Help RSS API Feed Maltego Contact                        

Domain > wefindco.com

More information on this domain is in AlienVault OTX

Is this malicious?

Reports

http://malware-traffic-analysis.net/2016/02/03/ind...    
https://otx.alienvault.com/pulse/56affb4c4637f2355...    
https://otx.alienvault.com/pulse/56b2251167db8c168...    
https://otx.alienvault.com/pulse/56b2572767db8c168...    
https://ransomwaretracker.abuse.ch/downloads/RW_UR...    
https://techhelplist.com/spam-list/1039-money-tran...    
https://www.virustotal.com/en/file/a5a5b9e1e629a37...    

Files that talk to wefindco.com

MD5A/V
2c17ca4c2e05ef0551d7618a243466f6[BehavesLike.Win32.AdwareNaviPromo.fh]
a95ffcb339e7daa98a2f68b65eeb64f1[BehavesLike.Win32.Dropper.dh]
4b3a65c38e75d95843a9c165961ad34c[BehavesLike.Win32.Dropper.dh]
e2cf4230402ab26407a344697e67c243[Win32.Trojan.Bp-dropperv.Bzmy] [BehavesLike.Win32.Dropper.dh]
201203d5caa58c3378a75a11c0f45b3e
4c3a6b40a7dbdc977f68c149278561c0[Troj.Downloader.Script!c] [VBS/Psyme] [JS/TrojanDownloader.Nemucod.DQ] [JS_CRYPLOD.YYSJR] [VBS.Downloader.877[h]] [JS_CRYPLOD.YYSJR] [Win32.Trojan.Raas.Auto]
ca05942d7d363c62caba7fe0c66e7770
1680835ab6998271127b9d172cf1c691[Suspicious.Cloud.2] [Trojan/Win32.Teslacrypt]
49b620989c6b52ead93430b7685812da[BehavesLike.JS.Downloader.xv]
f6a8270cb3b95ffaa8247f5a39181729[Trojan/Win32.Teslacrypt]
2b8238af766a56adbd80791bc1db61c5
54ab4e1834a1d6b27b8262c05c13a926
daa226bf52632cd0346dc33af9de0d0b
6e582dcada3d533f1ef01e4d79bf5e04
3ea78b0ba30e7adee892bf1360494007
0d648fd1aa0e41715a5684d3cf5ebcd3
c1b9f230e529e85cd7ba0c86e6ec0be6[Trojan/Win32.Teslacrypt]
1c7c453846fe873d430decc502fff97f
1c1187c0dbf9cdf8d113aa3bd42d7b3b
f94764141525ee06dd2a50cc76427eb4

Whois

PropertyValue
NameServer NS62.DOMAINCONTROL.COM
Created 2015-06-09 00:00:00
Changed 2015-06-09 00:00:00
Expires 2016-06-09 00:00:00
Registrar GODADDY.COM, LLC

DNS Resolutions

DateIP Address
2015-06-11206.190.152.224 (ClassC)
2016-03-23107.182.238.196 (ClassC)
2019-01-28204.11.56.48 (ClassC)
2019-06-08204.11.56.46 (ClassC)
2019-09-07208.91.197.46 (ClassC)
2024-12-23104.155.138.21 (ClassC)
2025-01-24107.178.223.183 (ClassC)
2025-05-3134.136.111.81 (ClassC)
2025-06-1434.132.102.6 (ClassC)
2025-08-2534.41.139.193 (ClassC)
2025-10-0175.2.18.233 (ClassC)
2025-12-0352.201.53.166 (ClassC)
2025-12-2998.82.42.139 (ClassC)
2026-01-1554.243.117.197 (ClassC)

Port 80

View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information