<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Malware Database &#187; djpnuemo</title>
	<atom:link href="http://malwaredatabase.net/blog/index.php/author/djpnuemo/feed/" rel="self" type="application/rss+xml" />
	<link>http://malwaredatabase.net/blog</link>
	<description>Malware Database is a group of security professionals and a few hobbyists who each contribute to a private distributed database of malicious binaries while raising awareness on current malware trends through our website.</description>
	<lastBuildDate>Fri, 16 Jul 2010 07:11:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>New rogue domain: personalonlinescanv3.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/07/13/new-rogue-domain-personalonlinescanv3-com/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/07/13/new-rogue-domain-personalonlinescanv3-com/#comments</comments>
		<pubDate>Mon, 13 Jul 2009 15:52:29 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Low Detection]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1997</guid>
		<description><![CDATA[Whois entry for personalonlinescanv3.com 83.133.126.155
Name: Yuvaraj K Jothi
Address: 88, Periyar EVR High Road
City: Chennai
Province/state: Chennai
Country: IN
Postal Code: 600007
Setup-fdbd6_02012.exe
Result: 2/41 (4.88%)
MD5: eb0111f5fd11420d70988bc21dcda65a
VirusTotal
ThreatExpert Analysis
hxxp://personalonlinescanv3.com/download/
]]></description>
			<content:encoded><![CDATA[<p><a href="http://whois.sc/personalonlinescanv3.com" target="_blank">Whois entry for personalonlinescanv3.com</a> 83.133.126.155<br />
Name: Yuvaraj K Jothi<br />
Address: 88, Periyar EVR High Road<br />
City: Chennai<br />
Province/state: Chennai<br />
Country: IN<br />
Postal Code: 600007</p>
<p><strong>Setup-fdbd6_02012.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">2</span>/41 (4.88%)</span><br />
MD5: eb0111f5fd11420d70988bc21dcda65a<br />
<a href="http://www.virustotal.com/analisis/a3b79c41833d8144b014eef803cf801946445e10a817ddaceaaef6cb6deae893-1247500528" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=eb0111f5fd11420d70988bc21dcda65a" target="_blank">ThreatExpert Analysis</a><br />
hxxp://personalonlinescanv3.com/download/</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/07/13/new-rogue-domain-personalonlinescanv3-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New malware domain: hotexefiles.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/07/13/new-malware-domain-hotexefiles-com/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/07/13/new-malware-domain-hotexefiles-com/#comments</comments>
		<pubDate>Mon, 13 Jul 2009 15:38:52 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Infection]]></category>
		<category><![CDATA[Low Detection]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1992</guid>
		<description><![CDATA[hxxp://besttubetech.com/xplays.php?id=40014&#38;name=sahel+kazemi+dui+video&#38;hostingtype=vox&#38;theme=trends&#38;category=hottrends&#38;from=videoplayer
Whois entry for hotexefiles.com 64.20.38.172
Susan Field (susfie16@gmail.com)
1059 Rubaiyat Road
Grand Rapids
Michigan,49503
US
Tel. +001.56578987654
onlinemovies.40014.exe
Result: 8/41 (19.52%)
MD5: 2e02ea10960799a78792e39f5498adb6
VirusTotal
ThreatExpert Analysis
hxxp://hotexefiles.com/
onlinemovies.40069.exe
Result: 2/40 (5%)
MD5: 35b979934376577e4429db4317e5184f
VirusTotal
ThreatExpert Analysis
hxxp://hotexefiles.com/
SIDE NOTE: There may be a misconception as to the purpose of these posts.  It is not posting a NEW malware variant or NEW malware altogether.  These posts are simply to show the new domain [...]]]></description>
			<content:encoded><![CDATA[<p>hxxp://besttubetech.com/xplays.php?id=40014&amp;name=sahel+kazemi+dui+video&amp;hostingtype=vox&amp;theme=trends&amp;category=hottrends&amp;from=videoplayer</p>
<p><a href="http://whois.sc/hotexefiles.com" target="_blank">Whois entry for hotexefiles.com</a> 64.20.38.172<br />
Susan Field (susfie16@gmail.com)<br />
1059 Rubaiyat Road<br />
Grand Rapids<br />
Michigan,49503<br />
US<br />
Tel. +001.56578987654</p>
<p><strong>onlinemovies.40014.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">8</span>/41 (19.52%)</span><br />
MD5: 2e02ea10960799a78792e39f5498adb6<br />
<a href="http://www.virustotal.com/analisis/a69d420eec35043584d3af59a4ae5e52cd1aa32e0b2c83cf486ffb63835df0c5-1247499592" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=2e02ea10960799a78792e39f5498adb6" target="_blank">ThreatExpert Analysis</a><br />
hxxp://hotexefiles.com/</p>
<p><strong>onlinemovies.40069.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">2</span>/40 (5%)</span><br />
MD5: 35b979934376577e4429db4317e5184f<br />
<a href="http://www.virustotal.com/analisis/1c64e367a2cb0f8ef2cfb174ac576d100588660df804a286c2311d678b92b69b-1247500065" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=35b979934376577e4429db4317e5184f" target="_blank">ThreatExpert Analysis</a><br />
hxxp://hotexefiles.com/</p>
<p>SIDE NOTE: There may be a misconception as to the purpose of these posts.  It is not posting a NEW malware variant or NEW malware altogether.  These posts are simply to show the new domain it has switched to.  I include the the binary downloaded as additional information because we add it to our database.  Because the person(s) involved will not respond to my emails, I posted here.</p>
