Help RSS API Feed Maltego Contact                        

Domain > dns2.ipv6do.com

This indicator is referenced in AlienVault OTX pulse ""

Is this malicious?

Most users have voted this as MALICIOUS

Reports

https://blogs.rsa.com/wp-content/uploads/2015/05/R...    
https://otx.alienvault.com/pulse/557f0d30b45ff543a...    

Files that talk to dns2.ipv6do.com

MD5A/V
8c8680f9c095f8a49ea9a13bf5a9d44d[Trojan.Keylogger.MZT] [Trojan.Keylogger.MZT] [W32/Trojan.PARR-2567] [Trojan.Keylogger.MZT] [Trojan.Keylogger.MZT] [Backdoor.Inject.r5] [Win.Trojan.PlugX-113] [Trojan.DownLoader9.56215] [Trojan.Keylogger.MZT] [Win32/Korplug.A] [W32/Inject.A!tr.bdr] [Backdoor.Win32.Inject*Trojan.Win32.Korplug] [Backdoor.Win32.Inject.ymn] [Backdoor*Win32/Plugx.A] [Trojan.Keylogger.MZT[ZP]]

Whois

PropertyValue
Email ipv6do@yahoo.com
NameServer : YNS2.YAHOO.COM
Created : 2011-09-07T14:38:0
Changed 2014-09-24 00:00:00
Expires 2015-09-07 00:00:00
Registrar MELBOURNE IT, LTD. D