<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:annotate="http://purl.org/rss/1.0/modules/annotate/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
<!--
	This feed generated for Anonymous	More info at http://naklon.info/rss/about.htm
	Customized and Ported for CastleCops
-->
<channel>
<title>CastleCops MIRT Reports</title>
<link>http://www.castlecops.com/</link>
<description>Reports generated from the MIRT Tool</description>
<managingEditor>paul@castlecops.com</managingEditor>
<docs>http://blogs.law.harvard.edu/tech/rss</docs>
<generator>RSS Feed 2.2.1</generator>
<language>en</language><lastBuildDate>Sun, 06 Jul 2008 09:13:29 GMT</lastBuildDate>
<image>
	<url>http://isc2.castlecops.com/cclogo3.gif</url>
	<title>MIRT Reports</title>
	<link>http://www.castlecops.com/</link>
	<width>115</width>
	<height>58</height>
</image>
<item>
<title>MIRT Reports :: [MIRT#4648] Trojan on wmvmedialease.com AS25525</title>
<link>http://www.castlecops.com/postp1102306.html#1102306</link>
<pubDate>Mon, 30 Jun 2008 16:01:40 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1102306.html#1102306</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#4648] Trojan on wmvmedialease.com AS25525&lt;br /&gt;Posted: Mon Jun 30, 2008 9:01 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_malware4648.html&quot;&gt;http://www.castlecops.com/Trojan_malware4648.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 85.92.138.151
&lt;br /&gt;

&lt;br /&gt;
dword = 1432128151
&lt;br /&gt;
hex1 = 0x555c8a97
&lt;br /&gt;
hex2 = 0x55.0x5c.0x8a.0x97
&lt;br /&gt;
oct = 0125.0134.0212.0227
&lt;br /&gt;
codec.exe at this location is malware known as Trojan:Win32/Vundo.gen!D (Microsoft).View CIDR AS25525 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=25525&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=25525&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;25525 | NL | ripencc | 2002-12-23 | REASONNET Reasonnet IP Networks - Autonomous System Number&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS25525:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: nl
&lt;br /&gt;
Responsible Domain: reasonnet.com
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@reasonnet.com&quot;&gt;abuse@reasonnet.com&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://wmvmedialease.com/codec.php?aid=cj_11_2&amp;amp;v=v7&amp;amp;e=1&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1102306#1102306" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1102306</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#4647] Trojan on 205.177.122.104 AS3491</title>
<link>http://www.castlecops.com/postp1102305.html#1102305</link>
<pubDate>Mon, 30 Jun 2008 15:58:50 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1102305.html#1102305</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#4647] Trojan on 205.177.122.104 AS3491&lt;br /&gt;Posted: Mon Jun 30, 2008 8:58 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_malware4647.html&quot;&gt;http://www.castlecops.com/Trojan_malware4647.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 205.177.122.104
&lt;br /&gt;

&lt;br /&gt;
dword = 3450960488
&lt;br /&gt;
hex1 = 0xcdb17a68
&lt;br /&gt;
hex2 = 0xcd.0xb1.0x7a.0x68
&lt;br /&gt;
oct = 0315.0261.0172.0150
&lt;br /&gt;
vZZnu2VLvD.exe at this location is malware known as Trojan:Win32/Busky.D (Microsoft).View CIDR AS3491 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=3491&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=3491&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;3491 | US | arin | 1994-03-21 | BTN-ASN - Beyond The Network America, Inc.&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS3491:
&lt;br /&gt;
State/Province: va
&lt;br /&gt;
Country: us
&lt;br /&gt;
Responsible Domain: btnaccess.com
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:jray@btnaccess.com&quot;&gt;jray@btnaccess.com&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://205.177.122.104/PE/vZZnu2VLvD.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1102305#1102305" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1102305</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#4635] Trojan-Downloader on 209.120.242.82 AS6517</title>
<link>http://www.castlecops.com/postp1102303.html#1102303</link>
<pubDate>Mon, 30 Jun 2008 15:38:21 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1102303.html#1102303</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#4635] Trojan-Downloader on 209.120.242.82 AS6517&lt;br /&gt;Posted: Mon Jun 30, 2008 8:38 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Downloader_malware4635.html&quot;&gt;http://www.castlecops.com/Trojan_Downloader_malware4635.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 209.120.242.82
&lt;br /&gt;

&lt;br /&gt;
dword = 3514364498
&lt;br /&gt;
hex1 = 0xd178f252
&lt;br /&gt;
hex2 = 0xd1.0x78.0xf2.0x52
&lt;br /&gt;
oct = 0321.0170.0362.0122
&lt;br /&gt;
claro.exe at this location is malware known as TrojanDownloader:Win32/Banload (Microsoft).View CIDR AS6517 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=6517&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=6517&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;6517 | US | arin | 2000-04-13 | RELIANCEGLOBALCOM - Reliance Globalcom Services, Inc&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS6517:
&lt;br /&gt;
State/Province: ca
&lt;br /&gt;
Country: us
&lt;br /&gt;
Responsible Domain: yipes.com
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@yipes.com&quot;&gt;abuse@yipes.com&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://209.120.242.82/index2.php?cod=claro&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1102303#1102303" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1102303</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#4549] Trojan-Downloader on liveupdatesnet.com AS36445</title>
<link>http://www.castlecops.com/postp1102297.html#1102297</link>
<pubDate>Mon, 30 Jun 2008 15:12:48 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1102297.html#1102297</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#4549] Trojan-Downloader on liveupdatesnet.com AS36445&lt;br /&gt;Posted: Mon Jun 30, 2008 8:12 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Downloader_malware4549.html&quot;&gt;http://www.castlecops.com/Trojan_Downloader_malware4549.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 85.255.121.117
&lt;br /&gt;

