WARNING: All domains on this website should be considered dangerous. If you do
not know what you are doing here, it is recommended you leave right away. This
website is a resource for security professionals and enthusiasts.
Date (UTC)DomainIPReverse LookupDescriptionRegistrant ASN
2010/03/09_21:19yougoodvideo.net/forum/exe/file.exe122.115.63.24netnic.com.cn.rootkit TDSSDomain Admin / contact@privacyprotect.org9803
2010/03/09_21:19diaiscjdthr.com/nte/INDEPHANDLER66.135.37.211server6.randasolutions.com.NeoSploit, payload ZeusJim Nelson / Nelsondwer4@yahoo.com13768
2010/03/09_21:19diaiscjdthr.com/nte/INDEPHANDLER/eU8ea8ef33Hdfd932d2V0100f070006R00000000102T944f9e0c201l0409K08d8010532066.135.37.211server6.randasolutions.com.zeus/wsnpoem v2 trojanJim Nelson / Nelsondwer4@yahoo.com13768
2010/03/09_21:19www.youporn8.net/yama.exe174.120.148.1549a.94.78ae.static.theplanet.com.trojan StartPageAhmet ERCETIN21844
2010/03/09_21:19trastlifer.hk/vmxts.exe91.212.220.10-zeus/wsnpoem v2 trojandomain@now.net.cn49365
2010/03/09_21:19trastlifer.hk/ribbn.tar91.212.220.10-zeus/wsnpoem v2 config filedomain@now.net.cn49365
2010/03/09_21:19trastlifer.hk/index1.php91.212.220.10-zeus/wsnpoem v2 drop zonedomain@now.net.cn49365
2010/03/09_19:08stroimvmeste.in/affiliate/index.php?b=b77.222.56.35caracas.sweb.ru.YES exploit kitBolortseseg Nagsadorj / trf00ok@gmail.com44112
2010/03/09_19:08stroimvmeste.in/affiliate/admin77.222.56.35caracas.sweb.ru.control panel of YES exploit kitBolortseseg Nagsadorj / trf00ok@gmail.com44112
2010/03/09_19:08stroimvmeste.in/affiliate/cache/PDF.php?st=Internet77.222.56.35caracas.sweb.ru.Explorer 6.0Bolortseseg Nagsadorj / trf00ok@gmail.com44112
2010/03/09_19:08stroimvmeste.in/affiliate/load.php?a=a&e=477.222.56.35caracas.sweb.ru.rootkit TDSSBolortseseg Nagsadorj / trf00ok@gmail.com44112
2010/03/09_19:08foreinternet.com/sys/index.php91.210.173.2lc-b2.lorercorp.com.YES exploit kittangrongnn@163.com48588
2010/03/09_19:08foreinternet.com/sys/admin91.210.173.2lc-b2.lorercorp.com.control panel of YES exploit kittangrongnn@163.com48588
2010/03/09_19:08foreinternet.com/sys/load.php?a=a&e=491.210.173.2lc-b2.lorercorp.com.trojan Oficla/Sasfistangrongnn@163.com48588
2010/03/09_19:08antiviruspc-update.com/mavzoley/bb.php?v=200&id=554905388&b=ze-us&tm=391.210.173.25lc-b25.lorercorp.com.Oficla/Sasfis C&CJan Winstrom / dns@antiviruspc2009.com48588
2010/03/09_18:32yes-exploit-system.ru91.212.198.156-YES exploit kit advertisementadmin@yes-exploit-system.ru49314
2010/03/09_17:39streamlinemediaworks.com/images/space.gif72.167.131.22p3swh205.shr.phx3.secureserver.net.zeus/wsnpoem v2 config fileStreamline Mediaworks26496
2010/03/09_17:39kokojamba.com/a/d.php?e=CollabUTIL79.171.22.190static.vitalhosting.com.tr.trojankokojamba.com / magikmind13@gmail.com44565
2010/03/09_17:39kokojamba.com/a/s/files/ie.swf79.171.22.190static.vitalhosting.com.tr.flash exploitkokojamba.com / magikmind13@gmail.com44565
2010/03/09_17:39kokojamba.com/a/admin.php79.171.22.190static.vitalhosting.com.tr.control panel of Liberty exploit kitkokojamba.com / magikmind13@gmail.com44565
2010/03/09_17:39kokojamba.com/a/s/files/clb.pdf79.171.22.190static.vitalhosting.com.tr.pdf exploitkokojamba.com / magikmind13@gmail.com44565
2010/03/09_17:39kokojamba.com/a/s/0.php79.171.22.190static.vitalhosting.com.tr.Liberty exploit kitkokojamba.com / magikmind13@gmail.com44565
2010/03/09_17:39-98.126.17.138/g86f3cbi2.phpCUSTOMER.KRYPT.COM.zeus/wsnpoem v2 drop zone-35908
2010/03/09_17:39inasss.info/pt_newold.exe122.115.63.9netnic.com.cn.zeus/wsnpoem v2 trojanAndrey Aleksandrovich Polev / o00o.code@gmail.com9803
2010/03/09_17:39calvinkleinstuffz.com/calvinklein2/cfg.bin122.115.63.37netnic.com.cn.zeus/wsnpoem v1 config fileJOHN DUNCAN / contact@myprivateregistration.com9803
2010/03/09_17:39calvinkleinstuffz.com/calvinklein2/logger.php122.115.63.37netnic.com.cn.zeus/wsnpoem v1 drop zoneJOHN DUNCAN / contact@myprivateregistration.com9803
2010/03/09_17:39hourbrand.com/scn/c4f12d4be2e5a718fc0fab8ff0519a17/0540f0d2bb566d0ed0d80150e2b728ef/f85b7b377112c272bc87f3e73f10508d98.142.243.10-fake online ScannerChris Mosh / mosh@dev.mosh.com30407
2010/03/09_17:39zannualnews.com/download/0540f0d2bb566d0ed0d80150e2b728ef/f85b7b377112c272bc87f3e73f10508d/491.212.127.144-trojan fakeSmokePrivate Whois Service efiis0c4b94e72d25553@ahwyn0f4b73feacadaa2.privatewhois.net49087
2010/03/09_17:39www.antivp.com/asvzgdwebasvzgdweb.htm?get=e0b399bd994a0556517f96487dd3ab2991.212.127.142-rogue installerPrivate Whois Service nvu6cp14b744046930da@ahwyn0f4b73feacadaa2.privatewhois.net49087
2010/03/09_17:39antispyware-comp.com69.4.231.42no-rdns.ord02.hostingservicesinc.net.fake av sitePavel Eroshkin / volt@maillife.ru36351
2010/03/09_17:39antivirus-onecare2010.com76.76.102.198generic.gogax.com.fake av sitebarley@freenetbox.ru21793
2010/03/09_17:39pc-carelive.com76.76.102.197generic.gogax.com.fake av sitebette@bigmailbox.ru21793
2010/03/09_17:39pccare-live.com76.76.102.195generic.gogax.com.fake av sitebette@bigmailbox.ru21793
2010/03/09_17:39pcguard2010.com76.76.102.197generic.gogax.com.fake av siteYuri Vernitsky / larks@freenetbox.ru21793
2010/03/09_17:39pcguard-2010.com69.4.231.42no-rdns.ord02.hostingservicesinc.net.fake av sitebette@bigmailbox.ru36351
2010/03/09_17:39pc-guard-2010.com173.192.214.194173.192.214.194-static.reverse.softlayer.com.fake av sitebette@bigmailbox.ru36351
2010/03/09_17:39pcguard20-10.com69.4.231.43no-rdns.ord02.hostingservicesinc.net.fake av sitebette@bigmailbox.ru36351
2010/03/09_17:39pc-guard-20-10.com173.192.214.194173.192.214.194-static.reverse.softlayer.com.fake av sitebette@bigmailbox.ru36351
2010/03/09_17:39pcwindowslive.com69.4.231.40no-rdns.ord02.hostingservicesinc.net.fake av siteAnanoliy Kunirkin / mazda@freenetbox.ru36351
2010/03/09_17:39pc-windowslive.com69.4.231.43no-rdns.ord02.hostingservicesinc.net.fake av siteAnanoliy Kunirkin / mazda@freenetbox.ru36351
2010/03/09_17:39pcwindows-live.com69.4.231.41no-rdns.ord02.hostingservicesinc.net.fake av siteAnanoliy Kunirkin / mazda@freenetbox.ru36351
2010/03/09_17:39pc-windows-live.com173.192.214.192173.192.214.192-static.reverse.softlayer.com.fake av siteAnanoliy Kunirkin / mazda@freenetbox.ru36351
2010/03/09_17:39pcwinlive.com173.83.26.46-fake av siteAnanoliy Kunirkin / mazda@freenetbox.ru32392
2010/03/09_17:39pc-winlive.com173.83.26.44-fake av siteAnanoliy Kunirkin / mazda@freenetbox.ru32392
2010/03/09_17:39pcwin-live.com76.76.102.196generic.gogax.com.fake av siteAnanoliy Kunirkin / mazda@freenetbox.ru21793
2010/03/09_17:39pc-win-live.com69.4.231.41no-rdns.ord02.hostingservicesinc.net.fake av siteYuri Vernitsky / larks@freenetbox.ru36351
2010/03/09_17:39pcwinlive2010.com173.192.214.193173.192.214.193-static.reverse.softlayer.com.fake av siteYuri Vernitsky / larks@freenetbox.ru36351
2010/03/09_17:39pc-winlive2010.com69.4.231.42no-rdns.ord02.hostingservicesinc.net.fake av siteYuri Vernitsky / larks@freenetbox.ru36351
2010/03/09_17:39pcwinlive-2010.com173.83.26.44-fake av siteYuri Vernitsky / larks@freenetbox.ru32392
2010/03/09_17:39pc-win-live-2010.com173.83.26.45-fake av siteYuri Vernitsky / larks@freenetbox.ru32392
2010/03/09_17:39spyware-destroyerone.com69.4.231.41no-rdns.ord02.hostingservicesinc.net.fake av siteAnton Nikiforov / astral@freenetbox.ru36351
2010/03/09_17:39tragicapple.com76.76.98.196reverse-mtl-76-76-98-196.gogax.com.fake av siteproxy1621500@1and1-private-registration.com21793
2010/03/09_17:39windef2010.com69.4.231.43no-rdns.ord02.hostingservicesinc.net.fake av siteAlexander Bulatov / bands@freenetbox.ru 36351
2010/03/09_17:39win-defender10.com69.4.231.40no-rdns.ord02.hostingservicesinc.net.fake av siteskies@freenetbox.ru36351
2010/03/09_17:39windefender-10.com69.4.231.41no-rdns.ord02.hostingservicesinc.net.fake av siteLyubov Bushmakina / boil@maillife.ru36351
