Help RSS API Feed Maltego Contact                        

Domain > sys.firewall-gateway.net

This indicator is referenced in AlienVault OTX pulse ""

Is this malicious?

Most users have voted this as MALICIOUS

Reports

http://blog.cylance.com/puttering-into-the-future    
http://blog.passivetotal.org/scarletcitizen-defens...    
http://researchcenter.paloaltonetworks.com/2016/01...    
https://citizenlab.org/2016/03/shifting-tactics/    
https://otx.alienvault.com/pulse/56965f594637f2624...    
https://otx.alienvault.com/pulse/56a5aa2867db8c6aa...    
https://otx.alienvault.com/pulse/56e17a334637f24cb...    
https://otx.alienvault.com/pulse/56e1d26f4637f24cb...    
https://raw.githubusercontent.com/citizenlab/malwa...    

Files that talk to sys.firewall-gateway.net

MD5A/V
ea45265fe98b25e719d5a9cc3b412d66[Trojan/W32.Inject.18944.S] [Trojan.Inject.r3] [Artemis!EA45265FE98B] [Posible_Worm32] [Trojan.Win32.Inject.cvydsc] [Trojan.Win32.Inject.njpl] [Trojan.Inject!jTqtEv2i6Bs] [UnclassifiedMalware] [Trojan.DownLoader10.5279] [BehavesLike.Win32.Injector.lc] [Trojan/Inject.bmwl] [W32/Injector.BDNV!tr] [Trojan/Win32.Inject] [Win32.Troj.Inject.nd.(kcloud)] [Trojan.Kazy.D37671] [VirTool:Win32/Obfuscator.AID] [Trojan.Inject] [Trj/CI.A] [Win32.Trojan.Inject.Akor] [Trojan.Win32.Inject] [BackDoor.SmallX.BKI] [Trojan.Win32.Inject.njpl] [Win32/Trojan.c0e]

Whois

PropertyValue
NameOliver Hausmann
Organization Securepoint GmbH
Email oliver.hausmann@securepoint.de
Address Salzstr. 1
Zip Code 21335
City Lueneburg
Country DE
NameServer mhwserv01.mhw.de
Created 2010-01-14 20:01:15
Changed 2014-01-15 01:39:58
Expires 2015-01-14 00:00:00
Registrar Ascio Technologies,