CF1757142840929-tsm20250905231252

DNSWHOIS.INFO - cnc.sh

Search for IP or hostnames:

cnc.sh checked at 2025-09-06T07:14:00.904Z 909ms 143/143/143 100% R:15

cnc.sh

NSdns7.hichina.com
A2408:4009:501::15 🇨🇳 Alibaba (China)
A39.96.153.43🇨🇳 Alibaba (China)
A39.96.153.63🇨🇳 Alibaba (China)
A47.118.199.203🇨🇳 Alibaba (China)
A47.118.199.213🇨🇳 Alibaba (China)
A120.76.107.43🇨🇳 Alibaba (China)
A120.76.107.63🇨🇳 Alibaba (China)
A139.224.142.113🇨🇳 Alibaba (China)
A139.224.142.123🇨🇳 Alibaba (China)
NSdns8.hichina.com
A2408:4009:501::16 🇨🇳 Alibaba (China)
A39.96.153.44🇨🇳 Alibaba (China)
A39.96.153.54🇨🇳 Alibaba (China)
A47.118.199.204🇨🇳 Alibaba (China)
A47.118.199.214🇨🇳 Alibaba (China)
A120.76.107.44🇨🇳 Alibaba (China)
A120.76.107.54🇨🇳 Alibaba (China)
A139.224.142.114🇨🇳 Alibaba (China)
A139.224.142.124🇨🇳 Alibaba (China)
MXmx1.qiye.aliyun.com
A47.246.137.47🇺🇸 Alibaba
MXmx2.qiye.aliyun.com
A47.246.136.231🇺🇸 Alibaba
PTRcz-clare.com
PTRreachsmartdwell.com
PTRwevolt.tech
MXmx3.qiye.aliyun.com
A47.246.136.231🇺🇸 Alibaba
PTRcz-clare.com
PTRreachsmartdwell.com
PTRwevolt.tech
A47.246.137.47🇺🇸 Alibaba
A154.85.52.163🇺🇸 Baidu

sh

NSa0.nic.sh
NSa2.nic.sh
NSb0.nic.sh
NSc0.nic.sh

AI analysis

www.cnc.sh has cnc.sh as its parent.

154.85.52.163 is the IP number pointed to by cnc.sh.

Two name servers, dns7.hichina.com and dns8.hichina.com, are delegated to cnc.sh.

The name server setup of cnc.sh is shared with other domains such as hvfreight.com, htwl.com.cn, mjmj.cn, scctedu.com, and mului.com.

dns7.hichina.com and dns8.hichina.com each point to nine IP numbers: 2408:4009:501::15, 39.96.153.43, 39.96.153.63, 47.118.199.203, 47.118.199.213, 120.76.107.43, 120.76.107.63, 139.224.142.113, 139.224.142.123 for dns7.hichina.com and 2408:4009:501::16, 39.96.153.44, 39.96.153.54, 47.118.199.204, 47.118.199.214, 120.76.107.44, 120.76.107.54, 139.224.142.114, 139.224.142.124 for dns8.hichina.com.

Three mail servers, mx1.qiye.aliyun.com, mx2.qiye.aliyun.com, and mx3.qiye.aliyun.com, manage cnc.sh.

Other domains such as h-guard.com.cn, ikier.com, shindas.com, jsjmgroup.com, and vlivetech.com share some mail servers, at least partially, with cnc.sh.

The mail servers mxn.mxhichina.com, mxw.mxhichina.com, mxbiz1.qq.com, and mxbiz2.qq.com are typically utilized in conjunction.

IP addresses associated with mx1.qiye.aliyun.com, mx2.qiye.aliyun.com, and mx3.qiye.aliyun.com are as follows:

- mx1.qiye.aliyun.com points to 47.246.137.47.

- mx2.qiye.aliyun.com points to 47.246.136.231.

- mx3.qiye.aliyun.com points to 47.246.136.231 and 47.246.137.47.

dbq

twRBIQD CF johedugfp 2025-09-06