Help RSS API Feed Maltego Contact                        

Domain > www.18dd.net

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to www.18dd.net

MD5A/V
02acf516d0c18bc102f2692a921f5523[TR/PSW.Delf.AF.2] [W32/HLLP.Philis.kl] [W32.Philis-115] [Worm/Delf.4.J] [Virus*Win32/Viking.JB]
43c6a55ecea2bfcb888aae90b91d8456[W32/HLLP.Philis.kl] [W32.Philis-115] [Worm/Delf.4.J] [Virus*Win32/Viking.JB]
a55a24175142a34f306f399e415f6315[W32/HLLP.Philis.ku] [Worm/Viking.E] [Virus*Win32/Viking.JB] [W32.Philis-115] [WORM/Viking.DLL.1]
398a198301da5d42b53a0074216a35f4[W32/HLLP.Philis.ku] [W32.Philis-115] [WORM/Viking.DLL.1] [Worm/Viking.E] [Virus*Win32/Viking.JB]
37b01134cf1ce6947b2ab6e63d7fd3f3[W32/HLLP.Philis.ku] [W32.Philis-115] [WORM/Viking.DLL.1] [Worm/Viking.E] [Virus*Win32/Viking.JB]
799564249eec6c2f72ae9ab832f8adb7[W32/HLLP.Philis.kl] [W32.Philis-115] [Worm/Delf.4.J] [Virus*Win32/Viking.JB]
3a1d7759ade5848a1f9e111154dc5df0[W32/HLLP.Philis.ku] [W32.Philis-115] [WORM/Viking.DLL.1] [Worm/Viking.E] [Virus*Win32/Viking.JB]
c0399489751adb63e85fb00484b0d75c[W32/HLLP.Philis.ku] [W32.Philis-115] [WORM/Viking.DLL.1] [Worm/Viking.E] [Virus*Win32/Viking.JB]
6b0516e0b1d29108be61036e965571da[TR/PSW.Delf.AF.2] [W32/HLLP.Philis.kl] [W32.Philis-115] [Worm/Delf.4.J]
c73a51442ec28afca55e1766fd457cb9[W32/HLLP.Philis.kl] [W32.Philis-115] [Worm/Delf.4.J] [Virus*Win32/Viking.JB]
ddba57fe73fd09324cc5948a60329845[W32/HLLP.Philis.ku] [W32.Philis-115] [WORM/Viking.DLL.1] [Worm/Viking.E] [Virus*Win32/Viking.JB]
0ad2487f0f96a6a6069036bdb666baa4[W32/HLLP.Philis.kl] [W32.Philis-115] [Worm/Delf.4.J] [Virus*Win32/Viking.JB]
e90d5050487ea1c7a4cec177f670b4eb[W32/HLLP.Philis.ku] [W32.Philis-115] [WORM/Viking.DLL.1] [Worm/Viking.E] [Virus*Win32/Viking.JB]
b39911301fa62faf9e11405cfcea22c1[W32/HLLP.Philis.ku] [W32.Philis-115] [WORM/Viking.DLL.1] [Worm/Viking.E] [Virus*Win32/Viking.JB]
657f7f11aecb4dfe2bcc9a0fbb4df94d[W32/HLLP.Philis.ku] [W32.Philis-115] [WORM/Viking.DLL.1] [Worm/Viking.E] [Virus*Win32/Viking.JB]
66e3a886a2a0fa3a1b1b42087d894399[W32.Clodf6d.Trojan.9cdf] [W32/Delf.bs] [Downloader] [Obfuscated_MA] [TROJ_DELF.IVV] [Worm.Delf-41] [Worm.Win32.Delf.bs] [Trojan.Win32.Delf.onro] [Worm.Win32.S.Delf.16653] [Packed.Win32.Klone.~KMG] [Win32.HLLW.Autoruner] [Heuristic.BehavesLike.Win32.Suspicious-BAY.G] [Trojan/Win32.WOW.gic[GameThief]] [Backdoor:Win32/Hupigon.EA] [Trojan/Win32.OnlineGameHack] [MalwareScope.Trojan-PSW.Game.16] [Win32/Delf.NCY] [Trojan-Downloader.Win32.Mazahaka] [Downloader.Rozena] [Trojan.Win32.Delf.AJ] [Win32/Trojan]
7a180a14b8a57df7e7e444281f2893ad[TR/PSW.Delf.AF.2] [W32/HLLP.Philis.kl] [W32.Philis-115] [Worm/Delf.4.J] [Virus*Win32/Viking.JB]
6f48c8d710404dabeedf5594244b5014[W32/HLLP.Philis.kl] [W32.Philis-115] [Worm/Delf.4.J]
8b535d8260de4cdb8a822fc47025d7e5[W32/HLLP.Philis.kl] [W32.Philis-115] [Worm/Delf.4.J] [Virus*Win32/Viking.JB]
18299616567d19c9bbf3b7c57bde5d71[Worm/Viking.E] [Virus*Win32/Viking.JB] [W32.Philis-115] [WORM/Viking.DLL.1]

