# # this list of ponmocup malware redirection domains and infected web-servers is maintained by # email: toms.security.stuff -at- gmail.com # twitter: @c_APT_ure # blog: http://c-apt-ure.blogspot.com/ # # for use with CIF see malware-feeds here: # http://security-research.dyndns.org/pub/malware-feeds/ # date started: Thu Nov 2 00:00:01 PDT 2017 checking domain: www.jacquestrifin.be --> seems to be INFECTED: http://golfforkids.assistlist.com/fpc.pl --> DNS: golfforkids.assistlist.com (golfforkids.assistlist.com) / 31.210.96.158 checking domain: upetterbeek.be --> seems to be INFECTED: http://seelback.tfgjustsayin.net/delivery/lg.php --> DNS: seelback.tfgjustsayin.net (seelback.tfgjustsayin.net) / 31.210.96.157 checking domain: www.supportedholidaysantequera.co.uk --> seems to be INFECTED: http://shahree.azdiscus.com/url --> DNS: shahree.azdiscus.com (shahree.azdiscus.com) / 141.8.224.93 checking domain: www.ilmatrimoniocivile.it --> seems to be INFECTED: http://yoheezy.devilwithacause.com/t.gif --> DNS: yoheezy.devilwithacause.com (yoheezy.devilwithacause.com) / 31.210.96.155 checking domain: abus-spirituel.org --> seems to be INFECTED: http://transforminator.juddnelsonstudio.com/pview --> DNS: transforminator.juddnelsonstudio.com (transforminator.juddnelsonstudio.com) / failed: Name or service not known. checking domain: www.dynasun.com --> seems to be INFECTED: http://thousandmilitary.com/cgi-bin/r.cgi --> DNS: thousandmilitary.com (thousandmilitary.com) / 185.53.178.8 checking domain: www.agliran.co.il --> seems to be INFECTED: http://mercysiste.vehicleservicediscount.com/pview --> DNS: mercysiste.vehicleservicediscount.com (mercysiste.vehicleservicediscount.com) / 31.210.96.157 checking domain: www.aca-uccle.be --> seems to be INFECTED: http://omonkhegbele.wenerdhard.com/delivery/lg.php --> DNS: omonkhegbele.wenerdhard.com (omonkhegbele.wenerdhard.com) / 31.210.96.155 checking domain: www.upetterbeek.be --> seems to be INFECTED: http://seelback.tfgjustsayin.net/avatar/b8805389ee4391c3f8f9b91ce3cf11b9 --> DNS: seelback.tfgjustsayin.net (seelback.tfgjustsayin.net) / 31.210.96.157 checking domain: www.trikalasport.gr --> seems to be INFECTED: http://siene.webrunchhard.com/imgres --> DNS: siene.webrunchhard.com (siene.webrunchhard.com) / failed: Name or service not known. checking domain: 1980622.com --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 103.224.182.249 checking domain: afag.com.br --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 103.224.182.245 checking domain: agirazul.com.br --> seems to be INFECTED: http://lewisentitled.com/cgi-bin/r.cgi --> DNS: lewisentitled.com (lewisentitled.com) / 69.64.147.243 checking domain: agroservis.rs --> seems to be INFECTED: http://voictoall.com/cgi-bin/r.cgi --> DNS: voictoall.com (voictoall.com) / 5.39.99.49 checking domain: avionhome.com.tw --> seems to be INFECTED: http://intronetech.com/cgi-bin/r.cgi --> DNS: intronetech.com (intronetech.com) / 162.210.196.168 checking domain: avkolik.net --> seems to be INFECTED: http://shijothomas.softmn.com/openx/www/delivery/spc.php --> DNS: shijothomas.softmn.com (shijothomas.softmn.com) / failed: Name or service not known. checking domain: beakable.com --> seems to be INFECTED: http://zhylyanova.mygaycrush.com/b --> DNS: zhylyanova.mygaycrush.com (zhylyanova.mygaycrush.com) / failed: Name or service not known. checking domain: blackcanyoncoffee.com --> seems to be INFECTED: http://mudras.jordandowney.net/__utm.gif --> DNS: mudras.jordandowney.net (mudras.jordandowney.net) / failed: Name or service not known. checking domain: blog.autourdeminuit.com --> seems to be INFECTED: http://trackallnet.com/cgi-bin/r.cgi --> DNS: trackallnet.com (trackallnet.com) / 81.171.22.7 checking domain: bluewingz.