Help RSS API Feed Maltego Contact                        

Domain > ip-addr.es

More information on this domain is in AlienVault OTX

Is this malicious?

Reports

http://malware-traffic-analysis.net/2015/11/12/ind...    
http://researchcenter.paloaltonetworks.com/2015/11...    
http://www.malware-traffic-analysis.net/2015/10/13...    
http://www.malware-traffic-analysis.net/2015/10/16...    
http://www.malware-traffic-analysis.net/2015/10/18...    
http://www.malware-traffic-analysis.net/2015/10/20...    
http://www.malware-traffic-analysis.net/2015/11/15...    
https://otx.alienvault.com/pulse/561d745c67db8c47d...    
https://otx.alienvault.com/pulse/562508c467db8c47d...    
https://otx.alienvault.com/pulse/562787734637f21ec...    
https://otx.alienvault.com/pulse/5628f1124637f21ec...    
https://otx.alienvault.com/pulse/563ca90f67db8c7a1...    
https://otx.alienvault.com/pulse/5644e3154637f2388...    
https://otx.alienvault.com/pulse/564a34514637f2388...    

Files that talk to ip-addr.es

MD5A/V
ea2d03fe41db2ff3e5b29c1a08c84217[TR/Crypt.ZPACK.125365] [TrojanRansom.Crowti.A4] [Win32/Kryptik.CWZM] [W32/Kryptik.CXBS!tr] [Crypt3.BXSF] [Trojan.Win32.Crypt] [Ransom*Win32/Crowti.A*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
1de86948dd9570631ecdefe9b5996847[TR/Crypt.Xpack.138415] [Win32/Tnega.cKUZYdD] [Win32/Kryptik.DAVX] [W32/Kryptik.CWSU!tr] [Crypt3.BWMP] [Trojan.Win32.Crypt] [Ransom-FWE!1DE86948DD95] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-Z] [Trojan.Asprox.B]
829cd977ecb35878443c0cbb2dd2af35[TR/Crypt.Xpack.139927] [Win32/Tnega.UDAVCWB] [TrojanRansom.Crowti.A4] [Win32/Kryptik.CWTY] [W32/Kryptik.CXBS!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWF!829CD977ECB3] [Ransom*Win32/Crowti.A*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
88c8b75a7ca328fce685e2db0515e305[W32.DropperCrowtiG.Trojan] [TrojanDropper.Injector.r6] [Trojan/Filecoder.co] [Trojan.DR.Injector!Ba7sxn34Lec] [W32/Trojan3.OID] [Trojan.Cryptodefense] [ZBot.NLWN] [Trojan-Dropper.Win32.Injector.lnum] [Trojan.Win32.Androm.dpnyzc] [UnclassifiedMalware] [Trojan.Encoder.514] [Dropper.Injector.Win32.66084] [RDN/Spybot.bfr!p] [Troj/HkMain-DE] [W32/Trojan.UAVY-7015] [TrojanSpy.Zbot.huus] [Trojan[Spy]/Win32.Zbot] [Ransom:Win32/Crowti.A] [Trojan/Win32.MDA] [TrojanDropper.Injector] [Trojan.Win32.Dropper.lnum] [Win32/Filecoder.CO] [Trojan-Ransom.CryptoWall] [W32/Filecoder.CO!tr]
5e79c6c2ce384ce40b680586d0c98a32[TR/Crypt.Xpack.139709] [Win32/Tnega.IBAaLb] [Trojan.Betabot.3] [Win32/Kryptik.CWSU] [W32/Kryptik.CWSU!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWG!5E79C6C2CE38] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
d38c175edab5b364fe19699932a79331[TR/Crypt.Xpack.90303] [Win32/Tnega.JbVcXI] [Win32/Kryptik.CZAI] [W32/Kryptik.CXRU!tr] [Crypt3.BZQV] [Trojan.Win32.Crypt] [Ransom*Win32/Crowti] [Mal/Wonton-AN]