&lt;br /&gt;
dword = 1442806133
&lt;br /&gt;
hex1 = 0x55ff7975
&lt;br /&gt;
hex2 = 0x55.0xff.0x79.0x75
&lt;br /&gt;
oct = 0125.0377.0171.0165
&lt;br /&gt;
loader.exe at this location is malware known as TrojanDownloader:Win32/VB (Microsoft).View CIDR AS36445 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=36445&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=36445&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;36445 | US | arin | 2006-01-05 | CERNEL-ASN - Cernel, Inc&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS36445:
&lt;br /&gt;
State/Province: ca
&lt;br /&gt;
Country: us
&lt;br /&gt;
Responsible Domain: cernel.net
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@cernel.net&quot;&gt;abuse@cernel.net&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://liveupdatesnet.com/501/loader.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1102297#1102297" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1102297</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#4516] Exploit on search-biz.org AS27595</title>
<link>http://www.castlecops.com/postp1102294.html#1102294</link>
<pubDate>Mon, 30 Jun 2008 14:56:29 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1102294.html#1102294</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#4516] Exploit on search-biz.org AS27595&lt;br /&gt;Posted: Mon Jun 30, 2008 7:56 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Exploit_malware4516.html&quot;&gt;http://www.castlecops.com/Exploit_malware4516.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 85.255.117.213
&lt;br /&gt;

&lt;br /&gt;
dword = 1442805205
&lt;br /&gt;
hex1 = 0x55ff75d5
&lt;br /&gt;
hex2 = 0x55.0xff.0x75.0xd5
&lt;br /&gt;
oct = 0125.0377.0165.0325
&lt;br /&gt;
2.ani at this location is malware known as Exploit:Win32/Anicmoo.A (Microsoft).View CIDR AS27595 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=27595&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=27595&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;27595 | US | arin | 2003-04-07 | INTERCAGE - InterCage, Inc.&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS27595:
&lt;br /&gt;
State/Province: ca
&lt;br /&gt;
Country: us
&lt;br /&gt;
Responsible Domain: atrivo.com
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@atrivo.com&quot;&gt;abuse@atrivo.com&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://search-biz.org/2.ani&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1102294#1102294" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1102294</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#4515] Exploit on search-buy.info AS27595</title>
<link>http://www.castlecops.com/postp1102291.html#1102291</link>
<pubDate>Mon, 30 Jun 2008 14:48:29 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1102291.html#1102291</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#4515] Exploit on search-buy.info AS27595&lt;br /&gt;Posted: Mon Jun 30, 2008 7:48 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Exploit_malware4515.html&quot;&gt;http://www.castlecops.com/Exploit_malware4515.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 85.255.117.213
&lt;br /&gt;

&lt;br /&gt;
dword = 1442805205
&lt;br /&gt;
hex1 = 0x55ff75d5
&lt;br /&gt;
hex2 = 0x55.0xff.0x75.0xd5
&lt;br /&gt;
oct = 0125.0377.0165.0325
&lt;br /&gt;
cyber.wmf at this location is malware known as Exploit:Win32/Wmfap (Microsoft).View CIDR AS27595 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=27595&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=27595&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;27595 | US | arin | 2003-04-07 | INTERCAGE - InterCage, Inc.&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS27595:
&lt;br /&gt;
State/Province: ca
&lt;br /&gt;
Country: us
&lt;br /&gt;
Responsible Domain: atrivo.com
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@atrivo.com&quot;&gt;abuse@atrivo.com&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://search-buy.info/cyber.wmf&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1102291#1102291" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1102291</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#2810] Program on errorsafe.com AS16265</title>
<link>http://www.castlecops.com/postp1101897.html#1101897</link>
<pubDate>Sun, 29 Jun 2008 09:11:54 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101897.html#1101897</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#2810] Program on errorsafe.com AS16265&lt;br /&gt;Posted: Sun Jun 29, 2008 2:11 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Program_malware2810.html&quot;&gt;http://www.castlecops.com/Program_malware2810.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 85.17.4.103
&lt;br /&gt;

