Help RSS API Feed Maltego Contact                        

Domain > mx1.mail.139.com

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to mx1.mail.139.com

MD5A/V
c7bf064346fafe4fc55b43abcfe96b00[HW32.CDB.E6f3] [Backdoor.Kelihos.r3] [Backdoor.Hlux!zUFIktBYK3s] [Kryptik.CCFN] [Backdoor.Win32.Hlux.djfw] [Trojan.Win32.S.PSW-Tepfer.835600.AM] [UnclassifiedMalware] [BackDoor.Slym.14049] [Mal/Kelihos-A] [Backdoor:Win32/Kelihos] [Trojan/Win32.Tepfer] [W32/Trojan.QQUO-1304] [Backdoor.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt3.HUC] [Trojan.Win32.Kryptik.BZIX]
e6d960bf587f5cb1497520fe716f1fb4[Malware.Packer.FFS] [BackDoor.SlymENT.2075] [Heuristic.LooksLike.Win32.Suspicious.E] [Backdoor:Win32/Kelihos.F] [PE:Malware.XPACK/RDM!5.1]
24a034d09222c5370365c4cdadde0f65[HW32.CDB.Da0d] [Packed.Win32.Katusha.3!O] [Kryptik.CDQY] [TrojWare.Win32.Kryptik.CBCJ] [Trojan.Packed.26581] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BD!tr] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CBCJ] [Win32/Trojan.0de]
292ad75fbab2288a453c7f7db162eed0[HW32.CDB.A2b5] [Packed.Win32.Katusha.3!O] [Backdoor.Hlux!xuwpKhCjMA8] [WS.Reputation.1] [Kryptik.CDQY] [Backdoor.Win32.Hlux.dqzg] [UnclassifiedMalware] [Trojan.Packed.26581] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos] [W32/Trojan.HATR-5126] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.Aj] [Win32/Trojan.112]

Whois

PropertyValue
Email wanggang@gd.chinamobile.com
NameServer NS2.CNMOBILE.NET
Created 1997-04-26 00:00:00
Changed 2015-05-18 00:00:00
Expires 2019-04-27 00:00:00
Registrar XIN NET TECHNOLOGY C

DNS Resolutions

DateIP Address
2013-05-31221.176.9.178 (ClassC)
2015-05-28221.176.66.188 (ClassC)
2026-01-15120.232.169.1 (ClassC)

Subdomains

DateDomainIP
c.139.com2025-01-01117.161.4.213
ad.mcloud.139.com2025-11-24117.161.140.28
note.mcloud.139.com2025-12-03112.33.119.147
img.mcloud.139.com2026-01-14120.232.188.18
yun.mcloud.139.com2025-10-2336.138.4.153
mx1.mail.139.com2014-04-25221.176.9.178
middle.yun.139.com2024-11-0736.138.55.73
notesearch.yun.139.com2025-12-01112.33.119.147
ai.yun.139.com2024-09-1836.139.11.132
group.yun.139.com2024-07-2936.155.89.2
group-kd-njs.yun.139.com2025-11-2436.140.64.112
voice-njs.yun.139.com2025-12-05112.33.119.147
cardpackage-njs.yun.139.com2025-12-03112.33.119.147
note-njs.yun.139.com2025-12-0136.140.64.98
portal-njs.yun.139.com2025-12-01112.33.119.147
album-njs.yun.139.com2025-12-0136.140.64.98
user-njs.yun.139.com2025-09-0536.140.64.118
www.139.com2013-12-14120.132.134.57
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information