Help
RSS
API
Feed
Maltego
Contact
Domain > gotaterra.com
×
More information on this domain is in
AlienVault OTX
Is this malicious?
Yes
No
Files that talk to gotaterra.com
MD5
A/V
c685a3e272cbb298d924a517aa6bd488
[
Spyware.LokiBot
] [
Win32/PSW.Fareit.L
] [
TROJ_GE.CF63A3B7
] [
Win32.Trojan.Inject.Auto
] [
Trojan.PWS.Stealer.18836
] [
virus.win32.virut.bn
] [
BehavesLike.BadFile.gc
] [
PWS:Win32/Primarypass.A
] [
Artemis!9FAC68FD4F88
] [
BScope.Trojan.Diple
] [
Trojan.Inject
] [
W32/Fareit.L!tr.pws
] [
SHeur4.CMEH
]
DNS Resolutions
Date
IP Address
2024-05-12
178.33.161.194
(
ClassC
)
2024-12-28
77.37.127.219
(
ClassC
)
Port 80
HTTP/1.1 403 OKContent-type: text/html html>head>meta namerobots contentnoindex, follow>meta http-equivrefresh content60>title>/title>script> function setCookie(cname, cvalue, exdays) { var d new Date(); d.setTime(d.getTime() + (exdays*24*60*60*1000)); var expires expires+ d.toUTCString(); document.cookie cname + + cvalue + ; + expires; } function getCookie(cname) { var name cname + ; var ca document.cookie.split(;); for(var i 0; i ca.length; i++) { var c cai; while (c.charAt(0) ) { c c.substring(1); } if (c.indexOf(name) 0) { return c.substring(name.length,c.length); } } return ; } document.write(iframe width100% height100% frameborder0 styleoverflow:hidden;height:100%;width:100% srchttp://captcha.webempresa.eu/redirect.php?acp7111.webempresa.eu&b52.40.234.105&c+window.location.href+>/iframe);setTimeout(function(){ var script document.createElement(script); script.src http://captcha.webempresa.eu/tmp/cp7111.webempresa.eu-52.40.234.105.js; document.getElementsByTagName(head)0.appendChild(script);}, 5000);/script>/head>body>/body>/html>
Port 443
HTTP/1.1 200 OKServer: nginxDate: Sun, 24 Dec 2023 20:31:12 GMTContent-Type: text/htmlContent-Length: 3363Last-Modified: Tue, 29 May 2018 10:05:36 GMTConnection: keep-aliveVary: Accept-EncodingAccept- html>head> meta namerobots contentnoindex, follow> meta http-equivrefresh content30> meta http-equivcache-control contentno-store, no-cache, must-revalidate, post-check0, pre-check0 /> meta http-equivexpires content0 /> meta http-equivexpires contentTue, 01 Jan 1980 1:00:00 GMT /> meta http-equivpragma contentno-cache /> title>/title> script> (function(){ use strict; window.Captcha window.Captcha || {}; function setCookie(cname, cvalue, exdays) { var d new Date(); d.setTime(d.getTime() + (exdays*24*60*60*1000)); var expires expires+ d.toUTCString(); document.cookie cname + + cvalue + ; + expires; }; function getCookie(cname) { var name cname + ; var ca document.cookie.split(;); for(var i 0; i ca.length; i++) { var c cai; while (c.charAt(0) ) { c c.substring(1); } if (c.indexOf(name) 0) { return c.substring(name.length,c.length); } } return ; }; function _doRequest(source){ var source source; var xmlHttp new XMLHttpRequest(); xmlHttp.open( GET, source, false ); xmlHttp.send( null ); return xmlHttp.responseText; }; function listed(hostname, ip){ var r _doRequest(https://webempresa.io/api/listed.php?hostname+hostname+&ip+ip); return (undefined ! typeof r)?r:0; }; Captcha.init function(){ var selfthis; var hostname cp5030.webempresa.eu; var source https://webempresa.io/api/cualesmiip.php; var xmlHttp new XMLHttpRequest(); xmlHttp.open( GET, source, false ); xmlHttp.send(
View on OTX
|
View on ThreatMiner
Please enable JavaScript to view the
comments powered by Disqus.
Data with thanks to
AlienVault OTX
,
VirusTotal
,
Malwr
and
others
. [
Sitemap
]