Help RSS API Feed Maltego Contact                        

Domain > yahoo.co.in

Welcome! Right click nodes and scroll the mouse to navigate the graph.
More information on this domain is in AlienVault OTX

Is this malicious?

Reports

http://researchcenter.paloaltonetworks.com/2016/02...    
https://otx.alienvault.com/pulse/56cf3cc167db8c17d...    

Files that talk to yahoo.co.in

MD5A/V
d42c1a59b111316f7481770349e653db[HW32.CDB.87f3] [Malware.Packer.OCD]
69105950b2bb95843dea5937bea0e8f0[HW32.CDB.5919] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CDQY] [TrojWare.Win32.Kryptik.CBCJ] [BackDoor.Slym.13873] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CBCJ]
ebbf2139fa265c6896be78fe8bbd44f7
abe19665682ad3e10ba09471775c150b[Malware.Packer.FFS] [Heuristic.LooksLike.Win32.Suspicious.E]
e21b3469b4fc1efddf76d8c89f1ebb2a[Malware.Packer.HGX1] [Heuristic.LooksLike.Win32.Suspicious.E] [W32/Kryptik.AXUE!tr]
9aa81fa022c0b159758efa1bda4f9be1[HW32.CDB.A20b] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CCFN] [Backdoor.Win32.Hlux.dthd] [UnclassifiedMalware] [BackDoor.Slym.13011] [Backdoor:Win32/Kelihos] [Heur.Trojan.Hlux] [Win32/Kryptik.CBNK] [Win32.Backdoor.Hlux.Hwcu] [Trojan.Crypt3] [W32/Kryptik.BD!tr] [Crypt3.OHL] [Backdoor.Win32.Hlux.Ac]
971d6821a96e8f41da919db02ebc60da[Malware.Packer.FFS] [Heuristic.LooksLike.Win32.Suspicious.E] [Trojan/Win32.Yakes] [W32/Kelihos.BCEB!tr]
3fb83eaf2a665f71ac2065f5f6956d50[HW32.CDB.5da2] [Packed.Win32.Katusha.1!O] [Trojan.Win32.Hlux.cynagk] [Trojan.FakeAV] [Kryptik.CDQY] [Win32/Kelihos.GeEUUIB] [Backdoor.Win32.Hlux.dqkq] [Backdoor.Hlux!m6CCC6SKjdo] [Win32.Backdoor.Hlux.Lose] [Backdoor.Win32.Hlux.DUHE] [Trojan.Packed.26581] [Trojan[Backdoor]/Win32.Hlux] [Win32.Hack.Hlux.dq.(kcloud)] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.aDM]
4211b2d7121c11d5f032e6620030a384[HW32.CDB.Cd7e] [Packed.Win32.Katusha.3!O] [Hlux.ZY] [VirTool:Win32/Obfuscator.WT]
0f5f90b03b49b276d148f7e6be7c30f1[HW32.CDB.27e0] [Packed.Win32.Katusha.1!O] [Trojan.Win32.Hlux.cxxldj] [Trojan.FakeAV] [Kryptik.CCFN] [Win32/Kelihos.OWUMMQC] [Backdoor.Win32.Hlux.dqeh] [Backdoor.Hlux!9TTR+wn2IWc] [Backdoor.Win32.Hlux.DUHE] [BackDoor.Slym.12819] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Win32/Kryptik.CAXO] [Win32.Backdoor.Hlux.Hpn] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.ArxZ]
db5b440f6419090cd9567f3b33fd3ced[Malware.Packer.HGX1] [BackDoor.SlymENT.1498] [Heuristic.LooksLike.Win32.Suspicious.E] [W32/Kryptik.AXUE!tr]
833009a54c295a72ad64ab0941f482fe[Suspicious.Cloud.5] [Kryptik.CCFN] [TrojWare.Win32.Kryptik.BZOO] [Trojan.DownLoad3.28912] [TR/Crypt.EPACK.9220] [Heuristic.BehavesLike.Win32.Suspicious-BAY.K] [Mal/FakeAV-UF] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Win32.SuspectCrc] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GIF] [Trojan.Win32.Kryptik.BZOO]
b36385662ebdaf40bc3d28f90b6a4751[Spyware.Zbot.USBV] [Trojan] [BackDoor.SlymENT.1498] [Heuristic.LooksLike.Win32.Suspicious.E] [Trojan/Win32.Foreign]
3220ab9b63a767c299000ea9d9e3a056[HW32.CDB.1b0b] [Packed.Win32.Katusha.1!O] [Backdoor.Hlux!u8SUOkHyYnA] [Trojan.FakeAV] [Kryptik.CCFN] [Win32/Kelihos.RbUfAWB] [Backdoor.Win32.Hlux.dpoo] [Trojan.Win32.Hlux.cxxuzn] [TrojWare.Win32.Kryptik.CAUP] [BackDoor.Slym.12819] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Backdoor.Hlux] [Win32/Kryptik.CAXO] [Win32.Backdoor.Hlux.Lgjg] [Trojan.Crypt_s] [W32/Kryptik.CAXO!tr] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CAXO]
3a44da011fc699a6afc6cc7d07131dd6[HW32.CDB.14e7] [Trojan.Win32.Kryptik.cxajdj] [Kryptik.CDQY] [TrojWare.Win32.Kryptik.CAHC] [Trojan.Packed.26527] [Trojan:Win32/Dynamer!ac] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Backdoor.Win32.Kelihos] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GKZ]
27213d33434bf796a9f535ec98e8a918[HW32.CDB.03b6]
860dd245cbecd656df047b97456d0ad0[HW32.CDB.9069] [Malware.Packer.FFS] [Heuristic.LooksLike.Win32.Suspicious.E] [PE:Malware.AntiWare!1.9D9B] [W32/Kelihos.KK@mm]
c7bf064346fafe4fc55b43abcfe96b00[HW32.CDB.E6f3] [Backdoor.Kelihos.r3] [Backdoor.Hlux!zUFIktBYK3s] [Kryptik.CCFN] [Backdoor.Win32.Hlux.djfw] [Trojan.Win32.S.PSW-Tepfer.835600.AM] [UnclassifiedMalware] [BackDoor.Slym.14049] [Mal/Kelihos-A] [Backdoor:Win32/Kelihos] [Trojan/Win32.Tepfer] [W32/Trojan.QQUO-1304] [Backdoor.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt3.HUC] [Trojan.Win32.Kryptik.BZIX]
df902d85a5aebee35007be327e9f54d2[HW32.CDB.7c9b] [Malware.Packer.FFS] [Mal/FakeAV-UF] [Heuristic.LooksLike.Win32.Suspicious.E] [Trojan/Win32.Symmi]
e6d960bf587f5cb1497520fe716f1fb4[Malware.Packer.FFS] [BackDoor.SlymENT.2075] [Heuristic.LooksLike.Win32.Suspicious.E] [Backdoor:Win32/Kelihos.F] [PE:Malware.XPACK/RDM!5.1]

