Help RSS API Feed Maltego Contact                        

Domain > evcs-crl.ws.symantec.com

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to evcs-crl.ws.symantec.com

MD5A/V
76729286509909b810aae77907c75413[Artemis!767292865099] [TROJ_GE.A43B570E]
0861028d352941c03dca3fe7be6789ef[Worm.Rebhip.r4] [Trojan.Injector.Win32.221782] [Trojan.Win32.Injector.bxcaug] [Trojan.Zbot] [UnclassifiedMalware] [BehavesLike.Win32.Backdoor.gc] [Win32.Troj.Undef.(kcloud)] [Worm:Win32/Rebhip.A] [PWSZbot-FACM!0861028D3529] [Trojan.MSIL.Injector.bYN] [Win32.SuspectCrc] [MSIL/Injector.PE!tr] [Inject.AJQR] [Win32/Trojan.734]
64aef8226ad0e18df4a5b7d0e1cbb4c7
07a57b6581490bbc9f3da1e3ce34c341
4f2dac9d2500387d24faf05c5222a1d3
9d04eb2620e034d2f7b061cc5a5ed457[W32.HfsIframe.C3e1]
761728c46a64d588890643438ef3afa2
56289cce147148a4d854dfea6ba3e2db
121dc9da8632b649cd99d10f79045793
2a2647dcaafe304f6143074a475189d5[Artemis!2A2647DCAAFE] [Malware.AJILI] [Luhe.Fiha.A]
02561efbc06fc00ebe8b7faddb254f94
a9e0be1b184cd1bbae365accd66a2893[Artemis!A9E0BE1B184C] [DLOADER.Trojan] [Heuristic.BehavesLike.Win32.Suspicious-PKR.S]
87867ef4ca9163f3104eaec672ad4288[Artemis!87867EF4CA91] [WS.Reputation.1] [Malware] [Win.Trojan.Qhost-1813] [PUP/Win32.Helper]
afa6f6165bb637dadda656c9cb86f920[W32/A-ef3a91e1!Eldorado]
78274f866570cfcb5b12471b2a525ac3[W32.HfsAutoB.0fab] [Trojan/W32.KRBanker.21642] [TrojanProxy.Potukorp.r2] [Artemis!78274F866570] [Trojan.Qhost!2YNGuQoJWPc] [Trojan.Win32.NSPM.cyvvtf] [PE:Backdoor.Win32.Obfuscator.bl!1075339587] [Heuristic.LooksLike.Win32.Suspicious.C] [Mal/Behav-160] [TrojanProxy:Win32/Potukorp.A] [Trojan/Win32.Banki] [W32/Trojan.SHNZ-5798] [Trojan.Win32.Banker.bOW] [Win32.Backdoor.Obfuscator.Aglb] [Trojan-Proxy] [W32/Qhost_Banker.OW!tr] [Proxy.BDAM] [Trj/CI.A] [Suspicious.Cloud.5]
4a3530ed68e64f411cd0b66cc98ef058[Artemis!4A3530ED68E6] [Trojan.Downloader.cn] [WS.Reputation.1] [Startpage.ITJD] [Trojan.Win32.Badur.gcyr] [Heuristic.BehavesLike.Win32.Suspicious-PKR.S] [Win32.Troj.Badur.gc.(kcloud)] [PUP/Win32.StartPage] [Trojan.NSIS] [W32/Badur.GCYR!tr] [SHeur4.ALHH]
216334af4d221420e771ccadb0dc0c6a[Artemis!216334AF4D22] [PUP.Optional.Meinv] [TR/Dldr.Megone.tga] [TrojanDownloader:Win32/Hicrazyk.A] [NSIS/TrojanDownloader.Grinidou.F] [Trojan-Downloader.Win32.Hicrazyk] [W32/StartPage.NY!tr] [Trojan.NSIS.Grinidou.F]
1caf820f3d70a93a4d27bba92eaf3339[Artemis!1CAF820F3D70] [DLOADER.Trojan] [Heuristic.BehavesLike.Win32.Suspicious-PKR.S] [Trojan:Win32/Comroki]
20e1869be2d72209912aafb1e4924726[Trojan/W32.KRBanker.28160.G] [Trojan-Spy.Win32.Zbot!O] [TrojanSpy.Zbot.r4] [Spyware.Zbot.JWZ] [W32/Heuristic-210!Eldorado] [TROJ_FORUCON.BMC] [Trojan.Win32.Zbot.cxbdqz] [Trojan.Win32.A.Zbot.28160.D] [TrojWare.Win32.Injector.cej] [Trojan.Packed.22856] [Heuristic.LooksLike.Win32.Suspicious.C!86] [Mal/Dropper-AB] [Trojan/Hijacker.lc] [TrojanProxy:Win32/Potukorp.A] [Win-Trojan/Banki.28160] [Trj/CI.A] [PE:Trojan.Win32.Injector.fo!1075351907] [Trojan-Spy.Win32.Zbot] [W32/Injector.ZBT!tr] [Pakes_c.BPIV] [Trojan.Win32.Zbot.AF]
a17f71684883c039de826b2e42644dc0

Whois

PropertyValue
NameDomain Manager
Organization SymantecCorporation
Email domains@symantec.com
Address 350EllisStreet
Zip Code 94043
City MountainView
State CA
Country US
Phone +1.6505278000
Fax +1.6505278000
NameServer pdns5.ultradns.info
Created 1992-11-24 05:00:00
Changed 2014-11-19 11:28:31
Expires 2015-11-23 00:00:00
Registrar CSC CORPORATE DOMAIN

