Help RSS API Feed Maltego Contact                        

Domain > ymail.com

More information on this domain is in AlienVault OTX

Is this malicious?

Reports

http://researchcenter.paloaltonetworks.com/2016/02...    
https://otx.alienvault.com/pulse/56b2113f4637f2355...    
https://otx.alienvault.com/pulse/56cf3cc167db8c17d...    
https://www.fidelissecurity.com/sites/default/file...    

Files that talk to ymail.com

MD5A/V
d42c1a59b111316f7481770349e653db[HW32.CDB.87f3] [Malware.Packer.OCD]
7b34d19bfbc7f1b735f825de01b281f8
ebbf2139fa265c6896be78fe8bbd44f7
970a7ea91d4845a5c13d26b6fa4664a0[HW32.CDB.95aa] [PWSZbot-FBOS!970A7EA91D48] [Trojan.Crypt.NKN] [TROJ_FORUCON.BMC] [Trojan.Win32.Inject.nnuq] [TR/Dropper.VB.7310] [Virus.Win32.Heur.p] [SHeur4.BWOZ]
abe19665682ad3e10ba09471775c150b[Malware.Packer.FFS] [Heuristic.LooksLike.Win32.Suspicious.E]
e21b3469b4fc1efddf76d8c89f1ebb2a[Malware.Packer.HGX1] [Heuristic.LooksLike.Win32.Suspicious.E] [W32/Kryptik.AXUE!tr]
9aa81fa022c0b159758efa1bda4f9be1[HW32.CDB.A20b] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CCFN] [Backdoor.Win32.Hlux.dthd] [UnclassifiedMalware] [BackDoor.Slym.13011] [Backdoor:Win32/Kelihos] [Heur.Trojan.Hlux] [Win32/Kryptik.CBNK] [Win32.Backdoor.Hlux.Hwcu] [Trojan.Crypt3] [W32/Kryptik.BD!tr] [Crypt3.OHL] [Backdoor.Win32.Hlux.Ac]
971d6821a96e8f41da919db02ebc60da[Malware.Packer.FFS] [Heuristic.LooksLike.Win32.Suspicious.E] [Trojan/Win32.Yakes] [W32/Kelihos.BCEB!tr]
3fb83eaf2a665f71ac2065f5f6956d50[HW32.CDB.5da2] [Packed.Win32.Katusha.1!O] [Trojan.Win32.Hlux.cynagk] [Trojan.FakeAV] [Kryptik.CDQY] [Win32/Kelihos.GeEUUIB] [Backdoor.Win32.Hlux.dqkq] [Backdoor.Hlux!m6CCC6SKjdo] [Win32.Backdoor.Hlux.Lose] [Backdoor.Win32.Hlux.DUHE] [Trojan.Packed.26581] [Trojan[Backdoor]/Win32.Hlux] [Win32.Hack.Hlux.dq.(kcloud)] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.aDM]
4211b2d7121c11d5f032e6620030a384[HW32.CDB.Cd7e] [Packed.Win32.Katusha.3!O] [Hlux.ZY] [VirTool:Win32/Obfuscator.WT]
0f5f90b03b49b276d148f7e6be7c30f1[HW32.CDB.27e0] [Packed.Win32.Katusha.1!O] [Trojan.Win32.Hlux.cxxldj] [Trojan.FakeAV] [Kryptik.CCFN] [Win32/Kelihos.OWUMMQC] [Backdoor.Win32.Hlux.dqeh] [Backdoor.Hlux!9TTR+wn2IWc] [Backdoor.Win32.Hlux.DUHE] [BackDoor.Slym.12819] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Win32/Kryptik.CAXO] [Win32.Backdoor.Hlux.Hpn] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.ArxZ]
db5b440f6419090cd9567f3b33fd3ced[Malware.Packer.HGX1] [BackDoor.SlymENT.1498] [Heuristic.LooksLike.Win32.Suspicious.E] [W32/Kryptik.AXUE!tr]
