Help RSS API Feed Maltego Contact                        

Domain > sophos.skypetm.com.tw

This indicator is referenced in AlienVault OTX pulse ""

Is this malicious?

Most users have voted this as MALICIOUS

Reports

http://blog.cassidiancybersecurity.com/post/2014/0...    
https://bitbucket.org/cybertools/whitepapers/downl...    

Files that talk to sophos.skypetm.com.tw

MD5A/V
4ab74387f7a02c115deea2110f961fd3[Pakes_c.AMPX] [TR/Kazy.269574]
79e48961d1ee982a466d222671a42ccb[Trojan*Win32/Sisproc]
2b3149926ebced31284867e71648094b
bf95e89906b8a17fd611002660ffff32
ed35e43142b42b57f518197d930471d9[RTF.Exploit.2014.1761] [CVE-2014-1761.A] [Exploit.MSWord.CVE-2014-1761.a] [RTF:Malware.OddRTF/Heur!1.9E6F] [Exp/20141761-A] [UnclassifiedMalware] [Exploit.Rtf.CVE2012-0158] [Exploit:Win32/CVE-2012-2539] [Word.Exploit.Cve-2014-1761.Alij] [Exploit.Win32.CVE-2012] [virus.exp.20141761]
f4df831f061f9f4b11d865731d650273
839af8eea3d2d077418acfee08551f4d[W32/Trojan.YQGG-0912] [TR/Kazy.269574] [TrojanRansom.Blocker.r3] [Pakes_c.AMPX] [Trojan.Rerol] [Trojan-Ransom.Win32.Blocker.divb] [Trojan.Blocker.NR] [RDN/Ransom!eo] [Troj/Rerol-A] [Trojan.Pittyger]
1b0e8fbbace9272c8b8225fa0889c73d
ac653cad2dfc4dcdcdfa374d4a0e3537
5e2360a8c4a0cce1ae22919d8bff49fd[TrojanRansom.Blocker.r3] [Trojan.Blocker.Win32.13870] [Trojan.Kazy.D41D06] [Trojan.Win32.Blocker.cuclmv] [Backdoor.Trojan] [Trojan-Ransom.Win32.Blocker.divb] [Trojan.Blocker!bpINWZ8JgEs] [Win32.Trojan.Blocker.Swut] [Troj/Rerol-A] [UnclassifiedMalware] [BehavesLike.Win32.Downloader.lm] [W32/Trojan.XPTA-0912] [Trojan/Blocker.agwe] [TR/Kazy.269574] [Trojan[Ransom]/Win32.Blocker] [Win32.Troj.Undef.(kcloud)] [Trojan:Win32/Rimod!gmb] [Trojan.Win32.Z.Blocker.15872.A[h]] [Trojan/Win32.Pittyger] [Trojan.Win32.Ransomlock.divb] [PE:Malware.RDM.01!5.7[F1]] [Trojan.Rerol] [W32/Blocker.A!tr] [Trj/CI.A]

Whois

PropertyValue
Namelong sa
Organization information of network company
Email longsa33@yahoo.com
Address No.520.gongye road.shanghai
City shanghai, shanghai
Country CN
Phone +86.88885918
NameServer ns2.world-server.net
Created 2011-01-10 00:00:00
Expires 2015-01-10 00:00:00
Registrar AsiaRegister,Inc.

DNS Resolutions

DateIP Address
2013-09-27101.1.27.128 (ClassC)
2013-11-22198.100.121.15 (ClassC)
2013-12-02198.100.121.15 (ClassC)
2014-04-09198.100.113.27 (ClassC)
2014-07-0466.220.4.100 (ClassC)
2014-12-14127.0.0.1 (ClassC)
2019-11-0423.253.126.58 (ClassC)
2019-11-04104.239.157.210 (ClassC)
2025-07-09210.71.232.10 (ClassC)
2026-02-01210.71.232.9 (ClassC)

Port 80

Subdomains

DateDomainIP
ms11.skypetm.com.tw2014-12-14202.174.130.110
newb02.skypetm.com.tw2014-12-14127.0.0.1
032gunlike.skypetm.com.tw2019-07-0123.253.126.58
asdf.skypetm.com.tw2014-12-14113.10.240.54
zeng.skypetm.com.tw2014-05-30101.1.25.74
link.skypetm.com.tw2014-12-14127.0.0.1
botemail.skypetm.com.tw2014-12-14216.18.208.4
gmail.skypetm.com.tw2013-04-27122.208.59.188
tm.skypetm.com.tw2013-12-11198.100.121.15
margo.skypetm.com.tw2014-05-09113.10.169.162
qinoo.skypetm.com.tw2014-12-14113.10.240.54
ripper.skypetm.com.tw2014-12-1467.198.154.246
super.skypetm.com.tw2014-12-14211.75.195.1
sophos.skypetm.com.tw2014-12-14127.0.0.1
supports.skypetm.com.tw2014-07-172.3.5.7
killerhost.skypetm.com.tw2013-04-01113.10.240.54
aniu.skypetm.com.tw2013-05-2861.220.44.244
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information