Help RSS API Feed Maltego Contact                        

Domain > icanhazip.com

More information on this domain is in AlienVault OTX

Is this malicious?

Most users have voted this as MALICIOUS

Reports

http://blog.dynamoo.com/2015    
http://blog.dynamoo.com/2015/09/malware-spam-your-...    
http://www.malware-traffic-analysis.net/2015/09/04...    
https://otx.alienvault.com/pulse/55896f54b45ff55ab...    
https://otx.alienvault.com/pulse/55dd8ac94637f21c5...    
https://otx.alienvault.com/pulse/55ea223d4637f26df...    
https://otx.alienvault.com/pulse/5609390067db8c47d...    
https://otx.alienvault.com/pulse/561ebfe067db8c47d...    
http://www.malware-traffic-analysis.net/2015/09/04...    
https://www.reverse.it/sample/6b857ef314938d37997c...    
https://www.symantec.com/content/en/us/enterprise/...    

Files that talk to icanhazip.com

MD5A/V
826286f4a4b4a488abb6ed83409a5097[Trojan.Upatre] [Simda.TKP] [Trojan-Downloader.Win32.Upatre.mld] [PE:Malware.Obscure!1.9C59] [Troj/Wonton-RA] [Trojan.Upatre.702] [W32/Trojan3.PLD] [TR/Yarwi.A.831] [Trojan:Win32/Bulta!rfn] [Trojan/Win32.Upatre] [Downloader-FATU!826286F4A4B4] [W32/Kryptik.DHIG!tr] [Crypt4.ZYA]
e34d6d33f1196ad9539b92090688d160
64bbad8b24ce5e09dae19d7746963246
215da96e53b39699ff4152593eb872aa
f92d16302bb35016049c859af2e24c3c
12232cc38a9eb66b09548534e52d17a8
be6bd9a1d1f2936f3ccdb2eeba28e1c1
00fd29c9dcf57c78ee776b2b76fbf8d2
d429b11731898bc0226464a1382a71d7[Troj/Dyreza-ET] [VirTool:Win32/Obfuscator.AMJ] [W32/Waski.KI!tr]
a42c3679f391c20238f24f8647fb7eff
95ac31c40a32a6a44f84a6b77dd76332[Upatre-FAAR!95AC31C40A32] [Kryptik.CFCF] [Virus.Win32.Heur.c]
6289d7079d489e416fdc4633a6dc51c3
b2853010fa7ee2e6057d5c7e89ed4e60[Trojan.Win32.A.Lydra.1623552[h]]
10dc90d9477b5fbd25d37eefd254570b
c5e4cbb5d1ec1ee5f28a1cdf5b8a92c9
bc7bb730e98fcde7044251784e0d8ceb[Trojan-Downloader/W32.Upatre.35840.B] [TrojanDownloader.Upatre.r4] [Trojan.Upatre] [Win32.Malware!Drop] [Trojan/Downloader.Waski.a] [Trojan.Win32.Upatre.drhpcv] [Downloader.Upatre] [Kryptik.CLASS] [TROJ_UPATRE.DMI] [Trojan-Downloader.Win32.Upatre.ivy] [Win32.Trojan.Fakedoc.Auto] [Troj/Bredo-APK] [TrojWare.Win32.TrojanDownloader.Upatre.A] [Trojan.DownLoader13.9507] [Downloader-FASG!BC7BB730E98F] [TR/Yarwi.B.2] [Trojan[Downloader]/Win32.Upatre] [Trojan:Win32/Bagsu!rfn] [Trojan.Win32.S.Downloader.35840.AY[h]] [Trojan/Win32.Upatre] [Trojan.Win32.Waski.A] [Win32/TrojanDownloader.Waski.A] [Evilware.Outbreak] [W32/Waski.A!tr] [Win32.Outbreak]
6eb48ac6a562d6cf467e19409ed0b248
c36dc7ea9adf3312804d4f42c5296bf3
35d0d8c328cf1eddcd6b07c3a0ebc668
43bdb0c1d44d7976db44a5906871ebde[Upatre-FACA!BC7BB730E98F] [Trojan.Upatre] [Downloader.Upatre] [Zip.Suspect.ExecutableFax-zippwd-1] [Trojan-Downloader.Win32.Upatre.ivy] [Trojan.Win32.S.Downloader.35840.AY[h]] [Win32.Trojan.Fakedoc.Auto] [Mal/BredoZp-B] [Trojan.DownLoader13.9507] [Win32.Malware!Drop] [TROJ_UPATRE.DMI] [TR/Yarwi.B.2] [Trojan[Downloader]/Win32.Upatre] [Trojan.Win32.Upatre.ivy] [Win32/TrojanDownloader.Waski.A] [Trojan-Downloader.Win32.Upatre] [W32/Waski.A!tr] [Trojan-Downloader:W32/Kavala.B] [Win32.Outbreak]

Whois

PropertyValue
Email C725CE904662444E8F24840674AF5768.PROTECT@WHOISGUARD.COM
NameServer DNS2.STABLETRANSIT.COM
Created 2009-07-31 00:00:00
Changed 2014-07-01 00:00:00
Expires 2015-07-31 00:00:00
Registrar ENOM, INC.