&lt;br /&gt;
dword = 1427178599
&lt;br /&gt;
hex1 = 0x55110467
&lt;br /&gt;
hex2 = 0x55.0x11.0x4.0x67
&lt;br /&gt;
oct = 0125.021.04.0147
&lt;br /&gt;
ErrorSafeNewReleaseInstall.exe at this location is malware known as Program:Win32/Winfixer (Microsoft).View CIDR AS16265 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=16265&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=16265&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;16265 | NL | ripencc | 2001-12-20 | LEASEWEB LEASEWEB AS&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS16265:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: nl
&lt;br /&gt;
Responsible Domain: leaseweb.com
&lt;br /&gt;
Abuse Email: 
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://errorsafe.com/download/2007/index.php?lid=infy&amp;amp;ax=1&amp;amp;ex=1&amp;amp;p=2&amp;amp;aid=indianit_rdt_us_en_ed2&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101897#1101897" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101897</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#2621] Program on pcturbopro.com AS16265</title>
<link>http://www.castlecops.com/postp1101893.html#1101893</link>
<pubDate>Sun, 29 Jun 2008 08:54:37 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101893.html#1101893</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#2621] Program on pcturbopro.com AS16265&lt;br /&gt;Posted: Sun Jun 29, 2008 1:54 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Program_malware2621.html&quot;&gt;http://www.castlecops.com/Program_malware2621.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 85.17.4.103
&lt;br /&gt;

&lt;br /&gt;
dword = 1427178599
&lt;br /&gt;
hex1 = 0x55110467
&lt;br /&gt;
hex2 = 0x55.0x11.0x4.0x67
&lt;br /&gt;
oct = 0125.021.04.0147
&lt;br /&gt;
PCTurboProInstallerFree.exe at this location is malware known as Program:Win32/Winfixer (Microsoft).View CIDR AS16265 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=16265&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=16265&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;16265 | NL | ripencc | 2001-12-20 | LEASEWEB LEASEWEB AS&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS16265:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: nl
&lt;br /&gt;
Responsible Domain: leaseweb.com
&lt;br /&gt;
Abuse Email: 
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://pcturbopro.com/.download_now/index.php?lid=728mpl&amp;amp;ax=1&amp;amp;ex=1&amp;amp;p=13&amp;amp;hv=10&amp;amp;j=1&amp;amp;aid=drivehas_rdt_us_en_ed2&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101893#1101893" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101893</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#2581] Trojan-Downloader on files.seriall.com AS8492</title>
<link>http://www.castlecops.com/postp1101887.html#1101887</link>
<pubDate>Sun, 29 Jun 2008 08:38:48 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101887.html#1101887</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#2581] Trojan-Downloader on files.seriall.com AS8492&lt;br /&gt;Posted: Sun Jun 29, 2008 1:38 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Downloader_malware2581.html&quot;&gt;http://www.castlecops.com/Trojan_Downloader_malware2581.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 85.114.8.70
&lt;br /&gt;

&lt;br /&gt;
dword = 1433536582
&lt;br /&gt;
hex1 = 0x55720846
&lt;br /&gt;
hex2 = 0x55.0x72.0x8.0x46
&lt;br /&gt;
oct = 0125.0162.010.0106
&lt;br /&gt;
nero_key.exe at this location is malware known as TrojanDownloader:Win32/Matcash.F (Microsoft).View CIDR AS8492 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=8492&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=8492&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;8492 | RU | ripencc | 2005-02-17 | OBIT-AS Obit Telecommunications, St.Petersburg, Russia&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS8492:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: fr
&lt;br /&gt;
Responsible Domain: siris.fr
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:postmaster@siris.fr&quot;&gt;postmaster@siris.fr&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://files.seriall.com/seriall/nero_key.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101887#1101887" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101887</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#2548] Trojan-Downloader on ddm.tisnov.cz AS24971</title>
<link>http://www.castlecops.com/postp1101884.html#1101884</link>
<pubDate>Sun, 29 Jun 2008 08:30:23 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101884.html#1101884</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#2548] Trojan-Downloader on ddm.tisnov.cz AS24971&lt;br /&gt;Posted: Sun Jun 29, 2008 1:30 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Downloader_malware2548.html&quot;&gt;http://www.castlecops.com/Trojan_Downloader_malware2548.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Consumed following related reports:
&lt;br /&gt;

&lt;br /&gt;
[2555] &lt;a href=&quot;http://ddm.tisnov.cz/obrazky/terra/musicadedicada.scr&quot;&gt;http://ddm.tisnov.cz/obrazky/terra/musicadedicada.scr&lt;/a&gt; 
&lt;br /&gt;
Changed status to confirmed malware.IP Converted: 89.185.240.15
&lt;br /&gt;