2010/03/09_17:39win-defender-10.com69.4.231.42no-rdns.ord02.hostingservicesinc.net.fake av siteLyubov Bushmakina / boil@maillife.ru36351
2010/03/09_17:39windowsdefender10.com69.4.231.40no-rdns.ord02.hostingservicesinc.net.fake av siteIgor Goev / try@bigmailbox.ru36351
2010/03/09_17:39windows-defender10.com69.4.231.41no-rdns.ord02.hostingservicesinc.net.fake av siteSvetlana Alyamkina / quilt@bigmailbox.ru36351
2010/03/09_17:39windowsdefender-10.com69.4.231.42no-rdns.ord02.hostingservicesinc.net.fake av siteDmitriy Kolobanov / bob@qx8.ru36351
2010/03/09_17:39windows-defender-10.com69.4.231.43no-rdns.ord02.hostingservicesinc.net.fake av siteskies@freenetbox.ru36351
2010/03/09_15:29lipesnaskom.com/cgi-binn/hitss.php95.143.192.40-zeus/wsnpoem v2 drop zoneHilary Kneber hilarykneber@yahoo.com49770
2010/03/09_14:18842389423478923.com/2/l.php?i=6195.88.208.8hosted-by.antaro-hosting.ru.zeus/wsnpoem v2 trojanIgnat Alekseev / admin@842389423478923.com12695
2010/03/09_14:18842389423478923.com/2/statistics.php195.88.208.8hosted-by.antaro-hosting.ru.control panel of Phoenix exploit kitIgnat Alekseev / admin@842389423478923.com12695
2010/03/09_14:18842389423478923.com/2/index.php195.88.208.8hosted-by.antaro-hosting.ru.Phoenix exploit kitIgnat Alekseev / admin@842389423478923.com12695
2010/03/09_12:04bravetools.net/en/mytools.php74.54.41.82gator326.hostgator.com.exploit kitAmir Hossein Jadidi / domian@parandis.com21844
2010/03/09_12:04www.from-jucar.de/81.169.145.71w07.rzone.de.compromised site directs to exploit kithostmaster@strato.de6724
2010/03/09_11:50qnnualnews.com/download/0540f0d2bb566d0ed0d80150e2b728ef/f85b7b377112c272bc87f3e73f10508d/4212.150.147.45-trojan FakeSmokePrivate Whois Service prf9am94b94e72c4a346@ahwyn0f4b73feacadaa2.privatewhois.net1680
2010/03/09_11:50checkliet.com/scn/f7293174e497c1447e298176d78e0ae1/0540f0d2bb566d0ed0d80150e2b728ef/f85b7b377112c272bc87f3e73f10508d98.142.243.10-fake online ScannerChris Mosh / mosh@dev.mosh.com30407
2010/03/09_09:07openaskelisto.com/main1/view.php85.12.46.22-zeus/wsnpoem v2 drop zoneHary / admin@asusufurmeh.com34305
2010/03/09_08:26www.gaddem.net/scam/can/li.exe61.4.82.222-zeus/wsnpoem v2 trojanPavel Pugachev / ya_whois@yandex.ru17964
2010/03/09_08:26ertriuanfhaeritruonceif.com/barcelona/barccfg9832789/barccfg23084292.bin91.212.220.68-zeus/wsnpoem v2 config fileYu MingSuo / abuseemaildhcp@gmail.com49365
2010/03/09_08:26countrtds.ru/cxd/fe.vv91.201.196.102-zeus/wsnpoem v2 config filethru@freenetbox.ru42229
2010/03/09_08:26iiiiiiiiiiiiii.net/games/update.set203.174.83.98203-174-83-98.rev.ne.com.sg.zeus/wsnpoem v2 config fileAlexander A Reva / klimckoe@yahoo.com38001
2010/03/09_08:24777brabus777.com/tmp/404_ca.php94.228.220.66-zeus/wsnpoem v2 drop zoneBozvanovna L Olegovna / helukausa@yahoo.com47869
2010/03/09_08:24-193.105.0.71/yj6revg7.exe-zeus/wsnpoem v2 trojan-50390
2010/03/09_08:24777brabus777.com/fu/loc.so94.228.220.66-zeus/wsnpoem v2 config fileBozvanovna L Olegovna / helukausa@yahoo.com47869
2010/03/09_08:24-193.105.0.71/j65g5hh7.php-zeus/wsnpoem v2 drop zone-50390
2010/03/09_08:24-193.105.0.71/allovu.bin-zeus/wsnpoem v2 config file-50390
2010/03/09_01:44slavenkad.com/3/download.php?expid=3&fid=195.143.192.193-zeus/wsnpoem v2 trojanChan Su tahli@yahoo.com49770
2010/03/09_01:44slavenkad.com/3/admin.php95.143.192.193-control panel of Liberty exploit kitChan Su tahli@yahoo.com49770
2010/03/09_01:44slavenkad.com/3/index.php95.143.192.193-Liberty exploit kitChan Su tahli@yahoo.com49770
2010/03/09_01:44oooowor.com/stat/load.php?spl=pdf_2012122.115.63.24netnic.com.cn.trojanAlexander A Reva / klimckoe@yahoo.com9803
2010/03/09_01:44oooowor.com/stat/stat.php122.115.63.24netnic.com.cn.control panel of Eleonore Exploits pack v1.3.2Alexander A Reva / klimckoe@yahoo.com9803
2010/03/09_01:44oooowor.com/stat/index.php122.115.63.24netnic.com.cn.Eleonore Exploits pack v1.3.2Alexander A Reva / klimckoe@yahoo.com9803
2010/03/09_01:44kontroli.ru/s/load.php?id=&spl=495.211.4.6-trojana.kanevskiy@mail.ru16265
2010/03/09_01:44kontroli.ru/s/index.php95.211.4.6-exploit kita.kanevskiy@mail.ru16265
2010/03/09_01:44jl.chura.pl/rc/getexe.php?spl=mdac89.187.34.4host4-34.monitoring.md.trojan Virut-25129
2010/03/09_01:44jl.chura.pl/rc/stat.php89.187.34.4host4-34.monitoring.md.control panel of Eleonore Exploits pack v1.2-25129
2010/03/09_01:44jl.chura.pl/rc/index.pjp89.187.34.4host4-34.monitoring.md.Eleonore Exploits pack v1.2-25129
2010/03/09_01:44frondircass.cn/ee/imho.php95.143.192.193-zeus/wsnpoem v2 drop zoneLiTah / tahli@yahoo.com49770
2010/03/09_01:44frondircass.cn/ee/ee.txt95.143.192.193-zeus/wsnpoem v2 config fileLiTah / tahli@yahoo.com49770
2010/03/09_01:44brunongino.com/3/download.php?expid=3&fid=195.143.192.193-zeus/wsnpoem v2 trojanChan Su tahli@yahoo.com49770
2010/03/09_01:44brunongino.com/3/admin.php95.143.192.193-control panel of Liberty exploit kitChan Su tahli@yahoo.com49770
2010/03/09_01:44brunongino.com/3/index.php95.143.192.193-Liberty exploit kitChan Su tahli@yahoo.com49770
2010/03/09_01:44test2.salefale.com/exe.exe67.141.185.89h89.185.141.67.static.ip.windstream.net.zeus/wsnpoem v2 trojanVera Zaytseva, (20100301173314@antispam.alantron.com)7029
2010/03/09_01:44zxfr.salefale.com/exe.exe67.141.185.89h89.185.141.67.static.ip.windstream.net.zeus/wsnpoem v2 trojanVera Zaytseva, (20100301173314@antispam.alantron.com)7029
2010/03/09_00:29superlayout.org/ws/g899.php61.4.82.216-zeus/wsnpoem v2 drop zonealexey pronin / vin.bond@gmail.com17964
2010/03/09_00:29superlayout.org/125/tyu7.exe61.4.82.216-zeus/wsnpoem v2 trojanalexey pronin / vin.bond@gmail.com17964
2010/03/09_00:29superlayout.org/125/gfy6.bin61.4.82.216-zeus/wsnpoem v2 config filealexey pronin / vin.bond@gmail.com17964
2010/03/08_20:39img95.lmagebucket.com/img/acomsw.jpg112.121.163.174-trojanhotdogs c/o Dynadot Privacy / privacy@dynadot.com45753
2010/03/08_19:36ackstone.com/.sys/?getexe=v2captcha21.exe12.46.124.22112-46-124-221.daub.net.Koobface-7018
2010/03/08_19:36asiandvdtime.com/.sys/?getexe=v2captcha21.exe72.52.191.187-Koobface-32244
2010/03/08_19:36beautiteen.hostmaniacs.com/.sys/?getexe=v2captcha21.exe88.85.75.140-Koobface-35415
2010/03/08_19:36cedelevator.com/.sys/?getexe=v2captcha21.exe64.71.33.74-Koobface-20401
2010/03/08_19:36comunicat-de-presa.ro/.sys/?getexe=hosts2.exe89.42.216.60server32.whmpanels.com.Koobface-5606
2010/03/08_19:36ctsrmspos.com/.sys/?getexe=v2captcha21.exe216.177.193.194ns2.e-mailsglobal.com.Koobface-22364
2010/03/08_19:36daveshieldsphotography.com/.sys/?getexe=v2captcha21.exe64.71.33.197-Koobface-20401
2010/03/08_19:36derekmohr.com/.sys/?getexe=v2prx.exe207.150.212.89-Koobface-20401
2010/03/08_19:36dorothycooley.com/.sys/?getexe=v2captcha21.exe67.139.134.203o3.hostbaby.com.Koobface-7385
2010/03/08_19:36elenailyina.com/.sys/?getexe=v2captcha21.exe213.189.197.30axx30.distributed.zenon.net.Koobface-6903
2010/03/08_19:36fjdc.edu.pk/.sys/?getexe=v2bloggerjs.exe208.93.192.2www.brospeedheaders.info.Koobface-146562
2010/03/08_19:36fjdc.edu.pk/.sys/?getexe=v2captcha21.exe208.93.192.2www.brospeedheaders.info.Koobface-146562
2010/03/08_19:36fjdc.edu.pk/.sys/?getexe=v2newblogger.exe208.93.192.2www.brospeedheaders.info.Koobface-146562
2010/03/08_19:36frigologistics.nl/.sys/?getexe=pp.14.exe193.93.174.152wswww21.uwwebhostingprovider.nl.Koobface-39700
2010/03/08_19:36frigologistics.nl/.sys/?getexe=v2captcha21.exe193.93.174.152wswww21.uwwebhostingprovider.nl.Koobface-39700
2010/03/08_19:36goldmaniac.com/.sys/?getexe=v2bloggerjs.exe65.36.242.101grollfamily.comKoobface-20021
2010/03/08_19:36goldmaniac.com/.sys/?getexe=v2captcha21.exe65.36.242.101grollfamily.comKoobface-20021
2010/03/08_19:36goldmaniac.com/.sys/?getexe=v2newblogger.exe65.36.242.101grollfamily.comKoobface-20021