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.211.165, 208.73.210.202, 208.73.210.217, / checking domain: businessbythespirit.com --> seems to be INFECTED: http://everybodynames.org/cgi-bin/r.cgi --> DNS: everybodynames.org (everybodynames.org) / 103.224.182.241 checking domain: cbm.esp.br --> seems to be INFECTED: http://nalaras.farremuebles.com/b/ss/hphqglobal,hpcsecglobal,hphqna,hphqnahpshopping,hpcsecamsushhos/1/H.24.3/s81763155704102 --> DNS: nalaras.farremuebles.com (nalaras.farremuebles.com) / 81.92.219.62 checking domain: cdcookingbook.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 98.124.245.24 checking domain: demo.crg-sa.com --> seems to be INFECTED: http://sslabssys.com/cgi-bin/r.cgi --> DNS: sslabssys.com (sslabssys.com) / 158.69.145.48 checking domain: dialolinks.de --> seems to be INFECTED: http://hartrup.kemperfitness.com/b/ss/cnetasiacom2011/1/H.22.1/s32979342980492 --> DNS: hartrup.kemperfitness.com (hartrup.kemperfitness.com) / 173.239.8.164, 213.247.47.190, 173.239.5.6 checking domain: diningcity.net --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 185.53.178.9 checking domain: d-math1.com --> seems to be INFECTED: http://renolla.golfnewsnewyork.com/delivery/lg.php --> DNS: renolla.golfnewsnewyork.com (renolla.golfnewsnewyork.com) / 51.254.28.160 checking domain: duikeninzutphen.nl --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / 103.224.182.241 checking domain: eniaktesting.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 98.124.245.24 checking domain: equestrianinfluence.com --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 72.52.4.122 checking domain: espn-la.com --> seems to be INFECTED: http://guillaran.newcarsat.com/new2/www/delivery/lg.php --> DNS: guillaran.newcarsat.com (guillaran.newcarsat.com) / 31.210.96.157 checking domain: exclusivesms.com --> seems to be INFECTED: http://ifteiha.lions-mark.com/__utm.gif --> DNS: ifteiha.lions-mark.com (ifteiha.lions-mark.com) / 204.11.56.48 checking domain: ezkahuda.cz --> seems to be INFECTED: http://costslaid.com/cgi-bin/r.cgi --> DNS: costslaid.com (costslaid.com) / 185.53.179.6 checking domain: famedomain.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.210.202, 208.73.211.165, 208.73.210.217, / checking domain: forum.auto.am --> seems to be INFECTED: http://witchwyd.bestsilvercufflinks.com/delivery/lg.php --> DNS: witchwyd.bestsilvercufflinks.com (witchwyd.bestsilvercufflinks.com) / 31.210.96.156 checking domain: harlawacademy.org --> seems to be INFECTED: http://teethalong.org/cgi-bin/r.cgi --> DNS: teethalong.org (teethalong.org) / 158.69.143.113 checking domain: intermundos.org --> seems to be INFECTED: http://poumtas.effectsllc.com/www/delivery/lg.php --> DNS: poumtas.effectsllc.com (poumtas.effectsllc.com) / 31.210.96.158 checking domain: janeece.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 185.53.179.7 checking domain: jornalsodesporto.com --> seems to be INFECTED: http://yononz.totalslipsolutions.net/url --> DNS: yononz.totalslipsolutions.net (yononz.totalslipsolutions.net) / 178.211.33.205 checking domain: jornalvakio.com --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 72.52.4.122 checking domain: karavelle.com.br --> seems to be INFECTED: http://britts.oharvest.net/b --> DNS: britts.oharvest.net (britts.oharvest.net) / 31.210.96.156 checking domain: kw-dl.com --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 103.224.182.249 checking domain: leandromauricio.com --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 103.224.182.249 checking domain: