Help RSS API Feed Maltego Contact                        

Domain > myexternalip.com

This indicator is referenced in AlienVault OTX pulse ""

Is this malicious?

Most users have voted this as MALICIOUS

Reports

http://researchcenter.paloaltonetworks.com/2015/11...    
http://www.malware-traffic-analysis.net/2015/09/16...    
http://www.malware-traffic-analysis.net/2015/09/29...    
http://www.malware-traffic-analysis.net/2015/10/23...    
http://www.malware-traffic-analysis.net/2015/10/27...    
https://otx.alienvault.com/pulse/55f9a89967db8c6fb...    
https://otx.alienvault.com/pulse/560ad29d67db8c47d...    
https://otx.alienvault.com/pulse/5632c56c4637f2388...    
https://otx.alienvault.com/pulse/5632c59d4637f2388...    
https://otx.alienvault.com/pulse/563ca90f67db8c7a1...    
https://otx.alienvault.com/pulse/5668ab624637f27ed...    
https://otx.alienvault.com/pulse/566f48644637f2563...    
https://otx.alienvault.com/pulse/567a02ed67db8c417...    
https://otx.alienvault.com/pulse/5689799b4637f2624...    
https://blogs.sophos.com/2016/01/06/the-current-st...    
http://pastebin.com/d4EpJQgR    
https://portal.cybersecurity.mo.gov/util/url_black...    
https://techhelplist.com/spam-list/1005-agri-basic...    
https://techhelplist.com/spam-list/997-your-order-...    
https://twitter.com/Techhelplistcom/status/6793766...    
https://www.hybrid-analysis.com/sample/84dc3b2322e...    

