Help RSS API Feed Maltego Contact                        

Domain > feed.networksupdates.com

This indicator is referenced in AlienVault OTX pulse ""

Is this malicious?

Most users have voted this as MALICIOUS

Reports

https://www.arbornetworks.com/blog/asert/flokibot-...    
https://www.proofpoint.com/us/threat-insight/post/...    

Files that talk to feed.networksupdates.com

MD5A/V
dc31516a473d8b9cb634bf1f48a7065f[HW32.Packed.DE99] [Artemis!4A03B999B87C] [Trojan.Injector] [NSIS/Injector.JB] [Trojan-Dropper.Win32.Injector.pvlt] [virus.win32.sality.at] [BehavesLike.ObfusKovter.fc] [W32/Trojan.YGEE-1549] [TR/Injector.jmlid] [Trojan/Win32.Locky.R190066]
4a03b999b87cfe3c44e617ac911a2018[HW32.Packed.DE99] [Artemis!4A03B999B87C] [TROJ_INJECT.YMNOE] [Infostealer.Limitail] [NSIS/Injector.JB] [TROJ_INJECT.YMNOE] [Trojan-Dropper.Win32.Injector.pvlt] [virus.win32.sality.at] [BehavesLike.Win32.BadFile.fc] [Trojan/Win32.Locky.R190066]

Whois

PropertyValue
Email whoisbao@126.com
NameServer NS2.SUSPENDED-DOMAIN.COM
Created 2016-11-07 00:00:00
Changed 2016-11-09 00:00:00
Expires 2017-11-07 00:00:00
Registrar PDR LTD. D/B/A PUBLI