Help RSS API Feed Maltego Contact                        

Domain > gcs-cpa.com

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to gcs-cpa.com

MD5A/V
c05f0c46dbc6bfe046ad7ca12cf9f98e[W32.Cloda2c.Trojan.5c7a] [PWSZbot-FLN!C05F0C46DBC6] [Spyware.Zbot] [TrojanSpy.Zbot!d3kAaGLa0Gg] [Suspicious.Cloud] [TSPY_ZBOT.WGJ] [Trojan-Spy.Win32.Zbot.qqte] [Trojan.Win32.Zbot.cmzhij] [Trojan.PWS.Panda.4379] [TR/Spy.ZBot.anb.1] [Win32.Troj.Zbot.qq.(kcloud)] [PWS:Win32/Zbot] [Win32/Spy.Zbot.AAU] [Trojan-PWS.Win32.Zbot] [W32/Zbot.QQTE!tr] [Trojan.Win32.Zbot.Ax]
5345aff5ce85c0d99c484f2716071b7a[Win32.Heur.KVMF58.hy.(kcloud)]
390fc8a6672ba631df610de3fc76ad22[Heur.Win32.Veebee.1!O] [Trojan.LVBP.ED] [W32/Trojan2.OAPU] [TROJ_FORUCON.BMC] [Trojan-PSW.Win32.Tepfer.swki] [Trojan.PWS.Stealer.3128] [TR/Dropper.VB.7976] [W32/Trojan.VAGS-5670] [Trojan-PWS.Win32.Tepfer] [Trojan.Win32.InfoStealer.AY]
901fd56bd89d217effeca7e998d48b8f[BC.Heuristic.Trojan.SusPacked.BF-6.A] [Mal/EncPk-ZC] [Heuristic.LooksLike.Win32.SuspiciousPE.J!86] [TrojanDownloader.Upatre.A6] [Downloader-FVD!901FD56BD89D] [Trojan.Downloader] [Trojan.DL.Small!WegiOz7B/54] [W32/Trojan3.GJV] [Trojan.Zbot] [Upatre.X] [TROJ_UPATRE.BU] [Trojan.Win32.DownLoad3.cmcabg] [TrojWare.Win32.Spy.Zbot.ADCX] [TR/Yarwi.B.15] [TrojanDownloader:Win32/Upatre.A] [W32/Trojan.SXFM-2396] [Win32/TrojanDownloader.Small.AAB] [PE:Malware.FakePDF@CV!1.9C28] [Trojan.Injector] [Zbot.DFA] [Trojan.DownLoad3.28]
8043461e3d18f379dfd5c1d3dda25c6f[TrojanDownloader.Cutwail.BS4] [PWS-FBOF!] [Spyware.Zbot] [Trojan.Cutwail!ksLthdR/J5A] [W32/Trojan2.OBNX] [Backdoor.Trojan] [Kryptik.CDDW] [Win32/Cutwail.CAK] [BKDR_PUSHDO.IP] [Trojan.Win32.Cutwail.chg] [Trojan.Win32.Cutwail.cucyjl] [Trojan.Win32.A.Cutwail.87552] [TrojWare.Win32.Spy.Zbot.FRIN] [Trojan.PWS.Panda.5756] [TR/Injector.90112.43] [Trojan/Cutwail.ab] [Trojan/Win32.Cutwail] [Win32.Troj.Cutwail.c.(kcloud)] [TrojanDownloader:Win32/Cutwail.BS] [Spyware/Win32.Zbot] [W32/Trojan.WQFW-5190] [Trj/WLT.A] [Win32/Wigon.PI] [Win32.Trojan.Cutwail.Dxcl] [Trojan-Downloader.Win32.Cutwail] [W32/Cutwail.CHG!tr] [SHeur4.BRVM] [Trojan.Win32.Cutwail.aG]
48c156b5fb7c17d44265886e05c84cb4[W32.ApfixwitB.Trojan] [Backdoor.Pushdo.r4] [Trojan.Win32.Pushdo.cxsxde] [WS.Reputation.1] [ZBot.STQQ] [TROJ_SPNV.01DR14] [Backdoor.Win32.Pushdo.rln] [Trojan.Kryptik!Zvn35zSbM+Y] [UnclassifiedMalware] [Trojan.DownLoader11.6956] [TR/Dldr.Cutwail.BS.431] [Mal/Zbot-PT] [Trojan[Backdoor]/Win32.Pushdo] [TrojanDownloader:Win32/Cutwail.BS] [W32/Trojan.HDHP-3086] [Backdoor.Pushdo] [Win32.Backdoor.Pushdo.Pfjl] [Trojan-Dropper.Necurs] [W32/Pushdo.CAKI!tr.bdr] [Trojan.Win32.Kryptik.bCAKI] [Win32/Backdoor.f04]
f15be0daa762c12cda891a6390d77e86[WS.Reputation.1] [TROJ_CRILOCK.RNT] [Backdoor.Win32.Pushdo.rks] [TR/Crypt.ZPACK.40047] [Trojan[Backdoor]/Win32.Pushdo] [W32/Pushdo.RKS!tr.bdr] [SHeur4.BTFZ]
