mrassociattes.com
Classification: Malicious
mrassociattes.com is a malicious hostname. Linked to Icedid malware. Reported by 2 threat sources, last seen 2023-03-26.
Current activity
- Offline — no longer resolving. Last online 2024-11-20 20:22:06.
- Command & Control server — Used by cybercriminals to control victim computers.
MITRE ATT&CK associations
Malware families: ICEDID (S0483)
Intrusion sets: GAMAREDON GROUP (G0047)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Razor Tiger | Maltiverse | 2023-03-25 05:46:37 | 2023-03-26 18:35:20 | malicious-activity | |
| Gamaredon Group | Maltiverse | 2023-03-25 05:46:45 | 2023-03-26 18:35:19 | malicious-activity | G0047 Gamaredon Group |
| IcedID | ThreatFox Abuse.ch | 2023-02-22 00:11:49 | 2023-02-24 00:18:36 | malicious-activity | S0483 IcedID |
| IcedID Downloader | ThreatFox Abuse.ch | 2023-02-21 22:17:38 | 2023-02-21 22:17:38 | malicious-activity |
Tags
apt bokbot iceidIP addresses resolved by this hostname
- 174.138.188.6 (2024-11-20 20:22:06)
Whois information
- AS name
- AS19318 NEW JERSEY INTERNATIONAL INTERNET EXCHANGE LLC
- Domain
- mrassociattes.com
- TLD
- com
- First indexed
- 2023-02-21 22:17:38
- Last updated
- 2024-11-20 20:28:46