tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5774
|
Posted: Sun Apr 27, 2008 7:12 am Post subject: [MIRT#10582] Trojan-Dropper on ramsackent.com AS26496 |
|
|
Malware Alert Full Report: /Trojan_Dropper_malware10582.html Changed status to confirmed malware.IP Converted: 68.178.211.87
dword = 1152570199
hex1 = 0x44b2d357
hex2 = 0x44.0xb2.0xd3.0x57
oct = 0104.0262.0323.0127
video.exe at this location is malware known as TrojanDropper:Win32/Nuwar.gen!lds (Microsoft).View CIDR AS26496 Report: http://www.cidr-report.org/cgi-bin/as-report?as=26496
"26496 | US | arin | 2002-10-01 | PAH-INC - GoDaddy.com, Inc."<br />
Extended information for AS26496:
State/Province: az
Country: us
Responsible Domain: godaddy.com
Abuse Email: abuse@godaddy.com
| Quote: | | http://ramsackent.com/video.exe |
|
|