Help RSS API Feed Maltego Contact                        

Domain > yahoo.com.tw

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to yahoo.com.tw

MD5A/V
abe19665682ad3e10ba09471775c150b[Malware.Packer.FFS] [Heuristic.LooksLike.Win32.Suspicious.E]
e21b3469b4fc1efddf76d8c89f1ebb2a[Malware.Packer.HGX1] [Heuristic.LooksLike.Win32.Suspicious.E] [W32/Kryptik.AXUE!tr]
9aa81fa022c0b159758efa1bda4f9be1[HW32.CDB.A20b] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CCFN] [Backdoor.Win32.Hlux.dthd] [UnclassifiedMalware] [BackDoor.Slym.13011] [Backdoor:Win32/Kelihos] [Heur.Trojan.Hlux] [Win32/Kryptik.CBNK] [Win32.Backdoor.Hlux.Hwcu] [Trojan.Crypt3] [W32/Kryptik.BD!tr] [Crypt3.OHL] [Backdoor.Win32.Hlux.Ac]
3fb83eaf2a665f71ac2065f5f6956d50[HW32.CDB.5da2] [Packed.Win32.Katusha.1!O] [Trojan.Win32.Hlux.cynagk] [Trojan.FakeAV] [Kryptik.CDQY] [Win32/Kelihos.GeEUUIB] [Backdoor.Win32.Hlux.dqkq] [Backdoor.Hlux!m6CCC6SKjdo] [Win32.Backdoor.Hlux.Lose] [Backdoor.Win32.Hlux.DUHE] [Trojan.Packed.26581] [Trojan[Backdoor]/Win32.Hlux] [Win32.Hack.Hlux.dq.(kcloud)] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.aDM]
4211b2d7121c11d5f032e6620030a384[HW32.CDB.Cd7e] [Packed.Win32.Katusha.3!O] [Hlux.ZY] [VirTool:Win32/Obfuscator.WT]
db5b440f6419090cd9567f3b33fd3ced[Malware.Packer.HGX1] [BackDoor.SlymENT.1498] [Heuristic.LooksLike.Win32.Suspicious.E] [W32/Kryptik.AXUE!tr]
833009a54c295a72ad64ab0941f482fe[Suspicious.Cloud.5] [Kryptik.CCFN] [TrojWare.Win32.Kryptik.BZOO] [Trojan.DownLoad3.28912] [TR/Crypt.EPACK.9220] [Heuristic.BehavesLike.Win32.Suspicious-BAY.K] [Mal/FakeAV-UF] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Win32.SuspectCrc] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GIF] [Trojan.Win32.Kryptik.BZOO]
b36385662ebdaf40bc3d28f90b6a4751[Spyware.Zbot.USBV] [Trojan] [BackDoor.SlymENT.1498] [Heuristic.LooksLike.Win32.Suspicious.E] [Trojan/Win32.Foreign]
3220ab9b63a767c299000ea9d9e3a056[HW32.CDB.1b0b] [Packed.Win32.Katusha.1!O] [Backdoor.Hlux!u8SUOkHyYnA] [Trojan.FakeAV] [Kryptik.CCFN] [Win32/Kelihos.RbUfAWB] [Backdoor.Win32.Hlux.dpoo] [Trojan.Win32.Hlux.cxxuzn] [TrojWare.Win32.Kryptik.CAUP] [BackDoor.Slym.12819] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Backdoor.Hlux] [Win32/Kryptik.CAXO] [Win32.Backdoor.Hlux.Lgjg] [Trojan.Crypt_s] [W32/Kryptik.CAXO!tr] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CAXO]
3a44da011fc699a6afc6cc7d07131dd6[HW32.CDB.14e7] [Trojan.Win32.Kryptik.cxajdj] [Kryptik.CDQY] [TrojWare.Win32.Kryptik.CAHC] [Trojan.Packed.26527] [Trojan:Win32/Dynamer!ac] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Backdoor.Win32.Kelihos] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GKZ]
860dd245cbecd656df047b97456d0ad0[HW32.CDB.9069] [Malware.Packer.FFS] [Heuristic.LooksLike.Win32.Suspicious.E] [PE:Malware.AntiWare!1.9D9B] [W32/Kelihos.KK@mm]
e6d960bf587f5cb1497520fe716f1fb4[Malware.Packer.FFS] [BackDoor.SlymENT.2075] [Heuristic.LooksLike.Win32.Suspicious.E] [Backdoor:Win32/Kelihos.F] [PE:Malware.XPACK/RDM!5.1]
2263766e2732eb5e6eb78b5d35423883[Crypt2.BTUL] [TrojanDownloader*Win32/Cutwail.BS]
1be1d71fb76a46afa15fc4ee16ac1d11[HW32.CDB.39c9] [Backdoor.Hlux.r3] [RDN/q2z-art6.s_318383!a] [Kryptik.CCFN] [Backdoor.Win32.Hlux.dnzz] [Backdoor.Hlux!eaxFLDBT/AM] [Mal/FakeAV-UF] [BackDoor.Slym.13348] [Heuristic.LooksLike.Win32.Suspicious.E] [Trojan[Backdoor]/Win32.Hlux] [VirTool:Win32/Obfuscator.WT] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Win32/Kryptik.CASL] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Trojan.Win32.Kryptik.CASL]
34961ffc0f75d89da0b9464a4c7a02b1[Backdoor.Win32.Pushdo.qag] [BackDoor.Bulknet.893] [Win32.Heur.KVMF58.hy.(kcloud)] [TrojanDownloader:Win32/Cutwail.BS] [Backdoor/Win32.Pushdo] [Trojan-Downloader.Win32.Cutwail]
3b54013dbac240d454b929a3745a46e4[Artemis!3B54013DBAC2] [WS.Reputation.1] [HB_Pushdo-1] [Trojan.Win32.Jorik.Cutwail.ppt] [UnclassifiedMalware] [BackDoor.Bulknet.958] [W32/Pushdo.YOY!tr] [SHeur4.BMTZ]
2ba1c7eb19cc61d8cfb858e81b613787[Crypt2.BVGD] [RDN/Downloader.a!nu] [TrojanDownloader*Win32/Cutwail.BS]
2c2371e95bb5d87ccd5d19a114492f70[HW32.CDB.18af] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CDQY] [TrojWare.Win32.Kryptik.CBCJ] [BackDoor.Slym.13873] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Backdoor.Win32.Kelihos] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CBCJ] [Win32/Trojan.0de]
4c83c209b92c70bd0cff8a6036589670[HW32.CDB.E5ca] [Trojan.Win32.Kryptik.cwscgd] [Kryptik.CCFN] [UnclassifiedMalware] [Trojan.Packed.26527] [Heur.Trojan.Hlux] [Win32.SuspectCrc] [Crypt_s.GKU] [Trojan.Win32.Kryptik.BWUN] [Win32/Trojan.337]
315325f544912a68464bf38e3edf6371[HW32.CDB.9e5e] [Backdoor/W32.Hlux.829456.H] [Packed.Win32.Katusha.3!O] [Backdoor.Hlux.r3] [Backdoor.Hlux!aauIqdu764w] [Trojan.FakeAV] [Kryptik.CDQY] [Backdoor.Win32.Hlux.dqyy] [Win32.Backdoor.Hlux.Lhdb] [UnclassifiedMalware] [Trojan.Packed.26581] [Win32.Hack.Hlux.dq.(kcloud)] [Backdoor:Win32/Kelihos.F] [Backdoor.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.aZvR] [Win32/Trojan.337]

