Help
RSS
API
Feed
Maltego
Contact
Domain > cleanfiles.net
×
More information on this domain is in
AlienVault OTX
Is this malicious?
Yes
No
Most users have voted this as
MALICIOUS
Files that talk to cleanfiles.net
MD5
A/V
01c73914ef7b53c09570e0a2db517d58
03fffc831f2ef0c7ed572e3796967417
0595d6bb5a1dc386de147610b47a8188
f035b97196c765aebf4c814bbf4d4f0b
[
HW32.Packed.5EBB
] [
BehavesLike.Win32.FakeSecTool.fc
] [
TR/Drop.Kaymundler.ovka
] [
TrojanDropper:Win32/Kaymundler.C
] [
Artemis!F035B97196C7
] [
PUA.Amonetize
]
25bf32dd2f0f1610cef7497cde001450
[
HW32.Packed.E398
] [
PUP.Optional.Amonetize
] [
trojandropper.win32.kaymundler.c
]
Whois
Property
Value
Email
HELLOHELLOSHARP@GMAIL.COM
NameServer
JILL.NS.CLOUDFLARE.COM
Created
2012-08-07 00:00:00
Changed
2015-12-19 00:00:00
Expires
2016-08-07 00:00:00
Registrar
ENOM, INC.
DNS Resolutions
Date
IP Address
2012-12-22
199.59.58.177
(
ClassC
)
2013-05-11
173.247.246.58
(
ClassC
)
2013-08-07
199.59.166.109
(
ClassC
)
2013-12-20
141.101.123.47
(
ClassC
)
2013-12-20
190.93.243.46
(
ClassC
)
2013-12-21
190.93.240.47
(
ClassC
)
2013-12-21
141.101.112.47
(
ClassC
)
2013-12-22
141.101.113.47
(
ClassC
)
2014-02-10
134.213.1.114
(
ClassC
)
2014-03-28
190.93.249.13
(
ClassC
)
2014-03-28
190.93.248.13
(
ClassC
)
2014-05-04
190.93.249.104
(
ClassC
)
2014-05-04
190.93.248.104
(
ClassC
)
2014-05-12
190.93.255.84
(
ClassC
)
2014-05-14
190.93.254.84
(
ClassC
)
2014-06-12
141.101.123.47
(
ClassC
)
2014-06-12
190.93.243.46
(
ClassC
)
2014-06-15
141.101.113.47
(
ClassC
)
2014-09-27
164.177.132.32
(
ClassC
)
2014-10-11
190.93.255.143
(
ClassC
)
2014-10-13
190.93.254.143
(
ClassC
)
2014-10-20
190.93.251.5
(
ClassC
)
2014-10-20
190.93.250.5
(
ClassC
)
2014-11-03
190.93.250.130
(
ClassC
)
2014-11-06
190.93.251.130
(
ClassC
)
2015-10-26
104.20.6.112
(
ClassC
)
2015-10-26
104.20.7.112
(
ClassC
)
2019-12-13
104.31.83.242
(
ClassC
)
2019-12-13
104.31.82.242
(
ClassC
)
2022-03-09
172.64.80.1
(
ClassC
)
2022-12-16
188.114.96.3
(
ClassC
)
2022-12-17
188.114.97.3
(
ClassC
)
2022-12-17
188.114.97.0
(
ClassC
)
2022-12-18
188.114.96.0
(
ClassC
)
2022-12-18
188.114.96.8
(
ClassC
)
2022-12-18
188.114.96.12
(
ClassC
)
2023-01-05
188.114.97.2
(
ClassC
)
2023-01-17
188.114.96.1
(
ClassC
)
2023-07-21
188.114.97.1
(
ClassC
)
2023-07-31
188.114.96.7
(
ClassC
)
2023-07-31
188.114.97.7
(
ClassC
)
2024-11-27
188.114.96.2
(
ClassC
)
2025-06-17
172.67.161.77
(
ClassC
)
2025-08-07
104.21.15.36
(
ClassC
)
Port 80
HTTP/1.1 301 Moved PermanentlyDate: Mon, 29 Jan 2024 05:07:09 GMTContent-Type: text/htmlTransfer-Encoding: chunkedConnection: keep-aliveLocation: https://cleanfiles.net/CF-Cache-Status: DYNAMICReport- html>head>title>301 Moved Permanently/title>script src/cdn-cgi/apps/head/x2pBNi5EDuJvw6cA5zzPXNSw0hA.js>/script>/head>body bgcolorwhite>center>h1>301 Moved Permanently/h1>/center>hr>center>nginx/1.14.0 (Ubuntu)/center>/body>/html>
Port 443
HTTP/1.1 200 OKDate: Mon, 29 Jan 2024 05:07:09 GMTContent-Type: text/html; charsetutf-8Transfer-Encoding: chunkedConnection: keep-aliveSet-Cookie: checkedtrue; Path/Set-Cookie: csrf-token6b571451775e2 !DOCTYPE html>html langen>head> meta charsetUTF-8> meta nameviewport contentwidthdevice-width, initial-scale1.0> title>Index/title> script src/cdn-cgi/apps/head/x2pBNi5EDuJvw6cA5zzPXNSw0hA.js>/script>link hrefhttps://fonts.googleapis.com/css2?familyRoboto:wght@300&displayswap relstylesheet> script src/static/fingerprint2.min.js>/script> style> body { font-family: Roboto, sans-serif; } .center-image { display: flex; justify-content: center; align-items: center; height: 80vh; } .center-image img { max-width: 10%; height: auto; } #loading { font-size: 24px; position: absolute; top: 50%; left: 50%; transform: translate(-50%, -50%); } .dot { display: inline-block; width: 8px; height: 8px; border-radius: 50%; background-color: #000; margin-left: 5px; opacity: 0; animation: bounce 1.5s infinite ease-in-out; } .dot:nth-child(2) { animation-delay: 0.2s; } .dot:nth-child(3) { animation-delay: 0.4s; } @keyframes bounce { 0%, 100% { opacity: 0; transform: translateY(0); } 50% { opacity: 1; transform: translateY(-10px); } } /style>/head>body> form idchallenge-form action/ methodPOST> input typehidden idjs-enabled namejs-enabled valuefalse> input typehidden idfingerprint namefingerprint> input typehidden namecsrf-token value6b571451775e22e901ba6a9a681e52ae720fe69d322e44214fb60a2cd1ca7d58> /form> div classcontainer center-image> img src/static/head.jpg altSite Under Attack> /div> div idloading> Checking your browser div classdot>/div> div classdot>/div> div classdot>/div> /div>script>document.addEventListener(DOMContentLoaded, (event) > { // Устанавлив
Subdomains
Date
Domain
IP
email.cleanfiles.net
2025-05-24
172.67.161.77
View on OTX
|
View on ThreatMiner
Please enable JavaScript to view the
comments powered by Disqus.
Data with thanks to
AlienVault OTX
,
VirusTotal
,
Malwr
and
others
. [
Sitemap
]