avv-tdk.info
|
dns2.name-services.com => 216.40.47.201 dns5.name-services.com => 64.98.148.139 dns3.name-services.com => 64.98.148.138 dns1.name-services.com => 64.98.148.137 dns4.name-services.com => 216.40.47.202 |
(AS9009) M247 |
Trojan |
2025-01-30
|
ua-mil.cloud
|
dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 dns5.name-services.com => 64.98.148.139 dns3.name-services.com => 64.98.148.138 |
(AS26042) FIBERST |
Botnet controller |
2024-10-23
|
s3-monitoring.cloud
|
dns2.name-services.com => 216.40.47.201 dns5.name-services.com => 64.98.148.139 dns4.name-services.com => 216.40.47.202 dns3.name-services.com => 64.98.148.138 dns1.name-services.com => 64.98.148.137 |
(AS29802) HVC |
Botnet controller |
2024-10-23
|
s3-knowbe4.cloud
|
dns2.name-services.com => 216.40.47.201 dns5.name-services.com => 64.98.148.139 dns3.name-services.com => 64.98.148.138 dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 |
(AS9009) M247 |
Botnet controller |
2024-10-23
|
s3-csis.cloud
|
dns2.name-services.com => 216.40.47.201 dns5.name-services.com => 64.98.148.139 dns3.name-services.com => 64.98.148.138 dns1.name-services.com => 64.98.148.137 dns4.name-services.com => 216.40.47.202 |
(AS29802) HVC |
Botnet controller |
2024-10-23
|
mod-gov-il.cloud
|
dns4.name-services.com => 216.40.47.202 dns3.name-services.com => 64.98.148.138 dns1.name-services.com => 64.98.148.137 dns5.name-services.com => 64.98.148.139 dns2.name-services.com => 216.40.47.201 |
(AS51852) PLI |
Botnet controller |
2024-10-23
|
mfa-gov-il.cloud
|
dns5.name-services.com => 64.98.148.139 dns3.name-services.com => 64.98.148.138 dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 dns2.name-services.com => 216.40.47.201 |
(AS51852) PLI |
Botnet controller |
2024-10-23
|
aws-meetings.cloud
|
dns3.name-services.com => 64.98.148.138 dns1.name-services.com => 64.98.148.137 dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 dns5.name-services.com => 64.98.148.139 |
(AS8100) IPTELLIGENT |
Botnet controller |
2024-10-23
|
anaemiaalmostforests.com
|
dns1.name-services.com => 64.98.148.137 dns5.name-services.com => 64.98.148.139 dns3.name-services.com => 64.98.148.138 dns4.name-services.com => 216.40.47.202 dns2.name-services.com => 216.40.47.201 |
(AS16509) AMAZON-02 |
ApateWeb malware campaign (JS Script Redirects) |
2024-06-03
|
datapunchunite.com
|
dns1.name-services.com => 64.98.148.137 dns4.name-services.com => 216.40.47.202 dns5.name-services.com => 64.98.148.139 dns2.name-services.com => 216.40.47.201 dns3.name-services.com => 64.98.148.138 |
(AS16509) AMAZON-02 |
ApateWeb malware campaign (JS Script Redirects) |
2024-06-03
|
districtacrid.com
|
dns5.name-services.com => 64.98.148.139 dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 dns3.name-services.com => 64.98.148.138 dns2.name-services.com => 216.40.47.201 |
(AS16509) AMAZON-02 |
ApateWeb malware campaign (JS Script Redirects) |
2024-06-03
|
facultativecheating.com
|
dns4.name-services.com => 216.40.47.202 dns2.name-services.com => 216.40.47.201 dns3.name-services.com => 64.98.148.138 dns1.name-services.com => 64.98.148.137 dns5.name-services.com => 64.98.148.139 |
(AS16509) AMAZON-02 |
ApateWeb malware campaign (JS Script Redirects) |
2024-06-03
|
finishnecklace.com
|
