0-24.102.98.198.in-addr.arpa.Trojan.Zbot18978US
2014/05/27_04:02amazingvacationhotels.com/wp-content/themes/HotelWeb2/connect/mac.exe192.186.200.130ip-192-186-200-130.ip.secureserver.net.Trojan.Ransom.ED26496US
2014/05/27_04:02-209.35.37.129/schuld/schuld.zipdhwhiterealestate.com.Trojan.Extension.Exploit11305US
2014/05/27_04:02-209.35.37.129/schuld/schuld.zip?schuld-pdf=96498320212=areyphv@fag.dedhwhiterealestate.com.Trojan.Zbot11305US
2014/05/27_04:02-209.35.37.129/schuld/schuld.zip?schuld-pdf=96498320212=areyphv+at+fag.de%2Fdhwhiterealestate.com.Trojan.Zbot11305US
2014/05/27_04:02-185.38.249.242/b7.exen249h242.rev.sprintdatacenter.pl.Worm.Autorun197226PL
2014/05/27_04:02-185.38.249.242/b9.exen249h242.rev.sprintdatacenter.pl.Worm.Autorun197226PL
2014/05/27_04:02-185.38.249.242/b2.exen249h242.rev.sprintdatacenter.pl.Worm.Autorun197226PL
2014/05/27_04:02-185.38.249.242/b5.exen249h242.rev.sprintdatacenter.pl.Worm.Autorun197226PL
2014/05/27_04:02-185.38.249.242/a14.exen249h242.rev.sprintdatacenter.pl.Worm.Autorun197226PL
2014/05/27_04:02-185.38.249.242/a5.exen249h242.rev.sprintdatacenter.pl.Worm.Autorun197226PL
2014/05/27_04:02-111.26.23.2/11.exe-Trojan.Agent9808CN
2014/05/27_04:02-115.146.2.58/pqosepgfbswqxx58.secure.ne.jp.Spyware.ZeuS.GO9597JP
2014/05/27_04:02-185.38.249.242/a13.exen249h242.rev.sprintdatacenter.pl.Worm.Autorun197226PL
2014/05/12_19:03-62.76.43.78/p2p/PP_detalis_726716942049.pdf.exe62-76-43-78.clodo.ru.Trojan.Zbot48172RU
2014/05/12_00:24iwgtest.co.uk/homezinctech/wp-admin/main/adobe_flash.exe69.28.199.1069.28.199.10.hostpapa.com.Spyware.Zbot.ED13768US
2014/05/12_00:24kadirzerey.com/wp-content/themes/genegri/file.ecr31.169.73.112server98.tr73.dhs.com.tr.Trojan.ZeuS56582TR
2014/05/12_00:24murbil.hostei.com/wp-content/themes/Mizzo/file.ecr31.170.160.249-Trojan.ZeuS47583US
2014/05/12_00:24rentfromart.com/media/system/images/Java.exe72.167.149.183ip-72-167-149-183.ip.secureserver.net.Trojan.Agent26496US
2014/05/12_00:24tcrwharen.homepage.t-online.de/1180.150.6.138b2c.t-online.de.Spyware.ZeuS3320DE
2014/05/12_00:24uploads.tmweb.ru/sFAAd3uEW9.exe92.53.118.140ultra.timeweb.ru.Trojan.Zbot9123RU
2014/05/12_00:24strangeduckfilms.com/22272.34.42.5versace.livingdot.com.Trojan.Crypt.NKN33494US
2014/05/12_00:24citymediamagazin.hu/spacey/egress87.229.77.23webszerver.autofejlesztes.hu.Spyware.ZeuS61998HU
2014/05/12_00:24www.freemao.com/pics/file.ecr195.110.150.4net150-004.mclink.it.Spyware.ZeuS.GO5396IT
2014/05/12_00:24citymediamagazin.hu/poniards/figurine87.229.77.23webszerver.autofejlesztes.hu.Spyware.ZeuS61998HU
2014/05/12_00:24-181.50.248.15/webalizer/webstate/files/soft.exeStatic-IP-18150024815.cable.net.co.Trojan.Zbot10620CO
2014/05/12_00:24-185.38.249.242/pl.exen249h242.rev.sprintdatacenter.pl.Worm.Autorun197226PL
2014/05/12_00:24allforlove.de/11217.13.199.48www28.prosite.de.Spyware.Zbot.ED15657DE
2014/05/12_00:24adlock.in/download/371815/file.exe192.254.137.131adl.adlock.in.PUP.Optional.FileServer.A46606US
2014/05/12_00:24akirkpatrick.com/1181.27.85.16zeus7.easy-internet.co.uk.Spyware.Zbot.ED25577GB
2014/05/12_00:24alexanderinteriorsanddesign.com/errant/topics162.144.87.156server.alexanderinteriorsanddesign.com.Spyware.ZeuS46606US
2014/05/12_00:24arkinsoftware.in/images/nukotobne.exe216.151.164.53shared-hosting.njtech.com.Trojan.Agent.FSAVXGen7393US
2014/05/12_00:24arkinsoftware.in/images/inexsabit.exe216.151.164.53shared-hosting.njtech.com.Trojan.Inject.ED7393US
2014/05/12_00:24arkinsoftware.in/images/aveksynkens.exe216.151.164.53shared-hosting.njtech.com.Trojan.Zbot7393US
2014/05/12_00:24beespace.com.ua/hook/hookkey.exe91.222.136.251web123.ukraine.com.ua.Trojan.Agent47781UA
2014/05/12_00:24classicallyabsurdphotography.com/bunked/tinning184.168.236.1p3nlhg136c1136.shr.prod.phx3.secureserver.net.Spyware.ZeuS26496US
2014/05/09_15:10sadiqtv.com/111162.253.151.131stats.salmon.arvixe.com.Trojan.Zeus.GameOver36351US
2014/05/09_15:10rallyeair.com/11182.102.6.32ns2.webhs.org.Trojan.Zeus.GameOver25137PT
2014/05/09_15:10nbook.far.ru/111195.16.42.37far.ru.freehosting.centre.ru.Trojan.Zeus.GameOver3216RU
2014/05/09_15:10pgalvaoteles.pt/11182.102.5.201hosting27.serverhs.org.Trojan.Zeus.GameOver25137PT
2014/05/09_15:10lefos.net/11146.4.120.118eu3.1host.gr.Trojan.Zeus.GameOver24940DE
2014/05/09_15:10gogetgorgeous.com/111103.19.89.55cloud1.labelhosting.com.Trojan.Zeus.GameOver132717IN
2014/05/09_15:10decota.es/111134.0.14.18-Trojan.Zeus.GameOver197712ES
2014/05/09_15:10beautysafari.com/111209.159.189.43virtualmin1.vaxxine.com.Trojan.Zeus.GameOver11181CA
2014/05/09_15:10axisbuild.com/11162.233.121.75origin.easyspace.com.Trojan.Zeus.GameOver20860GB
2014/05/01_00:23ocpersian.com74.208.21.148-Android.Trojan.SMSStealer8560US
2014/04/29_08:25www.marss.eu/95.110.133.212host212-133-110-95.serverdedicati.aruba.it.obfuscated Javascript leads to fake flash player site31034IT
2014/04/27_12:36-94.242.225.240/download/34/VUBSXlcUUk9ITQQQbyctMScgNWkuKDk/YSAnPX4jJ3wzMCIIMio1NWMuKj1dUEQHDQFbUF9bXVxZXVlXVhcbHxEqHxNFDR21Og/anzhelika_varum_-_lyalyafa_zaycev_net.exe?packip-static-94-242-225-240.as5577.net.Win32/Kryptik.BZSH.Gen5577LU
2014/04/27_12:36-94.242.225.240/download/05/ZHNjYWYnY3h5fjU/PnR8ZnZzZDZ/e2hoMHN2Ug9QVgtCQ1N3Q1lEQhJdW1IMAxVQXFIKDw4IDAUNCgl2ZyQqKCAZLix0DR3GIA/voskresenie_-_muzykant_zaycev_net.exe?packip-static-94-242-225-240.as5577.net.Win32/Kryptik.BZSH.Gen5577LU
2014/04/27_12:36-94.242.225.240/download/ab/ytnJx8Cd2cbHxIZmN7WyNjZzpDZobK27qmstOm6vOWsqbmRpaOvOynobTq6fsrjg6ejS1tPa0NLUwY6Aho6zhIrSDR12BA/serebro_-_skazhi_ne_molchi_zaycev_net.exe?packip-static-94-242-225-240.as5577.net.Win32/Kryptik.BZSH.Gen5577LU
2014/04/27_12:36-94.242.225.240/download/3a/W05YVFESKDU2M35qaSEnOykuP2MoLiMlfz49J3glLXY9PigCNCwPD10QEAdbVk4NAw9RWlldR0lCRUFHUBERFR8kFRlDDR27YA/voskresenie_-_kto_vinovat_zaycev_net.exe?packip-static-94-242-225-240.as5577.net.Win32/Kryptik.BZSH.Gen5577LU
2014/04/27_12:36-94.242.225.240/download/3a/W05YVFESKDU2M35qaSEnOykuP2MoLiMlfz49J3glLXY9PigCNCwPD10QEAdbVk4NAw9RWlldR0lCS0dFUBERFR8kFRlDDR27YA/voskresenie_-_kto_vinovat_zaycev_net.exe?packip-static-94-242-225-240.as5577.net.Win32/Kryptik.BZSH.Gen5577LU
2014/04/27_12:36-94.242.225.240/download/e5/hJODgYbHg5iZntXf3pSchpaThNafm4iI0JOWci9wditiY3NXY3lkYjJ9e3IsIzVwfHIqLy4oLCQpLCsUB0RKSEB5TkwUDR2/YA/voskresenie_-_po_doroge_razocharovaniy_zaycev_net.exe?packip-static-94-242-225-240.as5577.net.Win32/Kryptik.BZSH.Gen5577LU
2014/04/27_12:36powershopnet.net82.194.66.169vlc-143.dns-servicios.com.Exploit16371ES
2014/04/27_12:36best100catfights.com216.87.173.52flamingowrestling.com.Exploit30217US
2014/04/27_12:36blackfalcon5.net216.87.173.52flamingowrestling.com.Exploit30217US
2014/04/27_12:36dancecourt.com216.87.173.52flamingowrestling.com.Exploit30217US
2014/04/27_12:36femalewrestlingnow.com216.87.173.52flamingowrestling.com.Exploit30217US
2014/04/27_12:36fetishfitnessbabes.com216.87.173.52flamingowrestling.com.Exploit30217US
2014/04/27_12:36fetishlocator.com216.87.173.52flamingowrestling.com.Exploit30217US
2014/04/27_12:36hotfacesitting.com216.87.173.52flamingowrestling.com.Exploit30217US
2014/04/27_12:36jeansvixens.com216.87.173.52flamingowrestling.com.Exploit30217US
2014/04/27_12:36oilwrestlingeurope.com216.87.173.52flamingowrestling.com.Exploit30217US
2014/04/27_12:36sexyoilwrestling.com216.87.173.52flamingowrestling.com.Exploit30217US
2014/04/11_11:48m2132.ehgaugysd.net/zyso.cgi?1866.96.223.209-leads to exploit kit21788US
2014/04/09_07:44id405441215-8305493831.h121h9.com/146.185.235.8-Browser Ransomware15626RU
2014/04/07_18:32-193.218.144.3/cp/login/-Gozi control panel197252UA
2014/04/06_04:49img001.com/business/qiji.exe36.250.3.247-Trojan.Spy4837CN
2014/04/06_04:49oprahsearch.com/scripts/net19.exe192.249.59.79-Trojan.Inject3842US
2014/04/06_04:49oprahsearch.com/scripts/brez251.exe192.249.59.79--3842US
2014/04/02_17:58rl8vd.kikul.com/ci7ka5t2ue173.212.223.250ooo.177ok.ru.exploit kit21788US
2014/04/02_08:53www.gmcjjh.org/DHL198.252.70.200stats.green.mysitehosted.com.Document.zip Trojan.Kryptic36351US
2014/04/02_08:53incoctel.cl/8RHFBgK4.php?html=27190.114.252.75server0126-0711.dnsmisitio.net.Drive-by52368CL
2014/04/02_08:53incoctel.cl/8RHFBgK4.php?id=23694557190.114.252.75server0126-0711.dnsmisitio.net.Drive-by52368CL
2014/03/31_11:44-5.135.43.43/adm/documentos.zip-Trojan.Banker16276FR
2014/03/31_11:44-185.12.14.208/tmp/Boleto_Vencido.zip-Trojan.Banker50673NL
2014/03/31_11:44-185.12.14.208/adm/documentos.zip-Trojan.Banker50673NL
2014/03/23_10:15aintdoinshit.com/74.220.207.85host85.hostmonster.com.Backdoor.IRCBot46606US
2014/03/23_10:15metrocuadro.com.ve/coolest/2013googledocs/66.111.47.8cinaruco.tepuyserver.net.Backdoor.IRCBot21840US
2014/03/23_10:15www.petpleasers.ca/templates/rhuk_milkyway/images/red/sll.exe66.49.201.136-Trojan.Dropper33139CA
2014/03/23_10:15-203.172.131.99/personal/?name=download&file=readdownload&id=8-VBScript.Drive-by, Backdoor.IRCBot23974TH
2014/03/23_10:15-203.172.131.99/personal/?name=download&file=readdownload&id=9-VBScript.Drive-by, Backdoor.IRCBot23974TH
2014/03/23_10:15-203.172.131.99/personal/?name=download&file=readdownload&id=6-VBScript.Drive-by, Backdoor.IRCBot23974TH
2014/03/23_10:15-203.172.131.99/personal/?name=download&file=readdownload&id=7-VBScript.Drive-by, Backdoor.IRCBot23974TH
2014/03/23_10:15-203.172.131.99/personal/?name=download&file=readdownload&id=5-VBScript.Drive-by, Backdoor.IRCBot23974TH
2014/03/23_10:15-203.172.131.99/personal/?name=download&file=readdownload&id=3-VBScript.Drive-by, Backdoor.IRCBot23974TH
2014/03/23_10:15-203.172.131.99/personal/?name=download&file=readdownload&id=4-VBScript.Drive-by, Backdoor.IRCBot23974TH
2014/03/23_10:15-203.172.131.99/personal/?name=download&file=readdownload&id=12-VBScript.Drive-by, Backdoor.IRCBot23974TH
2014/03/23_10:15-203.172.131.99/personal/?name=download&file=readdownload&id=11-VBScript.Drive-by, Backdoor.IRCBot23974TH
2014/03/23_10:15-203.172.131.99/personal/?name=download&file=readdownload&id=10-VBScript.Drive-by, Backdoor.IRCBot23974TH
2014/03/21_13:13zjjlf.croukwexdbyerr.net/zyso.cgi?1666.96.195.4966-96-195-49.static.hostnoc.net.redirects to exploit kit21788US
2014/03/21_13:13kids-fashion.dk/browser.php?copy=9763&common-prop=0&edit=094.231.107.252linux20.unoeuro.com.exploit kit48854DK
2014/03/21_11:24doktester.orgfree.com/styles/jrtXnMPq.php?html=27144.76.99.221users.orgfree.hosting.free.leads to fake flashplayer installer at OneDrive24940DE
2014/03/21_09:24www.two-of-us.at/images/W.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/vein.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/s4x.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/s2x.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/s2.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/m.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/digitalcoinminer.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/dgc4x.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/dc.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/bz.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/BR.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/aurcoinlab.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/au4x.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/1.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/pictures.php85.158.181.11server143-han.de-nserver.de.PHP.Shell34432DE
2014/03/21_09:24www.two-of-us.at/images/4x.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/2.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/youtube/d/flashplayer.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/3.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/777.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/au.exe85.158.181.11server143-han.de-nserver.de.Trojan.FakeFlash34432DE
2014/03/21_09:24www.two-of-us.at/images/youtube/d/flashplayer.html85.158.181.11server143-han.de-nserver.de.Mal.FakeFlash34432DE
2014/03/20_18:19instruminahui.edu.ec/201403/editor.html74.207.242.230host.saaslibre.info.exploit kit6939US
2014/03/13_18:46milleniumpapelaria.com.br/tag/class/editor.php?edit=gz192.185.213.84-exploit kit20013US
2014/03/13_12:51dev.wrathofshadows.net/255163377.htm98.131.229.2rev.opentransfer.com.2.229.131.98.in-addr.arpa.exploit kit32392US
2014/03/11_22:39www.0uk.net/zaaqw/Pony.exe178.211.53.17server-178.211.53.17.as42926.net.Trojan.Pony42926TR
2014/03/11_22:39www.0uk.net/zaaqw/cs.exe178.211.53.17server-178.211.53.17.as42926.net.Trojan.Pony42926TR
2014/03/11_22:39ukonline.hc0.me/new.exe5.135.127.68-Win32/Injector.Autoit.ABQ trojan16276FR
2014/03/11_22:39ukonline.hc0.me/Host.exe5.135.127.68-Win32/Spy.Agent.NYU trojan16276FR
2014/03/11_22:39somethingnice.hc0.me/Miner/CPUMiner.files5.135.127.68-Trojan.PlasmaRAT.Miner16276FR
2014/03/11_22:39directxex.com/uploads/965775728.crypt.exe108.162.199.96-Win32/Spy.Zbot.AAQ trojan13335US
2014/03/11_22:39directxex.com/uploads/813441197.ms.exe?dl=1813441197.ms.exe108.162.199.96-Backdoor.Win32.Androm.bwzj13335US
2014/03/11_22:39directxex.com/uploads/565785830.been.exe108.162.199.96-MSIL/Injector.CSR trojan13335US
2014/03/11_22:39directxex.com/uploads/482862824.kmahard.exe108.162.198.96-MSIL/Injector.CUX trojan13335US
2014/03/11_22:39directxex.com/uploads/472678730.2113899106.puttymanager.exe108.162.198.96-Win32/TrojanDropper.VB.OJG trojan13335US
2014/03/11_22:39directxex.com/uploads/39164388.ms.exe?dl=1108.162.198.96-Win32/Injector.AYKD trojan13335US
2014/03/11_22:39directxex.com/uploads/341043287.crypted.exe108.162.198.96-Win32/Injector.AYNZ trojan13335US
2014/03/11_22:39directxex.com/uploads/2056064399.ms.exe108.162.198.96-Backdoor.Win32.Androm.bwzj13335US
2014/03/11_22:39directxex.com/uploads/1870347935.http.exe108.162.198.96-MSIL/Injector.CSR trojan13335US
2014/03/11_22:39directxex.com/uploads/1835173533.ms.exe?dl=11835173533.ms.exe108.162.198.96-Backdoor.Win32.Androm.bwzj13335US
2014/03/11_22:39directxex.com/uploads/1803412028.mintt.exe108.162.199.96-Win32/Injector.AYNZ trojan13335US
2014/03/11_22:39directxex.com/uploads/1491944748.whaat.exe108.162.199.96-Gen:Variant.Strictor.5173613335US
2014/03/11_22:39directxex.com/uploads/1599687595.ms.exe?dl=11599687595.ms.exe108.162.199.96-Backdoor.Win32.Androm.bwzj13335US
2014/03/11_22:39directxex.com/uploads/1271351103.ms.exe?dl=1108.162.199.96-Backdoor.Win32.Androm.bwzj13335US
2014/03/11_22:39directxex.com/uploads/1271351103.ms.exe108.162.199.96-Backdoor.Win32.Androm.bwzj13335US
2014/03/11_22:39directxex.com/uploads/1005443056.cryptedserver.exe108.162.198.96-Win32/TrojanDropper.VB.OJG trojan13335US
2014/03/11_22:39ukonline.hc0.me/Host.exe5.135.127.68-DR/AutoIt.Gen216276FR
2014/03/11_22:39ukonline.hc0.me/new.exe5.135.127.68-DR/AutoIt.Gen216276FR
2014/03/11_22:39directxex.com/uploads/1835173533.ms.exe?dl=1108.162.198.96-Backdoor.Win32.Androm.bwzj13335US
2014/03/11_22:39directxex.com/uploads/1835173533.ms.exe108.162.199.96-Backdoor.Win32.Androm.bwzj13335US
2014/03/11_22:39directxex.com/uploads/1406101817.Server.exe108.162.199.96-MSIL/Bladabindi.F trojan13335US
2014/03/11_22:39directxex.com/uploads/1144786436.be.exe108.162.199.96-Gen:Variant.Symmi.3518613335US
2014/03/11_22:39directxex.com/uploads/1010343014.server12345.exe108.162.198.96-Win32/Injector.AYMT trojan13335US
2014/03/11_22:39directxex.com/uploads/1021119574.C-Chrome.exe108.162.199.96-Win32/Injector.AYKD trojan13335US
2014/03/11_22:39directxex.com/uploads/1010343014.server12345.exe108.162.199.96-Generic Malware13335US
2014/03/11_22:39mylondon.hc0.me/Panel/5.135.127.68-Solar EK16276FR
2014/03/11_22:39somethingnice.hc0.me/login.php5.135.127.68-PlasmaRAT ACP16276FR
2014/03/11_22:39somethingnice.hc0.me/Miner/YACMiner.files5.135.127.68-Trojan.PlasmaRAT16276FR
2014/03/11_22:39somethingnice.hc0.me/Miner/Ufasoft.files5.135.127.68-Trojan.PlasmaRAT16276FR
2014/03/11_22:39somethingnice.hc0.me/Miner/Miner.txt5.135.127.68-Trojan.PlasmaRAT16276FR
2014/03/11_22:39somethingnice.hc0.me/Miner/jhProtominer.files5.135.127.68-Trojan.PlasmaRAT16276FR
2014/03/11_22:39somethingnice.hc0.me/Miner/GPUMiner.files5.135.127.68-Trojan.PlasmaRAT16276FR
2014/03/11_22:39somethingnice.hc0.me/Miner/CPUMiner.files5.135.127.68-Trojan.PlasmaRAT16276FR
2014/03/06_17:46onrio.com.br/site/Pdf/187.1.140.30web601.uni5.net.Trojan28299BR
2014/03/06_17:46portalfiremasters.com.br/Fatura.Pdf.rar189.112.170.155155.128/25.170.112.189.in-addr.arpa.Trojan16735BR
2014/03/03_11:05mgfd1b.petrix.net/5i9fh30/?264.202.123.2server.fenixmediahosting.info.exploit kit23352US
2014/03/03_11:05mgfd1b.petrix.net/5i9fh30/counter.php?fid=264.202.123.2server.fenixmediahosting.info.redirects to exploit kit23352US
2014/02/28_10:40anshrit.com/images/m216.exe103.8.127.189server02.hostingraja.in.Trojan.Injector18229IN
2014/02/28_10:404dexports.com/images/wav1.exe103.8.127.189server02.hostingraja.in.Trojan.Zbot18229IN
2014/02/28_10:40bracbetul.com/images/sh-pdf.exe103.8.127.189server02.hostingraja.in.Trojan.Zbot18229IN
2014/02/28_10:40merrymilkfoods.com/wp-content/uploads/2014/01/wav.exe103.8.127.205server08.hostingraja.in.Trojan.Zbot18229IN
2014/02/25_12:51-142.0.79.184/agent/agent.php?cr=ila-leads to fake flashplayer54444US
2014/02/21_08:54www.acquisizionevideo.com/download-software-free.html/uploads/4/9/4/6/4946671/mp3mymp3install.exe185.53.177.8-Trojan61969DE
2014/02/21_07:00nlconsulateorlandoorg.siteprotect.net/index.zip64.71.35.58-Trojan.Zbot20401US
2014/02/21_07:00images.topguncustomz.com/index.zip67.59.130.154texashomeowner.org.Trojan.Zbot20021US
2014/02/21_07:00nlconsulateorlandoorg.siteprotect.net/inddex.html64.71.35.58-Leads to Trojan.Zbot20401US
2014/02/21_07:00images.topguncustomz.com/inddex.html67.59.130.154texashomeowner.org.Leads to Trojan.Zbot20021US
2014/02/21_06:01ama-alliance.com/inddex.html198.23.48.162hosted.by.liquidnetlimited.com.Leads to Trojan.Zbot32748US
2014/02/21_06:01faiyazahmed.com/inddex.html74.220.207.177host177.hostmonster.com.Leads to Trojan.Zbot46606US