&lt;br /&gt;
dword = 1505357839
&lt;br /&gt;
hex1 = 0x59b9f00f
&lt;br /&gt;
hex2 = 0x59.0xb9.0xf0.0xf
&lt;br /&gt;
oct = 0131.0271.0360.017
&lt;br /&gt;
cartao632471.scr at this location is malware known as TrojanDownloader:Win32/Small (Microsoft).musicadedicada.scr at this location is malware known as TrojanDownloader:Win32/Small (Microsoft).View CIDR AS24971 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=24971&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=24971&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;24971 | CZ | ripencc | 2002-06-11 | MASTER-AS Master Internet s.r.o / Czech Republic / &lt;a href=&quot;http://www.master.cz&amp;quot;&amp;lt;br&quot;&gt;www.master.cz&amp;quot;&amp;lt;br&lt;/a&gt; /&amp;gt;
&lt;br /&gt;
Extended information for AS24971:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: cz
&lt;br /&gt;
Responsible Domain: master.cz
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:postmaster@master.cz&quot;&gt;postmaster@master.cz&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://ddm.tisnov.cz/obrazky/uol/cartao632471.scr&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101884#1101884" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101884</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#2526] Trojan-Downloader on globobb7.smtp.ru AS6731</title>
<link>http://www.castlecops.com/postp1101883.html#1101883</link>
<pubDate>Sun, 29 Jun 2008 08:09:26 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101883.html#1101883</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#2526] Trojan-Downloader on globobb7.smtp.ru AS6731&lt;br /&gt;Posted: Sun Jun 29, 2008 1:09 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Downloader_malware2526.html&quot;&gt;http://www.castlecops.com/Trojan_Downloader_malware2526.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 82.204.219.231
&lt;br /&gt;

&lt;br /&gt;
dword = 1389157351
&lt;br /&gt;
hex1 = 0x52ccdbe7
&lt;br /&gt;
hex2 = 0x52.0xcc.0xdb.0xe7
&lt;br /&gt;
oct = 0122.0314.0333.0347
&lt;br /&gt;
carolbb7.exe at this location is malware known as TrojanDownloader:Win32/Banload.DE (Microsoft).View CIDR AS6731 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=6731&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=6731&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;6731 | RU | ripencc | 1996-07-30 | COMSTAR-AS COMSTAR Telecommunications&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS6731:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: ru
&lt;br /&gt;
Responsible Domain: comstar.ru
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@comstar.ru&quot;&gt;abuse@comstar.ru&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://globobb7.smtp.ru/carolbb7.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101883#1101883" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101883</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#2312] Trojan-Spy on oya.ru AS30943</title>
<link>http://www.castlecops.com/postp1101809.html#1101809</link>
<pubDate>Sat, 28 Jun 2008 20:35:59 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101809.html#1101809</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#2312] Trojan-Spy on oya.ru AS30943&lt;br /&gt;Posted: Sun Jun 29, 2008 1:35 am (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Spy_malware2312.html&quot;&gt;http://www.castlecops.com/Trojan_Spy_malware2312.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 217.112.42.39
&lt;br /&gt;

&lt;br /&gt;
dword = 3648006695
&lt;br /&gt;
hex1 = 0xd9702a27
&lt;br /&gt;
hex2 = 0xd9.0x70.0x2a.0x27
&lt;br /&gt;
oct = 0331.0160.052.047
&lt;br /&gt;
update.exe at this location is malware known as TrojanSpy:Win32/Goldun (Microsoft).View CIDR AS30943 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=30943&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=30943&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;30943 | GB | ripencc | 2004-01-23 | UTRANSIT-AS Utransit International Carrier Limited&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS30943:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: 
&lt;br /&gt;
Responsible Domain: utransit.net
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@utransit.net&quot;&gt;abuse@utransit.net&lt;/a&gt;
&lt;br /&gt;
Generated and sent email malware alert to respective parties.&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://oya.ru/vyhod/numizmat/ima/get.php?file=exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101809#1101809" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101809</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#1943] Exploit on planetanim.com AS21409</title>
<link>http://www.castlecops.com/postp1101789.html#1101789</link>
<pubDate>Sat, 28 Jun 2008 19:33:52 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101789.html#1101789</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#1943] Exploit on planetanim.com AS21409&lt;br /&gt;Posted: Sun Jun 29, 2008 12:33 am (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Exploit_malware1943.html&quot;&gt;http://www.castlecops.com/Exploit_malware1943.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 213.246.37.148
&lt;br /&gt;

&lt;br /&gt;
dword = 3589678484
&lt;br /&gt;
hex1 = 0xd5f62594
&lt;br /&gt;
hex2 = 0xd5.0xf6.0x25.0x94
&lt;br /&gt;
oct = 0325.0366.045.0224
&lt;br /&gt;
stats-global-daily-hosts.htm at this location is malware known as Exploit:JS/MS06014 (Microsoft).View CIDR AS21409 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=21409&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=21409&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;21409 | FR | ripencc | 2001-11-30 | IKOULA IKOULA European Backbone AS&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS21409:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: 
&lt;br /&gt;
Responsible Domain: ikoula.com
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:ikoula@ikoula.com&quot;&gt;ikoula@ikoula.com&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://www.planetanim.com/Openads-2.0.11/admin/stats-global-daily-hosts.htm&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101789#1101789" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101789</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#12316] Trojan-Downloader on freewebtown.com AS36820</title>
<link>http://www.castlecops.com/postp1101783.html#1101783</link>
<pubDate>Sat, 28 Jun 2008 19:08:37 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101783.html#1101783</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#12316] Trojan-Downloader on freewebtown.com AS36820&lt;br /&gt;Posted: Sun Jun 29, 2008 12:08 am (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Downloader_malware12316.html&quot;&gt;http://www.castlecops.com/Trojan_Downloader_malware12316.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 208.75.230.43
&lt;br /&gt;

