Help RSS API Feed Maltego Contact                        

Domain > www.dicemention.com

This indicator is referenced in AlienVault OTX pulse ""

Is this malicious?

Most users have voted this as MALICIOUS

Reports

http://www.welivesecurity.com/2014/11/12/korplug-m...    
http://researchcenter.paloaltonetworks.com/2016/06...    
https://www.proofpoint.com/us/threat-insight/post/...    

Files that talk to www.dicemention.com

MD5A/V
66c411a966f01575c0ab39f197638e73[Win32/Delf.AJC] [Virus.Win32.Delf.DTW] [Trojan.AntiAV!22E3]
751958396275a78b2102db45a5425f59
28158ca150fd6efd5d1e12653ac1373f[TR/Rogue.11852680] [Win32/Delf.AIL] [Delf.AQFD] [Virus.Win32.Delf.DTW] [winpe/Smalldoor.QLVR] [Trojan.AntiAV!22E3]
82cc9e40fe41f2c3976a6b6a01fea46f[Trojan.ScriptKD.231] [TR/ScriptKD.231.1] [Backdoor.Zegost.r5] [Win32/Korplug.CU] [W32/Zegost.ACPU!tr.bdr] [Backdoor.Win32.Zegost.acpu] [Trojan.FakeDOC] [Trojan.ScriptKD.231[ZP]]
273e3694afb362d836fdeafa03921a19[Backdoor.Win32.Zegost.aeqo] [Virus.Win32.Heur.l] [Troj/Plugx-AP] [Win32/Backdoor.3a8]
4c184b9f897999b4daa4fbe2b023292e[Virus.Win32.Delf.DTW] [Trojan.AntiAV!22E3]
66807c17e9b71046021cf43df83a2a41
d4c0390698f5332cc6e0f3fe611d1d38[Win32/Delf.AIW] [Virus.Win32.Delf.DTW] [winpe/Smalldoor.QLVR] [Trojan.AntiAV!22E3]
03b7614fc896909d5225933472c63c3b[Win32/Delf.AIZ] [Delf.AQGO] [Virus.Win32.Delf.DTW] [winpe/Smalldoor.QLVR] [Trojan.AntiAV!22E3]
953d9515147c61a32246b25fee08897d[Exp.RTF.CVE-2012-0158] [Exploit-CVE2012-0158.f] [Bloodhound.Exploit.551] [Trojan.Rtf.CVE20120158.dxopnd] [Exploit.Rtf.82] [Downloader.OpenConnection.JS.105247] [HEUR_RTFEXP.A] [Exploit-CVE2012-0158.f] [Troj/DocDrop-DM] [Exploit.CVE-2012-0158.a] [RTF/Cve-2012-0158] [Exploit_c.ABCD] [virus.exp.20122539]

Whois

PropertyValue
Email 123@123.com
NameServer NS2.EZDNSCENTER.COM
Created 2013-09-10 00:00:00
Changed 2014-09-12 00:00:00
Expires 2015-09-10 00:00:00
Registrar SHANGHAI MEICHENG TE