2014/02/21_06:01boschetto-hotel.gr/inddex.html69.61.106.201cerberus.impel.gr.Leads to Trojan.Zbot22653US
2014/02/21_06:01ama-alliance.com/index.zip198.23.48.162hosted.by.liquidnetlimited.com.Trojan.Zbot32748US
2014/02/21_06:01faiyazahmed.com/index.zip74.220.207.177host177.hostmonster.com.Trojan.Zbot46606US
2014/02/21_06:01boschetto-hotel.gr/index.zip69.61.106.201cerberus.impel.gr.Trojan.Zbot22653US
2014/02/21_05:43mirandolasrl.it/inddex.html194.209.228.109orion.servicedomus.org.Leads to Trojan.Zbot3303CH
2014/02/21_05:43mirandolasrl.it/index.zip194.209.228.109orion.servicedomus.org.Trojan.Zbot3303CH
2014/02/21_05:43dianepiette.co.uk/inddex.html87.117.220.252server3.velnetweb.co.uk.Leads to Trojan.Zbot20860GB
2014/02/21_05:43dianepiette.co.uk/index.zip87.117.220.252server3.velnetweb.co.uk.Trojan.Zbot20860GB
2014/02/21_05:43www.seal-technicsag.ch/inddex.html82.195.224.113gic-web-bsd-013.genotec.ch.Leads to Trojan.Zbot1836CH
2014/02/21_05:43h1666015.stratoserver.net/inddex.html85.214.157.217h1666015.stratoserver.net.Leads to Trojan.Zbot6724DE
2014/02/21_05:43h1666015.stratoserver.net/inddex.html85.214.157.217h1666015.stratoserver.net.Leads to Trojan.Zbot6724DE
2014/02/21_05:43www.seal-technicsag.ch/inddex.html82.195.224.113gic-web-bsd-013.genotec.ch.Leads to Trojan.Zbot1836CH
2014/02/21_05:43plantaardigebrandstof.nl/inddex.html5.200.7.36server.ccchost6.nl.Leads to Trojan.Zbot49544NL
2014/02/21_05:43www.seal-technicsag.ch/index.zip82.195.224.113gic-web-bsd-013.genotec.ch.Trojan.Zbot1836CH
2014/02/21_05:43h1666015.stratoserver.net/index.zip85.214.157.217h1666015.stratoserver.net.Trojan.Zbot6724DE
2014/02/21_05:43h1666015.stratoserver.net/index.zip85.214.157.217h1666015.stratoserver.net.Trojan.Zbot6724DE
2014/02/21_05:43www.seal-technicsag.ch/index.zip82.195.224.113gic-web-bsd-013.genotec.ch.Trojan.Zbot1836CH
2014/02/21_05:43plantaardigebrandstof.nl/index.zip5.200.7.36server.ccchost6.nl.Trojan.Zbot49544NL
2014/02/19_11:23ru.theswiftones.com/178.33.152.221-exploit kit / requires Google referrer16276FR
2014/02/19_08:08resolvethem.com141.101.116.122-DOS service13335EU
2014/02/19_08:08vitalityxray.com5.135.127.68-Exploit16276FR
2014/02/19_08:08fallencrafts.info37.59.68.26-Multiple.Malware16276FR
2014/02/19_08:08e1r.net/download/3.exe37.59.68.26-Win32/Injector.AXJG16276FR
2014/02/19_08:08e1r.net/download/xwmltc.exe37.59.68.26-Win32/Injector.AXDN16276FR
2014/02/19_08:08e1r.net/download/pts.exe37.59.68.26-Win32/BitCoinMiner.AU16276FR
2014/02/19_08:08e1r.net/download/ca.exe37.59.68.26-Win32/TrojanDownloader.Wauchos.X16276FR
2014/02/19_08:08e1r.net/download/beef.tgz37.59.68.26-multiple threats16276FR
2014/02/19_08:08e1r.net/download/x86.exe37.59.68.26-Win32/BitCoinMiner.AU16276FR
2014/02/19_08:08e1r.net/download/wmltc.exe37.59.68.26-Win32/CoinMiner.JG16276FR
2014/02/19_01:05directxex.com/uploads/841642867.johny.exe108.162.198.96-TR/Ransom.24371513335US
2014/02/19_01:05directxex.com/uploads/1769382244.HDPlayer_BETA_installer_v2.55.exe108.162.198.96-MSIL/Injector.CSR trojan13335US
2014/02/19_01:05directxex.com/uploads/606454025.Download.exe108.162.198.96-MSIL/Bladabindi.O trojan13335US
2014/02/19_01:05directxex.com/uploads/214894250.pics.rar108.162.198.96-RAR/Agent.X trojan13335US
2014/02/19_01:05directxex.com/uploads/1483904659.photooamirat-annaba.exe108.162.199.96-Win32/Injector.UJN trojan13335US
2014/02/19_01:05directxex.com/uploads/1844534592.avg.exe108.162.199.96-Win32/Injector.AXIM trojan13335US
2014/02/19_01:05download-archiver.ru103.31.186.207103.31.186.207.reserved.voxility.com.Win32/Injector.AYAH39743HK
2014/02/19_01:05downloads-finereader.ru103.31.186.207103.31.186.207.reserved.voxility.com.Win32/Injector.AYAH39743HK
2014/02/19_01:05myvksaver.ru103.31.186.207103.31.186.207.reserved.voxility.com.Win32/Injector.AYAH39743HK
2014/02/19_01:05winrar-soft.ru103.31.186.207103.31.186.207.reserved.voxility.com.Win32/Injector.AYAH39743HK
2014/02/19_01:05download-archiver.ru/download.php?file=winrar103.31.186.207103.31.186.207.reserved.voxility.com.Win32/Injector.AYAH39743HK
2014/02/19_01:05downloads-finereader.ru/download.php?file=winrar103.31.186.207103.31.186.207.reserved.voxility.com.Win32/Injector.AYAH39743HK
2014/02/19_01:05myvksaver.ru/download.php?file=winrar103.31.186.207103.31.186.207.reserved.voxility.com.Win32/Injector.AYAH39743HK
2014/02/19_01:05winrar-soft.ru/download.php?file=winrar103.31.186.207103.31.186.207.reserved.voxility.com.Win32/Injector.AYAH39743HK
2014/02/19_01:05download-archiver.ru/download.php?file=winrar103.31.186.207103.31.186.207.reserved.voxility.com.Win32/Injector.AYAH39743HK
2014/02/18_15:40funchill.com/Invoice.zip192.254.236.149-Trojan.Zbot46606US
2014/02/18_15:40nc2199.eden5.netclusive.de/Invoice.zip89.110.129.55eden5.netclusive.de.Trojan.Zbot24989DE
2014/02/18_15:40notebookservisru.161.com1.ru/PayInfo.zip89.108.67.65cp161.agava.net.Trojan.Zbot43146RU
2014/02/18_15:40www.fabioalbini.com/Invoice.zip195.110.150.4net150-004.mclink.it.Trojan.Zbot5396IT
2014/02/18_15:40www.notaverde.com/Invoice.zip205.236.147.30www2.securenet.net.Trojan.Zbot14112CA
2014/02/17_10:32bracewellfamily.com/PayInfo.zip?JQrk Trojan.Zbot96.127.180.194s9-chicago.accountservergroup.com.-32475US
2014/02/17_10:32www.fabioalbini.com/Order.zip?YIjoBgGhCBbs Trojan.Zbot195.110.150.4net150-004.mclink.it.-5396IT
2014/02/14_23:35-94.23.62.190/calc.exens206681.ovh.net.Trojan.Agent.FSA7416276FR
2014/02/14_23:35-94.23.62.190/upeksvr.exens206681.ovh.net.Trojan.Kelihos16276FR
2014/02/14_23:35edf.fr.kfskz.com/facture_edf.pdf.03.exe195.93.153.1web-c-1.neolabs.kz.Backdoor.Bot.MSIL44256KZ
2014/02/12_11:08www.studiochiarelli.eu/02-2014/clients/order.3757.zip195.110.124.133opus.register.it.Trojan39729IT
2014/02/12_11:08www.toochattoo.com/fond-ecran-anime/chinois1.exe88.190.253.247pf7-web.online.net.Trojan12322FR
2014/02/11_02:56www.tvnews.or.kr/web/view.html210.205.6.203-Win32/Exploit.CVE-2013-3897.A9318KR
2014/02/11_02:56www.tvnews.or.kr/web/menu.gif210.205.6.203-Trojan9318KR
2014/02/11_02:53www.tvnews.or.kr/web/main.gif210.205.6.203-Trojan9318KR
2014/02/11_02:45updat120.clanteam.com67.220.217.23567-220-217-235.hosted.static.webnx.com.Exploit18450US
2014/02/11_02:45updat120.clanteam.com/ie7.htm67.220.217.23567-220-217-235.hosted.static.webnx.com.Exploit18450US
2014/02/11_02:45updat120.clanteam.com/ie8.htm67.220.217.23567-220-217-235.hosted.static.webnx.com.Exploit18450US
2014/02/11_02:45updat120.clanteam.com/calc67.220.217.23567-220-217-235.hosted.static.webnx.com.Trojan18450US
2014/02/10_15:44vistatech.us/gangplanks/trysted.exe192.185.24.77ns227.websitewelcome.com.Trojan.Muiref20013US
2014/02/10_15:44batcoroadlinescorporation.com/concedes/diggers.exe184.172.49.3svr1.infowaveindia.com.Trojan.Muiref36351US
2014/02/10_13:58miracema.rj.gov.br/counter.php187.73.33.43web101.f1.k8.com.br.iFrame.Exploit (injected into compromised sites, e.g. www.plantes-sauvages.fr/fiche_lierre_terrestre.htm)262672BR
2014/02/07_19:06ip-182-50-129-181.ip.secureserver.net/~venkat/1.html182.50.129.181ip-182-50-129-181.ip.secureserver.net.Leads to exploit at jolygoestobeinvester.ru26496SG
2014/02/07_19:06treventuresonline.com/1.html192.185.41.48-Leads to exploit at jolygoestobeinvester.ru20013US
2014/02/07_17:40kadman.net/1.html195.189.140.2828.hosting-5.xtream.co.il.Leads to exploit at jolygoestobeinvester.ru9116IL
2014/02/07_17:35divine.lunarbreeze.com/~xenoa3/1.html216.227.215.8divine.lunarbreeze.com.Leads to exploit at jolygoestobeinvester.ru15244US
2014/02/07_17:20salon77.co.uk/1.html79.171.34.9mail62.hostinguk.net.Leads to exploit at jolygoestobeinvester.ru33968GB
2014/02/07_17:15marchen-toy.co.jp/1.html111.68.244.2marchen-toy.co.jp.Leads to exploit at jolygoestobeinvester.ru2914JP
2014/02/07_17:10d1171912.cp.blacknight.com/1.html78.153.215.53-Leads to exploit at jolygoestobeinvester.ru39122IE
2014/02/07_17:10phitenmy.com/1.html202.190.181.149149.128.181.190.202.in-addr.arpa.Leads to exploit at jolygoestobeinvester.ru2042MY
2014/02/07_17:00corroshield.estb.com.sg/1.html203.125.76.84ns2.e-dir.com.sg.Leads to exploit at jolygoestobeinvester.ru3758SG
2014/02/07_16:49www.3peaks.co.jp/1.html211.19.24.235usr235.g024.nabic.jp.Leads to exploit at jolygoestobeinvester.ru23641JP
2014/02/07_15:39landisbaptist.com/1.html67.210.126.85lyra.lunarpages.com.Leads to exploit at jolygoestobeinvester.ru15244US
2014/02/07_15:22noobgirls.com/pussy.php107.161.144.14pluffpass.com.Trojan36352US
2014/02/07_15:22noobgirls.com/pussy.exe107.161.144.14pluffpass.com.Trojan36352US
2014/02/07_15:13tamilcm.com/1.html67.227.152.196windows2.india-to.net.Leads to exploit at jolygoestobeinvester.ru32244US
2014/02/07_14:56advancetec.co.uk/1.html212.48.68.157atfx.atfx-systems.co.uk.Leads to exploit at jolygoestobeinvester.ru20738GB
2014/02/07_14:31finnhair.co.uk/1.html208.123.212.48wp03.yeg.alentus.net.Leads to exploit at jolygoestobeinvester.ru25745US
2014/02/07_14:21hrdcvn.com.vn/1.html123.30.184.132vdc184-132.vmms.vn.Leads to exploit at jolygoestobeinvester.ru7643VN
2014/02/07_14:04nortonfire.co.uk/1.html82.165.213.55kundenserver.de.Leads to exploit at jolygoestobeinvester.ru8560DE
2014/02/07_13:47alexandria90.etcserver.com/~psychica/1.html50.23.98.194alexandria90.etcserver.com.Leads to exploit at jolygoestobeinvester.ru36351US
2014/02/07_13:47-42.96.151.54/1.html-Leads to exploit at jolygoestobeinvester.ru37963CN
2014/02/07_13:47-91.99.102.154/1.html91.99.102.154.parsonline.net.Leads to exploit at jolygoestobeinvester.ru16322IR
2014/02/07_13:34alisat.biz/1.html211.43.212.39linux39.gabia.com.Leads to exploit at jolygoestobeinvester.ru3786KR
2014/02/07_13:34109-204-26-16.netconnexion.managedbroadband.co.uk/1.html109.204.26.16109-204-26-16.netconnexion.managedbroadband.co.uk.Leads to exploit at jolygoestobeinvester.ru20500GB
2014/02/07_13:34www.nothingcompares.co.uk/1.html82.165.204.223kundenserver.de.Leads to exploit at jolygoestobeinvester.ru8560DE
2014/02/07_13:34ip-182-50-129-164.ip.secureserver.net/1.html182.50.129.164ip-182-50-129-164.ip.secureserver.net.Leads to exploit at jolygoestobeinvester.ru26496SG
2014/02/07_13:34users173.lolipop.jp/~lolipop.jp-204f9d446b7f9eb/1.html210.157.22.62users173.phy.lolipop.jp.Leads to exploit at jolygoestobeinvester.ru7506JP
2014/02/07_12:01tavuks.com/_vti_bin/1und1.php/37.247.99.221host-37-247-99-221.routergate.com.Trojan43260TR
2014/02/07_11:39mylabsrl.com/1.html46.28.6.113-Leads to exploit at jolygoestobeinvester.ru1267IT
2014/02/07_11:30-91.99.102.154/1.html91.99.102.154.parsonline.net.Leads to exploit at jolygoestobeinvester.ru16322IR
2014/02/07_11:05d1054130-28095.cp.blacknight.com/1.html78.153.216.42PEMLINWEB133.blacknight.com.Leads to exploit at jolygoestobeinvester.ru39122IE
2014/02/07_11:02nestorconsulting.net/1.html74.50.25.155chaos.lunarbreeze.com.Leads to exploit at jolygoestobeinvester.ru15244US
2014/02/07_11:02portraitphotographygroup.com/~lorijill/1.html192.185.46.31-Leads to exploit at jolygoestobeinvester.ru20013US
2014/02/07_10:27nt-associates.com/1.html213.171.218.52server213-171-218-52.livedns.org.uk.Leads to exploit at jolygoestobeinvester.ru15418GB
2014/02/07_10:24www.lccl.org.uk/1.html67.231.249.62s62.EXCALIBURHOST.COM.Leads to exploit at jolygoestobeinvester.ru40244US
2014/02/07_09:50keyways.pt/~keyways/1.html94.23.79.17cluster006.ovh.net.Leads to exploit at jolygoestobeinvester.ru16276FR
2014/02/07_09:44www.t-gas.co.uk/1.txt212.227.26.21-Leads to exploit at jolygoestobeinvester.ru8560DE
2014/02/07_08:25www.zatzy.com/allmaent/391854-volvos-nya-drive-e.html81.201.217.115-compromised site leads to exploit kit41175SE
2014/01/22_22:22downloads-whatsapp.com/whatsapp-for-samsung.php91.218.229.16h7.ihc.ru.Android/Trojan.SMS.FakeInst48172RU
2014/01/22_22:22downloads-whatsapp.com91.218.229.16h7.ihc.ru.Android/Trojan.SMS.FakeInst48172RU
2014/01/22_22:22downloads-whatsapp.com/whatsapp-for-nokia.php91.218.229.16h7.ihc.ru.Android/Trojan.SMS.FakeInst48172RU
2014/01/22_14:39-221.132.37.26/sh-Linux malware7643VN
2014/01/19_09:40yumekin.com/inde.php108.179.202.25-Trojan36351US
2014/01/19_09:40yumekin.com/inde.php?comercial@cohesp.com.br108.179.202.25-Trojan36351US
2014/01/09_23:39-119.245.150.94/fF3krry.exe Trojan.Backdoor.RVsuntoy.jp.-2514JP
2014/01/09_23:39directxex.com/uploads/815597715.bot.exe Trojan.Agent173.245.61.76cf-173-245-61-76.cloudflare.com.-13335US
2014/01/09_23:39news4cars.com/misc/uip/adobe_flash.exe Trojan.Agent37.148.207.1n1nlhg640c1640.shr.prod.ams1.secureserver.net.-26496NL
2014/01/09_23:39rocksresort.com.au/image/pdf.exe Trojan.Zbot67.22.142.73unknown.dal.cologlobal.com.-12179CA
2014/01/09_23:39updo.nl/file/b24d1856.exe Trojan.Injector149.210.134.83149-210-134-83.colo.transip.net.-20857NL
2014/01/09_23:39directxex.com/uploads/1395655996.ss.exe Win32/AutoRun.IRCBot.JD173.245.61.76cf-173-245-61-76.cloudflare.com.-13335US
2014/01/09_23:39directxex.com/uploads/144543902.rundll32.exe Trojan173.245.61.76cf-173-245-61-76.cloudflare.com.-13335US
2014/01/09_23:39directxex.com/uploads/1552287385.igfxtray.exe Win32/CoinMiner.IS173.245.60.76cf-173-245-60-76.cloudflare.com.-13335US
2014/01/09_23:39directxex.com/uploads/1576253022.miner.txt Win32/CoinMiner.IS173.245.60.76cf-173-245-60-76.cloudflare.com.-13335US
2014/01/09_23:39directxex.com/uploads/2074531303.BIN.exe Win32/Napolar.A173.245.60.76cf-173-245-60-76.cloudflare.com.-13335US
2014/01/09_23:39directxex.com/uploads/815597715.bot.exe Win32/Spy.Zbot.AAQ173.245.60.76cf-173-245-60-76.cloudflare.com.-13335US
2014/01/09_23:39directxex.com/uploads/84937512.And.exe Win32/Injector.AUJQ173.245.60.76cf-173-245-60-76.cloudflare.com.-13335US
2014/01/09_23:39directxex.com/uploads/939195944.newmine.exe MSIL/CoinMiner.AY173.245.61.76cf-173-245-61-76.cloudflare.com.-13335US
2014/01/09_23:39ttb.tbddlw.com/download/request/51a9b7865f1c1eb81f000001/CtlLI2Yz?PubID=3457_2776&ClickID=3247011638 PUP.FakeJava54.218.45.67ec2-54-218-45-67.us-west-2.compute.amazonaws.com.-16509US
2014/01/08_22:49valouweeigenaren.nl/customers/cases/acc56-81-93.zip46.235.47.28srv047028.webreus.nl.Trojan34233NL
2014/01/08_22:47valouweeigenaren.nl/customers/billing/df367548-18.zip46.235.47.28srv047028.webreus.nl.Trojan34233NL
2014/01/06_12:28dl.downf468.com/n/3.0.25/3299664/manual-básico-de-windows-movie-maker.exe204.93.38.152-Win32/FirseriaInstaller.C20940US
2014/01/06_12:28dl.downf468.com/n/3.0.25/2629037/manual-de-configuración-del-putty.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/11975718/ultrasurf+13.03.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.25/11999301/Silver+TV+3.0.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.25/7412352/BTV+Solo.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/11433792/Automation+Studio+6.0.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/11649331/Super+Mario+Sunshine+64+1.0.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/12050993/Free+RAR+Extract+Frog.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.24.1/12015256/Windows+Product+Key+Code+Finder+2.20.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.24.1/12015430/NT+Key+Enterprise+Edition+3.80.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.25/12023961/Microsoft+Hesap+Makinesi++.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.25/4789416/LogiEscalierExpert.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.1/11630753/iniciación-a-la-soldadura-con-estaño.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.1/11812852/n5239.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.1/11358561/notepad+++.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.1/11707102/psx0139.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.1/11707353/psx0046.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/1033/poweriso.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/11431055/dragon+naturally+speaking+9.0.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/11431361/who+anthro+3.2.2.1.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/2269383/roadnav.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/2836178/gambas+a+la+egipcia.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/5345299/vietkey.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/5349388/adfender.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/5366358/mediaget.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/5366255/flv_media_player.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/5830397/matlab.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/6445693/calibre.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/6773557/odin3.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/11433792/AutomationStudio6.0.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/11649331/SuperMarioSunshine641.0.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/12050993/FreeRARExtractFrog.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.25/7412352/BTVSolo.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.24.1/4790826/Handball+Challenge.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/4812448/pointage+d%E2%80%99heures.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/5347935/wondershare+pdf+to+word.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.25/11999301/SilverTV3.0.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.24.1/12015256/WindowsProductKeyCodeFinder2.20.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.24.1/12015430/NTKeyEnterpriseEdition3.80.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/5331438/FLV_Media_Player.exe=0D=0Ahttp:/grandinstalls.ru/RlpaXhQBAUhBXE1LXQBMW1cDSEdCSwBcWwFJS1pxVkNCEUhHQktxR0oT/torrent/147458862/498349280/torrent.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/12014376/Setup.exe=0D=0Ahttp:/dl.softpzivrubajjui.net/n/3.0.26.2/5565169/FLVMPlayer.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/5738856/FLV_Media_Player.exe=0D=0Ahttp:/dl.softpzivrubajjui.net/n/3.0.26.2/10064255/HitmanPro.