Help RSS API Feed Maltego Contact                        

Domain > ip138.com

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to ip138.com

MD5A/V
103fb011f51f48f47f3cb3c13027b56f[Riskware/Qhost] [Spyware.OnlineGames]
dd2051e904df686c98c6058fc540e690
8d324e0949ae72820cbb0454645af647[Artemis!8D324E0949AE] [W32/Trojan.CZYU-2749] [Downloader] [Trojan.Win32.Z.Zusy.1968640[h]] [UnclassifiedMalware] [BehavesLike.Win32.Dropper.th] [Trojan.Zusy.D2BA7C] [Trj/GdSda.A] [Win32.Adware.Downloader.Auto] [Atros3.AHBM]
29f338d6557d5ab0363b7c146beb331a[Artemis!29F338D6557D] [Win32.Trojan.Graftor.Huzr] [BehavesLike.Win32.Downloader.th] [Trojan.Graftor.D3FEE9]
cec1bb832a1e07bc2a614a09fd34a4ec
cde2457ebc9427e6cde3b24d0c450f6c
d114c1e011e8c833bf0be14651bc8bb0
c4827fc11d8e50a4b758a5b206270d92
940e36f14c55992e8094f86a84b2bd1b[W32/A-8128ee96!Eldorado] [Riskware/FlyStudio] [Win32/Heur] [Spyware.OnlineGames]
7ce833c66513a30c7749fd885ecafe48[TR/Spy.Transmit.A.5] [Trojan.Pcclient-85] [FakeAlert.AD] [BackDoor-AWQ!fm] [Trojan*Win32/Conime.A]
f2fe00778fe7f6bc5b012d7957ff0c40[Trojan.Downloader.Hicrazyk.A] [StartPage-NY] [PUP.Optional.Meinv] [Riskware.Nsis.Downloader.cwhxun] [Malware] [TrojanDownloader:Win32/Hicrazyk.A] [W32/StartPage.NY!tr]
07c115461f195d2872cb61d3820e4072[Artemis!07C115461F19] [PUP.Optional.Meinv] [WS.Reputation.1] [Startpage.ITJD] [Trojan.Win32.A.Downloader.1085470] [UnclassifiedMalware] [TR/Dldr.Hicrazyk.A.4] [Heuristic.BehavesLike.Win32.Suspicious-PKR.S] [Troj/StartP-HV] [TrojanDownloader:Win32/Hicrazyk.A] [Trj/CI.A] [NSIS/TrojanDownloader.Grinidou.B] [PE:Trojan.Crypt!6.191F] [not-a-virus:Downloader.NSIS] [W32/StartPage.NY!tr] [SHeur4.ALHH] [Trojan.NSIS.Grinidou.B] [Win32/Trojan.Downloader.ca5]
a610c3bc444c8aba743d4f36dae0efaf[BScope.Lipler.045]
32909c36c90a7db192750eb6a6740d4c[Suspicious!SA] [Trojan-PWS.OnlineGames]
829ee56d095fee4cc545789d70ec64c3[Win32.SuspectCrc] [Mal/GamePSW-C] [BScope.Trojan-Dropper.Injector]
3af8b42e2d87e8488da6ae3bda6f27dd[Trojan.Downloader.Hicrazyk.A] [Artemis!3AF8B42E2D87] [PUP.Optional.Meinv] [WS.Reputation.1] [Malware] [Trojan.Nsis.Downloader.cwybig] [TR/Dldr.Hicrazyk.A.8362] [Troj/StartP-HV] [TrojanDownloader:Win32/Hicrazyk.A] [NSIS/TrojanDownloader.Grinidou.G] [Trojan-Downloader.Win32.Hicrazyk] [W32/StartPage.NY!tr] [Trojan.Win32.Hicrazyk.A] [Win32/Trojan.Downloader.ca5]
f9cc17734b51eae340b942e85418deb0[HW32.CDB.42dc] [Artemis!F9CC17734B51] [Trojan.Win32.Badur.ctprer] [WS.Reputation.1] [Trojan.Win32.Badur.gdxz] [Trojan.Badur!] [UnclassifiedMalware] [Trojan.DownLoader9.23781] [Heuristic.BehavesLike.Win32.Suspicious-BAY.S] [Trojan/Badur.cor] [Trojan.Badur] [Trojan.Win32.Badur.AFtx] [Win32/Packed.Themida.AAG] [Trojan.Win32.Badur] [Packed_c.BPJA] [Trj/Thed.A]
a7a7462fbf2435999ae822231ce4efd1[Malware] [Trojan/Win32.Banki] [Win32/DH{ICVkBg}]
8a47a3c8feac996e18301bf291445553
52c1f14804dc2c93cb5c060721ee8794[Trojan.Downloader.Hicrazyk.A] [Artemis!52C1F14804DC] [PUP.Optional.Meinv] [Win32.Malware!Drop] [Trojan.Nsis.Downloader.cwyayc] [WS.Reputation.1] [Malware] [Troj/StartP-HV] [Trojan.StartPage.62192] [TR/Dldr.Megone.tga] [TrojanDownloader:Win32/Hicrazyk.A] [Trojan.Win32.Hicrazyk.A] [PE:Trojan.Crypt!6.191F] [not-a-virus:Downloader.NSIS] [W32/StartPage.NY!tr]

