A Partial List of Some Malware Emailed to My Server Since 12-Feb-1999
VIRUS NAME  IP ADDRESS of EMail Origin  City of Origin EMail  DATE Received  TIME Received 
Unknown Harddrive Virus  Unknown  Unknown  12Feb1999  Lost ~3GBytes of Data 
W32/SirCam@MM  63.167.32.129  Honolulu, Hawaii  2Aug2001  06:18:37 HST 
W32/SirCam@MM  212.47.208.17  Tallinn, Estonia  2Aug2001  21:07:09 CST 
W32/SirCam@MM  65.8.167.59  Lexington, Kentucky  2Aug2001  18:23:12 CST 
W32/SirCam@MM  63.167.32.124  Honolulu, Hawaii  3Aug2001  04:34:26 HST 
W32/Aliz.eml  212.47.208.17  Tallinn, Estonia  21Nov2001  15:59:27 (+2hr) 
W32/Klez.eml  65.201.244.138  Chicago, Illinois  23Jul2002  16:35:33 (-5hr) 
W32/Klez.eml  65.201.244.138  Chicago, Illinois  24Jul2002  07:28:53 (-5hr) 
Not yet listed in DAT's  203.145.27.140  Bangkok, Thailand  25Jul2002  16:33:21 (+8hr) 
Not yet listed in DAT's  66.44.17.49  Washington, DC  2Oct2002  19:14:19 (-4hr) 
W32/Klez.eml  68.118.253.80  Ludlow, Massachusetts  23Jan2003  12:17:24 (-5hr) 
Not yet listed in DAT's  63.211.82.43  Newark, New Jersey  20Aug2003  07:29:08 PDT 
Not yet listed in DAT's  219.138.188.13  Milton, Australia  21Aug2003  12:03:29 PDT 
W32/Klez.eml  202.152.46.134  Denpasar, Indonesia  30Oct2003  08:42:07 (+7hr) 
W32/Swen@MM  spoofed IP  SE Asia (?)  30Oct2003  unknown time zone 
W32/Mimail.i@MM  68.115.235.33  Abbeville, South Carolina  17Nov2003  16:41:02 CST 
W32/Mimail.i@MM  68.115.235.33  Abbeville, South Carolina  18Nov2003  09:03:24 CST 
W32/Mimail.i@MM  68.115.235.33  Abbeville, South Carolina  18Nov2003  15:29:58 CST 
W32/Mimail.i@MM  68.115.235.33  Abbeville, South Carolina  19Nov2003  17:20:44 CST 
W32/Mimail.i@MM  68.115.235.33  Abbeville, South Carolina  20Nov2003  18:59:02 CST 
W32/Mimail.i@MM  68.115.235.33  Abbeville, South Carolina  21Nov2003  15:19:24 CST 
W32/Mimail.i@MM  68.115.235.33  Abbeville, South Carolina  21Nov2003  19:29:48 CST 
W32/Mimail.i@MM  24.196.247.69  Simpsonville, South Carolina  22Nov2003  14:58:18 CST 
W32/Mimail.i@MM  24.196.247.69  Simpsonville, South Carolina  23Nov2003  10:37:03 CST 
W32/Mimail.i@MM  24.196.247.69  Simpsonville, South Carolina  23Nov2003  14:51:26 CST 
W32/Mimail.i@MM  24.196.247.69  Simpsonville, South Carolina  23Nov2003  17:51:51 CST 
W32/Mimail.i@MM  24.196.247.69  Simpsonville, South Carolina  24Nov2003  19:23:50 CST 
W32/Mimail.i@MM  24.196.247.69  Simpsonville, South Carolina  25Nov2003  12:45:59 CST 
W32/Mimail.i@MM  24.196.247.69  Simpsonville, South Carolina  26Nov2003  11:12:49 CST 
W32/Mimail.i@MM  24.196.247.130  Simpsonville, South Carolina  29Nov2003  11:31:47 CST 
W32/Mimail.i@MM  24.196.247.130  Simpsonville, South Carolina  29Nov2003  11:51:19 CST 
