malicious-site.com - robtex.com

malicious-site.com

DNSSECโš ๏ธ Not signed
A103.224.182.212๐Ÿ‡ฆ๐Ÿ‡บ TRELLIAN-AS-AP103.224.182.0/23 Trellian Pty. Limited 8 East Concourse
PTRlb-182-212.above.com
NSns15.abovedomains.com โญ
A103.224.182.37๐Ÿ‡ฆ๐Ÿ‡บ TRELLIAN-AS-AP103.224.182.0/23 Trellian Pty. Limited 8 East Concourse
PTRns15.above.com
NSns1.abovedomains.com
A103.224.182.9๐Ÿ‡ฆ๐Ÿ‡บ TRELLIAN-AS-AP103.224.182.0/23 Trellian Pty. Limited 8 East Concourse
PTRns1.above.com
A103.224.212.9๐Ÿ‡ฆ๐Ÿ‡บ TRELLIAN-AS-AP103.224.212.0/23 Trellian Pty. Limited 8 East Concourse
PTRns1.above.com
NSns16.abovedomains.com
A103.224.212.37๐Ÿ‡ฆ๐Ÿ‡บ TRELLIAN-AS-AP103.224.212.0/23 Trellian Pty. Limited 8 East Concourse
PTRns16.above.com
MXpark-mx.above.com โญ
A103.224.212.34๐Ÿ‡ฆ๐Ÿ‡บ TRELLIAN-AS-AP103.224.212.0/23 Trellian Pty. Limited 8 East Concourse
PTRpark-mx.above.com
TXTv=spf1 ip6:fdcf:abda:4154::/48 -all
SOAns1.abovedomains.comhostmaster@trellian.com 2026-03-25 #1

com

Same first word

DNS History

16 records (5 active, 11 former)

20162017201820192020202120222023202420252026NSns1.abovedomains.comns15.abovedomains.comns16.abovedomains.comns-us.1and1-dns.comns-us.1and1-dns.dens-us.1and1-dns.orgns-us.1and1-dns.usns19.domaincontrol.comns20.domaincontrol.comMXpark-mx.above.commx00.1and1.commx01.1and1.comA103.224.182.212108.175.5.312607:f1c0:1000:6080:69ba:56a4:27a7:e50.63.202.54
โ—‹NSns-us.1and1-dns.com2015-05-11 โ†’ 2016-03-18 ยท 4 obs
โ— 2015-05-11 10:30:16
โ— 2016-03-18 11:27:38
โ—‹ 2016-08-11 03:34:02
โ—‹ 2026-03-25 00:45:42
โ—‹NSns-us.1and1-dns.de2015-05-11 โ†’ 2016-03-18 ยท 4 obs
โ— 2015-05-11 10:30:16
โ— 2016-03-18 11:27:38
โ—‹ 2016-08-11 03:34:02
โ—‹ 2026-03-25 00:45:42
โ—‹NSns-us.1and1-dns.org2015-05-11 โ†’ 2016-03-18 ยท 4 obs
โ— 2015-05-11 10:30:16
โ— 2016-03-18 11:27:38
โ—‹ 2016-08-11 03:34:02
โ—‹ 2026-03-25 00:45:42
โ—‹NSns-us.1and1-dns.us2015-05-11 โ†’ 2016-03-18 ยท 4 obs
โ— 2015-05-11 10:30:16
โ— 2016-03-18 11:27:38
โ—‹ 2016-08-11 03:34:02
โ—‹ 2026-03-25 00:45:42
โ—NSns1.abovedomains.com2026-03-12 โ†’ 2026-03-25 ยท 3 obs
โ—‹ 2017-06-25 17:08:18
โ— 2026-03-12 16:58:56
โ— 2026-03-25 00:45:42
โ—NSns15.abovedomains.com2026-03-12 โ†’ 2026-03-25 ยท 3 obs
โ—‹ 2017-06-25 17:08:18
โ— 2026-03-12 16:58:56
โ— 2026-03-25 00:45:42
โ—NSns16.abovedomains.com2026-03-12 โ†’ 2026-03-25 ยท 3 obs
โ—‹ 2017-06-25 17:08:18
โ— 2026-03-12 16:58:56
โ— 2026-03-25 00:45:42
โ—‹NSns19.domaincontrol.com2017-06-25 โ†’ 2017-06-25 ยท 4 obs
โ—‹ 2016-08-11 03:34:02
โ— 2017-06-25 17:08:18
โ—‹ 2026-03-12 16:58:56
โ—‹ 2026-03-25 00:45:42
โ—‹NSns20.domaincontrol.com2017-06-25 โ†’ 2017-06-25 ยท 4 obs
โ—‹ 2016-08-11 03:34:02
โ— 2017-06-25 17:08:18
โ—‹ 2026-03-12 16:58:56
โ—‹ 2026-03-25 00:45:42
โ—‹MXmx00.1and1.com2015-05-11 โ†’ 2016-03-18 ยท 4 obs
โ— 2015-05-11 10:30:16
โ— 2016-03-18 11:27:38
โ—‹ 2016-08-11 03:34:02
โ—‹ 2026-03-25 00:45:42
โ—‹MXmx01.1and1.com2015-05-11 โ†’ 2016-03-18 ยท 4 obs
โ— 2015-05-11 10:30:16
โ— 2016-03-18 11:27:38
โ—‹ 2016-08-11 03:34:02
โ—‹ 2026-03-25 00:45:42
โ—MXpark-mx.above.com2026-03-12 โ†’ 2026-03-25 ยท 3 obs
โ—‹ 2016-08-11 03:34:02
โ— 2026-03-12 16:58:56
โ— 2026-03-25 00:45:42
โ—A103.224.182.2122026-03-12 โ†’ 2026-03-25 ยท 3 obs
โ—‹ 2017-06-25 17:08:18
โ— 2026-03-12 16:58:56
โ— 2026-03-25 00:45:42
โ—‹A108.175.5.312015-05-11 โ†’ 2016-03-18 ยท 4 obs
โ— 2015-05-11 10:30:16
โ— 2016-03-18 11:27:38
โ—‹ 2016-08-11 03:34:02
โ—‹ 2026-03-25 00:45:42
โ—‹A2607:f1c0:1000:6080:69ba:56a4:27a7:e2015-05-11 โ†’ 2016-03-18 ยท 4 obs
โ— 2015-05-11 10:30:16
โ— 2016-03-18 11:27:38
โ—‹ 2016-08-11 03:34:02
โ—‹ 2026-03-25 00:45:42
โ—‹A50.63.202.542017-06-25 โ†’ 2017-06-25 ยท 4 obs
โ—‹ 2016-08-11 03:34:02
โ— 2017-06-25 17:08:18
โ—‹ 2026-03-12 16:58:56
โ—‹ 2026-03-25 00:45:42

