Help RSS API Feed Maltego Contact                        

Domain > www.duba.net

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to www.duba.net

MD5A/V
30e22da1e83695a42804b339fb72d364[Backdoor*Win32/Zegost.B]
12bf48aad67e6aa7ded1498c4858d865[Backdoor*Win32/Zegost.B]
f5ca13562fb1b3cec45358021a3b4a25
2ddadf338a58337d51c70f2b3105a5b2
f975521a337dbd521fb6e63bd18b6f8e[Backdoor*Win32/Zegost.B]
f8cb854597c18887433265702a72cfd4[Trojan.Spy-80656] [TR/PSW.Bjlog.lby.10] [TrojanDropper*Win32/Zegost.B]
73712259eecbe59245b03f6d8dbdd402[Heuristics.Broken.Executable] [Backdoor*Win32/Zegost.B]
3fabccdb91cf9038dcffff47bc364830[W32.Sality.PE] [Win32.Sality.3] [Packed.Win32.Obfuscated.10!O] [W32.Sality.U] [Win32.Sality.BL] [W32.Sality.AE] [Sality.ZHB] [Win32/Sality.AA] [PE_SALITY.RL] [Virus.Win32.Sality.beygb] [Win32.Sality.N] [Trojan.KillProc.26742] [Virus.Sality.Win32.20] [W32/Sality.AT] [Heuristic.LooksLike.Win32.Suspicious.C!80] [Virus:Win32/Sality.AT] [Win32/Kashu.E] [Virus.Win32.Sality.bakc] [W32/Sality.AA] [Win32/Sality.NBA] [Trojan-PWS.Win32.Bjlog] [Win32/Sality] [Virus.Win32.Sality.$Emu]
184f870d527eacc6e28f84efdb67df37[Backdoor*Win32/Zegost.B]
d850d6a5a34cbb5c030775d30d21b0d1[TrojanPSW.Bjlog.g5] [Trojan.Spy-80656] [Trojan.Packed.22267] [Win32/Redosdru.GL] [W32/Rincux.AA!tr] [Trojan-PWS.Win32.Bjlog*Win32.Malware] [Trojan-PSW.Win32.Bjlog.zeq] [TrojanDropper*Win32/Zegost.B] [Backdoor.Trojan] [BKDR_ZEGOST.SMZZ]
abec713acddf4ae5b9ddb593188d0b43[Backdoor*Win32/Zegost.B]
1b1dfac9b0f1356cb8167012164ffb75[Backdoor*Win32/Zegost.B]
7d290b1298b32cb15e5e4d6298d3e224[TrojanDropper*Win32/Zegost.B]
914ad1bd33207f40edb342d496abdc6f[Backdoor*Win32/Zegost.B]
77207de1291743910297c7c005580123
5900589b310931348632c29d0e1bcec6[Backdoor*Win32/Zegost.B]
99d8ef0fde1e23b1aa6000d36c3c7532
d96ac432402767edafb0d7bab79cc22d[Backdoor*Win32/Zegost.B]
1c8d4cd98f3ffe1b942f0a04692ed215[TR/PSW.Bjlog.lfzb] [Trojan.Spy-78740] [TrojanDropper*Win32/Zegost.B]
766c4d534ff8a1b5d048bcbade4a4865

Whois

PropertyValue
Email zhaoyiding@cmcm.com
NameServer LV3NS2.FFDNS.NET
Created 2002-03-20 00:00:00
Changed 2014-11-24 00:00:00
Expires 2018-03-20 00:00:00
Registrar ENAME TECHNOLOGY CO.