W32/Mimail.i@MM  24.196.247.130  Simpsonville, South Carolina  29Nov2003  13:27:07 CST 
W32/Mimail.i@MM  24.196.247.130  Simpsonville, South Carolina  30Nov2003  15:15:15 CST 
W32/Mimail.i@MM  24.196.247.130  Simpsonville, South Carolina  30Nov2003  15:16:40 CST 
W32/Mimail.i@MM  24.196.247.130  Simpsonville, South Carolina  1Dec2003  19:31:08 CST 
W32/Mimail.i@MM  24.196.247.130  Simpsonville, South Carolina  2Dec2003  13:54:07 CST 
W32/Mimail.i@MM  24.196.247.130  Simpsonville, South Carolina  2Dec2003  17:33:28 CST 
W32/Mimail.i@MM  24.196.247.130  Simpsonville, South Carolina  3Dec2003  12:32:08 CST 
W32/Mimail.i@MM  24.196.247.130  Simpsonville, South Carolina  3Dec2003  15:57:47 CST 
W32/Mimail.i@MM  66.191.166.114  Simpsonville, South Carolina  4Dec2003  17:57:08 CST 
W32/Mimail.i@MM  66.191.166.114  Simpsonville, South Carolina  6Dec2003  07:40:03 PST 
W32/Mimail.i@MM  66.191.166.114  Simpsonville, South Carolina  6Dec2003  08:05:57 PST 
W32/Mimail.i@MM  66.191.166.114  Simpsonville, South Carolina  7Dec2003  08:16:36 PST 
W32/Mimail.i@MM  66.191.166.114  Simpsonville, South Carolina  7Dec2003  12:10:14 PST 
W32/Mimail.i@MM  66.191.166.114  Simpsonville, South Carolina  7Dec2003  14:04:40 PST 
W32/Mimail.i@MM  66.191.166.114  Simpsonville, South Carolina  7Dec2003  15:22:09 PST 
W32/Mimail.i@MM  66.191.201.119  Greenville, South Carolina  8Dec2003  13:14:59 PST 
W32/Mimail.i@MM  66.191.201.119  Greenville, South Carolina  8Dec2003  14:48:25 PST 
W32/Mimail.i@MM  66.191.201.119  Greenville, South Carolina  9Dec2003  05:34:12 PST 
W32/Mimail.i@MM  66.191.201.119  Greenville, South Carolina  9Dec2003  17:56:23 PST 
W32/Mimail.i@MM  66.191.201.119  Greenville, South Carolina  9Dec2003  18:00:09 PST 
W32/Mimail.i@MM  66.191.201.119  Greenville, South Carolina  11Dec2003  18:28:40 PST 
W32/Mimail.i@MM  66.191.201.119  Greenville, South Carolina  11Dec2003  19:13:27 PST 
W32/Mimail.i@MM  66.191.201.119  Greenville, South Carolina  12Dec2003  14:51:26 PST 
W32/Mimail.i@MM  66.191.201.119  Greenville, South Carolina  12Dec2003  18:28:56 PST 
W32/Mimail.i@MM  66.191.201.119  Greenville, South Carolina  12Dec2003  21:40:58 PST 
W32/Mimail.i@MM  66.169.16.189  Greenville, South Carolina  14Dec2003  17:18:15 PST 
W32/Mimail.i@MM  66.169.16.189  Greenville, South Carolina  15Dec2003  15:16:06 PST 
W32/Mimail.i@MM  66.169.16.189  Greenville, South Carolina  15Dec2003  17:54:05 PST 
W32/Mimail.i@MM  66.169.16.189  Greenville, South Carolina  17Dec2003  10:01:08 PST 
W32.Mimail.M@mm  68.170.18.95  Liberal, Kansas  19Dec2003  07:46:55 PST 
