Help
RSS
API
Feed
Maltego
Contact
Domain > www.lisword.com
×
This indicator is
referenced
in AlienVault OTX pulse ""
Is this malicious?
Yes
No
Most users have voted this as
MALICIOUS
Reports
https://otx.alienvault.com/pulse/553e18f9b45ff54b6...
https://www2.fireeye.com/rs/fireye/images/rpt-apt3...
Files that talk to www.lisword.com
MD5
A/V
0a4fdacde69a566f53833500a0d53a35
010ca5e1de980f5f45f9d82027e1606c
[
W32/S-2819558c!Eldorado
] [
TR/Graftor.87826.6
] [
TrojanAPT.LecnaCBack.MUE.Z3
] [
Win.Trojan.Backspace
] [
Trojan.DownLoader7.62432
] [
Win32/Lecna.AI
] [
Luhe.Fiha.A
] [
Trojan.Win32.Swisyn
] [
Trojan.Downloader
] [
Downloader-FAQF!010CA5E1DE98
] [
Backdoor*Win32/Lecna.H!dha
] [
Troj/Lecna-S
] [
W32.Baksaz
]
4e5c116d874bbaaf7d6dadec7be926f5
[
W32/Backdoor.FFOQ-4061
] [
BDS/Lecna.4915.4
] [
TrojanAPT.LecnaCBack.MUE.Z3
] [
Win.Trojan.Backspace
] [
BackDoor.Dizhi.109
] [
Win32/Lecna.B
] [
W32/Lecna.DK!tr.bdr
] [
W32/Backdoor2.HBSF
] [
Backdoor.Win32.Lecna
] [
Trojan.Win32.Fsysna.td
] [
Trojan.FakeMS.EDIE
] [
BackDoor-FCNM!4E5C116D874B
] [
Backdoor*Win32/Lecna.M!dha
] [
Troj/Lecna-Q
] [
W32.Baksaz
] [
Backdoor.1F5037CFAFA1370F
]
6791254f160e98ac1f46b4d506b695ad
[
W32/S-2819558c!Eldorado
] [
TR/Rogue.982386.1
] [
TrojanAPT.LecnaCBack.MUE.Z3
] [
Win.Trojan.Backspace
] [
Trojan.DownLoader7.62432
] [
Win32/Lecna.AI
] [
W32/Lecna.AF
] [
Luhe.Fiha.A
] [
Trojan.Win32.Swisyn
] [
Trojan.Downloader
] [
Downloader-FAQF!6791254F160E
] [
Backdoor*Win32/Lecna.H!dha
] [
Troj/Lecna-S
] [
W32.Baksaz
] [
Trojan.B16C86ADCF8A9241
]
4b8531d294c020d5f856b58a5a23b238
[
W32/S-2819558c!Eldorado
] [
TR/Graftor.87826
] [
TrojanAPT.LecnaCBack.MUE.Z3
] [
Win.Trojan.Backspace
] [
Trojan.DownLoader7.62432
] [
Win32/Lecna.AI
] [
Luhe.Fiha.A
] [
Trojan.Win32.Swisyn
] [
Trojan.Downloader
] [
Downloader-FAQF!4B8531D294C0
] [
Backdoor*Win32/Lecna.H!dha
] [
Troj/Lecna-Q
] [
W32.Baksaz
]
Whois
Property
Value
Email
web@163ns.com
NameServer
DNS2.51DNS.TOP
Created
2008-03-07 00:00:00
Changed
2015-03-13 00:00:00
Expires
2016-03-07 00:00:00
Registrar
JIANGSU BANGNING SCI
DNS Resolutions
Date
IP Address
2013-05-27
221.231.138.41
(
ClassC
)
2016-07-20
123.60.70.26
(
ClassC
)
2017-02-28
198.11.172.242
(
ClassC
)
2017-06-01
13.112.234.189
(
ClassC
)
2017-08-29
54.172.131.220
(
ClassC
)
2017-10-31
52.71.185.125
(
ClassC
)
2018-02-15
54.164.198.60
(
ClassC
)
2018-03-28
54.175.183.209
(
ClassC
)
2018-04-24
52.86.22.136
(
ClassC
)
2018-05-26
54.174.212.152
(
ClassC
)
2018-06-07
54.208.174.161
(
ClassC
)
2018-06-09
54.80.72.81
(
ClassC
)
2018-06-23
52.5.103.164
(
ClassC
)
2018-06-28
52.73.115.80
(
ClassC
)
2018-06-28
52.55.168.146
(
ClassC
)
2018-07-30
52.72.89.116
(
ClassC
)
2018-07-30
52.5.142.190
(
ClassC
)
2018-08-12
52.6.128.155
(
ClassC
)
2018-08-12
52.54.24.134
(
ClassC
)
2018-08-23
54.208.75.210
(
ClassC
)
2018-08-23
52.6.224.208
(
ClassC
)
2018-08-29
54.174.45.28
(
ClassC
)
2018-09-05
52.7.6.73
(
ClassC
)
2018-09-18
54.152.137.87
(
ClassC
)
2018-10-06
52.6.46.72
(
ClassC
)
2018-10-10
52.87.45.42
(
ClassC
)
2018-10-10
52.5.251.20
(
ClassC
)
2018-10-23
54.144.21.246
(
ClassC
)
2018-10-31
52.55.164.156
(
ClassC
)
2018-10-31
52.54.154.33
(
ClassC
)
2018-11-07
52.22.89.169
(
ClassC
)
2018-11-14
52.6.234.76
(
ClassC
)
2018-11-26
54.208.56.179
(
ClassC
)
2018-11-26
52.73.179.54
(
ClassC
)
2018-11-30
54.165.193.163
(
ClassC
)
2018-11-30
52.86.122.241
(
ClassC
)
2019-10-25
23.20.239.12
(
ClassC
)
2021-02-23
3.223.115.185
(
ClassC
)
2021-11-24
54.152.178.215
(
ClassC
)
2021-11-26
52.2.147.58
(
ClassC
)
2023-12-12
3.130.253.23
(
ClassC
)
2023-12-17
52.86.6.113
(
ClassC
)
2024-03-30
54.161.222.85
(
ClassC
)
2024-04-17
18.119.154.66
(
ClassC
)
2024-06-16
3.130.204.160
(
ClassC
)
2024-06-20
3.94.41.167
(
ClassC
)
2024-07-15
3.18.7.81
(
ClassC
)
2024-08-01
34.205.242.146
(
ClassC
)
2024-08-07
52.71.57.184
(
ClassC
)
2024-08-10
3.140.13.188
(
ClassC
)
2024-08-17
3.19.116.195
(
ClassC
)
2025-08-01
104.21.51.40
(
ClassC
)
2025-08-24
172.67.220.180
(
ClassC
)
Port 80
HTTP/1.1 302 FoundCache-Control: privateContent-Type: text/html; charsetutf-8Location: https://www.hugedomains.com/domain_profile.cfm?dlisword&ecomServer: Microsoft-IIS/8.5X-Powered-By: ASP.NETDate: W html>head>title>Object moved/title>/head>body>h2>Object moved to a hrefhttps://www.hugedomains.com/domain_profile.cfm?dlisword&ecom>here/a>./h2>/body>/html>
View on OTX
|
View on ThreatMiner
Please enable JavaScript to view the
comments powered by Disqus.
Data with thanks to
AlienVault OTX
,
VirusTotal
,
Malwr
and
others
. [
Sitemap
]