<p>Let&#8217;s not make assumptions people.</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/07/13/new-malware-domain-hotexefiles-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New malware domain: exe-cosmos.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/07/10/new-malware-domain-exe-cosmos-com/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/07/10/new-malware-domain-exe-cosmos-com/#comments</comments>
		<pubDate>Fri, 10 Jul 2009 15:07:11 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Low Detection]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1989</guid>
		<description><![CDATA[hxxp://tubessite.com/xplays.php?id=40069
Whois entry for exe-cosmos.com 64.20.38.172
Jennifer Ket (jennifket@gmail.com)
1120 Broadway Avenue
Johnson City
Tennessee,37601
US
Tel. +001.43459898760
onlinemovies.40014.exe
Result: 3/41 (7.32%)
MD5: 64a411cce0da8680576a5314eb6ce8e0
VirusTotal
ThreatExpert Analysis
hxxp://exe-cosmos.com/
onlinemovies.40069.exe
Result: 3/41 (7.32%)
MD5: a8148ab3190ae2d5b2765b10ded7228b
VirusTotal
ThreatExpert Analysis
hxxp://exe-cosmos.com/
]]></description>
			<content:encoded><![CDATA[<p>hxxp://tubessite.com/xplays.php?id=40069</p>
<p><a href="http://whois.sc/exe-cosmos.com" target="_blank">Whois entry for exe-cosmos.com</a> 64.20.38.172<br />
Jennifer Ket (jennifket@gmail.com)<br />
1120 Broadway Avenue<br />
Johnson City<br />
Tennessee,37601<br />
US<br />
Tel. +001.43459898760</p>
<p><strong>onlinemovies.40014.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">3</span>/41 (7.32%)</span><br />
MD5: 64a411cce0da8680576a5314eb6ce8e0<br />
<a href="http://www.virustotal.com/analisis/b0317ae6ad66f4de440328c91d1c486b9912f9918f89399f1487b72a27968b71-1247238514" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=64a411cce0da8680576a5314eb6ce8e0" target="_blank">ThreatExpert Analysis</a><br />
hxxp://exe-cosmos.com/</p>
<p><strong>onlinemovies.40069.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">3</span>/41 (7.32%)</span><br />
MD5: a8148ab3190ae2d5b2765b10ded7228b<br />
<a href="http://www.virustotal.com/analisis/f1aa7db8011b713b388c9d2e87876006fc3d176e085b987222323779e63318cb-1247238518" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=a8148ab3190ae2d5b2765b10ded7228b" target="_blank">ThreatExpert Analysis</a><br />
hxxp://exe-cosmos.com/</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/07/10/new-malware-domain-exe-cosmos-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Database Update: 29 files (Low/Moderate Detection)</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/07/09/database-update-29-files-lowmoderate-detection/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/07/09/database-update-29-files-lowmoderate-detection/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 16:04:43 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Malicious Links]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1976</guid>
		<description><![CDATA[Files added to our database recently.
WARNING: URL&#8217;s may still be active.  Proceed at your own risk.
Setup-73cb3_02009-1938.exe
Result: 12/41 (29.27%)
MD5: 082c4b1a7b77db893364c3fd3a77b647
VirusTotal
ThreatExpert Analysis
hxxp://secured-virus-scanner.com/download/
id_0122.exe or setup.exe
Result: 13/40 (32.5%)
MD5: 5e6ea7e4f4fbe148e3a06afa58daf581
VirusTotal
ThreatExpert Analysis
hxxp://youtube-adult.name/
pdrv.exe or vcru_1246903147.exe
Result: 12/40 (30%)
MD5: 97207099a118be4091785119b1d9937d
VirusTotal
ThreatExpert Analysis
hxxp://upload.octopus-multimedia.be/1/pdrv.exe
pp.10.exe or pp10.exe
Result: 24/40 (60%)
MD5: 133f989d913fea3e8802282bd37c5927
VirusTotal
ThreatExpert Analysis
hxxp://upload.octopus-multimedia.be/1/pp.10.exe
ld12.exe
Result: 22/41 (53.66%)
MD5: 5c8c37b5ce36b12aaa670b30bd84887a
VirusTotal
ThreatExpert Analysis
install.48322.exe
Result: 17/41 (41.47%)
MD5: 6b8828c90810b4c46eb93bab5976be89
VirusTotal
ThreatExpert Analysis
codec.exe
Result: 19/41 (46.35%)
MD5: 50f81d56bc7e620032d6e87c917aa663
VirusTotal
ThreatExpert Analysis
lol.exe
Result: 5/41 (12.2%)
MD5: ee8171ed76ae49a9c68dd5d33ce74931
VirusTotal
ThreatExpert Analysis
service.exe
Result: 7/41 [...]]]></description>
			<content:encoded><![CDATA[<p>Files added to our database recently.</p>
<p><strong>WARNING</strong>: URL&#8217;s may still be active.  Proceed at your own risk.</p>
<p><strong>Setup-73cb3_02009-1938.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">12</span>/41 (29.27%)</span><br />
MD5: 082c4b1a7b77db893364c3fd3a77b647<br />
<a href="http://www.virustotal.com/analisis/02e161b32d114484e2be4b7d1e0c643ff6810e08be91f858de4afb9dd7d7a324-1247114812" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=082c4b1a7b77db893364c3fd3a77b647" target="_blank">ThreatExpert Analysis</a><br />
hxxp://secured-virus-scanner.com/download/</p>
<p><strong>id_0122.exe</strong> or <strong>setup.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">13</span>/40 (32.5%)</span><br />
MD5: 5e6ea7e4f4fbe148e3a06afa58daf581<br />
<a href="http://www.virustotal.com/analisis/4810a2bf193f9097f98912fba40878d8fd68d79e66d4b1c64482706462621940-1247115099" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=5e6ea7e4f4fbe148e3a06afa58daf581" target="_blank">ThreatExpert Analysis</a><br />
hxxp://youtube-adult.name/</p>
