Help RSS API Feed Maltego Contact                        

Domain > dtl.eatuo.com

This indicator is referenced in AlienVault OTX pulse ""

Is this malicious?

Most users have voted this as MALICIOUS

Reports

http://targetedthreats.net/media/2.2%20Extended%20...    
https://citizenlab.org/2013/08/surtr-malware-famil...    
https://citizenlab.org/wp-content/uploads/2012/07/...    
https://otx.alienvault.com/pulse/5543ca44b45ff52a6...    
https://otx.alienvault.com/pulse/55553e26b45ff5703...    
https://raw.githubusercontent.com/citizenlab/malwa...    
https://www.fireeye.com/resources/pdfs/fireeye-mal...    
https://www.mpi-sws.org/~stevens/pubs/sec14.pdf    
https://www.usenix.org/system/files/conference/use...    

Files that talk to dtl.eatuo.com

MD5A/V
f95ceaa498a81ba14adba05be96fbe3b
4e25355848ce2dd843a6ed74254a54f7
ab8ccda0a8866c824604971972e879b5
1eca2e8b0c4c30374b146cf4727dd87d
45441e4c20e0d1aadbf9775fe33d47e4[TR/Spy.30208.191]
6ff9a5a80fabe8da9d57576a5f60a3c4
3ef0b33f08a26e86d25a7012d8900d47
6f90f9cc76747e1f002618f17cc2d221[Exploit-CVE2012-0158.f!rtf] [Exploit] [Trojan.Dropper] [Win32.Trojan] [Exploit.Win32.CVE-2012-0158.j] [Exploit.CVE2012-0158.16] [EXP/CVE-2012-0158.A.1334] [Exp/20120158-A] [Exploit:Win32/CVE-2012-0158.AX] [Trojan.Win32.A.EX-CVE-2012-0158.985817] [Exploit.MS04.CVE-2004-0210-2012-0158] [W32/20120158.A!exploit]
5d86e9ae5f2a2bf9d00716344dd7a1f3
4a75d51b38c9ddb5a2393e237eb8c73f
0fe550a5d1187d38984c505ef7741638[Exploit.CVE-2012-0158.Heur] [Exploit-CVE2012-0158] [LooksLike.OLE.Malware.b]
e367819385f5444b89448f226181d5f5
ba1387b1f6052396e856803f57c15aab
5d37b79a39cc395769176c5377c05e4a
91b6ede1831eacda254d5f24e9857f36
5059de097e91a35285ce01085204aa5e
3f499725a4f46305da80bc53dcc51a14
8ea0e842fd88780f268bf9f6c049517e
a4a36fb4381b6c20e68c05e83575485d
734c2ca178dabe5ac073d39ba238446a

Whois

PropertyValue
Email ppyy@astpbx.com
NameServer V1N2.3322.NET
Created 2008-08-25 00:00:00
Changed 2014-04-12 00:00:00
Expires 2015-08-25 00:00:00
Registrar PDR LTD. D/B/A PUBLI