IP Location: Austria - ANEXIA Internetdienstleistungs GmbH - ANEXIA-AS
IP 188.65.74.70
AS42473
Registrant ID: TOD-42502831
Registrant/Registrant Email: Joudy Lay/admin@kjjm.biz
hxxp://kjjm.biz/backup.tgz
md5sum ===> 072ee350762c82aaf301e1973e2f91fc
SHA256 ===> 95bf83103fdb6c5ef0dae19f40dfd6905e39e5f1b311dbd215e3fb73192e07b9
IP Location: Taiwan - KGEX.com - KGTNET-TW KG Telecommunication Co
IP 61.61.20.136
AS9918
Registrant ID: TOD-42502831
Registrant/Registrant Email: Hilary Kneber/hilarykneber@yahoo.com
hxxp://lyuboidomen.net/src/footer.jpg
md5sum ===> 0e7ecc2599199d07700985cc463108cc
SHA256 ===> 8e58c71f1c06cbbd1d4e530a1ac38eefc3bb9ae87c1cfdfc3f14a8865d32831f
hxxp://yuboidomen.net/src/img.php
config file:IP Location: United States - PNAP-CHG layeredtech routes - FASTSERVERS , Inc
IP 74.200.236.203
[ws20.pronameserver.com]
AS16805
Registrant/Registrant Email: James Shayler/jamesshayler@btopenworld.com
hxxp:///phuket-apartmentrentals.com/baner.gif
md5sum ===> 9962d2be7b62475107534fd795d73c97
SHA256 ===> 3f16e7c6af7c71de93d52787e74bcf3e8064400ffdc13a36d6d1b42ef117bc0b
ZeuS trojan:IP Location: United States - ThePlanet.com Internet Services, Inc. - THEPLANET-AS2
IP 67.15.56.68
[win2.interactivedns.com]
AS21844
Registrant/Registrant Email: T-soft/prashpadia@gmail.com
hxxp://t-softindia.com/sisadmin_doktor_2.jpg
md5sum ===> f37409323f5fd5ec4851ba6e532e02a4
SHA256 ===> 346d6a6ebe57c28a64eb9fe1cb512332a5c25106904248945664f007f52642b2
http://www.virustotal.com/es/analisis/346d6a6ebe57c28a64eb9fe1cb512332a5c25106904248945664f007f52642b2-1278760851VT
19/41 (46.35%)
dropzone (already listed):hxxp://www.listwowgame.com/webstate/webstat.php
IP Location: Germany - HANSENET - HANSENET Telekommunikation GmbH
IP 92.227.85.52
[g227085052.adsl.alicedsl.de]
AS13184
Registrant/Registrant Email: Linda J. Watts/LindaJWatts@bigmail.net
hxxp://hosting-king.net/config.bin
md5sum ===> 10886337e9c6af2c15311f1538316f67
SHA256 ===> a314e5b0dc318a44572dcb40b15c05da1f619b53459df7bdbc2a6e575dddb361
hxxp://hosting-king.net/bot.exe
md5sum ===> ce81df0e7050bd417f2ff20ff98b1b60
SHA256 ===> 25a8ec602c85f1764543e2748a1dfaa86a7dfe387621d105f0f6892dc7809083
http://www.virustotal.com/es/analisis/25a8ec602c85f1764543e2748a1dfaa86a7dfe387621d105f0f6892dc7809083-1278757270VT
12/41 (29.27%)
IP Location: Germany - SCHLUND-PA-4 - ONEANDONE-AS
IP 82.165.223.177
[kundenserver.de]
AS8560
Registrant/Registrant Email: Frederic Fransen/fransen.f@gmail.com
hxxp://fredericfransen.com/zoom1.gif
md5sum ===> e6b33e0eb9791e6ebe49d40c62f80791
SHA256 ===> fbaa169a4e457cc8f10d29c77775ab6259da7d7848a73d3f191593a3d889fe6f
http://www.virustotal.com/es/analisis/fbaa169a4e457cc8f10d29c77775ab6259da7d7848a73d3f191593a3d889fe6f-1278760005VT
19/40 (47.5%)
config file (already listed):hxxp://ketengahholding.com.my/boom.jpg