2010/03/08_19:36goninja.fastlearningbrain.com/.sys/?getexe=v2captcha21.exe174.137.158.10-Koobface-27257
2010/03/08_19:36greystoneofellijay.com/.sys/?getexe=v2captcha21.exe198.92.147.210host24.ihostnetworks.com. host27.ihostnetworks.com.Koobface-3356
2010/03/08_19:36inartdesigns.com/.sys/?getexe=v2captcha21.exe67.227.177.47-Koobface-32244
2010/03/08_19:36internethosting.sg/.sys/?getexe=v2captcha21.exe203.211.140.165165.203-211-140.static.qala.com.sg.Koobface-17547
2010/03/08_19:36keeplan.com/.sys/?getexe=v2captcha21.exe64.71.33.35-Koobface-20401
2010/03/08_19:36leonardandself.com/.sys/?getexe=v2captcha21.exe216.180.225.10flexo.routesys.com.Koobface-3595
2010/03/08_19:36leonardandself.com/.sys/?getexe=v2captcha21.exe216.180.225.10flexo.routesys.com.Koobface-3595
2010/03/08_19:36mad-i-bevaegelse.dk/.sys/?getexe=pp.14.exe194.192.14.146serv29.wannafind.dk.Koobface-3292
2010/03/08_19:36mad-i-bevaegelse.dk/.sys/?getexe=v2bloggerjs.exe194.192.14.146serv29.wannafind.dk.Koobface-3292
2010/03/08_19:36mad-i-bevaegelse.dk/.sys/?getexe=v2captcha21.exe194.192.14.146serv29.wannafind.dk.Koobface-3292
2010/03/08_19:36mad-i-bevaegelse.dk/.sys/?getexe=v2newblogger.exe194.192.14.146serv29.wannafind.dk.Koobface-3292
2010/03/08_19:36mahjongmuseum.com/.sys/?getexe=v2captcha21.exe207.217.125.50webhost.earthlink.net.Koobface-4355
2010/03/08_19:36mkmohanty.com/.sys/?getexe=v2captcha21.exe174.37.216.1linux11.znetindia.net.Koobface-36351
2010/03/08_19:36mohammedistechnologies.com/.sys/?getexe=v2captcha21.exe91.186.25.40-Koobface-29550
2010/03/08_19:36musthaveitjewelry.com.mytempweb.com/.sys/?getexe=v2captcha21.exe66.252.239.235web08.appliedi.net.Koobface-14519
2010/03/08_19:36mycleveridea.co.za/.sys/?getexe=v2captcha21.exe72.9.250.162win1.nswebhost.com.Koobface-3595
2010/03/08_19:36qatar-business-guide.net/.sys/?getexe=v2captcha21.exe94.102.219.71-Koobface-41078
2010/03/08_19:36reishus.de/.sys/?getexe=loader.exe212.12.112.25web-ve-gamma.domainmedia.net.Koobface-12595
2010/03/08_19:36reishus.de/.sys/?getexe=v2captcha21.exe212.12.112.25web-ve-gamma.domainmedia.net.Koobface-12595
2010/03/08_19:36ritmotours.com.tr/.sys/?getexe=v2captcha21.exe89.106.12.55web6.turkticaret.net.Koobface-39582
2010/03/08_19:36roomservicedesign.com.au/.sys/?getexe=pp.14.exe122.201.80.95stradale.turboservers.com.au.Koobface-9512
2010/03/08_19:36roomservicedesign.com.au/.sys/?getexe=pp.14.exe122.201.80.95stradale.turboservers.com.au.Koobface-9512
2010/03/08_19:36roomservicedesign.com.au/.sys/?getexe=v2captcha21.exe122.201.80.95stradale.turboservers.com.au.Koobface-9512
2010/03/08_19:36skybluephoto.com/.sys/?getexe=loader.exe8.21.33.134cwpro1.crosswinds.net.Koobface-14112
2010/03/08_19:36skybluephoto.com/.sys/?getexe=v2captcha21.exe8.21.33.134cwpro1.crosswinds.net.Koobface-14112
2010/03/08_19:36skybluephoto.com/.sys/?getexe=v2captcha21.exe8.21.33.134cwpro1.crosswinds.net.Koobface-14112
2010/03/08_19:36strictlydetail.co.uk/.sys/?getexe=pp.14.exe88.208.252.192-Koobface-15418
2010/03/08_19:36strictlydetail.co.uk/.sys/?getexe=v2captcha21.exe88.208.252.192-Koobface-15418
2010/03/08_19:36tinytanks.net/.sys/?getexe=pp.14.exe66.7.206.75server.petfish.net.Koobface-33182
2010/03/08_19:36tinytanks.net/.sys/?getexe=v2captcha21.exe66.7.206.75server.petfish.net.Koobface-33182
2010/03/08_19:36tinytanks.net/.sys/?getexe=v2prx.exe66.7.206.75server.petfish.net.Koobface-33182
2010/03/08_19:36troytabor.com/.sys/?getexe=v2captcha21.exe66.96.146.8181.146.96.66.static.eigbox.net.Koobface-29873
2010/03/08_19:36troytabor.com/.sys/?getexe=v2prx.exe66.96.146.8181.146.96.66.static.eigbox.net.Koobface-29873
2010/03/08_19:36undercoversquilting.com/.sys/?getexe=pp.14.exe209.132.201.41cp287.mysite4now.com.Koobface-36066
2010/03/08_19:36undercoversquilting.com/.sys/?getexe=v2bloggerjs.exe209.132.201.41cp287.mysite4now.com.Koobface-36066
2010/03/08_19:36undercoversquilting.com/.sys/?getexe=v2captcha21.exe209.132.201.41cp287.mysite4now.com.Koobface-36066
2010/03/08_19:36undercoversquilting.com/.sys/?getexe=v2newblogger.exe209.132.201.41cp287.mysite4now.com.Koobface-36066
2010/03/08_19:36vivicohen.com.ar/.sys/?getexe=v2captcha21.exe200.62.54.122us22.toservers.com.Koobface-118747
2010/03/08_19:36whyviral.com/.sys/?getexe=v2captcha21.exe12.68.140.207-Koobface-46549
2010/03/08_19:36www.bastakigroup.com/.sys/?getexe=v2captcha21.exe66.223.111.166ns.thewoodexplorer.com.Koobface-11305
2010/03/08_19:36www.chateaudecoisse.com/.sys/?getexe=v2captcha21.exe207.150.212.12-Koobface-20401
2010/03/08_19:36www.comunicat-de-presa.ro/.sys/?getexe=v2captcha21.exe89.42.216.60server32.whmpanels.com.Koobface-5606
2010/03/08_19:36www.derekmohr.com/.sys/?getexe=v2captcha21.exe207.150.212.89-Koobface-20401
2010/03/08_19:36www.eom.it/.sys/?getexe=v2captcha21.exe195.225.236.90-Koobface-31239
2010/03/08_19:36www.fivestar.ch/.sys/?getexe=v2captcha21.exe77.72.71.43043.lognet.ch.Koobface8404
2010/03/08_19:36www.its-email.co.uk/.sys/?getexe=v2bloggerjs.exe81.201.129.12681.201.129.126.srvlist.ukfast.net.Koobface-8553
2010/03/08_19:36www.its-email.co.uk/.sys/?getexe=v2captcha21.exe81.201.129.12681.201.129.126.srvlist.ukfast.net.Koobface-8553
2010/03/08_19:36www.nautiqa.com.sg/.sys/?getexe=v2bloggerjs.exe203.116.95.196-Koobface-4657
2010/03/08_19:36www.nautiqa.com.sg/.sys/?getexe=v2captcha21.exe203.116.95.196-Koobface-4657
2010/03/08_19:36www.pwsd1pc.org/.sys/?getexe=v2captcha21.exe207.192.234.27www.nemr.net.Koobface-33165
2010/03/08_19:36www.vallesina.tv/.sys/?getexe=v2captcha21.exe195.225.168.238-Koobface-31034
2010/03/08_19:36zihabit.com/.sys/?getexe=v2captcha21.exe208.87.242.66ant.unixbsd.info.Koobface-40676
2010/03/08_19:03dogshowonline.info/ldr/mdply3d.exe94.228.219.189-trojanMarek Mazur / Marek.Mazur@ymail.com47869
2010/03/08_19:03dogshowonline.info/ldr/pod.exe94.228.219.189-trojanMarek Mazur / Marek.Mazur@ymail.com47869
2010/03/08_19:03skyfleck.com/perfmonss.bin218.8.245.123-trojan RefpronAlexander Heuwinkel / wnje589@yahoo.com4837
2010/03/08_19:03catsshow2online.info/cln/?i_date=08-03-2010&aff_id=1&downloaded=&build_ver=2&os_ver=WIN_XP&debug=&fetches=0&cid=0xA594B3E11767F21050DE03DCB481E08894.228.219.189-malware calls homeMarek Mazur / Marek.Mazur@ymail.com47869
2010/03/08_19:03www.cfdnf.com/md.exe61.147.99.83-trojanZhao Haibo / zihui8@vip.qq.com4134
2010/03/08_19:03dwlmorss.dw.funpic.de/probot.exe213.202.225.53213.202.225.53.rdns.funpic.de.trojan Killavabuse@funpic.de13301
2010/03/08_19:03saleotu.com/get.php?id=162.122.75.42-trojanPrivate Whois Service h9ig5ay4b743bf796461@ahwyn0f4b73feacadaa2.privatewhois.net5577
2010/03/08_19:03www.978cf.com/fkz/yuyanzhe.exe61.155.170.30-backdoorcaobaoqiao / 172626510@qq.com4134
2010/03/08_19:03www.scanerwhatever.cn/page2/setup0191.212.132.8-trojan TDSSDuntonKristin / KristinDunton@xhotmail.net49091
2010/03/08_19:03gotsick.cn/css/_void/crcmds/main91.212.132.7-malware calls homeLEMPENAUGEORGE / georgelem@xhotmail.net49091
2010/03/08_19:03gotsick.cn/css/_void/knock.php91.212.132.7-malware calls homeLEMPENAUGEORGE / georgelem@xhotmail.net49091
2010/03/08_19:03gotsick.cn/css/_void/srcr.dat91.212.132.7-malware calls homeLEMPENAUGEORGE / georgelem@xhotmail.net49091
2010/03/08_19:03gotsick.cn/css/_void/crcmds/install91.212.132.7-malware calls homeLEMPENAUGEORGE / georgelem@xhotmail.net49091
2010/03/08_19:03gotsick.cn/css/_void/crfiles/serf91.212.132.7-malware calls homeLEMPENAUGEORGE / georgelem@xhotmail.net49091
2010/03/08_19:03gotsick.cn/css/_void/crcmds/builds/bbr91.212.132.7-malware calls homeLEMPENAUGEORGE / georgelem@xhotmail.net49091
2010/03/08_19:03gotsick.cn/css/_void/crfiles/bbr91.212.132.7-malware calls homeLEMPENAUGEORGE / georgelem@xhotmail.net49091
2010/03/08_19:03gotsick.cn/css/_void/crcmds/extra91.212.132.7-malware calls homeLEMPENAUGEORGE / georgelem@xhotmail.net49091