DNS Resolutions

DateIP Address
0000-00-0023.253.254.67 (ClassC)
0000-00-0023.253.218.205 (ClassC)
2013-06-26198.101.241.44 (ClassC)
2013-06-26216.69.252.107 (ClassC)
2013-07-29162.209.15.246 (ClassC)
2013-10-28216.69.252.100 (ClassC)
2013-10-29216.69.252.101 (ClassC)
2014-07-1923.253.218.205 (ClassC)
2014-10-01104.130.129.139 (ClassC)
2014-10-02104.130.2.77 (ClassC)
2014-10-08119.9.94.185 (ClassC)
2014-10-0823.253.206.237 (ClassC)
2014-10-08104.130.141.155 (ClassC)
2014-10-08119.9.25.54 (ClassC)
2014-10-08162.242.252.170 (ClassC)
2014-10-19104.130.141.155 (ClassC)
2014-10-3123.253.206.237 (ClassC)
2015-04-22166.78.246.145 (ClassC)
2015-04-27104.130.28.231 (ClassC)
2015-05-1923.253.254.67 (ClassC)
2015-05-19166.78.246.145 (ClassC)
2015-05-19104.130.28.231 (ClassC)
2015-05-2064.182.208.183 (ClassC)
2015-07-15104.238.136.31 (ClassC)
2015-07-15104.238.141.75 (ClassC)
2015-08-01104.238.145.30 (ClassC)
2015-10-2764.182.208.184 (ClassC)
2015-10-2764.182.208.185 (ClassC)
2016-01-14104.238.162.182 (ClassC)
2016-01-1545.32.200.23 (ClassC)
2016-02-2164.182.208.181 (ClassC)
2016-04-08104.130.140.62 (ClassC)
2016-04-09104.130.230.155 (ClassC)
2016-04-09104.130.65.73 (ClassC)
2016-04-2064.182.208.182 (ClassC)
2016-08-0145.63.62.235 (ClassC)
2016-08-02104.156.226.90 (ClassC)
2016-12-0845.76.25.15 (ClassC)
2017-04-24107.191.44.218 (ClassC)
2017-04-2445.76.24.96 (ClassC)
2017-10-1745.63.77.134 (ClassC)
2017-10-1766.70.178.65 (ClassC)
2017-11-1545.76.59.118 (ClassC)
2017-11-1545.76.18.223 (ClassC)
2018-05-28198.61.150.28 (ClassC)
2018-05-29144.202.71.30 (ClassC)
2018-05-2945.63.64.111 (ClassC)
2018-08-13149.28.118.221 (ClassC)
2018-08-1345.32.193.226 (ClassC)
2018-08-1769.162.69.149 (ClassC)
2018-08-1769.162.69.150 (ClassC)
2018-08-1869.162.69.148 (ClassC)
2018-08-1869.162.69.147 (ClassC)
2019-03-20147.75.40.2 (ClassC)
2019-03-29147.75.96.57 (ClassC)
2019-03-29147.75.89.25 (ClassC)
2019-03-29147.75.92.157 (ClassC)
2019-03-3195.216.173.234 (ClassC)
2019-03-31116.203.128.34 (ClassC)
2019-03-31159.69.191.144 (ClassC)
2019-03-31116.203.143.189 (ClassC)
2019-03-3188.99.80.146 (ClassC)
2019-05-09139.178.68.38 (ClassC)
2019-05-09139.178.82.59 (ClassC)
2019-11-12104.20.17.242 (ClassC)
2020-03-14104.20.16.242 (ClassC)
2020-04-18104.22.19.188 (ClassC)
2020-04-2746.4.63.102 (ClassC)
2020-04-27188.40.60.252 (ClassC)
2020-06-23116.202.244.153 (ClassC)
2020-08-26116.202.55.106 (ClassC)
2020-08-31116.203.119.16 (ClassC)
2020-12-30147.75.47.199 (ClassC)
2021-02-16136.144.56.255 (ClassC)
2021-02-25172.67.9.138 (ClassC)
2021-05-02104.22.18.188 (ClassC)
2021-06-07104.18.6.156 (ClassC)
2021-07-27104.18.7.156 (ClassC)
2022-11-0711.23.33.44 (ClassC)
2024-02-12104.18.115.97 (ClassC)
2024-02-23104.18.114.97 (ClassC)
2025-05-05104.16.185.241 (ClassC)
2025-05-12104.16.184.241 (ClassC)

Subdomains

DateDomainIP
4.icanhazip.com2023-12-23104.18.115.97
ipv4.icanhazip.com2014-04-1423.253.218.205
www.icanhazip.com2024-01-16104.18.114.97
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information