medicosco.publicvm.com

Classification: Malicious

medicosco.publicvm.com is a malicious hostname. Linked to Apt-C-36 activity. Reported by 2 threat sources, last seen 2023-03-03.

Current activity

  • Offline — no longer resolving. Last online 2023-03-03 15:19:15.

MITRE ATT&CK associations

Intrusion sets: APT-C-36 (G0099)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
APT-C-36 Maltiverse 2023-03-03 15:19:15 2023-03-03 15:19:15 G0099 APT-C-36 G0099 APT-C-36
HEUR:Trojan.MSIL.Crypt Hybrid-Analysis 2019-02-25 09:30:06 2021-04-29 15:30:57
Malicious site Hybrid-Analysis 2020-01-14 19:30:29 2020-01-14 19:30:29
VB:Trojan.VBA.Agent Hybrid-Analysis 2019-05-30 15:45:18 2019-05-30 15:45:18
Trojan.Generic Hybrid-Analysis 2019-02-25 07:30:15 2019-02-25 07:30:15
HEUR.VBA.Trojan Hybrid-Analysis 2019-02-25 07:30:05 2019-02-25 07:30:05

IP addresses resolved by this hostname

Whois information

AS name
AS22363 Powerhouse Management, Inc.
Domain
publicvm.com
TLD
com
DNSSEC
['unsigned']
Nameservers
NS10.DNSEXIT.COM, NS11.DNSEXIT.COM, NS12.DNSEXIT.COM, NS13.DNSEXIT.COM, ns10.dnsExit.com, ns11.dnsExit.com, ns12.dnsExit.com, ns13.dnsExit.com
Registrant
Netdorm, Inc. dba DNSExit.com
Address
8190-A Beechmont Ave, Ste 278
City
Cincinnati
State
Ohio
Country
US — United States 🇺🇸
Contact email
[email protected], [email protected], [email protected]
Domain created
2007-07-19 05:57:17
Domain expires
2028-07-19 05:57:17
First indexed
2019-02-25 07:03:45
Last updated
2026-07-15 06:36:20