Help RSS API Feed Maltego Contact                        

Domain > qx.rausers.com

This indicator is referenced in AlienVault OTX pulse ""

Is this malicious?

Most users have voted this as MALICIOUS

Reports

http://blog.cylance.com/cylanceprotect-vs-glassrat    
https://blog.cylance.com/cylanceprotect-vs-glassra...    
https://blogs.rsa.com/peering-into-glassrat/    
https://blogs.rsa.com/wp-content/uploads/2015/11/G...    
https://otx.alienvault.com/pulse/565372a04637f2388...    
https://otx.alienvault.com/pulse/5659bb5667db8c7a1...    
https://otx.alienvault.com/pulse/56af8fbf67db8c6aa...    

Files that talk to qx.rausers.com

MD5A/V
37adc72339a0c2c755e7fef346906330[Backdoor.Trojan] [TrojanDropper:Win32/GlassRat.A!RAT] [Trojan/Win32.GlassRat] [Win32/GlassRAT.A] [Trojan-Dropper.Win32.GlassRat] [Trj/CI.A]

Whois

PropertyValue
Email raxiangmu@yahoo.com.cn
NameServer NS.CNKUAI.COM
Created 2013-02-27 00:00:00
Changed 2015-03-16 00:00:00
Expires 2017-02-27 00:00:00
Registrar WEB COMMERCE COMMUNI