dns1.name-services.com => 64.98.148.137 dns5.name-services.com => 64.98.148.139 dns4.name-services.com => 216.40.47.202 dns3.name-services.com => 64.98.148.138 dns2.name-services.com => 216.40.47.201 |
(AS16509) AMAZON-02 |
ApateWeb malware campaign (JS Script Redirects) |
2024-06-03
|
pushedgraceful.com
|
dns2.name-services.com => 216.40.47.201 dns5.name-services.com => 64.98.148.139 dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 dns3.name-services.com => 64.98.148.138 |
(AS16509) AMAZON-02 |
ApateWeb malware campaign (JS Script Redirects) |
2024-06-03
|
obesewaterfall.com
|
dns2.name-services.com => 216.40.47.201 dns1.name-services.com => 64.98.148.137 dns4.name-services.com => 216.40.47.202 dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 |
(AS16509) AMAZON-02 |
ApateWeb malware campaign (JS Script Redirects) |
2024-06-03
|
uncoverherbal.com
|
dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 dns2.name-services.com => 216.40.47.201 |
(AS16509) AMAZON-02 |
ApateWeb malware campaign (JS Script Redirects) |
2024-06-03
|
wantimpeccablecornflower.com
|
dns1.name-services.com => 64.98.148.137 dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 dns5.name-services.com => 64.98.148.139 dns3.name-services.com => 64.98.148.138 |
(AS16509) AMAZON-02 |
ApateWeb malware campaign (JS Script Redirects) |
2024-06-03
|
examinationevolutionmingle.com
|
dns3.name-services.com => 64.98.148.138 dns1.name-services.com => 64.98.148.137 dns5.name-services.com => 64.98.148.139 dns4.name-services.com => 216.40.47.202 dns2.name-services.com => 216.40.47.201 |
(AS16509) AMAZON-02 |
ApateWeb malware campaign (JS Script Redirects) |
2024-06-03
|
lnk.360clickmedia.com
|
dns4.name-services.com => 216.40.47.202 dns2.name-services.com => 216.40.47.201 dns1.name-services.com => 64.98.148.137 dns5.name-services.com => 64.98.148.139 dns3.name-services.com => 64.98.148.138 |
(AS16509) AMAZON-02 |
Leads to malware (ApateWeb) |
2024-06-03
|
360clickmedia.com
|
dns5.name-services.com => 64.98.148.139 dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 dns3.name-services.com => 64.98.148.138 dns1.name-services.com => 64.98.148.137 |
(AS32133) AS-TING-BACKB |
Leads to malware (ApateWeb) |
2024-06-03
|
geoffreyjelly.com
|
dns3.name-services.com => 64.98.148.138 dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 dns5.name-services.com => 64.98.148.139 |
(AS16509) AMAZON-02 |
ApateWeb malware campaign |
2024-05-24
|
lse-crypto.com
|
dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 dns1.name-services.com => 64.98.148.137 dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 |
(AS139646) HKMTC-AS-AP HONG KONG Megalayer Technology Co.,Limited, HK |
Phishing |
2024-03-03
|
lscryptv.com
|
dns2.name-services.com => 216.40.47.201 dns5.name-services.com => 64.98.148.139 dns3.name-services.com => 64.98.148.138 dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 |
(AS139646) HKMTC-AS-AP HONG KONG Megalayer Technology Co.,Limited, HK |
Phishing |
2024-03-03
|
alareeef.com
|
dns4.name-services.com => 216.40.47.202 dns5.name-services.com => 64.98.148.139 dns2.name-services.com => 216.40.47.201 dns1.name-services.com => 64.98.148.137 dns3.name-services.com => 64.98.148.138 |
(AS55293) A2HOSTING |
Malicious domain |
2024-03-03
|
m.bitshjo.com
|
dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 dns2.name-services.com => 216.40.47.201 dns5.name-services.com => 64.98.148.139 dns3.name-services.com => 64.98.148.138 |