DNS Resolutions

DateIP Address
2014-01-25114.112.68.197 (ClassC)
2014-02-19114.112.68.197 (ClassC)
2014-12-258.37.231.21 (ClassC)
2014-12-318.37.231.22 (ClassC)
2015-01-108.37.231.19 (ClassC)
2015-02-18183.136.217.82 (ClassC)
2015-03-068.37.231.20 (ClassC)
2015-04-1458.218.208.199 (ClassC)
2016-03-0859.56.26.49 (ClassC)
2016-10-31220.243.199.149 (ClassC)
2017-05-28123.134.184.158 (ClassC)
2017-10-02122.228.9.42 (ClassC)
2017-10-30150.138.238.137 (ClassC)
2018-03-30123.132.254.205 (ClassC)
2018-03-31123.132.254.219 (ClassC)
2018-06-19112.253.11.135 (ClassC)
2018-06-19112.253.11.137 (ClassC)
2018-07-06123.134.184.162 (ClassC)
2018-07-06123.134.184.151 (ClassC)
2018-07-06119.188.244.81 (ClassC)
2018-07-09222.132.5.26 (ClassC)
2019-03-2342.54.2.23 (ClassC)
2019-03-2442.54.2.25 (ClassC)
2019-03-2442.54.2.17 (ClassC)
2019-03-2442.54.2.26 (ClassC)
2019-03-2442.54.2.21 (ClassC)
2019-03-2442.54.2.22 (ClassC)
2019-03-2442.54.2.16 (ClassC)
2019-08-15113.1.2.31 (ClassC)
2019-08-15113.1.2.29 (ClassC)
2019-08-24218.24.18.62 (ClassC)
2019-09-22218.24.18.52 (ClassC)
2019-10-01218.24.18.57 (ClassC)
2020-01-09218.24.18.14 (ClassC)
2020-03-14117.23.1.15 (ClassC)
2020-05-26123.149.174.22 (ClassC)
2020-07-2942.81.57.20 (ClassC)
2020-10-1160.222.11.51 (ClassC)
2020-11-1760.222.11.44 (ClassC)
2020-12-01183.146.208.135 (ClassC)
2021-01-17150.138.39.240 (ClassC)
2021-01-17150.138.39.242 (ClassC)
2021-01-20182.86.84.228 (ClassC)
2021-01-20182.86.84.232 (ClassC)
2021-02-0227.22.56.239 (ClassC)
2021-02-0227.22.56.248 (ClassC)
2021-02-0427.22.58.191 (ClassC)
2021-02-05117.91.179.132 (ClassC)
2021-02-14117.91.179.131 (ClassC)
2021-02-24150.138.180.244 (ClassC)
2021-03-30221.229.165.205 (ClassC)
2021-04-13110.80.139.221 (ClassC)
2021-04-28183.162.226.117 (ClassC)
2021-04-28183.162.226.118 (ClassC)
2021-04-28183.162.226.119 (ClassC)
2021-04-29113.219.136.27 (ClassC)
2021-04-29113.219.136.32 (ClassC)
2021-06-041.180.13.241 (ClassC)
2021-06-06150.139.240.239 (ClassC)
2021-06-07140.249.158.248 (ClassC)
2021-07-0658.220.55.241 (ClassC)
2021-07-08150.139.241.248 (ClassC)
2021-07-08150.139.241.238 (ClassC)
2021-07-1259.63.238.164 (ClassC)
2021-07-1259.63.238.166 (ClassC)
2021-07-1259.63.238.168 (ClassC)
2021-07-1259.63.238.170 (ClassC)
2021-07-22223.99.232.215 (ClassC)
2021-07-22223.99.232.217 (ClassC)
2021-07-29111.13.210.230 (ClassC)
2021-07-29111.13.210.227 (ClassC)
2021-07-30113.214.174.229 (ClassC)
2021-08-03111.32.169.250 (ClassC)
2021-08-14115.238.201.199 (ClassC)
2021-09-03122.225.217.248 (ClassC)
2021-09-07122.225.216.238 (ClassC)
2021-09-07122.225.216.241 (ClassC)
2021-09-14150.139.250.236 (ClassC)
2021-09-14150.139.250.239 (ClassC)
2021-09-14150.139.250.248 (ClassC)
2021-09-16116.211.221.8 (ClassC)
2021-09-16116.211.221.10 (ClassC)
2021-09-20119.96.77.237 (ClassC)
2021-09-26113.113.101.242 (ClassC)
2022-01-04150.139.248.238 (ClassC)
2022-01-13223.76.171.227 (ClassC)
2022-07-2361.155.221.222 (ClassC)
2023-07-17222.73.33.242 (ClassC)
2023-12-05120.52.95.239 (ClassC)
2023-12-17120.232.206.81 (ClassC)
2023-12-20218.12.76.167 (ClassC)
2023-12-27120.232.206.82 (ClassC)
2024-01-22218.12.76.170 (ClassC)
2024-02-18120.52.95.236 (ClassC)
2024-02-21120.52.95.235 (ClassC)
2024-03-15218.12.76.169 (ClassC)
2024-04-0736.42.77.170 (ClassC)
2024-04-1936.42.77.164 (ClassC)
2024-07-14218.12.76.168 (ClassC)
2024-07-1436.42.77.167 (ClassC)
2024-07-26120.232.206.78 (ClassC)
2024-11-25221.194.141.170 (ClassC)
2024-11-25221.194.141.171 (ClassC)
2024-12-0536.42.77.171 (ClassC)
2025-02-04218.12.76.171 (ClassC)
2025-03-05120.233.178.92 (ClassC)
2025-04-01221.194.141.169 (ClassC)
2025-04-05221.194.141.165 (ClassC)
2025-05-03221.194.141.163 (ClassC)
2025-05-11120.233.178.91 (ClassC)
2025-05-26218.12.76.166 (ClassC)
2025-06-28221.194.141.168 (ClassC)
2025-07-07221.194.141.236 (ClassC)
2025-07-17120.241.30.102 (ClassC)
2025-07-2336.42.77.136 (ClassC)
2025-08-07221.194.141.166 (ClassC)

