IP Location: United Kingdom - RoadRunner RR-RC-Enet-Columbus
IP 209.190.85.14
[node6.byetcluster.com]
AS10297
Name Server: NS1.BYET.ORG | NS2.BYET.ORG
Registrant/Email Registrant: Administrator Administrator/unsecretarygeneral@gmail.com
hxxp://gafilacu.webshost.info/profi.bin md5sum ===> 9253fadc3ac88a790ac3cb1b43c0a791
IP Location: United Kingdom - RoadRunner RR-RC-Enet-Columbus
IP 209.190.85.252
[www.quark.byethost4.com]
AS10297
Name Server: ns1.byet.org | ns2.byet.org
Registrant/Email Registrant: Chris Chadd/rebelcreek@live.com
hxxp://zoqovix.torridhosting.com/profi.bin/profi.bin md5sum ===> 9253fadc3ac88a790ac3cb1b43c0a791
IP Location: Spain - Euskatel S.A.
IP 85.84.40.195
[195.85-84-40.dynamic.clientes.euskaltel.es]
AS12338
Name Server: ns1.acorngroupinc.com | ns2.acorngroupinc.com
Registrant/Email Registrant: Private Person/built@ppmail.ru
hxxp://fabsnot.ru/search/old02ziu.bin md5sum ===> 910f15aa718842dadc678dceeb541aee
hxxp://rudeink.ru/search/frings.php
hxxp://rudeink.ru/search/baby2011.php
IP Location: United States - Ecommerce Inc
IP 98.130.177.73
[rev.opentransfer.com.73.177.130.98.in-addr.arpa]
AS32392
Name Server: NS13.IXWEBHOSTING.COM | NS14.IXWEBHOSTING.COM
Registrant/Email Registrant: E Z RED/luketucker@ezred.com
hxxp://ezred.com/new2.bin md5sum ===> 8accd1bd050ac84aac24c7a2a8b98670
IP Location: Russian Federation - Agava Ltd
[vm3464.vps.agava.net]
AS24971
hxxp://80.78.243.44/settings/rp003.php
hxxp://80.78.243.44/settings/config.php
IP Location: Singapore - SINGNET Singapore Telecommunications
IP 58.185.33.163
AS3758
Name Server: ns1.footwalmoth.ru | ns1.heilingalatrole.com
Registrant/Email Registrant: Egidia Palomo/fq@mail13.com
hxxp://flowersinamew.com/pof/deq.nk md5sum ===> bbc1f163ddabaecef8608f0bcee47945
http://flowersinamew.com/pof/pol.exe md5sum ===> e2434b930eb9c79358388501b8dd137b
http://www.virustotal.com/file-scan/report.html?id=23920e7595ef71df685321adc78b0e76d7fdfc96dce482f7a263bf7fedf39d74-1318009706VT
31/43 (72.1%)