Help RSS API Feed Maltego Contact                        

Domain > regiefernando.me

More information on this domain is in AlienVault OTX

Is this malicious?

Reports

http://malwarefor.me/2015-12-03-nuclear-ek-sending...    
https://otx.alienvault.com/pulse/56649a164637f27ed...    
https://blogs.sophos.com/2016/01/06/the-current-st...    

Files that talk to regiefernando.me

MD5A/V
4818850de2ee2b318ffc100cce179338
f96a37a0fc5de361af5a64515f21c481[BehavesLike.JS.ExploitBlacole.xv]
0aa2129d4c34230c758edb2371c55435[JS:Trojan.Script.CQX] [JS:Trojan.Script.CQX] [JS:Trojan.Script.CQX] [BehavesLike.JS.ExploitBlacole.xv] [JS:Trojan.Script.CQX]
446071be407efeb4e0d7c83bb504774a
fbf1b81263b4712b6d9c9c2d39371d1d[HW32.Packed.916F] [Suspicious.Cloud.5] [BehavesLike.Win32.SoftPulse.fh]
92c4dd41e6fcfaead5290a4fcd3f144b
a446eaca4d14b5eacf45c0604d43f278
4b0337453d575e49b704f4e311c37284
616270f7e2c1c1ef134c46a79d09798f
24a87c47bb9f0655708613fc50f83732
e79b66756a9b6156392192560f81e2ff[Trojan.MalPack] [Trojan.Encoder.3104] [BehavesLike.Win32.Sality.dh]
57408cecd35d55e73629e1dfda8894bf[HW32.Packed.1C7E] [Ransom.Teslacrypt.D4] [Ransom.FileCryptor] [Trojan.Win32.AVKill.dzajbw] [Ransom_CRYPTESLA.SM] [Trojan.Win32.Yakes.nprb] [Trojan.Yakes!tr20ym672BQ] [Trojan.Win32.TeslaCrypt.393216.A[h]] [Trojan.AVKill.59520] [Trojan.Kryptik.Win32.823582] [BehavesLike.Win32.Madangel.fh] [W32/Trojan.DSVW-7517] [TR/Crypt.ZPACK.220626] [Ransom:Win32/Tescrypt!rfn] [SScope.Malware-Cryptor.Drixed] [Trj/CI.A] [Win32.Trojan.Inject.Auto] [Trojan.Win32.Crypt] [W32/Kryptik.DL!tr] [Zbot.AKMO] [Trojan.Win32.Yakes.nprb]

Whois

PropertyValue
NameRegie Fernando
Email tekgik@regiefernando.com
Address Manila
Zip Code 1440
City Manila
State Manila
Country PH
Phone +63.26365708
NameServer ns348.hostgator.com
Created 2010-09-22 04:05:14
Changed 2015-09-24 06:52:45
Expires 2016-09-22 04:05:14
Registrar GoDaddy.com, LLC R41