lesmanguiers.com --> seems to be INFECTED: http://jernighan.sullivan-county.com/b/ss/jobsdb-prd-id/1/H.23.6/s93187398763191 --> DNS: jernighan.sullivan-county.com (jernighan.sullivan-county.com) / failed: Name or service not known. checking domain: levantdistribution.com --> seems to be INFECTED: http://herocopter.com/cgi-bin/r.cgi --> DNS: herocopter.com (herocopter.com) / 185.53.179.6 checking domain: matzlpage.de --> seems to be INFECTED: http://forhed.dealerholidayevent.com/b/ss/avgfreepublicww/1/H.17/s57541987974985 --> DNS: forhed.dealerholidayevent.com (forhed.dealerholidayevent.com) / 31.210.96.157 checking domain: mile2000.com --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 91.195.241.72 checking domain: mvrccc.com.au --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 185.53.179.7 checking domain: myexfuzeoffice.com --> seems to be INFECTED: http://batilekaleka.laallstars.com/url --> DNS: batilekaleka.laallstars.com (batilekaleka.laallstars.com) / 178.211.33.205 checking domain: nancyhudsonassociates.com --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / 103.224.182.241 checking domain: nitpl.com --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 209.99.64.43 checking domain: northbatonrougejournal.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 98.124.245.24 checking domain: ofarroupilha.com.br --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 91.195.241.72 checking domain: perca.pl --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 103.224.182.249 checking domain: php2.twinner.com.tw --> seems to be INFECTED: http://45234.flatblastard.com/url --> DNS: 45234.flatblastard.com (45234.flatblastard.com) / 91.207.4.51 checking domain: phuongdanhvonghe.edu.vn --> seems to be INFECTED: http://everybodynames.org/cgi-bin/r.cgi --> DNS: everybodynames.org (everybodynames.org) / 103.224.182.241 checking domain: pileus.fr --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 98.124.245.24 checking domain: pmmilrec.com --> seems to be INFECTED: http://elinah.midnightastronomy.com/imghover --> DNS: elinah.midnightastronomy.com (elinah.midnightastronomy.com) / 31.210.96.155 checking domain: pntc.ac.th --> seems to be INFECTED: http://twowayserf.com/cgi-bin/r.cgi --> DNS: twowayserf.com (twowayserf.com) / 199.59.242.150 checking domain: police.moraga.ca.us --> seems to be INFECTED: http://clubshop.boeckman.net/pview --> DNS: clubshop.boeckman.net (clubshop.boeckman.net) / 31.210.96.158 checking domain: porntamil.com --> seems to be INFECTED: http://germanattention.org/cgi-bin/r.cgi --> DNS: germanattention.org (germanattention.org) / 68.178.213.61 checking domain: quantica.cl --> seems to be INFECTED: http://gamecomes.org/cgi-bin/r.cgi --> DNS: gamecomes.org (gamecomes.org) / 141.8.224.93 checking domain: radiogurbeti.com --> seems to be INFECTED: http://sonagara.slyforkfarm.com/s --> DNS: sonagara.slyforkfarm.com (sonagara.slyforkfarm.com) / 54.217.222.113 checking domain: reimagery.com --> seems to be INFECTED: http://stiepcic.z-sat.com/b --> DNS: stiepcic.z-sat.com (stiepcic.z-sat.com) / 31.210.96.158 checking domain: rose.kuro-tejina.com --> seems to be INFECTED: http://intronetech.com/cgi-bin/r.cgi --> DNS: intronetech.com (intronetech.com) / 162.210.196.168 checking domain: saobacdau.com.vn --> seems to be INFECTED: http://underbuild.net/cgi-bin/r.cgi --> DNS: underbuild.net (underbuild.net) / 149.202.120.33 checking domain: sseo.elk.pl --> seems to be INFECTED: http://gensapa.valentinesalesevent.com/_xhr/ugccomments/ --> DNS: gensapa.valentinesalesevent.com (gensapa.valentinesalesevent.com) / 31.210.96.156 checking domain: stillcatholic.com --> seems