833009a54c295a72ad64ab0941f482fe[Suspicious.Cloud.5] [Kryptik.CCFN] [TrojWare.Win32.Kryptik.BZOO] [Trojan.DownLoad3.28912] [TR/Crypt.EPACK.9220] [Heuristic.BehavesLike.Win32.Suspicious-BAY.K] [Mal/FakeAV-UF] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Win32.SuspectCrc] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GIF] [Trojan.Win32.Kryptik.BZOO]
b36385662ebdaf40bc3d28f90b6a4751[Spyware.Zbot.USBV] [Trojan] [BackDoor.SlymENT.1498] [Heuristic.LooksLike.Win32.Suspicious.E] [Trojan/Win32.Foreign]
3220ab9b63a767c299000ea9d9e3a056[HW32.CDB.1b0b] [Packed.Win32.Katusha.1!O] [Backdoor.Hlux!u8SUOkHyYnA] [Trojan.FakeAV] [Kryptik.CCFN] [Win32/Kelihos.RbUfAWB] [Backdoor.Win32.Hlux.dpoo] [Trojan.Win32.Hlux.cxxuzn] [TrojWare.Win32.Kryptik.CAUP] [BackDoor.Slym.12819] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Backdoor.Hlux] [Win32/Kryptik.CAXO] [Win32.Backdoor.Hlux.Lgjg] [Trojan.Crypt_s] [W32/Kryptik.CAXO!tr] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CAXO]
3a44da011fc699a6afc6cc7d07131dd6[HW32.CDB.14e7] [Trojan.Win32.Kryptik.cxajdj] [Kryptik.CDQY] [TrojWare.Win32.Kryptik.CAHC] [Trojan.Packed.26527] [Trojan:Win32/Dynamer!ac] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Backdoor.Win32.Kelihos] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GKZ]
18e659efd6bd23972f0a9a6a9ecae920[HW32.CDB.9c4f] [Trojan.Win32.Kryptik.cxapgj] [Kryptik.CCFN] [Backdoor.Win32.Hlux.dmyv] [Backdoor.Hlux!x5Q6ZTEiRSs] [BackDoor.Slym.13348] [Mal/FakeAV-UF] [Trojan[Backdoor]/Win32.Hlux] [VirTool:Win32/Obfuscator.WT] [Heur.Trojan.Hlux] [Win32/Kryptik.CASL] [Win32.SuspectCrc] [W32/Kryptik.BWUN!tr] [Crypt3.LQN] [Trojan.Win32.Kryptik.CASL] [Win32/Trojan.337]
924be15014f785cb08ccda07be93344c[HW32.CDB.954a] [Trojan.Gatak.r3] [Spyware.Password] [TROJ_GATAK.SMZ] [UnclassifiedMalware] [Trojan.Inject1.39822] [Trojan:Win32/Gatak] [W32/Trojan.YPKT-3534] [Trojan.Win32.Dropper.Arz] [PE:Malware.XPACK-HIE/Heur!1.9C48] [Trojan.SuspectCRC] [W32/Kryptik.BWVS!tr] [Crypt3.CQE] [Win32/Trojan.e46]
651f650dfb3e715927cee5103e68e0c7[HW32.CDB.F91a] [Packed.Win32.Katusha.1!O] [Kryptik.CCQY] [Backdoor.Win32.Hlux.cri] [Win32.Malware!Drop] [Artemis!651F650DFB3E] [Backdoor:Win32/Kelihos.F] [W32/Hlux.CBWM!tr.bdr] [Crypt_s.GQG] [Backdoor.Win32.Hlux.AB]
a84c15fb551aa1de0ff9af31f4cad0f6[Worm.Gamarue.B] [Trojan-Downloader] [TROJ_SPNR.0BDA13] [Trojan-Downloader.Win32.Andromeda.ubd] [Trojan.DL.Andromeda!gQAduHfFSvg] [Trojan.Win32.A.Downloader.137216.WB] [Troj/Dloadr-DSB] [UnclassifiedMalware] [BackDoor.Andromeda.22] [TR/Dldr.Andromeda.ubd] [Win32.Troj.Undef.(kcloud)] [Worm:Win32/Gamarue.F] [W32/Backdoor.JHEQ-4682] [TrojanDownloader.Andromeda] [Worm.Win32.Gamarue] [W32/Andromeda.UBD!tr.dldr]

Whois

PropertyValue
Email domainadmin@yahoo-inc.com
NameServer NS2.YAHOO.COM
Created 1999-03-03 00:00:00
Changed 2015-01-30 00:00:00
Expires 2016-03-03 00:00:00
Registrar MARKMONITOR INC.