Whois

PropertyValue
NameDomain Administrator
Organization Yahoo Web Service India Pvt. Ltd.
Email domainadmin@yahoo-inc.com
Zip Code 400 025
City Mumbai
State Maharashtra
Country IN
Phone +91.4622222
Fax +91.4622244
NameServer ns3.yahoo.com
Created 2003-06-30 04:00:00
Changed 2014-05-29 09:09:23
Expires 2016-06-30 04:00:00
Registrar Mark Monitor (R84-AF

DNS Resolutions

DateIP Address
2013-09-19106.10.165.51 (ClassC)
2013-12-0268.180.206.184 (ClassC)
2014-03-24106.10.165.51 (ClassC)
2014-04-29212.82.102.24 (ClassC)
2014-05-0177.238.184.24 (ClassC)
2014-05-0574.6.50.24 (ClassC)
2014-05-0798.137.236.24 (ClassC)
2014-05-16106.10.212.24 (ClassC)
2014-06-18106.10.212.24 (ClassC)
2014-07-0874.6.50.24 (ClassC)
2014-07-2377.238.184.24 (ClassC)
2017-04-19124.108.105.24 (ClassC)
2020-03-16212.82.100.151 (ClassC)
2020-05-05124.108.115.101 (ClassC)
2020-05-08106.10.248.151 (ClassC)
2020-07-0874.6.136.151 (ClassC)
2020-08-0298.136.103.24 (ClassC)
2020-08-17124.108.115.100 (ClassC)
2021-01-1998.136.103.23 (ClassC)
2021-02-27212.82.100.150 (ClassC)
2023-08-15106.10.248.150 (ClassC)
2023-08-2674.6.136.150 (ClassC)
2023-12-1113.49.212.207 (ClassC)
2023-12-2618.136.37.69 (ClassC)
2024-01-2534.213.101.254 (ClassC)
2024-02-0834.225.127.72 (ClassC)
2024-02-1654.161.105.65 (ClassC)
2024-02-2213.50.184.192 (ClassC)
2024-03-1013.251.69.97 (ClassC)
2025-05-1213.248.158.7 (ClassC)
2025-05-1876.223.84.192 (ClassC)

Subdomains

DateDomainIP
music.yahoo.co.in2025-04-10203.199.70.100
finance.yahoo.co.in2014-08-0674.6.50.150
search.yahoo.co.in2025-04-0876.223.84.192
mail.yahoo.co.in2014-10-14188.125.73.108
pop.mail.yahoo.co.in2025-02-1167.195.12.15
smtp.mail.yahoo.co.in2025-04-2667.195.12.42
www.mail.yahoo.co.in2025-04-0674.6.160.107
messenger.yahoo.co.in2024-10-0874.6.160.106
kids.yahoo.co.in2025-04-09121.101.146.65
groups.yahoo.co.in2025-04-0676.223.84.192
answers.yahoo.co.in2014-12-0374.6.50.150
news.yahoo.co.in2014-08-0774.6.50.150
cricket.yahoo.co.in2014-12-3074.6.50.150
www.yahoo.co.in2014-05-0374.6.50.24
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information