Help RSS API Feed Maltego Contact                        

Domain > parts.woodwardcounselinginc.com

More information on this domain is in AlienVault OTX

Is this malicious?

Reports

http://www.fireeye.com/blog/threat-research/2016/0...    
https://otx.alienvault.com/pulse/56eff152aef9214b1...    
http://www.fireeye.com/blog/threat-research/2016/0...    

Files that talk to parts.woodwardcounselinginc.com

MD5A/V
8f6bf8bee6d47e2d4cff66ffb2512c28[virus.office.obfuscated.1]
d5ec53321e4e130ee8cb86abacba8d06[virus.office.obfuscated.1]
46680b59ad89c330eb36420858e925ad[virus.office.obfuscated.1]
d193926f317dda237a2444c6f31a11b2[virus.office.obfuscated.1]
5b7813105cf9ebccb46cf7e63a5a836d[virus.office.obfuscated.1]
8f787ddedbaa8af3f6a73d0c6cd4e33e[virus.office.obfuscated.1]
c27ce9e3b1925c22593f3987100258ae[virus.office.obfuscated.1]
0488011678544ea178ce5c52e81fe47f[virus.office.obfuscated.1]
876d081e8b474a3c1ac57cf435e330cb[W2KM_DRIDEX.KD] [W2KM_DRIDEX.YYSSE] [virus.office.obfuscated.1]
a79445f98b7976f58fffcf7c68ea55c7[virus.office.obfuscated.1]
c395ed2f0e507600416f0c4b053e06a4[W2KM_DRIDEX.KD] [W2KM_DRIDEX.YYSSE] [virus.office.obfuscated.1]
d8eebe2a08fff86abd06ec94e8bdd165[W2KM_DRIDEX.KD] [W2KM_DRIDEX.YYSSE] [virus.office.obfuscated.1]
d5eb26d20ee17c4e9d8fc62acab0bcef[virus.office.obfuscated.1]
a77a3966d295e4c4725c592cf812dea2[virus.office.obfuscated.1]
aff54d68cbf6ac8611fe89cd9f0dc2de[W97M.Dropper.BD] [W97M.Dropper.BD] [W97M/Dridex.N] [W97M.Downloader] [W2KM_DRIDEX.YYSSE] [Troj/DocDl-BPL] [W97M.Dropper.BD] [W2KM_DRIDEX.YYSSE] [W97M/Dridex.N] [W97M.Dropper.BD] [virus.office.obfuscated.1]
ac2a5c1bbd9903bdbbde650465cf0a1a[Troj.Downloader.Script!c] [Troj/JSDldr-FR] [VBS/Downloader.bq] [virus.vbs.dropper.d]

Whois

PropertyValue
NameServer NS44.DOMAINCONTROL.COM
Created 2008-12-09 00:00:00
Changed 2015-12-09 00:00:00
Expires 2017-12-09 00:00:00
Registrar GODADDY.COM, LLC