malicious-site.com - robtex.com
malicious-site.com
| DNSSEC | โ ๏ธ Not signed | ||||||
| A | 103.224.182.212๐ฆ๐บ TRELLIAN-AS-AP103.224.182.0/23 Trellian Pty. Limited 8 East Concourse | ||||||
| PTR | lb-182-212.above.com | ||||||
| NS | ns15.abovedomains.com โญ | ||||||
| A | 103.224.182.37๐ฆ๐บ TRELLIAN-AS-AP103.224.182.0/23 Trellian Pty. Limited 8 East Concourse | ||||||
| PTR | ns15.above.com | ||||||
| NS | ns1.abovedomains.com | ||||||
| A | 103.224.182.9๐ฆ๐บ TRELLIAN-AS-AP103.224.182.0/23 Trellian Pty. Limited 8 East Concourse | ||||||
| PTR | ns1.above.com | ||||||
| A | 103.224.212.9๐ฆ๐บ TRELLIAN-AS-AP103.224.212.0/23 Trellian Pty. Limited 8 East Concourse | ||||||
| PTR | ns1.above.com | ||||||
| NS | ns16.abovedomains.com | ||||||
| A | 103.224.212.37๐ฆ๐บ TRELLIAN-AS-AP103.224.212.0/23 Trellian Pty. Limited 8 East Concourse | ||||||
| PTR | ns16.above.com | ||||||
| MX | park-mx.above.com โญ | ||||||
| A | 103.224.212.34๐ฆ๐บ TRELLIAN-AS-AP103.224.212.0/23 Trellian Pty. Limited 8 East Concourse | ||||||
| PTR | park-mx.above.com | ||||||
| TXT | v=spf1 ip6:fdcf:abda:4154::/48 -all | ||||||
| SOA | ns1.abovedomains.comhostmaster@trellian.com 2026-03-25 #1 | ||||||
com
| DNSSEC | ๐ Signed (DS record present) | ||||||
| NS | a.gtld-servers.net โญ | ||||||
| NS | b.gtld-servers.net | ||||||
| NS | c.gtld-servers.net | ||||||
| NS | d.gtld-servers.net | ||||||
| NS | e.gtld-servers.net | ||||||
| NS | f.gtld-servers.net | ||||||
| NS | g.gtld-servers.net | ||||||
| NS | h.gtld-servers.net | ||||||
| NS | i.gtld-servers.net | ||||||
| NS | j.gtld-servers.net | ||||||
| NS | k.gtld-servers.net | ||||||
| NS | l.gtld-servers.net | ||||||
| NS | m.gtld-servers.net | ||||||
| SOA | a.gtld-servers.netnstld@verisign-grs.com serial=1774398522 | ||||||
Same first word
malicious-site.com |
DNS History
16 records (5 active, 11 former)
โNSns-us.1and1-dns.com2015-05-11 โ 2016-03-18 ยท 4 obs
โ 2016-03-18 11:27:38
โ 2016-08-11 03:34:02
โ 2026-03-25 00:45:42
โNSns-us.1and1-dns.de2015-05-11 โ 2016-03-18 ยท 4 obs
โ 2016-03-18 11:27:38
โ 2016-08-11 03:34:02
โ 2026-03-25 00:45:42
โNSns-us.1and1-dns.org2015-05-11 โ 2016-03-18 ยท 4 obs
โ 2016-03-18 11:27:38
โ 2016-08-11 03:34:02
โ 2026-03-25 00:45:42
โNSns-us.1and1-dns.us2015-05-11 โ 2016-03-18 ยท 4 obs
โ 2016-03-18 11:27:38
โ 2016-08-11 03:34:02
โ 2026-03-25 00:45:42
โNSns1.abovedomains.com2026-03-12 โ 2026-03-25 ยท 3 obs
โ 2026-03-12 16:58:56
โ 2026-03-25 00:45:42
โNSns15.abovedomains.com2026-03-12 โ 2026-03-25 ยท 3 obs
โ 2026-03-12 16:58:56
โ 2026-03-25 00:45:42
โNSns16.abovedomains.com2026-03-12 โ 2026-03-25 ยท 3 obs
โ 2026-03-12 16:58:56
โ 2026-03-25 00:45:42
โNSns19.domaincontrol.com2017-06-25 โ 2017-06-25 ยท 4 obs
โ 2017-06-25 17:08:18
โ 2026-03-12 16:58:56
โ 2026-03-25 00:45:42
โNSns20.domaincontrol.com2017-06-25 โ 2017-06-25 ยท 4 obs
โ 2017-06-25 17:08:18
โ 2026-03-12 16:58:56
โ 2026-03-25 00:45:42
โMXmx00.1and1.com2015-05-11 โ 2016-03-18 ยท 4 obs
โ 2016-03-18 11:27:38
