Why it is still listed here: http://cyberwarzone.com/malicious-history-of-146-185-238-185/
Given: https://www.virustotal.com/nl/ip-address/146.185.238.185/information/
dummy → http://toolbar.netcraft.com/site_report?url=146.185.238.185
Also this IP: http://cyberwarzone.com/tag/146-185-238-144-russian-federationnet-for-sev-koroleva-ltdmalware-research/
Had loadstart and other BHO’s,
polonus