2010/03/08_18:21gerbalaif.com/account91.213.174.9-control panel of botnet C&Cgoodys / abuseemaildhcp@gmail.com29106
2010/03/08_18:21arriviertes.com/rihBeufAQU917Xa.php?id=1&magic=40594073691.213.174.3-malware calls homeNini Lee / ninilee@yahoo.com29106
2010/03/08_18:21whydaddy.biz/91.213.174.9-redirects to botnet control panelHillery Harris / refaerdomain@gmail.com29106
2010/03/08_18:21gerbalaif.com/knok.php?id=SYSTEM!82536A52D9654DB!083C3353&ver=3&up=2732&91.213.174.9-botnet C&Cgoodys / abuseemaildhcp@gmail.com29106
2010/03/08_15:21podmena.us/1100_0005.exe69.65.40.26cp05.buyhttp.com.fake avAlex Tramp / sh-kesha@ya.ru32181
2010/03/08_14:33openaskelisto.com/main1/open.gif85.12.46.22-zeus/wsnpoem v2 config fileHary / admin@asusufurmeh.com34305
2010/03/08_11:38-195.242.161.111/~chetir/chet/n.php-zeus/wsnpoem v2 drop zone-47434
2010/03/08_11:38-95.143.192.35/~clients/version.php-zeus/wsnpoem v2 drop zone-49770
2010/03/08_10:25papindos.info/checkVersions/database.dat85.12.46.7-zeus/wsnpoem v2 config fileShoen Overns / ovenersbox@yahoo.com34305
2010/03/08_10:25papindos.info/expertAds/FileMirror.php85.12.46.7-zeus/wsnpoem v2 drop zoneShoen Overns / ovenersbox@yahoo.com34305
2010/03/08_10:25bestreportwas142.in/urrla/c1.bin188.124.3.225static.vitalhosting.com.tr.zeus/wsnpoem v2 config filevaleriy / rikollenis@gmail.com44565
2010/03/08_10:25bestreportwas142.in/urrla/hey.php188.124.3.225static.vitalhosting.com.tr.zeus/wsnpoem v2 drop zonevaleriy / rikollenis@gmail.com44565
2010/03/08_10:25-193.105.0.211/royalkingston.bin-zeus/wsnpoem v2 config file-50390
2010/03/08_10:25-193.105.0.211/rtr89i7uyt.exe-zeus/wsnpoem v2 trojan-50390
2010/03/08_10:25-193.105.0.211/njtrefg67i7.php-zeus/wsnpoem v2 drop zone-50390
2010/03/08_10:25usworldcast.com/100/cfg33.bin188.124.5.106static.vitalhosting.com.tr.zeus/wsnpoem v2 config filerekon / vin345686866664444@gmail.com44565
2010/03/08_10:25manyafa.com/m0933/stat1.php188.124.5.118static.vitalhosting.com.tr.zeus/wsnpoem v2 drop zonevin.bond@gmail.com44565
2010/03/08_10:25salebogs.com/scn/022e0c0781be117a248ab0dd5002e7bd/0540f0d2bb566d0ed0d80150e2b728ef/f85b7b377112c272bc87f3e73f10508d213.163.65.2hosted-by.i3d.net.fake online ScannerFitah Ulaf / f.ulaf@hush.com49544
2010/03/08_10:25chephall.com/download/0540f0d2bb566d0ed0d80150e2b728ef/f85b7b377112c272bc87f3e73f10508d/491.212.127.144-trojan FakeSmokeczw06nc4b90e8f4704a6@ahwyn0f4b73feacadaa2.privatewhois.net49087
2010/03/08_08:17milzvortex.info/gate.php69.175.66.34cl67.justhost.com.zeus/wsnpoem v2 drop zoneJonathan Kaufman / admin@naqzo.com32475
2010/03/08_08:11milzvortex.info/config.bin69.175.66.34cl67.justhost.com.zeus/wsnpoem v2 config fileJonathan Kaufman / admin@naqzo.com32475
2010/03/08_08:11milzvortex.info/bot.exe69.175.66.34cl67.justhost.com.zeus/wsnpoem v2 trojanJonathan Kaufman / admin@naqzo.com32475
2010/03/07_21:37tieos.com/new/show.php85.17.90.206hosted-by.leaseweb.com.NULLED/Fragus exploit kitKabinkova Kristina / Kristina (kabinkovakristina@yahoo.com)16265
2010/03/07_21:37tieos.com/new/admin.php85.17.90.206hosted-by.leaseweb.com.control panel of NULLED/Fragus exploit kitKabinkova Kristina / Kristina (kabinkovakristina@yahoo.com)16265
2010/03/07_21:37tieos.com/new/post.php85.17.90.206hosted-by.leaseweb.com.zeus/wsnpoem v2 trojanKabinkova Kristina / Kristina (kabinkovakristina@yahoo.com)16265
2010/03/07_20:58-193.105.0.101/hgbvfe5yju.exe-zeus/wsnpoem v2 trojan-50390
2010/03/07_20:58-193.105.0.101/kaspers.bin-zeus/wsnpoem v2 config file-50390
2010/03/07_20:58-193.105.0.101/dfghnybtvj.php-zeus/wsnpoem v2 drop zone-50390
2010/03/07_20:58www.iiiiiiiiiiiiii.net/games/update.set203.174.83.98203-174-83-98.rev.ne.com.sg.zeus/wsnpoem v2 config fileAlexander A Reva / klimckoe@yahoo.com38001
2010/03/07_20:58www.iiiiiiiiiiiiii.net//games/update.php203.174.83.98203-174-83-98.rev.ne.com.sg.zeus/wsnpoem v2 drop zoneAlexander A Reva / klimckoe@yahoo.com38001
2010/03/07_20:58cpaos.com/new/viewtopic.php?s=7b5c3dff4685.17.90.206hosted-by.leaseweb.com.NULLED/Fragus exploit kitKabinkova Kristina / Kristina (kabinkovakristina@yahoo.com)16265
2010/03/07_20:58cpaos.com/new/admin.php85.17.90.206hosted-by.leaseweb.com.control panel of NULLED/Fragus exploit kitKabinkova Kristina / Kristina (kabinkovakristina@yahoo.com)16265
2010/03/07_20:58cpaos.com/new/post.php85.17.90.206hosted-by.leaseweb.com.trojan Oficla/SasfisKabinkova Kristina / Kristina (kabinkovakristina@yahoo.com)16265
2010/03/07_20:58aafoocgv.cn/el2/index.php91.212.41.87-Eleonore Exploits pack v1.3.3wang9619@163.com29371
2010/03/07_20:58aafoocgv.cn/el2/stat.php91.212.41.87-control panel of Eleonore Exploits pack v1.3.3wang9619@163.com29371
2010/03/07_20:58aafoocgv.cn/el2/load/load.exe91.212.41.87-trojanwang9619@163.com29371
2010/03/07_20:58autotradersuk.net/arc/bb.php?v=200&id=554905388&b=0306les&tm=385.17.90.206hosted-by.leaseweb.com.Oficla/Sasfis C&Cedininskovvaleriy@mail.com16265
2010/03/07_20:58topesuna.com/v2/out/flash_10_10.exe85.17.87.159-trojan downloaderKokovin Vladimir / Vladimir (kokovinvladimir@gmail.com)16265
2010/03/07_20:58rlosswe.com/win32.exe61.4.82.216-trojan Kobckaw8231058@163.com17964
2010/03/07_19:11ad0ra8ili7y.com/index.php?s=3e5cf2bce9808386868aa6270d6a787791.213.174.22-Eleonore Exploits pack v1.3.2Nini Lee / ninilee@yahoo.com29106
2010/03/07_19:11ad0ra8ili7y.com/stat.php91.213.174.22-control panel of Eleonore Exploits pack v1.3.2Nini Lee / ninilee@yahoo.com29106
2010/03/07_19:11ad0ra8ili7y.com/UT1Wf-l.php/2aaaa5cb544cf49656cb609d48407c88?spl=pdf_202291.213.174.22-bot, C&C at volosanka.cnNini Lee / ninilee@yahoo.com29106
2010/03/07_19:11aciraee.com/index.php?s=5ca68bcfbc2ecbdef4c1890bf171187691.213.174.14-Eleonore Exploits pack v1.3.2Nini Lee / ninilee@yahoo.com29106
2010/03/07_19:11aciraee.com/stat.php91.213.174.14-Eleonore Exploits pack v1.3.2Nini Lee / ninilee@yahoo.com29106
2010/03/07_19:11adidasmikey.com/index.php?s=3e5cf2bce9808386868aa6270d6a787791.213.174.22--Nini Lee / ninilee@yahoo.com29106
2010/03/07_19:11adidasmikey.com/stat.php91.213.174.22-control panel of Eleonore Exploits pack v1.3.2Nini Lee / ninilee@yahoo.com29106
2010/03/07_19:11www.ucheba.ru85.192.36.173173.160-191.36.192.85.in-addr.arpa.iframe directs to exploit kitadministrator@rdw.ru12695
2010/03/07_19:11aylmershotgun.com/index.php?s=1b9e7bf762c6f459848ec04d4390a33a91.213.174.22-Eleonore Exploits pack v1.3.2Nini Lee / ninilee@yahoo.com29106
2010/03/07_19:11aylmershotgun.com/stat.php91.213.174.22-control panel of Eleonore Exploits pack v1.3.2Nini Lee / ninilee@yahoo.com29106
2010/03/07_18:18horovod.in/soft/load.php?id=CNwdYyWTfvsmxDY&src=&requestID=sHVSkgmfwI188.124.16.18static.vit.com.tr.trojan HilotiSofia Grekova / sofiagrekova@yahoo.com44565
2010/03/07_18:18horovod.in/soft/load.php?id=CNwdYyWTfvsmxDY&src=&requestID=tzrLKzfWDY188.124.16.18static.vit.com.tr.fake av downloaderSofia Grekova / sofiagrekova@yahoo.com44565
2010/03/07_18:18horovod.in/soft/load.php?id=CNwdYyWTfvsmxDY&src=&requestID=fdJhxQSJOF188.124.16.18static.vit.com.tr.trojan TDSSSofia Grekova / sofiagrekova@yahoo.com44565
2010/03/07_18:00kornoval.in/counter/188.124.16.18static.vit.com.tr.exploit kitSofia Grekova / sofiagrekova@yahoo.com44565
2010/03/07_18:00kornoval.in/counter/jar.jar188.124.16.18static.vit.com.tr.java exploitSofia Grekova / sofiagrekova@yahoo.com44565
2010/03/07_18:00kornoval.in/counter/exe.php?src=&x=jas188.124.16.18static.vit.com.tr.trojanSofia Grekova / sofiagrekova@yahoo.com44565
2010/03/07_18:00kornoval.in/counter/pdf.php?src=188.124.16.18static.vit.com.tr.pdf exploitSofia Grekova / sofiagrekova@yahoo.com44565
2010/03/07_18:00kornoval.in/counter/exe.php?src=&x=mdac188.124.16.18static.vit.com.tr.trojanSofia Grekova / sofiagrekova@yahoo.com44565
2010/03/07_18:00kornoval.in/counter/exe.php?src=&x=snap188.124.16.18static.vit.com.tr.trojanSofia Grekova / sofiagrekova@yahoo.com44565
