Help RSS API Feed Maltego Contact                        

Domain > www.zeuwran.exofire.com

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to www.zeuwran.exofire.com

MD5A/V
a9b7afd6a55ce0ec41f589efef6d0783[PWS*Win32/Wowsteal.AA] [TR/PWS.Wow.A]
a90d46cc457de06077c5cddf5aee1442[Win32/Sality] [Virus*Win32/Sality.AU]
31c9b3ae311ff6b2a9be73eee5156a22[TR/PWS.Wow.A]
a56976e201d1eb939dbb12dc624af1c1[PWS*Win32/Wowsteal.AA]
44a462d875501c76381e05932a25b116[W32/Worm.NTCX-2095] [TR/PWS.Wow.A] [Win32/Cutwail.AQB] [Trojan.PWS.Stealer.116] [W32/Worm.BIRK] [P2P-Worm.Win32.Deecee] [Trojan-Dropper.Win32.Dorifel.ahkw] [PWS*Win32/Wowsteal.AA] [Trojan.Win32.Delf.fxm] [Troj/WowStl-A] [WORM_DEECEE.B] [P2P-Worm.Deecee]
67793d9130666136cb26918393625ce9[PWS*Win32/Wowsteal.AA] [TR/PWS.Wow.A]
bd077854406c33de204e9321ac1761fd
e2b0606a8041513986c68f5026146cd9[Trojan.Downloader-94073] [I-Worm/Delf.KG] [WORM/Deecee.A.9] [PWS-OnlineGames.em] [PWS*Win32/Wowsteal.AA]
ffb93ec4947b273e7294046be7cd9f01[PWS*Win32/Wowsteal.AA]
2c4b3b3fb895cb12cec53eef8d0f15be[W32/Worm.NTCX-2095] [TR/PWS.Wow.A] [Win32/Cutwail.AQB] [Trojan.PWS.Stealer.116] [W32/Worm.BIRK] [P2P-Worm.Win32.Deecee] [Trojan-Dropper.Win32.Dorifel.ahkw] [PWS*Win32/Wowsteal.AA] [Trojan.Win32.Delf.fxm] [Troj/WowStl-A] [WORM_DEECEE.B] [P2P-Worm.Deecee]

Whois

PropertyValue
Email PRIVACY@PROXYTECH.COM
NameServer NS2.POWER-DNS.COM
Created 2007-01-21 00:00:00
Changed 2015-03-04 00:00:00
Expires 2016-01-21 00:00:00
Registrar ENOM, INC.

DNS Resolutions

DateIP Address
2014-04-1698.124.199.1 (ClassC)
2014-04-1898.124.198.1 (ClassC)
2014-04-2498.124.198.1 (ClassC)
2015-02-058.5.1.30 (ClassC)
2015-02-098.5.1.30 (ClassC)
2015-05-15-
2018-04-0435.182.185.60 (ClassC)
2020-02-2615.222.229.152 (ClassC)
2023-12-0299.79.130.80 (ClassC)
2023-12-193.98.133.153 (ClassC)
2024-01-0915.156.145.62 (ClassC)
2024-01-293.98.61.186 (ClassC)
2024-03-1752.60.75.200 (ClassC)
2024-03-303.97.146.112 (ClassC)
2024-04-0799.79.95.2 (ClassC)
2024-05-033.98.14.216 (ClassC)
2024-05-2552.60.130.13 (ClassC)
2024-06-1835.183.88.190 (ClassC)
2024-07-0315.157.123.91 (ClassC)
2024-07-183.97.24.183 (ClassC)
2024-07-2315.156.176.115 (ClassC)
2024-08-1135.183.214.74 (ClassC)
2024-08-2752.60.81.137 (ClassC)
2024-09-0115.157.89.240 (ClassC)
2024-10-183.98.246.31 (ClassC)
2024-11-1499.79.1.155 (ClassC)
2024-11-2215.156.229.150 (ClassC)
2025-01-053.99.69.228 (ClassC)
2025-01-2315.157.250.185 (ClassC)
2025-04-2215.157.56.239 (ClassC)
2025-04-263.97.156.204 (ClassC)
2025-05-223.97.89.198 (ClassC)
2025-05-3035.182.168.105 (ClassC)
2025-07-0515.157.145.169 (ClassC)
2025-08-303.98.181.85 (ClassC)
2025-09-2316.52.0.243 (ClassC)
2026-01-2416.54.22.158 (ClassC)

Port 80

Subdomains

DateDomainIP
www.endrothkel.exofire.com2014-04-2498.124.198.1
www.zeuwran.exofire.com2014-04-2498.124.198.1
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information