Hi everyone, I am kind of new here but I regularly encounter malware links. I would liek to regularly share them with people who will do the right things with them. Please let me know if there is a better place to put these.
This file was downloaded to update someone infected with zlob:
62.176.16.161/bingo/loadexe2/KvmSecure(dot)exe
Also I did a reverse dns lookup on that IP and found some other nasty places, if anyone has time to dig deeper I am sure you will find more malware:
sextubecodec93.com A 62.176.16.161
ns1.sextubecodec93.com A 62.176.16.161
ns2.sextubecodec93.com A 62.176.16.161
kvm-secure.com A 62.176.16.161
ns1.kvm-secure.com A 62.176.16.161
ns2.kvm-secure.com A 62.176.16.161
kvmsecure.com A 62.176.16.161
ns1.kvmsecure.com A 62.176.16.161
ns2.kvmsecure.com A 62.176.16.161
sexycodecadult.com A 62.176.16.161
ns1.sexycodecadult.com A 62.176.16.161
ns2.sexycodecadult.com A 62.176.16.161
161.16.176.62.in-addr.arpa PTR nechnoshit.podolsk-mo.ru
Thanks!