2010/03/07_17:45mioanali.com/188.124.9.69static.vitalhosting.com.tr.SEO Sploit kitvin.bond@gmail.com44565
2010/03/07_17:45mioanali.com/stat.php188.124.9.69static.vitalhosting.com.tr.control panel of SEO Sploit kitvin.bond@gmail.com44565
2010/03/07_17:45mioanali.com/mdac.php188.124.9.69static.vitalhosting.com.tr.mdac exploitvin.bond@gmail.com44565
2010/03/07_17:45mioanali.com/newload.php?ids=MDAC188.124.9.69static.vitalhosting.com.tr.dropper for several malware, e.g. Zeusvin.bond@gmail.com44565
2010/03/07_17:45mioanali.com/pdfadmnplay.php188.124.9.69static.vitalhosting.com.tr.directs to pdf exploitsvin.bond@gmail.com44565
2010/03/07_17:45mioanali.com/files/itisnogoclear.pdf188.124.9.69static.vitalhosting.com.tr.pdf exploitvin.bond@gmail.com44565
2010/03/07_17:45mioanali.com/files/hardworkbreasts.pdf188.124.9.69static.vitalhosting.com.tr.pdf exploitvin.bond@gmail.com44565
2010/03/07_17:45mioanali.com/loadpdf.php188.124.9.69static.vitalhosting.com.tr.dropper for several malware, e.g. Zeusvin.bond@gmail.com44565
2010/03/07_17:45mioanali.com/konec.php188.124.9.69static.vitalhosting.com.tr.directs to java exploitvin.bond@gmail.com44565
2010/03/07_17:45mioanali.com/files/common.jar188.124.9.69static.vitalhosting.com.tr.java exploitvin.bond@gmail.com44565
2010/03/07_17:45mioanali.com/loadjavad.php?page=1188.124.9.69static.vitalhosting.com.tr.dropper for several malware, e.g. Zeusvin.bond@gmail.com44565
2010/03/07_17:45arraysaw.net/188.124.9.69static.vitalhosting.com.tr.SEO Sploit kitvin.bond@gmail.com44565
2010/03/07_17:45arraysaw.net/stat.php188.124.9.69static.vitalhosting.com.tr.control panel of SEO Sploit kitvin.bond@gmail.com44565
2010/03/07_17:45arraysaw.net/mdac.php188.124.9.69static.vitalhosting.com.tr.mdac exploitvin.bond@gmail.com44565
2010/03/07_17:45arraysaw.net/newload.php?ids=MDAC188.124.9.69static.vitalhosting.com.tr.dropper for several malware, e.g. Zeusvin.bond@gmail.com44565
2010/03/07_17:45arraysaw.net/pdfadmnplay.php188.124.9.69static.vitalhosting.com.tr.directs to pdf exploitsvin.bond@gmail.com44565
2010/03/07_17:45arraysaw.net/files/heardthatpolice.pdf188.124.9.69static.vitalhosting.com.tr.pdf exploitvin.bond@gmail.com44565
2010/03/07_17:45arraysaw.net/files/goofybeautiful.pdf188.124.9.69static.vitalhosting.com.tr.pdf exploitvin.bond@gmail.com44565
2010/03/07_17:45arraysaw.net/loadpdf.php188.124.9.69static.vitalhosting.com.tr.dropper for several malware, e.g. Zeusvin.bond@gmail.com44565
2010/03/07_17:45arraysaw.net/konec.php188.124.9.69static.vitalhosting.com.tr.directs to java exploitvin.bond@gmail.com44565
2010/03/07_17:45arraysaw.net/files/common.jar188.124.9.69static.vitalhosting.com.tr.java exploitvin.bond@gmail.com44565
2010/03/07_17:45arraysaw.net/loadjavad.php?page=1188.124.9.69static.vitalhosting.com.tr.dropper for several malware, e.g. Zeusvin.bond@gmail.com44565
2010/03/07_17:19solaruploader.com/46.exe188.124.9.56static.vitalhosting.com.tr.trojan dropperNicole Kidman / bei978097804@gmail.com44565
2010/03/07_17:00fhjslk21.org/b/cfg275.bin61.61.20.134-zeus/wsnpoem v2 config fileHilary Kneber / hilarykneber@yahoo.com9918
2010/03/07_17:00fhjslk21.org/75/e.php61.61.20.134-zeus/wsnpoem v2 drop zoneHilary Kneber / hilarykneber@yahoo.com9918
2010/03/07_17:00salebotw.com/scn/7a3f4f13e300335dd0260efc4514fb1c/0540f0d2bb566d0ed0d80150e2b728ef/f85b7b377112c272bc87f3e73f10508d194.54.83.163163.83.54.194.static.server.ua.fake online ScannerFitah Ulaf / Pf.ulaf@hush.com41671
2010/03/07_17:00ottalfight.com/scn/0e65e06120d6c118331cbb7a896e7e5a/0540f0d2bb566d0ed0d80150e2b728ef/f85b7b377112c272bc87f3e73f10508d194.54.83.163163.83.54.194.static.server.ua.fake online ScannerMartin Sterling / Martin.sterling@mail.com41671
2010/03/07_17:00cheaphgall.com/download/0540f0d2bb566d0ed0d80150e2b728ef/f85b7b377112c272bc87f3e73f10508d/491.212.127.144-trojan FakeSmokePrivate Whois Service jdjzh7v4b90e8ec9e775@ahwyn0f4b73feacadaa2.privatewhois.net49087
2010/03/07_17:00lettsoiol.com/download/0540f0d2bb566d0ed0d80150e2b728ef/f85b7b377112c272bc87f3e73f10508d/491.212.127.144-trojan FakeSmokePrivate Whois Service v4ubvba4b8fb9ea37c67@ahwyn0f4b73feacadaa2.privatewhois.net49087
2010/03/07_17:00trstcam.com/download/0540f0d2bb566d0ed0d80150e2b728ef/f85b7b377112c272bc87f3e73f10508d/491.212.127.144-trojan FakeSmokePrivate Whois Service vfc9nzp4b7e775d3ef93@ahwyn0f4b73feacadaa2.privatewhois.net49087
2010/03/07_17:00www.antivpc.com/agaz17mgxagaz17mgx.htm?get=e0b399bd994a0556517f96487dd3ab29212.150.147.46-rogue avPrivate Whois Service ie6re764b7440466e32b@ahwyn0f4b73feacadaa2.privatewhois.net1680
2010/03/07_17:00www.pcs-av.com/asvzgdwebasvzgdweb.htm?get=e0b399bd994a0556517f96487dd3ab29212.150.147.46-rogue avacbu0he4b7440463f178@ahwyn0f4b73feacadaa2.privatewhois.net1680
2010/03/07_16:06www.scanerwhatever.cn/page2/setup91.212.132.8-fake avDuntonKristin / KristinDunton@xhotmail.net49091
2010/03/07_15:58n1ews.hermison.com/200.63.44.247-exploit kitJeff Anderson / skeletor71@comcast.net27716
2010/03/07_15:58n1ews.hermison.com/pdf.php200.63.44.247-pdf exploitJeff Anderson / skeletor71@comcast.net27716
2010/03/07_15:58n1ews.hermison.com/nc.jar200.63.44.247-java exploitJeff Anderson / skeletor71@comcast.net27716
2010/03/07_15:58n1ews.hermison.com/exe.php?spl=MDAC200.63.44.247-trojan downloaderJeff Anderson / skeletor71@comcast.net27716
2010/03/07_15:58n1ews.hermison.com/exe.php?spl=java200.63.44.247-trojan downloaderJeff Anderson / skeletor71@comcast.net27716
2010/03/07_15:58greatarray.com/188.124.9.69static.vitalhosting.com.tr.SEO Sploit packvin.bond@gmail.com44565
2010/03/07_15:58greatarray.com/mdac.php188.124.9.69static.vitalhosting.com.tr.MDAC exploitvin.bond@gmail.com44565
2010/03/07_15:58greatarray.com/newload.php?ids=MDAC188.124.9.69static.vitalhosting.com.tr.dropper for several malware, e.g. Zeusvin.bond@gmail.com44565
2010/03/07_15:58greatarray.com/pdfadmnplay.php188.124.9.69static.vitalhosting.com.tr.directs to pdf exploitvin.bond@gmail.com44565
2010/03/07_15:58greatarray.com/files/grindgrub.pdf188.124.9.69static.vitalhosting.com.tr.pdf exploitvin.bond@gmail.com44565
2010/03/07_15:58greatarray.com/files/contrivenotconvergefusty.pdf188.124.9.69static.vitalhosting.com.tr.pdf exploitvin.bond@gmail.com44565
2010/03/07_15:58greatarray.com/loadpdf.php188.124.9.69static.vitalhosting.com.tr.dropper for several malware, e.g. Zeusvin.bond@gmail.com44565
2010/03/07_15:58greatarray.com/konec.php188.124.9.69static.vitalhosting.com.tr.directs to java exploitvin.bond@gmail.com44565
2010/03/07_15:58greatarray.com/files/gsb50.jar188.124.9.69static.vitalhosting.com.tr.java exploitvin.bond@gmail.com44565
2010/03/07_15:58greatarray.com/files/common.jar188.124.9.69static.vitalhosting.com.tr.java exploitvin.bond@gmail.com44565
2010/03/07_15:58greatarray.com/loadjavad.php188.124.9.69static.vitalhosting.com.tr.dropper for several malware, e.g. Zeusvin.bond@gmail.com44565
2010/03/07_15:34analitocs.com/188.124.9.69static.vitalhosting.com.tr.SEO Sploit packvin.bond@gmail.com44565
2010/03/07_15:34analitocs.com/admin.php188.124.9.69static.vitalhosting.com.tr.control panel of SEO Sploit packvin.bond@gmail.com44565
2010/03/07_15:34analitocs.com/mdac.php188.124.9.69static.vitalhosting.com.tr.directs to mdac exploitvin.bond@gmail.com44565
2010/03/07_15:34analitocs.com/newload.php?ids=MDAC188.124.9.69static.vitalhosting.com.tr.dropper for several malware, e.g. Zeusvin.bond@gmail.com44565
2010/03/07_15:34analitocs.com/pdfadmnplay.php188.124.9.69static.vitalhosting.com.tr.directs to pdf exploitsvin.bond@gmail.com44565
2010/03/07_15:34analitocs.com/files/jivegood.pdf188.124.9.69static.vitalhosting.com.tr.pdf exploitvin.bond@gmail.com44565
2010/03/07_15:34analitocs.com/files/suckcat.pdf188.124.9.69static.vitalhosting.com.tr.pdf exploitvin.bond@gmail.com44565
