botnet.ventoxcfx.click - robtex.com
botnet.ventoxcfx.click
ventoxcfx.click
| DNSSEC | β οΈ Not signed | ||||||
| A | 2600:1900:4001:96e:8000:1:45de:ee64πΊπΈ Google2600:1900:4000::/44 | ||||||
| A | 34.41.139.193πΊπΈ Google34.41.0.0/16 | ||||||
| NS | ns1.hwrn.net β | ||||||
| NS | ns2.hwrn.net | ||||||
| MX | mx1.csof.net β | ||||||
| MX | mx2.csof.net β | ||||||
| TXT | v=spf1 include:_incspfcheck.mailspike.net -all | ||||||
| SOA | ns1.hwrn.nethostmaster@hwrn.net 2026-04-25 #2 | ||||||
β οΈ On DNS blocklist: tif
Same first word
Similar names
DNS History
6 records (6 active, 0 former)
βA2600:1900:4001:96e:8000:1:45de:ee642026-04-12 β 2026-04-26 Β· 2 obs
β 2026-04-26 01:27:08
βA34.41.139.1932026-04-12 β 2026-04-26 Β· 2 obs
β 2026-04-26 01:27:08
π DNS Trace
π Delegation Chain
| Zone | Nameservers | Glue |
|---|---|---|
| click | ns01.trs-dns.com, ns01.trs-dns.net, ns10.trs-dns.org, ns10.trs-dns.info | - |
| ventoxcfx.click | ns1.hwrn.net, ns2.hwrn.net | - |
β Authoritative Response
Server:34.46.191.171
NS records: ns1.hwrn.net, ns2.hwrn.net
π DNSSEC Status
β οΈ Insecure (no DNSSEC)
No DS record for ventoxcfx.click (unsigned zone)
β±οΈ Timing
Total: 692ms | Queries: -
π Records
| Type | Count | Sample Data |
|---|---|---|
| A | 1 | 34.41.139.193 |
| AAAA | 1 | 2600:1900:4001:96e:8000:1:45de:ee64 |
| NS | 2 | ns2.hwrn.net, ns1.hwrn.net |
| MX | 2 | mx2.csof.net (pri: 10), mx1.csof.net (pri: 10) |
| TXT | 1 | v=spf1 include:_incspfcheck.mailspike.ne |
Analysis
IP Addresses
botnet.ventoxcfx.click points to two IP numbers: 2600:1900:4001:96e:8000:1:45de:ee64 and 34.41.139.193.
Other host names, for instance busks.dedspac.ru, xd84b50c5.ip.e-nt.net, ydrehn2cfmmzx4g1bs36.qwo231sdx.club, 8dfabcdefgh.us and static-26.202.93.111-tataidc.co.in share IP numbers with botnet.ventoxcfx.click.
Name Servers
botnet.ventoxcfx.click's delegation is to two name servers ns1.hwrn.net and ns2.hwrn.net.
botnet.ventoxcfx.click shares the same name server configuration as other domains, such as 128cm8.cable.soderhamn-net.com, bot.abcproxy.click, berigora.matsuro.ru, x4207163f.ip.e-nt.net and yolks.virosat.ru.
Host names with six IP numbers:
ns1.hwrn.net points to: 2600:1900:4000:cb7c:8000::, 2600:1900:4061:58e:8000::, 2600:1900:4081:2f2:8000::, 34.32.207.228, 34.46.191.171 and 35.187.247.195.
ns2.hwrn.net points to: 2600:1900:4000:cb7c:8000:4::, 2600:1900:4061:58e:8000:4::, 2600:1900:4081:2f2:8000:4::, 34.124.162.145, 34.136.0.93 and 34.147.11.210.
Mail Servers
Two mail servers mx1.csof.net and mx2.csof.net handle botnet.ventoxcfx.click.
botnet.ventoxcfx.click uses the same mail server setup as other domains such as mail.cinemay.biz, adhara.vadilops.ru, xd1156e3f.ip.e-nt.net, xd839286b.ip.e-nt.net and alphas.dedspac.ru.
Host names with a single IP:
mx1.csof.net resolves to 46.4.12.146.
mx2.csof.net resolves to 46.4.10.173.