to be INFECTED: http://zahasky.greatserviceforless.com/bbc/bbc/s --> DNS: zahasky.greatserviceforless.com (zahasky.greatserviceforless.com) / 31.210.96.157 checking domain: stw-eu.com --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 209.99.64.43 checking domain: syrena.gminanekla.pl --> seems to be INFECTED: http://apartliberal.com/cgi-bin/r.cgi --> DNS: apartliberal.com (apartliberal.com) / 103.224.182.241 checking domain: theflightattendantlife.com --> seems to be INFECTED: http://skagger.automotiveservicesavings.com/_xhr/ugccomments/ --> DNS: skagger.automotiveservicesavings.com (skagger.automotiveservicesavings.com) / 31.210.96.157 checking domain: upunder.com --> seems to be INFECTED: http://everybodynames.org/cgi-bin/r.cgi --> DNS: everybodynames.org (everybodynames.org) / 103.224.182.241 checking domain: watchourvideo.net --> seems to be INFECTED: http://formedtouch.com/cgi-bin/r.cgi --> DNS: formedtouch.com (formedtouch.com) / 103.224.182.241 checking domain: wbu.wroc.pl --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 103.224.182.245 checking domain: wodzirejka.com.pl --> seems to be INFECTED: http://formedtouch.com/cgi-bin/r.cgi --> DNS: formedtouch.com (formedtouch.com) / 103.224.182.241 checking domain: workandlifebalance.eu --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 91.195.241.72 checking domain: workpanel.de --> seems to be INFECTED: http://creighton.wenerdhard.com/t.gif --> DNS: creighton.wenerdhard.com (creighton.wenerdhard.com) / 31.210.96.155 checking domain: www.actiogen.com --> seems to be INFECTED: http://teethalong.org/cgi-bin/r.cgi --> DNS: teethalong.org (teethalong.org) / 158.69.143.113 checking domain: www.aguadarocha.com.br --> seems to be INFECTED: http://costslaid.com/cgi-bin/r.cgi --> DNS: costslaid.com (costslaid.com) / 185.53.179.6 checking domain: www.alhassanain.com --> seems to be INFECTED: http://travelmeant.net/cgi-bin/r.cgi --> DNS: travelmeant.net (travelmeant.net) / 103.224.182.245 checking domain: www.alnimrexpo.com --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 98.124.245.24 checking domain: www.apmc.com.hk --> seems to be INFECTED: http://capitalinformer.com/cgi-bin/r.cgi --> DNS: capitalinformer.com (capitalinformer.com) / 72.52.4.122 checking domain: www.aspi.ag --> seems to be INFECTED: http://umxamzah.mrsstyleseeker.com/__utm.gif --> DNS: umxamzah.mrsstyleseeker.com (umxamzah.mrsstyleseeker.com) / 31.210.96.157 checking domain: www.bharatinfoline.com --> seems to be INFECTED: http://lesbon.ksupridewrestling.com/servlet/ajrotator/126371/0/vj --> DNS: lesbon.ksupridewrestling.com (lesbon.ksupridewrestling.com) / 213.247.47.190, 173.239.5.6, 173.239.8.164 checking domain: www.bienenmilch.com --> seems to be INFECTED: http://jonestown.serenehomeandlandscapes.com/imghover --> DNS: jonestown.serenehomeandlandscapes.com (jonestown.serenehomeandlandscapes.com) / failed: Name or service not known. checking domain: www.bobthebugman.com --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 209.99.64.43 checking domain: www.bodasexclusivas.com --> seems to be INFECTED: http://compass.automotiveeventregistration.com/__utm.gif --> DNS: compass.automotiveeventregistration.com (compass.automotiveeventregistration.com) / 31.210.96.157 checking domain: www.carlosmeschini.com.br --> seems to be INFECTED: http://fulpagar.tropicaltoner.com/_adserver_new/www/delivery/lg.php --> DNS: fulpagar.tropicaltoner.com (fulpagar.tropicaltoner.com) / 31.210.96.158 checking domain: www.carlosvuam.com --> seems to be INFECTED: http://lewisentitled.com/cgi-bin/r.cgi --> DNS: lewisentitled.com (lewisentitled.com) / 69.64.147.243 checking domain: