medicosco.publicvm.com
Classification: Malicious
medicosco.publicvm.com is a malicious hostname. Linked to Apt-C-36 activity. Reported by 2 threat sources, last seen 2023-03-03.
Current activity
- Offline — no longer resolving. Last online 2023-03-03 15:19:15.
MITRE ATT&CK associations
Intrusion sets: APT-C-36 (G0099)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| APT-C-36 | Maltiverse | 2023-03-03 15:19:15 | 2023-03-03 15:19:15 | G0099 APT-C-36 G0099 APT-C-36 | |
| HEUR:Trojan.MSIL.Crypt | Hybrid-Analysis | 2019-02-25 09:30:06 | 2021-04-29 15:30:57 | ||
| Malicious site | Hybrid-Analysis | 2020-01-14 19:30:29 | 2020-01-14 19:30:29 | ||
| VB:Trojan.VBA.Agent | Hybrid-Analysis | 2019-05-30 15:45:18 | 2019-05-30 15:45:18 | ||
| Trojan.Generic | Hybrid-Analysis | 2019-02-25 07:30:15 | 2019-02-25 07:30:15 | ||
| HEUR.VBA.Trojan | Hybrid-Analysis | 2019-02-25 07:30:05 | 2019-02-25 07:30:05 |
IP addresses resolved by this hostname
- 128.90.115.79 (2019-02-25 07:03:45)
Whois information
- AS name
- AS22363 Powerhouse Management, Inc.
- Domain
- publicvm.com
- TLD
- com
- DNSSEC
- ['unsigned']
- Nameservers
- NS10.DNSEXIT.COM, NS11.DNSEXIT.COM, NS12.DNSEXIT.COM, NS13.DNSEXIT.COM, ns10.dnsExit.com, ns11.dnsExit.com, ns12.dnsExit.com, ns13.dnsExit.com
- Registrant
- Netdorm, Inc. dba DNSExit.com
- Address
- 8190-A Beechmont Ave, Ste 278
- City
- Cincinnati
- State
- Ohio
- Country
- US — United States 🇺🇸
- Contact email
- [email protected], [email protected], [email protected]
- Domain created
- 2007-07-19 05:57:17
- Domain expires
- 2028-07-19 05:57:17
- First indexed
- 2019-02-25 07:03:45
- Last updated
- 2026-07-15 06:36:20