twtw.toh.info(chinese malware hosted in Hong Kong Nwt Idc Data Service)

Name Query Type Query Result Successful Protocol
twtw.toh.info DNS_TYPE_A 58.64.203.53 YES udp

– Unknown TCP Traffic:
58.64.203.53:443
State: Connection established, not terminated – Transferred outbound Bytes: 672 – Transferred inbound Bytes: 14657
Data sent:

exe file:
http://a3dc4d85.theseblogs.com

infos about hosting:
http://whois.domaintools.com/58.64.203.53

Categories: Uncategorized