Port 80

Subdomains

DateDomainIP
infoc0.duba.net2014-03-12119.147.146.84
duba-011.duba.net2015-03-10222.132.18.81
cs1.duba.net2013-08-18125.39.136.78
infoc2.duba.net2014-03-12119.147.146.70
cs2.duba.net2013-08-18219.239.93.145
cs13.duba.net2013-12-18121.14.11.100
123.duba.net2014-10-278.37.231.19
cs3.duba.net2014-01-11114.112.68.186
dr.cs3.duba.net2014-07-13114.112.93.52
cs4.duba.net2013-08-18125.39.136.78
kwsdata.duba.net2014-07-11125.39.136.78
vipzone.c.duba.net2013-11-1061.188.191.96
i2c.duba.net2014-07-11125.39.136.78
union.infoc.duba.net2024-06-22139.9.36.178
download.duba.net2014-07-19218.60.107.32
bj.download.duba.net2024-02-17116.177.237.157
hd.duba.net2013-08-18122.228.218.146
uuid.duba.net2025-07-14114.112.68.186
udp.cloud.duba.net2025-07-26120.131.3.117
rq.cct.cloud.duba.net2025-07-14110.43.89.7
rq.lbcct.cloud.duba.net2025-07-14110.43.89.7
rq.kpcct.cloud.duba.net2025-07-29110.43.89.9
rq.drcct.cloud.duba.net2025-07-14110.43.89.7
rq.wpscct.cloud.duba.net2025-07-14110.43.89.7
optimize.duba.net2023-12-06175.6.49.1
static.i.duba.net2014-11-2661.240.135.34
config.i.duba.net2015-04-07222.163.198.56
hy-shengji.duba.net2014-05-19221.204.22.208
libmini.duba.net2014-05-12112.253.26.34
quick.duba.net2014-04-04101.28.252.194
sem.duba.net2023-12-24119.39.154.247
wan.duba.net2013-04-26222.243.110.166
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information