attacker-controlled.com - robtex.com

attacker-controlled.com

com

Same first word

DNS History

10 records (5 active, 5 former)

20192020202120222023202420252026NSns1.afternic.comns2.afternic.comverification-d3jclucsp89ganyqbydeny.ns101.verify.hndns1.registrar-servers.comdns2.registrar-servers.comMXmx1.privateemail.commx2.privateemail.comA13.248.169.4876.223.54.146192.64.119.176
β—‹NSdns1.registrar-servers.com2018-08-17 β†’ 2018-08-17 Β· 3 obs
● 2018-08-17 09:25:18
β—‹ 2026-04-20 15:54:26
β—‹ 2026-05-10 15:09:50
β—‹NSdns2.registrar-servers.com2018-08-17 β†’ 2018-08-17 Β· 3 obs
● 2018-08-17 09:25:18
β—‹ 2026-04-20 15:54:26
β—‹ 2026-05-10 15:09:50
●NSns1.afternic.com2026-04-20 β†’ 2026-05-10 Β· 3 obs
β—‹ 2018-08-17 09:25:18
● 2026-04-20 15:54:26
● 2026-05-10 15:09:50
●NSns2.afternic.com2026-04-20 β†’ 2026-05-10 Β· 3 obs
β—‹ 2018-08-17 09:25:18
● 2026-04-20 15:54:26
● 2026-05-10 15:09:50
●NSverification-d3jclucsp89ganyqbydeny.ns101.verify.hn2026-04-20 β†’ 2026-05-10 Β· 3 obs
β—‹ 2018-08-17 09:25:18
● 2026-04-20 15:54:26
● 2026-05-10 15:09:50
β—‹MXmx1.privateemail.com2018-08-17 β†’ 2018-08-17 Β· 3 obs
● 2018-08-17 09:25:18
β—‹ 2026-04-20 15:54:26
β—‹ 2026-05-10 15:09:50
β—‹MXmx2.privateemail.com2018-08-17 β†’ 2018-08-17 Β· 3 obs
● 2018-08-17 09:25:18
β—‹ 2026-04-20 15:54:26
β—‹ 2026-05-10 15:09:50
●A13.248.169.482026-04-20 β†’ 2026-05-10 Β· 3 obs
β—‹ 2018-08-17 09:25:18
● 2026-04-20 15:54:26
● 2026-05-10 15:09:50
β—‹A192.64.119.1762018-08-17 β†’ 2018-08-17 Β· 3 obs
● 2018-08-17 09:25:18
β—‹ 2026-04-20 15:54:26
β—‹ 2026-05-10 15:09:50
●A76.223.54.1462026-04-20 β†’ 2026-05-10 Β· 3 obs
β—‹ 2018-08-17 09:25:18
● 2026-04-20 15:54:26
● 2026-05-10 15:09:50

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
coma.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net...-
attacker-controlled.comns1.afternic.com, ns2.afternic.com, verification-d3jclucsp89ganyqbydeny.ns101.verify.hn4 records

βœ… Authoritative Response

Server:97.74.98.69

NS records: ns1.afternic.com, ns2.afternic.com, verification-d3jclucsp89ganyqbydeny.ns101.verify.hn

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for attacker-controlled.com (unsigned zone)

⏱️ Timing

Total: 3291ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A276.223.54.146, 13.248.169.48
NS2ns1.afternic.com, ns2.afternic.com
MX1. (pri: 0)
TXT1v=spf1 -all
SOA1ns1.afternic.com dns.jomax.net

πŸ“Œ Glue Records Collected

Total: 4

Out-of-bailiwick: 4 (ns1.afternic.com, ns1.afternic.com, ns2.afternic.com...)

Analysis

IP Addresses

attacker-controlled.com points to two IPs: 13.248.169.48 and 76.223.54.146.

Other host names, for instance 7-betsixty.com, tour-ksc.com, elitepiano.com, mass-marketing.com and bithab.com share IP numbers with attacker-controlled.com.

Name Servers

attacker-controlled.com is delegated to name servers ns1.afternic.com, ns2.afternic.com and verification-d3jclucsp89ganyqbydeny.ns101.verify.hn.

attacker-controlled.com at least partially shares name servers with other domains such as wallcoupon.com, weblife.es, 324605225r.cdn30s.com, vlog.company and mainsta.com.

These name servers are commonly used with verification-frb6pqdkkjlns5j4tthxc3.ns101.verify.hn and verification-ilzyovyxkjcylcmj8rbffy.ns101.verify.hn.

Host names with two IP numbers:

ns1.afternic.com points to 2603:5:2126::45 and 97.74.98.69.

ns2.afternic.com points to 2603:5:2226::45 and 173.201.66.69.

verification-d3jclucsp89ganyqbydeny.ns101.verify.hn points to 13.248.169.48 and 76.223.54.146.