citrix.vipreclod.com
Classification: Malicious
citrix.vipreclod.com is a malicious hostname. Reported by 2 threat sources, last seen 2024-08-14. IoC context and downloadable threat intel on Maltiverse.
Current activity
- Offline — no longer resolving. Last online 2024-08-14 15:19:44.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Sakula RAT | ThreatFox Abuse.ch | 2024-08-12 15:59:39 | 2024-08-14 15:19:43 | malicious-activity | |
| Trojan.Scar | Hybrid-Analysis | 2019-10-19 19:15:07 | 2021-10-01 07:46:04 | ||
| Gen:Trojan.Heur.D | Hybrid-Analysis | 2019-04-01 18:30:09 | 2019-04-01 18:45:17 |
Tags
ais-fibre-as-ap as133481 c2 rat sakurelIP addresses resolved by this hostname
- 204.11.56.48 (2019-04-01 18:30:09)
Whois information
- AS name
- AS40034 Confluence Networks Inc
- Domain
- vipreclod.com
- TLD
- com
- DNSSEC
- ['unsigned']
- Nameservers
- NS63.DOMAINCONTROL.COM, NS64.DOMAINCONTROL.COM
- Registrant
- GoDaddy.com, LLC
- Contact email
- [email protected]
- Domain created
- 2018-05-19 18:24:59
- Domain expires
- 2027-05-19 18:24:59
- First indexed
- 2019-04-01 18:30:09
- Last updated
- 2026-07-02 17:00:41