c2-server.evil.com - robtex.com

c2-server.evil.com

DNSSEC⚠️ Not signed
A66.96.146.129πŸ‡ΊπŸ‡Έ EIG-2987366.96.128.0/18 Endurance International Group, Inc
PTR129.146.96.66.static.eigbox.net
MXmx.evil.com ⭐
A66.96.140.158πŸ‡ΊπŸ‡Έ EIG-2987366.96.128.0/18 Endurance International Group, Inc
PTR158.140.96.66.static.eigbox.net
A66.96.140.159πŸ‡ΊπŸ‡Έ EIG-2987366.96.128.0/18 Endurance International Group, Inc
PTR159.140.96.66.static.eigbox.net

evil.com

DNSSEC⚠️ Not signed
A66.96.146.129πŸ‡ΊπŸ‡Έ EIG-2987366.96.128.0/18 Endurance International Group, Inc
NSns1.verio.com ⭐
NSns2.verio.com
MXmx.evil.com ⭐
TXTv=spf1 ip4:66.96.128.0/18 include:websitewelcome.com ?all
SOAns1.verio.comdnsadmin@verio.com 2016-11-17 #29
WOT: SAFE (61/100)
rank #232640 globally
rank #96354 in the tld
⚠️ On DNS blocklist: pro.plus, tif, ultimate
WOT: SAFE (67/100)
πŸ“ˆ Tranco rank: #496,384

DNS History

2 records (2 active, 0 former)

MXmx.evil.comA66.96.146.129
●MXmx.evil.com2026-03-26 β†’ 2026-04-24 Β· 2 obs
● 2026-03-26 22:16:44
● 2026-04-24 10:05:28
●A66.96.146.1292026-03-26 β†’ 2026-04-24 Β· 2 obs
● 2026-03-26 22:16:44
● 2026-04-24 10:05:28

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
comh.gtld-servers.net, i.gtld-servers.net, j.gtld-servers.net, m.gtld-servers.net...-
evil.comns1.verio.com, ns2.verio.com2 records

βœ… Authoritative Response

Server:66.96.142.149

NS records: ns1.verio.com, ns2.verio.com

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for evil.com (unsigned zone)

⏱️ Timing

Total: 178ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A166.96.146.129
MX1mx.evil.com (pri: 30)

πŸ“Œ Glue Records Collected

Total: 2

Out-of-bailiwick: 2 (ns1.verio.com, ns2.verio.com)

Analysis

IP Addresses

c2-server.evil.com points to IP number: 66.96.146.129.

Other host names such as yachtsilvercloud.com, www.3dwarehouse.com, diamondscan.com, mad-dog.com and bsmcon9.verio.com share IPs with c2-server.evil.com.

Mail Servers

c2-server.evil.com is handled by a single mail server, mx.evil.com.

c2-server.evil.com shares the same mail server setup as other domains, for instance www.evil.com, relay.evil.com and evil.com.

mx.evil.com points to two IPs: 66.96.140.158 and 66.96.140.159.