DNS Resolutions

DateIP Address
2012-12-2266.196.66.156 (ClassC)
2012-12-2298.136.145.152 (ClassC)
2012-12-3063.250.192.40 (ClassC)
2013-03-2798.136.145.154 (ClassC)
2013-05-11206.190.57.60 (ClassC)
2013-05-1698.139.102.145 (ClassC)
2013-07-2998.136.145.153 (ClassC)
2013-09-2498.139.102.145 (ClassC)
2013-10-1868.180.206.184 (ClassC)
2014-03-2468.180.206.184 (ClassC)
2014-06-1277.238.184.150 (ClassC)
2014-06-1698.137.236.150 (ClassC)
2014-06-17188.125.73.108 (ClassC)
2014-06-2374.6.50.150 (ClassC)
2014-07-0574.6.50.150 (ClassC)
2014-07-0898.137.236.150 (ClassC)
2014-07-23188.125.73.108 (ClassC)
2014-12-1177.238.184.150 (ClassC)
2021-11-0867.195.204.77 (ClassC)
2021-11-0898.136.96.91 (ClassC)
2021-11-0867.195.228.111 (ClassC)
2021-11-0898.136.96.74 (ClassC)
2021-11-0867.195.204.79 (ClassC)
2021-11-0867.195.228.94 (ClassC)
2021-11-0867.195.204.72 (ClassC)
2021-11-0898.136.96.75 (ClassC)
2021-11-0867.195.228.106 (ClassC)
2021-11-0867.195.204.73 (ClassC)
2021-11-0867.195.228.109 (ClassC)
2021-11-0867.195.204.74 (ClassC)
2021-11-0898.136.96.77 (ClassC)
2021-11-0867.195.228.110 (ClassC)
2021-11-1198.136.96.76 (ClassC)
2023-08-2698.136.103.23 (ClassC)
2023-09-2813.50.184.192 (ClassC)
2023-11-0174.6.136.150 (ClassC)
2023-11-13212.82.100.150 (ClassC)
2024-01-2954.161.105.65 (ClassC)
2024-02-0818.136.37.69 (ClassC)
2024-02-1334.213.101.254 (ClassC)
2024-02-1613.49.212.207 (ClassC)
2024-02-2834.225.127.72 (ClassC)
2024-03-0244.228.206.170 (ClassC)
2024-03-1013.251.69.97 (ClassC)
2025-07-2176.223.84.192 (ClassC)
2025-07-2413.248.158.7 (ClassC)

Subdomains

DateDomainIP
2011.ymail.com2025-06-0176.223.84.192
boonjames88.ymail.com2025-02-1676.223.84.192
poczta.ymail.com2014-11-1374.6.50.150
senior.mohamed.ymail.com2014-05-0374.6.50.24
ne1-attach.ymail.com2014-04-0498.139.199.204
bf1-attach.ymail.com2014-10-14217.12.13.40
sp1-attach.ymail.com2025-07-0376.223.84.192
gq1-attach.ymail.com2014-10-14217.12.13.40
tw1-attach.ymail.com2014-10-15217.12.13.40
tp2-attach.ymail.com2014-07-0198.139.199.204
ir2-attach.ymail.com2014-10-14217.12.13.40
sg3-attach.ymail.com2014-10-15217.12.13.40
ird-attach.ymail.com2015-03-1698.139.199.205
mud-attach.ymail.com2015-03-2498.138.81.72
test-attach.ymail.com2014-10-15217.12.13.40
sipinternal.ymail.com2014-09-0774.6.50.150
dl-mail.ymail.com2015-07-10216.115.110.118
m.ymail.com2014-07-0674.6.50.150
com.ymail.com2024-02-2744.228.206.170
ruslan.ymail.com2014-12-2174.6.50.150
sip.ymail.com2014-09-0774.6.50.150
discoverreceiver.ymail.com2014-09-2374.6.50.150
autodiscover.ymail.com2014-05-0874.6.50.24
abcs.ymail.com2025-05-1713.248.158.7
www.ymail.com2014-05-0774.6.50.24
owww.ymail.com2015-02-1274.6.50.150
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information