WARNING: All domains on this website should be considered dangerous. If you do
not know what you are doing here, it is recommended you leave right away. This
website is a resource for security professionals and enthusiasts.
Date (UTC) | Domain | IP | Reverse Lookup | Description | ASN | |
⇑ ⇓ | ⇑ ⇓ | ⇑ ⇓ | ⇑ ⇓ | ⇑ ⇓ | ⇑ ⇓ | |
2009/05/31_00:00 | - | 190.246.55.231/pid=1000/setup.exe | 231-55-246-190.fibertel.com.ar | Koobface | 10318 |  |
2009/08/28_00:00 | www.prolab.com.co/images/banners/a.txt | 190.248.129.86 | cable190-248-129-86.une.net.co. | RFI | 13489 |  |
2009/12/27_11:46 | apollo.deltasystem.cl/mods/cfg.bin | 190.3.183.11 | apollo.deltasystem.cl. | zeus v1 config file | 28098 |  |
2009/12/27_21:06 | apollo.deltasystem.cl/mods/gate.php | 190.3.183.11 | apollo.deltasystem.cl. | zeus v1 drop zone | 28098 |  |
2009/12/28_14:16 | apollo.deltasystem.cl/mods/cfgg.bin | 190.3.183.11 | apollo.deltasystem.cl. | zeus v1 config file | 28098 |  |
2009/12/27_12:54 | - | 190.3.183.11/mods/cfg.bin | apollo.deltasystem.cl. | zeus v1 config file | 28098 |  |
2010/04/03_08:12 | financialdeposit.com/dat/stat.dat | 190.32.203.56 | - | zeus v1 trojan | 11556 |  |
2009/09/13_00:00 | marksistskaya.hopto.org:8080 | 190.34.148.26 | - | compromised server with nginx at port 8080 | 27990 |  |
2010/03/23_08:42 | www.your-updates.net/microsoft/IE8.bin | 190.34.188.117 | - | zeus v1 config file | 27990 |  |
2010/03/23_08:42 | www.your-updates.net/microsoft/IE8.exe | 190.34.188.117 | - | zeus v1 trojan | 27990 |  |
2010/03/23_08:42 | www.win-uploads.net/win/111xjhjewhkjhdkjhkjdshkjhdkj_z01_cp.php | 190.34.188.36 | - | zeus v1 drop zone | 27990 |  |
2009/07/17_00:00 | www.aeronautica.gob.pa/modules/MambWeather/templates/default/icons/id.txt | 190.34.189.245 | - | RFI | 11556 |  |
2009/12/01_20:38 | online.cdc.gov.yttt4r.com.im/h1n1flu/vacc_profile.exe | 190.34.29.179 | - | zeus v1 trojan | 11556 |  |
2009/09/29_00:00 | www.irs.gov.dotrpet.com/fraud_application/directory/tax-statement.exe | 190.46.93.230 | pc-230-93-46-190.cm.vtr.net. | zeus v1 trojan | 22047 |  |
2012/08/17_13:24 | mariajosesmith.cl/wmagM9k6/index.htm | 190.54.12.101 | cp12101scl.adx.cl. | Compromised site leads to Blackhole exploit | 6429 |  |
2012/02/21_11:39 | leercontubebe.cl/tienda/mail.html | 190.54.12.96 | cp1296scl.adx.cl. | leads to Blackhole exploit | 6429 |  |
2011/10/31_14:24 | giabkjsgmcp.com/w.php?f=26&e=2 | 190.60.35.167 | 190-60-35-167.ifxnw.com.ve. | trojan Sinowal/Mebroot | 18747 |  |
2009/09/15_00:00 | despnar.idsn.gov.co/pol/includes/local/felc/fx29id1.txt | 190.69.156.10 | idsn.gov.co. | RFI | 3816 |  |
2011/04/01_13:13 | gemma.unisabana.edu.co/scredito/Ver.asp?BaixarComprovante6528.php-Cliente?MostraComprovanteCliente=6528 | 190.69.3.31 | - | redirects to trojan downloader | 3816 |  |
2009/11/30_20:11 | www.distrilamadrid.com.ar/img/gal/,,/,,/file/dir/CMD.txt | 190.7.31.149 | ns3.dnsprivados.com. | RFI | 20207 |  |
2016/01/23_00:46 | www.proascolcolombia.com/portal/modules/mod_banners/Imprimir_IntimacaoCTI2015-03698541.rar?cli=Cliente&/yRpBKPujKU/nNqRc6QsuO.php | 190.8.176.235 | bartolome.colombiahosting.com.co. | Trojan.Banload | 52335 |  |
2016/01/23_00:46 | www.proascolcolombia.com/portal/modules/mod_banners/Imprimir_IntimacaoCTI2015-03698541.rar?cli=Cliente&/yRpBKPujKU/nNqRc6QsuO.php | 190.8.176.235 | bartolome.colombiahosting.com.co. | Trojan.Banload | 52335 |  |
2012/03/06_17:48 | clkjshdflhhshdf.ru:8080/images/aublbzdni.php | 190.81.107.70 | - | Phoenix exploit kit | 12252 |  |
2012/03/06_17:48 | zolindarkksokns.ru:8080/images/jw.php?i=2 | 190.81.107.70 | - | trojan Cridex | 12252 |  |