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/5738856/FLV_Media_Player.exe=0D=0Ahttp:/dl.softpzivrubajjui.net/n/3.0.26.2/11799286/Opera.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/5785797/FLV_Media_Player.exe=0D=0Ahttp:/dl.softohqimjjedf0jq.net/n/3.0.26.2/5784498/FLV_Media_Player.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/5785797/FLV_Media_Player.exe=0D=0Ahttp:/dl.softohqimjjedf0jq.net/n/3.0.26.2/11359629/Stream_Movies_Online.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/6068293/winrarfree.exe=0D=0Ahttp:/dl.softpzivrubajjui.net/n/3.0.26.2/11717749/Winzip.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/11797512/FLV_Media_Player.exe=0D=0Ahttp:/redtubes.ru/FgoKDkRRURgRDB0bDVAcCwdTGBcSG1AMC1EZGwohBhMSQRgXEhshFxpD/audio/127974014/481402808/toca_toca_radio_edit.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/4924888/100-villancicos.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.1/12023961/microsofthesapmakinesi.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/4800574/sculptris.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/5436359/FLV_Media_Player.exe=0D=0Ahttp:/dl01.fabdmr.com/n/3.0.26/6498621/FLV_Media_Player.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/187807/Utorrent.exe=0D=0Ahttp:/dl01.facdmr.com/n/3.0.26/4993202/Mediaget.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/2105371/AVS_Media_Player.exe=0D=0Ahttp:/dl01.faadmr.com/n/3.0.26/11822316/FLV_Media_Player.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/2094912/AVS_Media_Player.exe=0D=0Ahttp:/installsupdater.info/syshost.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/5738856/FLV_Media_Player.exe=0D=0Ahttp:/dl.softohqimjjedf0jq.net/n/3.0.26/3484691/SimTractor.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/2632028/AVS_Media_Player.exe=0D=0Ahttp:/download.multiinstall.com.br/a75e4b51a7dfadaa4b8a88436b76af41/Quadro_1600x1200.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/2105407/AVS_Media_Player.exe=0D=0Ahttp:/dl.softohqimjjedf0jq.net/n/3.0.26/4351718/Vlc_Media_Player.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/11813765/n0140.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/2105407/AVS_Media_Player.exe=0D=0Ahttp:/tube-city.ru/1MjIzIaTk8/J0c/J0tvPzNnfyM6SzsmT29nI49jTy9LQ093Y48TR0OOPg9XYgQ=3D=3D/torrent/5387708/159507868/download.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/4351718/Vlc_Media_Player.exe=0D=0Ahttp:/dl.softohqimjjedf0jq.net/n/3.0.26/6708421/Ares.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/6068293/winrarfree.exe=0D=0Ahttp:/dl01.fabdmr.com/n/3.0.26/5034600/J_DOWNLOADER.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/11810098/n2018.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.1/2629037/manual-de-configuraci&;amp;oacute;n-del-putty.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/11853911/Adobe_PDF_Reader.exe=0D=0Ahttp:/dl.softpzivrubajjui.net/n/3.0.26.2/5565169/FLVMPlayer.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/11975718/ultrasurf13.03.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/4866666/macromedia-freehand.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/6690540/minecraft1.5.2.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/5983928/app.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/11930758/File_installer.exe=0D=0Ahttp:/dl.downe468.com/n/3.0.26/11928104/Ares.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/4889139/the-hunter.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/11930758/File_installer.exe=0D=0Ahttp:/dl.downf468.com/n/3.0.26/11893495/Update_Code_Generator.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.2/5570947/mipony.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/11930758/File_installer.exe=0D=0Ahttp:/dl.softohqimjjedf0jq.net/n/3.0.26/12091048/Skype.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/11930758/File_installer.exe=0D=0Ahttp:/dl01.fabdmr.com/n/3.0.26/187807/Utorrent.exe=96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26/11930758/File_installer.exe=0D=0Ahttp:/dl.downf468.com/n/3.0.26/7088851/FLV_Media_Player.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.25/11810424/n5250.exeo:=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/11706753/d0005.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/11810692/n5062.exeo:p/o:p=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.25/11706811/psx0109.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.25/11784924/p1232.exeo:=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.25/11560994/d3dx9_31.exe=96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.1/3285684/lógica-y-teoría-de-conjuntos.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/4789537/setup.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/8311230/avast.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/4812448/pointagedheures.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/5347935/wondersharepdftoword.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.24.1/4790826/HandballChallenge.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/11439286/msvcr100.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/3708/teamviewer.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/11442660/d3dx9_43.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.1/6156061/¿dónde-está-carmen-sandiego?.exe96.17.161.145a96-17-161-145.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/11812198/n4250.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/11811219/n4911.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/11970252/skype.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/6654650/alzip.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/2836178/gambasalaegipcia.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/11809923/n5574.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/11707321/psx0026.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2014/01/06_12:28dl.downf468.com/n/3.0.26.3/11706755/d0004.exe96.17.161.137a96-17-161-137.deploy.akamaitechnologies.com.Win32/FirseriaInstaller.C12989US
2013/12/29_17:53aippnetworks.com/plugins/authentication/joomla/aviancataca/aviancatacafreeticket.php195.74.65.196195-74-65-196.ip.aleto.nl.Redirects to Trojan25459NL
2013/12/20_15:23down2.feiyang163.com/soft/wavtomp3.exe211.101.12.49-Trojan.Android4808CN
2013/12/20_15:23down3.feiyang163.com/soft/fcssq.exe211.101.12.49-Trojan.Android4808CN
2013/12/20_15:23d1.kuai8.com/setup/kuai8_zjy.exe61.158.145.141141.145.158.61.ha.cnc.Trojan.Backdoor4837CN
2013/12/20_15:23down.unadnet.com.cn/soft/2Dmofang.exe211.101.12.49-Trojan.Chad4808CN
2013/12/20_15:23down.unadnet.com.cn/soft/loveletter.exe211.101.12.49-Trojan.Chad4808CN
2013/12/20_15:23ddd.gouwuke.cn/down/exejmman.exe211.101.12.49-Trojan.Delf4808CN
2013/12/20_15:23-211.101.12.49/dls/axuip.exe-Trojan.Downloader4808CN
2013/12/20_15:23-211.101.12.49/dls/axujp.exe-Trojan.Downloader4808CN
2013/12/20_15:23down.feiyang163.com/soft/alexacha.exe211.101.12.49-Trojan.Downloader4808CN
2013/12/20_15:23down.feiyang163.com/soft/usblock.exe211.101.12.49-Trojan.Downloader4808CN
2013/12/20_15:23down.feiyang163.com/soft/wbjfsys.exe211.101.12.49-Trojan.Downloader4808CN
2013/12/20_15:23down.guangsu.cn/qdn/setup_qd262.exe121.63.179.184-Trojan.Dropper4134CN
2013/12/20_15:23down.guangsu.cn/qdn/setup_qd304.exe122.225.106.101-Trojan.Dropper4134CN
2013/12/20_15:23www.sj88.com/hezi/jm/s1000.exe202.97.174.68-Trojan.Dropper4837CN
2013/12/20_15:23k.h.a.d.free.fr/pub/utils/oepv.exe212.27.63.102perso102-g5.free.fr.Trojan.Emogen.U12322FR
2013/12/20_15:23-211.101.12.49/dls/axujo.exe-Trojan.SelfDel4808CN
2013/12/20_15:23download.grandcloud.cn/9291/15474/setup_2949-14598.exe211.147.13.224-Trojan.Symmi17431CN
2013/12/20_15:23download.grandcloud.cn/9291/16411/80347_al.exe58.215.169.42-Trojan.Symmi4134CN
2013/12/20_15:23download.grandcloud.cn/9291/17147/cool_ES_PC35152730.exe58.215.169.42-Trojan.Symmi4134CN
2013/12/20_15:23www.feiyang163.com/soft/fySpeaker.exe211.101.12.49-Win32/Trojan.Backdoor4808CN
2013/12/20_15:23thefxarchive.com/Downloads/WLMM/MMK_Warp_Variations.exe98.131.172.1rev.opentransfer.com.1.172.131.98.in-addr.arpa.Win32/Trojan.Genome32392US
2013/12/20_15:23formessengers.com/download.php?PN=MLP72.167.131.157p3slh193.shr.phx3.secureserver.net.Win32/Trojan.Injects26496US
2013/12/20_15:23dl.microsword.net/softdown/filerubber.exe211.101.12.49-Win32/Trojan.Pasta.h4808CN
2013/12/20_15:23dl.microsword.net/Softdown/VideoRecord.exe211.101.12.49-Win32/Trojan.Pasta.h4808CN
2013/12/20_15:23download.56.com/lp/client/update.lua59.32.213.195195.213.32.59.broad.sg.gd.dynamic.163data.com.cn.Win32/Trojan.Spy4134CN
2013/12/20_15:23download.56.com/lp/client/woxiu1.0.15_20119070.exe59.32.213.195195.213.32.59.broad.sg.gd.dynamic.163data.com.cn.Win32/Trojan.Spy4134CN
2013/12/20_15:23download.ttrili.com:98/Setup%5B57%5D-rl.exe223.244.255.16-Win32/Trojan.Spy4134CN
2013/12/20_15:23download.ttrili.com:98/Setup%5B75%5D-rl.exe117.28.254.156-Win32/Trojan.Spy4134CN
2013/12/20_15:23download.ttrili.com:98/setup%5B79%5D-rl.exe117.28.254.156-Win32/Trojan.Spy4134CN
2013/12/20_15:23download.ttrili.com:98/Setup[11]-rl.exe117.28.254.156-Win32/Trojan.Spy4134CN
2013/12/20_15:23f.gj555.net/download/setups30035.exe118.26.178.5-Win32/Trojan.Spy4808CN
2013/12/20_15:23f.gj555.net/download/setups30138.exe118.26.178.5-Win32/Trojan.Spy4808CN
2013/12/20_15:23f.gj555.net/download/setups34338.exe118.26.178.5-Win32/Trojan.Spy4808CN
2013/12/20_15:23f.gj555.net/download/setups75613.exe118.26.178.5-Win32/Trojan.Spy4808CN
2013/12/20_15:23f.gj555.net/download/setups83563.exe118.26.178.5-Win32/Trojan.Spy4808CN
2013/12/20_15:23f.gj555.net/download/setups91646.exe118.26.178.5-Win32/Trojan.Spy4808CN
2013/12/20_15:23f.gj555.net/download/setups95191.exe118.26.178.5-Win32/Trojan.Spy4808CN
2013/12/20_15:23files.dsnetwb.com/aTube_Catcher_5188_ATU3.exe174.37.194.151sky.dsnetwb.com.Win32/Trojan.Spy36351US
2013/12/20_15:23www.zctei.com/date/9377chiyue_Y_Cdcr1124.exe122.225.107.85-Win32/Trojan.Spy4134CN
2013/12/19_16:43directxex.com/uploads/1201296916.8h.exe108.162.198.96-Backdoor.Bot13335US
2013/12/19_16:43directxex.com/uploads/1251104917.p9g.exe108.162.199.96-Trojan.Zbot.CXgen13335US
2013/12/19_16:43directxex.com/uploads/1353613345.ih.exe108.162.199.96-Trojan.IRCbot13335US
2013/12/19_16:43directxex.com/uploads/143265795.ohi.exe108.162.199.96-Trojan.Ircbot.SI13335US
2013/12/19_16:43directxex.com/uploads/1565397800.9g.exe108.162.199.96-Trojan.Zbot.CXgen13335US
2013/12/19_16:43directxex.com/uploads/158511922.uf.exe108.162.198.96-Trojan.IRCbot13335US
2013/12/19_16:43directxex.com/uploads/1607796965.id100.exe108.162.198.96-Trojan.Agent13335US
2013/12/19_16:43directxex.com/uploads/1836606807.9g.exe108.162.198.96-Trojan.FakeMIRC13335US
2013/12/19_16:43directxex.com/uploads/1853928844.97g.exe108.162.198.96-Trojan.Zbot.CXgen13335US
2013/12/19_16:43directxex.com/uploads/1991519040.aeg.exe108.162.199.96-Trojan.Ircbot.SI13335US
2013/12/19_16:43directxex.com/uploads/223478294.insid-start-sjw.exe108.162.199.96-Trojan.Agent.MNR13335US
2013/12/19_16:43directxex.com/uploads/232683212.igi.exe108.162.199.96-Trojan.Agent.DE13335US
2013/12/19_16:43directxex.com/uploads/31401351.final5.exe108.162.199.96-Trojan.Agent.AI13335US
2013/12/19_16:43directxex.com/uploads/384011806.gotter.exe108.162.199.96-Trojan.LVBP13335US
2013/12/19_16:43directxex.com/uploads/414294618.009.exe108.162.199.96-Trojan.Inject13335US
2013/12/19_16:43directxex.com/uploads/609015994.mining.exe108.162.199.96-Backdoor.MSIL.P13335US
2013/12/19_16:43directxex.com/uploads/620509324.MINIMON.exe108.162.199.96-Trojan.MSIL13335US
2013/12/19_16:43directxex.com/uploads/623307317.inst.exe108.162.198.96-Trojan.Agent13335US
2013/12/19_16:43directxex.com/uploads/636954784.ok.exe108.162.198.96-Trojan.Agent.DEED13335US
2013/12/19_16:43directxex.com/uploads/662268336.BIN.exe108.162.198.96-Trojan.Napolar13335US
2013/12/19_16:43directxex.com/uploads/687255529.delfi.exe108.162.198.96-Trojan.Inject13335US
2013/12/19_16:43directxex.com/uploads/744646896.rbsrb.exe108.162.198.96-Trojan.Zbot.CXgen13335US
2013/12/19_16:43directxex.com/uploads/777724411.safetyCheck.exe108.162.198.96-Trojan.Agent.AI13335US
2013/12/19_16:43directxex.com/uploads/818611823.insidrazor.exe108.162.198.96-Trojan.Autoit13335US
2013/12/19_16:43directxex.com/uploads/836587333.skp.exe108.162.198.96-Trojan.Ircbot.SI13335US
2013/12/19_16:43directxex.com/uploads/845426478.xa.exe108.162.199.96-Trojan.FakeMIRC13335US
2013/12/19_16:43directxex.com/uploads/90200102.neusteBotLoader.exe108.162.199.96-Backdoor.Bot.Tor13335US
2013/12/19_16:43directxex.com/uploads/995578741.miner.exe108.162.199.96-Trojan.MSIL13335US
2013/12/19_16:43directxex.com/uploads/1744698061.miner.txt108.162.199.96-Trojan.MSIL13335US
2013/12/19_16:43directxex.com/uploads/281742754.abbba.exe108.162.199.96-Win32/Injector.ATSD trojan13335US
2013/12/19_16:43directxex.com/uploads/566077266.ms.exe108.162.199.96-Win32/Injector.Autoit.VH trojan13335US
2013/12/19_16:43directxex.com/uploads/1347878398.miner2.exe108.162.199.96-MSIL/CoinMiner.CV trojan13335US
2013/12/19_16:43directxex.com/uploads/1565998043.test.exe108.162.199.96-Trojan..HKWQREW13335US
2013/12/19_16:43directxex.com/uploads/2111586998.onoj.exe108.162.198.96-Win32/Injector.ATFB trojan13335US
2013/12/19_16:43directxex.com/uploads/566077266.ms.exe?dl=1108.162.198.96-Win32/Injector.Autoit.VH trojan13335US
2013/12/12_10:24-31.220.3.68/www/BotLoader.exededicated.koddos.com.Trojan.Atrax199636DE
2013/12/12_10:24-31.220.3.68/www/402022Rechnung.PDF.exededicated.koddos.com.Trojan199636DE
2013/12/12_10:24-31.220.3.68/www/StealerDllx86.dll_rawdedicated.koddos.com.Trojan.PWS199636DE
2013/12/12_10:10-31.220.3.68/www/dedicated.koddos.com.Java drive-by199636DE
2013/12/12_10:10-31.220.3.68/www/BotLoader.exededicated.koddos.com.Trojan.Atrax199636DE
2013/12/09_11:19amu.adduraddonhere.info/lpgreenseal/141.101.117.61-Leads to Win32/InstallRex13335EU
2013/12/09_11:19amu.boxinstallercompany.info/iframe/?d=746162.210.192.9-Leads to Win32/InstallRex30633US
2013/12/09_11:11amu.brandnewinstall.info/yaelmendel/gadget/162.210.192.9-Leads to Win32/InstallRex30633US
2013/12/09_11:11amu.helpyourselfinstall.info/iframe/?d=1271162.210.192.5-Leads to Win32/InstallRex30633US
2013/12/09_11:11amu.twobox4addon.info/rachel/162.210.192.5-Leads to Win32/InstallRex30633US
2013/12/09_11:11amu.helpyourselfinstall.info/iframe/?d=1118162.210.192.5-Leads to Win32/InstallRex30633US
2013/12/09_10:57mobatory.com/7jwgzo2ub186py0imhspqlfoe78.140.142.178-Leads to ransomware35415NL
2013/12/09_10:57mobatory.com/5uxfljc5z4s6eacz305ic45h25hq3srib5tc1b51g?j8c=49ljg&pjz9ci=rapid8.com/&3kgiokr8=t3619158&80ipnpaegcqj19=rapid8.com/stage2.php&4kf7k=0&31n33=0&3ea6o=0&3cvlt=0&wr71g34ni=1&127ehq780r=0&6s89o644imz=0&78ob3sh84zkh1z=1&6iu2mhp1=0&rpo5za53h=1024&yq84eazbm=768&8v0luzzkqq3=0&6s5iunzsdhm2mj30=178.140.142.178-Leads to ransomware35415NL
2013/12/09_10:57mobatory.com/5uxfljc5z4s6eacz305ic45h25hq3srib5tc1b51g?j8c=49ljg&pjz9ci=rapid8.com/&3kgiokr8=t3619158&80ipnpaegcqj19=rapid8.com/stage2.php&4kf7k=0&31n33=0&3ea6o=0&3cvlt=0&wr71g34ni=1&127ehq780r=0&6s89o644imz=0&78ob3sh84zkh1z=1&6iu2mhp1=0&rpo5za53h=1024&yq84eazbm=768&8v0luzzkqq3=0&7uyedgxpbuv6y8kxg34cuxdmz=99780&98uca7ro8qv6eu5qpnguteh6r=78.140.142.186-Leads to ransomware35415NL
2013/12/09_10:22vroll.net78.140.142.165-Leads to ransomware35415NL
2013/12/09_10:22mobatory.com/70i1sxn6q8s86lqb6tfkgdehq78.140.142.178-Leads to ransomware35415NL
2013/12/09_10:17mobatory.com/5bj0eswiecc78rvp3egufo5xossn1segz4653xhs4?37o78=46se8http%2F%3F%3Ftrahic.ru%3F6h3m0gs9sgb8vxr70voqj1fa6?&j68ljm=&6b42bbis=t85660263&pqsubf2hr=178.140.142.178-Leads to ransomware35415NL
2013/12/09_09:52mobatory.com/8jxjj7ifv3055xytz5ih3o130iar6rf978.140.142.186-Leads to ransomware35415NL
2013/12/09_09:52trahic.ru/5ebydvkrgw04am7wjly78.140.142.178-Leads to ransomware35415NL
2013/12/09_09:52trahic.ru/6h3m0gs9sgb81g8h0hdefhh9a?zhkk4a8gv=178.140.142.178-Leads to ransomware35415NL
2013/12/09_09:52trahic.ru/5mm3i7t83m2t8dlja78.140.142.178-Leads to ransomware35415NL
2013/12/09_09:52trahic.ru/6h3m0gs9sgb8vxr70voqj1fa6?78.140.142.186-Leads to ransomware35415NL
2013/12/09_09:45europol.europe.eu.id214218540-7444056787.h5841.com/?flow_id=2000&870470=33440/case_id=17188193.169.87.247-Leads to ransomware48031UA
2013/12/09_09:45europol.europe.eu.france.id647744160-2176514326.h5841.com/?flow_id=8615&511004=52895/case_id=27223193.169.87.247-Ransomware48031UA
2013/12/09_09:45z7752.com/checkout.php?step=1195.191.56.113-Ransomware payment processor50395UA
2013/12/03_08:36www.lostartofbeingadame.com/wp-content/plugins/www.fotosupload.php70.88.182.38-redirects to trojan download7725US
2013/12/03_08:36bride1.com/File/www.fotosupload.com/fotosuploadcominfidelidadfotos2dediciembreparaquenoquedendudasc.zip216.151.221.238-trojan inside zip file13768US
2013/11/19_15:22silurian.cn/modules/mod_cmsfix/fix.php159.226.74.251-iframe leads to exploit kit7497CN
2013/10/31_18:23www.blueimagen.com/Attachment/Invoice-List2013-10-20-Copy.jar65.99.225.72server79.neubox.net.Trojan.AdWind36024US
2013/10/27_03:06bizzibeans.net/wp-admin/zope/82.165.116.169-Leads to trojan8560DE
2013/10/27_03:06bizzibeans.net/wp-admin/zope/adobe_flash.exe82.165.116.169-Trojan8560DE
2013/10/27_03:02tecslide.com/js/down/Sbin1/MS0ftAdapter.exe80.241.217.134-Trojan51167DE
2013/10/27_03:02www.slivki.com.ua/as/Ponynl.exe212.26.135.68-Trojan8788UA
2013/10/27_03:02www.slivki.com.ua/as/smp.exe212.26.135.68-Trojan8788UA
2013/10/27_02:59-94.228.222.47/index.html?p=6175-Trojan47869NL
2013/10/27_02:56-178.150.192.50/traff01.exe-Trojan13188UA
2013/10/27_02:56-178.150.192.50/upeksvr.exe-Trojan13188UA
2013/10/27_02:56-178.150.202.131/same7b1.exe-Trojan13188UA
