Help
RSS
API
Feed
Maltego
Contact
Domain > sbacsav.com
×
More information on this domain is in
AlienVault OTX
Is this malicious?
Yes
No
Files that talk to sbacsav.com
MD5
A/V
c58d66135101850883bc5bc5da668fd2
[
Backdoor.Pushdo.qyz
] [
BackDoor-FBGL!C58D66135101
] [
WS.Reputation.1
] [
Backdoor.Win32.Pushdo.qyz
] [
Virus.Win32.Heur.c
] [
UnclassifiedMalware
] [
Win32.Hack.Pushdo.q.(kcloud)
] [
TrojanDownloader:Win32/Cutwail.BS
] [
Trojan/Win32.Bublik
] [
BScope.Malware-Cryptor.Bubblik
] [
Backdoor.Win32.Pushdo
] [
W32/Pushdo.QYZ!tr.bdr
] [
Trj/dtcontx.G
]
bbce5846c2f15579e1c2ee6bcb4f5685
31573165ce326ec1134a40c18dfa4902
[
TrojanDownloader*Win32/Cutwail
]
DNS Resolutions
Date
IP Address
2013-09-19
69.55.161.138
(
ClassC
)
2024-08-12
199.16.172.50
(
ClassC
)
2025-01-09
199.16.173.37
(
ClassC
)
Port 80
HTTP/1.1 301 Moved PermanentlyServer: nginxDate: Sun, 27 Aug 2023 01:00:31 GMTContent-Type: text/htmlContent-Length: 162Connection: keep-aliveLocation: https://sbacsav.com/X-ac: 3.sea _atomic_bur BYPA html>head>title>301 Moved Permanently/title>/head>body>center>h1>301 Moved Permanently/h1>/center>hr>center>nginx/center>/body>/html>
Port 443
HTTP/1.1 200 OKServer: nginxDate: Sun, 27 Aug 2023 01:00:33 GMTContent-Type: text/html; charsetUTF-8Transfer-Encoding: chunkedConnection: keep-aliveStrict-Transport-Security: max-age31536000Vary: Acce !DOCTYPE html>html langen-US>head >meta charsetUTF-8 />script typetext/javascript>var gform;gform||(document.addEventListener(gform_main_scripts_loaded,function(){gform.scriptsLoaded!0}),window.addEventListener(DOMContentLoaded,function(){gform.domLoaded!0}),gform{domLoaded:!1,scriptsLoaded:!1,initializeOnLoaded:function(o){gform.domLoaded&&gform.scriptsLoaded?o():!gform.domLoaded&&gform.scriptsLoaded?window.addEventListener(DOMContentLoaded,o):document.addEventListener(gform_main_scripts_loaded,o)},hooks:{action:{},filter:{}},addAction:function(o,n,r,t){gform.addHook(action,o,n,r,t)},addFilter:function(o,n,r,t){gform.addHook(filter,o,n,r,t)},doAction:function(o){gform.doHook(action,o,arguments)},applyFilters:function(o){return gform.doHook(filter,o,arguments)},removeAction:function(o,n){gform.removeHook(action,o,n)},removeFilter:function(o,n,r){gform.removeHook(filter,o,n,r)},addHook:function(o,n,r,t,i){nullgform.hookson&&(gform.hookson);var egform.hookson;nulli&&(in+_+e.length),gform.hookson.push({tag:i,callable:r,priority:tnullt?10:t})},doHook:function(n,o,r){var t;if(rArray.prototype.slice.call(r,1),null!gform.hooksno&&((ogform.hooksno).sort(function(o,n){return o.priority-n.priority}),o.forEach(function(o){function!typeof(to.callable)&&(twindowt),actionn?t.apply(null,r):r0t.apply(null,r)})),filtern)return r0},removeHook:function(o,n,t,i){var r;null!gform.hookson&&(r(rgform.hookson).filter(function(o,n,r){return!!(null!i&&i!o.tag||null!t&&t!o.priority)}),gform.hooksonr)}});/script>meta nameviewport contentwidthdevice-width, initial-scale1 /> !-- script typetext/javascript> WebFontConfig { google: { families: Chonburi,Hind:400,500,600,Open+Sans:400,600,700 } }; (function() { var wf document.createElement(script); wf.src (https: document.location.protocol ? https : http) + ://ajax.googleapis.com/ajax/libs/webfont/1.5.18/webfont.js; wf.type text/javascript; wf.async true; var s document.getElementsByTagName(script)0; s.parentNode.insertBefore(wf, s); })(); /script> --> meta
View on OTX
|
View on ThreatMiner
Please enable JavaScript to view the
comments powered by Disqus.
Data with thanks to
AlienVault OTX
,
VirusTotal
,
Malwr
and
others
. [
Sitemap
]