&lt;br /&gt;
dword = 3494635051
&lt;br /&gt;
hex1 = 0xd04be62b
&lt;br /&gt;
hex2 = 0xd0.0x4b.0xe6.0x2b
&lt;br /&gt;
oct = 0320.0113.0346.053
&lt;br /&gt;
alteracao.com at this location is malware known as Trojan-Downloader.Win32.Banload.pqm (Kaspersky).View CIDR AS36820 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=36820&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=36820&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;36820 | US | arin | 2006-05-05 | TULIP-SYSTEMS-INC-HOSTING-55-MARIETTA-ATLANTA - TULIP SYSTEMS, INC.&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS36820:
&lt;br /&gt;
State/Province: ga
&lt;br /&gt;
Country: us
&lt;br /&gt;
Responsible Domain: tulix.com
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:kacer@tulix.com&quot;&gt;kacer@tulix.com&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://www.freewebtown.com/alteradasenha/hotmail/alteracao.com&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101783#1101783" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101783</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#1411] Program on winsoftware.com AS22822</title>
<link>http://www.castlecops.com/postp1101777.html#1101777</link>
<pubDate>Sat, 28 Jun 2008 18:19:35 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101777.html#1101777</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#1411] Program on winsoftware.com AS22822&lt;br /&gt;Posted: Sat Jun 28, 2008 11:19 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Program_malware1411.html&quot;&gt;http://www.castlecops.com/Program_malware1411.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 208.111.153.244
&lt;br /&gt;

&lt;br /&gt;
dword = 3496974836
&lt;br /&gt;
hex1 = 0xd06f99f4
&lt;br /&gt;
hex2 = 0xd0.0x6f.0x99.0xf4
&lt;br /&gt;
oct = 0320.0157.0231.0364
&lt;br /&gt;
WinAntiVirusPro2007Install.exe at this location is malware known as Program:Win32/Winfixer (Microsoft).View CIDR AS22822 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=22822&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=22822&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;22822 | US | arin | 2001-11-28 | LLNW - Limelight Networks, Inc.&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS22822:
&lt;br /&gt;
State/Province: az
&lt;br /&gt;
Country: us
&lt;br /&gt;
Responsible Domain: limelightnetworks.com
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@limelightnetworks.com&quot;&gt;abuse@limelightnetworks.com&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://download.cdn.winsoftware.com/files/installers/WinAntiVirusPro2007Install.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101777#1101777" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101777</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#14098] Trojan-Dropper on franjerplast.it AS44029</title>
<link>http://www.castlecops.com/postp1101763.html#1101763</link>
<pubDate>Sat, 28 Jun 2008 16:52:40 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101763.html#1101763</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#14098] Trojan-Dropper on franjerplast.it AS44029&lt;br /&gt;Posted: Sat Jun 28, 2008 9:52 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Dropper_malware14098.html&quot;&gt;http://www.castlecops.com/Trojan_Dropper_malware14098.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Consumed following related reports:
&lt;br /&gt;

&lt;br /&gt;
[14168] &lt;a href=&quot;http://www.franjerplast.it/r.html&quot;&gt;http://www.franjerplast.it/r.html&lt;/a&gt; 
&lt;br /&gt;
Changed status to confirmed malware.IP Converted: 80.88.81.40
&lt;br /&gt;

&lt;br /&gt;
dword = 1347965224
&lt;br /&gt;
hex1 = 0x50585128
&lt;br /&gt;
hex2 = 0x50.0x58.0x51.0x28
&lt;br /&gt;
oct = 0120.0130.0121.050
&lt;br /&gt;
video1.exe at this location is malware known as TrojanDropper:Win32/Nuwar.gen!ldt (Microsoft).View CIDR AS44029 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=44029&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=44029&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;44029 | IT | ripencc | 2007-11-07 | WIDESTORE-ASN Widestore S.R.L.&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS44029:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: 
&lt;br /&gt;
Responsible Domain: 
&lt;br /&gt;
Abuse Email: 
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://www.franjerplast.it/video1.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101763#1101763" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101763</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#14094] Trojan-Dropper on dimagine.co.za AS21844</title>
<link>http://www.castlecops.com/postp1101761.html#1101761</link>
<pubDate>Sat, 28 Jun 2008 16:48:44 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101761.html#1101761</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#14094] Trojan-Dropper on dimagine.co.za AS21844&lt;br /&gt;Posted: Sat Jun 28, 2008 9:48 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Dropper_malware14094.html&quot;&gt;http://www.castlecops.com/Trojan_Dropper_malware14094.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 67.18.107.21
&lt;br /&gt;