(AS64050)
BCPL-SG |
Malicious domain |
2024-03-03
|
bank.triangletech.com.bd
|
dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 dns1.name-services.com => 64.98.148.137 dns4.name-services.com => 216.40.47.202 dns2.name-services.com => 216.40.47.201 |
(AS63949) LINODE-AP |
Malicious domain |
2024-03-02
|
zapatoventa.shop
|
dns1.name-services.com => 64.98.148.137 dns2.name-services.com => 216.40.47.201 dns3.name-services.com => 64.98.148.138 dns4.name-services.com => 216.40.47.202 dns5.name-services.com => 64.98.148.139 |
(AS16509) AMAZON-02 |
Malicious domain |
2024-03-03
|
restorescotia.com
|
dns2.name-services.com => 216.40.47.201 dns1.name-services.com => 64.98.148.137 dns4.name-services.com => 216.40.47.202 dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 |
(AS32133) AS-TING-BACKB |
Malicious domain |
2024-03-03
|
growth-capital.ltd
|
dns3.name-services.com => 64.98.148.138 dns2.name-services.com => 216.40.47.201 dns1.name-services.com => 64.98.148.137 dns4.name-services.com => 216.40.47.202 dns5.name-services.com => 64.98.148.139 |
(AS16509) AMAZON-02 |
Malicious domain |
2024-03-03
|
cpcalendars.growth-capital.ltd
|
dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 dns4.name-services.com => 216.40.47.202 dns2.name-services.com => 216.40.47.201 dns1.name-services.com => 64.98.148.137 |
(AS16509) AMAZON-02 |
Malicious domain |
2024-03-03
|
webmail.growth-capital.ltd
|
dns5.name-services.com => 64.98.148.139 dns1.name-services.com => 64.98.148.137 dns3.name-services.com => 64.98.148.138 dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 |
(AS16509) AMAZON-02 |
Malicious domain |
2024-03-03
|
cfxfinance.com
|
dns1.name-services.com => 64.98.148.137 dns5.name-services.com => 64.98.148.139 dns3.name-services.com => 64.98.148.138 dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 |
(AS32133) AS-TING-BACKB |
Malicious domain |
2024-03-03
|
td-accessrestore.com
|
dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 dns2.name-services.com => 216.40.47.201 dns1.name-services.com => 64.98.148.137 dns4.name-services.com => 216.40.47.202 |
(AS32133) AS-TING-BACKB |
Malicious domain |
2024-03-03
|
intesasanpaloe.com
|
dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 dns2.name-services.com => 216.40.47.201 dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 |
(AS32133) AS-TING-BACKB |
Malicious domain |
2024-03-03
|
cpanel.goldparkhosting.com
|
dns4.name-services.com => 216.40.47.202 dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 dns1.name-services.com => 64.98.148.137 dns2.name-services.com => 216.40.47.201 |
(AS36218) CIRRUSTECHLTD |
Malicious domain |
2024-03-03
|
cpcontacts.goldparkhosting.com
|
dns4.name-services.com => 216.40.47.202 dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 dns2.name-services.com => 216.40.47.201 dns1.name-services.com => 64.98.148.137 |
(AS36218) CIRRUSTECHLTD |
Malicious domain |
2024-03-03
|
webmail.goldparkhosting.com
|
dns4.name-services.com => 216.40.47.202 dns5.name-services.com => 64.98.148.139 dns2.name-services.com => 216.40.47.201 dns3.name-services.com => 64.98.148.138 dns1.name-services.com => 64.98.148.137 |
(AS36218) CIRRUSTECHLTD |
Malicious domain |
2024-03-03
|
cpanel.premiumshareslimited.com
|