Whois

PropertyValue
NameServer PNS2.CLOUDNS.NET
Created 2013-11-04 00:00:00
Changed 2014-10-06 00:00:00
Expires 2015-11-04 00:00:00
Registrar MAFF INC.

DNS Resolutions

DateIP Address
2013-08-16173.208.188.4 (ClassC)
2014-01-0862.116.181.25 (ClassC)
2014-01-08199.59.243.105 (ClassC)
2014-01-08199.59.243.105 (ClassC)
2014-02-19199.59.243.107 (ClassC)
2014-10-24109.201.133.191 (ClassC)
2015-02-08109.201.133.191 (ClassC)
2016-06-04185.34.216.18 (ClassC)
2016-06-08149.56.117.189 (ClassC)
2017-11-14104.18.54.169 (ClassC)
2018-06-09209.99.40.222 (ClassC)
2018-06-19209.99.40.223 (ClassC)
2019-10-07198.54.117.211 (ClassC)
2019-10-07198.54.117.218 (ClassC)
2019-10-07198.54.117.212 (ClassC)
2019-10-07198.54.117.215 (ClassC)
2019-10-07198.54.117.216 (ClassC)
2019-10-07198.54.117.210 (ClassC)
2019-10-07198.54.117.217 (ClassC)
2019-10-11103.254.208.243 (ClassC)
2019-12-09113.52.134.81 (ClassC)
2019-12-09123.176.102.80 (ClassC)
2020-02-2547.56.129.142 (ClassC)
2020-03-17127.0.0.1 (ClassC)
2020-10-17198.54.117.198 (ClassC)
2020-10-17198.54.117.199 (ClassC)
2020-10-17198.54.117.200 (ClassC)
2020-10-17198.54.117.197 (ClassC)
2022-01-05107.148.126.117 (ClassC)
2023-07-31156.234.127.154 (ClassC)
2023-08-15156.234.127.108 (ClassC)
2023-08-25156.234.127.101 (ClassC)
2023-09-02156.234.127.158 (ClassC)
2023-09-02156.234.127.104 (ClassC)
2023-09-03156.234.127.153 (ClassC)
2023-09-08156.234.127.100 (ClassC)
2023-09-25156.234.127.99 (ClassC)
2023-10-21156.234.127.186 (ClassC)
2023-10-29156.234.127.180 (ClassC)
2023-11-02156.251.239.178 (ClassC)
2024-09-0638.173.90.56 (ClassC)
2025-08-1538.174.209.152 (ClassC)

Port 80

Subdomains

DateDomainIP
bodis2.18dd.net2014-08-05109.201.133.191
aa.18dd.net2015-03-25109.201.133.191
cc.18dd.net2014-09-06109.201.133.191
down.18dd.net2015-05-16109.201.133.191
www.18dd.net2014-01-08199.59.243.105
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information