Help
RSS
API
Feed
Maltego
Contact
Domain > ghostwriter-24.de
×
More information on this domain is in
AlienVault OTX
Is this malicious?
Yes
No
Most users have voted this as
MALICIOUS
Reports
http://www.malware-traffic-analysis.net/2015/09/02...
https://otx.alienvault.com/pulse/55e819e767db8c2de...
Files that talk to ghostwriter-24.de
MD5
A/V
99df44fd0000ff1d7a810b5012ef06b0
[
Win32/Filecoder.EM
]
9cd70299c5f16642411c241c6dab45bd
[
HW32.Packed.E546
]
35334f1fcb9d9350eb6e49b234372b5a
[
HW32.Packed.A975
]
92e6e23de4e8d594aed40fd9847ff1fd
e190e83fbfa8268b738da01d9b972ffb
[
HW32.Packed.1F6A
] [
Trojan.VBInject
] [
Trojan.Kryptik!N1/Qwv1Nf9Q
] [
W32/Trojan.ZIBX-8506
] [
Trojan.Cryptolocker.N
] [
Trojan.Win32.AD.dwbezb
] [
UnclassifiedMalware
] [
Trojan.Encoder.1770
] [
TeslaCrypt!E190E83FBFA8
] [
TR/AD.CryptoWall.Y.24
] [
Trojan:Win32/Dynamer!ac
] [
Trojan/Win32.Tescrypt
] [
TeslaCrypt!E190E83FBFA8
] [
Win32.Trojan.Ad.Ajbc
] [
Trojan.Win32.Crypt
] [
W32/Kryptik.DVAX!tr
] [
Crypt4.CDCO
] [
Adware.Win32.iBryte.DVGO
]
ffa1a998dceeec83f078c0527038e8d7
[
Trojan.Filecoder!U/t4sCtUKr8
] [
Trojan.Cryptolocker.N
] [
Win32/Filecoder.EM
] [
Trojan.Win32.MulDrop6.dwnqsi
] [
Trojan.MulDrop6.4658
] [
Trojan.Filecoder.Win32.778
] [
W32/Trojan.LSBV-1361
] [
Ransom:Win32/Tescrypt!rfn
] [
Trojan/Win32.Teslacrypt
] [
W32/Filecoder.EM!tr
] [
FileCryptor.DKM
] [
Trojan.Win32.Filecoder.EM
]
7902f2c1d0ef5353d6ddf1f551a68a2d
[
HW32.Packed.9976
] [
Trojan.TeslaCrypt
] [
Trojan.Cryptolocker.N
] [
Win32/Filecoder.EM
] [
TROJ_CRYPTESLA.CC
] [
Win32.Trojan.Crypt.Agba
] [
TROJ_CRYPTESLA.CC
] [
RDN/Ransom
] [
TR/Crypt.ZPACK.54367
] [
Ransom:Win32/Tescrypt.A
] [
Trojan/Win32.Netcurs
] [
RDN/Ransom
] [
Trj/CI.A
] [
Trojan.Win32.Filecoder
] [
W32/CRYPTESLA.CC!tr
] [
FileCryptor.DFF
] [
Trojan.Win32.Filecoder.EM
]
cfd7fe7b563971e20920f840d8f9619f
[
HW32.Packed.D28B
] [
Trojan.TeslaCrypt
] [
Trojan-Ransom.Win32.Bitman.yr
] [
Troj/Ransom-BGJ
] [
Trojan.DownLoader16.4942
] [
TR/Crypt.ZPACK.55171
] [
W32/Kryptik.8C4B!tr
] [
Ransom:Win32/Tescrypt.A
] [
Trojan/Win32.Tescrypt
] [
TeslaCrypt!CFD7FE7B5639
] [
Trojan.Win32.Ransom.yr
] [
Trojan.Win32.Crypt
] [
Crypt4.CDMN
]
Whois
Property
Value
Email
info@evanzo.de
NameServer
s9053.evanzo-server.de
Changed
2013-05-15 09:15:58
DNS Resolutions
Date
IP Address
2014-05-24
87.238.192.96
(
ClassC
)
2024-11-19
91.90.146.100
(
ClassC
)
Port 80
HTTP/1.1 301 Moved PermanentlyServer: nginxDate: Wed, 31 Jul 2019 12:59:13 GMTContent-Type: text/htmlContent-Length: 178Connection: keep-aliveLocation: https://ghostwriter-24.de/ html>head>title>301 Moved Permanently/title>/head>body bgcolorwhite>center>h1>301 Moved Permanently/h1>/center>hr>center>nginx/center>/body>/html>
Port 443
HTTP/1.1 301 Moved PermanentlyServer: nginxDate: Wed, 31 Jul 2019 12:59:14 GMTContent-Type: text/html; charsetiso-8859-1Content-Length: 312Connection: keep-aliveLocation: https://ghostwriter-24.de/wor !DOCTYPE HTML PUBLIC -//IETF//DTD HTML 2.0//EN>html>head>title>301 Moved Permanently/title>/head>body>h1>Moved Permanently/h1>p>The document has moved a hrefhttps://ghostwriter-24.de/wordpress/>here/a>./p>hr>address>Apache Server at ghostwriter-24.de Port 443/address>/body>/html>
View on OTX
|
View on ThreatMiner
Please enable JavaScript to view the
comments powered by Disqus.
Data with thanks to
AlienVault OTX
,
VirusTotal
,
Malwr
and
others
. [
Sitemap
]