Help RSS API Feed Maltego Contact                        

Domain > wtfismyip.com

More information on this domain is in AlienVault OTX

Is this malicious?

Reports

http://pastebin.com/d4EpJQgR    

Files that talk to wtfismyip.com

MD5A/V
d3b1afeee13e5c0144dab4c7b0f8dd78[Backdoor.Swrort]
ba6fcea833bbffeec7456b4da1fbd7b5
3b1940d675673a718114b372f8d177e8
86fc5040c8c717f88078b5fd362e065b
b73fee03a645694393c859ea0be31719
7ff6bd13beceebc9df5982422b4efb0d
c27b90309c929b6cf16b2cec3edb1914[HW32.Packed.8C82] [Trojan-FJJV!C27B90309C92] [Win32.Trojan.WisdomEyes.16070401.9500.9932] [Heur.AdvML.B] [Ransom_HPCERBER.SMJ] [Win32.Trojan.Raasj.Auto] [Trojan.DownLoader22.63827] [BehavesLike.Win32.Malware.dc] [Trojan.Zusy.D34714]
f78d37308ff9f44068a093920b275232[HEUR_JSRANSOM.O2] [HEUR.JS.Trojan.b] [Js.Trojan.Raas.Auto]
b5de2950294cc3e70ab54778e3908ba5[HW32.Packed.22B8] [Trojan/W32.Trickster.304174] [Artemis!B5DE2950294C] [Ransom_HPCERBER.SMJ] [Win32.Trojan.WisdomEyes.16070401.9500.9888] [Ransom_HPCERBER.SMJ] [Trojan.Win32.Trickster.bq] [Troj.W32.Trickster!c] [Trojan.DownLoader22.63827] [BehavesLike.Win32.Malware.dc] [Troj/Injecto-LE] [TR/Dropper.VB.giome] [Trojan/Win32.Trickster] [Trojan:Win32/Totbrick.C] [Win32/TrickBot.A] [W32/TrickBot.A!tr]
50a4a9be4395d0708379a74ce45608f1[Trojan.TrickBot] [Uds.Dangerousobject.Multi!c] [Win32.Trojan.WisdomEyes.16070401.9500.9987] [TROJ_TRICKBOT.D] [Trojan.Win32.Trickster.bg] [Trojan.PWS.Spy.20372] [backdoor.win32.bifrose.aci] [BehavesLike.Win32.VBObfus.dc] [Troj/Injecto-KV] [TR/Dropper.VB.gmzmy] [Trojan/Win32.Trickster.C1705114] [Artemis!50A4A9BE4395] [Trojan.Win32.Injector]

Whois

PropertyValue
Email CRUOHO@GMAIL.COM
NameServer NS2.WTFISMYIP.COM
Created 2003-05-19 00:00:00
Changed 2015-06-03 00:00:00
Expires 2019-05-19 00:00:00
Registrar ENOM, INC.

DNS Resolutions

DateIP Address
2015-02-1954.200.182.206 (ClassC)
2019-07-25198.27.74.146 (ClassC)
2019-11-2869.195.159.158 (ClassC)
2022-05-1163.141.246.34 (ClassC)
2023-08-1595.217.228.176 (ClassC)
2023-11-1315.204.2.228 (ClassC)
2024-10-05108.181.15.129 (ClassC)
2025-07-10198.27.70.99 (ClassC)
2025-10-14142.44.215.161 (ClassC)
2025-10-1865.108.75.112 (ClassC)
2025-12-29138.201.134.231 (ClassC)
2026-01-1823.158.72.62 (ClassC)

Port 80

Port 443

Subdomains

DateDomainIP
ns1.wtfismyip.com2024-02-193.231.180.250
NS2.WTFISMYIP.COM2026-01-18158.101.39.95
ns4.wtfismyip.com2021-05-29129.146.154.12
ipv4.wtfismyip.com2021-02-24207.231.106.130
xml.wtfismyip.com2024-10-08108.181.15.129
ipv4.xml.wtfismyip.com2024-09-28108.181.15.129
json.wtfismyip.com2024-09-17108.181.15.129
ipv4.json.wtfismyip.com2023-08-0495.217.228.176
stun.wtfismyip.com2025-08-27198.27.70.99
text.wtfismyip.com2025-06-27198.27.70.99
ipv4.text.wtfismyip.com2025-01-2865.108.75.112
www.wtfismyip.com2023-11-0115.204.2.228
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information