2010/03/07_15:34analitocs.com/konec.php188.124.9.69static.vitalhosting.com.tr.directs to java exploitvin.bond@gmail.com44565
2010/03/07_15:34analitocs.com/files/common.jar188.124.9.69static.vitalhosting.com.tr.java exploitvin.bond@gmail.com44565
2010/03/07_12:32-193.105.0.23/gairichi.bin-zeus/wsnpoem v2 config file-50390
2010/03/07_12:32-193.105.0.23/juytrert5h6.php-zeus/wsnpoem v2 drop zone-50390
2010/03/07_12:32-193.105.0.23/ynbhgbj65r.exe-zeus/wsnpoem v2 trojan-50390
2010/03/07_12:32-193.105.0.202/sandyx.bin-zeus/wsnpoem v2 config file-50390
2010/03/07_12:32-193.105.0.202/ryjhtr78u.exe-zeus/wsnpoem v2 trojan-50390
2010/03/07_12:32-193.105.0.202/23iuyt.php-zeus/wsnpoem v2 drop zone-50390
2010/03/07_12:32-193.105.0.96/olimp.bin-zeus/wsnpoem v2 config file-50390
2010/03/07_12:32-193.105.0.96/dfgerg46hh.exe-zeus/wsnpoem v2 trojan-50390
2010/03/07_12:32-193.105.0.96/rth4554ght.php-zeus/wsnpoem v2 drop zone-50390
2010/03/07_12:32-92.60.177.232/crypt_Rapport.exegrusha-92-60-177-232.hostinghutor.com.trojan-15772
2010/03/07_11:36www.google-statistics-uk.com/jhtcd6u52nmTGHNQ25MUAym23GSajt2835JMhgsHJ735he.php61.4.82.216-zeus/wsnpoem v2 drop zonejeff anderson / skeletor71@comcast.net17964
2010/03/07_11:36aaa419.com/vv12218/mmmi1871.php61.4.82.249-zeus/wsnpoem v2 drop zonejeff anderson / skeletor71@comcast.net17964
2010/03/07_11:36socks5.real-host.ru/admins/index1.php92.60.176.41real-host.ru.zeus/wsnpoem v2 drop zonesupport@real-host.ru15772
2010/03/07_11:36www.gaddem.net/scam/gat.php61.4.82.222-zeus/wsnpoem v2 drop zonePavel Pugachev / ya_whois@yandex.ru17964
2010/03/07_11:36logislat.com/zs/gate.php115.100.250.105-zeus/wsnpoem v2 drop zoneYu MingSuo / abuseemaildhcp@gmail.com9803
2010/03/07_11:36nordrilskre.com/cgi-binn/hitss.php124.217.239.158-zeus/wsnpoem v2 drop zoneAlina Mazuka karlshening@yahoo.com45420
2010/03/07_11:36blacktraf.su/zevs/gate.php122.115.63.24netnic.com.cn.zeus/wsnpoem v2 drop zonedinontt@gmail.com9803
2010/03/07_11:36cam.rubberduck.ws/z28/access.php188.124.15.180static.vit.com.tr.zeus/wsnpoem v2 drop zoneRupert Dobre44565
2010/03/07_11:36centryfag.com/error/404.php216.12.207.250saturn.phpwebhosting.com.zeus/wsnpoem v2 drop zoneShane Betrue21844
2010/03/07_11:36narkyl.com/404/error.php198.66.210.22narkyl.com.zeus/wsnpoem v2 drop zoneJames Lonergan / nesquick01@safe-mail.net2914
2010/03/07_11:36ddknet.biz/hi/grate.php61.4.82.249-zeus/wsnpoem v2 drop zonecontact@privacyprotect.org17964
2010/03/07_11:36olypoos.com/123/cgi-bin/gate.php115.100.250.105-zeus/wsnpoem v2 drop zoneReal Host / abuseemaildhcp@gmail.com9803
2010/03/07_11:32tagbuckets.com/qwerty.exe91.201.28.58-trojanpusto-pusto@hotmail.com44107
2010/03/07_11:32unlockers122.info/ata.exe74.208.210.240perfora.net.zeus/wsnpoem v2 trojanelizabeth ch / allanos.bortos79@yahoo.com8560
2010/03/07_11:24ceffincf.com/fuama/show.php93.186.127.211static.vitalhosting.com.tr.Fragus exploit kitAlbert Zeveritch / albertxxl@gmail.com44565
2010/03/07_11:24ceffincf.com/fuama/admin.php93.186.127.211static.vitalhosting.com.tr.control panel of Fragus exploit kitAlbert Zeveritch / albertxxl@gmail.com44565
2010/03/07_11:24ceffincf.com/fuama/load.php?e=193.186.127.211static.vitalhosting.com.tr.botAlbert Zeveritch / albertxxl@gmail.com44565
2010/03/07_11:24mennlyndy.com/mendus/gate.php?magic=103410350001&ox=2-5-1-2600&tm=5&id=55167822&cache=2835167791&N=093.186.127.238static.vitalhosting.com.tr.malware calls homeAlbert Zeveritch / albertxxl@gmail.com44565
2010/03/07_11:24adpool-3.com/cgi-bin/npr/web/t_new.cgi?magic=103457470000;ox=2-5-1-2600;tm=60&id=-1&cache=133420825693.190.137.98-malware calls homeMichael Voronin / info@wtsexp.com49981
2010/03/07_11:24globalhead.net/besvchst.exe74.127.7.8manashosting.biz.trojannone / nawaz.rahman@gmail.com7393
2010/03/07_11:24clipplaces.com/file.exe91.201.28.58-trojanpusto-pusto@hotmail.com44107
2010/03/07_11:24horovod.in/soft/exe/severa.exe188.124.16.18static.vit.com.tr.fake av downloaderSofia Grekova / sofiagrekova@yahoo.com44565
2010/03/07_11:24-95.143.192.161/phpen_hfkqkepaa.exe-fake av-49770
2010/03/07_11:24i-want-u.ru/cgi-bin/click68.232.188.18068.232.188.180.choopa.net.NeoSploitinfo@i-want-u.ru20473
2010/03/07_11:24rezervzv.ru/ele/index.php193.200.255.10s10.x-host.net.ua.Eleonore Exploits pack v1.2 fofkmh@mail.ru25456
2010/03/07_11:24rezervzv.ru/ele/stat.php193.200.255.10s10.x-host.net.ua.control panel of Eleonore Exploits pack v1.2 fofkmh@mail.ru25456
2010/03/07_11:24rezervzv.ru/ele/getexe.php?spl=mdac193.200.255.10s10.x-host.net.ua.zeus/wsnpoem v2 trojan fofkmh@mail.ru25456
2010/03/07_10:12www.grahamscaner.cn/page2/setup01193.169.234.31-trojan TDSSRaymondiRick / RickRaymondi@xhotmail.net32181
2010/03/07_10:12www.grahamscaner.cn/page2/setup193.169.234.31-trojan TDSSRaymondiRick / RickRaymondi@xhotmail.net32181
2010/03/07_10:12www.stationsecurity.com/page2/setup0191.212.127.86-trojan TDSSMarkus Shishkas / MarkusShishkas@gmail.com49087
2010/03/07_10:12findreliable.org/css/_void/crcmds/main92.48.91.14792-48-91-147.static.as29550.net.malware calls homeLee Majmin / leemajmin@xhotmail.net29550
2010/03/07_10:12www.stationsecurity.com/page2/setup91.212.127.86-trojan TDSSMarkus Shishkas / MarkusShishkas@gmail.com49087
2010/03/07_10:12findreliable.org/css/_void/knock.php92.48.91.14792-48-91-147.static.as29550.net.malware calls homeLee Majmin / leemajmin@xhotmail.net29550
2010/03/07_10:12findreliable.org/css/_void/srcr.dat92.48.91.14792-48-91-147.static.as29550.net.malware calls homeLee Majmin / leemajmin@xhotmail.net29550
2010/03/07_10:12findreliable.org/css/_void/crcmds/install92.48.91.14792-48-91-147.static.as29550.net.malware calls homeLee Majmin / leemajmin@xhotmail.net29550
2010/03/07_10:12findreliable.org/css/_void/crfiles/serf92.48.91.14792-48-91-147.static.as29550.net.malware calls homeLee Majmin / leemajmin@xhotmail.net29550
2010/03/07_10:12findreliable.org/css/_void/crcmds/builds/bbr92.48.91.14792-48-91-147.static.as29550.net.malware calls homeLee Majmin / leemajmin@xhotmail.net29550
2010/03/07_10:12findreliable.org/css/_void/crfiles/bbr92.48.91.14792-48-91-147.static.as29550.net.malware calls homeLee Majmin / leemajmin@xhotmail.net29550
2010/03/07_10:12findreliable.org/css/_void/crcmds/extra92.48.91.14792-48-91-147.static.as29550.net.malware calls homeLee Majmin / leemajmin@xhotmail.net29550
2010/03/07_10:12-188.124.15.228/sw/8654/03010/0/4b9b3fc6-c42b-3fc6-3fc6-36710fa08b69/e6bb2271-a00e-4d35-b148-2c503fd58837/x.datstatic.vit.com.tr.--44565
2010/03/07_10:12abc.ispesk.com/a3.exe98.126.132.252ALBANIAMIX.NET.132.126.98.in-addr.arpa.Adware Cinmus ming li / hetao160@163.com4213
2010/03/07_10:12abc.ispesk.com/a4.exe98.126.132.252ALBANIAMIX.NET.132.126.98.in-addr.arpa.Adware Cinmus ming li / hetao160@163.com4213
2010/03/07_10:12abc.ispesk.com/a5.exe98.126.132.252ALBANIAMIX.NET.132.126.98.in-addr.arpa.trojan ming li / hetao160@163.com4213
2010/03/07_10:12abc.ispesk.com/a7.exe98.126.132.252ALBANIAMIX.NET.132.126.98.in-addr.arpa.trojan downloader Saffle ming li / hetao160@163.com4213
2010/03/07_10:12abc.ispesk.com/a8.exe98.126.132.252ALBANIAMIX.NET.132.126.98.in-addr.arpa.trojan OnlinesGames ming li / hetao160@163.com4213
2010/03/07_10:12abc.ispesk.com/a9.exe98.126.132.252ALBANIAMIX.NET.132.126.98.in-addr.arpa.Adware Rugo ming li / hetao160@163.com4213
2010/03/07_10:12abc.ispesk.com/a10.exe98.126.132.252ALBANIAMIX.NET.132.126.98.in-addr.arpa.trojan ming li / hetao160@163.com4213
2010/03/07_10:12abc.ispesk.com/a11.exe98.126.132.252ALBANIAMIX.NET.132.126.98.in-addr.arpa.trojan OnlinesGames ming li / hetao160@163.com4213
2010/03/07_10:12abc.ispesk.com/a12.exe98.126.132.252ALBANIAMIX.NET.132.126.98.in-addr.arpa.trojan downloader ming li / hetao160@163.com4213
