Help RSS API Feed Maltego Contact                        

Domain > do.ddns.ms

This indicator is referenced in AlienVault OTX pulse ""

Is this malicious?

Most users have voted this as MALICIOUS

Reports

https://raw.githubusercontent.com/fireeye/pivy-rep...    
https://www.fireeye.com/resources/pdfs/fireeye-poi...    

Files that talk to do.ddns.ms

MD5A/V
bf553932f6f418250a4dd81c63b3ccee[W32.Clod354.Trojan.e12b] [Trojan/W32.Small.36864.AVB] [Backdoor.Win32.Inject!O] [BackDoor-AMQ.dr] [Backdoor.Poison] [Backdoor/Inject.rbn] [Trojan.Win32.Inject.grgsm] [W32/Backdoor2.HJJS] [Backdoor.Darkmoon] [Win32/PoisonIvy.DW] [Backdoor.Inject!zeM5NgZ6dpo] [Heur.Suspicious] [Trojan.DownLoader5.4689] [BDS/Poisonivy.E.693] [BKDR_DARKMOON.SM1] [Troj/Bckdr-RJH] [Backdoor/Inject.acc] [Backdoor:Win32/Poison.E] [Backdoor/Win32.Inject] [W32/Backdoor.KEPB-2432] [Backdoor.Inject] [Win32/Poison] [Backdoor.Win32.Inject] [W32/Inject.RBN!tr.bdr] [Bck/Poison.F]
81B53D61922C944D3D4C9031F3861D0B

Whois

PropertyValue
Email akaelin@web.com
NameServer ns2.changeip.org
Created 2002-08-14 14:00:00
Changed 2012-08-14 15:17:06
Expires 2017-08-14 14:00:00
Registrar Network Solutions, L

DNS Resolutions

DateIP Address
2014-04-2754.241.6.130 (ClassC)
2025-08-2454.241.6.130 (ClassC)
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information