<p style="padding-left: 30px;"><strong>pdrv.exe</strong> or <strong>vcru_1246903147.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">12</span>/40 (30%)</span><br />
MD5: 97207099a118be4091785119b1d9937d<br />
<a href="http://www.virustotal.com/analisis/ff8151b8e85ad3be26fe84aa5ba1cb5a617388d4d0a70ea8e992f7a2c8225584-1247150501" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=97207099a118be4091785119b1d9937d" target="_blank">ThreatExpert Analysis</a><br />
hxxp://upload.octopus-multimedia.be/1/pdrv.exe</p>
<p style="padding-left: 30px;"><strong>pp.10.exe</strong> or <strong>pp10.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">24</span>/40 (60%)</span><br />
MD5: 133f989d913fea3e8802282bd37c5927<br />
<a href="http://www.virustotal.com/analisis/4698edb015333a382b6ea2944aabb031c5e2f445afeba8ed3f83df2749bcf469-1247150475" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=133f989d913fea3e8802282bd37c5927" target="_blank">ThreatExpert Analysis</a><br />
hxxp://upload.octopus-multimedia.be/1/pp.10.exe</p>
<p style="padding-left: 30px;"><strong>ld12.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">22</span>/41 (53.66%)</span><br />
MD5: 5c8c37b5ce36b12aaa670b30bd84887a<br />
<a href="http://www.virustotal.com/analisis/b12632589def1c8447237317491b4ca03a8c1519a2e683481eb8161fa853911c-1247150425" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=5c8c37b5ce36b12aaa670b30bd84887a" target="_blank">ThreatExpert Analysis</a></p>
<p style="padding-left: 30px;"><strong>install.48322.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">17</span>/41 (41.47%)</span><br />
MD5: 6b8828c90810b4c46eb93bab5976be89<br />
<a href="http://www.virustotal.com/analisis/ad18b4ac181377017336daf9784fa8297eda1693190fdf6c91484351bc2cdbbb-1247150440" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=6b8828c90810b4c46eb93bab5976be89" target="_blank">ThreatExpert Analysis</a></p>
<p style="padding-left: 30px;"><strong>codec.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">19</span>/41 (46.35%)</span><br />
MD5: 50f81d56bc7e620032d6e87c917aa663<br />
<a href="http://www.virustotal.com/analisis/330c24817c65edd69bc1f092ff5438145b4e52e671156570fb4ee16610f74b01-1247150445" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=50f81d56bc7e620032d6e87c917aa663" target="_blank">ThreatExpert Analysis</a></p>
<p style="padding-left: 30px;"><strong>lol.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">5</span>/41 (12.2%)</span><br />
MD5: ee8171ed76ae49a9c68dd5d33ce74931<br />
<a href="http://www.virustotal.com/analisis/3ca539787a012c669a99e87150c4e891ae9891e118ee5f87d12e90203c6f07f7-1247150459" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=ee8171ed76ae49a9c68dd5d33ce74931" target="_blank">ThreatExpert Analysis</a></p>
<p style="padding-left: 30px;"><strong>service.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">7</span>/41 (17.08%)</span><br />
MD5: 6e42355db044533bea5f06552065efa3<br />
<a href="http://www.virustotal.com/analisis/8152f5a64f6f5d8d2694687a1b1fe9ff030c215dbe443b40ead6903375e8bda6-1247150464" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=6e42355db044533bea5f06552065efa3" target="_blank">ThreatExpert Analysis</a></p>
<p style="padding-left: 30px;"><strong>391.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">8</span>/41 (19.52%)</span><br />
MD5: 39ef491b937577930f7057f2a7d2e3f4<br />
<a href="http://www.virustotal.com/analisis/57ac04df005c3f55954478304b847d5d54f9b6a55467be21935ce2b19a25e2f1-1247150494" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=39ef491b937577930f7057f2a7d2e3f4" target="_blank">ThreatExpert Analysis</a></p>
<p style="padding-left: 30px;"><strong>setup.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">21</span>/41 (51.22%)</span><br />
MD5: 513ffc855daed8d0889188431add9d34<br />
<a href="http://www.virustotal.com/analisis/bdc3bfdfabe20ba63489bf9701ebf23c443f319c7fa826eefa736d386a7c60d9-1247150498" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=513ffc855daed8d0889188431add9d34" target="_blank">ThreatExpert Analysis</a></p>
<p><strong>FlashPlayer.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">18</span>/41 (43.91%)</span><br />
MD5: 88d88eb7a3941e89c1c9dac8797e7301<br />
<a href="http://www.virustotal.com/analisis/e187860a00b50775c4578bfead92182ea4c0e00ad674450477a3d5eb9881435e-1247114898" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=88d88eb7a3941e89c1c9dac8797e7301" target="_blank">ThreatExpert Analysis</a><br />
hxxp://healsearcher.com/download/2b58736731513d3d150878b420090701/</p>
<p style="padding-left: 30px;"><strong>.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">11</span>/41 (26.83%)</span><br />
MD5: 174aa8777d77426485747d6de4d0039b<br />
<a href="http://www.virustotal.com/analisis/872e63490818d8243a2c6c399a0612705e5f2716752cb8dcbdb2aaa788fe8006-1247151049" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=174aa8777d77426485747d6de4d0039b" target="_blank">ThreatExpert Analysis</a></p>
<p><strong>setup.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">20</span>/41 (48.79%)</span><br />
MD5: e28ecac172dd0b6a178e4abbd6e92af7<br />
<a href="http://www.virustotal.com/analisis/bb261e0740321a984fac2c6a8f69090791de63377889b78de5acdb036008efda-1247114933" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=e28ecac172dd0b6a178e4abbd6e92af7" target="_blank">ThreatExpert Analysis</a></p>