2010/03/07_10:12abc.ispesk.com/tjn/2.exe98.126.132.252ALBANIAMIX.NET.132.126.98.in-addr.arpa.backdoor ming li / hetao160@163.com4213
2010/03/07_10:12dd6s.zhuhc.cn:62518/jqk8.exe219.235.3.13host-219-235-3-13.iphost.gotonets.com.trojan dropper Wansrog 8026151@qq.com4812
2010/03/07_10:12dd6s.zhuhc.cn:62518/ken12.exe219.235.3.13host-219-235-3-13.iphost.gotonets.com.trojan downloader Liwak 8026151@qq.com4812
2010/03/07_09:53aa419.ru/doc2.doc85.12.24.16-zeus/wsnpoem v2 config fileaa419.ru@r01-service.ru34305
2010/03/07_09:53austinme.com/media/23/cfg.bin74.208.10.2s171042742.onlinehome.us.zeus/wsnpoem v2 config fileproxy804103@1and1-private-registration.com8560
2010/03/07_09:53greatuk.org/tt/cfg/config.bin193.104.22.100-zeus/wsnpoem v2 config fileHilary Kneber / hilarykneber@yahoo.com34305
2010/03/07_09:28-195.242.161.111/~chetir/chet/bm.png-zeus/wsnpoem v2 config file-47434
2010/03/07_09:28-91.201.196.37/ahGi5E.weoG3e-zeus/wsnpoem v2 config file-42229
2010/03/07_09:28-91.201.196.37/mai9Oo.exe-zeus/wsnpoem v2 trojan-42229
2010/03/07_09:28-91.201.196.38/ahGi5E.weoG3e-zeus/wsnpoem v2 config file-42229
2010/03/07_09:28-91.201.196.76/eiH8zi.Nai9ee-zeus/wsnpoem v2 config file-42229
2010/03/07_09:28-91.201.196.76/Hoo0Ae.exe-zeus/wsnpoem v2 trojan-42229
2010/03/07_09:28-91.201.196.76/Iet4uh.exe-zeus/wsnpoem v2 trojan-42229
2010/03/07_09:28-91.201.196.76/IWool8.OoN7ze-zeus/wsnpoem v2 config file-42229
2010/03/07_09:28-91.201.196.76/kee3aC.aey5Ch-zeus/wsnpoem v2 config file-42229
2010/03/07_09:28-91.201.196.76/Kohke1.exe-zeus/wsnpoem v2 trojan-42229
2010/03/07_09:28-91.201.196.77/eiH8zi.Nai9ee-zeus/wsnpoem v2 config file-42229
2010/03/07_09:28-91.201.196.77/IWool8.OoN7ze-zeus/wsnpoem v2 config file-42229
2010/03/07_09:28-91.201.196.77/kee3aC.aey5Ch-zeus/wsnpoem v2 config file-42229
2010/03/07_09:28-95.143.192.35/~clients/c/o/compliteOS.bin-zeus/wsnpoem v2 config file-49770
2010/03/07_09:28-95.143.192.35/~clients/m/s/msi32.exe-zeus/wsnpoem v2 trojan-49770
2010/03/07_09:28aaa419.com/vv12218/calc.exe61.4.82.249-zeus/wsnpoem v2 trojanjeff anderson / skeletor71@comcast.net17964
2010/03/07_09:28blacktraf.su/zevs/bot.exe122.115.63.24netnic.com.cn.zeus/wsnpoem v2 trojandinontt@gmail.com9803
2010/03/07_09:28blacktraf.su/zevs/cfg.bin122.115.63.24netnic.com.cn.zeus/wsnpoem v2 config filedinontt@gmail.com9803
2010/03/07_09:28cargounioninc.com/digit_alianse/ttt_makkopolo/GXzinExUBZDA8.bin59.53.91.102-zeus/wsnpoem v2 config filerouse@freemailbox.ru4134
2010/03/07_09:28centryfag.com/error/header.png216.12.207.250saturn.phpwebhosting.com.zeus/wsnpoem v2 config fileShane Betrue21844
2010/03/07_09:28ioretiop.com/oy/o/vs.bin122.115.63.30netnic.com.cn.zeus/wsnpoem v2 config fileTodd Echols moonbeam@konocti.net9803
2010/03/07_09:28logislat.com/zs/bot.exe115.100.250.105-zeus/wsnpoem v2 trojanYu MingSuo / abuseemaildhcp@gmail.com9803
2010/03/07_09:28lopokerasandco.hk/files/a.out91.212.41.89-zeus/wsnpoem v2 config filedomain@now.net.cn29371
2010/03/07_09:28narkyl.com/404/db_arch_01.exe198.66.210.22narkyl.com.zeus/wsnpoem v2 trojanJames Lonergan / nesquick01@safe-mail.net2914
2010/03/07_09:28narkyl.com/404/header.png198.66.210.22narkyl.com.zeus/wsnpoem v2 config fileJames Lonergan / nesquick01@safe-mail.net2914
2010/03/07_09:28olypoos.com/123/cgi-bin/config.bin115.100.250.105-zeus/wsnpoem v2 config fileReal Host / abuseemaildhcp@gmail.com9803
2010/03/07_09:28socks5.real-host.ru/admins/535345345435535.bin92.60.176.41real-host.ru.zeus/wsnpoem v2 config filesupport@real-host.ru15772
2010/03/07_09:28socks5.real-host.ru/admins/update.exe92.60.176.41real-host.ru.zeus/wsnpoem v2 trojansupport@real-host.ru15772
2010/03/07_09:28umor.sumy.ua/lx.cfg66.197.160.24566-197-160-245.hostnoc.net.zeus/wsnpoem v2 config fileshumov.sergey@gmail.com21788
2010/03/07_09:28www.google-statistics-uk.com/Y5v20t6Fdw7t3uT.bin61.4.82.216-zeus/wsnpoem v2 config filejeff anderson / skeletor71@comcast.net17964
2010/03/07_09:28z.sunbon.net/gate.php119.42.150.4343.1-255.150.42.119.in-addr.arpa.zeus/wsnpoem v2 drop zonechina com / 123@34.com45753
2010/03/07_09:28z.sunbon.net/z.exe119.42.150.4343.1-255.150.42.119.in-addr.arpa.zeus/wsnpoem v2 trojanchina com / 123@34.com45753
2010/03/07_09:28z.sunbon.net/z/cfg.bin119.42.150.4343.1-255.150.42.119.in-addr.arpa.zeus/wsnpoem v2 config filechina com / 123@34.com45753
2010/03/07_09:23thundhack7.ref-host.com/cfg.bin93.174.93.11hosting1.nl.santrex.net.zeus/wsnpoem v2 config fileref-host.com@protecteddomainservices.com29073
2010/03/07_09:23thundhack7.ref-host.com/gate.php93.174.93.11hosting1.nl.santrex.net.zeus/wsnpoem v2 drop zoneref-host.com@protecteddomainservices.com29073
2010/03/07_09:23thundhack7.ref-host.com/bt.exe93.174.93.11hosting1.nl.santrex.net.zeus/wsnpoem v2 trojanref-host.com@protecteddomainservices.com29073
2010/03/06_23:05tttbbbttt.ru/z/config.bin95.31.234.395-31-234-3.broadband.corbina.ru.zeus/wsnpoem v2 config fileshurikmailru@mail.ru8402
2010/03/06_23:05tttbbbttt.ru/z/svhost.exe95.31.234.395-31-234-3.broadband.corbina.ru.zeus/wsnpoem v2 trojanshurikmailru@mail.ru8402
2010/03/06_23:05tttbbbttt.ru/z/gate.php95.31.234.395-31-234-3.broadband.corbina.ru.zeus/wsnpoem v2 drop zoneshurikmailru@mail.ru8402
2010/03/06_23:05www.austinme.com/media/23/cfg.bin74.208.10.2s171042742.onlinehome.us.zeus/wsnpoem v2 config fileproxy804103@1and1-private-registration.com8560
2010/03/06_23:05www.austinme.com/media/23/setup.exe74.208.10.2s171042742.onlinehome.us.zeus/wsnpoem v2 trojanproxy804103@1and1-private-registration.com8560
2010/03/06_23:05www.freedose.info/webbinder/binder2.bin88.191.17.26sd-2179.dedibox.fr.zeus/wsnpoem v2 config fileanthony fiore / janekobywad@gmail.com12322
2010/03/06_23:05www.sicha-linna.com/brigus_saloma/prts.exe61.235.117.77-zeus/wsnpoem v1 trojanAlexey Vinyaev / stay@bigmailbox.ru9394
2010/03/06_23:05www.sicha-linna.com/brigus_saloma/s.php61.235.117.77-zeus/wsnpoem v1 drop zoneAlexey Vinyaev / stay@bigmailbox.ru9394
2010/03/06_23:05ygyg.net/cc/cfg.bin70.84.62.194gator15.hostgator.com.zeus/wsnpoem v1 config file5375b2ddb4b85d7a6120bb7dea1336f3-353092@contact.gandi.net21844
2010/03/06_22:13fiwzv.net/cms/cfg2.bin89.187.37.30host30-37.monitoring.md.zeus/wsnpoem v2 config fileOleg Lojko oleg.loyko@yahoo.com25129
2010/03/06_22:13fiwzv.net/cms/gate.php89.187.37.30host30-37.monitoring.md.zeus/wsnpoem v2 drop zoneOleg Lojko oleg.loyko@yahoo.com25129
2010/03/06_20:42bombozzz.com/bugaga/buga.exe122.115.63.8netnic.com.cn.zeus/wsnpoem v2 trojanabuseemaildhcp@gmail.com9803
2010/03/06_20:42bombozzz.com/newstart/botopriem.php122.115.63.8netnic.com.cn.zeus/wsnpoem v2 drop zoneabuseemaildhcp@gmail.com9803
2010/03/06_20:42bombozzz.com/bugaga/bugaga.bin122.115.63.8netnic.com.cn.zeus/wsnpoem v2 config fileabuseemaildhcp@gmail.com9803
2010/03/06_20:04motoavto.limewebs.com/serv/web/cn/config.bin64.90.182.181hfree001.limedomains.com.zeus/wsnpoem v2 config filezeus@limedomains.com11403
2010/03/06_20:04motoavto.limewebs.com/serv/web/gate.php64.90.182.181hfree001.limedomains.com.zeus/wsnpoem v2 drop zonezeus@limedomains.com11403
2010/03/06_20:04zeussave.comuv.com/cn/config.bin216.108.235.169serverpoint.com.zeus/wsnpoem v2 config file-26277
2010/03/06_20:04eurosport.ueuo.com/web/cn/config.bin216.245.218.246users.u.hosting.free.zeus/wsnpoem v2 config fileFreeWebHostingArea.com / FreeWebHostingArea.com (support@freewha.com)46475
2010/03/06_13:08nordrilskre.com/cgi-binn/kisme.bin124.217.239.158-zeus/wsnpoem v2 config fileAlina Mazuka karlshening@yahoo.com45420
2010/03/06_11:47romms.in/2/load/player_update.exe188.124.9.38static.vitalhosting.com.tr.rootkit TDSSJames J Trump / jessica357ass@gmail.com44565
2010/03/06_11:31gamevery1.ru/s3/217.23.8.72-exploit kitgfhe4556h@yahoo.com49981
2010/03/06_11:31gamevery1.ru/s3/file.php?spl=00md217.23.8.72-bot, C&C located on volosanka.cngfhe4556h@yahoo.com49981
