Help RSS API Feed Maltego Contact                        

Domain > leadserve.net

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to leadserve.net

MD5A/V
dc9a5196bea1e305e844abe5e487761d[Win32/Kryptik.BQWI] [W32/Kryptik.BCFJ!tr] [Trojan.Win32.Spy] [TSPY_NIVDORT.SM]
a7aca679e7a04bded34ebba03769d774[TR/Crypt.ZPACK.109512] [Win32/Kryptik.CCLE] [W32/Kryptik.CCLE!tr] [Win32/Cryptor] [Trojan.Crypt3] [Troj]
a6ab7bd26787c98b4810b861ea2ffdcf[TR/Crypt.ZPACK.101456] [Win32/Kryptik.CCLE] [W32/Kryptik.CCLE!tr] [Win32/Cryptor] [Trojan.Win32.Staser] [Trojan.Win32.Staser.aqsc] [TrojanSpy*Win32/Nivdort.P] [Troj/Wonton-KH] [Trojan.Staser]
70b10188f4909fa855ee4fb3ef301cb8[Win32/Kryptik.CCLE] [W32/Kryptik.CCLE!tr] [Win32/Cryptor] [Troj/Wonton-KH]
66083df5976335ee1a4106241d466cb6[Win32/Kryptik.CCLE] [W32/Kryptik.CCLE!tr] [Win32/Cryptor] [Trojan.Crypt3] [Troj/Wonton-KH]
9833a474f030658c25f4e32a347960c5[TR/Crypt.ZPACK.107479] [Win32/Tnega.XAXA!suspicious] [Win32/Kryptik.CCLE] [W32/Kryptik.CCLE!tr] [Win32/Cryptor] [Trojan.Crypt3]
ae1220bac6b0fe685c5ff96588a6c74b[Win32/Kryptik.BQWI] [W32/COMROKI.A!tr] [Win32/Cryptor] [Trojan.Crypt2] [TrojanSpy*Win32/Nivdort.Y] [TSPY_NIVDORT.SM]

Whois

PropertyValue
NameServer NS12.DOMAINCONTROL.COM
Created 2014-05-16 00:00:00
Changed 2015-04-26 00:00:00
Expires 2016-05-16 00:00:00
Registrar GODADDY.COM, LLC

DNS Resolutions

DateIP Address
2014-12-1150.63.202.21 (ClassC)
2015-06-24184.168.221.27 (ClassC)
2015-06-29-
2016-04-0554.231.9.84 (ClassC)
2016-04-1554.231.17.244 (ClassC)
2016-06-1654.231.13.124 (ClassC)
2016-06-1654.231.80.186 (ClassC)
2019-06-2252.216.145.218 (ClassC)
2019-06-2652.216.179.226 (ClassC)
2019-06-2952.216.114.250 (ClassC)
2019-07-1352.216.206.202 (ClassC)
2019-07-2152.216.177.178 (ClassC)
2019-09-0152.216.101.242 (ClassC)
2021-02-0452.217.91.27 (ClassC)
2021-02-1052.217.87.59 (ClassC)
2021-04-2952.217.194.229 (ClassC)
2024-02-2652.216.62.229 (ClassC)
2024-03-2352.217.168.93 (ClassC)
2024-06-2752.217.168.149 (ClassC)
2024-07-2152.217.203.125 (ClassC)
2024-08-1216.182.67.213 (ClassC)
2024-09-2154.231.228.173 (ClassC)
2024-09-2916.182.70.221 (ClassC)
2024-11-2352.217.166.181 (ClassC)
2024-12-1052.217.229.85 (ClassC)
2025-03-0252.216.43.149 (ClassC)
2025-03-313.5.31.15 (ClassC)
2025-04-093.5.31.28 (ClassC)
2025-05-0152.216.240.131 (ClassC)
2025-06-0116.182.38.37 (ClassC)
2025-06-0454.231.170.61 (ClassC)
2025-06-3052.217.0.2 (ClassC)
2025-07-0452.217.80.155 (ClassC)
2025-07-1752.216.61.189 (ClassC)
2025-07-2652.216.34.69 (ClassC)
2025-08-0654.231.225.29 (ClassC)

Port 80

Subdomains

DateDomainIP
www.leadserve.net2024-05-3052.216.24.19
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information