Help RSS API Feed Maltego Contact                        

Domain > ns1.oray.net

More information on this domain is in AlienVault OTX

Is this malicious?

Most users have voted this as MALICIOUS

Reports

https://otx.alienvault.com/pulse/55553e26b45ff5703...    
https://www.mpi-sws.org/~stevens/pubs/sec14.pdf    
https://www.usenix.org/system/files/conference/use...    

Files that talk to ns1.oray.net

MD5A/V
8455bbb9a210ce603a1b646b0d951bce[Backdoor.Tranikpik] [BackDoor-FBSR] [Backdoor.ZXShell] [ZXProxy.AB] [Backdoor.Win32.S.ZxPlug.86016] [UnclassifiedMalware] [BDS/Tranikpik.A] [BKDR_ZXSHELL.V] [Troj/ZxShell-A] [Backdoor:Win32/Tranikpik.A] [Win-Trojan/Backdoor.86016.R] [BScope.Trojan.SvcHorse.01643] [Backdoor.Win32.Tranikpik]
eddfbf35ac07fa9ab25cc4c421e205fe
3532e0f9244c0b89e9fe426afc8226cb
84536c2157e9b22ac9d17b3a6e032121

Whois

PropertyValue
Email yezi@oray.com
NameServer NS2.ORAY.NET
Created 1998-11-02 00:00:00
Changed 2011-08-19 00:00:00
Expires 2018-11-01 00:00:00
Registrar SHANGHAI BEST ORAY I

DNS Resolutions

DateIP Address
2013-04-01220.170.79.231 (ClassC)
2013-04-18220.170.79.233 (ClassC)
2013-04-30122.226.163.8 (ClassC)
2013-06-21183.136.132.170 (ClassC)
2014-02-24220.170.79.229 (ClassC)
2014-02-24183.136.132.170 (ClassC)
2014-08-21199.193.253.110 (ClassC)
2015-01-0561.174.40.200 (ClassC)
2015-04-27220.170.79.229 (ClassC)
2015-07-03103.44.145.246 (ClassC)
2015-07-22115.29.234.127 (ClassC)
2018-10-16103.46.128.51 (ClassC)
2019-06-21103.46.128.52 (ClassC)
2019-07-12120.26.12.130 (ClassC)
2019-08-3147.91.136.105 (ClassC)
2024-07-02114.117.32.113 (ClassC)
2024-07-08116.62.241.133 (ClassC)
2024-09-2747.115.57.253 (ClassC)
2025-05-22101.37.15.183 (ClassC)
2025-05-26134.175.75.248 (ClassC)

Reverse NameServers

DateDomain
appleupdate.biz2015-04-19
sygay.cn2016-04-09
hagaku.cn2016-04-09
chinajili.com.cn2016-04-12
i64.biz2016-06-16
aliviews.cn2016-09-18
viewface.cn2016-09-19
mallcctv.cn2016-09-19
raytao.com.cn2016-09-20
viewdows.com.cn2016-09-21
hitvphone.cn2016-09-21
cay.so2016-09-28
yzkj.cc2016-10-03
abcstudio.biz2016-10-04

Subdomains

DateDomainIP
phtun-std0.oray.net2015-01-01120.24.223.57
phtun-prm0.oray.net2014-11-21202.105.21.213
phtun-biz0.oray.net2014-11-06202.105.21.213
ns1.oray.net2015-01-0561.174.40.200
NS1.ORAY.NET2015-04-27220.170.79.229
phservice2.oray.net2023-12-22115.236.153.182
phfwba-std-g2.oray.net2025-05-27115.236.153.172
ns2.oray.net2013-11-18115.238.186.55
NS2.ORAY.NET2021-03-01123.59.51.110
phfwba-std-g3.oray.net2025-05-17115.236.153.174
ns3.oray.net2025-05-2747.76.61.78
ns4.oray.net2025-05-2747.242.74.119
bb.oray.net2014-12-25199.193.253.110
billboard.oray.net2025-04-0138.145.211.157
hphwebservice.oray.net2024-01-09115.236.153.182
hphws-tp.oray.net2020-02-24175.6.228.198
client.oray.net2013-11-05220.170.79.233
www.oray.net2025-05-2747.110.142.43
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information