onlygoodman.com
Classification: Malicious
onlygoodman.com is a malicious hostname. Linked to Lokibot, Pony malware. Reported by 4 threat sources, last seen 2022-12-28.
Current activity
- Offline — no longer resolving. Last online 2022-12-28 07:53:03.
MITRE ATT&CK associations
Malware families: LOKIBOT (S0447) PONY (S0453)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Pony | Cybercrime-tracker.net | 2018-01-31 00:31:34 | 2022-12-28 07:53:03 | malicious-activity | S0453 Pony |
| Lokibot | Cybercrime-tracker.net | 2018-10-08 07:15:38 | 2022-12-28 07:40:09 | malicious-activity | S0447 Lokibot |
| Malicious domain | SANS Internet Storm Center | 2019-12-22 08:36:16 | 2019-12-22 08:36:16 | ||
| Gen:Variant.Strictor | Hybrid-Analysis | 2019-02-11 14:00:05 | 2019-02-11 14:00:05 | ||
| Malicious site | Hybrid-Analysis | 2019-01-30 15:00:06 | 2019-01-30 15:00:06 | ||
| Malware Download | Abuse.ch | 2018-12-10 20:10:31 | 2018-12-10 20:10:31 | ||
| CVE-2017-11882 | Hybrid-Analysis | 2018-09-24 11:30:18 | 2018-10-03 05:45:22 | ||
| W32.eHeur | Hybrid-Analysis | 2018-10-02 09:00:05 | 2018-10-02 09:00:05 | ||
| Backdoor.Androm | Hybrid-Analysis | 2018-09-25 04:30:09 | 2018-09-25 04:30:09 |
Tags
exeIP addresses resolved by this hostname
- 204.11.56.48 (2019-12-22 08:36:16)
Whois information
- AS name
- AS40034 Confluence Networks Inc
- Domain
- onlygoodman.com
- TLD
- com
- First indexed
- 2018-01-31 00:31:34
- Last updated
- 2024-11-27 12:10:47