2013/10/21_21:48gredinatib.org/got.php?l=dWlkPTgyODM3MTI1NiZpZD01MDIyNiZ0aWQ9Mjc2NDE4JnBjPW37.220.26.131-Drive-by35662GB
2013/10/21_21:43morenews3.net/got.php?l=dWlkP_IxMjg4NDU1ODImaWQ9NDAxO_AmdGlkP_QwNDM3Ni37.220.26.172-Drive-by35662GB
2013/09/23_04:50cofeb13east.com/download.php?ln5/cA==50.97.234.2-Win32/InstallMonetizer36351US
2013/09/12_05:48bluecutsystem.com/load3.exe173.254.28.141just141.justhost.com.Trojan.Zbot46606UNKNOWN
2013/09/12_05:48-103.31.186.29/2013/girl-fucked-by-dog.avi.exelh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsvrx.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsvtp.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidswsy.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidswtb.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidswys.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsxlo.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsxmx.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsxpg.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsxpp.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsxwu.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsycs.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsyip.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsymz.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsyre.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsyyf.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidszmi.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsznj.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsznx.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidscqs.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidscut.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsdob.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsdst.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsfgd.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidshhr.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidshkk.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidshrw.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsiet.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsiww.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsjac.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsjan.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsjhn.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsjtq.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidslmf.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidslni.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidslqk.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidslrz.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsnlq.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsnrt.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsnvd.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsnyp.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsolh.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsotz.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsowd.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidspeq.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsqof.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsrau.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsrdr.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsrhl.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsrom.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidssan.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidssjw.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidssyg.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidstrh.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidstyp.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsuty.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsvaj.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsvcs.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsvmr.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtuberfe.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtuberjj.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtuberme.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtuberue.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubesrs.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubesrw.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubesun.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubetmf.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubetmg.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubetns.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubetts.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeubp.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeujh.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeull.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeuvd.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubevdn.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubevih.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubevjk.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubewfl.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubewiq.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubewis.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubewmt.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubexei.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubexiv.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubexvq.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubexwb.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubexxq.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeyge.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeyhz.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeyza.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsbbr.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsbhy.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidsbzx.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidscjk.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubehdn.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubehli.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeidv.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeijc.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeiqb.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubejie.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubejlp.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubejpe.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubejvh.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubejyk.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubekad.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubekgj.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubekgv.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeklg.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubekpn.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubekrn.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubelap.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubelat.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubelfr.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubelzv.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubemue.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeneg.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeneu.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubengt.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubenqp.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubentf.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeocr.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeonf.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeopy.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeoxo.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeoxy.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeppj.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeqfo.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeqsh.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeqve.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeqwr.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtuberau.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtuberea.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtuberep.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48generalchemicalsupply.com/gLG.exe174.132.149.189bd.95.84ae.static.theplanet.com.Trojan.Agent.rfz21844UNKNOWN
2013/09/12_05:48slimxxxtubeacn.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubealn.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeanr.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeaxy.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeayv.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubebej.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubebgp.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubebmq.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubebnd.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubecgl.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubectk.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubecty.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeczp.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubedgv.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubedjm.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubedlb.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubedvj.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubedxc.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubedya.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeejs.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeemz.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubefdr.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubefel.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubeftb.dnset.com/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubefzc.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48slimxxxtubehan.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:48tube8vidszyj.ddns.name/2013/girl-fucked-by-dog.avi.exe103.31.186.29lh22450.voxility.net.Trojan.Ransom39743UNKNOWN
2013/09/12_05:43mmile.com/images/rhcs05.exe206.72.201.52mmile.com.Trojan.Zbot19318UNKNOWN
2013/09/12_05:43mmile.com/images/bl.exe206.72.201.52mmile.com.Trojan.Inject19318UNKNOWN
2013/09/12_05:43www.moviedownloader.net/d/GraboidMovieDownloader-3.54.exe64.20.45.228-Adware.Fusenet19318UNKNOWN
2013/09/06_04:59luggage-tv.com/adobe/update_flash_player.exe174.140.171.207-Trojan.FareIT46816US
2013/09/06_04:59luggagepreview.com/adobe/update_flash_player.exe174.140.171.207-Trojan.FareIT46816US
2013/09/06_04:59luggagecast.com/adobe/update_flash_player.exe174.140.171.207-Trojan.FareIT46816US
2013/09/06_04:59-174.140.171.207/adobe/update_flash_player.exe-Trojan.FareIT46816US
2013/09/06_04:59kapcotool.com/adobe/update_flash_player.exe74.207.227.154li69-154.members.linode.com.Trojan.FareIT3595US
2013/09/06_04:59kapcotool.com/topic/able_disturb_planning.php74.207.227.154li69-154.members.linode.com.Exploit3595US
2013/09/06_04:59luggage-tv.com//topic/able_disturb_planning.php174.140.171.207-Exploit46816US
2013/09/06_04:59luggagepreview.com//topic/able_disturb_planning.php174.140.171.207-Exploit46816US
2013/09/06_04:59by98.com/reincarnate/index.html210.152.132.1010.0/25.132.152.210.in-addr.arpa.Leads to exploit4694JP
2013/09/06_04:59-202.212.131.8/ruses/nonsmokers.jswww.melodian.co.jp.Leads to exploit2514JP
2013/09/06_04:59-207.188.69.171/colosseum/robed.js207.188.69.171.tor.pathcom.com.Leads to exploit11342CA
2013/09/06_04:59dcanscapital.co.uk/panhandled/scientists.js212.1.212.89-Leads to exploit47583US
2013/09/06_04:59japanesevehicles.us/vector/internees.js50.87.72.21950-87-72-219.unifiedlayer.com.Leads to exploit46606US
2013/09/06_04:59teameda.net/tipsier/stuttgart.js216.87.186.173-Leads to exploit30217US
2013/09/06_04:59luggagecast.com/topic/able_disturb_planning.php174.140.171.207-Exploit46816US
2013/09/06_04:59-174.140.171.207/topic/able_disturb_planning.php-Exploit46816US
2013/08/30_10:31-64.151.226.150/7aa1c07e79cac0a6beeccff5c987b36f/websites-reproductive.php-exploit kit26753CA
2013/08/30_07:38windspotter.net/?r=site/widget178.63.73.213static.213.73.63.178.clients.your-server.de.compromised site leads to Java exploit24940DE
2013/08/27_07:50-62.76.189.21662-76-189-216.clodo.ru.Leads to ransomware57010RU
2013/08/27_07:50-62.76.189.216/firefox/firefox.html62-76-189-216.clodo.ru.Leads to ransomware57010RU
2013/08/27_07:50-62.76.189.216/chrome/chrome.html62-76-189-216.clodo.ru.Leads to ransomware57010RU
2013/08/27_07:50-62.76.189.216/ie/ie.html62-76-189-216.clodo.ru.Leads to ransomware57010RU
2013/08/27_07:50-62.76.189.216/chrome/ChromeUpdate.exe62-76-189-216.clodo.ru.Trojan.FakePutt57010RU
2013/08/27_07:50-62.76.189.216/firefox/FirefoxUpdate.exe62-76-189-216.clodo.ru.Trojan.FakePutt57010RU
2013/08/27_07:50-62.76.189.216/ie/IEUpdate.exe62-76-189-216.clodo.ru.Trojan.FakePutt57010RU
2013/08/23_11:55-174.142.240.91/577ac477f62d4873cf41dc834d107b7c/influences-portal.php-exploit kit32613CA
2013/08/12_07:18manoske.com/main.php?label=TJaxqKIV0+wlz0MJN5SxypUhWaVDQDqE4PwfdxjPls0=184.173.230.95184.173.230.95-static.reverse.softlayer.com.trojan inside zip file36351US
2013/08/07_19:06rsiuk.co.uk/cinch/index.html78.129.255.46-Leads to exploit20860GB
2013/08/07_19:06-54.248.126.242/ruggedly/copernican.jsec2-54-248-126-242.ap-northeast-1.compute.amazonaws.com.Leads to exploit16509US
2013/08/07_19:06eliehabib.com/topic/regard_alternate_sheet.php173.246.105.15-Exploit29169US
2013/08/07_18:57kipasdenim.com/images/wp-sts.php94.73.146.5094-73-146-50.cizgi.net.tr.Leads to exploit34619TR
2013/08/07_18:57praxisww.com/wp-stc.php69.26.171.30webprecision.com.Leads to exploit27524US
2013/08/07_18:57romvarimarton.hu/wp-stc.php195.56.150.12mail.kepstudio.hu.Leads to exploit3340HU
2013/08/07_18:57saemark.is/wp-content/plugins/wp-sts.php212.30.229.50-Leads to exploit44515IS
2013/08/07_18:57vitamasaz.pl/wp-stc.php188.116.35.5n22.netmark.pl.Leads to exploit43333PL
2013/08/07_18:57www.coloritpak.by/wp-stc.php93.125.99.11vh41.hosterby.com.Leads to exploit6697BY
2013/08/07_18:57www.fasadobygg.com/wp-stc.php78.110.82.72host-78-110-82-72.n62.se.Leads to exploit31507SE
2013/08/07_18:57www.hausnet.ru/wp-stc.php188.191.224.17ks17.hausnet.ru.Leads to exploit197624RU
2013/08/07_18:57www.joomlalivechat.com/wp-stc.php174.129.234.86ec2-174-129-234-86.compute-1.amazonaws.com.Leads to exploit14618US
2013/08/07_18:57www.litra.com.mk/wp-sts.php98.130.102.2rev.opentransfer.com.2.102.130.98.in-addr.arpa.Leads to exploit32392US
2013/08/07_18:57www.over50datingservices.com/wp-stc.php79.170.44.116web116.extendcp.co.uk.Leads to exploit31727GB
2013/08/07_18:57www.praxisww.com/wp-stc.php69.26.171.30webprecision.com.Leads to exploit27524US
2013/08/07_18:57www.saemark.is/wp-content/plugins/wp-sts.php212.30.229.50-Leads to exploit44515IS
2013/08/07_18:57www.wyroki.eu/wp-stc.php85.128.187.109ame109.rev.netart.pl.Leads to exploit15967PL
2013/08/04_04:46-188.190.125.173/xUmEqHqYxi/uxrpdvcjbk.php?rehnreh=sjXovBJv&kjrthdrgs=13788997&rjthergsf=893-Exploit197145UA
2013/08/02_13:16nutnet.ir/dl/nnnew.txt64.79.83.14-Leads to exploit10297US
2013/07/25_06:31server1.extra-web.cz/dbm.exe212.80.69.55xhosting.cz.trojan29208CZ
2013/07/25_06:19teameda.comcastbiz.net/expanding/index.html216.87.186.173-leads to exploit kit30217US
2013/07/25_06:19wc0x83ghk.homepage.t-online.de/communed/ameba.js80.150.6.138b2c.t-online.de.redirects to exploit kit3320DE
2013/07/23_16:30guyscards.com/adobe/184.95.37.100-Fake.FlashPlayer.Trojan20454US
2013/07/23_16:30guyscards.com/adobe/update_flash_player.exe184.95.37.100-Trojan20454US
2013/07/22_11:48v.inigsplan.ru/lich/inc/v7675/?/90.156.212.70v7675.vps.masterhost.ru.redirects to Postbank phishing25532RU
2013/07/22_11:48mailboto.com/landing/themes/bluemarine/corso/index.htm64.235.52.182mailboto.com.Postbank phishing26277US
2013/07/11_16:54lcbcad.co.uk/4541b36fdd41b9610c2e870b21fc5022/q.php78.129.250.40server.brainstormdevelopment.co.uk.exploit kit20860GB
2013/07/11_12:54www.lowes-pianos-and-organs.com/images/d521c2a038/?zAXbu4Wah12XtNHf0YTNwgTNwIjM0ATMzIDfvgzMwEmMjFjM1Q2LzV2Zh1Wav02bj567.222.109.112d15.altserver.com.ycuF2Zy9WLk5WYtM3buFWaw1ycld3bs5yd3d3LvoDc0RHa8NnZ exploit kit33494US
2013/07/11_07:25www.rebeccacella.com/wp-content/plugins/subscribe/212.227.31.159kundenserver.de.compromised site leads to exploit kit8560DE
2013/07/11_02:06malest.com208.115.233.154154-233-115-208.static.reverse.lstn.net.Leads to fake Google Chrome46475US
2013/07/11_02:06dl01.faddmr.com/n/e176d94e-d9b7-11e2-a752-00259033c1da/Setup.exe?tid=102dccc4aa5799d2efb748b9dd0e4fFake50.17.189.198ec2-50-17-189-198.compute-1.amazonaws.com.Google Chrome14618US
2013/07/11_02:06dl01.faddmr.com/n/3.0.15.1/9041377/Setup.exe?tid=102dccc4aa5799d2efb748b9dd0e4f50.17.189.198ec2-50-17-189-198.compute-1.amazonaws.com.Fake Google Chrome14618US
2013/06/21_10:17-212.124.116.141:8080/7167888324/2.zip-Java exploit47328RU
2013/06/21_10:17-212.124.116.141:8080/7167888324/7521.zip-Java exploit47328RU
2013/06/20_14:31-212.124.116.129:8080/7167888324/3503.zip-Java exploit47328RU
2013/06/20_14:31-212.124.116.129:8080/7167888324/1.zip-Java exploit47328RU
2013/06/20_11:20www.rooversadvocatuur.nl/rel.php83.172.140.27ns1.securenameserver5.net.redirects to exploit kit25459NL
2013/06/17_11:56sunny99.cholerik.cz/plugins/3yvPRqFJ.php77.93.211.244f.banan.cz.redirects to exploit kit24971CZ
2013/06/05_20:17www.tdms.saglik.gov.tr/KDV_Guncel_Tevkifat_Oranlari.htm212.175.169.227-compromised sites leads to exploit kit9121TR
2013/06/03_19:38-143.95.1.6/31b9326e5a618c53/a.phpip-143-95-1-6.iplocal.exploit kit36444US
2013/05/20_20:35youtibe.com173.193.106.10173.193.106.10-static.reverse.softlayer.com.Redirects to Rogue.FakeFlashPlayer36351US
