evil-ware.com - robtex.com

evil-ware.com

CNAMEwww.evilware.com
CNAMEevilware.com
DNSSEC⚠️ Not signed
A15.204.240.210πŸ‡ΊπŸ‡Έ OVH15.204.128.0/17 Hosting route
PTRvps-e22fca79.vps.ovh.us
NSdns1.registrar-servers.com ⭐
A2610:a1:1024::200πŸ‡ΊπŸ‡Έ MAINT-ID-120082610:a1:1024::/48 Neustar
PTRdns1.namecheaphosting.com
PTRdns1.registrar-servers.com
A156.154.132.200πŸ‡ΊπŸ‡Έ MAINT-ID-12008156.154.132.0/24 Neustar
PTRdns1.namecheaphosting.com
PTRdns1.registrar-servers.com
NSdns2.registrar-servers.com
A2610:a1:1025::200πŸ‡ΊπŸ‡Έ MAINT-ID-120082610:a1:1025::/48 Neustar
PTRdns2.namecheaphosting.com
PTRdns2.registrar-servers.com
A156.154.133.200πŸ‡ΊπŸ‡Έ MAINT-ID-12008156.154.133.0/24 Neustar
PTRdns2.namecheaphosting.com
PTRdns2.registrar-servers.com
MXaspmx.l.google.com ⭐
A2a00:1450:4009:c0f::1bπŸ‡¬πŸ‡§ Google2a00:1450:4009::/48
PTRyulhrs-in-f27.1e100.net
A192.178.223.27πŸ‡ΊπŸ‡Έ Google192.178.223.0/24
PTRyulhrs-in-f27.1e100.net
MXalt1.aspmx.l.google.com(5)
A2a00:1450:4025:402::1bπŸ‡³πŸ‡± Google2a00:1450:4025::/48
PTRrb-in-f27.1e100.net
A142.250.102.26πŸ‡ΊπŸ‡Έ Google142.250.102.0/24
PTRrb-in-f26.1e100.net
MXalt2.aspmx.l.google.com(5)
A2607:f8b0:4023:1015::1bπŸ‡ΊπŸ‡Έ Google2607:f8b0::/32
PTRyudfwta-in-f27.1e100.net
A172.253.135.26πŸ‡ΊπŸ‡Έ Google172.253.135.0/24
PTRyudfwta-in-f26.1e100.net
MXalt3.aspmx.l.google.com(10)
A2a00:1450:4009:c0f::1bπŸ‡¬πŸ‡§ Google2a00:1450:4009::/48
PTRyulhrs-in-f27.1e100.net
A192.178.223.26πŸ‡ΊπŸ‡Έ Google192.178.223.0/24
PTRyulhrs-in-f26.1e100.net
MXalt4.aspmx.l.google.com(10)
A2a00:1450:4025:c01::1bπŸ‡΅πŸ‡± Google2a00:1450:4025::/48
PTRrd-in-f27.1e100.net
A142.250.147.27πŸ‡ΊπŸ‡Έ Google142.250.147.0/24
PTRrd-in-f27.1e100.net
SOAdns1.registrar-servers.comhostmaster@registrar-servers.com serial=1758252459

com

Same first word

Similar names

DNS History

9 records (3 active, 6 former)

20162017201820192020202120222023202420252026NSdns1.registrar-servers.comdns2.registrar-servers.comns11.domaincontrol.comns12.domaincontrol.comMXmailstore1.secureserver.netsmtp.secureserver.netA12.173.193.20045.55.38.20CNAMEwww.evilware.com
●NSdns1.registrar-servers.com2026-03-24 β†’ 2026-03-24 Β· 2 obs
β—‹ 2017-04-18 15:49:18
● 2026-03-24 23:31:56
●NSdns2.registrar-servers.com2026-03-24 β†’ 2026-03-24 Β· 2 obs
β—‹ 2017-04-18 15:49:18
● 2026-03-24 23:31:56
β—‹NSns11.domaincontrol.com2015-05-14 β†’ 2017-04-18 Β· 3 obs
● 2015-05-14 18:35:18
● 2017-04-18 15:49:18
β—‹ 2026-03-24 23:31:56
β—‹NSns12.domaincontrol.com2015-05-14 β†’ 2017-04-18 Β· 3 obs
● 2015-05-14 18:35:18
● 2017-04-18 15:49:18
β—‹ 2026-03-24 23:31:56
β—‹MXmailstore1.secureserver.net2015-05-14 β†’ 2017-04-18 Β· 3 obs
● 2015-05-14 18:35:18
● 2017-04-18 15:49:18
β—‹ 2026-03-24 23:31:56
β—‹MXsmtp.secureserver.net2015-05-14 β†’ 2017-04-18 Β· 3 obs
● 2015-05-14 18:35:18
● 2017-04-18 15:49:18
β—‹ 2026-03-24 23:31:56
β—‹A12.173.193.2002015-05-14 β†’ 2015-05-14 Β· 3 obs
● 2015-05-14 18:35:18
β—‹ 2015-10-20 08:23:36
β—‹ 2026-03-24 23:31:56
β—‹A45.55.38.202015-10-20 β†’ 2017-04-18 Β· 4 obs
β—‹ 2015-05-14 18:35:18
● 2015-10-20 08:23:36
● 2017-04-18 15:49:18
β—‹ 2026-03-24 23:31:56
●CNAMEwww.evilware.com2026-03-24 β†’ 2026-03-24 Β· 1 obs
● 2026-03-24 23:31:56