&lt;br /&gt;
dword = 1125280533
&lt;br /&gt;
hex1 = 0x43126b15
&lt;br /&gt;
hex2 = 0x43.0x12.0x6b.0x15
&lt;br /&gt;
oct = 0103.022.0153.025
&lt;br /&gt;
install_en.exe at this location is malware known as TrojanDropper:Win32/Nuwar.gen!ldt (Microsoft).View CIDR AS21844 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=21844&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=21844&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;21844 | US | arin | 2001-06-29 | THEPLANET-AS - ThePlanet.com Internet Services, Inc.&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS21844:
&lt;br /&gt;
State/Province: tx
&lt;br /&gt;
Country: us
&lt;br /&gt;
Responsible Domain: theplanet.com
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@theplanet.com&quot;&gt;abuse@theplanet.com&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://dimagine.co.za/2009/1/install_en.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101761#1101761" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101761</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#13741] Trojan-Dropper on rine-exe.de AS39023</title>
<link>http://www.castlecops.com/postp1101759.html#1101759</link>
<pubDate>Sat, 28 Jun 2008 16:46:10 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101759.html#1101759</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#13741] Trojan-Dropper on rine-exe.de AS39023&lt;br /&gt;Posted: Sat Jun 28, 2008 9:46 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Dropper_malware13741.html&quot;&gt;http://www.castlecops.com/Trojan_Dropper_malware13741.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Consumed following related reports:
&lt;br /&gt;

&lt;br /&gt;
[13744] &lt;a href=&quot;http://www.rine-exe.de/video.exe&quot;&gt;http://www.rine-exe.de/video.exe&lt;/a&gt; 
&lt;br /&gt;
[13784] &lt;a href=&quot;http://www.rine-exe.de/r.html&quot;&gt;http://www.rine-exe.de/r.html&lt;/a&gt; 
&lt;br /&gt;
Changed status to confirmed malware.IP Converted: 195.225.106.94
&lt;br /&gt;

&lt;br /&gt;
dword = 3286329950
&lt;br /&gt;
hex1 = 0xc3e16a5e
&lt;br /&gt;
hex2 = 0xc3.0xe1.0x6a.0x5e
&lt;br /&gt;
oct = 0303.0341.0152.0136
&lt;br /&gt;
video1.exe at this location is malware known as TrojanDropper:Win32/Nuwar.gen!ldt (Microsoft).View CIDR AS39023 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=39023&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=39023&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;39023 | DE | ripencc | 2005-11-30 | IU-AS InternetUniversum GmbH&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS39023:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: de
&lt;br /&gt;
Responsible Domain: internetuniversum.de
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:hostmaster@internetuniversum.de&quot;&gt;hostmaster@internetuniversum.de&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://www.rine-exe.de/video1.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101759#1101759" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101759</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#13969] Trojan-Downloader on ivipvideos.pisem.su AS6731</title>
<link>http://www.castlecops.com/postp1101756.html#1101756</link>
<pubDate>Sat, 28 Jun 2008 16:29:33 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101756.html#1101756</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#13969] Trojan-Downloader on ivipvideos.pisem.su AS6731&lt;br /&gt;Posted: Sat Jun 28, 2008 9:29 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Downloader_malware13969.html&quot;&gt;http://www.castlecops.com/Trojan_Downloader_malware13969.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 82.204.219.235
&lt;br /&gt;

&lt;br /&gt;
dword = 1389157355
&lt;br /&gt;
hex1 = 0x52ccdbeb
&lt;br /&gt;
hex2 = 0x52.0xcc.0xdb.0xeb
&lt;br /&gt;
oct = 0122.0314.0333.0353
&lt;br /&gt;
videos_237.com at this location is malware known as Trojan-Downloader.Win32.Delf.jkz (Kaspersky).View CIDR AS6731 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=6731&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=6731&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;6731 | RU | ripencc | 1996-07-30 | COMSTAR-AS COMSTAR Telecommunications&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS6731:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: ru
&lt;br /&gt;
Responsible Domain: comstar.ru
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@comstar.ru&quot;&gt;abuse@comstar.ru&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://ivipvideos.pisem.su/videos_237.com&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101756#1101756" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101756</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#13815] Trojan on mailer1.key-one.it AS3242</title>
<link>http://www.castlecops.com/postp1101754.html#1101754</link>
<pubDate>Sat, 28 Jun 2008 16:25:10 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101754.html#1101754</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#13815] Trojan on mailer1.key-one.it AS3242&lt;br /&gt;Posted: Sat Jun 28, 2008 9:25 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_malware13815.html&quot;&gt;http://www.castlecops.com/Trojan_malware13815.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Consumed following related reports:
&lt;br /&gt;

&lt;br /&gt;
[14077] &lt;a href=&quot;http://mailer1.key-one.it/gif/postcard.gif.exe&quot;&gt;http://mailer1.key-one.it/gif/postcard.gif.exe&lt;/a&gt; 
&lt;br /&gt;
Changed status to confirmed malware.IP Converted: 151.1.216.26
&lt;br /&gt;

&lt;br /&gt;
dword = 2533480474
&lt;br /&gt;
hex1 = 0x9701d81a
&lt;br /&gt;
hex2 = 0x97.0x1.0xd8.0x1a
&lt;br /&gt;
oct = 0227.01.0330.032
&lt;br /&gt;
postcard.gif.exe at this location is malware known as Trojan:IRC/Flood.BF (Microsoft).View CIDR AS3242 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=3242&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=3242&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;3242 | EU | ripencc | 1994-07-28 | ASN-ITNET&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS3242:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: 
&lt;br /&gt;
Responsible Domain: it.net
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:security@it.net&quot;&gt;security@it.net&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://mailer1.key-one.it/postcard.gif.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101754#1101754" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101754</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#13807] Trojan-Dropper on max-graf.com.pl AS12741</title>
<link>http://www.castlecops.com/postp1101752.html#1101752</link>
<pubDate>Sat, 28 Jun 2008 16:22:13 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101752.html#1101752</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#13807] Trojan-Dropper on max-graf.com.pl AS12741&lt;br /&gt;Posted: Sat Jun 28, 2008 9:22 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Dropper_malware13807.html&quot;&gt;http://www.castlecops.com/Trojan_Dropper_malware13807.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Consumed following related reports:
&lt;br /&gt;

