Help RSS API Feed Maltego Contact                        

Domain > ftp.xmahone.ocry.com

More information on this domain is in AlienVault OTX

Is this malicious?

Reports

http://www.commandfive.com/papers/C5_APT_C2InTheFi...    
http://www.symantec.com/content/en/us/enterprise/m...    

Files that talk to ftp.xmahone.ocry.com

MD5A/V
357AD1B88C493E62A119D696B851B61C
3E3736DFFEDAF2A0AE4D948567933B3F
0d38d6c2b9eb817b40afc4272545a43b[Backdoor.697C95A1B68EE869] [TR/Spy.73484] [TrojanDropper*Win32/Wykcores.A] [Win32/DH{CA?}] [W32/Trojan.FLAG-0782] [Win32/Wykcores.A] [BackDoor-EYO] [Troj/Wykcores-A] [TrojanDropper.Wykcores.r9]

Whois

PropertyValue
NameNetwork OperationsZZZ, ChangeIP
Email noc@changeip.com
Address 1200 Brickell Avenue
Zip Code 33131
City Miami
State FL
Country US
Phone +1.8007913367
Fax +1.7862246593
NameServer NS3.CHANGEIP.ORG
Created 2003-11-06 01:00:00
Changed 2013-04-23 02:00:00
Expires 2015-05-12 00:00:00
Registrar NETWORK SOLUTIONS, L