<p><strong>a.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">26</span>/41 (63.42%)</span><br />
MD5: eb4209ac9062804a8c83831ffb0dc6c7<br />
<a href="http://www.virustotal.com/analisis/4a21467c0c874598418151c215689e6dc8034d37fabd59607afe242e943249f9-1247115442" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=eb4209ac9062804a8c83831ffb0dc6c7" target="_blank">ThreatExpert Analysis</a><br />
hxxp://arplgm.cn/</p>
<p><strong>VideoCodec.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">14</span>/41 (34.15%)</span><br />
MD5: 8254d797dc12adaa7e50f30128199b17<br />
<a href="http://www.virustotal.com/analisis/a6eafe94a84080fe8596b30aacf9d0be69d68bed3c78df16c0497c5683ee6a31-1247115736" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=8254d797dc12adaa7e50f30128199b17" target="_blank">ThreatExpert Analysis</a><br />
hxxp://healsearcher.com/download/4672366463673d3d0c36c19720090701/</p>
<p style="padding-left: 30px;"><strong>Mediacodec.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">16</span>/41 (39.03%)</span><br />
MD5: 72ede7e934e0777120ec95fa229f0a2a<br />
<a href="http://www.virustotal.com/analisis/c85fb930e87ab1d2a1991f12446bca653381618d87935458bdcfa6883153ab09-1247151762" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=72ede7e934e0777120ec95fa229f0a2a" target="_blank">ThreatExpert Analysis</a></p>
<p><strong>win.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">23</span>/41 (56.1%)</span><br />
MD5: b6ebdb9c3e24ef845af65a8ea5d09540<br />
<a href="http://www.virustotal.com/analisis/ebd71cd5f7a4931a314b4544cff350ea980f50fbe485edeba58574bf6d1c35b4-1247115847" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=b6ebdb9c3e24ef845af65a8ea5d09540" target="_blank">ThreatExpert Analysis</a><br />
hxxp://ads.v8dc.com/win/</p>
<p><strong>evilItTheir.pdf</strong><br />
Result: <span id="porcentaje"><span style="color: red;">12</span>/41 (29.27%)</span><br />
MD5: 3e43e2393e03b76af5f7ff1b30ed83a1<br />
VirusTotal<br />
<a href="http://wepawet.cs.ucsb.edu/view.php?hash=3e43e2393e03b76af5f7ff1b30ed83a1&amp;type=js" target="_blank">Wepawet Analysis</a><br />
hxxp://imagehut3.cn/images/</p>
<p style="padding-left: 30px;"><strong>load.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">5</span>/41 (12.2%)</span><br />
MD5: 55126b500a9cbecb6e3df1a61592fcc7<br />
<a href="http://www.virustotal.com/analisis/c8e0c30ed5c3ff9a04b5799cc7a767d7c8180aa71b69d69c2027f2f8849e6313-1247116253" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=55126b500a9cbecb6e3df1a61592fcc7" target="_blank">ThreatExpert Analysis</a><br />
hxxp://imagehut3.cn/images/update.php</p>
<p><strong>install_flash_player.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">0</span>/41 (0%)</span><br />
MD5: a51b5d3fee2215f0068fc36174a53513<br />
<a href="http://www.virustotal.com/analisis/7da60e51f2229d44e7bb99f23f54fc42e8012bd7ee462a388cc174379febc336-1247116384" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=a51b5d3fee2215f0068fc36174a53513" target="_blank">ThreatExpert Analysis</a><br />
hxxp://missing-codecs.net/download/download.php</p>
<p><strong>load.exe</strong> or <strong>sysguard.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">2</span>/40 (5%)</span><br />
MD5: 507aedd5e26a6bf81635b067b8053ceb<br />
<a href="http://www.virustotal.com/analisis/765bcb755fcab715c8cfd5cee94e1f5c41ab319c6756bd58be3f5a6014c7be40-1247116687" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=507aedd5e26a6bf81635b067b8053ceb" target="_blank">ThreatExpert Analysis</a><br />
<span onmouseover="_tipon(this)" onmouseout="_tipoff()">hxxp://91.212.198.116/lib/update.php</span></p>
<p><strong>fotos_Album.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">21</span>/41 (51.22%)</span><br />
MD5: af50713e6ff1cfc0e190261a48dc8ee2<br />
<a href="http://www.virustotal.com/analisis/5a97054007d0887206d5b53a826208cecf1b0337c36a1e72417a103daaa7d64d-1247117280" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=af50713e6ff1cfc0e190261a48dc8ee2" target="_blank">ThreatExpert Analysis</a></p>
<p style="padding-left: 30px;"><strong>principal.txt</strong> or <strong>process.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">12</span>/40 (30%)</span><br />
MD5: 097fcf4368c94d83563f205ce335f89b<br />
<a href="http://www.virustotal.com/analisis/7116fd5e5278db8b4f1d6d2930510f89a288c7670ebc51ccfabb895bb2c765dd-1247152703" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=097fcf4368c94d83563f205ce335f89b" target="_blank">ThreatExpert Analysis</a><br />
hxxp://www.hoje-noticias.pagebr.com/downloads/</p>
<p style="padding-left: 60px;"><strong>TS45.SYS</strong><br />
Result: <span id="porcentaje"><span style="color: red;">2</span>/41 (4.88%)</span><br />
MD5: aba452fd10f74aabcac36b579046ede8<br />
<a href="http://www.virustotal.com/analisis/7ab79c5e7a63130e94242eab795ebb3b6d575a8be2a06d76b03e25f9285d1c1d-1247153477" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=aba452fd10f74aabcac36b579046ede8" target="_blank">ThreatExpert Analysis</a></p>
<p style="padding-left: 30px;"><strong>plug2.txt</strong> or <strong>wiskyx.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">20</span>/41 (48.79%)</span><br />
MD5: 6b88ad201100fe58920842be576f5482<br />
