backdoor.coffee - robtex.com

backdoor.coffee

DNSSEC⚠️ Not signed
NSns8.domainmonger.com ⭐
A162.251.82.124πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.124.reverse.myorderbox.com
A162.251.82.125πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.125.reverse.myorderbox.com
A162.251.82.252πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.252.reverse.myorderbox.com
A162.251.82.253πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.253.reverse.myorderbox.com
NSns5.domainmonger.com
A162.251.82.122πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.122.reverse.myorderbox.com
A162.251.82.123πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.123.reverse.myorderbox.com
A162.251.82.250πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.250.reverse.myorderbox.com
A162.251.82.251πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.251.reverse.myorderbox.com
NSns6.domainmonger.com
A162.251.82.120πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.120.reverse.myorderbox.com
A162.251.82.121πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.121.reverse.myorderbox.com
A162.251.82.248πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.248.reverse.myorderbox.com
A162.251.82.249πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.249.reverse.myorderbox.com
NSns7.domainmonger.com
A162.251.82.118πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.118.reverse.myorderbox.com
A162.251.82.119πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.119.reverse.myorderbox.com
A162.251.82.246πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.246.reverse.myorderbox.com
A162.251.82.247πŸ‡ΊπŸ‡Έ Cloudflare162.251.82.0/24 PDR
PTR162.251.82.247.reverse.myorderbox.com
SOAns8.domainmonger.comkbirr149@dustorm.com 2025-03-20 #1

coffee

DNSSECπŸ”’ Signed (DS record present)
NSv0n0.nic.coffee ⭐
NSv0n1.nic.coffee
NSv0n2.nic.coffee
NSv0n3.nic.coffee
NSv2n0.nic.coffee
NSv2n1.nic.coffee
SOAv0n0.nic.coffeehostmaster@donuts.email serial=1777297299

Same first word

Similar names

DNS History

4 records (4 active, 0 former)

NSns5.domainmonger.comns6.domainmonger.comns7.domainmonger.comns8.domainmonger.com
●NSns5.domainmonger.com2026-04-16 β†’ 2026-04-27 Β· 2 obs
● 2026-04-16 22:43:38
● 2026-04-27 13:58:36
●NSns6.domainmonger.com2026-04-16 β†’ 2026-04-27 Β· 2 obs
● 2026-04-16 22:43:38
● 2026-04-27 13:58:36
●NSns7.domainmonger.com2026-04-16 β†’ 2026-04-27 Β· 2 obs
● 2026-04-16 22:43:38
● 2026-04-27 13:58:36
●NSns8.domainmonger.com2026-04-16 β†’ 2026-04-27 Β· 2 obs
● 2026-04-16 22:43:38
● 2026-04-27 13:58:36

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
coffeev0n0.nic.coffee, v0n1.nic.coffee, v0n2.nic.coffee, v0n3.nic.coffee...12 records
backdoor.coffeens5.domainmonger.com, ns7.domainmonger.com, ns8.domainmonger.com, ns6.domainmonger.com-

βœ… Authoritative Response

Server:162.251.82.123

NS records: ns5.domainmonger.com, ns7.domainmonger.com, ns8.domainmonger.com, ns6.domainmonger.com

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for backdoor.coffee (unsigned zone)

⏱️ Timing

Total: 901ms | Queries: -

πŸ“„ Records

TypeCountSample Data
NS4ns7.domainmonger.com, ns5.domainmonger.com...
SOA1ns8.domainmonger.com kbirr149.dustorm.co

πŸ“Œ Glue Records Collected

Total: 12

In-bailiwick: 12 (v0n0.nic.coffee, v0n0.nic.coffee, v0n1.nic.coffee...)

Analysis

Name Servers

backdoor.coffee is delegated to four name servers: ns5.domainmonger.com, ns6.domainmonger.com, ns7.domainmonger.com and ns8.domainmonger.com.

backdoor.coffee at least partially shares name servers with other domains, for instance glowingsaltrocks.com, mkauto.net, kvcompany.com, atvtires.biz and makevfx.net.

These name servers are commonly used with the name servers 208.91.197.91.

Host names with four IP numbers

ns5.domainmonger.com points to 162.251.82.122, 162.251.82.123, 162.251.82.250 and 162.251.82.251

ns6.domainmonger.com points to 162.251.82.120, 162.251.82.121, 162.251.82.248 and 162.251.82.249

ns7.domainmonger.com points to 162.251.82.118, 162.251.82.119, 162.251.82.246 and 162.251.82.247

ns8.domainmonger.com points to 162.251.82.124, 162.251.82.125, 162.251.82.252 and 162.251.82.253