W32.Novarg.A@mm  202.58.130.41  Papua, New Guinea  26Jan2004  22:15:54 PST 
W32.Novarg.A@mm  62.47.153.65  Vienna, Austria  27Jan2004  05:34:05 PST 
W32.Mydoom.A@mm  203.77.222.18  Taipei, Taiwan  6Feb2004  02:04:05 PST 
W32.Mydoom.A@mm  203.77.222.18  Taipei, Taiwan  9Feb2004  11:02:36 MET 
W32.Mydoom.A@mm.enc  203.82.54.37  Multan, Pakistan  10Feb2004  21:16:22 PST 
W32.Mydoom.A@mm.enc  unknown  Australia (?)  11Feb2004  10:16:32 PST 
W32.Mydoom.A@mm  12.166.41.196  Clarks Summit, Pennsylvania  11Feb2004  17:52:57 PST 
W32.Mydoom.A@mm  12.166.41.196  Clarks Summit, Pennsylvania  11Feb2004  20:56:12 PST 
W32.Mydoom.A@mm  12.166.41.196  Clarks Summit, Pennsylvania  11Feb2004  21:09:37 PST 
W32.Mydoom.A@mm  12.166.41.196  Clarks Summit, Pennsylvania  12Feb2004  05:51:07 MET 
W32.Mydoom.A@mm  12.166.41.196  Clarks Summit, Pennsylvania  12Feb2004  00:01:00 PST 
W32.Mydoom.A@mm  12.166.41.196  Clarks Summit, Pennsylvania  12Feb2004  15:06:36 PST 
W32.Netsky.B@mm  24.200.172.104  Ottawa, Canada  23Feb2004  06:31:26 PST 
W32.Netsky.B@mm  213.103.143.78  Schaffhausen, Switzerland  23Feb2004  08:57:43 PST 
W32.Netsky.B@mm  24.200.172.104  Ottawa, Canada  24Feb2004  06:28:03 PST 
w32/netsky.c@mm (not in DAT @ receipt)  208.0.114.27  Richmond, Virginia (MCV Hospitals)  25Feb2004  08:11:03 PST 
W32/Netsky.b@MM  81.6.20.77  Zug, Switzerland  9Mar2004  21:33:05 UTC 
W32/Netsky.C@MM  205.245.94.202  Richmond, Virginia  15Mar2004  13:50:56 EST 
W32/Netsky.D@mm  24.200.172.104  Ottawa, Canada  21Mar2004  09:13:09 PST 
W32/Netsky.D@mm  24.200.172.104  Ottawa, Canada  21Mar2004  12:14:16 EST 
W32/Netsky.q@MM (not in DAT @ receipt)  195.34.32.56  Moscow, Russia  25Mar2004  21:42:01 PST 
W32/Netsky.q@MM (not in DAT @ receipt)  192.220.127.147  Portland, Oregon 26Mar2004  04:08:21 PST 
W32/Netsky.D@mm  210.232.239.81  Osaka, Japan  14Apr2004  13:00:49 JST 
Virus Removed by ISP  24.200.172.104  Ottawa, Canada  15Apr2004  03:38:57 PDT 
Virus Removed by ISP  203.130.194.70  Malang, Indonesia  16Apr2004  02:52:04 PDT 
W32.Netsky.P@mm  202.154.33.3  Jakarta, Indonesia  16Apr2004  17:15:32 (+7hr) 
W32.Bugbear@mm  68.164.224.111  Chicago, Illinois  17Apr2004  20:30:10 (-04hr) 
W32/Netsky.d@MM 207.96.251.197  Quebec, Canada  18Apr2004  04:31:07 PDT 
W32.Beagle.gen (Symantec)  160.36.143.168 Knoxville, TN (UTK.EDU)  26Apr2004  11:13:22 PDT 
W32/Bagle.z@MM  160.36.143.168 Knoxville, TN (UTK.EDU)  26Apr2004  14:34:52 CDT 
W32.Beagle.X@mm  216.151.232.228  Manassas, Virginia  29Apr2004  06:35:14 PDT 
W32.Beagle.X@mm  216.151.232.228  Manassas, Virginia  29Apr2004  08:28:29 PDT 
W32.Beagle.X@mm  63.168.124.133  Pass Christian, Mississippi  29Apr2004  10:14:41 PDT 
