Help RSS API Feed Maltego Contact                        

Domain > api.officeonlinetool.com

This indicator is referenced in AlienVault OTX pulse ""

Is this malicious?

Most users have voted this as MALICIOUS

Reports

https://foxitsecurity.files.wordpress.com/2016/06/...    
https://github.com/fox-it/mofang    
https://foxitsecurity.files.wordpress.com/2016/06/...    

Files that talk to api.officeonlinetool.com

MD5A/V
dae34424ad8e4f8811a9a77158b5ee0d[Virus.Win32.Part.a] [Trojan-Downloader.Win32.Upatre]

Whois

PropertyValue
NameServer NS2.CYBERTHREATSINKHOLE.COM
Created 2015-05-05 00:00:00
Changed 2016-05-06 00:00:00
Expires 2017-05-05 00:00:00
Registrar GODADDY.COM, LLC