<a href="http://www.virustotal.com/analisis/f8f6718d02427308cd3b617adbd2a6aa0b2e7b2e347a3a49eb15fe03e39cdcc4-1247152566" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=6b88ad201100fe58920842be576f5482" target="_blank">ThreatExpert Analysis</a><br />
hxxp://www.hoje-noticias.pagebr.com/downloads/</p>
<p style="padding-left: 30px;"><strong>winsex2.txt</strong> or <strong>winsex2.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">11</span>/40 (27.5%)</span><br />
MD5: 3abb2f2eda63e9ed447aad1e502b5e25<br />
<a href="http://www.virustotal.com/analisis/2f60c3d3962a8d374fb9bb2926444c7b9c04204809c26277b473d9066d406c19-1247152673" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=3abb2f2eda63e9ed447aad1e502b5e25" target="_blank">ThreatExpert Analysis</a><br />
hxxp://www.hoje-noticias.pagebr.com/downloads/</p>
<p><strong>Setup-27a_02022.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">6</span>/41 (14.64%)</span><br />
MD5: a778ceee0fa0161bf77fa318fa3f1a51<br />
<a href="http://www.virustotal.com/analisis/c3b4c5d75fa6aa45c6fdb47108e5c7a93f74905552bd8fe5e4cc791eaecb46a9-1247117288" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=a778ceee0fa0161bf77fa318fa3f1a51" target="_blank">ThreatExpert Analysis</a></p>
<p><strong>update.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">14</span>/40 (35%)</span><br />
MD5: 4e37097b45d8885a55ef8bd0a0669446<br />
<a href="http://www.virustotal.com/analisis/b72339e62703cf5077628f6acf549674a87128d9e2adc0ef5a88d9d610fe1e52-1247154925" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=4e37097b45d8885a55ef8bd0a0669446" target="_blank">ThreatExpert Analysis</a><br />
hxxp://vikd3jj-2.com/2/index.php</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/07/09/database-update-29-files-lowmoderate-detection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New malware domain: red-exe.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/07/09/new-malware-domain-red-exe-com/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/07/09/new-malware-domain-red-exe-com/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 14:15:56 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Low Detection]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1982</guid>
		<description><![CDATA[hxxp://go-go-tube.com/xplays.php?id=40069
Whois entry for red-exe.com 64.20.38.172
Tasha Chambers (tashcham@gmail.com)
2520 North Street
Kearns
Utah,84118
US
Tel. +001.98985647689
onlinemovies.40069.exe
Result: 0/40 (0%)
MD5: 39c1a48433c6de8c08d75926cb468d20
VirusTotal
ThreatExpert Analysis
hxxp://red-exe.com/
onlinemovies.40014.exe
Result: 0/40 (0%)
MD5: a24bcd49eb5d266d11fb2883a203ef76
VirusTotal
ThreatExpert Analysis
hxxp://red-exe.com/
]]></description>
			<content:encoded><![CDATA[<p>hxxp://go-go-tube.com/xplays.php?id=40069</p>
<p><a href="http://whois.sc/red-exe.com" target="_blank">Whois entry for red-exe.com</a> 64.20.38.172<br />
Tasha Chambers (tashcham@gmail.com)<br />
2520 North Street<br />
Kearns<br />
Utah,84118<br />
US<br />
Tel. +001.98985647689</p>
<p><strong>onlinemovies.40069.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">0</span>/40 (0%)</span><br />
MD5: 39c1a48433c6de8c08d75926cb468d20<br />
<a href="http://www.virustotal.com/analisis/6f8dd5d39e78570bb01273f8b901110075f4a6a64a13b5780077a97b8a68d61f-1247149037" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=39c1a48433c6de8c08d75926cb468d20" target="_blank">ThreatExpert Analysis</a><br />
hxxp://red-exe.com/</p>
<p><strong>onlinemovies.40014.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">0</span>/40 (0%)</span><br />
MD5: a24bcd49eb5d266d11fb2883a203ef76<br />
<a href="http://www.virustotal.com/analisis/85fe85ecd6395bc8d38d592608d5bad923f0a5052b350cc3548931a37344f572-1247149173" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=a24bcd49eb5d266d11fb2883a203ef76" target="_blank">ThreatExpert Analysis</a><br />
hxxp://red-exe.com/</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/07/09/new-malware-domain-red-exe-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rogue domain: securedvirusscan.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/07/09/rogue-domain-securedvirusscan-com/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/07/09/rogue-domain-securedvirusscan-com/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 14:10:54 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Low Detection]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1979</guid>
		<description><![CDATA[Whois entry for securedvirusscan.com 69.4.230.205
Privat person
Aleksandr Rozanov adsff@freebbmail.com
+74952783441 fax: +74952783441
ul. Peshkova 29-52
Moskva Moskovskay oblast 126106
ru
Setup-4e45_02022.exe
Result: 0/40 (0%)
MD5: abc17998e1b33fe99f60497010028523
VirusTotal
ThreatExpert Analysis
hxxp://securedvirusscan.com/download/
]]></description>
			<content:encoded><![CDATA[<p><a href="http://whois.sc/securedvirusscan.com" target="_blank">Whois entry for securedvirusscan.com</a> 69.4.230.205<br />
Privat person<br />
Aleksandr Rozanov adsff@freebbmail.com<br />
+74952783441 fax: +74952783441<br />
ul. Peshkova 29-52<br />
Moskva Moskovskay oblast 126106<br />
ru</p>
<p><strong>Setup-4e45_02022.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">0</span>/40 (0%)</span><br />
MD5: abc17998e1b33fe99f60497010028523<br />
