mail.indiarailways.net

Classification: Malicious

mail.indiarailways.net is a malicious hostname. Linked to Ke3Chang, Backdoordiplomacy activity. Reported by 1 threat source, last seen 2023-01-21.

Current activity

  • Offline — no longer resolving. Last online 2025-10-02 00:05:41.

MITRE ATT&CK associations

Intrusion sets: KE3CHANG (G0004) BACKDOORDIPLOMACY (G0135)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Mirage Maltiverse 2023-01-20 04:14:49 2023-01-21 17:52:05 malicious-activity G0004 Ke3chang
Backdoordiplomacy Maltiverse 2023-01-20 04:14:49 2023-01-21 17:52:02 malicious-activity G0135 BackdoorDiplomacy

Tags

apt

IP addresses resolved by this hostname

Whois information

AS name
AS4713 NTT Communications Corporation
Domain
indiarailways.net
TLD
net
DNSSEC
['unsigned, Unsigned']
Nameservers
PARKING1.NET-CHINESE.COM.TW, PARKING2.NET-CHINESE.COM.TW
Registrant
Net-Chinese Co., Ltd.
Address
REDACTED FOR PRIVACY
City
REDACTED FOR PRIVACY
State
Taiwan
Country
TW — Taiwan, Province of China 🇹🇼
Contact email
[email protected], [email protected]
Domain created
2024-09-25 03:30:10
Domain expires
2026-09-25 11:30:10
First indexed
2023-01-21 17:52:02
Last updated
2025-10-25 18:21:34