2010/03/06_11:31gamevery1.ru/s2/217.23.8.72-exploit kitgfhe4556h@yahoo.com49981
2010/03/06_11:31gamevery1.ru/s2/file.php?spl=00md217.23.8.72-bot, C&C located on volosanka.cngfhe4556h@yahoo.com49981
2010/03/06_11:11ioretiop.com/eet/eoeo/o.php122.115.63.30netnic.com.cn.zeus/wsnpoem v2 drop zoneTodd Echols moonbeam@konocti.net9803
2010/03/06_11:02ioretiop.com/r/a/upd5.bin122.115.63.30netnic.com.cn.zeus/wsnpoem v2 config fileTodd Echols moonbeam@konocti.net9803
2010/03/06_11:02www.doctormiler.com/imagesflash/index.php91.212.41.14-zeus/wsnpoem v2 drop zoneKris Miller cheburaskogro@yahoo.com29371
2010/03/06_10:54www.greatuk.org/tt/cfg/config.bin193.104.22.100-zeus/wsnpoem v2 config fileHilary Kneber / hilarykneber@yahoo.com34305
2010/03/06_10:54www.greatuk.org/tt/bot/bot.exe193.104.22.100-zeus/wsnpoem v2 trojanHilary Kneber / hilarykneber@yahoo.com34305
2010/03/06_10:54www.greatuk.org/tt/gt.php193.104.22.100-zeus/wsnpoem v2 drop zoneHilary Kneber / hilarykneber@yahoo.com34305
2010/03/06_10:54-122.115.63.32/gus/tdnetnic.com.cn.zeus/wsnpoem v2 config file-9803
2010/03/06_10:54-122.115.63.32/gus/windir.exenetnic.com.cn.zeus/wsnpoem v2 trojan-9803
2010/03/06_10:54-124.217.230.39/~ddusa/7tImddbTH8HY.php-zeus/wsnpoem v2 drop zone-45839
2010/03/06_10:54abouttraffic.net/news/dim.exe95.143.192.59-zeus/wsnpoem v2 trojanVladislav Grenich / fob@freemailbox.ru49770
2010/03/06_09:34video-info.info/show.php91.212.41.88-directs to trojanJohoske George / videinfo@gmail.com29371
2010/03/06_09:34tubetechltd.com/xplay.php?id=4001866.45.255.226reverse255-226.reserver.ru.directs to trojanRalph L Furr / furr@chemist.com19318
2010/03/06_09:34greatmultimediaservices.com/video-plugin.40018.exe1.1.1.1-trojanJames Yeung / yeung@counsellor.com36561
2010/03/06_09:18cargoworldexchange.com/trendi_duglas/iojfiowejfio/tytorials.bin91.212.41.88-zeus/wsnpoem v2 config fileValeriy Dmitrievich Konstan / admin@cargoworldexchange.com29371
2010/03/06_00:44herewereytinj.com/tera/sv777/58.23.64.240-Eleonore Exploits pack v1.3.2contact@privacyprotect.org4837
2010/03/06_00:44herewereytinj.com/tera/sv777/stat.php58.23.64.240-control panel of Eleonore Exploits pack v1.3.2contact@privacyprotect.org4837
2010/03/06_00:44herewereytinj.com/tera/sv777/load.php?spl=pdf_pack58.23.64.240-backdoor Hodprotcontact@privacyprotect.org4837
2010/03/06_00:44tomorrrrow.cn/loader/bb.php?v=200&id=636608811&b=0196019827&tm=2122.115.63.57netnic.com.cn.Oficla/Sasfis C&CReal Host / abuseemaildhcp@gmail.com9803
2010/03/06_00:19vcipo.info/cgi-bin/login.htm74.118.192.166-NeoSploit, payload fake ava05e0d353ba24a34a899eefb9882f932.protect@whoisguard.com46664
2010/03/05_21:56av-guru.net79.135.152.55.152.135.79.microlines.lv.Rogue AVSemen Orokov / admin@av-guru.net2588
2010/03/05_21:56avcommand.net79.135.152.55.152.135.79.microlines.lv.Rogue AVTatjana Lozova / admin@avcommand.net2588
2010/03/05_21:56softcoregroup.com79.135.152.55.152.135.79.microlines.lv.Rogue AVVitaliy Rozov / admin@softcoregroup.com2588
2010/03/05_21:20ablegang.com/master/bb.php?id=465538349&v=200&tm=2&b=ruslann91.207.192.23-Oficla/Sasfis C&Ccontact@privacyprotect.org9269
2010/03/05_21:09cargounioninc.com/digit_alianse/gigager/morstils.php59.53.91.102-zeus/wsnpoem v2 drop zonerouse@freemailbox.ru4134
2010/03/05_21:09cargounioninc.com/digit_alianse/ttt_makkopolo/yJaILxquGyq3jeP.exe59.53.91.102-zeus/wsnpoem v2 trojanrouse@freemailbox.ru4134
2010/03/05_21:09cargoworldexchange.com/trendi_duglas/mama_geras/babilon.php91.212.41.88-zeus/wsnpoem v2 drop zoneValeriy Dmitrievich Konstan / admin@cargoworldexchange.com29371
2010/03/05_21:00-193.105.0.85/uj65vrev.exe-zeus/wsnpoem v2 trojan-50390
2010/03/05_21:00-193.105.0.85/scratkey.bin-zeus/wsnpoem v2 config file-50390
2010/03/05_21:00-193.105.0.85/dfh7445.php-zeus/wsnpoem v2 drop zone-50390
2010/03/05_20:25inroyal.info/fps/bb.php?v=200&id=482651473&b=semen&tm=5122.115.63.35netnic.com.cn.Oficla/Sasfis C&CAndrey Aleksandrovich Polev / o00o.code@gmail.com9803
2010/03/05_20:20puthere.info/fps/bb.php?v=200&id=482651443&b=semen&tm=5122.115.63.35netnic.com.cn.Oficla/Sasfis C&CBozvanovna L Olegovna / helukausa@yahoo.com9803
2010/03/05_19:17grepsync.com/86.57.246.177by104.activeby.net.ftp drop zone for stolen documentsNOSPAM ASSOCIATION / domains@atservers.com6697
2010/03/05_16:53castellanasportsclub.com/modules/mod_poll/5/in.php74.55.38.242svr96.edns1.com.exploit kitCASTELLANASPORTSCLUB.COM / fvm@castellanasportsclub.com21844
2010/03/05_16:53castellanasportsclub.com/modules/mod_poll/5/pdfNode.php74.55.38.242svr96.edns1.com.pdf exploitCASTELLANASPORTSCLUB.COM / fvm@castellanasportsclub.com21844
2010/03/05_16:53castellanasportsclub.com/modules/mod_poll/5/load.php?id=174.55.38.242svr96.edns1.com.zeus/wsnpoem v2 trojanCASTELLANASPORTSCLUB.COM / fvm@castellanasportsclub.com21844
2010/03/05_16:23adobeserverupdate.com/ezik.bin64.20.52.218-zeus/wsnpoem v2 config fileGary Cowan19318
2010/03/05_16:23adobeserverupdate.com/gate.php64.20.52.218-zeus/wsnpoem v2 drop zoneGary Cowan19318
2010/03/05_13:03samsonite-shop.cz/photos/images/0.exe88.146.119.130archie.thinline.cz.zeus/wsnpoem v2 trojaninfo@etasky.cz6706
2010/03/05_13:02antiviruspc-update.com/setup1.exe91.210.173.25lc-b25.lorercorp.com.fake av-48588
2010/03/05_13:02mydevnet.ca/zTw6Q50392.exe216.157.148.192hsphere.cc.trojan Hiloti-16557
2010/03/05_13:02yougoodvideo.net/exe/change.exe122.115.63.24netnic.com.cn.trojan Alureoncontact@privacyprotect.org9803
2010/03/05_13:02-92.60.177.238/file.exegrusha-92-60-177-238.hostinghutor.com.trojan Oficla/Sasfis-15772
2010/03/05_12:28-89.149.254.182/cache/anime6/cl.exe89-149-254-182.local.backdoor Hupigon, C&C 89.149.244.208/wm.php-28753
2010/03/05_11:39nsboxdownblodmids.com/s/gate.php?magic=105910600001&ox=2-5-1-2600&tm=1&id=91723646&cache=1971623625&N=0188.124.7.243static.vitalhosting.com.tr.malware calls homeshilovvladimir77@gmail.com44565
2010/03/05_11:39updatesupportsystem.com/update/gate.php?magic=103310350001&ox=2-5-1-2600&tm=2&id=1907106991&cache=&N=0188.124.5.10static.vitalhosting.com.tr.malware calls homeDaria Inozemtseva / ouch@maillife.ru44565
2010/03/05_09:28-193.105.0.210/revoltver.bin-zeus/wsnpoem v2 config file-50390
2010/03/05_09:28-193.105.0.210/antweprer.exe-zeus/wsnpoem v2 trojan-50390
2010/03/05_09:28-193.105.0.210/huizhu.php-zeus/wsnpoem v2 drop zone-50390
2010/03/05_09:11aeroninc.com/tytorials.bin115.100.250.105-zeus/wsnpoem v2 config fileOksana Boyko / sperm@corporatemail.ru9803
2010/03/05_09:11secline999.net/999.exe195.78.108.70-zeus/wsnpoem v2 trojanjeff anderson / skeletor71@comcast.net49544
2010/03/05_09:11inasss.info/_etc/pt.php122.115.63.9netnic.com.cn.zeus/wsnpoem v2 drop zoneAndrey Aleksandrovich Polev / o00o.code@gmail.com9803
2010/03/05_09:11www.whoismak.net/whois/index.php91.212.41.13-zeus/wsnpoem v2 drop zoneSteve Park stvpark1970@yahoo.com29371
2010/03/05_09:11shop.ccomp.cz/images/zs/brama.php80.95.108.218smtp.poslimail.cz.zeus/wsnpoem v2 drop zoneCRACK Computers, s.r.o. / info@crackcomputers.com21435
2010/03/05_09:07usworldcast.com/100/cfg3.bin188.124.5.106static.vitalhosting.com.tr.zeus/wsnpoem v2 config filerekon / vin345686866664444@gmail.com44565
2010/03/05_09:07promolistings.net/nulled/help.txt61.4.82.249-zeus/wsnpoem v2 config filejeff anderson / williamashley40@yahoo.com17964
2010/03/05_09:07promolistings.net/nulled/game.exe61.4.82.249-zeus/wsnpoem v2 trojanjeff anderson / williamashley40@yahoo.com17964
2010/03/05_09:07promolistings.net/nulled/gate.php61.4.82.249-zeus/wsnpoem v2 drop zonejeff anderson / williamashley40@yahoo.com17964
2010/03/05_01:39wrapp.info/setup_build13401.php?cmd=getFile&counter=1&data=MigHWF5yDVUgETFIU6Rtbzdd8x9KMFBwb01vAlh7UyVyUyOxpUHX3gPSaD4AMfk%3D193.169.235.5-fake avVitalij Tiaskevic / stormpayclicker@gmail.com32181