&lt;br /&gt;
[13849] &lt;a href=&quot;http://max-graf.com.pl/video1.exe&quot;&gt;http://max-graf.com.pl/video1.exe&lt;/a&gt; 
&lt;br /&gt;
[13982] &lt;a href=&quot;http://max-graf.com.pl/r.html&quot;&gt;http://max-graf.com.pl/r.html&lt;/a&gt; 
&lt;br /&gt;
Changed status to confirmed malware.IP Converted: 81.219.17.6
&lt;br /&gt;

&lt;br /&gt;
dword = 1373311238
&lt;br /&gt;
hex1 = 0x51db1106
&lt;br /&gt;
hex2 = 0x51.0xdb.0x11.0x6
&lt;br /&gt;
oct = 0121.0333.021.06
&lt;br /&gt;
video.exe at this location is malware known as TrojanDropper:Win32/Nuwar.gen!ldt (Microsoft).View CIDR AS12741 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=12741&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=12741&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;12741 | PL | ripencc | 1999-10-21 | INTERNETIA-AS Netia SA&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS12741:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: pl
&lt;br /&gt;
Responsible Domain: inetia.pl
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@inetia.pl&quot;&gt;abuse@inetia.pl&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://max-graf.com.pl/video.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101752#1101752" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101752</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#13796] Trojan-Dropper on dj-samy.fr AS35830</title>
<link>http://www.castlecops.com/postp1101751.html#1101751</link>
<pubDate>Sat, 28 Jun 2008 16:18:16 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101751.html#1101751</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#13796] Trojan-Dropper on dj-samy.fr AS35830&lt;br /&gt;Posted: Sat Jun 28, 2008 9:18 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Dropper_malware13796.html&quot;&gt;http://www.castlecops.com/Trojan_Dropper_malware13796.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Consumed following related reports:
&lt;br /&gt;

&lt;br /&gt;
[13808] &lt;a href=&quot;http://dj-samy.fr/video.exe&quot;&gt;http://dj-samy.fr/video.exe&lt;/a&gt; 
&lt;br /&gt;
Changed status to confirmed malware.IP Converted: 193.37.145.41
&lt;br /&gt;

&lt;br /&gt;
dword = 3240464681
&lt;br /&gt;
hex1 = 0xc1259129
&lt;br /&gt;
hex2 = 0xc1.0x25.0x91.0x29
&lt;br /&gt;
oct = 0301.045.0221.051
&lt;br /&gt;
video1.exe at this location is malware known as TrojanDropper:Win32/Nuwar.gen!ldt (Microsoft).video.exe at this location is malware known as TrojanDropper:Win32/Nuwar.gen!ldt (Microsoft).View CIDR AS35830 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=35830&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=35830&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;35830 | FR | ripencc | 2005-11-09 | SIVIT-AS SIVIT Network - &lt;a href=&quot;http://www.sivit.net/&amp;quot;&amp;lt;br&quot;&gt;http://www.sivit.net/&amp;quot;&amp;lt;br&lt;/a&gt; /&amp;gt;
&lt;br /&gt;
Extended information for AS35830:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: fr
&lt;br /&gt;
Responsible Domain: sivit.fr
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:gregory@sivit.fr&quot;&gt;gregory@sivit.fr&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://dj-samy.fr/video1.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101751#1101751" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101751</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#13786] Trojan on IceMan.ro AS30976</title>
<link>http://www.castlecops.com/postp1101749.html#1101749</link>
<pubDate>Sat, 28 Jun 2008 16:11:22 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101749.html#1101749</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#13786] Trojan on IceMan.ro AS30976&lt;br /&gt;Posted: Sat Jun 28, 2008 9:11 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_malware13786.html&quot;&gt;http://www.castlecops.com/Trojan_malware13786.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 85.204.4.215
&lt;br /&gt;

&lt;br /&gt;
dword = 1439433943
&lt;br /&gt;
hex1 = 0x55cc04d7
&lt;br /&gt;
hex2 = 0x55.0xcc.0x4.0xd7
&lt;br /&gt;
oct = 0125.0314.04.0327
&lt;br /&gt;
hallmark.gif.exe at this location is malware known as Trojan:Win32/Zapchast (Microsoft).View CIDR AS30976 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=30976&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=30976&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;30976 | RO | ripencc | 2004-02-02 | IT4WEB IT4WEB S.R.L.&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS30976:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: ro
&lt;br /&gt;
Responsible Domain: it4web.ro
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:zozo@it4web.ro&quot;&gt;zozo@it4web.ro&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://IceMan.ro/hallmark.gif.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101749#1101749" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101749</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#14144] Trojan-Dropper on energical.com AS16276</title>
<link>http://www.castlecops.com/postp1101607.html#1101607</link>
<pubDate>Sat, 28 Jun 2008 08:40:23 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101607.html#1101607</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#14144] Trojan-Dropper on energical.com AS16276&lt;br /&gt;Posted: Sat Jun 28, 2008 1:40 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_Dropper_malware14144.html&quot;&gt;http://www.castlecops.com/Trojan_Dropper_malware14144.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Consumed following related reports:
&lt;br /&gt;

