Help
RSS
API
Feed
Maltego
Contact
Domain > rghost.ru
×
More information on this domain is in
AlienVault OTX
Is this malicious?
Yes
No
Files that talk to rghost.ru
MD5
A/V
19ff2e8613be36335a88ca30f2d66eab
a8243df96256c1c425a75acd7c1a760e
[
Worm.VBS.Dunihi.W
] [
Worm/VBS.Dinihou
]
3b0e3916f98277882c6f942bf643e4b8
41e67dca33376c8723aa88c49c0a38af
e446afebaa40ba5ff5043b16fd1c2a36
3c9b84d13045a38f9994693ffa3ee725
52660d440348342d7663fd3173763fef
[
W32.NeshtaB.PE
] [
Win32.Neshta.A
] [
Virus/W32.Neshta
] [
Virus.Win32.Neshta!O
] [
W32.Neshta.A
] [
Virus.Ramnit
] [
Virus.Neshta.Win32.1
] [
Trojan.Win32.Neshta.cwfstr
] [
W32/HLLP.41472
] [
W32.Neshuta
] [
Neshta.C
] [
Win32/Neshta.A
] [
PE_NESHTA.A
] [
W32.Neshuta.A
] [
Virus.Win32.Neshta.a
] [
Win32.Neshta.B
] [
PE:Win32.Netsha.a!411233
] [
Win32.Ramnit
] [
Win32.HLLP.Neshta
] [
W32/Neshta.A
] [
Heuristic.BehavesLike.Win32.Suspicious.D
] [
W32/Bloat-A
] [
Virus.Neshta.a
] [
Virus/Win32.Neshta.a
] [
Virus:Win32/Neshta.A
] [
Win32/Neshta
] [
Virus.Win32.Neshta
] [
Worm/Delf.FF
] [
Virus.Win32.Neshta.$a
] [
Virus.Win32.Neshta.B
]
36d68b0d8bada85675cb2fccab5d68fd
[
PUP-FEX!36D68B0D8BAD
] [
PUP.Optional.LoadMoney
] [
Trojan.Win32.LMN.cmhxoa
] [
LoadMoney.DGNB
] [
TrojWare.Win32.Kryptik.BEUX
] [
Trojan.LoadMoney.225
] [
PUP-FEA!36D68B0D8BAD
] [
Troj/LdMon-D
] [
Trojan/Win32.LoadMoney
] [
Malware-Cryptor.Limpopo
] [
W32/Kryptik.WIE!tr
] [
Win32/Cryptor
]
52cb9d6fe8c9d09eb28e6a250f235ade
36ae9e597b297fdc2543dac51978720d
38fa884e6cf1eeccd8a134701e2b87a2
4bd939cf0747f726cc4f99104fbf491d
555f39d1119ce270d6614d1d0f11cf82
25893d268cdc2c9ff630226b82d0fedd
2408b2c4fe8208c59a303f6281f9b72b
[
Trojan.DownLoader4.56255
]
014e2ae816258eb51061f3c8cafe32b6
[
Artemis!014E2AE81625
] [
Adware.Downware.3965
] [
Trojan.Win32.Llac
] [
PossibleThreat
]
4b95c5997a834624a5d08bd9ae54899c
42100d0d9a40803a6f99c69d463d3dce
a698c316aec4374394c3643429a382f5
92ec6db2df53d85fee61f86f0491dd0e
DNS Resolutions
Date
IP Address
2011-04-08
217.199.218.103
(
ClassC
)
2011-08-28
217.199.218.101
(
ClassC
)
2012-01-28
217.199.217.180
(
ClassC
)
2012-12-30
217.199.217.181
(
ClassC
)
2012-12-30
217.199.218.98
(
ClassC
)
2013-08-13
141.101.127.140
(
ClassC
)
2013-08-13
108.162.200.141
(
ClassC
)
2013-10-19
217.199.218.100
(
ClassC
)
2013-12-04
108.162.207.189
(
ClassC
)
2013-12-04
141.101.124.189
(
ClassC
)
2013-12-15
217.199.218.100
(
ClassC
)
2014-02-14
108.162.198.174
(
ClassC
)
2014-02-14
108.162.199.174
(
ClassC
)
2014-02-18
89.248.225.50
(
ClassC
)
2014-02-27
89.248.225.44
(
ClassC
)
2014-03-03
89.248.225.42
(
ClassC
)
2014-03-17
89.248.225.43
(
ClassC
)
2014-07-01
89.248.225.50
(
ClassC
)
2014-10-25
162.159.243.134
(
ClassC
)
2014-10-25
162.159.242.134
(
ClassC
)
2016-06-04
163.172.19.203
(
ClassC
)
2016-06-06
37.59.33.100
(
ClassC
)
2018-07-29
198.251.84.79
(
ClassC
)
2020-08-20
104.28.14.51
(
ClassC
)
2020-10-28
104.28.15.51
(
ClassC
)
2022-04-21
172.67.131.47
(
ClassC
)
2022-05-05
104.21.3.207
(
ClassC
)
2022-08-16
188.114.96.2
(
ClassC
)
2022-09-03
188.114.97.2
(
ClassC
)
2023-08-11
188.114.97.7
(
ClassC
)
2023-08-11
188.114.96.7
(
ClassC
)
2023-12-01
188.114.97.0
(
ClassC
)
2023-12-01
188.114.96.0
(
ClassC
)
2024-11-11
172.67.175.16
(
ClassC
)
2024-12-23
104.21.64.31
(
ClassC
)
2025-01-09
104.21.64.1
(
ClassC
)
2025-05-01
104.21.48.1
(
ClassC
)
2025-07-11
104.21.80.1
(
ClassC
)
2025-07-20
104.21.112.1
(
ClassC
)
2025-07-27
104.21.32.1
(
ClassC
)
2025-08-08
104.21.16.1
(
ClassC
)
2025-08-12
104.21.96.1
(
ClassC
)
Port 80
HTTP/1.1 302 FoundDate: Tue, 04 Jun 2019 21:40:57 GMTContent-Type: text/html; charsetutf-8Transfer-Encoding: chunkedConnection: keep-aliveSet-Cookie: __cfduidd02f99d82f0ba57cb6891338475970244155968445 html>body>You are being a hrefhttp://rgho.st/>redirected/a>./body>/html>
Port 443
HTTP/1.1 302 FoundDate: Tue, 04 Jun 2019 21:40:57 GMTContent-Type: text/html; charsetutf-8Transfer-Encoding: chunkedConnection: keep-aliveSet-Cookie: __cfduiddc3d260be746da6f40c30bc28b3def502155968445 html>body>You are being a hrefhttp://rgho.st/>redirected/a>./body>/html>
Subdomains
Date
Domain
IP
plasmon.rghost.ru
2013-10-19
217.199.218.98
polariton.rghost.ru
2024-10-17
104.21.64.31
higgs.rghost.ru
2013-10-19
217.199.217.181
tau.rghost.ru
2013-10-19
217.199.217.180
www.rghost.ru
2024-09-12
172.67.175.16
View on OTX
|
View on ThreatMiner
Please enable JavaScript to view the
comments powered by Disqus.
Data with thanks to
AlienVault OTX
,
VirusTotal
,
Malwr
and
others
. [
Sitemap
]