Help RSS API Feed Maltego Contact                        

Domain > cmdcmdcmd.php0h.com

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to cmdcmdcmd.php0h.com

MD5A/V
31484df48eeeaba117b43b9fa746da0e[W32.PikachuGTA.Worm] [Worm.Chupik.A3] [W32/Worm-FEL!31484DF48EEE] [W32/VB.aso] [Trojan.Win32.MulDrop2.crsvig] [W32/Worm.APUJ] [W32.SillyFDC] [Win32/Chupika.A] [TROJ_SPNR.02EM12] [Win32:Sality] [Worm.Chupik!EXA4Vn+0eQg] [Worm.Win32.VB.110592.B] [Worm.Win32.Autorun.d] [Worm.Win32.Autorun.eb0] [Trojan.MulDrop2.63234] [Worm.VB.Win32.2095] [Heuristic.BehavesLike.Win32.Suspicious-BAY.K] [Mal/VB-F] [Worm/VB.ayi] [Worm.VB.417792.(kcloud)] [Worm:Win32/Chupik.A] [Trojan/Win32.Cosmu] [W32/Worm.LPKA-4508] [Worm.VB] [Win32/VB.NSP] [PE:Worm.VobfusEx!1.99E4] [Worm.Win32.VB] [W32/VB.SDE!tr] [Worm/VB.ADVW] [W32/Picachu.A.worm]

Whois

PropertyValue
Email ABUSE@BYETHOST.ORG
NameServer NS2.BYET.ORG
Created 2006-02-20 00:00:00
Changed 2015-01-21 00:00:00
Expires 2016-02-20 00:00:00
Registrar ENOM, INC.

DNS Resolutions

DateIP Address
2013-04-01199.59.243.64 (ClassC)
2013-04-01199.59.243.124 (ClassC)
2014-06-1523.253.135.157 (ClassC)
2014-07-30199.59.243.123 (ClassC)
2024-08-29199.59.243.226 (ClassC)
2024-12-27199.59.243.227 (ClassC)
2025-07-16199.59.243.228 (ClassC)

Port 80

Subdomains

DateDomainIP
gehhem123.php0h.com2013-04-13209.190.85.145
dfree3.php0h.com2015-05-24185.27.134.159
paypa.php0h.com2013-04-01209.190.24.4
transmitindoterra.php0h.com2014-05-2923.253.135.157
hfeiya.php0h.com2013-04-01199.59.243.124
wpxnbd.php0h.com2015-01-24185.27.134.127
pferrarikid.php0h.com2013-04-01199.59.243.64
cmdcmdcmd.php0h.com2013-04-01199.59.243.64
fingguboard.php0h.com2013-04-21209.190.85.35
www.fingguboard.php0h.com2013-05-20209.190.85.35
shutembe.php0h.com2013-11-30185.27.134.111
horse.php0h.com2013-05-07209.190.85.145
arsperug.php0h.com2013-07-03199.59.243.109
ziwatik.php0h.com2013-04-09209.190.24.9
www.lion.php0h.com2013-08-05209.190.24.9
baston.php0h.com2013-05-10209.190.85.35
echo.php0h.com2013-12-05185.27.134.213
rhonoto.php0h.com2014-07-16185.27.134.142
sohocop.php0h.com2013-05-29209.51.196.248
taylodrop.php0h.com2014-07-15199.59.243.123
ftp.php0h.com2025-06-26185.27.134.11
bonusonlinepoker.php0h.com2013-06-12199.59.243.109
radioplayer.php0h.com2013-04-01199.59.243.110
smart_cis.php0h.com2013-05-13209.190.85.35
finggunews.php0h.com2013-04-01209.190.85.9
bancoposteit.php0h.com2013-06-12199.59.243.109
www.toplisteskort.php0h.com2025-05-09185.27.134.219
cbasketbe1u.php0h.com2013-07-03199.59.243.109
postepay.php0h.com2014-06-30205.164.14.79
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information