IP Location: Ukraine - ITMUA-AS TOB
IP 194.1.220.35
AS50738
ns1.no-more-sleep.com
ns2.no-more-sleep.com
Registrant/Email Registrant: Sigurny Parker/admin@no-more-sleep.com
hxxp://no-more-sleep.com/z2/config.bin
md5sum ===> 0444d129b431101d953bd8a5a7d470fb
hxxp://no-more-sleep.com/z2/bot.exe
md5sum ===> 0a1addfe1423891b80afba1df567dd99
http://www.virustotal.com/file-scan/report.html?id=50bf72a171dd401a4415fec17c0c5017c1b0686a87899b6b5910656c82a4faf7-1292434204VT
4/43 (9.3%)
hxxp://no-more-sleep.com/z2/gate.php
IP Location: Ukraine - L-NET Route Object - LYAHOV-AS Lyahovich Maksim
IP 91.217.249.140
AS51554
free01.editdns.net
free02.editdns.net
Registrant/Email Registrant: Pavel Pugachev/ya_whois@yandex.ru
hxxp://shitorfuck.com/gorozo/y.b
md5sum ===> 0c154c4c5567b1561950fff3eb617236
hxxp://shitorfuck.com/gorozo/olololo.php
IP Location: Ukraine -ITMUA-AS TOB
IP 194.1.220.142
AS20564
NS1.DOMAINSERVICE.COM 208.73.210.41
NS2.DOMAINSERVICE.COM 208.73.211.42
NS3.DOMAINSERVICE.COM
NS4.DOMAINSERVICE.COM
Registrant/Email Registrant: Mark Carter/oxumafehidygady@yahoo.com
hxxp://ngmsoggkrrriljrv.com/news/?s=161356
md5sum ===> 041ba8cae1a8176f1fd88c5e6bcf1b6d
hxxp://ngmsoggkrrriljrv.com/news/?s=6225
md5sum ===> a43202b4492e4fa036e7dcdb3c35548e
http://www.virustotal.com/file-scan/report.html?id=7eb9a3c17c6fc4ce5c08c5bfa48b8621d9128a5a1152a11d8012bd414ff77949-1292429585VT
18/43 (41.9%)
IP Location: China - CHINA-TELECOM
IP 122.227.108.26
AS4134
ns1.holdglass.com
ns2.holdglass.com
Registrant/Email Registrant: Igor Nikenin/i-nikitin.2000@gmail.com
hxxp://flowershopco.com/panel3/ppnl3.exe
hxxp://wzcqwrmchtl4flrhdfngr4jnl.net/panel3/ppnl3.exe
md5sum ===> 57571888ad9d1dc4774863fdb10b58c8
http://www.virustotal.com/file-scan/report.html?id=f2d1c4895e41beb2d3411a43c8a6986ea2d0d9432dcdd5576f54a056b01ee58e-1292430380VT
24/43 (55.8%)
hxxp://flowershopco.com/panel3/gotobank.php
hxxp://wzcqwrmchtl4flrhdfngr4jnl.net/panel3/gotobank.php
IP Location: Ukraine - Antarktida-PLUS
IP 91.220.62.35
AS50738
ns2.reg.ru
ns1.reg.ru
Registrant/Email Registrant: PrivacyProtect.org/contact@privacyprotect.org
hxxp://illusiohstar.com/000x119.so
md5sum ===> 2a9496a4edee4cc8f6c23055fd18d3a5
hxxp://illusiohstar.com/i.php
IP Location: Ukraine - Antarktida-PLUS
IP 91.220.62.35
AS50738
ns2.reg.ru
ns1.reg.ru
Registrant/Email Registrant: PrivacyProtect.org/contact@privacyprotect.org
hxxp://interodialset.com/000x120.so
md5sum ===> 240e74250254543e4b7d38f0b9016021
hxxp://interodialset.com/i.php