<a href="http://www.virustotal.com/analisis/d0bf2dfddf95b4ae667c59e0181b9a6154a42a371eecd2bef34a238d2c58de04-1247148774" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=abc17998e1b33fe99f60497010028523" target="_blank">ThreatExpert Analysis</a><br />
hxxp://securedvirusscan.com/download/</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/07/09/rogue-domain-securedvirusscan-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Multiple domains targeting pornographic videos distributing malware codec</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/07/08/multiple-domains-targeting-pornographic-videos-distributing-malware-codec/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/07/08/multiple-domains-targeting-pornographic-videos-distributing-malware-codec/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 02:01:02 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Codec]]></category>
		<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Infection]]></category>
		<category><![CDATA[Low Detection]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1968</guid>
		<description><![CDATA[Found these sites today while browsing on Google Video.  This redirection is triggered from having a video.google.com referrer and pushes the user through a few domains to redirect and download content.  It may be triggered by other video sites as well.  This is offering an HD codec for flash player and features a cute installation [...]]]></description>
			<content:encoded><![CDATA[<p>Found these sites today while browsing on Google Video.  This redirection is triggered from having a video.google.com referrer and pushes the user through a few domains to redirect and download content.  It may be triggered by other video sites as well.  This is offering an HD codec for flash player and features a cute installation process when you visit the site.</p>
<p>hxxp://best.viralprn.net<br />
<em><strong>Redirects to<br />
</strong></em>hxxp://only.hdpornr.net<br />
<em><strong>Loads files from</strong></em><br />
hxxp://tvcodec.net</p>
<p><img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/07/hdporn.JPG" alt="" /></p>
<p><a href="http://whois.sc/viralprn.net" target="_blank">Whois entry for viralprn.net</a> 88.80.19.191</p>
<p><a href="http://whois.sc/hdpornr.net" target="_blank">Whois entry for hdpornr.net</a> 195.95.151.178</p>
<p><a href="http://whois.sc/tvcodec.net" target="_blank">Whois entry for tvcodec.net</a> 91.194.10.60<br />
PrivacyProtect.org<br />
Domain Admin (contact@privacyprotect.org)<br />
P.O. Box 97<br />
Note &#8211; All Postal Mails Rejected, visit Privacyprotect.org<br />
Moergestel<br />
null,5066 ZH<br />
NL<br />
Tel. +45.36946676</p>
<p><a href="http://whois.sc/hdenabled.com" target="_blank">Whois entry for hdenabled.com</a> 213.163.66.241</p>
<p><strong>Flash.Player.HD.v10.0.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">12</span>/41 (29.27%)</span><br />
MD5: 947828203c38f7cc2e98277076b747a0<br />
<a href="http://www.virustotal.com/analisis/4dad8759f6e7d5a3cd1e1a450c01f80d1535b68acd8ae39f1177672278a0951f-1247104583" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=947828203c38f7cc2e98277076b747a0" target="_blank">ThreatExpert Analysis</a><br />
hxxp://hdenabled.com/download/5a6a576343673d3d050cf77920090701/</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/07/08/multiple-domains-targeting-pornographic-videos-distributing-malware-codec/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New malware domain: exe-site.com</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/07/08/new-malware-domain-exe-site-com/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/07/08/new-malware-domain-exe-site-com/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 14:34:22 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Codec]]></category>
		<category><![CDATA[Database Update]]></category>
		<category><![CDATA[Low Detection]]></category>
		<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1964</guid>
		<description><![CDATA[hxxp://go-go-tube.com/xplays.php?id=40069
Whois entry for exe-site.com exe-site.com
Queenie Ziegler (queeziegl@gmail.com)
4806 Green Avenue
Fremont
California,94536
US
Tel. +001.34980976583
streamviewer.40069.exe
Result: 0/40 (0%)
MD5: 7f14d9626761ac467f85b542028259e3
VirusTotal
ThreatExpert Analysis
hxxp://exe-site.com/
]]></description>
			<content:encoded><![CDATA[<p>hxxp://go-go-tube.com/xplays.php?id=40069</p>
<p><a href="http://whois.sc/exe-site.com" target="_blank">Whois entry for exe-site.com</a> exe-site.com<br />
Queenie Ziegler (queeziegl@gmail.com)<br />
4806 Green Avenue<br />
Fremont<br />
California,94536<br />
US<br />
Tel. +001.34980976583</p>
<p><strong>streamviewer.40069.exe</strong><br />
Result: <span id="porcentaje"><span style="color: red;">0</span>/40 (0%)</span><br />
MD5: 7f14d9626761ac467f85b542028259e3<br />
<a href="http://www.virustotal.com/analisis/2ac431d9930be53375de4560db1796fc265ccc8c681177f2aec0d5d1ace10966-1247063821" target="_blank">VirusTotal</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=7f14d9626761ac467f85b542028259e3" target="_blank">ThreatExpert Analysis</a><br />
