Hostname
office.net.cn
Last fetched
office.net.cn resolves to 1.56.98.184, announced in 1.56.0.0/13 by CHINA169-Backbone - CHINA UNICOM China169 Backbone in CN. office.net.cn is not listed on any threat feed indexed by WhisperGraph; reconciled level NONE.
Threat posture
0threat score (procedure-native scale)
NONENo threats observed.
- Threat feeds listing this
- 0
- Verdict coverage
- known-clean
Nutrition Label
Resolution chain
- 1.56.98.184
1.56.0.0/13 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Harbin, CN
- 1.62.64.79
1.56.0.0/13 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Harbin, CN
- 116.131.57.65
116.131.0.0/16 · CHINA169-Backbone - CHINA UNICOM China169 Backbone
- 116.153.4.244
116.153.0.0/16 · CHINA169-Backbone - CHINA UNICOM China169 Backbone
- 116.163.31.218
116.163.0.0/18 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Beijing, CN
- 119.167.229.212
119.164.0.0/14 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Jinan, CN
- 211.93.211.158
211.93.211.0/24 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Beijing, CN
- 221.204.15.51
221.204.0.0/15 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Taiyuan, CN
- 221.204.209.225
221.204.0.0/15 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Taiyuan, CN
- 42.56.64.131
42.56.0.0/14 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Shenyang, CN
- 42.56.81.77
42.56.0.0/14 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Shenyang, CN
- 60.13.97.57
60.13.64.0/18 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Haikou, CN
- 116.169.183.111
116.169.0.0/16 · CHINA169-Backbone - CHINA UNICOM China169 Backbone
- 36.35.39.162
36.32.0.0/14 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Hefei, CN
- 122.189.168.219
122.188.0.0/14 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Wuhan, CN
- 42.236.90.50
42.224.0.0/12 · CHINA169-Backbone - CHINA UNICOM China169 Backbone · Zhengzhou, CN
- 58.20.197.186
58.20.0.0/16 · CHINA169-Backbone - CHINA UNICOM China169 Backbone
- 116.178.78.215
116.178.0.0/16 · CHINA169-Backbone - CHINA UNICOM China169 Backbone
IPv6 resolution
No AAAA record for office.net.cn is recorded in WhisperGraph.
Attribution
cncgroup ip of shanghai idc
ORIGIN_AS
WHOIS identity
- Registrar
- registrar:阿里云计算有限公司(万网)
- Registrant organisation
- 北京听唐网络科技有限公司
- Contact emails
- lshjie@163.com
Company
- Company
- Office
Technology
Office has been observed using 9 technologies somewhere in its estate. This is observed use, not an exposure finding.
- jQuery · javascript libraries
- Nginx · web servers
- Bootstrap · software framework
- Baidu Analytics · analytics
- Alibaba Cloud DNS · domain name services
- HiChina · cloud hosting
- Tencent Exmail · email
- Sensors Data · analytics
- Tencent · content delivery network
Subdomains
Mail and authentication
Nameservers
- dns21.hichina.com
- dns22.hichina.com
MX records
- mxbiz1.qq.com
- mxbiz2.qq.com
SPF policy
- include: spf.mail.qq.com
Threat-feed evidence
History
Related pages
Pivot from office.net.cn into the addresses, networks and registries it depends on.
Queries
This hostname's full card — resolution chain, registration, mail policy, DNSSEC and mail authentication.
MATCH (h:HOSTNAME {name: $host})
OPTIONAL MATCH (h)-[:RESOLVES_TO]->(ip:IPV4)-[:ANNOUNCED_BY]->(ap:ANNOUNCED_PREFIX)
OPTIONAL MATCH (a:ASN)-[:ROUTES]->(ap)
OPTIONAL MATCH (a)-[:HAS_NAME]->(an:ASN_NAME)
OPTIONAL MATCH (ip)-[:LOCATED_IN]->(city:CITY)
OPTIONAL MATCH (ip)-[:HAS_COUNTRY]->(ipc:COUNTRY)
WITH h, ip, ap, a, an, city, ipc
LIMIT 20
WITH h,
collect({ip: ip.name, prefix: ap.name, asn: a.name, network: an.name, city: city.name, country: ipc.name}) AS resolutions,
collect(a.name) AS asnNames,
collect(ap.name) AS prefixNames,
collect(ap.isMoas) AS moasFlags,
collect(ap.rpkiStatus) AS rpkiStatuses,
head(collect(a)) AS primaryAsn,
head(collect(ap)) AS primaryPrefix
OPTIONAL MATCH (primaryPrefix)-[:CONFLICTS_WITH]->(conflict:ASN)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn,
collect(conflict.name) AS conflictAsns
OPTIONAL MATCH (h)-[:HAS_REGISTRAR]->(reg:REGISTRAR)