www.choice.md --> seems to be INFECTED: http://rangihaeata.hurricanesandylegaladvice.com/js_flat_1_0/ --> DNS: rangihaeata.hurricanesandylegaladvice.com (rangihaeata.hurricanesandylegaladvice.com) / failed: Name or service not known. checking domain: www.ciren.net --> seems to be INFECTED: http://treescha.automotiveservicesavings.com/t.gif --> DNS: treescha.automotiveservicesavings.com (treescha.automotiveservicesavings.com) / 31.210.96.157 checking domain: www.comune.santa-maria-capua-vetere.ce.it --> seems to be INFECTED: http://gesneriaceae.telecomillinois.com/__utm.gif --> DNS: gesneriaceae.telecomillinois.com (gesneriaceae.telecomillinois.com) / 31.210.96.155 checking domain: www.creativ-art1.com --> seems to be INFECTED: http://vermillon.serenehomeandlandscapes.com/spc.php --> DNS: vermillon.serenehomeandlandscapes.com (vermillon.serenehomeandlandscapes.com) / failed: Name or service not known. checking domain: www.dallascustomfurniture.com --> seems to be INFECTED: http://bonusforall.net/cgi-bin/r.cgi --> DNS: bonusforall.net (bonusforall.net) / failed: Name or service not known. checking domain: www.doctorhelp.de --> seems to be INFECTED: http://switchett.virtualsofts.com/event.js --> DNS: switchett.virtualsofts.com (switchett.virtualsofts.com) / 173.239.5.6, 173.239.8.164, 213.247.47.190 checking domain: www.dreamboxturk.com --> seems to be INFECTED: http://baylet.autoeventregistration.com/api/getCount2.php --> DNS: baylet.autoeventregistration.com (baylet.autoeventregistration.com) / 31.210.96.157 checking domain: www.dulceselsombreron.com --> seems to be INFECTED: http://thousandmilitary.com/cgi-bin/r.cgi --> DNS: thousandmilitary.com (thousandmilitary.com) / 185.53.178.8 checking domain: www.ejmii.com --> seems to be INFECTED: http://mahaphontrakoon.vehicleservicediscount.com/www/delivery/ajs.php --> DNS: mahaphontrakoon.vehicleservicediscount.com (mahaphontrakoon.vehicleservicediscount.com) / 31.210.96.157 checking domain: www.elsiedesigns.com --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 185.53.178.9 checking domain: www.enimex.gr --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 103.224.182.249 checking domain: www.farmasanmodababy.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.211.165, 208.73.211.177, 208.73.210.217, / checking domain: www.fatherlinh.com --> seems to be INFECTED: http://germanattention.org/cgi-bin/r.cgi --> DNS: germanattention.org (germanattention.org) / 68.178.213.61 checking domain: www.fishingtackleindia.com --> seems to be INFECTED: http://urladyms.newlogiq.com/__utm.gif --> DNS: urladyms.newlogiq.com (urladyms.newlogiq.com) / 31.210.96.155 checking domain: www.freesure.com.tr --> seems to be INFECTED: http://earlyanswered.com/cgi-bin/r.cgi --> DNS: earlyanswered.com (earlyanswered.com) / 141.8.224.93 checking domain: www.freilandschwein.info --> seems to be INFECTED: http://earlyanswered.com/cgi-bin/r.cgi --> DNS: earlyanswered.com (earlyanswered.com) / 141.8.224.93 checking domain: www.geoffwhite.ws --> seems to be INFECTED: http://trackallnet.com/cgi-bin/r.cgi --> DNS: trackallnet.com (trackallnet.com) / 162.210.196.166 checking domain: www.greenfieldadvisorsltd.com --> seems to be INFECTED: http://moutsiouna.iretarpg.com/t.gif --> DNS: moutsiouna.iretarpg.com (moutsiouna.iretarpg.com) / 185.53.178.7 checking domain: www.gswsftp01.com --> seems to be INFECTED: http://parallag.bmemkitchens.com/tracker --> DNS: parallag.bmemkitchens.com (parallag.bmemkitchens.com) / failed: Name or service not known. checking domain: www.highsport.se --> seems to be INFECTED: http://udomchum.telecommichigan.com/api/getCount2.php --> DNS: