Help RSS API Feed Maltego Contact                        

Domain > scuba90.codns.com

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to scuba90.codns.com

MD5A/V
9bb31558f3f9b7d5270d2bca50f411bb[Trojan-Dropper.MSIL] [DDoS*Win32/Nitol.A] [DDoS*Win32/Nitol.A] [MSIL/Dropper.WT!tr] [MSIL/Dropper.WT!tr] [Trojan.Injector.A4] [Trojan-Dropper.MSIL] [Trojan.PWS.Spy.11887] [Trojan.PWS.Spy.11887] [Trojan.Injector.A4] [W32/Trojan.KPHJ-8739] [W32/Trojan.KPHJ-8739]
b682eb68eab5e15413b0df1b1ec255bd[Trojan.ServStart] [DDoS*Win32/Nitol.A] [W32/ServStart.AS!tr] [RDN/Downloader.a!uq] [RDN/Downloader.a!uq] [DDoS*Win32/Nitol.A] [Win32/ServStart.DT] [Win32/ServStart.DT] [Trojan.ServStart.A4] [Trojan.DownLoader10.22140] [Trojan.Win32.ServStart] [Trojan.ServStart] [W32/Trojan.RHMO-4586] [W32/Trojan.RHMO-4586] [Win32/Nitol.AI] [Trojan.DownLoader10.22140] [TR/Spy.109568.200] [TR/Spy.109568.200] [Trojan.ServStart.A4] [Win32/Nitol.AI] [W32/ServStart.AS!tr] [Trojan.Win32.ServStart] [Backdoor.Overie!486D] [Backdoor.Overie!486D]
2faa20d47bd266bf1117df070c4e78a2[DDoS*Win32/Nitol.A] [W32/ServStart.AS!tr] [DDoS*Win32/Nitol.A] [W32/ServStart.AS!tr] [Pakes2_c.BPSP] [Win32/YahLover.HidI_I] [Win32/YahLover.HidI_I] [Pakes2_c.BPSP] [Trojan.DownLoad3.40063] [Trojan.DownLoad3.40063]

Whois

PropertyValue
Email manager@nehom.com
NameServer NS3.CODNS.COM
Created 2000-06-28 00:00:00
Changed 2014-06-28 00:00:00
Expires 2019-06-28 00:00:00
Registrar INAMES CO., LTD.