hxxp://exe-site.com/</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/07/08/new-malware-domain-exe-site-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Website selling multiple rogue programs as legitimate-Pt. 2</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/07/08/website-selling-multiple-rogue-programs-as-legitimate-pt-2/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/07/08/website-selling-multiple-rogue-programs-as-legitimate-pt-2/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 14:21:57 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1959</guid>
		<description><![CDATA[hxxp://browsersecurityinfo.com

Redirects to
hxxp://ieprotectionlist.com/2/

Redirects to
hxxp://bennysaintscathedral.com/buy.php?nh=1&#38;id=
Redirects to
hxxp://secure.buysecuritysoftwareonline.com/buy.php?nh=1&#38;id=

Whois entry for browsersecurityinfo.com 83.133.123.113
Name: Gupta C Deepak
Address: 580 Booth
City: Edmonton
Province/state: AB
Country: CA
Postal Code: 787843
Whois entry for ieprotectionlist.com 83.133.123.109
Name: Van M Jane
Address: Rod. 5C 41 &#8211; Km. 4,8
City: Santa Catarina
Province/state: Santa Catarina
Country: BR
Postal Code: 88122
Whois entry for bennysaintscathedral.com 83.133.123.113
Name: Gayao M Mel
Address: 16-18 Kingsley Close
City: Melbourne
Province/state: Melbourne
Country: RU
Postal Code: 31781
Whois entry for [...]]]></description>
			<content:encoded><![CDATA[<p>hxxp://browsersecurityinfo.com<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/07/warning.JPG" alt="" /></p>
<p><em><strong>Redirects to</strong></em><br />
hxxp://ieprotectionlist.com/2/<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/07/pav.JPG" alt="" /></p>
<p><em><strong>Redirects to</strong></em><br />
hxxp://bennysaintscathedral.com/buy.php?nh=1&amp;id=</p>
<p><em><strong>Redirects to</strong></em><br />
hxxp://secure.buysecuritysoftwareonline.com/buy.php?nh=1&amp;id=<br />
<img src="http://malwaredatabase.net/blog/wp-content/uploads/2009/07/buypage.JPG" alt="" /></p>
<p><a href="http://whois.sc/browsersecurityinfo.com" target="_blank">Whois entry for browsersecurityinfo.com</a> 83.133.123.113<br />
Name: Gupta C Deepak<br />
Address: 580 Booth<br />
City: Edmonton<br />
Province/state: AB<br />
Country: CA<br />
Postal Code: 787843</p>
<p><a href="http://whois.sc/ieprotectionlist.com" target="_blank">Whois entry for ieprotectionlist.com</a> 83.133.123.109<br />
Name: Van M Jane<br />
Address: Rod. 5C 41 &#8211; Km. 4,8<br />
City: Santa Catarina<br />
Province/state: Santa Catarina<br />
Country: BR<br />
Postal Code: 88122</p>
<p><a href="http://whois.sc/bennysaintscathedral.com" target="_blank">Whois entry for bennysaintscathedral.com</a> 83.133.123.113<br />
Name: Gayao M Mel<br />
Address: 16-18 Kingsley Close<br />
City: Melbourne<br />
Province/state: Melbourne<br />
Country: RU<br />
Postal Code: 31781</p>
<p><a href="http://whois.sc/buysecuritysoftwareonline.com" target="_blank">Whois entry for buysecuritysoftwareonline.com</a> 83.133.123.109<br />
Name: Rauf K Abdur<br />
Address: 79-E, Al-Rehman Chamber<br />
City: Islamabad<br />
Province/state: Islamabad<br />
Country: PK<br />
Postal Code: 53241</p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/07/08/website-selling-multiple-rogue-programs-as-legitimate-pt-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New rogue domains associated with known malware distributors-Pt. 2</title>
		<link>http://malwaredatabase.net/blog/index.php/2009/07/08/new-rogue-domains-associated-with-known-malware-distributors-pt-2/</link>
		<comments>http://malwaredatabase.net/blog/index.php/2009/07/08/new-rogue-domains-associated-with-known-malware-distributors-pt-2/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 14:02:29 +0000</pubDate>
		<dc:creator>djpnuemo</dc:creator>
				<category><![CDATA[Malicious Domains]]></category>
		<category><![CDATA[Rogue Security Software]]></category>

		<guid isPermaLink="false">http://malwaredatabase.net/blog/?p=1956</guid>
		<description><![CDATA[Here is a fresh round of domains sent in to MDB linked to known malware distributors.  You can click on each domain name to view the whois info.  You can see more domains that were sent in in my previous post.
securebrowsingmode.com
internetbrowsersecurity.com
securing-your-browser.com
safe-browsing-network.com
bestringostarr.com
paul-mccartney-site.com
londonweekendtv.com
hawaiian-monarchy.com
countrymusicsrtists.com
2009-wimbledon.com
yorkshire-offroad-club.com
offroaddrivingcentres.com
fastvirusscan3.com
spywarefastscannerv6.com
antivirussecurescannerv3.com
antivirusbestscannerv5.com
manualspywareremoval.com
antivirusfolderscanv5.com
antivirusfolderscannerv5.com
antiviruspcscannerv7.com
antivirusscannerv9.com
antivirusforcomputrerv5.com
antimalwarecheckv6.com
antimalwareproscannerv9.com
antimalwareproscannerv8.com
antimalwarescanv4.com 78.47.172.69
antimalwarescanv7.com 83.133.126.155
dallastopnews.com
gulfbreakingnews.com
dailynatureandscience.com
australiandemocratsorg.com
you-will-be-fine.com
battle-for-europe.com
biofeedbackfoundation.com
bbcnewsstyleguide.com 78.47.91.155
whitelistbrowserpages.com
browserprivacytips.com
webbrowsersecuritysummary.com
securingyourwebbrowser.com 78.47.91.155
web-browser-security.com
securitybugfixserverv9.com
securitybugfixupdatev4.com
securitybugfixserverv1.com
securitybugfixupdate.com
update-my-software.com
latestupdateserver.com
recentupdatesserver.com
]]></description>
