Help RSS API Feed Maltego Contact                        

Domain > swchoco.codns.com

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to swchoco.codns.com

MD5A/V
cabf23f0c3f932d4a5a0335b86f8b79d[Win32/Smalldoor.UZ] [Backdoor.Overie!486D] [RDN/Downloader.a!uq] [TR/Spy.109568.200] [Virus.EC90@2FF50FF15@124.mg] [Win32/ServStart.AD] [Flooder.MFJ] [Backdoor.Nitol] [DDoS*Win32/Nitol.A] [Trojan.ServStart] [Trojan.Win32.ServStart] [WORM_NITOL.SMB] [Troj/Dloadr-DNE] [Trojan.ServStart.A4] [Trojan.DownLoader10.22140]
58abb369686a8838e1054b1376bcb693[Win32/Smalldoor.UZ] [Trojan.Click3.7576] [TScope.Trojan.VB] [Trojan.ServStart.A4] [Troj/Dloadr-DNE] [WORM_NITOL.SMB] [Trojan.Win32.Writos.rdp] [Trojan.Writos.Win32.821] [Trojan.Win32.ServStart] [Trojan*Win32/Bagsu!rfn] [VB2.AECS] [Win32/ServStart.AD] [Trojan.Writos.rdp.qzsi] [TR/Spy.109568.200] [RDN/Downloader.a!uq] [Backdoor.Overie!486D]
c3daaf225ed20a7a2757467efd7619f8[Win32/ServStart.AD] [SHeur4.BCZL] [W32/ServStart.AS!tr] [DDoS*Win32/Nitol.A] [W32/S-0c93dfc7!Eldorado] [Trojan.Win32.ServStart] [Trojan.DownLoader4.49535]
0f42e4d9ccb801a7b558f03d0a702bc7[Backdoor.ADAD@240FF53#00.mg] [Win32/ServStart.AD] [Downloader] [W32/ServStart.AS!tr] [TrojanDownloader*Win32/Yemrok.A] [Backdoor.Win32.PcClient] [DDOS_HPNITOL.SM] [Mal/Packer] [Ddos.Nitol.018956] [Trojan.DownLoader4.49535]

Whois

PropertyValue
Email manager@nehom.com
NameServer NS3.CODNS.COM
Created 2000-06-28 00:00:00
Changed 2014-06-28 00:00:00
Expires 2019-06-28 00:00:00
Registrar INAMES CO., LTD.