&lt;br /&gt;
[14163] &lt;a href=&quot;http://energical.com/video.exe&quot;&gt;http://energical.com/video.exe&lt;/a&gt; 
&lt;br /&gt;
Changed status to confirmed malware.IP Converted: 91.121.105.199
&lt;br /&gt;

&lt;br /&gt;
dword = 1534683591
&lt;br /&gt;
hex1 = 0x5b7969c7
&lt;br /&gt;
hex2 = 0x5b.0x79.0x69.0xc7
&lt;br /&gt;
oct = 0133.0171.0151.0307
&lt;br /&gt;
video1.exe at this location is malware known as TrojanDropper:Win32/Nuwar.gen!ldt (Microsoft).View CIDR AS16276 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=16276&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=16276&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;16276 | FR | ripencc | 2001-02-15 | OVH OVH&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS16276:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: 
&lt;br /&gt;
Responsible Domain: ovh.net
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:abuse@ovh.net&quot;&gt;abuse@ovh.net&lt;/a&gt;
&lt;br /&gt;
Generated and sent email malware alert to respective parties.&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://energical.com/video1.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101607#1101607" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101607</comments>
</item>
<item>
<title>MIRT Reports :: [MIRT#13677] Trojan on personales.ya.com AS20838</title>
<link>http://www.castlecops.com/postp1101599.html#1101599</link>
<pubDate>Sat, 28 Jun 2008 08:08:42 -0500</pubDate>
<guid isPermaLink="true">http://www.castlecops.com/postp1101599.html#1101599</guid>
<description>Author: &lt;a href=&quot;http://www.castlecops.com/modules.php?name=Forums&amp;file=profile&amp;mode=viewprofile&amp;u=170180&quot; target=&quot;_blank&quot;&gt;tetak&lt;/a&gt;&lt;br /&gt;
Subject: [MIRT#13677] Trojan on personales.ya.com AS20838&lt;br /&gt;Posted: Sat Jun 28, 2008 1:08 pm (GMT 0)&lt;br /&gt;
&lt;br /&gt;&lt;span class="postbody"&gt;
&lt;span style=&quot;font-size: 18px; line-height: normal&quot;&gt;&lt;span style=&quot;color: darkred&quot;&gt;&lt;span style=&quot;font-weight: bold&quot;&gt;Malware Alert&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Full Report: &lt;a href=&quot;http://www.castlecops.com/Trojan_malware13677.html&quot;&gt;http://www.castlecops.com/Trojan_malware13677.html&lt;/a&gt; &lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;display: none;&quot;&gt;&amp;nbsp;&lt;/span&gt;Changed status to confirmed malware.IP Converted: 62.151.4.22
&lt;br /&gt;

&lt;br /&gt;
dword = 1050084374
&lt;br /&gt;
hex1 = 0x3e970416
&lt;br /&gt;
hex2 = 0x3e.0x97.0x4.0x16
&lt;br /&gt;
oct = 076.0227.04.026
&lt;br /&gt;
greeting.gif.exe at this location is malware known as Trojan:Win32/Zapchast (Microsoft).View CIDR AS20838 Report: &lt;a href=&quot;http://www.cidr-report.org/cgi-bin/as-report?as=20838&quot;&gt;http://www.cidr-report.org/cgi-bin/as-report?as=20838&lt;/a&gt; 
&lt;br /&gt;

&lt;br /&gt;
&amp;quot;20838 | ES | ripencc | 2001-06-12 | YIF-AS YIF Autonomous System&amp;quot;&amp;lt;br /&amp;gt;
&lt;br /&gt;
Extended information for AS20838:
&lt;br /&gt;
State/Province: 
&lt;br /&gt;
Country: es
&lt;br /&gt;
Responsible Domain: corp.ya.com
&lt;br /&gt;
Abuse Email: &lt;a href=&quot;mailto:postmaster@ya.com&quot;&gt;postmaster@ya.com&lt;/a&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Quote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;http://personales.ya.com/q1w2/greeting.gif.exe&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;/span&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;/span&gt;&lt;br /&gt;
</description>
<dc:creator>tetak</dc:creator>
<dc:subject>MIRT Reports</dc:subject>
<annotate:reference rdf:resource="http://www.castlecops.com/postp1101599#1101599" />
<comments>http://www.castlecops.com/modules.php?name=Forums&amp;file=posting&amp;mode=quote&amp;p=1101599</comments>
</item>
</channel>
</rss>
<!-- Page generation time: 0.2525s  - GZIP disabled -->