Help RSS API Feed Maltego Contact                        

Domain > ar.rghost.net

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to ar.rghost.net

MD5A/V
c185203cc781e769719054af61522222[TR/Dldr.Bladabindi.A.88] [TrojanDownloader*MSIL/Bladabindi.A]
49debd97285c2374192e4561b00d97b0[Artemis!49DEBD97285C] [Trojan.MSIL.S] [Variant.Adware.Barys] [Trojan.Win32.Llac.dbhuqk] [TrojanDownloader.J] [BehavesLike.Win32.Backdoor.dh] [Trojan.Inject] [Win32/Trojan.1c9]
fae1da877f5fc19e1b6742dadd38d07c
7a7f5361b575265c361383b725791b68
8243b610441dea895bb83290c209e1ab[Artemis!8243B610441D] [Trojan.MSIL.UL] [BehavesLike.Win32.Trojan.mh] [Trojan.MSIL.Kryptik.bIC]
7d03e1fafcd85df8b2cbeddaea9be22f

Whois

PropertyValue
Email contact@realisticgroup.com
NameServer JAKE.NS.CLOUDFLARE.COM
Created 2007-07-15 00:00:00
Changed 2014-05-21 00:00:00
Expires 2016-07-15 00:00:00
Registrar REGTIME LTD.

DNS Resolutions

DateIP Address
2013-08-10217.199.218.100 (ClassC)
2013-10-19217.199.218.102 (ClassC)
2014-02-1989.248.225.50 (ClassC)
2014-10-1989.248.225.50 (ClassC)
2014-10-2689.248.225.51 (ClassC)
2019-09-05104.28.14.51 (ClassC)
2025-08-02172.67.212.239 (ClassC)
2025-08-06104.21.50.229 (ClassC)

Port 443

Subdomains

DateDomainIP
ipv6.rghost.net2025-05-25104.21.50.229
fa.rghost.net2025-06-15104.21.50.229
id.rghost.net2025-05-25104.21.50.229
pl.rghost.net2025-06-27104.21.50.229
ar.rghost.net2013-08-10217.199.218.100
tr.rghost.net2025-06-29172.67.212.239
www.rghost.net2025-04-18172.67.212.239
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information