W32/Netsky.g@MM  12.96.54.33  Houston, Texas  4May2004  16:42:16 PDT 
W32/Netsky.d@MM 24.201.105.89  Ottawa, Canada  7May2004  11:39:07 EDT 
W32.Beagle.K@mm  216.111.20.102  Knoxville, Tennessee  11May2004  13:48:26 PDT 
W32/Lovgate.ab@MM  12.96.54.33  Houston, Texas  19May2004  13:45:55 PDT 
Virus Removed by ISP  213.23.36.64  Hannover, Germany  31May2004  18:05:47 UTC 
W32.Beagle.X@mm  24.205.205.195  Sparks, Nevada  1Jun2004  20:56:02 PDT 
W32.Beagle.X@mm  24.205.205.195  Sparks, Nevada  1Jun2004  20:57:20 PDT 
Not yet listed in DAT's  63.238.179.181  Luebbering, Missouri  9June2004  22:14:44 PDT 
Worm/NetSky.P  217.184.96.39  Munich, Germany  11Jun2004  15:03:36 CEST 
W32/Netsky.j@MM  24.200.192.76  Ottawa, Canada  13Jun2004  13:56:00 (+0100) 
Virus Removed by ISP  80.140.244.46  Dusseldorf, Germany  17Jun2004  03:43:52 (NZST) 
I-Worm.NetSky.ac  202.158.19.4  Jakarta, Indonesia  24Jun2004  05:53:54 (-7hr) 
W32.Beagle.AC@mm  68.118.85.206  Kingsport, Tennessee  17Jul2004  14:36:53 PDT 
W32.Beagle.AC@mm  68.118.85.206  Kingsport, Tennessee  18Jul2004  12:28:46 PDT 
W32.Beagle.AC@mm  192.127.94.7  Dayton, Ohio  18Jul2004  22:46:53 PDT 
Exploit-MIME.gen.c  207.35.188.59  Toronto District School Board (Toronto, Canada)  20Jul2004  18:09:00 PDT 
Exploit-MIME.gen.c  207.35.188.59  Toronto District School Board (Toronto, Canada)  22Jul2004  15:21:25 PDT 
Exploit-MIME.gen.c  207.35.188.59  Toronto District School Board (Toronto, Canada)  24Jul2004  00:57:36 PDT 
W32.Beagle.AC@mm  68.118.85.206  Kingsport, Tennessee  25Jul2004  10:01:30 PDT 
W32.Beagle.AC@mm  68.118.85.206  Kingsport, Tennessee  25Jul2004  17:11:05 PDT 
Attachment Removed by ISP  63.238.179.181  Luebbering, Missouri  6Aug2004  18:12:34 PDT 
W32/Bagle.aq@MM  68.118.99.227  Morristown, Tennessee  9Aug2004  11:02:54 PDT 
Unknown Virus  81.247.13.176  Belgium  27Aug2004  04:22:28 (-4hr) 
W32.Netsky.Q@mm  (headers deleted by ISP)  (unknown)  3Sep2004  08:23:01 PDT 
W32.Netsky.Q@mm.enc  (headers deleted by ISP)  (unknown)  3Sep2004  13:05:34 PDT 
W32.Netsky.Q@mm  (headers deleted by ISP)  (unknown)  3Sep2004  21:56:40 PDT 
W32.Netsky.Q@mm.enc  (headers deleted by ISP)  (unknown)  8Sep2004  22:12:11 PDT 
W32.Lovgate.R@mm (55 Copies) 212.0.146.58 Khartoum, Sudan 9Sep2004 07:14:36-12:34:12 UTC
W32.Netsky.Q@mm.enc  (headers deleted by ISP)  (unknown)  9Sep2004  19:57:52 PDT 
W32.Netsky.B@mm  (headers deleted by ISP)  (unknown)  11Sep2004  18:46:47 (+7hr) 
W32.Netsky.K@mm (headers deleted by ISP) (unknown) 12Sep2004 13:11:14 PDT
W32.Lovgate.R@mm (72 Copies) 212.0.146.58 Khartoum, Sudan 13Sep2004 05:16:51-13:22:01 UTC
W32.Netsky.P@mm.enc (headers deleted by ISP) (unknown) 14Sep2004 15:30:05 PDT