2013/05/20_18:00yougube.com199.223.209.169server.ambertechnic.com.Redirects to Rogue.FakeFlashPlayer25847US
2013/05/20_18:00youtuhe.com174.140.17.100-Redirects to Rogue.FakeFlashPlayer32311US
2013/05/12_14:55-103.4.218.22:8080//get/e3943d7369aa6add911aca18b3a507f4.exe-Trojan.FakeAlert131472TH
2013/05/12_14:55-180.235.132.29:8080//get/e3943d7369aa6add911aca18b3a507f4.exe-Trojan.FakeAlert55639HK
2013/05/12_14:55-208.88.5.229:8080//get/e3943d7369aa6add911aca18b3a507f4.exed05805e4.powerprojct.ca.Trojan.FakeAlert36218CA
2013/05/12_14:55-217.8.253.250:8080//get/e3943d7369aa6add911aca18b3a507f4.exemail.trcontents.co.uk.Trojan.FakeAlert20738GB
2013/05/12_14:55-5.135.115.100:8080//get/e3943d7369aa6add911aca18b3a507f4.exe-Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.193:8080//get/e3943d7369aa6add911aca18b3a507f4.exeserv2-am.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.194:8080//get/e3943d7369aa6add911aca18b3a507f4.exeserv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.195:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta1.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.196:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta2.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.197:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta3.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.198:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta4.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.199:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta5.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.201:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta7.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.202:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta8.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.203:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta9.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.204:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta10.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.205:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta11.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.206:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta12.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.207:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta13.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.208:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta14.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.209:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta15.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.210:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta16.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.211:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta17.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.212:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta18.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.213:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta19.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.214:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta20.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.215:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta21.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.216:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta22.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.217:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta23.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.218:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta24.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.219:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta25.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.220:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta26.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.221:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta27.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-5.135.115.222:8080//get/e3943d7369aa6add911aca18b3a507f4.exemta28.serv1-am-mta.com.Trojan.FakeAlert16276FR
2013/05/12_14:55-66.175.218.117:8080//get/e3943d7369aa6add911aca18b3a507f4.exeli513-117.members.linode.com.Trojan.FakeAlert6939US
2013/05/12_14:55-78.110.162.72:8080//get/e3943d7369aa6add911aca18b3a507f4.exe78-110-162-72.rdns.ldni.net.Trojan.FakeAlert42831GB
2013/05/12_14:55-78.110.162.73:8080//get/e3943d7369aa6add911aca18b3a507f4.exe78-110-162-73.rdns.ldni.net.Trojan.FakeAlert42831GB
2013/05/12_14:55-78.110.162.79:8080//get/e3943d7369aa6add911aca18b3a507f4.exe78-110-162-79.rdns.ldni.net.Trojan.FakeAlert42831GB
2013/05/12_14:55-85.214.133.237:8080//get/e3943d7369aa6add911aca18b3a507f4.exegamelevel.de.Trojan.FakeAlert6724DE
2013/05/12_14:55-94.23.38.214:8080//get/e3943d7369aa6add911aca18b3a507f4.exens368891.ovh.net.Trojan.FakeAlert16276FR
2013/05/10_17:35-5.135.115.193:8080/get/e3943d7369aa6add911aca18b3a507f4.exeserv2-am.com.trojan16276FR
2013/05/10_17:35-5.135.115.194:8080/get/e3943d7369aa6add911aca18b3a507f4.exeserv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.195:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta1.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.196:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta2.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.197:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta3.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.198:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta4.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.199:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta5.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.100:8080/get/e3943d7369aa6add911aca18b3a507f4.exe-trojan16276FR
2013/05/10_17:35-5.135.115.201:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta7.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.202:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta8.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.203:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta9.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.204:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta10.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.205:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta11.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.206:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta12.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.207:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta13.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.208:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta14.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.209:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta15.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.210:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta16.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.211:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta17.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.212:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta18.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.213:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta19.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.214:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta20.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.215:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta21.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.216:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta22.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.217:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta23.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.218:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta24.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.219:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta25.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.220:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta26.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.221:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta27.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-5.135.115.222:8080/get/e3943d7369aa6add911aca18b3a507f4.exemta28.serv1-am-mta.com.trojan16276FR
2013/05/10_17:35-78.110.162.72:8080/get/e3943d7369aa6add911aca18b3a507f4.exe78-110-162-72.rdns.ldni.net.trojan42831GB
2013/05/10_17:35-78.110.162.73:8080/get/e3943d7369aa6add911aca18b3a507f4.exe78-110-162-73.rdns.ldni.net.trojan42831GB
2013/05/10_17:35-78.110.162.79:8080/get/e3943d7369aa6add911aca18b3a507f4.exe78-110-162-79.rdns.ldni.net.trojan42831GB
2013/05/10_17:35-94.23.38.214:8080/get/e3943d7369aa6add911aca18b3a507f4.exens368891.ovh.net.trojan16276FR
2013/05/10_17:35-217.8.253.250:8080/get/e3943d7369aa6add911aca18b3a507f4.exemail.trcontents.co.uk.trojan20738GB
2013/05/10_17:35-103.4.218.22:8080/get/e3943d7369aa6add911aca18b3a507f4.exe-trojan131472TH
2013/05/10_17:35-85.214.133.237:8080/get/e3943d7369aa6add911aca18b3a507f4.exegamelevel.de.trojan6724DE
2013/05/10_17:35-94.23.38.214:8080/get/e3943d7369aa6add911aca18b3a507f4.exens368891.ovh.net.trojan16276FR
2013/05/10_17:35-180.235.132.29:8080/get/e3943d7369aa6add911aca18b3a507f4.exe-trojan55639HK
2013/05/10_17:35-208.88.5.229:8080/get/e3943d7369aa6add911aca18b3a507f4.exed05805e4.powerprojct.ca.trojan36218CA
2013/05/10_17:35-66.175.218.117:8080/get/e3943d7369aa6add911aca18b3a507f4.exeli513-117.members.linode.com.trojan6939US
2013/05/06_09:50-198.50.194.26/statistic/increases/street_throwing_keeps.php-exploit kit16276CA
2013/04/17_08:58-61.63.123.44/news.html61-63-123-44.nty.dynamic.tbcnet.net.tw.iframe leads to Java exploit4780TW
2013/04/16_00:32freefblikes.phpnet.us209.190.85.252www.quark.byethost4.com.VBScript.Trojan.IRC10297US
2013/04/07_09:31www.daspar.net/components/.kkcpgr.php?action=ss00_323176.9.90.164stegro-cos-mpr-200.unaxus.net.Trojan.Krypt24940DE
2013/03/20_12:34customsboysint.com/1/25/human-head-wireframe72.167.131.8p3slh153.shr.phx3.secureserver.net.redirecting to Sweet Orange exploit kit with Google referrer26496US
2013/03/20_09:36bbs.bjchun.com/report.htm115.47.69.193-redirects to exploit kit17964CN
2013/03/13_14:46mycleanpc.tk/download/31.170.163.144-leads to malicious download on Mediafire47583US
2013/02/11_08:24www.offerent.com/tmp/5lro65.php?receipt_print=825_417011330200.58.119.30texila.dattaweb.com.trojan inside zip file27823AR
2013/01/26_00:14-78.110.62.95/airyoleg.php?boutfage=88982195-62-110-78.net.hts.ru.Impact exploit kit31240RU
2013/01/26_00:14-78.110.62.95/jentrate.php95-62-110-78.net.hts.ru.Part of Impact exploit kit31240RU
2013/01/26_00:14-78.110.62.95/jeanfage/aimoping.jar95-62-110-78.net.hts.ru.Part of Impact exploit kit31240RU
2013/01/26_00:14-78.110.62.95/jeanfage/jokevity.jar95-62-110-78.net.hts.ru.Part of Impact exploit kit31240RU
2013/01/26_00:14-78.110.62.95/jeanfage/test.jar95-62-110-78.net.hts.ru.Part of Impact exploit kit31240RU
2013/01/18_08:22-66.230.143.147/it/-Dialler.GlobalAccess23393US
2013/01/11_07:0850efa6486f1ef.skydivesolutions.be/news/refusal/natural.cgi93.189.40.173-Cool exploit kit41853RU
2013/01/05_20:04cwmgaming.com198.27.64.67ns4004653.ip-198-27-64.net.iFrames to Exploit16276CA
2013/01/04_18:06-82.113.204.228:8080/get/lite.dll.crp-malware calls home30848IT
2012/12/26_19:46webordermanager.com98.124.199.1redirector-sjl.enom.com.Redirects to exploit21740US
2012/12/26_19:46videoflyover.com98.124.198.1redirector-ash.enom.com.redirects to exploit21740US
2012/12/21_02:03port.bg/wfgv.html?php=receipt91.196.124.59host124-59.superhosting.bg.Redirects to exploit8262BG
2012/12/10_15:48private.hotelcesenaticobooking.info/r/l/updating-bugs_keeping.php93.190.43.44-Cool exploit kit6849UA
2012/12/10_09:06analxxxclipsyjh.dnset.com/latest/amateur_dog_sex_01.avi.exe94.199.53.203ded-srv-pool-53-203.23net.hu.trojan30836HU
2012/12/02_21:28-212.84.187.68/job.php?php=receipt68-187.skymarket.net.uk.trojan inside zip file20860GB
2012/11/27_10:18winlock.usa.cc/k8uiaii89819aj/get.php?f=7109.163.231.219lh20422.voxility.net.backdoor39743RO
2012/11/26_08:23-85.143.166.181/t221112d/i.php?token=default85-143-166-181.clodo.ru.CritXPack exploit kit56534RU
2012/11/25_18:48gravityexp.com/go.php?sid=1246.163.117.144lvps46-163-117-144.dedicated.hosteurope.de.redirects to exploit kit20773DE
2012/11/23_07:35mlpoint.pt/Scripts/d.html81.88.48.97-obfuscated iframe leads to Nuclear exploit kit39729IT
2012/11/22_12:32ukrfarms.com.ua/images/tovar.jpg.php213.227.207.89h1-kv.alkar.net.iframe leads to CritXPack exploit kit6703UA
2012/11/22_12:32babos.scrapping.cc/v211112n/i.php?token=forum62.76.47.1262-76-47-12.clodo.ru.CritXPack exploit kit48172RU
2012/11/19_18:52-209.236.67.163/8bd7d5194/wergwrg3gwer209.236.67.163.static.westdc.net.trojan29854US
2012/11/19_18:52upswings.net/track.php?c005174.120.146.138shared0003.apthost.com.redirects to exploit kit21844US
2012/11/19_18:52www.lyzgs.com/track.php?c005203.158.16.75-redirects to exploit kit17964CN
2012/11/19_18:52weboxmedia.by/track.php?c00577.222.40.74-redirects to exploit kit44112RU
2012/11/19_07:51natural.buckeyeenergyforum.com/r/l/the-joint.php193.0.179.20frolov4me.biz.Cool exploit kit57062RU
2012/11/19_07:51narrow.azenergyforum.com/r/l/brown_season.php193.0.179.20frolov4me.biz.Cool exploit kit57062RU
2012/11/18_15:21xpornstarsckc.ddns.name/latest/xxx-porn-movie.avi.exe94.199.53.203ded-srv-pool-53-203.23net.hu.trojan30836HU
2012/11/13_10:00-61.19.251.27/web/cb.php-CrimeBoss exploit kit9931TH
2012/10/26_23:28-69.55.49.159/Ice/index.php-exploit kit46652US
2012/10/26_23:28-69.55.49.159/config.bin-Zeus config file46652US
2012/10/26_23:28-69.55.49.159/gate.php-Zeus drop zone46652US
2012/10/24_20:51xamateurpornlic.www1.biz/latest/xxx-porn-movie.avi.exe94.199.53.203ded-srv-pool-53-203.23net.hu.trojan ZeroAccess/Sirefef30836HU
2012/08/30_06:59www.perupuntocom.com/claroideas.exe68.178.254.187p3slh042.shr.phx3.secureserver.net.trojan26496US
2012/07/20_23:08elew72isst.rr.nu/mm.php?d=x1194.28.115.150h150-115.net.lan-rybnitsa.com.Leads to Fake AV48691MD
2012/07/15_00:08-203.63.5.190/2m0AZfuu/WM4.exe24x7Shop.cyberefficiency.com.au.Trojan2764AU
2012/07/14_19:38-109.163.225.232/download.php?id=25lh17626.limehost.ro.Trojan39743RO
2012/07/05_12:06-91.202.244.122/files/2f646-Ransom WindowsSecurity44784UA
2012/07/05_12:06-91.202.244.122/files/2c753-Ransom WindowsSecurity44784UA
2012/07/05_12:06-91.202.244.122/files/36cf4-Ransom WindowsSecurity44784UA
2012/07/03_13:43-69.162.82.26/version2/webber/1/config.bin26-82-162-69.static.reverse.lstn.net.Zeus config file46475US
2012/07/03_13:43-69.162.82.26/version2/webber/1/gate.php26-82-162-69.static.reverse.lstn.net.Zeus drop zone46475US
2012/07/03_13:17wetjane.x10.mx/69.175.121.66boru.x10hosting.com.Java exploit32475US
2012/06/29_21:50-188.190.98.132/ph/dmg5.php?i=8ip-188-190-98-132.hosted-in.infiumhost.com.trojan Gataka197145UA
2012/06/28_21:29-91.223.82.58/~rivernig/19/config.bin-Zeus config file51430NL
2012/06/28_21:29-91.223.82.58/~rivernig/19/gate.php-Zeus drop zone51430NL
2012/06/26_05:59ns1.updatesdns.org/static.htmls46.17.102.124node-46.17.102.124.reverse.x4b.org.zeus config file49335RU
2012/06/21_19:08-216.18.228.149/~anon/jdb/inf.php?id=455cec1f823b2f0a13dd26655ac6bcfa-Java drive-by33569US
2012/06/19_07:03www.panazan.ro/online/libraries/pattemplate/patTemplate/Modifier/HTML/im/o/z/3pingo/cfg.bin89.42.216.47server20.whmpanels.com.zeus config file5606RO
2012/06/19_07:03www.panazan.ro/online/libraries/pattemplate/patTemplate/Modifier/HTML/im/o/z/3pingo/gate.php89.42.216.47server20.whmpanels.com.zeus drop zone5606RO
2012/06/01_21:45-95.163.104.80/spielberg/start.php-Ransom message text12695RU
2012/05/31_21:49-184.154.76.237/search.php?q=fa16f5d3def51288184.154.76.237.virtualsrv.com.Exploit32475US
2012/05/31_21:49dimenal.com.br/cUEDN4w2/index.html?s=883&lid=2267&elq=11f7b1b5179f45b09737bdf10d0fe61f187.19.96.13server03.certto.com.br.Leads to exploit kits28130BR
2012/05/31_21:49dimenal.com.br/HHv0oxBP/index.html?s=883&lid=2298&elq=11f7b1b5179f45b09737bdf10d0fe61f187.19.96.13server03.certto.com.br.Leads to exploit kits28130BR
2012/05/31_21:49miespaciopilates.com/7Fy2FzNg/index.html69.61.18.58linux51.webhosting-network-services.com.Leads to exploit kits22653US
2012/05/31_21:49puenteaereo.info/fHA5c5iw/index.html?s=883&lid=2231&elq=11f7b1b5179f45b09737bdf10d0fe61f50.22.86.1050.22.86.10-static.reverse.softlayer.com.Leads to exploit kits36351US
2012/05/31_21:49puenteaereo.info/fHA5c5iw/index.html?s=883&lid=2270&elq=11f7b1b5179f45b09737bdf10d0fe61f50.22.86.1050.22.86.10-static.reverse.softlayer.com.Leads to exploit kits36351US
2012/05/31_21:49puenteaereo.info/KE3pt5Ye/index.html?s=883&lid=2328&elq=11f7b1b5179f45b09737bdf10d0fe61f50.22.86.1050.22.86.10-static.reverse.softlayer.com.Leads to exploit kits36351US
2012/05/10_12:55-91.202.244.89/files/920b8-Ransom WindowsSecurity44784UA
2012/05/10_12:55-91.202.244.89/files/443aa-Ransom WindowsSecurity44784UA
2012/05/07_21:32-91.202.244.89/files/957f2-Ransom.WindowsSecurity44784UA
2012/05/07_21:32-91.202.244.89/files/a69fa-Ransom.WindowsSecurity44784UA
2012/05/07_21:32-91.202.244.89/files/bdd35-Ransom.WindowsSecurity44784UA
2012/05/07_13:49-91.202.244.89/files/957f2-Ransom WindowsSecurity44784UA
2012/05/07_13:49-91.202.244.89/files/a69fa-Ransom WindowsSecurity44784UA
2012/05/07_13:49-91.202.244.89/files/bdd35-Ransom WindowsSecurity44784UA
2012/05/05_12:32-46.166.146.110/-AnonJDB Control Panel57668GB
2012/05/02_13:48-194.183.224.73/out/out.htmwww.van-helden.net.Java exploits serves Poison Ivy5463BE
2012/04/30_16:15-91.223.223.244/c.bin91.223.223.244.hostpro.com.ua.zeus config file21219UA
2012/04/30_16:15-91.223.223.244/b.php91.223.223.244.hostpro.com.ua.zeus drop zone21219UA
2012/04/30_16:15-188.40.168.128/c.binstatic.128.168.40.188.clients.your-server.de.zeus config file24940DE