Files that talk to myexternalip.com

MD5A/V
ea2d03fe41db2ff3e5b29c1a08c84217[TR/Crypt.ZPACK.125365] [TrojanRansom.Crowti.A4] [Win32/Kryptik.CWZM] [W32/Kryptik.CXBS!tr] [Crypt3.BXSF] [Trojan.Win32.Crypt] [Ransom*Win32/Crowti.A*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
1de86948dd9570631ecdefe9b5996847[TR/Crypt.Xpack.138415] [Win32/Tnega.cKUZYdD] [Win32/Kryptik.DAVX] [W32/Kryptik.CWSU!tr] [Crypt3.BWMP] [Trojan.Win32.Crypt] [Ransom-FWE!1DE86948DD95] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-Z] [Trojan.Asprox.B]
829cd977ecb35878443c0cbb2dd2af35[TR/Crypt.Xpack.139927] [Win32/Tnega.UDAVCWB] [TrojanRansom.Crowti.A4] [Win32/Kryptik.CWTY] [W32/Kryptik.CXBS!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWF!829CD977ECB3] [Ransom*Win32/Crowti.A*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
5e79c6c2ce384ce40b680586d0c98a32[TR/Crypt.Xpack.139709] [Win32/Tnega.IBAaLb] [Trojan.Betabot.3] [Win32/Kryptik.CWSU] [W32/Kryptik.CWSU!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWG!5E79C6C2CE38] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
d38c175edab5b364fe19699932a79331[TR/Crypt.Xpack.90303] [Win32/Tnega.JbVcXI] [Win32/Kryptik.CZAI] [W32/Kryptik.CXRU!tr] [Crypt3.BZQV] [Trojan.Win32.Crypt] [Ransom*Win32/Crowti] [Mal/Wonton-AN]
1013486c1a4c4b60de39fe804c1c6bba[TR/Crypt.Xpack.139709] [Win32/Tnega.IBAaLb] [Win32/Kryptik.CWSU] [W32/Kryptik.CWSU!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWG!1013486C1A4C] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
9f683591b7b156f44c902776a0d75f03[TR/Crypt.Xpack.139709] [Win32/Tnega.IBAaLb] [Win32/Kryptik.CWSU] [W32/Kryptik.CWSU!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWG!9F683591B7B1] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
316dbc992b37e19fb6741f286b96c5d4
b57261e61e1593d2db3e4ee8d5a67a22[TR/Crypt.Xpack.139927] [Win32/Tnega.UDAVCWB] [TrojanRansom.Crowti.A4] [Win32/Kryptik.CWTY] [W32/Kryptik.CXBS!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWF!B57261E61E15] [Ransom*Win32/Crowti.A*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
fc7ce2f21e8366b9c671241a3cf5195c[TR/Crypt.Xpack.138415] [Win32/Tnega.cKUZYdD] [Win32/Kryptik.DAVX] [W32/Kryptik.CWSU!tr] [Crypt3.BWMP] [Trojan.Win32.Crypt] [Ransom-FWE!FC7CE2F21E83] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-Z] [Trojan.Asprox.B]
fdbe707910870ba2467596164e8e5222
a27a377c673b0d9cf709cc413924037c[TR/Crypt.ZPACK.125052] [TrojanRansom.Crowti.A4] [Trojan.Encoder.514] [Win32/Kryptik.CWWK] [W32/Kryptik.CXFI!tr] [Crypt3.BXBZ] [Trojan.Crypt] [Ransom*Win32/Crowti.A*Trojan*Win32/Fleercivet.D] [Infostealer.Limitail]
e6b37becbc6fae7e58db75e9b2a66934[TR/Crypt.Xpack.75480] [W32/Kryptik.CXRU!tr] [Crypt3.BZQV] [Trojan.Win32.Crypt] [Trojan-Ransom.Win32.Foreign.lmkk] [Ransom*Win32/Crowti.A] [Mal/Wonton-AN]
8a50a392b230b67e6e5e0f7002bdbff0[TR/Crypt.Xpack.138415] [Win32/Tnega.cKUZYdD] [Trojan.DownLoad3.35619] [Win32/Kryptik.DAVX] [W32/Kryptik.CWSU!tr] [Crypt3.BWMP] [Trojan.Win32.Crypt] [Ransom-FWE!8A50A392B230] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-Z] [Trojan.Asprox.B]
bed8dbc8379dd8294e74582a82544676[TR/Crypt.Xpack.139709] [Win32/Tnega.IBAaLb] [Win32/Kryptik.CWSU] [W32/Kryptik.CWSU!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWG!BED8DBC8379D] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
ca51840439d19e70001c4e8038b7c102[TR/Crypt.Xpack.139709] [Win32/Tnega.IBAaLb] [Win32/Kryptik.CWSU] [W32/Kryptik.CWSU!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWG!CA51840439D1] [Ransom*Win32/Crowti*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
8ea6b7d90d3a25f743af9f70f1387689[Trojan.MSIL.Kryptik.bjh] [Tool.MailPassView.236] [Mal/Limitles-A] [Artemis!8EA6B7D90D3A] [MSIL6.EMJ]
f6ce84c87e4b438380a58d64291cd085[TR/Crypt.ZPACK.125365] [TrojanRansom.Crowti.A4] [Trojan.Packed.18626] [Win32/Kryptik.CWZM] [W32/Kryptik.CXBS!tr] [Crypt3.BXSF] [Trojan.Win32.Crypt] [Ransom*Win32/Crowti.A*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
ed526538cfac7e20609543542bc87c50[TR/Crypt.Xpack.140093] [Win32/Tnega.dHROTLB] [Win32/Kryptik.CWSU] [W32/Kryptik.CWSU!tr] [Win32/Cryptor] [Trojan.Win32.Crypt] [Ransom-FWG!ED526538CFAC] [Ransom*Win32/Crowti.A*Trojan*Win32/Fleercivet.D] [Mal/Wonton-AN] [Trojan.Asprox.B]
a746353639462342a94f006041e0dfcf[TR/Crypt.ZPACK.71793] [W32/Kryptik.CXRB!tr] [Crypt3.BZOM] [Trojan.Win32.Crypt] [Trojan-Ransom.Win32.Foreign.lmjn] [Ransom-FWP!A74635363946] [Trojan*Win32/Fleercivet] [Mal/Wonton-AN]

Whois

PropertyValue
Email info@2hoch5.com
NameServer ROBOTNS2.SECOND-NS.DE
Created 2010-08-02 00:00:00
Changed 2014-08-03 00:00:00
Expires 2015-08-02 00:00:00
Registrar HETZNER ONLINE AG

DNS Resolutions

DateIP Address
2015-02-2681.169.172.124 (ClassC)
2018-12-2778.47.139.102 (ClassC)
2020-09-11216.239.32.21 (ClassC)
2020-11-30216.239.36.21 (ClassC)
2020-12-20216.239.34.21 (ClassC)
2021-02-17216.239.38.21 (ClassC)
2021-03-2634.117.59.81 (ClassC)
2024-07-1134.117.118.44 (ClassC)
2025-08-2034.160.111.145 (ClassC)

Port 80

Port 443

Subdomains

DateDomainIP
4.myexternalip.com2024-07-0534.117.118.44
v4.myexternalip.com2024-06-2634.117.118.44
ipv4.myexternalip.com2024-06-2634.117.118.44
6.myexternalip.com2024-07-1334.117.118.44
ipv6.myexternalip.com2024-09-1434.160.111.145
api.myexternalip.com2025-01-2234.160.111.145
w.myexternalip.com2024-12-2834.160.111.145
ww.myexternalip.com2024-12-2834.160.111.145
www.myexternalip.com2015-05-1781.169.172.124
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information