tetak
MIRT Team Lead Premium Member
 Joined: Jan 19, 2007 Posts: 5879
|
Posted: Wed Nov 07, 2007 9:01 pm Post subject: [MIRT#5758] eCard on 75.46.64.49 AS7132 |
|
|
Malware Alert Full Report: /eCard_malware5758.html Consumed following related reports:
[5759] http://75.46.64.49/halloween.exe
Changed status to confirmed malware. IP Converted: 75.46.64.49
dword = 1261322289
hex1 = 0x4b2e4031
hex2 = 0x4b.0x2e.0x40.0x31
oct = 0113.056.0100.061
View CIDR AS7132 Report: http://www.cidr-report.org/cgi-bin/as-report?as=7132
"7132 | US | arin | 1996-09-13 | SBIS-AS - AT&T Internet Services"<br />
Extended information for AS7132:
State/Province: tx
Country: us
Responsible Domain: swbell.net
Abuse Email: abuse@swbell.net
dancer.exe at this location is malware known as Packed.Win32.Tibs.dn (Kaspersky)
| Quote: | | http://75.46.64.49/ |
|
|