2012/04/30_16:15-188.40.168.128/b.phpstatic.128.168.40.188.clients.your-server.de.zeus drop zone24940DE
2012/04/20_15:11-91.196.216.64/s.php?ref=referrer&cls=colorDepth&sw=width&sh=height&dc=charset&lc=location&ua=userAgent-Exploit43239RU
2012/04/16_14:40police11.provenprotection.net/?1284cf325cf33aa48aeb29aee89b347391.195.254.86-Ransom message text43997RU
2012/04/16_14:40-91.195.254.86/?1284cf325cf33aa48aeb29aee89b3473-Ransom message text43997RU
2012/04/16_14:40-91.195.254.74/?b933de68eae80dadb34b9d4b889575eb-Ransom message text43997RU
2012/04/12_20:21-91.195.254.71/?a8b15ffc5b06664b1e119cc1c6942b3d-trojan Ransom message text43997RU
2012/04/12_15:12-69.194.192.229/q.php?f=7245d&e=2-Zeus trojan14670US
2012/04/11_20:36-62.109.29.101/a/xwy.php?i=15geovanne.fvds.ru.Zeus trojan29182LU
2012/04/10_08:31-88.190.22.72:8080/navigator/jueoaritjuir.phpsd-29537.dedibox.fr.Phoenix exploit kit12322FR
2012/04/10_08:31-89.31.145.154:8080/navigator/jueoaritjuir.phpvserver-mpfppr2.nexen.net.Phoenix exploit kit41628FR
2012/04/10_08:31-62.85.27.129:8080/navigator/jueoaritjuir.phpsw-gbit-1.gw.27-129.ime.lv.Phoenix exploit kit39201LV
2012/04/10_08:31-219.94.194.138:8080/navigator/jueoaritjuir.php-Phoenix exploit kit9371JP
2012/04/09_12:25-112.78.124.115:8080/navigator/jueoaritjuir.php-Phoenix exploit kit9371JP
2012/04/08_09:23-188.127.249.241/~alert/alert.php?id=5-Message text for Ransom48172RU
2012/04/05_08:08-211.44.250.173:8080/navigator/jueoaritjuir.php-Phoenix exploit kit9318KR
2012/04/05_08:08-180.235.150.72:8080/navigator/jueoaritjuir.php-Phoenix exploit kit45731ID
2012/04/02_20:11-193.107.19.80/inter/gate.php?hwid=4281525696&pc=COMPUTERNAME&localip=127.0.0.1&winver=x32-malware calls home197794RU
2012/04/01_19:58-178.248.85.67/zeus/config.bin67.85.248.178.sta.211.ru.zeus config file41794RU
2012/04/01_19:58-178.248.85.67/zeus/gate.php67.85.248.178.sta.211.ru.zeus drop zone41794RU
2012/03/17_20:32-31.186.102.170/lolomgfucku/3214spackasd324/-Bleeding Life exploit kit49505RU
2012/03/17_20:32-31.186.102.170/lolomgfucku/3214spackasd324//download_file.php?e=JavaSignedApplet-trojan49505RU
2012/02/26_21:35cswilliamsburg.com/site7/data/174.122.148.945e.94.7aae.static.theplanet.com.CrimePack exploit kit21844US
2011/11/16_18:14nobodyspeakstruth.narod.ru/upload/main.exe87.250.250.83wrz.yandex.ru.trojan13238RU
2011/11/10_21:52-202.157.165.152/zfin.html-redirects to exploit kit9892SG
2011/10/21_23:55-121.10.107.78:88/b7/0.exe-trojan OnlineGames4134CN
2011/10/21_23:55-121.10.107.78:88/b7/1.exe-trojan OnlineGames4134CN
2011/10/21_23:55-121.10.107.78:88/b7/3.exe-trojan OnlineGames4134CN
2011/10/21_23:55-121.10.107.78:88/b7/4.exe-trojan OnlineGames4134CN
2011/10/21_23:55-121.10.107.78:88/b7/5.exe-trojan OnlineGames4134CN
2011/10/21_23:55-121.10.107.78:88/b7/6.exe-trojan OnlineGames4134CN
2011/10/21_23:55-121.10.107.78:88/b7/7.exe-trojan OnlineGames4134CN
2011/10/21_23:55-121.10.107.78:88/b7/8.exe-trojan OnlineGames4134CN
2011/10/21_23:55-121.10.107.78:88/b7/9.exe-trojan OnlineGames4134CN
2011/10/21_23:55-121.10.107.78:88/b7/10.exe-trojan OnlineGames4134CN
2011/10/21_23:55-121.10.107.78:88/b7/11.exe-trojan OnlineGames4134CN
2011/10/21_23:55-121.10.107.78:88/b7/13.exe-trojan OnlineGames4134CN
2011/09/18_15:59elocumjobs.com/_sql/1/index.php?spl=mdac78.136.20.106132775-www1.ecarers.com.fake av15395GB
2011/09/12_18:49www.infra.by/conflq.php91.149.157.133vh16.hoster.by.obfuscated iframe leads to exploit kit6697BY
2011/08/31_21:38seoholding.com/13/boardhost80.91.176.192ds2.hosted.in.redirects to trojan21219UA
2011/08/17_23:29crackzone.net/data/Super_Mp3_Download_Version_3.3.4.6_serial_keys_gen-bee3afe71a.html188.95.53.17-Rootkit.0Access57172EU
2011/07/31_19:47www.makohela.tk/kingofthelamers.jar72.20.53.34server9020.alkareklam.com.java exploit25761US
2011/07/30_20:33-46.16.240.18/9VBMa76FFnB4VAYu0X5j755pMiSyVrcV?s=odayz&-trojan51632UA
2011/07/29_23:50seoholding.com/13/overblog&usg=AFQjCNGS7Xe0yilVQ6lGj3Oroonf7-gfhg80.91.176.192ds2.hosted.in.Redirects to trojan21219UA
2011/07/28_01:54seoholding.com/13/overblog80.91.176.192ds2.hosted.in.Redirects to trojan21219UA
2011/07/28_01:54seonetwizard.com/in.cgi?380.91.176.192ds2.hosted.in.Redirects to trojan21219UA
2011/07/26_18:33-46.16.240.18/9VBMa76FFnB4VAYu0X5j755pMiSyVrcV?s=mdacot-trojan51632UA
2011/07/21_15:16-77.221.149.219/get/311/2363977.221.149.219.addr.datapoint.ru.Fraud Skype setup30968RU
2011/07/14_05:52-79.142.65.179/crack-keygen/592147/emu8086-300.htmlhosted-by.altushost.com.Leads to Renos trojan49544EU
2011/07/14_05:52-79.142.65.179/crack-keygen/223644/wavclean-183.htmlhosted-by.altushost.com.Leads to Renos trojan49544EU
2011/07/14_05:52-79.142.65.179/crack-keygen/390415/pdf-snake-v237-for-adobe-acrobat.htmlhosted-by.altushost.com.Leads to Renos trojan49544EU
2011/07/09_02:48-186.190.213.10/x/wan18.b2bprovidersite.com.Trojan.FakeAV52302PA
2011/07/04_19:06-186.190.213.10/dl/wan18.b2bprovidersite.com.trojan52302PA
2011/05/30_10:22www.casamama.nl/109.72.86.5nl05.pcextreme.nl.obfuscated iframe on compromised site leads to exploit kit48635NL
2011/04/01_04:46www.widestep.com/files/ws_qk_install.exe205.186.183.224ekiaioocks.gs07.gridserver.com.Win32/Agent.HSDNOGR31815US
2011/03/26_16:01-95.64.8.76/hex/jwh.php?i=15-fake av49873RO
2011/03/22_19:21-70.43.40.116/PRISM/CSS/a.gif70.43.40.116.nw.nuvox.net.trojan Banload11456US
2011/03/22_19:21-70.43.40.116/PRISM/CSS/b.gif70.43.40.116.nw.nuvox.net.trojan11456US
2011/03/22_19:21-70.43.40.116/PRISM/CSS/c.gif70.43.40.116.nw.nuvox.net.trojan11456US
2011/03/20_17:23-70.38.124.97/distrmaincp/-SpyEye C&C32613CA
2011/03/20_17:23-91.220.62.84/123/index.php-Eleonore Exploits pack version 1.4.4mod51699UA
2011/03/20_17:23-91.220.62.84/123/stat.php-control panel of Eleonore Exploits pack version 1.4.4mod51699UA
2011/03/20_17:23-91.220.62.84/123/load.php?spl=mdac-trojan downloader51699UA
2011/03/20_17:23-91.220.62.84/info/load.php?file=0-backdoor Cycbot51699UA
2011/03/20_17:23-91.220.62.84/info/load.php?file=1-fake av51699UA
2011/03/18_19:29-69.50.192.250:8000-malware calls home18866US
2011/03/13_21:47download207.mediafire.com/2ezaemp68lyg/fe8lc6kqa1f06n1/Grand+Theft+Modification.zip38.114.196.226-trojan46179US
2011/03/12_14:57seet10.jino.ru81.177.139.113srv16-h-st.jino.ru.Trojan8342RU
2011/03/12_14:57vkont.bos.ru194.186.208.8as3.centre.ru.Trojan3216RU
2011/03/11_15:52-174.127.70.195/8545/4544/174.127.70.195.static.midphase.com.fake AV36351US
2011/02/25_16:20rat-on-subway.mhwang.com/212.117.169.139ip-212-117-169-139.server.lu.Compromised site leading to fake AV5577LU
2011/02/24_21:30wallpapers91.com67.23.129.220-Exploit12053CA
2011/02/24_21:26skiholidays4beginners.com/subtraction-scorpio-male-and-virgo-female-compatiblity/67.215.248.8-Compromised site leading to fake AV29761US
2011/02/24_21:26patrickhickey.eu/concertina-free-short-skits-scripts-in-hindi-for-independence-day/89.234.64.136web4.hosting.digiweb.ie.Compromised site leading to fake AV31122IE
2011/02/24_21:26rolemodelstreetteam.invasioncrew.com/raazuc/Dossier-For-M98.131.132.1rev.opentransfer.com.1.132.131.98.in-addr.arpa.Compromised site leading to fake AV32392US
2011/02/24_21:26hy-brasil.mhwang.com/212.117.169.139ip-212-117-169-139.server.lu.Compromised site leading to fake AV5577LU
2011/02/24_21:26marx-brothers.mhwang.com/212.117.169.139ip-212-117-169-139.server.lu.Compromised site leading to fake AV5577LU
2011/02/24_21:26networkmedical.com.hk/defeating-innova-champion-discs-inc-raven/66.7.213.86queen.host-care.com.Compromised site leading to fake AV33182US
2011/02/22_20:34-71.235.85.177/images/xc.gifc-71-235-85-177.hsd1.ct.comcast.net.trojan Banload7015US
2011/02/22_20:34-200.13.244.245/cw-assenda/bin/es/es/post.aspstatic-epm200-13-244-245.epm.net.co.malware calls home13489CO
2011/02/22_20:34-200.13.244.245/cw-assenda/bin/es/es/contador.aspstatic-epm200-13-244-245.epm.net.co.infection counter13489CO
2011/02/21_08:18-91.200.240.7/T6yRslk8JrR5sOpskHs51L/bin/config.bin-SpyEye C&C48709UA
2011/02/20_11:07-194.247.58.174/js/config.binvpn18-dip-t-pool29-194-247-58.174.sevpn.com.SpyEye config file52093UA
2011/02/20_10:48alissonluis-musico.sites.uol.com.br/mar.jpg200.147.33.21200-147-33-21.static.uol.com.br.trojan Banker7162BR
2011/02/19_16:50infoweb-coolinfo.tk/90/?afid=9046.21.169.41-fake av42755NL
2011/02/18_20:25-91.200.240.7/T6yRslk8JrR5sOpskHs51L/bin/config.bin-SpyEye config file48709UA
2011/02/18_20:25-91.200.240.7/T6yRslk8JrR5sOpskHs51L/gate.php-SpyEye C&C48709UA
2011/02/18_18:03bookofkisl.com/album.php67.195.145.141p8p-a.geo.vip.sp1.yahoo.com.irc backdoor36752US
2011/02/13_22:50hosting-controlpr.tk/go/?afid=5141.223.53.147host-41.223.53.147.citynet.com.eg.fake av33785EG
2011/02/13_22:04hosting-controlpin.tk/go/?afid=5141.223.53.147host-41.223.53.147.citynet.com.eg.fake av33785EG
2011/02/13_10:45hosting-controlid1.tk/go/?afid=9041.223.53.147host-41.223.53.147.citynet.com.eg.fake av33785EG
2011/02/12_09:57-194.247.58.51/ir7.php?i=15vpn6-dip-t-pool2-194-247-58.51.sevpn.com.trojan SpyEye52093UA
2011/02/12_09:57hosting-controlnext.tk/go/?afid=5141.223.53.147host-41.223.53.147.citynet.com.eg.fake av33785EG
2011/02/12_09:57hosting-controlid1.tk/go/?afid=15641.223.53.147host-41.223.53.147.citynet.com.eg.fake av33785EG
2011/02/10_08:05faq-candrive.tk/go/?afid=51206.217.131.101host.colocrossing.com.fake av36352US
2011/02/08_20:17-195.80.151.59/7box/dqj.php?i=15-trojan Bamital50877DE
2011/02/05_20:56orkut.krovatka.su/imagem-542454.jpg194.186.88.38ftp.krovatka.su.trojan Banker3216RU
2011/02/05_17:53-91.200.240.7/Yh89RfaPh7bBss1zOFn7saOaOOa/bin/config.bin-SpyEye config file48709UA
2011/02/05_17:53-91.200.240.7/Yh89RfaPh7bBss1zOFn7saOaOOa/gate.php-SpyEye C&C48709UA
2011/02/03_10:51-46.17.101.2/main/gate.php-SpyEye C&C48211RU
2011/02/02_18:13www.kcta.or.kr/js/json.js210.109.97.193193.0-255.97.109.210.in-addr.arpa.obfuscated iframe leads to exploit9848KR
2011/02/02_18:13www.spris.com/images/log.txt210.114.221.53-IE exploit4670KR
2011/02/02_13:30-195.242.182.30/xxx1/xob.php?i=15-trojan44994EU
2011/02/01_17:30-186.202.16.186/winjar2011.dllcpro0867.publiccloud.com.br.trojan Bancos27715BR
2011/02/01_08:21-67.21.76.33/fvp.htm-IE exploit46844US
2011/02/01_08:21-67.21.76.33/rcf.htm-IE exploit46844US
2011/01/30_21:40-208.76.54.224/shop/jp.php?i=15-fake av47869US
2011/01/30_20:52-95.169.186.126/wp-logs/cm.php?i=15ns.km33904.keymachine.de.trojan downloader31103DE
2011/01/26_19:40-194.247.58.96/soln_1/knb.php?i=2vpn10-dip-t-pool2-194-247-58.96.sevpn.com.trojan SpyEye52093UA
2011/01/26_19:40-194.247.58.95/mypanel/gate.php?guid=5.1.2600!SANDBOX0!D06F0742&ver=10305&ie=6.0.2900.2180&os=5.1.2600&ut=Admin&ccrc=169E4359&md5=72079beedbc873cb73e7326ef3f8de56&plg=customconnector;webfakes;socks5;ftpbc;ccgrabber&stat=onlinevpn10-dip-t-pool2-194-247-58.95.sevpn.com.SpyEye C&C52093UA
2011/01/25_18:09www.downloaddirect.com/software/vlc-player/256767.55.67.250welcome23.webcamclub.com.trojan27257US
2011/01/23_20:06site-checksite.tk/go/?afid=14474.63.76.18pc1.regionaladnetwork.com.fake av30058US
2011/01/21_20:32-173.244.192.245/zfotp.htm173.244.192.245.static.midphase.com.IE exploit36351US
2011/01/20_11:16-71.7.3.60/webctrl_client/a/xp001.gifgrnl-static-04-0012.dsl.iowatelecom.net.trojan Banker30160US
2011/01/17_10:30-110.45.136.181/stat/x.asp-IE exploit3786KR
2011/01/14_18:43-89.187.50.195/index.php?3104c3a31c438f61b5e85b6b6c751c0e-exploit kit25129MD
2011/01/14_18:43-89.187.50.195/server_privileges.php?03b32fe00ceb95f0a9fc8dd78a0d58d1=3-trojan25129MD
2011/01/12_19:15-209.216.193.107/registrydoktor-newde.phpwww.antivirus-reports.org.fake av21607US
2011/01/12_14:33-220.128.152.141/aspnet_client/system_web/1_1_4322/flash.htm220-128-152-141.HINET-IP.hinet.net.leads to trojan Banker3462TW
2011/01/11_19:16-71.7.3.60/webctrl_client/1_0/TreeImages/rtl/l1.gifgrnl-static-04-0012.dsl.iowatelecom.net.trojan30160US
2011/01/11_19:16-71.7.3.60/webctrl_client/1_0/TreeImages/rtl/l2.gifgrnl-static-04-0012.dsl.iowatelecom.net.trojan30160US
2011/01/11_19:16-71.7.3.60/webctrl_client/1_0/TreeImages/rtl/l3.gifgrnl-static-04-0012.dsl.iowatelecom.net.trojan30160US
2011/01/10_20:06url-cameralist.tk/go/?afid=136206.217.137.210mail.ogairealeyes.com.fake av36352US
2011/01/10_20:06-208.76.54.216/shop/gva.php?i=2-fake av47869US
2011/01/08_17:42-173.192.136.92/sdh.htm173.192.136.92-static.reverse.softlayer.com.exploit36351US
2011/01/08_17:42-173.192.136.92/tow.htm173.192.136.92-static.reverse.softlayer.com.exploit36351US
2011/01/03_17:34beldiplomcom.75.com1.ru/true.php89.108.66.188cp60.agava.net.exploit kit43146RU
2011/01/03_17:34beldiplomcom.75.com1.ru/loading.php?spl=mdac89.108.66.188cp60.agava.net.trojan FireThief43146RU
2010/12/31_23:36-125.141.196.59/A.asp-IE exploit4766KR
2010/12/31_19:40-74.81.73.134:9082/exemple.com/index.phpgnax-ded100.simplehelix.com.Eleonore exploit pack16626US
2010/12/31_19:40-74.81.73.134:9082/exemple.com/load.php?spl=javasgnax-ded100.simplehelix.com.trojan16626US
2010/12/29_19:10-195.234.124.41/kor/du.php?i=15-trojan20489UA
2010/12/28_23:01-61.57.227.5/js/b1.aspupgroup.piinet.net.IE exploit17710TW
2010/12/28_23:01-61.57.227.5/js/b3.aspupgroup.piinet.net.IE exploit17710TW
2010/12/28_18:17-116.255.180.231/elt/e/index.php-Eleonore Exploits pack v1.4.4mod4837CN
2010/12/28_18:17-116.255.180.231/elt/e/stat.php-control panel of Eleonore Exploits pack v1.4.4mod4837CN
2010/12/27_23:22-69.50.202.16/stop/xsd.php?i=15-trojan18866US
2010/12/27_19:51-91.217.162.199/images/hni.php?i=15-trojan51441UA
2010/12/27_17:55-91.207.182.56/xxx2/kt.php?i=15-fake av48280UA
2010/12/27_17:18-193.107.172.11/abr.v.alg/gate.php?guid=User!SANDBOX2!D06F0742&ver=10299&stat=ONLINE&ie=6.0.2900.2180&os=5.1.2600&ut=Admin&ccrc=4C78BF5E&md5=dbe81c844053e377da221d2d0bdb34d4-SpyEye C&C196957UA
2010/12/27_17:18-193.107.172.11/abr.v.alg/bin/config.bin-SpyEye config file196957UA
2010/12/26_11:57-67.21.76.6/zhk.htm-IE exploit46844US
2010/12/26_11:57-67.21.76.6/zfc.htm-IE exploit46844US
2010/12/26_10:17-211.234.117.47/index.htm-IE exploit3786KR
2010/12/25_13:57-173.244.194.236/goi.php?i=15173.244.194.236.static.midphase.com.trojan36351US
2010/12/25_13:35-116.255.180.231/smc/bue.php?i=15-trojan4837CN
2010/12/25_13:35-69.64.63.204/hqi.php?i=15balder038.server4you.net.trojan30083US
2010/12/21_21:00-91.217.162.239/shikel/dz2.php?i=15-trojan51441UA
2010/12/21_21:00-69.50.209.109/stat/bv.php?i=15-trojan18866US
2010/12/21_06:50-91.213.217.91/index.php?9t=w3N0U4cAIZamABawd7aWMGAE56&4TBG=28CPTYS8X181QOG5P6PTtO&80Il=WdbMk8vV24%2FPiw7&009jY=2V3N01&00=ATK2HJ1U73F8&8Ad03=MCoqPV&7AQe=OBVYMUtDK&0Cj9=VZPPUSVI5ZR9DI77X&46l5k=Q0E6IYM722K66&H7W=SgdOCT9iMD9gDmpSCF&h6=zBHtRBCprYmlnamd9BGJkTSE6Qw%3D%3D&MYyjG=JmfSNUZFJtelNxLwFm&O1u5v=VgclWgU-fake scanner page49806UA
2010/12/19_16:35-195.234.124.40/kor/du.php?i=15-trojan20489UA
2010/12/18_20:26-211.234.117.132/index.htm-IE exploit3786KR
2010/12/16_19:46-91.213.174.10/KillEXE.exe-trojan Banker29106UA
2010/12/16_19:46-69.197.135.51/ins/gts/xw.php?i=15-trojan32097US
2010/12/16_17:28-98.158.178.231/pics.scrwhm.profissionalizando.org.backdoor32780US
2010/12/15_21:06-91.213.174.44/KillEXE.exe-trojan29106UA
2010/12/15_19:15-189.108.44.42/envc.php?praquem=dianalnogueira@gmail.com&titulo=Empresas%20000000-C9913A97%2011:11:47&texto=Sony%20Samsung%20Philipis%20Gradiente%20MMX%20EBX%20Toyota%20Volks%20BMW%20Mercedez%20Fiatmail.lavapes.com.br.maklware calls home10429BR
2010/12/15_19:15-222.24.94.19/default/index/images/manual/oracle.txt-Windows hosts file used by banking trojan4538CN
2010/12/15_19:15-202.38.97.217/manual/readme.txt-Windows hosts file used by banking trojan4538CN
2010/12/12_23:48-109.196.143.136/andru333_lfdshogerhah.exe-trojan39150UA
2010/12/12_23:48-109.196.143.137/setup.exe-trojan39150UA
2010/12/12_20:02-91.207.182.56/xxx1/gw.php?i=15-trojan SpyEye48280UA
2010/12/08_20:40-91.217.162.228/pic/cq.php?i=15-trojan downloader51441UA
2010/12/08_13:37vvps.ws/44/mothersdarlingcross.php?91.200.240.46-trojan48709UA
2010/12/03_18:04-203.157.204.2/icons/facebook_toolbar.exe-irc backdoor9649TH
2010/12/03_17:29-201.76.178.58/.YAMAHA/kx.gifmvx-201-76-178-58.mundivox.com.trojan Banker17222BR
2010/12/03_17:29-201.76.178.58/.YAMAHA/sx.gifmvx-201-76-178-58.mundivox.com.trojan Banker17222BR
2010/12/03_17:29-201.76.178.58/.YAMAHA/24.gifmvx-201-76-178-58.mundivox.com.trojan Banker17222BR
2010/12/02_20:17-220.110.138.52/MNRSys/images/install_flash_player.exe52.48.138.110.220.in-addr.arpa.trojan4713JP
2010/12/02_18:42-91.213.174.46/KillEXE.exe-trojan29106UA
2010/12/02_18:42-91.213.174.46/all-zahlung.exe-trojan Ramnit29106UA
2010/12/02_17:39-109.196.143.136/setup.exe-fake av39150UA
2010/12/02_17:39-109.196.143.136/vlx777_sdhgjklaogreah.exe-trojan39150UA
2010/11/26_21:56-91.207.182.55/xxx1/gw.php?i=15-trojan SpyEye48280UA
2010/11/26_20:26-195.226.197.51/my_spl3/dzf.php?i=15-trojan51303UA
2010/11/26_20:26-69.50.195.232/-Bleeding Life exploit kit18866US
2010/11/26_19:18-69.50.208.164/stat/co.php?i=15-fake av18866US
2010/11/26_17:33www.gameangel.com/System/html/js/html.js121.156.126.10-iframe directs to exploit4766KR
2010/11/24_19:20-80.24.67.44/images/install_flash_player.exe44.Red-80-24-67.staticIP.rima-tde.net.trojan3352ES
2010/11/22_12:30-195.226.197.51/my_spl4/xt.php?i=15-trojan51303UA
2010/11/22_07:25-91.217.162.158/pic/is.php?i=15-trojan downloader51441UA
2010/11/21_16:10new-address.tk/go/?afid=80217.119.57.22bvtk02.synserver.de.fake av31100DE
2010/11/21_16:10-92.60.177.236/old/jzc.php?i=15grusha-92-60-177-236.hostinghutor.com.trojan15772UA
2010/11/21_11:02-128.134.30.87/w.exe-trojan4766KR
2010/11/21_11:02-128.134.30.87/s.exe-trojan4766KR
2010/11/20_09:49-204.45.48.15/shop/xsf.php?i=15actualemailsavings.info.fake av30058US
2010/11/20_07:03-114.203.87.195/help.asp-exploit9318KR
2010/11/20_07:03-121.254.145.212/w3c/ad.exe-trojan3786KR
2010/11/19_19:45-109.196.143.136/aff422_flsgejrlhjtrag.exe-trojan39150UA
