Help RSS API Feed Maltego Contact                        

Domain > masterhost.ru

More information on this domain is in AlienVault OTX

Is this malicious?

Reports

https://otx.alienvault.com/pulse/56accf974637f2355...    
https://www.virustotal.com/en/ip-address/104.28.11...    

Files that talk to masterhost.ru

MD5A/V
4211b2d7121c11d5f032e6620030a384[HW32.CDB.Cd7e] [Packed.Win32.Katusha.3!O] [Hlux.ZY] [VirTool:Win32/Obfuscator.WT]
db5b440f6419090cd9567f3b33fd3ced[Malware.Packer.HGX1] [BackDoor.SlymENT.1498] [Heuristic.LooksLike.Win32.Suspicious.E] [W32/Kryptik.AXUE!tr]
b36385662ebdaf40bc3d28f90b6a4751[Spyware.Zbot.USBV] [Trojan] [BackDoor.SlymENT.1498] [Heuristic.LooksLike.Win32.Suspicious.E] [Trojan/Win32.Foreign]
2c2371e95bb5d87ccd5d19a114492f70[HW32.CDB.18af] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CDQY] [TrojWare.Win32.Kryptik.CBCJ] [BackDoor.Slym.13873] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Backdoor.Win32.Kelihos] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CBCJ] [Win32/Trojan.0de]
4a110bd7cb835d71df2345ad50c25b23[HW32.CDB.9f50] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [UnclassifiedMalware] [BackDoor.Slym.13873] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CBCJ] [Win32/Trojan.0de]
3223f61af50aa26a1c3bb96fe1779011[HW32.CDB.D56b] [Packed.Win32.Katusha.3!O] [Backdoor.Hlux.r3] [Backdoor.Hlux.Win32.9065] [Trojan.Win32.Kryptik.czfnsp] [Trojan.FakeAV] [Kryptik.CCQY] [Backdoor.Win32.Hlux.dueu] [Backdoor.Hlux!DdFHfWii/ns] [UnclassifiedMalware] [TR/Kryptik.oenzk] [Backdoor:Win32/Kelihos] [Trojan/Win32.FakeAV] [Heur.Trojan.Hlux] [Backdoor.Win32.Hlux.cri] [Trojan.Crypt3] [W32/Kryptik.CBOM!tr] [Crypt3.ORV] [Backdoor.Win32.Hlux.Acmu] [Win32/Trojan.7bf]
e21b3469b4fc1efddf76d8c89f1ebb2a[Malware.Packer.HGX1] [Heuristic.LooksLike.Win32.Suspicious.E] [W32/Kryptik.AXUE!tr]

DNS Resolutions

DateIP Address
2012-09-2487.242.99.124 (ClassC)
2013-06-0390.156.150.168 (ClassC)
2019-05-3090.156.219.61 (ClassC)
2019-09-1390.156.219.62 (ClassC)
2023-08-2690.156.153.253 (ClassC)
2025-08-1990.156.132.125 (ClassC)

Port 80

Port 443

Subdomains

DateDomainIP
nimap1.masterhost.ru2025-07-2583.222.23.140
npop1.masterhost.ru2025-01-1683.222.23.140
builder1.masterhost.ru2025-03-1490.156.201.54
ns1.masterhost.ru2024-03-30217.16.16.20
NS1.MASTERHOST.RU2025-08-1590.156.137.50
mx1.masterhost.ru2014-06-16217.16.16.81
NS2.MASTERHOST.RU2019-10-25217.16.22.30
ns2.masterhost.ru2024-03-29217.16.22.15
mx4.masterhost.ru2025-04-2190.156.133.179
nmx5.masterhost.ru2013-05-1690.156.155.55
nmx7.masterhost.ru2014-07-0590.156.155.75
static.shared.masterhost.ru2025-01-1890.156.201.55
sample.masterhost.ru2025-08-0890.156.241.25
abuse.masterhost.ru2025-07-0490.156.136.84
mail.masterhost.ru2025-05-2490.156.132.124
autoconfig.mail.masterhost.ru2025-06-2890.156.132.124
webmail.masterhost.ru2025-07-1090.156.132.124
www.webmail.masterhost.ru2025-07-2990.156.132.124
listadmin.masterhost.ru2025-05-1590.156.132.124
phpmyadmin.masterhost.ru2025-04-2690.156.136.69
rdap.masterhost.ru2025-07-2590.156.136.78
imap.masterhost.ru2025-06-2990.156.132.123
www.imap.masterhost.ru2025-05-1690.156.132.123
cp.masterhost.ru2025-04-2690.156.132.121
shop.masterhost.ru2025-08-1687.242.67.67
pop.masterhost.ru2025-07-1490.156.132.123
www.pop.masterhost.ru2025-05-1190.156.132.123
mx1.mail.corp.masterhost.ru2025-07-2790.156.136.107
mx2.mail.corp.masterhost.ru2025-05-1490.156.136.108
chat.corp.masterhost.ru2025-08-0690.156.136.75
webftp.masterhost.ru2025-05-1690.156.131.152
old.webftp.masterhost.ru2025-08-0690.156.131.149
smtp.masterhost.ru2025-05-1790.156.132.122
www.smtp.masterhost.ru2025-07-1990.156.132.122
backup.masterhost.ru2025-04-2790.156.137.34
mssqltools.masterhost.ru2025-08-1090.156.137.70
ns.masterhost.ru2024-01-12217.16.20.20
NS.MASTERHOST.RU2024-04-06217.16.20.16
clients.masterhost.ru2025-03-1687.242.71.171
repo.virt.masterhost.ru2025-01-1690.156.131.111
callback-notify.new.test.masterhost.ru2025-05-1790.156.136.67
callback-notify.test.masterhost.ru2025-06-0290.156.136.66
atol-notify.test.masterhost.ru2025-04-2590.156.202.72
monitoring.ext.masterhost.ru2025-07-26213.183.48.168
fra.monitoring.ext.masterhost.ru2025-04-29213.226.68.55
msc.monitoring.ext.masterhost.ru2025-05-07213.183.48.168
ams.monitoring.ext.masterhost.ru2025-07-11213.183.51.50
sb.dev.masterhost.ru2025-05-0990.156.202.72
ptafrm.dev.masterhost.ru2025-06-1290.156.207.27
callback-notify.dev.masterhost.ru2025-06-0390.156.136.65
atol-notify.dev.masterhost.ru2025-07-1090.156.202.73
hv.masterhost.ru2025-01-1690.156.154.61
rdp.hv.masterhost.ru2025-05-1790.156.136.8
www.masterhost.ru2025-04-2190.156.132.125
sb-epay.masterhost.ru2025-07-1690.156.136.81
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information