Help RSS API Feed Maltego Contact                        

Domain > safe-mail.net

More information on this domain is in AlienVault OTX

Is this malicious?

Reports

http://blog.trendmicro.com/trendlabs-security-inte...    
http://www.cyintanalysis.com/a-quick-look-at-a-lik...    
https://otx.alienvault.com/pulse/562e5e2f4637f2189...    
https://otx.alienvault.com/pulse/5674426c4637f2563...    

Files that talk to safe-mail.net

MD5A/V
0f5f90b03b49b276d148f7e6be7c30f1[HW32.CDB.27e0] [Packed.Win32.Katusha.1!O] [Trojan.Win32.Hlux.cxxldj] [Trojan.FakeAV] [Kryptik.CCFN] [Win32/Kelihos.OWUMMQC] [Backdoor.Win32.Hlux.dqeh] [Backdoor.Hlux!9TTR+wn2IWc] [Backdoor.Win32.Hlux.DUHE] [BackDoor.Slym.12819] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Win32/Kryptik.CAXO] [Win32.Backdoor.Hlux.Hpn] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.ArxZ]
c7bf064346fafe4fc55b43abcfe96b00[HW32.CDB.E6f3] [Backdoor.Kelihos.r3] [Backdoor.Hlux!zUFIktBYK3s] [Kryptik.CCFN] [Backdoor.Win32.Hlux.djfw] [Trojan.Win32.S.PSW-Tepfer.835600.AM] [UnclassifiedMalware] [BackDoor.Slym.14049] [Mal/Kelihos-A] [Backdoor:Win32/Kelihos] [Trojan/Win32.Tepfer] [W32/Trojan.QQUO-1304] [Backdoor.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt3.HUC] [Trojan.Win32.Kryptik.BZIX]
315325f544912a68464bf38e3edf6371[HW32.CDB.9e5e] [Backdoor/W32.Hlux.829456.H] [Packed.Win32.Katusha.3!O] [Backdoor.Hlux.r3] [Backdoor.Hlux!aauIqdu764w] [Trojan.FakeAV] [Kryptik.CDQY] [Backdoor.Win32.Hlux.dqyy] [Win32.Backdoor.Hlux.Lhdb] [UnclassifiedMalware] [Trojan.Packed.26581] [Win32.Hack.Hlux.dq.(kcloud)] [Backdoor:Win32/Kelihos.F] [Backdoor.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.aZvR] [Win32/Trojan.337]
2748ea7375275e992ebde4575fe7c1a6[HW32.CDB.90bf] [Backdoor.Hlux.r3] [Backdoor.Hlux!wF4QLfqeA5I] [Kryptik.CCFN] [Backdoor.Win32.Hlux.crc] [Trojan.Win32.Hlux.cwzkvh] [TrojWare.Win32.Kryptik.BZOO] [BackDoor.Slym.14056] [Heuristic.LooksLike.Win32.Suspicious.E] [Mal/Kelihos-A] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GID] [Trojan.Win32.Kryptik.BZOO]
30faa031b0c6122bc91cff8996474b4a[HW32.CDB.E594] [Trojan.Inject2]
fe734b28009c7dd5389f64d72722bb21
281bba52133b42b0041a72e8baf03600[HW32.CDB.Eca9] [Backdoor.Hlux.r3] [Backdoor.Hlux!xA6rCWjNVLE] [Kryptik.CCFN] [Backdoor.Win32.Hlux.dmfd] [Trojan.Win32.Kryptik.cxbhpv] [Trojan.Packed.26544] [Heuristic.LooksLike.Win32.Suspicious.E] [Mal/FakeAV-UF] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos] [W32/Trojan.KRFJ-3745] [Heur.Trojan.Hlux] [Win32/Kryptik.CASL] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt_s.GME] [Trojan.Win32.Kryptik.CASL]
0d4fa9360c4139d1a33a6203f510f886[HW32.CDB.07a1] [Packed.Win32.Katusha.1!O] [Trojan.Win32.Hlux.cymqun] [Trojan.FakeAV] [Kryptik.CCQY] [Backdoor.Win32.Hlux.cri] [Backdoor.Hlux!tlFvhPzYgZ0] [Win32.Backdoor.Hlux.Glz] [Backdoor.Win32.Hlux.DUHE] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos] [Heur.Trojan.Hlux] [Trojan.Crypt] [W32/Hlux.CCCY!tr.bdr] [Crypt_s.GRA] [Backdoor.Win32.Hlux.aNkU]
0f85c93f59bf57bcc7573e7f8e373c21[HW32.CDB.47eb] [Backdoor.Hlux.r3] [Backdoor.Hlux!kSgAszTjhZg] [Kryptik.CCFN] [Backdoor.Win32.Hlux.dmru] [Trojan.Win32.Hlux.cwzljo] [Mal/FakeAV-UF] [BackDoor.Slym.13348] [Heuristic.LooksLike.Win32.Suspicious.E] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos] [W32/Trojan.VZXF-1556] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Win32/Kryptik.CASL] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Trojan.Win32.Kryptik.CASL]

Whois

PropertyValue
Namealmond systerms international Ltd.
Organization almond systerms international Ltd.
Email amiram@GALIAD.CO.IL
Address 2-26-23-701 Minami-Otsuka,Toshima-ku
Zip Code 170-0005
City Tokyo
Country JP
Phone +81.9999999999
Fax +81.9999999999
NameServer EGOZ.GALIAD.CO.IL
Created 1998-10-10 04:00:00
Changed 2015-01-28 23:30:32
Expires 2017-10-09 00:00:00
Registrar NETWORK SOLUTIONS, L

DNS Resolutions

DateIP Address
2013-09-13213.8.161.230 (ClassC)
2014-05-25212.29.227.230 (ClassC)
2014-06-18212.29.227.230 (ClassC)
2023-08-27212.29.227.81 (ClassC)
2025-05-22212.235.89.107 (ClassC)
2025-07-1962.0.12.164 (ClassC)

Port 80

Port 443

Subdomains

DateDomainIP
mx1.safe-mail.net2014-05-24213.8.192.75
nsa.safe-mail.net2025-07-0662.0.12.164
nsb.safe-mail.net2025-07-0162.0.12.164
tamar.safe-mail.net2024-02-1362.0.12.163
tapuz.safe-mail.net2025-05-13212.235.89.107
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information