tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5741
|
Posted: Sat Aug 25, 2007 11:37 am Post subject: [MIRT#350] eCard on 24.166.136.57 AS7017 |
|
|
Malware Alert Full Report: /eCard_malware350.html Changed status to confirmed malware. IP Converted: 24.166.136.57
dword = 413567033
hex1 = 0x18a68839
hex2 = 0x18.0xa6.0x88.0x39
oct = 030.0246.0210.071
View CIDR AS7017 Report: http://www.cidr-report.org/cgi-bin/as-report?as=7017
"7017 | US | arin | 2000-06-21 | SCRR-7015 - Road Runner HoldCo LLC"<br />
Extended information for AS7017:
State/Province: va
Country: us
Responsible Domain: rr.com
Abuse Email: abuse@rr.com
video.exe at this location is a Trojan:Win32/Tibs.gen!B Trojan as seen by Microsoft
| Quote: | | http://24.166.136.57/?8ec43d852d4b9999b98562bd22c |
|
|