CF1760359885121-tsm20251012143351

MXLIST.NET - cnc.sh

Search for IP or hostnames:

cnc.sh checked at 2025-10-13T12:51:25.109Z 309ms 143/143/143 100% R:14

cnc.sh

NSdns7.hichina.com
A2408:4009:501::15 🇨🇳 Alibaba (China)
A39.96.153.43🇨🇳 Alibaba (China)
A39.96.153.63🇨🇳 Alibaba (China)
A47.118.199.203🇨🇳 Alibaba (China)
A47.118.199.213🇨🇳 Alibaba (China)
A120.76.107.43🇨🇳 Alibaba (China)
A120.76.107.63🇨🇳 Alibaba (China)
A139.224.142.113🇨🇳 Alibaba (China)
A139.224.142.123🇨🇳 Alibaba (China)
NSdns8.hichina.com
A2408:4009:501::16 🇨🇳 Alibaba (China)
A39.96.153.44🇨🇳 Alibaba (China)
A39.96.153.54🇨🇳 Alibaba (China)
A47.118.199.204🇨🇳 Alibaba (China)
A47.118.199.214🇨🇳 Alibaba (China)
A120.76.107.44🇨🇳 Alibaba (China)
A120.76.107.54🇨🇳 Alibaba (China)
A139.224.142.114🇨🇳 Alibaba (China)
A139.224.142.124🇨🇳 Alibaba (China)
MXmx1.qiye.aliyun.com
A47.246.137.47🇺🇸 Alibaba
MXmx2.qiye.aliyun.com
A47.246.136.231🇺🇸 Alibaba
PTRcz-clare.com
PTRreachsmartdwell.com
PTRwevolt.tech
MXmx3.qiye.aliyun.com
A47.246.136.231🇺🇸 Alibaba
PTRcz-clare.com
PTRreachsmartdwell.com
PTRwevolt.tech
A47.246.137.47🇺🇸 Alibaba
A154.85.52.163🇺🇸 Baidu

sh

NSa0.nic.sh
NSa2.nic.sh
NSb0.nic.sh
NSc0.nic.sh

Up

Starts with same word

Starts similarily

AI analysis

cnc.sh is the parent of www.cnc.sh.

cnc.sh points to a single IP number: 154.85.52.163.

cnc.sh is delegated to two name servers: dns7.hichina.com and dns8.hichina.com.

cnc.sh shares the same name server setup as other domains, for example hvfreight.com, htwl.com.cn, mjmj.cn, scctedu.com and mului.com.

Host names with nine IP numbers:

dns7.hichina.com points to: 2408:4009:501::15, 39.96.153.43, 39.96.153.63, 47.118.199.203, 47.118.199.213, 120.76.107.43, 120.76.107.63, 139.224.142.113 and 139.224.142.123.

dns8.hichina.com points to: 2408:4009:501::16, 39.96.153.44, 39.96.153.54, 47.118.199.204, 47.118.199.214, 120.76.107.44, 120.76.107.54, 139.224.142.114 and 139.224.142.124.

cnc.sh is handled by three mail servers: mx1.qiye.aliyun.com, mx2.qiye.aliyun.com and mx3.qiye.aliyun.com.

cnc.sh shares mail servers with other domains at least partially, including h-guard.com.cn, ikier.com, shindas.com, jsjmgroup.com and vlivetech.com.

these mail servers are often used with the mail servers mxn.mxhichina.com, mxw.mxhichina.com, mxbiz1.qq.com and mxbiz2.qq.com.

Host names with two IPs:

mx3.qiye.aliyun.com points to 47.246.136.231 and 47.246.137.47.

Host names with one IP:

mx1.qiye.aliyun.com points to 47.246.137.47

mx2.qiye.aliyun.com points to 47.246.136.231

Names pointing to 47.246.136.231: mx3.qiye.aliyun.com and mx2.qiye.aliyun.com

Names pointing to 47.246.137.47: mx3.qiye.aliyun.com and mx1.qiye.aliyun.com

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

VKGtSuv CF johedugfp 2025-10-13