๐Ÿ” DNS Trace

๐Ÿ“‹ Delegation Chain

ZoneNameserversGlue
comk.gtld-servers.net, j.gtld-servers.net, l.gtld-servers.net, d.gtld-servers.net...-
malicious-site.comns15.abovedomains.com, ns16.abovedomains.com2 records

โœ… Authoritative Response

Server:103.224.212.37

NS records: ns15.abovedomains.com, ns16.abovedomains.com

๐Ÿ”’ DNSSEC Status

โš ๏ธ Insecure (no DNSSEC)

No DS record for malicious-site.com (unsigned zone)

โฑ๏ธ Timing

Total: 302ms | Queries: -

๐Ÿ“„ Records

TypeCountSample Data
A1103.224.182.212
NS2ns16.abovedomains.com, ns15.abovedomains.com
MX1park-mx.above.com (pri: 10)
TXT1v=spf1 ip6:fdcf:abda:4154::/48 -all
SOA1ns1.abovedomains.com hostmaster.trellian

๐Ÿ“Œ Glue Records Collected

Total: 2

Out-of-bailiwick: 2 (ns15.abovedomains.com, ns16.abovedomains.com)

Analysis

IP Addresses

malicious-site.com points to a single IP number: 103.224.182.212.

Other host names, for instance nasmork.pro, www.ashazkawg.com, chat-whatsappqigh2cm.gxscv.com, m34.xuatrlr.com and hyacint.info share IP numbers with malicious-site.com.

Name Servers

The delegation for malicious-site.com is handled by three name servers: ns15.abovedomains.com, ns16.abovedomains.com and ns1.abovedomains.com.

malicious-site.com at least partially shares name servers with other domains, for instance owes.com, 203-121-213-63.e-wire.net.au, timbrado6.meinastrohoroskop.com, crushphoto-sample.ch.vu and www.(0x78766964656f73)1.com.

These name servers are often used together with ns2.abovedomains.com, ns3.abovedomains.com, ns4.abovedomains.com, 421.ns1.abovedomains.com and 421.ns2.abovedomains.com.

Host names with two IP numbers:

ns1.abovedomains.com points to 103.224.182.9 and 103.224.212.9.

Host names with one IP number:

ns15.abovedomains.com points to 103.224.182.37.

ns16.abovedomains.com points to 103.224.212.37.

Mail Servers

malicious-site.com is handled by a single mail server, park-mx.above.com.

malicious-site.com uses the same mail server configuration as other domains, such as localhost.leggy.com.au, financiero.de, myspectrumbusiness.com, www.azleisd.com and www.rules.it.

park-mx.above.com points to a single IP: 103.224.212.34.