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
comk.gtld-servers.net, h.gtld-servers.net, f.gtld-servers.net, l.gtld-servers.net...-
evil-ware.comdns1.registrar-servers.com, dns2.registrar-servers.com4 records

βœ… Authoritative Response

Server:156.154.133.200

NS records: dns1.registrar-servers.com, dns2.registrar-servers.com

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for evil-ware.com (unsigned zone)

⏱️ Timing

Total: 174ms | Queries: -

πŸ“„ Records

TypeCountSample Data
NS2dns1.registrar-servers.com, dns2.registrar-servers.com
CNAME1www.evilware.com
SOA1dns1.registrar-servers.com hostmaster.re

πŸ“Œ Glue Records Collected

Total: 4

Out-of-bailiwick: 4 (dns1.registrar-servers.com, dns1.registrar-servers.com, dns2.registrar-servers.com...)

Analysis

IP Addresses

evil-ware.com points to a single IP: 15.204.240.210.

Other host names such as vps-e22fca79.vps.ovh.us and evilware.com share IP numbers with evil-ware.com.

Name Servers

Two name servers dns1.registrar-servers.com and dns2.registrar-servers.com handle delegation for evil-ware.com.

evil-ware.com uses the same name server setup as other domains, for example beetech.pw, calculator.engineering, kraigoverholt.com, aaewr.com and 94111app.com.

evil-ware.com partially shares name servers with other domains; examples include shedreamsinfrench.com, thewildcard.net, gamin-ators.com, britsby.com and theunemployedmillionaire.com.

These name servers are commonly used with dns3.registrar-servers.com, dns4.registrar-servers.com and dns5.registrar-servers.com.

Host names with two IP numbers:

dns1.registrar-servers.com points to: 2610:a1:1024::200 and 156.154.132.200

dns2.registrar-servers.com points to: 2610:a1:1025::200 and 156.154.133.200

Mail Servers

Five mail servers handle evil-ware.com: aspmx.l.google.com, alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, alt3.aspmx.l.google.com and alt4.aspmx.l.google.com.

evil-ware.com shares some mail servers with other domains, at least partially, such as ncmventures.com, temametal.com, twnet.se, ns500731.ns500754.ns500754.ns500754.ns500731.ns500704.ns500704.ns500742.ns500671.ns500704.ns500704.ns500704.ns500671.ns500678.ns500688.ns500671.ns500649.lustychickser.com and ns500671.ns500671.ns500754.ns500671.ns500671.ns500704.ns500731.ns500705.ns500671.ns500678.ns500678.ns500678.ns500688.ns500671.ns500649.lustychickser.com.

These mail servers are often used with aspmx2.googlemail.com, aspmx3.googlemail.com, aspmx4.googlemail.com and aspmx5.googlemail.com.

Host names with two IP numbers

aspmx.l.google.com points to 2a00:1450:4009:c0f::1b and 192.178.223.27

alt1.aspmx.l.google.com points to 2a00:1450:4025:402::1b and 142.250.102.26

alt2.aspmx.l.google.com points to 2607:f8b0:4023:1015::1b and 172.253.135.26

alt3.aspmx.l.google.com points to 2a00:1450:4009:c0f::1b and 192.178.223.26

alt4.aspmx.l.google.com points to 2a00:1450:4025:c01::1b and 142.250.147.27

Host names that point to 2a00:1450:4009:c0f::1b: aspmx.l.google.com and alt3.aspmx.l.google.com