udomchum.telecommichigan.com (udomchum.telecommichigan.com) / 31.210.96.155 checking domain: www.holidayinn-mulhouse.com --> seems to be INFECTED: http://hunton.valentinesalesevent.com/t.gif --> DNS: hunton.valentinesalesevent.com (hunton.valentinesalesevent.com) / 31.210.96.156 checking domain: www.hostal3soles.com --> seems to be INFECTED: http://besidesdream.com/cgi-bin/r.cgi --> DNS: besidesdream.com (besidesdream.com) / 52.4.209.250 checking domain: www.hostpix.de --> seems to be INFECTED: http://xlau.kalkanturqouise.com/dcsis0ifv10000gg3ag82u4rf_7b1e/dcs.gif --> DNS: xlau.kalkanturqouise.com (xlau.kalkanturqouise.com) / failed: Connection timed out. checking domain: www.ijerd.com --> seems to be INFECTED: http://verzeroli.outbreakm3dia.com/__utm.gif --> DNS: verzeroli.outbreakm3dia.com (verzeroli.outbreakm3dia.com) / 199.115.116.216 checking domain: www.jalba.gr --> seems to be INFECTED: http://watchingsquare.com/cgi-bin/r.cgi --> DNS: watchingsquare.com (watchingsquare.com) / 185.53.178.9 checking domain: www.jornalfarroupilha.com.br --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 91.195.241.72 checking domain: www.jtcomms.com --> seems to be INFECTED: http://solichana.telecommichigan.com/safe_image.php --> DNS: solichana.telecommichigan.com (solichana.telecommichigan.com) / 31.210.96.155 checking domain: www.karavelle.com.br --> seems to be INFECTED: http://britts.oharvest.net/b --> DNS: britts.oharvest.net (britts.oharvest.net) / 31.210.96.156 checking domain: www.klanglos-studio.de --> seems to be INFECTED: http://camplong.barbeveragesnv.com/ps/ifr --> DNS: camplong.barbeveragesnv.com (camplong.barbeveragesnv.com) / failed: Name or service not known. checking domain: www.kyalasushi.com --> seems to be INFECTED: http://vesman.autoserviceevent.com/js_flat_1_0/ --> DNS: vesman.autoserviceevent.com (vesman.autoserviceevent.com) / 31.210.96.157 checking domain: www.lipika.com --> seems to be INFECTED: http://malamut.revolverindy.com/api/getCount2.php --> DNS: malamut.revolverindy.com (malamut.revolverindy.com) / 67.227.226.240 checking domain: www.little-moon-aussies.com --> seems to be INFECTED: http://jahren.prestigehonda.net/new/www/delivery/ajs.php --> DNS: jahren.prestigehonda.net (jahren.prestigehonda.net) / 31.210.96.157 checking domain: www.livre-etre-bien.com --> seems to be INFECTED: http://nedou.kidstryingtopayforcollege.com/ttj --> DNS: nedou.kidstryingtopayforcollege.com (nedou.kidstryingtopayforcollege.com) / 81.92.219.61 checking domain: www.loxsavvy.com.au --> seems to be INFECTED: http://trialworld.net/cgi-bin/r.cgi --> DNS: trialworld.net (trialworld.net) / 103.224.182.241 checking domain: www.maquinaslitograficas.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.211.177, 208.73.210.217, 208.73.211.165, / checking domain: www.mazus-art.com --> seems to be INFECTED: http://allintercom.net/cgi-bin/r.cgi --> DNS: allintercom.net (allintercom.net) / 185.53.178.9 checking domain: www.microforme.com --> seems to be INFECTED: http://suryoko.hitodeki.com/__utm.gif --> DNS: suryoko.hitodeki.com (suryoko.hitodeki.com) / failed: Name or service not known. checking domain: www.miniaturesupplier.com --> seems to be INFECTED: http://koumparou.mwhiteman.com/www/app_full_proxy.php --> DNS: koumparou.mwhiteman.com (koumparou.mwhiteman.com) / failed: Name or service not known. checking domain: www.mitsuadvclub.net --> seems to be INFECTED: http://loardy.exquisiteclasscenter.com/url --> DNS: loardy.exquisiteclasscenter.com (loardy.exquisiteclasscenter.com) / 178.211.33.203 checking domain: www.monah.us --> seems to be INFECTED: http://kukuljac.basslakeshagclub.com/mostra.jsp --> DNS: kukuljac.basslakeshagclub.com (kukuljac.basslakeshagclub.com) / 31.210.96.158 checking domain: www.movingtransfer.com --> seems to be INFECTED: http://taiugac.vehicleservicediscount.com/__utm.gif --> DNS: taiugac.vehicleservicediscount.com (taiugac.vehicleservicediscount.com) / 31.210.96.157 checking domain: www.msm.mc --> seems to be INFECTED: http://poserio.thecaregrouppc.net/delivery/lg.php --> DNS: poserio.thecaregrouppc.net (poserio.thecaregrouppc.net) / 185.53.178.6 checking domain: www.mywoom.com --> seems to be INFECTED: http://virtualmapping.org/cgi-bin/r.cgi --> DNS: virtualmapping.org (virtualmapping.org) / 185.53.179.7 checking domain: www.neonconcursos.com.br --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 209.99.64.43 checking domain: www.newsflash.org --> seems to be INFECTED: http://srse.techsupportauction.com/1pix.gif --> DNS: srse.techsupportauction.com (srse.techsupportauction.com) / failed: Name or service not known. checking domain: www.nwd-ly.com --> seems to be INFECTED: http://metromanias.com/cgi-bin/r.cgi --> DNS: metromanias.com (metromanias.com) / 208.73.210.202, 208.73.211.165, 208.73.210.217, / checking domain: www.oo5.com --> seems to be INFECTED: http://uglyugly.savedalyfield.com/s --> DNS: uglyugly.savedalyfield.com (uglyugly.savedalyfield.com) / 167.114.156.214 checking domain: www.pfotenranch.de --> seems to be INFECTED: http://zaquitsha.vetsingreensboro.com/delivery/lg.php --> DNS: zaquitsha.vetsingreensboro.com (zaquitsha.vetsingreensboro.com) / 185.53.178.7 checking domain: www.radiogurbeti.com --> seems to be INFECTED: http://sonagara.slyforkfarm.com/b/ss/jobsdb-prd-id/1/H.23.6/s21023602889073 --> DNS: sonagara.slyforkfarm.com (sonagara.slyforkfarm.com) / 54.217.222.113 checking domain: www.recrutam.ro --> seems to be INFECTED: http://dambalang.vehicleexchangeprogram.com/__utm.gif --> DNS: dambalang.vehicleexchangeprogram.com (dambalang.vehicleexchangeprogram.com) / 31.210.96.157 checking domain: www.retrosheet.org --> seems to be INFECTED: http://trafficsources.org/cgi-bin/r.cgi --> DNS: trafficsources.org (trafficsources.org) / 103.224.182.249 checking domain: www.rgjassociation.info --> seems to be INFECTED: http://weedx.fubarpaintball.com/re_/ping --> DNS: weedx.fubarpaintball.com (weedx.fubarpaintball.com) / 31.210.96.156 checking domain: www.rich.co.ke --> seems to be INFECTED: http://andritsos.newyorkjester.com/b --> DNS: andritsos.newyorkjester.com (andritsos.newyorkjester.com) / failed: Name or service not known. checking domain: www.rollershop.de --> seems to be INFECTED: http://yinpou.aredietsok.com/__utm.gif --> DNS: yinpou.aredietsok.com (yinpou.aredietsok.com) / 31.210.96.158 checking domain: www.santuariodalapa.pt --> seems to be INFECTED: http://tixon.theafternoonjoker.com/api/getCount2.php --> DNS: tixon.theafternoonjoker.com (tixon.theafternoonjoker.com) / 31.210.96.158 checking domain: www.sculpture1940.com --> seems to be INFECTED: http://pizzaexperience.internet1495.com/avatar/1157a9858c2bccc90dc7f8610956ee4c --> DNS: pizzaexperience.internet1495.com (pizzaexperience.internet1495.com) / 178.211.33.203 checking domain: www.sdfbd.org --> seems to be INFECTED: http://handsexual.com/cgi-bin/r.cgi --> DNS: handsexual.com (handsexual.com) / 208.91.196.32 checking domain: www.siacgroup.com --> seems to be INFECTED: http://kahili.techsupportauction.com/b --> DNS: kahili.techsupportauction.com (kahili.techsupportauction.com) / failed: Name or service not known. checking domain: www.sri.cmu.ac.th --> seems to be INFECTED: http://twansha.yourcakedecoratingclass.com/__utm.gif --> DNS: twansha.yourcakedecoratingclass.com (twansha.yourcakedecoratingclass.com) / failed: Name or service not known. checking domain: www.successinteaching.info --> seems to be INFECTED: http://protechere.com/cgi-bin/r.cgi --> DNS: protechere.com (protechere.com) / 103.224.182.241 checking domain: www.televideoproductions.com --> seems to be INFECTED: http://interestingchapter.net/cgi-bin/r.cgi --> DNS: interestingchapter.net (interestingchapter.net) / 209.99.64.43 checking domain: www.therapiehyperbare.com --> seems to be INFECTED: http://tagipur.mrsstyleseeker.com/st --> DNS: tagipur.mrsstyleseeker.com (tagipur.mrsstyleseeker.com) / 31.210.96.157 checking domain: www.timelessimagesmi.com --> seems to be INFECTED: http://abusalewm.exceltoner.com/s --> DNS: abusalewm.exceltoner.com (abusalewm.exceltoner.com) / 31.210.96.158 checking domain: www.tintasluxor.com.br --> seems to be INFECTED: http://severalcamp.com/cgi-bin/r.cgi --> DNS: severalcamp.com (severalcamp.com) / 98.124.245.24 checking domain: www.tri-tex.net --> seems to be INFECTED: http://vicrant.newworldheroes.com/delivery/lg.php --> DNS: vicrant.newworldheroes.com (vicrant.newworldheroes.com) / 31.210.96.158 checking domain: www.tunefreak.org --> seems to be INFECTED: http://wawabeh.williamsfp.com/getSegment.php --> DNS: wawabeh.williamsfp.com (wawabeh.williamsfp.com) / failed: Name or service not known. checking domain: www.turbo-mixer.de --> seems to be INFECTED: http://schmakel.strongpsychic.com/fbml/ajax/uiserver.php --> DNS: schmakel.strongpsychic.com (schmakel.strongpsychic.com) / 31.210.96.155 checking domain: www.unitedmgtii.com --> seems to be INFECTED: http://petel.golfnewstennessee.com/__utm.gif --> DNS: petel.golfnewstennessee.com (petel.golfnewstennessee.com) / failed: Name or service not known. checking domain: www.vfbhermsdorf.de --> seems to be INFECTED: http://hinouchi.greatserviceforless.com/gadgets/ifr --> DNS: hinouchi.greatserviceforless.com (hinouchi.greatserviceforless.com) / 31.210.96.157 checking domain: www.vidvanern.se --> seems to be INFECTED: http://usnai.restoremystuff.com/dcs0junic89k7m2gzez6wz0k8_7v8n/dcs.gif --> DNS: usnai.restoremystuff.com (usnai.restoremystuff.com) / 31.210.96.156 checking domain: www.vitaminbude.de --> seems to be INFECTED: http://karepii.dealerholidayevent.com/_xhr/ugccomments/ --> DNS: karepii.dealerholidayevent.com (karepii.dealerholidayevent.com) / 31.210.96.157 checking domain: www.wallyontheweb.com --> seems to be INFECTED: http://ichinohe.casabodamia.com/api/getCount2.php --> DNS: ichinohe.casabodamia.com (ichinohe.casabodamia.com) / 81.171.22.7 checking domain: www.wcgconline.net --> seems to be INFECTED: http://keniisha.realdealpsychic.com/b/ss/natgeophoto,natgeoglobal/1/H.23.8/s32297229133495 --> DNS: keniisha.realdealpsychic.com (keniisha.realdealpsychic.com) / 31.210.96.155 checking domain: www.wmc.kylos.pl --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 91.195.241.72 checking domain: www.wonderwhistle.co.uk --> seems to be INFECTED: http://infernomag.com/cgi-bin/r.cgi --> DNS: infernomag.com (infernomag.com) / 91.195.241.72 checking domain: www.wordgod.com.tw --> seems to be INFECTED: http://sahmari.theafternoonjoker.com/_xhr/ugccomments/ --> DNS: sahmari.theafternoonjoker.com (sahmari.theafternoonjoker.com) / 31.210.96.158 checking domain: www.zoeblitzer-natursteine.de --> seems to be INFECTED: http://besidesdream.com/cgi-bin/r.cgi --> DNS: besidesdream.com (besidesdream.com) / 52.4.209.250 checking domain: zarov.com.br --> seems to be INFECTED: http://upanesh.kemperfitness.com/url --> DNS: upanesh.kemperfitness.com (upanesh.kemperfitness.com) / 173.239.5.6, 173.239.8.164, 213.247.47.190 date finished: Thu Nov 2 00:34:52 PDT 2017