2010/11/19_19:45-109.196.143.137/setup.exe-trojan39150UA
2010/11/19_19:45-78.26.187.41/god/bp.php?i=15vps70-6.elaninet.com.trojan downloader34187UA
2010/11/19_19:45-92.60.177.246/other/cu.php?i=15grusha-92-60-177-246.hostinghutor.com.trojan15772UA
2010/11/19_12:41-213.155.12.144/sec/bin/config.bin-SpyEye config file41665UA
2010/11/19_12:41-213.155.12.144/sec/bin/k.exe-trojan SpyEye41665UA
2010/11/19_12:41-213.155.12.144/sec/bin/load.exe-trojan41665UA
2010/11/19_12:41-213.155.12.144/sec/bin/upload/45.exe-trojan41665UA
2010/11/19_12:41-213.155.12.144/sec/bin/upload/baby.exe-trojan41665UA
2010/11/19_12:41-213.155.12.144/sec/bin/upload/v1crypted.exe--41665UA
2010/11/19_12:41-213.155.12.144/sec/bin/upload/v1crypted1.exe--41665UA
2010/11/19_12:41-213.155.12.144/sec/bin/upload/v2crypted.exe-trojan41665UA
2010/11/19_12:41-213.155.12.144/sec/bin/upload/v2crypted1.exe-trojan41665UA
2010/11/18_21:14-200.63.44.192/hk/show.php?key=27b7d8fb16d42bb82f9cf3a156f77994&u=user123-exploit kit27716PA
2010/11/18_21:14-200.63.44.192/hk/show.php?key=27b7d8fb16d42bb82f9cf3a156f77994&u=user123-trojan27716PA
2010/11/18_20:56-91.217.249.136/jwb.php?i=15-trojan Bredolab51554UA
2010/11/18_20:56unlim-app.tk/go/?afid=51217.119.57.22bvtk02.synserver.de.fake av31100DE
2010/11/16_18:59-91.217.162.176/dm3.exe-trojan TDSS51441UA
2010/11/15_18:37-89.209.91.49/e/bin/config.binstream-91.49.users.odessa.comstar.net.ua.Spyeye config file8359UA
2010/11/15_18:37-89.209.91.49/e/bt_version_checker.phpstream-91.49.users.odessa.comstar.net.ua.SpyEye C&C8359UA
2010/11/15_18:37-78.26.187.39/god/jwi.php?i=15vps70-16.elaninet.com.fake av34187UA
2010/11/15_18:18-92.60.177.244/out/al8.php?i=15grusha-92-60-177-244.hostinghutor.com.trojan downloader15772UA
2010/11/14_22:12sexyster.tk/lo/index.php217.119.57.22bvtk02.synserver.de.Zombie exploitation kit31100DE
2010/11/14_22:12sexyster.tk/lo/load.php?f=1&e=6217.119.57.22bvtk02.synserver.de.trojan downloader31100DE
2010/11/14_18:06-91.217.162.141/adult/bq.php?i=15-trojan downloader51441UA
2010/11/13_14:59-193.104.146.77/f1_heiught3o2iryhe/2uiew__t/zxconfig.bin--50134CZ
2010/11/13_14:59-193.104.146.77/f1_heiught3o2iryhe/2uiew__t/up1/bot_up1_144.exe--50134CZ
2010/11/13_09:52www.zyxyfy.com/images/ner.html61.178.85.177vip.lz118114.cn.exploit4134CN
2010/11/13_09:52-188.95.159.100/phpbb/image2/cp.php?i=15-trojan Oficla/Sasfis51306UA
2010/11/12_18:17-69.64.63.220/ar.php?i=15balder038.server4you.net.trojan Vilsel30083US
2010/11/12_18:17-69.50.213.106/1/bqe.php?i=15-trojan18866US
2010/11/12_07:47-91.217.249.160/KILL.exe-trojan51554UA
2010/11/09_19:33-195.226.197.50/spl_4/xt.php?i=15-trojan51303UA
2010/11/09_19:19-193.178.172.60/1.exe-anti Trusteer Rapport trojan20564UA
2010/11/07_10:30-92.60.177.235/iza.php?i=15grusha-92-60-177-235.hostinghutor.com.trojan downloader15772UA
2010/11/06_11:29internet-bb.tk/go/?afid=51217.119.57.22bvtk02.synserver.de.fake av31100DE
2010/11/01_20:08linkforme.tk/www1/load.php?f=1&e=2217.119.57.22bvtk02.synserver.de.fake av31100DE
2010/11/01_20:08linkforme.tk/www1/index.php217.119.57.22bvtk02.synserver.de.Zombie exploitation kit31100DE
2010/10/29_20:42scaner-sbite.tk/go/?afid=217.119.57.22bvtk02.synserver.de.fake av31100DE
2010/10/29_11:24scaner-sboom.tk/go/?afid=96217.119.57.22bvtk02.synserver.de.fake av31100DE
2010/10/28_17:28-109.196.143.133/1.exe-trojan Bredolab39150UA
2010/10/28_17:28-109.196.143.133/bm/-Bredolab C&C39150UA
2010/10/26_18:45-195.226.197.50/spl_3/dzf.php?i=15-trojan51303UA
2010/10/23_14:38-188.65.74.163/cash2_rwhoajdtyjtyysd.exe-fake av42473AT
2010/10/22_22:17scaner-or.tk/go/?afid=51217.119.57.22bvtk02.synserver.de.fake av31100DE
2010/10/22_06:27-109.196.143.135/outlook.exe-trojan39150UA
2010/10/19_19:22-195.226.197.49/spl_6/bn8.php?i=15-trojan51303UA
2010/10/18_09:54-83.133.122.54/r.php?type=0srv243.cyberhost.name.return malware url13237EU
2010/10/12_06:40scaner-figy.tk/go/?afid=51217.119.57.22bvtk02.synserver.de.fake av31100DE
2010/10/10_11:05-69.64.50.78/foj.php?i=15vds104.entdev.org.trojandownloader Vilsel30083US
2010/10/07_08:41-69.64.50.78/kmxqildtbnangvd.phpvds104.entdev.org.Phoenix exploit kit30083US
2010/10/07_07:10scdsfdfgdr12.tk/go/?afid=51217.119.57.22bvtk02.synserver.de.fake av31100DE
2010/10/06_20:13-178.63.2.21/www/delivery/ajs.php?zoneid=4&cb=52206126077static.21.2.63.178.clients.your-server.de.iframe directs to exploit kits24940DE
2010/10/06_07:08-188.65.74.163/vlx777_sdhgjklaogreah.exe-fake av42473AT
2010/09/28_18:49-70.86.83.194/~unix/PLUGIN/Install-TvFlashPlayer.exeserver1.ddf.com.br.trojan21844US
2010/09/22_19:04-178.17.163.108/ez/178-17-163-108.static-host.net.exploit kit43289MD
2010/09/22_19:04-178.17.163.108/ez/stats.php178-17-163-108.static-host.net.control panel of exploit kit43289MD
2010/09/22_19:04-178.17.163.108/ez/load.php?f=1&e=0178-17-163-108.static-host.net.trojan43289MD
2010/09/19_09:45sudcom.org/tmp/source/index.php81.31.145.112da45.joomlahost.it.control panel of Eleonore Exploits pack v1.4.147242IT
2010/09/19_09:45sudcom.org/tmp/source/pdf.php81.31.145.112da45.joomlahost.it.pdf exploit47242IT
2010/09/16_18:37-89.248.111.226/page/contacts-exploit kit45001ES
2010/09/16_18:37-89.248.111.226/page/b6609413801fe046af0a9bd9dff148af.php?site=12&name=47942584&quote=contacts&-trojan45001ES
2010/09/15_21:29-94.100.25.139/np/index.php139.25.100.94.king-servers.com.CRiMEPACK35017PL
2010/09/15_21:29-94.100.25.139/np/admin.php139.25.100.94.king-servers.com.control panel of CRiMEPACK35017PL
2010/09/15_21:29-94.100.25.139/np/load.php?spl=hcp&b=ff&o=xp&i=hcp139.25.100.94.king-servers.com.trojan Oficla/Sasfis35017PL
2010/09/15_17:18update.onescan.co.kr/setupa/onescansetup.exe115.68.13.152-fake av38700KR
2010/09/12_10:10-188.65.74.162/fuckemall_dfljgsdhfog.exe-fake av42473AT
2010/09/12_10:10-194.28.112.3/outlook.exe-trojan48691MD
2010/09/09_19:49-91.211.117.25/sp/admin/bin/upload/gbotout.exe-trojan48587UA
2010/09/09_19:49-91.211.117.25/sp/admin/bin/upload/out.exe-trojan48587UA
2010/09/09_19:49-91.211.117.25/sp/admin/bin/upload/out1.exe-trojan48587UA
2010/09/09_19:49-91.211.117.25/sp/admin/bin/upload/pedoout.exe-trojan48587UA
2010/09/09_17:06-188.65.74.162/invisible_eorighroeig.exe-fake av42473AT
2010/09/07_20:34-188.65.74.162/test_severyan_sdhkjwg.exe-trojan42473AT
2010/09/05_12:09-208.79.232.46:8444/exemple.com/load.php?spl=mdachost.hotmommagossip.com.trojan19066US
2010/09/05_12:09-212.117.161.31/js/ip-212-117-161-31.server.lu.exploit kit5577LU
2010/09/05_12:09-212.117.161.31/js/fi_4.phpip-212-117-161-31.server.lu.trojan TDSS5577LU
2010/08/30_18:49-61.147.75.89/index.php?open=1&myid=14c7c6847c09807.44463926-malware calls home23650CN
2010/08/30_18:49-112.84.189.89/mks.exe-TrojanDownloader:Win32/Doneltart.gen4837CN
2010/08/26_17:01luwyou.com/photos.php208.87.149.250-trojan Yimfoca40634US
2010/08/26_16:20-91.188.59.10/exe/sweater.exe-fake av6851LV
2010/08/26_16:20-91.188.59.10/exe/dogma.exe-trojan TDSS6851LV
2010/08/26_16:20-91.188.59.10/report/log.php-malware calls home6851LV
2010/08/23_20:18-69.50.221.196/x22/load/load.exe-fake av18866US
2010/08/23_20:18-69.50.221.196/x33/load/load.exe-trojan18866US
2010/08/23_20:18-69.50.221.196/x44/load/load.exe-fake av18866US
2010/08/23_20:18-69.50.221.196/x55/load/load.exe-fake av18866US
2010/08/22_08:38helesouurusa.cjb.com/land/video.php?l=4:52&id=1&n=my_loli2&a=mike&path=./tmb/my_loli2/31.jpg&rat=./img/rating5.jpg&v=61545216.194.70.11redirect.cjb.net.redirects to trojan TDSS13911CA
2010/08/22_08:38helesouurusa.cjb.com/land/?n=my_loli2&id=1216.194.70.11redirect.cjb.net.redirects to trojan TDSS13911CA
2010/08/21_19:01-91.188.59.150/show.php?s=bc0915c6c2-Incognito exploit kit6851LV
2010/08/21_19:01-91.188.59.150/admin.php-control panel of Incognito exploit kit6851LV
2010/08/21_19:01-91.188.59.150/load.php?e=2-fake av6851LV
2010/08/20_09:37-87.118.88.140/pizda/show.phpns.server.leo-host.ru.Siberia exploit pack31103DE
2010/08/20_09:37-87.118.88.140/pizda/stat.phpns.server.leo-host.ru.control panel of Siberia exploit pack31103DE
2010/08/20_09:37-87.118.88.140/pizda/exe.php?spl=HCPns.server.leo-host.ru.trojan31103DE
2010/08/18_14:45-188.65.74.161/archi_orweihaorgaigph.exe-trojan42473AT
2010/08/13_18:44-202.109.143.16:81/ma.exe-PWS:Win32/Frethog.gen!G4134CN
2010/08/12_12:51-69.50.221.190/l1/bb.php?v=200&id=636608811&b=9468674099&tm=2--18866US
2010/08/11_19:28-188.65.74.161/netpoint_ghlaerggweqa.exe-fake av42473AT
2010/08/11_14:26-193.104.146.12:443-malware calls home over SSL50134CZ
2010/08/10_09:17-69.50.221.190/l1/bb.php?v=200&id=554905388&b=9468674099&tm=3-Oficla/Sasfis C&C18866US
2010/08/01_10:11-188.65.74.161/varag_sdfgkwlkgadfshn.exe-trojan42473AT
2010/07/29_13:45-85.21.235.231/psd/index.html85-21-235-231.dar-ekspo.corbina.ru.obfuscated script / java downloader8402RU
2010/07/28_14:08pornstarss.tk/ntk/index.php?ID=105828217.119.57.22bvtk02.synserver.de.exploit kit31100DE
2010/07/25_17:24-91.188.59.10/opapa.exe-trojan6851LV
2010/07/24_11:27-188.65.74.161/wrath_ehgoihgwpigpehh.exe-trojan42473AT
2010/07/23_08:01-91.188.60.5/hit.php?v=46&app_type_id=1&wm_id=acc0047&u=6a397086-fc8c-4e4e-bd44-05f8f376ab0f&t=2-malware calls home6851LV
2010/07/23_08:01-91.188.60.5/l.php?wm_id=acc0047-trojan downloader6851LV
2010/07/22_14:56-91.212.226.33/qkl4Cix7f4XUCs8MTQ1fGRvd25sb2FkfA==18k.gif-backdoor SdBot5577CZ
2010/07/21_01:11-219.255.13.77:8080/Home/exemple.com/-exploit9318KR
2010/07/21_01:11-219.255.13.77:8080/Home/exemple.com/api.php-exploit9318KR
2010/07/21_01:11-219.255.13.77:8080/Home/exemple.com/992.jar-Java exploit9318KR
2010/07/21_01:11-219.255.13.77:8080/Home/exemple.com/cbe.jar-Java exploit9318KR
2010/07/21_01:11-219.255.13.77:8080/Home/exemple.com/error.js.php-exploit9318KR
2010/07/21_01:11-219.255.13.77:8080/Home/exemple.com/gogol.Familie.class-exploit9318KR
2010/07/21_01:11-219.255.13.77:8080/Home/exemple.com/MyName-exploit9318KR
2010/07/19_21:04-91.188.60.5/hit.php?v=45&app_type_id=1&wm_id=acc0049&u=28b6d4a0-f30b-43bc-8cc8-c466a4ca72bc&t=2-malware calls home6851LV
2010/07/17_20:53-193.105.240.59/optima/index.php?uid=080286&ver=6g%20XP-malware calls home, returns base64 encoded url list43513LV
2010/07/17_20:20allxscan.tk/ddt/load.php?f=1&e=4217.119.57.22bvtk02.synserver.de.trojan downloader31100DE
2010/07/14_20:45freeserials.ws/sn/64850.html91.195.110.9991-195-110-99.hmrtelecom.ru.fake crack site directs to trojan43671RU
2010/07/14_18:02montezuma.spb.ru/key/72548.htm91.195.110.9991-195-110-99.hmrtelecom.ru.fake crack site directs to trojan43671RU
2010/07/13_12:51-91.188.60.5/hit.php?v=44&app_type_id=1&wm_id=acc0044&u=d6c9b08c-89d3-46bf-b610-08c742b7ebf2&t=2-malware calls home6851LV
2010/07/10_07:57fgawegwr.chez.com/images/1273471091.exe212.27.63.127perso127-g5.free.fr.trojan TDSS12322FR
2010/06/30_19:51-72.18.206.103/nervoso/download01.rarns2.amigoxeternamente.com.trojan Banker26277US
2010/06/30_19:51-72.18.206.103/nervoso/download02.rarns2.amigoxeternamente.com.trojan Banker26277US
2010/06/30_19:51-72.18.206.103/nervoso/download03.rarns2.amigoxeternamente.com.trojan Banker26277US
2010/06/01_18:58-213.252.116.180:81/roundcubemail/bin/1.gif213.252.116.180.clients.rmt.ru.RFI5523RU
2010/05/26_18:24-83.133.125.178/r.php?type=0srv45.cyberhost.name.returns malware url13237EU
2010/05/15_21:10-193.105.207.21/ccc/dede.qwas--50793CZ
2010/05/15_21:10-193.105.207.21/dede/gate.php--50793CZ
2010/05/13_10:04-188.65.74.166-fake av42473AT
2010/05/13_10:04-188.65.74.167-fake av42473AT
2010/05/13_10:04-188.65.74.168-fake av42473AT
2010/05/13_10:04-188.65.74.169-fake av42473AT
2010/05/13_10:04-188.65.74.170-fake av42473AT
2010/05/13_10:04afa15.com.ne.kr/media/videoxxx.avi.exe211.119.245.140-fake av3786KR
2010/05/09_19:02-193.105.174.42/stat/halo-i16/o.php-malware calls home196954UA
2010/05/09_19:02-193.105.174.42/stat/halo-i16/s.php-malware calls home196954UA
2010/05/09_19:02-193.105.174.42/stat/halo-i5/s.php-malware calls home196954UA
2010/05/09_19:02-193.105.174.42/stat/halo-i5/l.php-malware calls home196954UA
2010/05/08_11:02-116.127.121.27/~brownsoftdown/download/servprodect27.exe-trojan9318KR
2010/05/07_06:52-62.122.75.237/-Rogue AV5577UA
2010/04/27_06:45w4988.nb.host127-0-0-1.com/bins/int/np_pkz.int?affid=NP_0104&fxp=85c26940bd074d9ebe8290842bca496331374b71c3b8806954f77f966.220.17.200-trojan Swizzor6939US
2010/04/27_06:45z32538.nb.host127-0-0-1.com/bins/int/np_pkz.int?affid=NP_0104&fxp=2ac11c971204a16811817c725e04d68a44f9d4987c472f66eb08d066.220.17.200-trojan Swizzor6939US
2010/04/25_06:54w612.nb.host127-0-0-1.com/bins/int/kr3_znp.int?fxp=384bd820008ee37f030b3e65bca6e8a1a65beab33574f567a23b0a987ca83e6544e3e64566.220.17.200-trojan Swizzor6939US
2010/04/25_06:54q28840.nb.host127-0-0-1.com/bins/int/tp_map16.int?fxp=5936289861f351e362768cf97e7b45e0648647f26c6d6750fb2298af91238cf9c815a46166.220.17.200-trojan Swizzor6939US
2010/04/20_16:20www.angolotesti.it/J/testi_canzoni_jovanotti_168/testo_canzone_chissa_se_stai_dormendo_9566.html174.122.221.186ba.dd.7aae.static.theplanet.com.obfuscated iframe directs to exploits21844US
2010/04/20_10:45pic.starsarabian.com/98.130.32.2rev.opentransfer.com.2.32.130.98.in-addr.arpa.obfuscated iframe directs to exploits32392US
2010/04/17_23:47-78.140.15.82/quu3aiVai7Lei6epha7azoYegah4da9za2rec8ahngoosu7tuneemoizee5vael5eBoazahHephaahohTa3eecoochaiseesheichoh7aikuz0uas8zeekiaChiayeVa/scripts/tasks.xml-Gootkit31357RU
2010/04/16_20:16pokachi.net/77.222.40.91varna.sweb.ru.compromised site directs to exploits44112RU
2010/04/16_20:16pride-u-bike.com/2006/09/30/akkymtlator/206.225.20.77-compromised site directs to exploits6428US
2010/04/16_20:16pride-u-bike.com/2007/06/23/s-tolkacha/206.225.20.77-compromised site directs to exploits6428US
2010/04/16_20:16pride-u-bike.com/2007/07/30/doroga-smerti/206.225.20.77-compromised site directs to exploits6428US
2010/04/16_20:16pride-u-bike.com/byzapimoto/206.225.20.77-compromised site directs to exploits6428US
2010/04/16_20:16pride-u-bike.com/motorcycle/suzuki-motorcycle/206.225.20.77-compromised site directs to exploits6428US
2010/04/16_20:16pride-u-bike.com/motorcycle/vozdeniye-motorcycle/206.225.20.77-compromised site directs to exploits6428US
2010/04/16_20:16pride-u-bike.com/sell/honda-steed-400-1996/206.225.20.77-compromised site directs to exploits6428US
2010/04/16_20:16pride-u-bike.com/sell/honda-vfr400r-nc30/206.225.20.77-compromised site directs to exploits6428US
2010/04/16_20:16quotidiennokoue.com/66.7.214.152pass81.dizinc.com.compromised site directs to exploits33182US
2010/04/16_20:16quotidiennokoue.com/?cat=566.7.214.152pass81.dizinc.com.compromised site directs to exploits33182US
2010/04/16_20:16quotidiennokoue.com/?p=55866.7.214.152pass81.dizinc.com.compromised site directs to exploits33182US
2010/04/16_20:16safety.amw.com/family/ask-john-walsh-how-can-i-tell-if-a-child-has-been-abused/4.59.56.18-compromised site directs to exploits3356US
2010/04/16_20:16safety.amw.com/home/stop-domestic-violence-before-it-starts/4.59.56.18-compromised site directs to exploits3356US
2010/04/16_20:16wmserver.net/sgcg/?page_id=5217.30.180.48virtual22.nebula.fi.compromised site directs to exploits29422FI
2010/04/16_20:16wp9.ru/188.127.248.545.mirit.su.compromised site directs to exploits48172RU
2010/04/16_20:16www.sanseracingteam.com/wordpress/85.10.140.251wpc4811.host7x24.com.compromised site directs to exploits48185FR
2010/04/16_20:16www.sanseracingteam.com/wordpress/?p=12885.10.140.251wpc4811.host7x24.com.compromised site directs to exploits48185FR
2010/04/16_20:16www.sonnoli.com/?page_id=562.149.140.107webx97.aruba.it.compromised site directs to exploits31034IT
2010/04/16_20:16www.stirparts.ru/89.108.67.238cp141.agava.net.compromised site directs to exploits43146RU
2010/04/16_20:16www.tiergestuetzt.de/80.190.144.115sv05.net-housting.de.compromised site directs to exploits15598DE
2010/04/14_05:32-78.140.15.82/bootstrap-Gootkit31357RU
2010/04/12_20:14-193.86.3.170/region/karneva2003-2/karneval2003-2.htmlns3.oku-zn.cz.obfuscated iframe directs to exploit kit2819CZ
2010/04/12_11:29-95.143.193.60/dir/gate.php?box=war&take=0&uid=pecwghrc-trojan Peerfit49770SE
2010/04/10_09:07-62.75.152.79/MeinEigenerServer/index.php?p=Loginvs152079.vserver.de.control panel of Warbot8972DE
2010/04/08_15:26-202.38.97.217/manual/readme.txt-trojan4538CN
2010/04/08_15:26bargainracks.co.uk/img/common/1x2.gif77.75.105.9-trojan39326GB
2010/04/07_14:26-78.140.15.82/protod.exe-backdoor31357RU
2010/04/07_06:26blacknite.eu/cracking/Pelite.EXE89.234.64.135web3.hosting.digiweb.ie.trojan31122IE
2010/04/03_10:04-91.207.6.134/spm/page.php?id=1378328&tick=1378328&ver=100&smtp=ok&task=0134.6.207.91.unknown.SteepHost.Net.-47142CZ
2010/04/01_16:14wkmg.co.kr/bbs/lib/1.txt218.38.243.71-RFI17845KR
2010/03/29_06:18obkom.net.ua/bancodes/rotator.php?place=indexfoot193.178.146.235obkom.net.ua.iframe directs to redirector/exploits28907UA
2010/03/24_11:51-58.55.127.16:8080/files/image.jpg-Backdoor Koutodoor4134CN
2010/03/17_15:54vette-porno.nl213.132.197.60webguru104.webguru.nl.obfuscated iframe directs to exploit kit24793NL
2010/03/17_04:53-83.139.194.168/images/comprovanteEmail_Html.com-Trojan33942IT
2010/02/26_16:30-77.245.61.232/offersfortoday/multi/28.exeafleet15.amsnl.webair.com.trojan36057NL
2010/02/26_16:28-77.245.61.232/offersfortoday/get_file.phpafleet15.amsnl.webair.com.redirects to trojan36057NL
2010/02/25_21:26a.update.51edm.net/20100223/01.kdg?md5=ab2676ca2190bc21abcba6e5f5b3b2a7222.222.204.68-trojan4134CN
2010/02/17_15:39-66.220.17.157/toolbar_uninstall.exe157.17.220.66.in-addr.arpaTrojan.Obfuscated.BX / Lop / Swizzor6939US
2010/02/17_15:39-89.28.13.212/in.php?s=89.28.13.21489-28-13-212.starnet.mdredirects to fake av31252MD
2010/02/14_15:14-119.145.143.6/aspnet_client/system_web/update.exe-trojan Redosdru4134CN
2010/02/13_09:21reishus.de/.sys/?action=fbgen&mode=s&age=193&a=-186345958&v=82&crc=669&ie=6.0.2900.2180212.12.112.25web-ve-gamma.domainmedia.net.Koobface12595DE