Whois

PropertyValue
Email myxp778899hhh@gmail.com
NameServer NS2.DNSV2.COM
Created 2004-04-19 00:00:00
Changed 2013-11-19 00:00:00
Expires 2018-04-19 00:00:00
Registrar DOMAIN NAME NETWORK

DNS Resolutions

DateIP Address
2009-11-30219.153.15.76 (ClassC)
2011-11-09123.103.14.236 (ClassC)
2012-03-1561.147.122.44 (ClassC)
2012-05-2758.222.24.241 (ClassC)
2012-06-3058.253.70.143 (ClassC)
2012-07-03123.103.14.219 (ClassC)
2012-10-10118.144.105.9 (ClassC)
2012-10-29118.144.105.2 (ClassC)
2013-01-07118.244.190.70 (ClassC)
2013-04-0161.153.56.166 (ClassC)
2013-05-1661.147.122.39 (ClassC)
2013-05-2260.211.182.20 (ClassC)
2013-06-3061.147.122.56 (ClassC)
2013-07-1161.147.122.57 (ClassC)
2013-07-2361.147.122.63 (ClassC)
2013-08-05218.92.221.58 (ClassC)
2013-08-16218.92.221.56 (ClassC)
2014-04-29106.38.244.141 (ClassC)
2014-06-10221.235.187.48 (ClassC)
2014-07-08106.38.199.35 (ClassC)
2014-08-01183.57.84.87 (ClassC)
2014-08-10183.57.84.85 (ClassC)
2014-10-13203.130.61.17 (ClassC)
2014-10-13203.130.61.21 (ClassC)
2014-11-27106.38.199.15 (ClassC)
2014-11-29106.38.199.16 (ClassC)
2014-12-27203.130.61.92 (ClassC)
2015-03-31218.93.206.51 (ClassC)
2015-04-16218.93.206.52 (ClassC)
2015-06-0561.153.56.182 (ClassC)
2015-11-14222.186.132.65 (ClassC)
2016-02-2759.56.26.49 (ClassC)
2016-03-04125.90.206.44 (ClassC)
2016-08-25113.107.58.87 (ClassC)
2016-09-25183.6.240.74 (ClassC)
2017-12-14203.130.59.30 (ClassC)
2017-12-1842.81.36.249 (ClassC)
2018-04-0858.51.168.47 (ClassC)
2018-05-26110.88.145.95 (ClassC)
2018-06-07157.185.149.167 (ClassC)
2018-07-1558.223.164.87 (ClassC)
2018-07-1558.223.166.231 (ClassC)
2018-07-31125.90.206.42 (ClassC)
2018-07-31125.90.206.43 (ClassC)
2018-08-21163.171.128.148 (ClassC)
2019-01-21125.77.147.127 (ClassC)
2019-06-28157.185.170.143 (ClassC)
2019-08-06163.171.133.123 (ClassC)
2019-10-18157.185.146.132 (ClassC)
2020-02-29163.171.140.179 (ClassC)
2021-09-18218.77.18.147 (ClassC)
2023-08-27138.113.102.11 (ClassC)
2023-10-0559.37.89.174 (ClassC)
2024-07-31157.185.175.102 (ClassC)
2024-10-24138.113.29.74 (ClassC)
2024-11-01157.185.179.12 (ClassC)
2024-11-09138.113.159.20 (ClassC)
2024-11-18138.113.159.190 (ClassC)
2025-01-26138.113.24.64 (ClassC)
2025-02-22157.185.156.194 (ClassC)
2025-04-05140.150.36.51 (ClassC)
2025-05-31138.113.128.20 (ClassC)
2025-07-08157.185.145.100 (ClassC)
2025-07-18138.113.102.14 (ClassC)
2025-08-0566.114.53.22 (ClassC)

Port 443

Subdomains

DateDomainIP
2020.ip138.com2025-04-30110.81.155.137
202020.ip138.com2025-02-2159.57.13.133
1.ip138.com2024-11-17138.113.159.20
1111.ip138.com2014-11-18183.238.101.232
2021.ip138.com2024-12-1459.57.13.133
1212.ip138.com2016-11-181.31.173.43
2022.ip138.com2022-06-27103.254.188.41
2023.ip138.com2023-08-15157.185.156.194
20140507.ip138.com2024-08-3059.57.13.182
2017.ip138.com2024-07-1059.57.13.182
2018.ip138.com2025-02-19110.81.155.138
2000019.ip138.com2024-11-2559.57.14.11
200019.ip138.com2025-03-28110.81.155.138
2019.ip138.com2025-03-16110.81.155.138
idc.ip138.com2025-08-02157.185.156.194
cache.ip138.com2023-08-16138.113.102.11
iframe.ip138.com2014-08-19117.25.148.120
site.ip138.com2025-06-16124.156.105.121
bf.ip138.com2025-08-02157.185.156.194
h.ip138.com2025-08-0266.114.53.22
api.ip138.com2025-07-08170.106.158.96
caipiao.ip138.com2025-05-09150.109.105.209
top.ip138.com2024-07-12157.185.175.102
sewer.ip138.com2024-11-22110.81.155.137
www.ip138.com2015-02-18218.92.221.152
city.ip138.com2014-11-2736.250.72.119
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information