Help RSS API Feed Maltego Contact                        

Domain > open.citibank.co.kr

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to open.citibank.co.kr

MD5A/V
74c7fd7485b506227b48c8d7a753598f[Suspicious.Cloud.5] [BackDoor.Tdss.11228] [Artemis] [TrojanSpy:Win32/Wedots.A] [Artemis!74C7FD7485B5] [BScope.P2P-Worm.Palevo] [Win32.SuspectCrc] [PSW.Banker7.AQY.dropper]
54ef9c6081750e1edc56c1acda43a22f[HW32.Packed.815C] [Artemis!54EF9C608175] [Win32.Trojan.Startpage.Sxox] [BehavesLike.Win32.BadFile.cc] [TrojanSpy:Win32/Wedots.A]
4d478143711cbd2c7f26c3a5ed354bad[HW32.Packed.2437] [Artemis!4D478143711C] [TSPY_WEDOTS.B] [TSPY_WEDOTS.B] [BehavesLike.Win32.BadFile.cc] [TrojanSpy:Win32/Wedots.A] [Win32/Heur] [Win32/Trojan.97a]
ce57ff193cbe410b1b9561c33e0da6a2
11b9401daec4c85cddd9fba66fae75ba[Backdoor.Trojan] [BackDoor.Tdss.11228] [TrojanSpy:Win32/Wedots.A] [BScope.P2P-Worm.Palevo] [Win32/DH{Jw9YZ1I}] [Win32/Trojan.97a]
f201e087e3c3a827497798939b891acb
6937609df01ac327b02a41d780aefbd8[Suspicious.Cloud.5] [Mal/EncPk-CK] [BackDoor.Tdss.11228] [BehavesLike.Win32.BadFile.cc] [W32/Banker.ABEA!tr.spy] [Artemis!6937609DF01A] [BScope.P2P-Worm.Palevo] [PSW.Banker7.BWA] [Trojan.Win32.Banker.ABEA]
efcb0636e429e3f099400ef276db96b0
7cdc187a56e483a6aa0a519a8c2c3c62

Whois

PropertyValue
NameCitibank NA
Email domain.admin@citi.com
Address Citigroup 4F, #1127, Guwol-dong, Namdong-gu
Zip Code 405220
NameServer ns2.citicorp.com
Created 1997-06-28 00:00:00
Changed 2015-08-01 00:00:00
Expires 2016-10-15 00:00:00
Registrar Gabia, Inc.

DNS Resolutions

DateIP Address
2014-01-09192.193.83.182 (ClassC)
2014-11-19192.193.81.182 (ClassC)
2019-06-30192.193.83.203 (ClassC)
2019-07-19192.193.81.203 (ClassC)
2019-09-06104.109.113.217 (ClassC)
2023-12-18104.112.189.210 (ClassC)
2024-07-30184.25.199.213 (ClassC)
2024-09-0323.44.247.167 (ClassC)
2024-09-1023.6.107.161 (ClassC)
2024-09-1323.195.239.185 (ClassC)
2024-12-3123.55.167.25 (ClassC)
2025-03-2223.55.111.161 (ClassC)
2025-04-1123.192.230.142 (ClassC)
2025-05-1123.192.230.138 (ClassC)

Port 80

Port 443

Subdomains

DateDomainIP
mobile.citibank.co.kr2023-08-25104.90.249.16
open.citibank.co.kr2014-11-19192.193.81.182
echat.citibank.co.kr2025-04-04192.193.83.202
mobileuat.citibank.co.kr2023-08-2523.222.151.222
homeuat.citibank.co.kr2023-08-2523.195.237.236
echatuat.citibank.co.kr2025-04-16192.193.81.210
mobilesit.citibank.co.kr2024-03-2323.44.250.82
echatsit.citibank.co.kr2025-05-13192.193.81.221
www.citibank.co.kr2024-07-3023.213.21.144
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information