CF1757211426692-tsm20250906182357

WWW.RTSAK.COM - cnc.sh

Search for IP or hostnames:

cnc.sh checked at 2025-09-07T02:17:06.663Z 620ms 143/143/143 100% R:17

cnc.sh

NSdns7.hichina.com
A2408:4009:501::15 🇨🇳 Alibaba (China)
A39.96.153.43🇨🇳 Alibaba (China)
A39.96.153.63🇨🇳 Alibaba (China)
A47.118.199.203🇨🇳 Alibaba (China)
A47.118.199.213🇨🇳 Alibaba (China)
A120.76.107.43🇨🇳 Alibaba (China)
A120.76.107.63🇨🇳 Alibaba (China)
A139.224.142.113🇨🇳 Alibaba (China)
A139.224.142.123🇨🇳 Alibaba (China)
NSdns8.hichina.com
A2408:4009:501::16 🇨🇳 Alibaba (China)
A39.96.153.44🇨🇳 Alibaba (China)
A39.96.153.54🇨🇳 Alibaba (China)
A47.118.199.204🇨🇳 Alibaba (China)
A47.118.199.214🇨🇳 Alibaba (China)
A120.76.107.44🇨🇳 Alibaba (China)
A120.76.107.54🇨🇳 Alibaba (China)
A139.224.142.114🇨🇳 Alibaba (China)
A139.224.142.124🇨🇳 Alibaba (China)
MXmx1.qiye.aliyun.com
A47.246.137.47🇺🇸 Alibaba
MXmx2.qiye.aliyun.com
A47.246.136.231🇺🇸 Alibaba
PTRcz-clare.com
PTRreachsmartdwell.com
PTRwevolt.tech
MXmx3.qiye.aliyun.com
A47.246.136.231🇺🇸 Alibaba
PTRcz-clare.com
PTRreachsmartdwell.com
PTRwevolt.tech
A47.246.137.47🇺🇸 Alibaba
A154.85.52.163🇺🇸 Baidu

sh

NSa0.nic.sh
NSa2.nic.sh
NSb0.nic.sh
NSc0.nic.sh

AI analysis

The parent of www.cnc.sh is cnc.sh.

154.85.52.163 is the IP number that cnc.sh points to.

Two name servers, dns7.hichina.com and dns8.hichina.com, have been delegated for cnc.sh.

Other domains like hvfreight.com, htwl.com.cn, mjmj.cn, scctedu.com, and mului.com, share the same name server setup as cnc.sh.

dns7.hichina.com and dns8.hichina.com each point to nine IP numbers respectively: 2408:4009:501::15, 39.96.153.43, 39.96.153.63, 47.118.199.203, 47.118.199.213, 120.76.107.43, 120.76.107.63, 139.224.142.113, and 139.224.142.123 for dns7.hichina.com; 2408:4009:501::16, 39.96.153.44, 39.96.153.54, 47.118.199.204, 47.118.199.214, 120.76.107.44, 120.76.107.54, 139.224.142.114, and 139.224.142.124 for dns8.hichina.com.

Three mail servers, mx1.qiye.aliyun.com, mx2.qiye.aliyun.com, and mx3.qiye.aliyun.com, handle cnc.sh.

Domains such as h-guard.com.cn, ikier.com, shindas.com, jsjmgroup.com, and vlivetech.com share some mail servers, at least partially, with cnc.sh.

Mail servers such as mxn.mxhichina.com, mxw.mxhichina.com, mxbiz1.qq.com, and mxbiz2.qq.com are frequently employed in combination.

IP addresses for mx1.qiye.aliyun.com, mx2.qiye.aliyun.com, and mx3.qiye.aliyun.com are as follows: 47.246.137.47, 47.246.136.231, 47.246.136.231, and 47.246.137.47 respectively.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

LGnLJCG CF johedugfp 2025-09-07