Whois

PropertyValue
NameDomain Administrator
Organization Yahoo! Inc.
Email domainadmin@yahoo-inc.com
Address 701 First Avenue
City Sunnyvale, CA
Country US
Phone +1.4083493300
Fax +1.4083493301
NameServer ns2.yahoo.com
Created 1997-05-01 00:00:00
Expires 2019-07-12 00:00:00
Registrar Markmonitor, Inc.

DNS Resolutions

DateIP Address
2013-07-2668.180.206.184 (ClassC)
2013-11-01106.10.165.51 (ClassC)
2013-11-20203.84.197.77 (ClassC)
2013-12-02106.10.165.51 (ClassC)
2014-06-28119.160.253.28 (ClassC)
2014-07-0868.180.206.184 (ClassC)
2014-07-2198.137.236.150 (ClassC)
2014-07-2477.238.184.150 (ClassC)
2014-07-26188.125.73.108 (ClassC)
2014-07-2874.6.50.150 (ClassC)
2021-02-2498.136.103.23 (ClassC)
2021-12-23212.82.100.150 (ClassC)
2023-08-2674.6.136.150 (ClassC)
2023-11-0134.225.127.72 (ClassC)
2024-01-2234.213.101.254 (ClassC)
2024-02-0854.161.105.65 (ClassC)
2024-02-1513.49.212.207 (ClassC)
2024-02-2444.228.206.170 (ClassC)
2024-03-1013.50.184.192 (ClassC)
2025-06-2913.248.158.7 (ClassC)
2025-08-0876.223.84.192 (ClassC)

Subdomains

DateDomainIP
bid.yahoo.com.tw2025-07-0176.223.84.192
guce.yahoo.com.tw2023-08-2535.82.6.96
stage.guce.yahoo.com.tw2025-04-1135.163.231.37
trunk.guce.yahoo.com.tw2025-04-1244.233.71.247
knowledge.yahoo.com.tw2014-10-14188.125.73.108
mobile.yahoo.com.tw2015-02-0874.6.50.150
home.yahoo.com.tw2015-04-01188.125.73.108
mail.yahoo.com.tw2014-10-14188.125.73.108
smtp.mail.yahoo.com.tw2025-07-0667.195.12.42
order.yahoo.com.tw2025-06-1167.195.231.22
m.order.yahoo.com.tw2025-07-0213.248.158.7
ws.order.yahoo.com.tw2025-08-02124.108.100.191
www.yahoo.com.tw2014-05-0274.6.50.24
money.yahoo.com.tw2014-11-1774.6.50.150
dictionary.yahoo.com.tw2014-07-2574.6.50.150
buy.yahoo.com.tw2025-06-1976.223.84.192
m.buy.yahoo.com.tw2025-05-1513.248.158.7
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information