โ 2016-08-11 03:34:02
โ 2026-03-25 00:45:42
โMXmx01.1and1.com2015-05-11 โ 2016-03-18 ยท 4 obs
โ 2016-03-18 11:27:38
โ 2016-08-11 03:34:02
โ 2026-03-25 00:45:42
โMXpark-mx.above.com2026-03-12 โ 2026-03-25 ยท 3 obs
โ 2026-03-12 16:58:56
โ 2026-03-25 00:45:42
โA103.224.182.2122026-03-12 โ 2026-03-25 ยท 3 obs
โ 2026-03-12 16:58:56
โ 2026-03-25 00:45:42
โA108.175.5.312015-05-11 โ 2016-03-18 ยท 4 obs
โ 2016-03-18 11:27:38
โ 2016-08-11 03:34:02
โ 2026-03-25 00:45:42
โA2607:f1c0:1000:6080:69ba:56a4:27a7:e2015-05-11 โ 2016-03-18 ยท 4 obs
โ 2016-03-18 11:27:38
โ 2016-08-11 03:34:02
โ 2026-03-25 00:45:42
โA50.63.202.542017-06-25 โ 2017-06-25 ยท 4 obs
โ 2017-06-25 17:08:18
โ 2026-03-12 16:58:56
โ 2026-03-25 00:45:42
๐ DNS Trace
๐ Delegation Chain
| Zone | Nameservers | Glue |
|---|---|---|
| com | k.gtld-servers.net, j.gtld-servers.net, l.gtld-servers.net, d.gtld-servers.net... | - |
| malicious-site.com | ns15.abovedomains.com, ns16.abovedomains.com | 2 records |
โ Authoritative Response
Server:103.224.212.37
NS records: ns15.abovedomains.com, ns16.abovedomains.com
๐ DNSSEC Status
โ ๏ธ Insecure (no DNSSEC)
No DS record for malicious-site.com (unsigned zone)
โฑ๏ธ Timing
Total: 302ms | Queries: -
๐ Records
| Type | Count | Sample Data |
|---|---|---|
| A | 1 | 103.224.182.212 |
| NS | 2 | ns16.abovedomains.com, ns15.abovedomains.com |
| MX | 1 | park-mx.above.com (pri: 10) |
| TXT | 1 | v=spf1 ip6:fdcf:abda:4154::/48 -all |
| SOA | 1 | ns1.abovedomains.com hostmaster.trellian |
๐ Glue Records Collected
Total: 2
Out-of-bailiwick: 2 (ns15.abovedomains.com, ns16.abovedomains.com)
Analysis
IP Addresses
malicious-site.com points to a single IP number: 103.224.182.212.
Other host names, for instance nasmork.pro, www.ashazkawg.com, chat-whatsappqigh2cm.gxscv.com, m34.xuatrlr.com and hyacint.info share IP numbers with malicious-site.com.
Name Servers
The delegation for malicious-site.com is handled by three name servers: ns15.abovedomains.com, ns16.abovedomains.com and ns1.abovedomains.com.
malicious-site.com at least partially shares name servers with other domains, for instance owes.com, 203-121-213-63.e-wire.net.au, timbrado6.meinastrohoroskop.com, crushphoto-sample.ch.vu and www.(0x78766964656f73)1.com.
These name servers are often used together with ns2.abovedomains.com, ns3.abovedomains.com, ns4.abovedomains.com, 421.ns1.abovedomains.com and 421.ns2.abovedomains.com.
Host names with two IP numbers:
ns1.abovedomains.com points to 103.224.182.9 and 103.224.212.9.
Host names with one IP number:
ns15.abovedomains.com points to 103.224.182.37.
ns16.abovedomains.com points to 103.224.212.37.
Mail Servers
malicious-site.com is handled by a single mail server, park-mx.above.com.
malicious-site.com uses the same mail server configuration as other domains, such as localhost.leggy.com.au, financiero.de, myspectrumbusiness.com, www.azleisd.com and www.rules.it.
park-mx.above.com points to a single IP: 103.224.212.34.