IP Location: Ukraine - Pe Bondarenko Dmitriy Vladimirovich
IP 91.213.174.43
AS29106
ns2.reg.ru
ns1.reg.ru
Registrant/Email Registrant: PrivacyProtect.org/contact@privacyprotect.org
hxxp://erj439ujje.com/005.so
md5sum ===> 74336aa5f9cc53eb32d8cbb0db5ec722
hxxp://erj439ujje.com/i.php
IP Location: Romania - SA-NOVA-TELECOM-GRUP-SRL
IP 188.229.90.138
AS49469
ns3.cnmsn.com
ns4.cnmsn.com
Registrant/Email Registrant: Whois Privacy Protection Service/rnyfxwgrjk@whoisservices.cn
hxxp://securedalertcheck.com/trash/oldinfo/deleted/stdata.bin
md5sum ===> 218be4f34792e8e0a07785f8f0e4081b
hxxp://securedalertcheck.com/service/repair/backup/setup/login.php
IP Location: Ukraine - it-outsource-as LLC
IP 91.207.182.50
AS48280
NS01.DOMAINCONTROL.COM
NS02.DOMAINCONTROL.COM
Registrant ID: CR70183061
Registrant/Email Registrant: Julie Hennessey/juliehennessey81@yahoo.com
hxxp://sparkgirls.biz/z2/config.bin
md5sum ===> 66342adb1a865bb1476e7e15e8d481b1
hxxp://sparkgirls.biz/z2/bot.exe
md5sum ===> 94a9a1bb68411343205b0862d9f89193
http://www.virustotal.com/file-scan/report.html?id=c10c8eff899f7a6e98fcf3b47cbbbf27a5b75d4a4f933b3b0afa0d93ff93f7f0-1290448225VT
20/43 (46.5%)
hxxp://sparkgirls.biz/z2/gate.php
IP Location: Russian Federation - VLTELECOM-AS
IP 109.196.130.58
AS39150
ns1.niceday242steal.net 109.196.130.58
ns2.niceday242steal.net 109.196.130.58
Registrant ID: SXCKEOV-RU
Registrant/Email Registrant: Victor I Brikatnin/mire@maillife.ru
hxxp://niceday242steal.net/nnesx/cf2.bin
md5sum ===> 156a55d94f6203d971357f79100fe74a
IP Location: China - CRNET_BJ_IDC-CNNIC-AP
IP 222.35.139.225
AS24138
ns1.r3registry.com
ns2.r3registry.com
Registrant ID: DI_13517667
Registrant/Email Registrant: Yosha Harimo/info@yahooanalytics.in
hxxp://dvadoma.in/traher/tashmik.bin
md5sum ===> 21705df723735b4f2807de6c86ce4dc7
hxxp://odindoma.in/yptas/francherinki.php