1013486c1a4c4b60de39fe804c1c6bba[TR/Crypt.Xpack.139709] [Win32/Tnega.IBAaLb] [Win32/Kryptik.CWSU] [W32/Kryptik.CWSU!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWG!1013486C1A4C] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
9f683591b7b156f44c902776a0d75f03[TR/Crypt.Xpack.139709] [Win32/Tnega.IBAaLb] [Win32/Kryptik.CWSU] [W32/Kryptik.CWSU!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWG!9F683591B7B1] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
6c3e6143ab699d6b78551d417c0a1a45
ec8f375201e7fc6d1442c6ce573d0727[W32.RansomBlockerAT.Trojan] [Trojan.Msilobfuscator.WR3] [Trojan.Tinba] [Trojan.Win32.Blocker.dpuktq] [Win32/Crowti.eUMQUPD] [TROJ_CRYPWALL.TE] [Trojan-Ransom.Win32.Blocker.gtkx] [Trojan.Blocker!31Cc8700NV8] [UnclassifiedMalware] [Trojan.DownLoader12.49379] [Trojan.Blocker.Win32.27183] [RDN/Spybot.bfr!p] [Mal/MSIL-NO] [W32/Trojan.MILC-6478] [Trojan[Ransom]/Win32.Blocker] [Ransom:Win32/Crowti] [Trojan/Win32.Blocker] [Hoax.Blocker] [Trojan.Win32.Ransomlock.gtkx] [Trojan-Ransom.CryptoWall] [W32/Blocker.GTKX!tr] [Inject2.BVCM] [Trj/Chgt.O]
06b4b16ce0ad5d1be4ab1c30a7785ba0[Trojan.Lethic.B4] [Trojan.Win32.Cryptodef.dnpiox] [Trojan.Cryptodefense] [Kryptik.CEWW] [Win32/Tnega.MNUGDaB] [Trojan-Ransom.Win32.Cryptodef.cfk] [Trojan.Cryptodef!] [Trojan.Win32.Fosniw.121856[h]] [Mal/Wonton-AN] [TrojWare.Win32.Ropest.AK] [Trojan.Foreign.Win32.48108] [Trojan/Foreign.aqfh] [Trojan[Ransom]/Win32.Foreign] [Ransom:Win32/Crowti] [Worm/Win32.Ngrbot] [Hoax.Cryptodef] [Trj/Chgt.O] [Win32.Trojan.Cryptodef.Glo] [Trojan.Win32.Crypt] [W32/Cryptodef.AN!tr] [Win32/Cryptor] [Trojan.Win32.Ransom.cfk]
3ff2d7c5b497467b1aaf3441391cf597[W32.CripisaoA.Trojan] [TrojanRansom.Cryptodef.r4] [Trojan.Ransom.ED] [Trojan/Filecoder.co] [Trojan.Cryptodef!] [W32/S-5799ca41!Eldorado] [Suspicious.MH690.A] [Trojan-Ransom.Win32.Cryptodef.cio] [Troj/Ransom-AGU] [UnclassifiedMalware] [Trojan.Encoder.514] [Trojan.Cryptodef.Win32.298] [Ransom-FTT!3FF2D7C5B497] [Trojan[Ransom]/Win32.Cryptodef] [Ransom:Win32/Crowti.A] [Trojan/Win32.Crowti] [BScope.TrojanRansom.Cryptowall] [Trojan.Win32.Filecoder] [W32/Cryptodef.AGU!tr] [FileCryptor.VX] [Trojan.Win32.Ransom.cio] [Win32/Trojan.1a7]
bf184f005668f82447ea7d7b20166249[HW32.Packed.3B0C] [Artemis!BF184F005668] [WS.Reputation.1] [TROJ_FORUCON.BMC] [Trojan-Spy.Win32.Zbot.gsj] [Trojan.Win32.Zbot.drcamy] [Win32.Trojan-spy.Zbot.Pgmq] [Mal/MSIL-OG] [Trojan.Zbot.Win32.178727] [TrojanSpy.Zbot.hwit] [TR/Dropper.MSIL.152059] [Trojan[Spy]/Win32.Zbot] [Ransom:Win32/Crowti] [Trojan.Win32.Zbot.gsj] [Win32/Filecoder.CO] [Trojan.Win32.Filecoder] [W32/Filecoder.CO!tr] [Trj/Chgt.O]
2653b0e170899c2b5eab42d5c2f618c3[W32.RansomBlockerAQ.Trojan] [Ransom.Crowti.A3] [Trojan.MSIL.ED] [Dropper.Injector.Win32.66018] [Trojan.DR.Injector!g24XLc/1aCI] [W32/S-363fb959!Eldorado] [Trojan.Cryptodefense] [TROJ_CRYPWALL.XXQD] [Trojan-Dropper.Win32.Injector.logs] [Trojan.Win32.Injector.dpuyfn] [Mal/MSIL-NR] [UnclassifiedMalware] [Trojan.DownLoader12.51639] [BackDoor-FCPD!2653B0E17089] [TR/Dropper.MSIL.139104] [Trojan[Dropper]/Win32.Injector] [Ransom:Win32/Crowti] [Trojan/Win32.Ransom] [TrojanDropper.Injector] [Trj/CI.A] [Trojan-Ransom.CryptoWall] [W32/ITT.XXQD!tr] [MSIL7.BBTI] [Trojan.Win32.Dropper.logs]