1dc798c5cda1dfb8e321e68f1cf116c4[W32.DalverM.Trojan] [Trojan.Cutwail.r5] [RDN/Downloader.a!qr] [Trojan.Cutwail] [TROJ_CUTWAIL.YAJ] [Trojan.Win32.Cutwail.cuo] [Trojan.Cutwail!Dw5GluQCwY0] [UnclassifiedMalware] [BackDoor.Bulknet.1150] [Trojan/Win32.Cutwail] [TrojanDownloader:Win32/Cutwail.BS] [W32/Trojan.LTBF-7078] [Trj/CI.A] [Win32.Trojan.Cutwail.Eclb] [Trojan] [W32/Cutwail.CBPJ!tr] [Crypt3.OXR] [Trojan.Win32.Kryptik.BCBPJ] [Win32/Trojan.Multi.daf]
8e691ed88a926b0255f2514f37866d31
556c3819778ac91261be8821206aa1ca[Trojan.Zbot.cw3] [Trojan.Crypt.NKN] [Trojan.VBKrypt.Win32.226775] [Trojan.Win32.VBKrypt.cvwaev] [W32/Trojan4.AFNE] [WS.Reputation.1] [Win32/Zbot.IDY] [TROJ_FORUCON.BMC] [Trojan.Win32.VBKrypt.uqco] [Trojan.VBKrypt!sgvTFCNPRto] [UnclassifiedMalware] [BackDoor.Andromeda.273] [TR/Dropper.VB.12577] [Trojan/VBKrypt.jafc] [PWS:Win32/Zbot] [Backdoor/Win32.Androm] [W32/Trojan.XEYN-6246] [Virus.Win32.Heur.p] [Trj/WLT.A] [Win32/Wigon.PH] [Virus.Win32.VBInject] [W32/VBKrypt.PH!tr] [SHeur4.BSLG] [Trojan.Win32.VBKrypt.ahI] [Win32/Trojan.Multi.daf]
175dcdd59c914b24d14c40a7e96786c1[W32.Sality.PE] [Win32.Sality.3] [Trojan.Win32.Krap.1!O] [W32.Sality.U] [Virus.Sality.Win32.20] [Win32.Sality.BL] [W32.Sality.AE] [Sality.ZHB] [Win32/Sality.AA] [PE_SALITY.RL] [Win32:SaliCode] [Virus.Win32.Sality.beygb] [Win32.Sality.N] [Mal/Sality-D] [Win32.Sector.22] [W32/Sality.AT] [Heuristic.LooksLike.Win32.Suspicious.F] [Virus:Win32/Sality.AT] [Win32/Kashu.E] [Virus.Win32.Sality.bakc] [W32/Sality.AA] [Win32/Sality.NBA] [Virus.Win32.Sality] [Win32/Sality] [Virus.Win32.Sality.$Emu] [Win32/Trojan.1ef]
befb64cbe1dbd0d82dfbfe4d5ea6249a[Packed.Win32.Katusha.1!O] [PWSZbot-FTJ!BEFB64CBE1DB] [Spyware.Zbot.ED] [Trojan.Win32.Cutwail.cuodvy] [Trojan.DownLoader9.48272] [Trojan/Win32.Cutwail] [Trojan.Cutwail]
7cdb7bd134239bf0fc686cdec723ff12[Trojan] [Backdoor.Trojan] [TrojanDownloader:Win32/Cutwail] [W32/Backdoor.UMOH-9056] [Backdoor/Win32.Androm] [Win32/Wigon.PH] [W32/Wigon.PH] [Crypt2.BOOA] [Trojan.Win32.Kryptik.BMUN]
6177f407a983aa9c860f47f1423bd5d5
da53b7983185de17e67579e2de0231be[Trojan-Dropper.Win32.Dorifel.aguj] [W32/Injector.ALPQ!tr]
2c2371e95bb5d87ccd5d19a114492f70[HW32.CDB.18af] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CDQY] [TrojWare.Win32.Kryptik.CBCJ] [BackDoor.Slym.13873] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Backdoor.Win32.Kelihos] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CBCJ] [Win32/Trojan.0de]
67fa719ca9c20016b7d044d179bb2a2f
8016f017cd252788a6e7e6802c10e0b2[Trojan.Pushdo.D] [Trojan.Cryptor.r4] [Trojan.Necurs] [Backdoor.Pushdo!QBuGAcEYs7o] [Backdoor.Trojan] [ZBot.UPRE] [Win32/Cutwail.DVCWUKD] [TROJ_KRYPTIK.YVV] [Backdoor.Win32.Pushdo.rkx] [Trojan.Win32.Pushdo.cwhqoj] [TrojWare.Win32.UMal.~A] [BackDoor.Bulknet.1150] [Backdoor.Pushdo.Win32.713] [TR/Cutwail.A.55] [Mal/Zbot-PT] [TrojanDownloader:Win32/Cutwail] [W32/Trojan.SCHC-6463] [Backdoor/Win32.Necurs] [Backdoor.Pushdo] [Win32/Wigon.PH] [Win32.Backdoor.Pushdo.Dvza] [Trojan-Dropper.Necurs] [W32/Pushdo.BZGH!tr.bdr] [Crypt3.IEL] [BackDoor.Win32.Pushdo.77] [Win32/Backdoor.4da]
58d7917e004d65a1294bc93814a7cee0
2f8aaaf8f6772625a9eb19e08bf0bf9c[HW32.Laneul.naqy] [Backdoor.Win32.Pushdo.rcf]