DNS Resolutions

DateIP Address
2013-04-01199.7.55.190 (ClassC)
2013-04-01199.7.59.190 (ClassC)
2013-05-16199.7.51.190 (ClassC)
2013-05-16199.7.52.190 (ClassC)
2013-07-0923.55.149.163 (ClassC)
2013-07-1223.35.165.163 (ClassC)
2013-07-182.22.133.163 (ClassC)
2013-10-1123.61.181.163 (ClassC)
2013-10-1923.60.133.163 (ClassC)
2013-10-2323.61.69.163 (ClassC)
2013-10-2523.36.149.163 (ClassC)
2013-10-2523.37.37.163 (ClassC)
2013-12-0723.65.5.163 (ClassC)
2014-02-0923.51.117.163 (ClassC)
2014-02-2123.4.37.163 (ClassC)
2014-03-1523.50.69.163 (ClassC)
2014-04-1523.52.53.163 (ClassC)
2014-04-1723.5.245.163 (ClassC)
2014-05-2223.13.165.163 (ClassC)
2014-06-1223.64.165.163 (ClassC)
2014-06-2323.5.5.163 (ClassC)
2014-06-2323.7.133.163 (ClassC)
2014-06-2723.5.5.163 (ClassC)
2014-07-2023.7.69.163 (ClassC)
2014-07-2123.9.85.163 (ClassC)
2014-09-1023.7.133.163 (ClassC)
2014-10-1423.37.37.163 (ClassC)
2014-10-1723.53.181.163 (ClassC)
2014-10-2323.5.245.163 (ClassC)
2015-08-1423.49.133.163 (ClassC)
2016-03-2923.9.117.163 (ClassC)
2016-07-2723.4.181.163 (ClassC)
2017-06-1923.15.149.163 (ClassC)
2017-09-0823.63.133.163 (ClassC)
2017-09-2923.46.117.163 (ClassC)
2018-03-2123.37.165.163 (ClassC)
2018-04-0123.54.181.163 (ClassC)
2018-05-0823.43.69.163 (ClassC)
2018-05-1223.4.53.163 (ClassC)
2019-05-2893.184.220.29 (ClassC)
2019-11-10117.18.237.29 (ClassC)
2020-12-3172.21.91.29 (ClassC)
2023-03-01192.229.221.95 (ClassC)
2024-12-22192.229.211.108 (ClassC)
2025-03-0123.221.103.101 (ClassC)
2025-05-1823.198.106.123 (ClassC)
2025-06-0523.196.145.101 (ClassC)

Subdomains

DateDomainIP
ncw-01.symantec.com2024-12-1235.190.72.88
fe0001.symantec.com2014-11-17184.50.238.8
mrs-uat-tus1.symantec.com2025-05-1734.107.142.185
ns2.symantec.com2025-05-26204.74.109.1
shasta-rrs-sim-43.symantec.com2025-05-2635.190.125.30
ns4.symantec.com2025-05-12199.7.68.1
icd-schema.symantec.com2025-05-1235.227.208.79
test-inquira.symantec.com2015-04-0763.236.252.176
shasta-rrs-beta.symantec.com2025-05-2635.190.125.30
sec.symantec.com2025-06-0234.8.226.100
kbdownload.symantec.com2014-02-27165.254.155.115
esdownload.symantec.com2014-11-20205.185.206.155
entced.symantec.com2025-05-27192.19.145.20
gold.symantec.com2016-03-17107.20.174.202
activate.atpcloud.symantec.com2019-10-1513.224.29.53
securitycloud.symantec.com2025-04-2834.117.90.54
usea1.r3.securitycloud.symantec.com2025-01-2234.117.32.246
us.spoc.securitycloud.symantec.com2025-05-0434.117.217.74
sepc.securitycloud.symantec.com2025-06-0235.186.217.224
us-mc1.sepmobile.securitycloud.symantec.com2025-05-1734.98.100.43
mitm2.sepmobile.securitycloud.symantec.com2024-12-22152.199.4.152
aad.sepmobile.securitycloud.symantec.com2025-05-1334.120.129.121
apkdownload.sepmobile.securitycloud.symantec.com2025-05-2834.120.129.121
api.sepmobile.securitycloud.symantec.com2025-05-2534.120.129.121
us-mc1-api.sepmobile.securitycloud.symantec.com2025-04-1034.98.100.43
mdm.sepmobile.securitycloud.symantec.com2025-05-1234.120.129.121
mitm.sepmobile.securitycloud.symantec.com2024-12-03152.195.19.241
cdn.sepmobile.securitycloud.symantec.com2024-12-12152.195.19.241
demo.sepmobile.securitycloud.symantec.com2025-05-2534.120.129.121
mdatp.sepmobile.securitycloud.symantec.com2025-06-0434.120.129.121
incidents.sepmobile.securitycloud.symantec.com2023-09-2534.117.234.137
mgmt.sepmobile.securitycloud.symantec.com2025-05-1234.120.129.121
sep.in.securitycloud.symantec.com2025-05-1235.186.232.85
sep.securitycloud.symantec.com2025-05-3135.186.217.224
uep.securitycloud.symantec.com2019-10-1252.45.217.119
scwp.securitycloud.symantec.com2025-05-3134.117.32.246
bds.securitycloud.symantec.com2025-05-2934.117.32.246
us.securitycloud.symantec.com2025-05-0634.117.90.54
eu.securitycloud.symantec.com2025-05-0134.117.90.54
sep.eu.securitycloud.symantec.com2025-05-1234.111.33.195
clicktime.symantec.com2025-05-3154.185.0.191
www-secure.symantec.com2025-05-12172.64.150.145
securityresponse.symantec.com2014-12-31165.254.207.80
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information