dns1.name-services.com => 64.98.148.137 dns2.name-services.com => 216.40.47.201 dns5.name-services.com => 64.98.148.139 dns4.name-services.com => 216.40.47.202 dns3.name-services.com => 64.98.148.138 |
(AS16509) AMAZON-02 |
Malicious domain |
2024-03-03
|
cpcontacts.td-accessrestore.com
|
dns2.name-services.com => 216.40.47.201 dns1.name-services.com => 64.98.148.137 dns4.name-services.com => 216.40.47.202 dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 |
(AS32133) AS-TING-BACKB |
Malicious domain |
2024-03-03
|
coinbase.thawrani.com
|
dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 dns2.name-services.com => 216.40.47.201 |
(AS46606) BLUEHOST |
Malicious domain |
2024-03-02
|
webmail.mygreentechnologyinternetsolutions.com
|
dns1.name-services.com => 64.98.148.137 dns5.name-services.com => 64.98.148.139 dns4.name-services.com => 216.40.47.202 dns3.name-services.com => 64.98.148.138 dns2.name-services.com => 216.40.47.201 |
(AS16509) AMAZON-02 |
Malicious domain |
2024-03-02
|
webmail.mybingsolutions.com
|
dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 dns5.name-services.com => 64.98.148.139 dns2.name-services.com => 216.40.47.201 dns3.name-services.com => 64.98.148.138 |
(AS16509) AMAZON-02 |
Malicious domain |
2024-03-02
|
cpcontacts.tdrecovery-client.com
|
dns5.name-services.com => 64.98.148.139 dns4.name-services.com => 216.40.47.202 dns2.name-services.com => 216.40.47.201 dns3.name-services.com => 64.98.148.138 dns1.name-services.com => 64.98.148.137 |
(AS32133) AS-TING-BACKB |
Malicious domain |
2024-03-02
|
cpcalendars.tdrecovery-client.com
|
dns1.name-services.com => 64.98.148.137 dns5.name-services.com => 64.98.148.139 dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 dns3.name-services.com => 64.98.148.138 |
(AS32133) AS-TING-BACKB |
Malicious domain |
2024-03-02
|
cpanel.tdrecovery-client.com
|
dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 dns1.name-services.com => 64.98.148.137 dns3.name-services.com => 64.98.148.138 dns5.name-services.com => 64.98.148.139 |
(AS32133) AS-TING-BACKB |
Malicious domain |
2024-03-02
|
coinex-nitro.com
|
dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 dns5.name-services.com => 64.98.148.139 dns1.name-services.com => 64.98.148.137 dns3.name-services.com => 64.98.148.138 |
(AS16509) AMAZON-02 |
Malicious domain |
2024-02-29
|
support-mobile-alb.com
|
dns2.name-services.com => 216.40.47.201 dns3.name-services.com => 64.98.148.138 dns4.name-services.com => 216.40.47.202 dns5.name-services.com => 64.98.148.139 dns1.name-services.com => 64.98.148.137 |
(AS32133) AS-TING-BACKB |
Malicious domain |
2024-03-01
|
pelicanexpress.netqps.net
|
dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 dns5.name-services.com => 64.98.148.139 dns1.name-services.com => 64.98.148.137 dns3.name-services.com => 64.98.148.138 |
(AS32133) AS-TING-BACKB |
Malicious domain |
2024-03-01
|
support-netbank.com
|
dns2.name-services.com => 216.40.47.201 dns4.name-services.com => 216.40.47.202 dns5.name-services.com => 64.98.148.139 dns1.name-services.com => 64.98.148.137 dns3.name-services.com => 64.98.148.138 |
(AS32133) AS-TING-BACKB |
Malicious domain |
2024-03-01
|
ftradinx.net
|
dns5.name-services.com => 64.98.148.139 dns2.name-services.com => 216.40.47.201 dns1.name-services.com => 64.98.148.137 dns3.name-services.com => 64.98.148.138 dns4.name-services.com => 216.40.47.202 |
(AS16509) AMAZON-02 |
Malicious domain |
2024-02-29
|