CF1757711676837-tsm20250912070358

IPLIST.NET - cnc.sh

Search for IP or hostnames:

cnc.sh checked at 2025-09-12T21:14:36.709Z 1286ms 143/143/143 100% R:14

cnc.sh

NSdns7.hichina.com
A2408:4009:501::15 🇨🇳 Alibaba (China)
A39.96.153.43🇨🇳 Alibaba (China)
A39.96.153.63🇨🇳 Alibaba (China)
A47.118.199.203🇨🇳 Alibaba (China)
A47.118.199.213🇨🇳 Alibaba (China)
A120.76.107.43🇨🇳 Alibaba (China)
A120.76.107.63🇨🇳 Alibaba (China)
A139.224.142.113🇨🇳 Alibaba (China)
A139.224.142.123🇨🇳 Alibaba (China)
NSdns8.hichina.com
A2408:4009:501::16 🇨🇳 Alibaba (China)
A39.96.153.44🇨🇳 Alibaba (China)
A39.96.153.54🇨🇳 Alibaba (China)
A47.118.199.204🇨🇳 Alibaba (China)
A47.118.199.214🇨🇳 Alibaba (China)
A120.76.107.44🇨🇳 Alibaba (China)
A120.76.107.54🇨🇳 Alibaba (China)
A139.224.142.114🇨🇳 Alibaba (China)
A139.224.142.124🇨🇳 Alibaba (China)
MXmx1.qiye.aliyun.com
A47.246.137.47🇺🇸 Alibaba
MXmx2.qiye.aliyun.com
A47.246.136.231🇺🇸 Alibaba
PTRcz-clare.com
PTRreachsmartdwell.com
PTRwevolt.tech
MXmx3.qiye.aliyun.com
A47.246.136.231🇺🇸 Alibaba
PTRcz-clare.com
PTRreachsmartdwell.com
PTRwevolt.tech
A47.246.137.47🇺🇸 Alibaba
A154.85.52.163🇺🇸 Baidu

sh

NSa0.nic.sh
NSa2.nic.sh
NSb0.nic.sh
NSc0.nic.sh

Up

Starts with same word

Starts similarily

AI analysis

The parent of www.cnc.sh is cnc.sh.

cnc.sh points to a single IP address: 154.85.52.163.

Two name servers, dns7.hichina.com and dns8.hichina.com, are delegated to cnc.sh.

The name server setup of cnc.sh is shared with other domains such as hvfreight.com, htwl.com.cn, mjmj.cn, scctedu.com, and mului.com.

dns7.hichina.com and dns8.hichina.com both point to nine IP numbers each: 2408:4009:501::15, 39.96.153.43, 39.96.153.63, 47.118.199.203, 47.118.199.213, 120.76.107.43, 120.76.107.63, 139.224.142.113, 139.224.142.123 for dns7.hichina.com and 2408:4009:501::16, 39.96.153.44, 39.96.153.54, 47.118.199.204, 47.118.199.214, 120.76.107.44, 120.76.107.54, 139.224.142.114, 139.224.142.124 for dns8.hichina.com.

Three mail servers, mx1.qiye.aliyun.com, mx2.qiye.aliyun.com, and mx3.qiye.aliyun.com, are responsible for handling cnc.sh.

Some mail servers are shared, at least partially, by cnc.sh with other domains like h-guard.com.cn, ikier.com, shindas.com, jsjmgroup.com, and vlivetech.com.

The mail servers mxn.mxhichina.com, mxw.mxhichina.com, mxbiz1.qq.com, and mxbiz2.qq.com are frequently utilized in conjunction.

mx1.qiye.aliyun.com points to IP number 47.246.137.47, while mx2.qiye.aliyun.com points to IP number 47.246.136.231. mx3.qiye.aliyun.com, on the other hand, points to two IP numbers: 47.246.136.231 and 47.246.137.47.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

rFJiyka CF johedugfp 2025-09-12