Whois

PropertyValue
Email jwinter@gcs-cpa.com
NameServer NS2.DOMAINDISCOVER.COM
Created 2001-01-19 00:00:00
Changed 2015-01-20 00:00:00
Expires 2016-01-19 00:00:00
Registrar TIERRANET INC. D/B/A

DNS Resolutions

DateIP Address
2013-10-1164.14.68.37 (ClassC)
2014-08-22173.236.171.201 (ClassC)
2014-11-04173.236.171.201 (ClassC)
2019-09-06104.27.176.106 (ClassC)
2020-12-30104.27.177.106 (ClassC)
2023-12-2972.1.32.168 (ClassC)
2024-01-1434.224.160.149 (ClassC)
2024-02-1618.210.31.118 (ClassC)
2024-02-2472.1.32.14 (ClassC)
2024-06-2238.28.186.214 (ClassC)
2024-12-17104.21.39.240 (ClassC)
2025-01-12172.67.150.146 (ClassC)
2025-03-31104.21.11.16 (ClassC)
2025-04-08172.67.147.141 (ClassC)
2025-04-11204.11.56.37 (ClassC)
2025-05-1623.225.134.175 (ClassC)
2025-11-04107.151.102.152 (ClassC)
2026-01-17154.213.255.235 (ClassC)

Port 80

Port 443

Subdomains

DateDomainIP
www.gcs-cpa.com2015-03-10173.236.171.201
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information