Help RSS API Feed Maltego Contact                        

Domain > ult-thanks.fordownloading.net

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to ult-thanks.fordownloading.net

MD5A/V
65d7d9a7faf7bb1085997a32cc148020[Packed.Win32.TDSS.2!O] [Artemis!65D7D9A7FAF7] [PUP.Optional.OptimumInstaller.A] [Trojan.Win32.IBryte.cxaaqu] [Application.Win32.IBryte.X] [Trojan.DownLoader11.6764] [Adware/iBryte.Z] [Win32.Troj.Undef.(kcloud)] [AdWare.iBryte] [Riskware/IBryte] [AdPlugin.GL] [Win32/Trojan.e6d]
c736d08608ca02c614cc8606fcf4671c
852670db9b97aaee33052e6f790909c0[Packed.Win32.TDSS.2!O] [Artemis!852670DB9B97] [Trojan.Win32.IBryte.cxaaqu] [Application.Win32.IBryte.X] [Adware/iBryte.Z] [Riskware/IBryte] [AdPlugin.GL] [Win32/Trojan.e6d]
6b2e0fcb1341f249dc22b2212c378fb1[Packed.Win32.TDSS.2!O] [Artemis!6B2E0FCB1341] [PUP.Optional.OptimumInstaller.A] [Trojan.Win32.IBryte.cxaaqu] [Application.Win32.IBryte.X] [Trojan.DownLoader11.6764] [Adware/iBryte.Z] [Win32.Troj.Undef.(kcloud)] [AdWare.iBryte] [Riskware/IBryte] [AdPlugin.GL] [Win32/Trojan.e6d]
e48e7833367269586c3aaf7dac0be4d9
426f8df2991a2abc98369c2eee417bce[Packed.Win32.TDSS.2!O] [PUP.Optional.OptimumInstaller.A] [Application.Win32.iBryte.WRP] [Trojan.Packed.26508]
37aede61ae166294cce7a184d396ed7c
bf390284df909b16f1bcbb82af5467ff
806c41049fe53729b12d25048b265ef1[Packed.Win32.TDSS.2!O] [Artemis!806C41049FE5] [PUP.Optional.OptimumInstaller.A] [Trojan.Win32.IBryte.cxaaqu] [Application.Win32.IBryte.X] [Adware/iBryte.Z] [AdWare.iBryte] [Riskware/IBryte] [AdPlugin.GC] [Win32/Trojan.e6d]
3023f01d594b878511a3e53d8ae10b6a
67a1a0844c42ee85b34edec88868b891[Packed.Win32.TDSS.2!O] [Artemis!67A1A0844C42] [PUP.Optional.OptimumInstaller.A] [Trojan.Win32.IBryte.cxaaqu] [Application.Win32.IBryte.X] [Trojan.DownLoader11.6764] [Adware/iBryte.Z] [Win32.Troj.Undef.(kcloud)] [AdWare.iBryte] [Riskware/IBryte] [AdPlugin.GL] [Win32/Trojan.e6d]
874ce6555b208eff1e63d07018d82372
935070944aeea83f2a84d66fa4b866ce
474af43d9f95632a3700df3097e0c633
6ee18ce3d68ce02a5cf2f3015927d609
32544161b2ec15f75a01384222f1cdc6
a14162586c79684e148b9c739b5d3c64[PUP.Optional.Ibryte] [PUA.iBryte!] [not-a-virus:AdWare.Win32.iBryte.jgf] [Riskware.Win32.IBryte.cwjtfl] [Application.Win32.Ibryte.DIU] [GrayWare[AdWare:not-a-virus]/Win32.iBryte] [PE:Malware.iBryte!6.17C5] [Riskware/IBryte] [AdPlugin.DU]
17ac78c54b6a99000d28404c112b67dd
387bbd7893d16b74abe8cf63977cc2b4
6b1c3d0bbe6d736f0c1c5bc81160f272[Artemis!6B1C3D0BBE6D] [PUP.Optional.Ibryte] [Riskware.Win32.IBryte.cwggau] [WS.Reputation.1] [not-a-virus:AdWare.Win32.iBryte.jge] [PUA.iBryte!] [Application.Win32.Ibryte.DIU] [Adware.iBryte.Win32.830] [GrayWare[AdWare:not-a-virus]/Win32.iBryte] [Win32.Troj.iBryte.j.(kcloud)] [Win32.Adware.Ibryte.G] [AdWare.iBryte] [PE:Malware.iBryte!6.17B4] [Riskware/IBryte] [AdPlugin.DP] [Adware.Win32.iBryte.R]

Whois

PropertyValue
NameServer NS-414.AWSDNS-51.COM
Created 2012-05-16 00:00:00
Changed 2015-04-28 00:00:00
Expires 2016-05-16 00:00:00
Registrar GODADDY.COM, LLC

DNS Resolutions

DateIP Address
2013-05-1866.56.68.18 (ClassC)
2014-05-3066.56.68.18 (ClassC)
2017-11-13103.224.212.222 (ClassC)
2018-01-19192.184.12.62 (ClassC)
2018-03-0970.32.1.32 (ClassC)
2018-06-13104.247.81.101 (ClassC)
2019-01-05185.53.178.7 (ClassC)
2019-11-25185.53.178.8 (ClassC)
2020-10-03104.247.81.131 (ClassC)
2022-07-16185.53.177.51 (ClassC)
2025-07-23104.247.81.51 (ClassC)
2025-08-07104.247.81.171 (ClassC)

Port 80

Subdomains

DateDomainIP
thanks.fordownloading.net2025-07-08104.247.81.51
music-thanks.fordownloading.net2025-06-20104.247.81.51
zoom-thanks.fordownloading.net2025-07-09104.247.81.51
ult-thanks.fordownloading.net2014-05-3066.56.68.18
manythanks.fordownloading.net2025-07-24104.247.81.51
zoomc-thx.fordownloading.net2025-06-14104.247.81.51
wise-thx.fordownloading.net2025-07-01104.247.81.51
zoom-thx.fordownloading.net2025-06-15104.247.81.51
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information