2012/03/14_13:10 | dkijhsdkjfhsdf.ru:8080/images/kobzfoivdpdzilx.php | 190.81.107.70 | - | pdf exploit, part of Phoenix exploit kit | 12252 |  |
2009/11/16_19:27 | - | 190.81.28.182/incaware/id1.txt | - | RFI | 12252 |  |
2010/02/10_21:00 | www.dixon-link.com/PDF/thumbs/m1v3/cont/zombie.php?id=WindowsNTCOMPUTERNAME5.1build2600 | 190.81.33.115 | - | malware calls home | 12252 |  |
2009/10/12_16:38 | online.hmrc.gov.uk.nyyyyase.com/SecurityWebApp/httpsmode/tax-statement.exe | 190.82.14.118 | 190-82-14-118.adsl.tie.cl. | zeus v1 trojan | 7418 |  |
2009/12/01_20:38 | online.cdc.gov.yhnbad.co.im/h1n1flu/vacc_profile.exe | 190.82.243.167 | 190-82-243-167.adsl.tie.cl. | zeus v1 trojan | 7418 |  |
2009/12/01_20:38 | online.cdc.gov.yhnbak.org.im/h1n1flu/vacc_profile.exe | 190.82.243.167 | 190-82-243-167.adsl.tie.cl. | zeus v1 trojan | 7418 |  |
2009/12/01_20:38 | online.cdc.gov.yhnbam.net.im/h1n1flu/vacc_profile.exe | 190.82.243.167 | 190-82-243-167.adsl.tie.cl. | zeus v1 trojan | 7418 |  |
2010/04/01_16:14 | www.miranda.gov.ve/modules/mod_sections/id1.txt | 190.9.130.13 | 190.9-130-13.static.cantv.net. | RFI | 8048 |  |
2012/02/28_07:52 | asrtinrows.com/w.php?f=5a20e&e=2 | 190.94.221.33 | 190-94-221-33.ifxnw.com.ve. | trojan Sinowal | 18747 |  |
2009/10/23_21:45 | transmarecuador.com/navidad/sitemap.php | 190.95.249.107 | host-190-95-249-107.telconet.net. | compromized by Gumblar | 27947 |  |
2011/11/16_07:35 | www.puranovia.cl/images/js.js | 190.98.219.43 | power83.powerhost.cl. | redirects to Blackhole exploit kit | 14259 |  |
2014/05/27_04:02 | neumashop.cl/bmfbnoou | 190.98.227.154 | gtd154.dch.cl. | Spyware.ZeuS.GO | 14259 |  |
2013/03/20_12:16 | suiauuqe.anitamcfarlandhomes.com/rcLogin/test/dialogs/reviews.php?profiles=267&live=432&cookies=24&comments=718&story=669 | 192.111.144.10 | - | Sweet Orange Exploit Kit | 31863 |  |
2013/03/20_14:49 | xaumous.club-106.com.ar/forums/webadmin/reviews.php?watch=100&stories=415&cookies=24&pixel=379&fisting=383 | 192.111.144.10 | - | Sweet Orange exploit kit | 31863 |  |
2013/03/26_09:38 | heilaiqo.garagesport.ch:7354/cont/reprints.php?space=253&features=378&documents=897&students=843&press=355&pubsphoto=24&release=297 | 192.111.144.12 | - | Sweet Orange exploit kit | 31863 |  |
2013/04/15_16:27 | socks.vpgconsulting.com.br:2390/guest/about_us.php?usage=42 | 192.111.144.13 | - | Java exploits | 31863 |  |
2010/04/21_12:06 | sktdo.com/bb.php?v=1&id=qfbg1rlwevurmqowm23cxmdkesxvbax&b=traf9&tm=1 | 192.114.71.84 | 500.granthost.org. | Oficla/Sasis C&C | 8551 |  |
2009/08/19_00:00 | www.planetnana.co.il/flaw/idf.exe | 192.116.45.29 | planet.nana.co.il. | Backdoor/IRCBot | 1680 |  |
2009/05/22_00:00 | dreams.co.il/images/z/ex.php?h=ex2 | 192.117.232.137 | gold.live4all.co.il. | Rogue | 8551 |  |
2009/05/22_00:00 | dreams.co.il/images/z/static.php | 192.117.232.137 | gold.live4all.co.il. | Exploits | 8551 |  |
2009/03/15_00:00 | dreams.co.il/images/z | 192.117.232.150 | zmani.datascope.co.il. | trojan | 8551 |  |
2012/12/14_14:49 | 6.bbnsmsgateway.com/string/obscure-logs-useful.php | 192.155.81.9 | li567-9.members.linode.com. | Blackhole exploit kit 2.0 | 6939 |  |
2012/11/23_07:27 | 5.eventiduepuntozero.com/links/becoming-either.php | 192.155.83.191 | li570-191.members.linode.com. | Blackhole exploit kit 2.0 | 6939 |  |
2012/11/23_07:27 | 5.estasiatica.com/links/becoming-either.php | 192.155.83.191 | li570-191.members.linode.com. | Blackhole exploit kit 2.0 | 6939 |  |
2012/09/05_09:13 | shell.boxertbear.com/main.php?page=023c51b081df5717 | 192.162.102.38 | - | Blackhole exploit kit | 12608 |  |
2012/09/05_09:13 | shell.boxertbear.com/w.php?f=d4fc7&e=2 | 192.162.102.38 | - | Zeus trojan | 12608 |  |