2010/02/13_09:21sexzoznamka.eu/lightbox/js/r/files/tasks/AC87.236.199.153boom.barad.cz.returns malware url base64 encoded35592CZ
2010/02/10_11:39www.secondome.com/sora-margherita/69.163.145.107apache2-moon.suns.dreamhost.com.obfuscated iframe directs to exploit kit26347US
2010/02/02_08:40www.rempko.sk/kontakt.htm213.81.152.60wep.t-com.sk.compromised site directs to exploits6855SK
2010/02/01_11:14websalesusa.com/ken208.112.22.66-RFI20021US
2009/12/23_02:35inlinea.co.uk213.230.203.8686.0/24.203.230.213.in-addr.arpa.exploit33970GB
2009/12/23_02:35inlinea.co.uk/suspended.page/213.230.203.8686.0/24.203.230.213.in-addr.arpa.exploit33970GB
2009/12/23_02:35inlinea.co.uk/adnep/simple.php213.230.203.8686.0/24.203.230.213.in-addr.arpa.fake av33970GB
2009/12/23_02:35inlinea.co.uk/adnep/tahitian.php213.230.203.8686.0/24.203.230.213.in-addr.arpa.fake av33970GB
2009/12/12_10:56-218.25.203.5/images/images/js.gif-trojan4837CN
2009/12/10_15:48cznshuya.ivnet.ru/81.20.97.13hosting.ivnet.ru.compromized site loads external script with exploits24699RU
2009/12/10_15:48www.tpt.edu.in/76.163.253.1-compromized site loads external script with exploits32392US
2009/12/04_19:56www.doctor-alex.com/files/SetupDrAlex.exe69.89.20.48box48.bluehost.com.Rogue11798US
2009/12/02_20:32www.sitepalace.com/w0rmreaper/NoVaC.jpeg216.45.58.150-trojan29761US
2009/11/24_19:27-88.80.10.1/pp/anp.php-RFI33837SE
2009/11/16_21:00santacruzsuspension.com/?j=bleach-episode-24566.96.130.2121.130.96.66.static.eigbox.net.redirects to Rogue if referer is a search engine29873US
2009/11/15_16:09www.purplehorses.net/?page=bleach-244-online69.89.19.20019-200.bluehost.com.redirects to Rogue if referer is a search engine11798US
2009/11/15_16:09www.wildsap.com/?kkk=bleach-episodes-24469.89.31.59box259.bluehost.com.redirects to Rogue if referer is a search engine11798US
2009/11/15_16:09www.ohiomm.com/?page=bleach-244-vosta74.220.219.67box467.bluehost.com.redirects to Rogue if referer is a search engine11798US
2009/11/15_16:09be-funk.com/?kkk=bleach-244-english-sub69.89.18.20box20.bluehost.com.redirects to Rogue if referer is a search engine11798US
2009/11/15_16:09revistaelite.com/?topic=bleach-244-english-sub69.89.22.116box116.bluehost.com.redirects to Rogue if referer is a search engine11798US
2009/11/15_16:09www.wrestlingexposed.com/faq.php?t=bleach-244-english-sub67.20.108.6367-20-108-63.bluehost.com.redirects to Rogue if referer is a search engine11798US
2009/11/15_16:09revistaelite.com/?topic=bleach-244-raw69.89.22.116box116.bluehost.com.redirects to Rogue if referer is a search engine11798US
2009/11/13_20:52-200.80.97.174/maravilha.txtmultilink-97-174.ipAddr.multilink-ht.net.RFI27767HT
2009/11/01_18:49-217.23.6.17:10283/d3n2829231.dat-malware calls home15435NL
2009/09/26_00:00dp-medien.eu81.169.145.69w05.rzone.de.compromised site directs to exploits6724DE
2009/09/26_00:00juedische-kammerphilharmonie.de85.13.135.179dd14202.kasserver.com.compromised site directs to exploits34788DE
2009/09/26_00:00vernoblisk.com67.228.85.201hostica.com.compromised site directs to exploits36351US
2009/09/26_00:00vural-electronic.com81.169.145.82w82.rzone.de.compromised site directs to exploits6724DE
2009/09/24_00:00typeofmarijuana.com/204.93.171.26web01.snaago.com.obfuscated script directs to exploits23352US
2009/09/24_00:00trafficgrowth.com/204.93.171.26web01.snaago.com.obfuscated script directs to exploits23352US
2009/09/24_00:00thcvaporizer.com/204.93.171.26web01.snaago.com.obfuscated script directs to exploits23352US
2009/09/24_00:00roorbong.com/204.93.171.26web01.snaago.com.obfuscated script directs to exploits23352US
2009/09/24_00:00thcextractor.com/204.93.171.26web01.snaago.com.obfuscated script directs to exploits23352US
2009/09/24_00:00purethc.com/204.93.171.26web01.snaago.com.obfuscated script directs to exploits23352US
2009/09/24_00:00potvaporizer.com/204.93.171.26web01.snaago.com.obfuscated script directs to exploits23352US
2009/09/24_00:00portablevaporizer.com/204.93.171.26web01.snaago.com.obfuscated script directs to exploits23352US
2009/09/24_00:00cannabispicture.com/204.93.171.26web01.snaago.com.obfuscated script directs to exploits23352US
2009/09/24_00:00cannabislyric.com/204.93.171.26web01.snaago.com.obfuscated script directs to exploits23352US
2009/09/23_00:00-213.163.89.54/mito/-redirects to exploit kit20495NL
2009/09/19_00:00www.whitesports.co.kr211.202.2.17web-7.blueweb.co.kr.iframe directs to LuckySploit9318KR
2009/09/18_00:000koryu0.easter.ne.jp208.71.106.216super-html-7.fc2.com.obfuscated iframe directs to LuckySploit40263US
2009/09/16_00:00www.professionalblackbook.com/96.30.28.181host.disantolaw.com.obfuscated iframe directs to exploits19066US
2009/09/13_00:00-66.96.214.117:80806696214117.hostnoc.netcompromised server with nginx at port 808021788US
2009/09/13_00:00-84.242.167.49:8080www.sopharma.bgcompromised server with nginx at port 80808672BG
2009/09/13_00:00hst-19-33.splius.lt:808077.79.19.33hst-19-33.splius.lt.compromised server with nginx at port 808025406LT
2009/09/13_00:00tabex.sopharma.bg:808084.242.167.49www.sopharma.bg.compromised server with nginx at port 80808672BG
2009/09/13_00:00-209.9.188.130/t.txt-RFI3491US
2009/09/12_00:00sportsulsan.co.kr/poll/aipi/id.txt211.171.231.215sportsulsan.co.kr.RFI3786KR
2009/09/11_00:00-213.163.89.54/lib/index.php?t=2-redirects to exploit kit20495NL
2009/09/11_00:00www.vvvic.com118.220.175.24-obfuscated iframe directs to exploits9318KR
2009/09/05_00:00adgallery.whitehousedrugpolicy.gov/members/Miley-Cyrus-Nude/default.aspx198.77.71.192adgallery.whitehousedrugpolicy.gov.directs to trojan3356US
2009/08/30_00:00www.oiluk.net/cache/cache_94afbfb2f291e0bf253fcf222e9d238e_180836f9b956ab9d91a50f9add968699188.64.184.32bluechip3.ukhost4u.com.-47625GB
2009/08/25_00:00js.tongji.linezing.com/1189582/tongji.js119.42.225.167lvs1.bmvip.cnz.alimama.com.directs to exploits37963CN
2009/08/17_00:00callingcardsinstantly.com/webalizer/050709wareza/crack=17=keygen=serial.html216.157.140.193hsphere.cc.directs to exploits16557US
2009/08/17_00:00dawnframing.com/webalizer/050709wareza/crack=17=keygen=serial.html216.81.64.192rapidcolo.com.directs to exploits16557US
2009/08/17_00:00free-crochet-pattern.com/webalizer/050709wareza/crack=17=keygen=serial.html216.157.140.192hsphere.cc.directs to exploits16557US
2009/08/17_00:00-199.238.181.161/setup.exe-Rogue2914US
2009/08/15_00:00www.obyz.de/webproxytest.txt85.13.138.226dd18438.kasserver.com.RFI34788DE
2009/08/12_00:00wfoto.front.ru/fotos.com194.186.88.45ftp.front.ru.trojan Banload3216RU
2009/08/12_00:00ska.energia.cz/download/imer.up217.31.49.10kojak.core.ignum.cz.trojan Bancos29134CZ
2009/08/05_00:00update.51edm.net/20090728/01.dll222.222.204.68-trojan4134CN
2009/08/05_00:00update.51edm.net/20090728/01.kdg222.222.204.67-trojan4134CN
2009/08/05_00:00www.xiruz.kit.net/mola.jpg201.7.184.2-trojan28604BR
2009/08/03_00:00dl.heima8.com/pv/dl.htm?adid=20132&sid=021158.215.240.96--4134CN
2009/07/24_00:00www.hospedar.xpg.com.br/nome.txt200.149.77.224-RFI7738BR
2009/07/21_00:00firehouse651.com/gallery/images/copyright.txt64.40.123.35mercury.van-dns.com.RFI14280CA
2009/07/21_00:00www.freewebtown.com/atakus/Nokia/BotNetNew.txt208.75.230.43www.freewebtown.com.RFI36820US
2009/07/21_00:00webcashmaker.com/v2/members/trade_traffic.php74.206.224.180-RFI27257US
2009/07/21_00:00sentrol.cl/components/kampret.jpg74.200.91.144unknown144.91.200.74.defenderhosting.com.RFI14383US
2009/07/21_00:00www.kjbbc.net/bbs/data/gallery/1207290228/inbox.txt112.216.25.75-RFI3786KR
2009/07/21_00:00www.torgi.kz/help/id2.txt212.154.208.169-RFI9198KZ
2009/07/21_00:00www.torgi.kz/help/idxx.txt212.154.208.169-RFI9198KZ
2009/07/21_00:00www.uriyuri.com/bbs/skin/zero_vote/1.txt202.131.25.49-RFI23576KR
2009/07/21_00:00www.usaenterprise.com/images/images.txt212.70.224.183virtweb-cms.nethouse.it.RFI16141IT
2009/07/21_00:00www.wigglewoo.com/portfolio/contests/contest-006.png85.13.136.149dd15308.kasserver.com.RFI34788DE
2009/07/21_00:00xorgwebs.webs.com/stx.1216.52.115.50membersite.webs.com.RFI10913US
2009/07/21_00:00plengeh.wen.ru/id.txt91.189.80.71www.wen.ru.RFI8342RU
2009/07/21_00:00wahyufian.zoomshare.com/files/bot.txt64.94.37.195frontend.zoomshare.com.RFI19024US
2009/07/11_00:00www.propan.ru/forum/downloads.php89.111.177.27fe91-1.hc.ru.RFI41126RU
2009/07/01_00:00xoomer.alice.it/email02/bom.jpg62.211.68.12-trojan20580IT
2009/06/30_00:00bde.be194.146.224.100cluster.sivit.org.directs to exploits13193FR
2009/06/30_00:00pwvita.pl77.55.70.169acs169.rev.netart.pl.directs to exploits15967PL
2009/06/30_00:00roks.ua80.91.176.135uahost01.hc.ua.directs to exploits21219UA
2009/06/30_00:00skgroup.kiev.ua80.91.176.135uahost01.hc.ua.directs to exploits21219UA
2009/06/30_00:00tecnocuer.com190.228.29.81mx2981.godns.net.directs to exploits7303AR
2009/06/30_00:00tk-gregoric.si91.185.202.90mail.internetstoritve.com.directs to exploits41828SI
2009/06/30_00:00tomalinoalambres.com.ar190.228.29.81mx2981.godns.net.directs to exploits7303AR
2009/06/30_00:00vipdn123.blackapplehost.com69.162.86.44-86-162-69.static.reverse.lstn.net.vbscript downloader46475US
2009/06/30_00:00womenslabour.org83.142.47.61www.linux.webserwer.pl.directs to exploits39168PL
2009/06/30_00:00wroclawski.com.pl83.142.47.61www.linux.webserwer.pl.directs to exploits39168PL
2009/06/29_00:00nadegda-95.ru87.242.126.153ant6.fast.ru.directs to exploits25532RU
2009/06/29_00:00romsigmed.ro86.35.15.214www4.linux.romtelecom.net.directs to exploits9050RO
2009/06/29_00:00spatsz.com67.210.126.110orion.lunarpages.com.directs to exploits15244US
2009/06/29_00:00svetyivanrilski.com212.36.9.1ns5.tophostbg.net.directs to exploits39388BG
2009/06/29_00:00titon.info212.36.9.10ns1.tophostbg.net.directs to exploits39388BG
2009/06/29_00:00tophostbg.net212.36.9.10ns1.tophostbg.net.directs to exploits39388BG
2009/06/29_00:00vivaweb.org212.36.9.1ns5.tophostbg.net.directs to exploits39388BG
2009/06/29_00:00vocational-training.us216.8.179.24ptr-216-8-179-24.ptr.nextdimensioninc.com.directs to exploits13727CA
2009/06/29_00:00warco.pl81.2.200.162host-81-2-200-162.alpha.pl.directs to exploits24806CZ
2009/06/28_00:00sbnc.hak.su/spread.txt91.189.81.71www2.wen.ru.RFI8342RU
2009/06/28_00:00somnoy.com91.197.128.216h6.data-xata.net.directs to exploits8870UA
2009/06/25_00:00hanulsms.com124.217.216.40-directs to exploits38661KR
2009/06/25_00:00semengineers.com216.245.193.34thor.corpservers.net.directs to exploits46475US
2009/06/25_00:00srslogisticts.com64.191.16.37reseller4.hostingmadeeasy.com.directs to exploits21788US
2009/06/25_00:00tendersource.com75.125.56.218218.56.125.75.in-addr.ev1.opticaljungle.com.directs to exploits21844US
2009/06/25_00:00traff1.com/in.cgi?566.232.116.49-directs to trojan29802US
2009/06/25_00:00web-olymp.ru81.176.232.104server4.neoweb.ru.directs to exploits8342RU
2009/06/24_00:00www.t-sb.net72.232.219.152152.219.232.72.static.reverse.ltdomains.com.directs to exploits22576US
2009/06/20_00:00unalbilgisayar.com84.51.21.163host-84-51-21-163.teletektelekom.com.directs to exploits34104TR
2009/06/18_00:00-69.3.109.79/1.htmlh-69-3-109-79-static.nycmny83.covad.netExploits18566US
2009/06/18_00:00antalya.ru/links/89.111.176.89fe31-1.hc.ru.directs to exploits41126RU
2009/06/18_00:00conds.ru90.156.201.22fe.shared.masterhost.ru.directs to exploits25532RU
2009/06/16_00:00-213.174.143.196/v/g.php?d=79-directs to rogue39572UA
2009/06/16_00:00achren.org83.245.63.229http.sodium.lon.periodicnetwork.com.directs to exploits33970GB
2009/06/16_00:00associatesexports.com209.25.133.107altar14.supremepanel14.com.directs to exploits11388US
2009/06/15_00:00buffalogoesout.com66.96.146.201201.146.96.66.static.eigbox.net.directs to exploits29873US
2009/06/14_00:00dimsnetwork.com88.214.193.196-Directs to exploits46636GB
2009/06/14_00:00luckyblank.info89.185.228.15ex14.exmasters.com.directs to rogue24971CZ
2009/06/14_00:00luckyclean.info89.185.228.15ex14.exmasters.com.directs to rogue24971CZ
2009/06/14_00:00luckyclear.info89.185.228.15ex14.exmasters.com.directs to rogue24971CZ
2009/06/14_00:00luckyeffect.info89.185.228.15ex14.exmasters.com.directs to rogue24971CZ
2009/06/14_00:00luckyhalo.info89.185.228.15ex14.exmasters.com.directs to rogue24971CZ
2009/06/14_00:00luckypure.info89.185.228.15ex14.exmasters.com.directs to rogue24971CZ
2009/06/14_00:00luckyshine.info89.185.228.15ex14.exmasters.com.directs to rogue24971CZ
2009/06/14_00:00luckysuccess.info89.185.228.15ex14.exmasters.com.directs to rogue24971CZ
2009/06/14_00:00luckysure.info89.185.228.15ex14.exmasters.com.directs to rogue24971CZ
2009/06/14_00:00luckytidy.info89.185.228.15ex14.exmasters.com.directs to rogue24971CZ
2009/06/14_00:00nudebeachgalleries.net88.214.242.12-directs to exploits46636GB
2009/06/13_00:00noveslovo.com77.222.131.8686.0-127.131.222.77.in-addr.arpa.directs to exploits21219UA
2009/06/12_00:00hardcorepornparty.com88.214.193.196-directs to exploits46636GB
2009/06/12_00:00zous.szm.sk88.86.113.4freehosting.szm.com.directs to exploits39392CZ
2009/06/10_00:00www.realinnovation.com/css/menu.js67.202.87.234ip234.67-202-87.static.steadfast.net.redirects to exploits32748US
2009/06/08_00:00oknarai.ru66.118.146.6966-118-146-69.static.sagonet.net.directs to exploits21840US
2009/06/07_00:00bezproudoff.cz93.185.104.30www20.pipni.cz.directs to exploits43541CZ
2009/06/07_00:00ceskarepublika.net93.185.104.27www17.pipni.cz.directs to exploits43541CZ
2009/06/07_00:00hotspot.cz93.185.104.30www20.pipni.cz.directs to exploits43541CZ
2009/06/07_00:00nerez-schodiste-zabradli.com93.185.104.29www19.pipni.cz.directs to exploits43541CZ
2009/06/07_00:00nordiccountry.cz93.185.104.28www18.pipni.cz.directs to exploits43541CZ
2009/06/07_00:00nowina.info93.185.104.30www20.pipni.cz.directs to exploits43541CZ
2009/06/07_00:00obada-konstruktiwa.org81.2.194.138c138un.forpsi.com.directs to exploits24806CZ
2009/06/07_00:00otylkaaotesanek.cz81.2.195.176d176ud.forpsi.com.directs to exploits24806CZ
2009/06/07_00:00pb-webdesign.net93.185.104.29www19.pipni.cz.directs to exploits43541CZ
2009/06/07_00:00pension-helene.cz81.2.195.176d176ud.forpsi.com.directs to exploits24806CZ
2009/06/07_00:00podzemi.myotis.info93.185.104.29www19.pipni.cz.directs to exploits43541CZ
2009/06/07_00:00smrcek.com93.185.104.29www19.pipni.cz.directs to exploits43541CZ
2009/06/07_00:00spekband.com93.185.104.30www20.pipni.cz.directs to exploits43541CZ
2009/06/07_00:00webcom-software.ws/links/?153646e8b0a8864.70.19.33mailrelay.33.website.ws.exploits3561US
2009/06/07_00:00worldgymperu.com74.54.143.242impulse.websitewelcome.com.directs to exploits21844US
2009/06/07_00:00zgsysz.com125.65.112.23-directs to exploits4134CN
2009/06/05_00:00nuptialimages.com64.6.241.22s22.n241.n6.n64.static.myhostcenter.com.directs to exploits11343US
2009/06/04_00:00-202.91.74.136/bjp3/id3.txt-RFI9830IN
2009/06/03_00:00-63.227.18.137/id5.txtmail.vail-valley.comRFI209US
2009/06/03_00:00juicypussyclips.com74.81.93.72ip72.envelopebizs.com.Directs to sites with exploits27413US
2009/05/31_00:00adserving.favorit-network.com/eas?camp=19320;cre=mu&grpid=1738&tag_id=618&nums=FGApbjFAAA91.209.163.184vemw04.c76.fvtn.net.-48445EU
2009/05/31_00:00cracks.vg/d1.php111.92.237.115server111092237115.i-services.com.hk.Directs to rogue45816HK
2009/05/28_00:00ruiyangcn.com61.139.126.15-directs to exploits4134CN
2009/05/28_00:00zkic.com174.37.172.162www.se.parahost.com.directs to exploits36351US
2009/05/26_00:00deletespyware-adware.com174.120.200.218da.c8.78ae.static.theplanet.com.Fake Antivirus21844US
2009/05/26_00:00orbowlada.strefa.pl/text396.htm217.74.66.183www.strefa.pl.Directs to rogue16138PL
2009/05/24_00:00freeserials.spb.ru/key/68703.htm91.195.110.9991-195-110-99.hmrtelecom.ru.TDSS43671RU
2009/05/23_00:00-219.148.34.9/dmdown/sss.exe-Trojan17672CN
2009/05/23_00:00outporn.com63.217.31.51web-r1-h51.globecorp.net.directs to sites with exploits3491US
2009/05/23_00:00timothycopus.aimoo.com74.52.179.179b3.b3.344a.static.theplanet.com.directs to trojan21844US
2009/05/23_00:00xindalawyer.com218.5.79.63-Exploits4134CN
2009/05/22_00:00officeon.ch.ma/office.js?google_ad_format=728x90_as88.191.20.248ns2.venez.net.directs to Exploits12322FR
2009/05/22_00:00sn-gzzx.com222.76.215.12-Exploits4134CN
2009/05/22_00:00sunlux.net/company/about.html211.234.100.137-directs to Exploits3786KR
2009/05/20_00:00pos-kupang.com/202.146.4.119-redirects to exploits18365ID
2009/05/20_00:00rupor.info62.149.12.191rupor.info.redirects to exploits15497UA
2009/05/20_00:00svision-online.de/mgfi/administrator/components/com_babackup/classes/fx29id1.txt78.31.65.216-RFI24961DE
2009/05/18_00:00-85.13.236.154/v50/?v=66&s=I&uid=1824245000&p=13310&q=85.13.236.154.reverse.coreix.netMalware calls home31708GB
2009/05/18_00:00crackspider.us/toolbar/install.php?pack=exe85.159.233.47-Adware.Cracksearch.A43350NL
2009/05/17_00:00ipl.hk77.232.66.1877-232-66-18.static.servage.net.redirects to exploits29671DE
2009/05/13_00:00-72.10.169.26/loader.exe-Cutwail/Pushdo36666CA
2009/05/13_00:00tubemoviez.com63.251.171.80-redirects to rogue14744US
2009/05/08_00:00diaryofagameaddict.com208.76.80.16ossus.tchmachines.com.directs to exploits25767US
2009/05/08_00:00espdesign.com.au64.49.219.215-directs to exploits10532US
2009/05/08_00:00iamagameaddict.com208.76.80.16ossus.tchmachines.com.directs to exploits25767US
2009/05/08_00:00kalantzis.net208.83.210.33box7.vistapages.com.directs to exploits13826CA
2009/05/08_00:00slightlyoffcenter.net208.76.80.19yavin.tchmachines.com.directs to exploits25767US
2009/04/27_00:00-200.122.168.229/dl/goldvipclub/-trojan Casino3790CR
2009/04/27_00:00-200.122.168.229/dl/goldvipclub/TrackDownload.dll?DID=991392-trojan Casino3790CR
2009/03/22_00:00-205.209.143.94/000f1.htm-Trojan33314US
2009/03/22_00:00-205.209.143.94/000f2.htm-Trojan33314US

You can find an overview of downloadable lists here