OPTIONAL MATCH (h)-[:REGISTERED_BY]->(org:ORGANIZATION)
OPTIONAL MATCH (h)-[:CHILD_OF]->(tld:TLD)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
collect(reg.name) AS registrars,
collect(org.name) AS organizations,
collect(tld.name) AS tlds
OPTIONAL MATCH (h)-[:HAS_EMAIL]->(em:EMAIL)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds,
collect(em.name) AS emails
OPTIONAL MATCH (h)-[:HAS_PHONE]->(ph:PHONE)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails,
count(ph) AS phoneCount
OPTIONAL MATCH (h)<-[:MAIL_FOR]-(mx:HOSTNAME)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount,
collect(mx.name)[0..20] AS mxHosts
OPTIONAL MATCH (h)<-[:NAMESERVER_FOR]-(ns:HOSTNAME)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts,
collect(ns.name) AS nameservers
OPTIONAL MATCH (h)-[spf:SPF_A|SPF_EXISTS|SPF_INCLUDE|SPF_IP|SPF_MX|SPF_REDIRECT]->(spfTarget)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts, nameservers,
collect({mechanism: type(spf), target: spfTarget.name})[0..50] AS spf
OPTIONAL MATCH (h)-[:SIGNED_WITH]->(alg:DNSSEC_ALGORITHM)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts, nameservers, spf,
collect(alg.name) AS dnssecAlgorithms
OPTIONAL MATCH (h)-[:DMARC_REPORTS_TO]->(dm:DMARC_RECIPIENT)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts, nameservers, spf, dnssecAlgorithms,
collect(dm.name)[0..5] AS dmarcRecipients
OPTIONAL MATCH (h)-[:DKIM_SIGNED_BY]->(dk:VENDOR)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts, nameservers, spf, dnssecAlgorithms,
dmarcRecipients,
collect(coalesce(dk.displayName, dk.name))[0..5] AS dkimVendors
OPTIONAL MATCH (h)-[:HAS_SIGNAL]->(hs:THREAT_SIGNAL_TYPE)
WITH h, resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, primaryAsn, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts, nameservers, spf, dnssecAlgorithms,
dmarcRecipients, dkimVendors,
collect(hs.name) AS dnsSignals
CALL { WITH primaryAsn MATCH (primaryAsn)-[:BGP_NEIGHBOR]-(peer:ASN) RETURN count(peer) AS asnPeerCount }
RETURN h.name AS name,
h.rank AS rank,
h.verdictLevel AS verdictLevel,
h.verdictScore AS verdictScore,
h.verdictBlocking AS verdictBlocking,
h.verdictCoverage AS verdictCoverage,
h.verdictAdvisory AS verdictAdvisory,
h.threatSources AS threatSources,
h.threatFirstSeen AS threatFirstSeen,
h.threatLastSeen AS threatLastSeen,
h.isTor AS isTor,
h.isVpn AS isVpn,
h.isProxy AS isProxy,
h.isC2 AS isC2,
h.isPhishing AS isPhishing,
resolutions, asnNames, prefixNames, moasFlags, rpkiStatuses, conflictAsns,
registrars, organizations, tlds, emails, phoneCount, mxHosts, nameservers, spf,
dnssecAlgorithms, dmarcRecipients, dkimVendors, dnsSignals,
h.companyName AS companyName,
h.companyIndustry AS companyIndustry,
h.companyHqCountry AS companyHqCountry,
h.companyHqCity AS companyHqCity,
asnPeerCountRun yourself →The observed subdomain count, to depth 3.
MATCH (h:HOSTNAME {name: $host})
CALL { WITH h MATCH (h)<-[:CHILD_OF*1..3]-(sub:HOSTNAME) RETURN count(sub) AS subdomainCount }
RETURN subdomainCountRun yourself →Technologies the company behind this domain has been observed running, most widely adopted first.
MATCH (:HOSTNAME {name: $host})-[:RUNS_TECHNOLOGY]->(t:TECHNOLOGY)
WITH t.name AS name, t.category AS category, t.adopterCount AS adopters
ORDER BY adopters DESC, name
WITH collect({name: name, category: category}) AS technologies, count(*) AS total
RETURN total, technologies[0..20] AS technologiesRun yourself →Peer companies (outbound SIMILAR_TO).
MATCH (:HOSTNAME {name: $host})-[:SIMILAR_TO]->(peer:HOSTNAME) RETURN peer.name AS host ORDER BY host LIMIT 8Run yourself →The parent company's domain and this company's domain portfolio (PARENT_OF).
MATCH (h:HOSTNAME {name: $host})
OPTIONAL MATCH (h)<-[:PARENT_OF]-(parent:HOSTNAME)
WITH h, collect({host: parent.name, company: parent.companyName})[0..3] AS parents
OPTIONAL MATCH (h)-[:PARENT_OF]->(child:HOSTNAME)
RETURN parents, collect({host: child.name, company: child.companyName})[0..10] AS portfolioRun yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.