W32.Lovgate.R@mm 212.0.146.58 Khartoum, Sudan 15Sep2004 07:37:16 PDT
W32.Lovgate.R@mm 212.76.71.83 Dhahran, Saudi Arabia 15Sep2004 17:51:48 (+3hr)
W32.Lovgate.R@mm (50 Copies) 212.0.146.58 Khartoum, Sudan 16Sep2004 05:10:43-09:06:04 UTC
W32.Lovgate.R@mm (43 Copies) 212.0.146.58 Khartoum, Sudan 20Sep2004 14:28:06-18:22:48 UTC
W32.Lovgate.R@mm (57 Copies) 212.0.146.58 Khartoum, Sudan 20Sep2004 18:59:06 UTC 21Sep2004 10:51:51 UTC
W32.Netsky.P@mm!enc (headers deleted by ISP) (unknown) 19Nov2004 19:33:59 (-5hr)
W32.Netsky.P@mm!enc (headers deleted by ISP) (unknown) 8Apr2005 05:09:28 PDT
W32.Netsky.P@mm!enc (headers deleted by ISP) (unknown) 9May2005 11:48:57 (-5hr)
W32.Netsky.P@mm!enc (headers deleted by ISP) (unknown) 15May2005 07:36:28 (-5hr)
Trojan.Tooso.B 69.150.118.122 Plano, Texas 31May2005 14:22:48 (EDT)
W32.Mytob@mm 210.213.148.20 Cebu City, Philippines 11Sep2005 17:42:16 (PDT)
W32.Mytob@mm 210.213.144.50 Cebu City, Philippines 13Sep2005 17:35:11 (PDT)
W32.Mytob@mm 210.213.147.206 Cebu City, Philippines 14Sep2005 17:37:42 (PDT)
W32.Mytob@mm 210.213.147.206 Cebu City, Philippines 15Sep2005 00:51:47 (PDT)
W32.Mytob@mm 210.213.151.45 Cebu City, Philippines 16Sep2005 01:45:19 (PDT)
Not yet listed in DAT's (2 copies) 66.230.74.66 Scenery Hill, Pennsylvania 19Sep2005 08:19:27 (PDT)
W32.Mytob@mm 210.213.191.76 Cebu City, Philippines 19Sep2005 18:08:56 (PDT)
W32.Mytob@mm 210.213.139.177 Cebu City, Philippines 20Sep2005 23:13:44 (PDT)
W32.Mytob@mm 210.213.138.186 Cebu City, Philippines 21Sep2005 23:47:55 (PDT)
W32.Mytob@mm 210.213.147.54 Cebu City, Philippines 23Sep2005 18:03:05 (PDT)
W32.Mytob@mm 210.213.153.170 Cebu City, Philippines 25Sep2005 22:11:44 (PDT)
W32.Mytob@mm 210.213.145.76 Cebu City, Philippines 29Sep2005 19:50:35 (PDT)
W32.Mytob@mm 210.213.145.76 Cebu City, Philippines 29Sep2005 22:23:30 (PDT)
W32.Mytob.KU@mm 202.22.194.66 Dhaka, Bangladesh 23Oct2005 20:52:49 PDT
W32.Mytob.KU@mm (12 copies) 202.22.194.66 Dhaka, Bangladesh 24Oct2005 02:31:22-21:52:58 PDT
W32.Mytob.KU@mm (3 copies) 202.22.194.66 Dhaka, Bangladesh 25Oct2005 00:08:00-05:46:54 PDT
W32.Sober.X@mm!zip (headers deleted by ISP) (unknown) 24Nov2005 22:11:03 UTC
W32.Sober.X@mm!zip (headers deleted by ISP) (unknown) 30Nov2005 12:56:51 GMT
W32.Beagle.DW@mm 80.87.87.111 New York, NY 2Mar2006 21:56:19 (PST)
Bloodhound.Beagle 80.87.87.111 New York, NY 3Mar2006 02:29:12 (PST)
Bloodhound.Beagle 80.87.87.111 New York, NY 3Mar2006 02:31:07 (PST)
W32.Beagle.DX@mm 80.87.85.13 New York, NY 5Mar2006 09:13:32 (PST)
W32.Beagle.DW@mm 80.87.84.215 New York, NY 5Mar2006 22:02:35 (PST)
CMU-7197-20081110 75.61.221.146 Bakersfield, CA 8Nov2008 23:32:00 (EST)
