Help RSS API Feed Maltego Contact                        

Domain > retsback.com

This indicator is referenced in AlienVault OTX pulse ""

Is this malicious?

Most users have voted this as MALICIOUS

Reports

https://securelist.com/blog/research/73866/atmzomb...    

Files that talk to retsback.com

MD5A/V
efa5ea2c511b08d0f8259a10a49b27ad[Trojan.Tepoyx.r5] [Trojan.PWS.Capper!JPzL/8fme4U] [Suspicious.Cloud.9] [Win32/ProxyChanger.TO] [Trojan-Banker.Win32.Capper.zyg] [Trojan.Win32.Capper.dyjdmf] [Win32.Trojan-banker.Capper.Aosz] [UnclassifiedMalware] [Trojan.Proxy.27876] [Artemis!Trojan] [TR/ProxChange.159366] [Trojan[Banker]/Win32.Capper] [Trojan:Win32/Tepoyx] [Artemis!EFA5EA2C511B] [Trojan.Win32.Banker.zyg] [Trojan.Win32.ProxyChanger] [W32/ProxyChanger.TO!tr]
d08e51f8187df278296a8c4ff5cff0de[Trojan.Win32.Capper.dyjdmf] [Win32/ProxyChanger.TO] [Trojan-Banker.Win32.Capper.zys] [Trojan.Proxy.27876] [BehavesLike.Win32.Downloader.cm] [Trojan/Banker.Capper.kj] [Trojan[Banker]/Win32.Capper] [Trojan:Win32/Tepoyx] [Artemis!D08E51F8187D] [TrojanBanker.Capper] [Proxy.BJJW]
11776bb73be11088edc24f666c536078
f3c8ab1b4aeb584d62e8923689e3a3a6

Whois

PropertyValue
Email mant@teleworm.us
NameServer B.DNSPOD.COM
Created 2015-10-25 00:00:00
Changed 2015-11-24 00:00:00
Expires 2016-10-25 00:00:00
Registrar TODAYNIC.COM, INC.