Help RSS API Feed Maltego Contact                        

IP > 139.209.89.73

More information on this IP is in AlienVault OTX

Is this malicious?

Malware

MD5A/V
12bf48aad67e6aa7ded1498c4858d865[Backdoor*Win32/Zegost.B]
432efb2996011b34d4dcd6c5d60f196e[Backdoor*Win32/Zegost.B]
5900589b310931348632c29d0e1bcec6[Backdoor*Win32/Zegost.B]
77207de1291743910297c7c005580123
7e73261632d29f3f24cd0d8ad41ea86c[BackDoor-EQO] [Win.Trojan.Zegost-1749] [Backdoor*Win32/Zegost.B]
914ad1bd33207f40edb342d496abdc6f[Backdoor*Win32/Zegost.B]
976c810fa1764d3fc7f0f3e70911a513[BackDoor-EQO] [Win.Trojan.Zegost-1749] [Backdoor*Win32/Zegost.B]
99d8ef0fde1e23b1aa6000d36c3c7532
9dc15e18ad9d12fd396087bb505dcfdd
a0a29901cb45502e5b4fc1c917627905
abec713acddf4ae5b9ddb593188d0b43
f5ca13562fb1b3cec45358021a3b4a25
f975521a337dbd521fb6e63bd18b6f8e

IP Whois

PropertyValue
Location Changchun, China
Country China

Reverse DNS

DomainDate
apk.lenovomm.com2019-01-07
apkg.lenovomm.com2019-01-07
suapk.lenovomm.com2019-01-07
uapkg.lenovomm.com2019-01-07
papkg.lenovomm.com2018-12-30
suapkg.lenovomm.com2018-12-30
uapk.lenovomm.com2018-12-30
cdn2.yyhudong.com2018-12-15
13.h.last1.cnc.ccgslb.com.cn2018-12-11
papk.lenovomm.com2018-12-06
cdn.tvall.cn2018-04-10
client01.pdl.wow.battlenet.com.cn2018-03-03
sbs.mof.gov.cn2018-01-17
bj.mof.gov.cn2018-01-16
cq.mof.gov.cn2018-01-06
xzzf.mof.gov.cn2017-12-25
dl.mof.gov.cn2017-12-23
zj.mof.gov.cn2017-12-19
sx.mof.gov.cn2017-12-12
xj.mof.gov.cn2017-12-08
wcm.mof.gov.cn2017-12-04
hn.mof.gov.cn2017-12-03
yss.mof.gov.cn2017-11-11
fj.mof.gov.cn2017-10-16
zgb.mof.gov.cn2017-10-14
czzz.mof.gov.cn2017-09-28
jl.mof.gov.cn2017-09-03
gss.mof.gov.cn2017-09-02
card.cgbchina.com.cn2017-08-29
qys.mof.gov.cn2017-08-15
www.mof.gov.cn2017-08-15
www.okooo.com2017-08-14
bgt.mof.gov.cn2017-08-11
download036.rdb.cnc.ccgslb.com.cn2015-08-20
dl.uuad.net2015-07-28
a2.res.meizu.com2015-07-24
rcmd.pop.ijinshan.com2015-07-03
wup1.cache.wps.cn2015-06-19
ddmyapp.cc.tc.qq.com2015-06-04
cd001.www.duba.net2015-05-14
cc.a.yximgs.com2015-03-31
dl.cm.ksmobile.com2015-03-31
cu003.www.duba.cnc.ccgslb.com.cn2014-09-16
quick.duba.net2013-12-26
cu003.www.duba.cncssr.chinacache.net2013-12-24
cu004.www.duba.net2013-12-11
fsigns.duba.net2013-11-20
cu003.www.duba.net2013-09-28
dl1.91rb.com2013-09-16
cdn.market.hiapk.com2013-08-28

DNS Resolutions

SSL Certficate

SSL MD5 ece041070ff237733a308910d66f73e8
SSL SHA1 43e9ffe2bc70af1961f11a04d7323a367c549bb3

IP Classes

139.209.89..x=Browse , 139.209.89..x.x=Browse | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information