CMU-7197-20081110 63.250.234.2 Plainfield, IL 10Nov2008 14:49:00 (EST)
CMU-7197-20081110 113.10.23.57 Seoul, Korea 12Nov2008 01:52:48 (+09UT)
CMU-7197-20081110 117.102.86.69 Tangerang, Indonesia 12Nov2008 15:04:00 (+07UT)
CMU-7295-20081202 75.28.91.10 St. Louis, MO 16Dec2008 00:51:34 (-06UT)
CMU-8092-20090807 202.181.233.214 Islamabad, Pakistan 7Aug2009
CMU-8100-20090807 86.47.42.133 Dublin, Ireland 7Aug2009
CMU-8297-20090829 deleted by ISP deleted by ISP 29Aug2009
CMU-8417-20090908 62.81.91.38 Madrid, Spain 8Sep2009 16:55:40 (+1hr)
CMU-8477-20090910 190.235.8.45 Lima, Peru 10Sep2009 12:51:16 (-5hr)
CMU-9477-20091018 116.126.103.141 Seoul, South Korea 19Oct2009 10:08:43 (+9hr)
CMU-9494-20091019 85.14.154.6 Paris, France 19Oct2009 16:12:47 (+1hr)
CMU-9510-20091019 218.189.207.138 Hong Kong 20Oct2009 09:38:40 (+8hr)
CMU-9769-20091028 116.226.207.218 Beijing, China 29Oct2009 11:49:34 (+8hr)
CMU-9790-20091029 217.39.158.210 Sutton, England 29Oct2009 15:05:09 (+0hr)
CMU-9821-20091030 119.165.175.12 Beijing, China 30Oct2009 16:54:20 (+8hr)
CMU-9932-20091102 210.23.149.49 Sydney, Australia 02Nov2009
CMU-12089-20100716 24.72.48.42 Regina, Saskatchewan, Canada 16Jul2010 12:21:33 (-6hr)
Trojan.GenericFD.4832 (headers deleted by ISP) (unknown) 5Oct2010 17:29:11 (-4hr)
Suspect.Bredozip-zippwd-2 86.23.96.248 London, England 13Nov2010 00:58:09 (+1hr)
Obamacare Warning (116 Copies) 66.223.50.58 Seattle, Washington 14Jan2011 16:08:51 (PST)
Microsoft Corporation Password Trojan (2 Copies) 40.92.255.41 New York, NY 16Sep2019 20:14:02 (-4hr)
Microsoft Corporation Password Trojan (1 Copy) 40.92.69.96 New York, NY 27Oct2019 21:47:57 (-4hr)
Microsoft Corporation Password Trojan (1 Copy) 40.92.68.97 New York, NY 4Nov2019 02:40:29 (-5hr)
Virus QUARANTINED by ISP Unknown Unknown 20Dec2019 02:51:30 (+0hr)
Virus QUARANTINED by ISP Unknown Unknown 26Dec2019 20:46:47 (-5hr)
Blackmail Trojan from CAT TELECOM TOWER Bangrak Bangkok Thailand (1 Copy) 110.78.183.111 Pattaya, CB, Thailand 29Dec2019 07:53:56 (+0hr)
Spoofed address generated by the source listed on the previous line 40.92.255.78 New York, NY 29Dec2019 02:54:28 (-5hr)
Virus QUARANTINED by ISP 54.194.224.26 Dublin, Ireland 24Jan2020 21:39:43 (-5hr)
TashHostW Trojan Fake Adobe PDF Update Fake Adobe PDF Update 14Feb2020 01:01:00 (-5hr)
Blackmail Trojan from Skytelecom Transit provider (1 Copy) 139.5.158.18 Vientiane, Laos 16Mar2020 00:12:46 (-4hr)
Blackmail Trojan from Vietnam Posts and Telecommunications Group (1 Copy) 14.240.216.159 Ha Noi City, Vietnam 17Mar2020 04:17:27 (-4hr)
Virus Removed by ISP  95.216.74.26 Helsinki, Finland 3Apr2020 19:30:49 (+0hr)