www.yswm.net
Classification: Malicious
www.yswm.net is a malicious hostname. Reported by 2 threat sources, last seen 2021-11-30. IoC context and downloadable threat intel on Maltiverse.
Current activity
- Offline — no longer resolving. Last online 2026-09-03 13:49:09.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Gen:Trojan.Heur.Dropper | Hybrid-Analysis | 2021-11-30 09:00:23 | 2021-11-30 09:00:23 | ||
| downloader,trojan | Maltiverse | 2017-12-28 10:16:01 | 2017-12-28 10:16:01 |
Tags
downloader trojanIP addresses resolved by this hostname
- 110.53.246.119 (2017-12-28 10:16:02)
- 125.211.204.209 (2017-12-28 10:16:02)
- 42.56.79.189 (2017-12-28 10:16:02)
- 42.236.125.112 (2017-12-28 10:16:02)
- 121.29.54.65 (2017-12-28 10:16:02)
- 123.125.46.112 (2017-12-28 10:16:02)
- 111.202.99.200 (2017-12-28 10:16:02)
- 157.255.128.111 (2017-12-28 10:16:02)
- 1.31.173.114 (2017-12-28 10:16:02)
- 1.189.213.108 (2017-12-28 10:16:02)
- 112.90.58.190 (2017-12-28 10:16:02)
- 123.125.46.202 (2017-12-28 10:16:02)
- 220.194.79.119 (2017-12-28 10:16:02)
- 221.204.60.123 (2017-12-28 10:16:02)
Whois information
- AS name
- AS4837 CNCGROUP China169 Backbone
- Domain
- yswm.net
- TLD
- net
- DNSSEC
- ['unsigned']
- Nameservers
- F1G1NS1.DNSPOD.NET, F1G1NS2.DNSPOD.NET, f1g1ns1.dnspod.net, f1g1ns2.dnspod.net
- Whois server
- whois.paycenter.com.cn
- Registrant
- XINNET TECHNOLOGY CORPORATION
- Address
- ahhf
- City
- hf
- State
- ah
- Country
- CN — China 🇨🇳
- Contact email
- [email protected], [email protected]
- First indexed
- 2017-12-28 10:16:01
- Last updated
- 2021-11-30 09:00:23