			<content:encoded><![CDATA[<p>Here is a fresh round of domains sent in to MDB linked to known malware distributors.  You can click on each domain name to view the whois info.  You can see more domains that were sent in in <a href="http://malwaredatabase.net/blog/index.php/2009/06/30/new-rogue-domains-associated-with-known-malware-distributors/" target="_blank">my previous post</a>.</p>
<p><a href="http://whois.sc/securebrowsingmode.com" target="_blank">securebrowsingmode.com</a><br />
<a href="http://whois.sc/internetbrowsersecurity.com" target="_blank">internetbrowsersecurity.com</a><br />
<a href="http://whois.sc/securing-your-browser.com" target="_blank">securing-your-browser.com</a><br />
<a href="http://whois.sc/safe-browsing-network.com" target="_blank">safe-browsing-network.com</a><br />
<a href="http://whois.sc/bestringostarr.com" target="_blank">bestringostarr.com</a><br />
<a href="http://whois.sc/paul-mccartney-site.com" target="_blank">paul-mccartney-site.com</a><br />
<a href="http://whois.sc/londonweekendtv.com" target="_blank">londonweekendtv.com</a><br />
<a href="http://whois.sc/hawaiian-monarchy.com" target="_blank">hawaiian-monarchy.com</a><br />
<a href="http://whois.sc/countrymusicsrtists.com" target="_blank">countrymusicsrtists.com</a><br />
<a href="http://whois.sc/2009-wimbledon.com" target="_blank">2009-wimbledon.com</a><br />
<a href="http://whois.sc/yorkshire-offroad-club.com" target="_blank">yorkshire-offroad-club.com</a><br />
<a href="http://whois.sc/offroaddrivingcentres.com" target="_blank">offroaddrivingcentres.com</a><br />
<a href="http://whois.sc/fastvirusscan3.com" target="_blank">fastvirusscan3.com</a><br />
<a href="http://whois.sc/spywarefastscannerv6.com" target="_blank">spywarefastscannerv6.com</a><br />
<a href="http://whois.sc/antivirussecurescannerv3.com" target="_blank">antivirussecurescannerv3.com</a><br />
<a href="http://whois.sc/antivirusbestscannerv5.com" target="_blank">antivirusbestscannerv5.com</a><br />
<a href="http://whois.sc/manualspywareremoval.com" target="_blank">manualspywareremoval.com</a><br />
<a href="http://whois.sc/antivirusfolderscanv5.com" target="_blank">antivirusfolderscanv5.com</a><br />
<a href="http://whois.sc/antivirusfolderscannerv5.com" target="_blank">antivirusfolderscannerv5.com</a><br />
<a href="http://whois.sc/antiviruspcscannerv7.com" target="_blank">antiviruspcscannerv7.com</a><br />
<a href="http://whois.sc/antivirusscannerv9.com" target="_blank">antivirusscannerv9.com</a><br />
<a href="http://whois.sc/antivirusforcomputrerv5.com" target="_blank">antivirusforcomputrerv5.com</a><br />
<a href="http://whois.sc/antimalwarecheckv6.com" target="_blank">antimalwarecheckv6.com</a><br />
<a href="http://whois.sc/antimalwareproscannerv9.com" target="_blank">antimalwareproscannerv9.com</a><br />
<a href="http://whois.sc/antimalwareproscannerv8.com" target="_blank">antimalwareproscannerv8.com</a><br />
<a href="http://whois.sc/antimalwarescanv4.com" target="_blank">antimalwarescanv4.com</a> 78.47.172.69<br />
<a href="http://whois.sc/antimalwarescanv7.com" target="_blank">antimalwarescanv7.com</a> 83.133.126.155<br />
<a href="http://whois.sc/dallastopnews.com" target="_blank">dallastopnews.com</a><br />
<a href="http://whois.sc/gulfbreakingnews.com" target="_blank">gulfbreakingnews.com</a><br />
<a href="http://whois.sc/dailynatureandscience.com" target="_blank">dailynatureandscience.com</a><br />
<a href="http://whois.sc/australiandemocratsorg.com" target="_blank">australiandemocratsorg.com</a><br />
<a href="http://whois.sc/you-will-be-fine.com" target="_blank">you-will-be-fine.com</a><br />
<a href="http://whois.sc/battle-for-europe.com" target="_blank">battle-for-europe.com</a><br />
<a href="http://whois.sc/biofeedbackfoundation.com" target="_blank">biofeedbackfoundation.com</a><br />
<a href="http://whois.sc/bbcnewsstyleguide.com" target="_blank">bbcnewsstyleguide.com</a> 78.47.91.155<br />
<a href="http://whois.sc/whitelistbrowserpages.com" target="_blank">whitelistbrowserpages.com</a><br />
<a href="http://whois.sc/browserprivacytips.com" target="_blank">browserprivacytips.com</a><br />
<a href="http://whois.sc/webbrowsersecuritysummary.com" target="_blank">webbrowsersecuritysummary.com</a><br />
<a href="http://whois.sc/securingyourwebbrowser.com" target="_blank">securingyourwebbrowser.com</a> 78.47.91.155<br />
<a href="http://whois.sc/web-browser-security.com" target="_blank">web-browser-security.com</a><br />
<a href="http://whois.sc/securitybugfixserverv9.com" target="_blank">securitybugfixserverv9.com</a><br />
<a href="http://whois.sc/securitybugfixupdatev4.com" target="_blank">securitybugfixupdatev4.com</a><br />
<a href="http://whois.sc/securitybugfixserverv1.com" target="_blank">securitybugfixserverv1.com</a><br />
<a href="http://whois.sc/securitybugfixupdate.com" target="_blank">securitybugfixupdate.com</a><br />
<a href="http://whois.sc/update-my-software.com" target="_blank">update-my-software.com</a><br />
<a href="http://whois.sc/latestupdateserver.com" target="_blank">latestupdateserver.com</a><br />
<a href="http://whois.sc/recentupdatesserver.com" target="_blank">recentupdatesserver.com</a></p>
]]></content:encoded>
			<wfw:commentRss>http://malwaredatabase.net/blog/index.php/2009/07/08/new-rogue-domains-associated-with-known-malware-distributors-pt-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
