IP Location: Russian Federation - VLine Telecom - VLTELECOM-AS
IP 109.196.130.58
AS39150
ns1.1223vsvsn21221.net
ns2.1223vsvsn21221.net
Registrant/Email Registrant: Malus Ozanakis/malusozanakis@yahoo.com
hxxp://1223vsvsn21221.net/urla/c2.bin
md5sum ===> ea3a690b8d0249a1fdbb452ddc5c2a7c
IP Location: Russian Federation - L-NET Route Object - LYAHOV-AS Lyahovich Maksim
IP 91.217.249.167
AS51554
ns1.derttttt.ru
ns2.derttttt.ru
Email Registrant: info@derttttt.ru
hxxp://basildomut.ru/files/file.exe
md5sum ===> 91e3f63be4c3d71fd920c7d45b537909
http://www.virustotal.com/file-scan/report.html?id=7ea21ea7efad475d22d7189a09331792ec88bda569b9615c8916b1a27daa52cb-1290208558VT
8/43 (18.6%)
IP Location: Russian Federation - K2K-NET - K2K-AS
IP 193.27.232.51
AS43181
ns1.nameself.com AS43146
ns2.nameself.com AS30968
Email Registrant: admin@nvffr.ru
hxxp://ulssew.ru/a.bin
md5sum ===> 002ade0a52c34c82bd0d9dd997de12f5
hxxp://ulssew.ru/b.php
IP Location: Singapore - AH-INC Go Daddy Software
IP 182.50.134.1
[sg2nlhg96c1096.shr.prod.sin2.secureserver.net]
AS26496
ns1.freedns.ws AS24940
ns2.freedns.ws AS50297
hxxp://chilliwinefactory.com/last/fversion
md5sum ===> 68650d695ecfd2055f32d28df70d4ce8
hxxp://chilliwinefactory.com/gamecenter/versioncheck.php