b57261e61e1593d2db3e4ee8d5a67a22[TR/Crypt.Xpack.139927] [Win32/Tnega.UDAVCWB] [TrojanRansom.Crowti.A4] [Win32/Kryptik.CWTY] [W32/Kryptik.CXBS!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWF!B57261E61E15] [Ransom*Win32/Crowti.A*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
dc604cc2ab66e0032438fc9fc5fac14a[Ransom.CryptoWall.A4] [Kryptik.CFAG] [Win32/Crowti.fGDdOb] [Trojan.Win32.DownLoader12.dpllqg] [Mal/Wonton-AU] [UnclassifiedMalware] [Trojan.DownLoader12.39576] [Trojan.Kryptik.Win32.702453] [W32/Trojan.XCLR-7772] [Trojan/Blocker.ahib] [Ransom:Win32/Crowti] [Trojan/Win32.Kryptik] [Adware.Win32.iBryte.DCDL] [Trojan.Win32.Crypt] [W32/Kryptik.DBBA!tr] [Inject2.BTTP] [Trj/Chgt.O]
fc7ce2f21e8366b9c671241a3cf5195c[TR/Crypt.Xpack.138415] [Win32/Tnega.cKUZYdD] [Win32/Kryptik.DAVX] [W32/Kryptik.CWSU!tr] [Crypt3.BWMP] [Trojan.Win32.Crypt] [Ransom-FWE!FC7CE2F21E83] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-Z] [Trojan.Asprox.B]
35dbf14ccd580c19ade8b4378b7ef228[Trojan.Msilobfuscator.WR3] [RDN/Ransom!eu] [Trojan.MSIL.ED] [Trojan.Blocker!abaiAG0e3v8] [W32/S-e370a845!Eldorado] [TROJ_CRYPTOWALL.M] [Trojan-Ransom.Win32.Blocker.gsxf] [Trojan.Win32.Blocker.dpmdcp] [Mal/MSIL-NO] [UnclassifiedMalware] [Packed:MSIL/ILCrypt.A] [Trojan.Encoder.514] [Trojan.Blocker.Win32.27272] [Trojan/Blocker.ahuz] [TR/Dropper.MSIL.137814] [Trojan[Ransom]/Win32.Blocker] [Ransom:Win32/Crowti] [Trojan/Win32.Crowti] [Hoax.Blocker] [Trojan.Win32.Ransomlock.gsxf] [Trojan.MSIL.Injector] [MSIL/Injector.IQQ!tr] [Filecoder.R] [Trj/CI.A]
ef466d9b0cebfcbae016649d34a161b6[Trojan.Msilobfuscator.WR3] [Trojan.MSIL.ED] [Trojan.Blocker.Win32.27158] [Trojan/Filecoder.co] [Trojan.Win32.Blocker.dpatza] [Win32/Tnega.PYDTUGC] [TROJ_CRYPWALL.YOE] [Trojan-Ransom.Win32.Blocker.gqkg] [Trojan.Blocker!rQAAhUKfRmY] [Mal/MSIL-NB] [TrojWare.Win32.Filecoder.a] [Trojan.Encoder.514] [BehavesLike.Win32.Trojan.cc] [W32/Trojan.KSUS-1376] [Trojan/Blocker.agya] [TR/Dropper.MSIL.130439] [Trojan[Ransom]/Win32.Blocker] [Ransom:Win32/Crowti] [RDN/Spybot.bfr!p] [TScope.Trojan.MSIL] [Trojan.Win32.Ransomlock.gqkg] [Win32/Filecoder.CO] [Trojan-Ransom.CryptoWall3] [W32/Blocker.GQKG!tr] [MSIL7.AEWN] [Trj/Chgt.O]
a27a377c673b0d9cf709cc413924037c[TR/Crypt.ZPACK.125052] [TrojanRansom.Crowti.A4] [Trojan.Encoder.514] [Win32/Kryptik.CWWK] [W32/Kryptik.CXFI!tr] [Crypt3.BXBZ] [Trojan.Crypt] [Ransom*Win32/Crowti.A*Trojan*Win32/Fleercivet.D] [Infostealer.Limitail]

DNS Resolutions

DateIP Address
2015-03-08188.165.164.184 (ClassC)
2016-02-12216.146.38.70 (ClassC)
2016-12-0764.182.208.181 (ClassC)
2019-05-22127.0.0.1 (ClassC)
2025-08-24188.165.164.184 (ClassC)

Subdomains

DateDomainIP
www.ip-addr.es2020-01-07127.0.0.1
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information