ms12hinet.com - robtex.com

ms12hinet.com

DNSSEC⚠️ Not signed
A44.244.22.128πŸ‡ΊπŸ‡Έ Amazon44.224.0.0/11 EC2 PDX prefix
PTRec2-44-244-22-128.us-west-2.compute.amazonaws.com
NSns4.csof.net ⭐
A52.20.19.77πŸ‡ΊπŸ‡Έ Amazon52.20.0.0/14 EC2 IAD prefix
PTRec2-52-20-19-77.compute-1.amazonaws.com
NSns1.csof.net
A18.205.186.231πŸ‡ΊπŸ‡Έ Amazon18.204.0.0/14 EC2 IAD prefix
PTRec2-18-205-186-231.compute-1.amazonaws.com
NSns2.csof.net
A23.21.178.27πŸ‡ΊπŸ‡Έ Amazon23.20.0.0/15 EC2 IAD prefix
PTRec2-23-21-178-27.compute-1.amazonaws.com
NSns3.csof.net
A3.214.185.54πŸ‡ΊπŸ‡Έ Amazon3.208.0.0/12 EC2 IAD prefix
PTRec2-3-214-185-54.compute-1.amazonaws.com
MXmx1.ms12hinet.com ⭐
A46.4.12.146πŸ‡©πŸ‡ͺ Hetzner46.4.0.0/16 HETZNER-RZ-FKS-BLK3
PTRstatic.146.12.4.46.clients.your-server.de
MXmx2.ms12hinet.com ⭐
A46.4.10.173πŸ‡©πŸ‡ͺ Hetzner46.4.0.0/16 HETZNER-RZ-FKS-BLK3
PTRstatic.173.10.4.46.clients.your-server.de
TXTv=spf1 include:_incspfcheck.mailspike.net ?all
SOAns4.csof.nethostmaster@ms12hinet.com serial=1776602720

com

⚠️ On DNS blocklist: tif
🦠 Blackbook: Known malware/C&C domain
WOT: SUSPICIOUS (19/100)

Same first word

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
comk.gtld-servers.net, f.gtld-servers.net, i.gtld-servers.net, d.gtld-servers.net...-
ms12hinet.comns1.csof.net, ns2.csof.net, ns4.csof.net, ns3.csof.net-

βœ… Authoritative Response

Server:3.214.185.54

NS records: ns1.csof.net, ns2.csof.net, ns4.csof.net, ns3.csof.net

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for ms12hinet.com (unsigned zone)

⏱️ Timing

Total: 330ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A144.244.22.128
NS4ns4.csof.net, ns2.csof.net...
MX2mx2.ms12hinet.com (pri: 10), mx1.ms12hinet.com (pri: 10)
TXT1v=spf1 include:_incspfcheck.mailspike.ne
SOA1ns4.csof.net hostmaster.ms12hinet.com

Analysis

IP Addresses

ms12hinet.com resolves to one IP number: 44.244.22.128.

other host names including www.1c0580563c7233db533fc51789fef808.com, 65b4d.cnhkwy.com, www.073ef1d4f2bfe5be15f7a65f3d0819d9.org, 75836.cnhkwy.com and 535aa.cnhkwy.com share IP numbers with ms12hinet.com.

Name Servers

ms12hinet.com is delegated to four name servers: ns1.csof.net, ns2.csof.net, ns3.csof.net and ns4.csof.net.

ms12hinet.com at least partially shares name servers with other domains, for instance ra.mailrover.net, 240b1b2e778a9d40a7266662f993ce23.net, alifmedical.shop, aegieuueueuuruia.ru and brokensoul.ga.

these name servers are often used together with ns5.csof.net, ns6.csof.net, ns7.csof.net and ns8.csof.net.

Host names with one IP number: ns1.csof.net points to 18.205.186.231; ns2.csof.net points to 23.21.178.27; ns3.csof.net points to 3.214.185.54; ns4.csof.net points to 52.20.19.77.

Mail Servers

Two mail servers handle ms12hinet.com: mx1.ms12hinet.com and mx2.ms12hinet.com.

Host names with one IP number:

mx1.ms12hinet.com points to 46.4.12.146

mx2.ms12hinet.com points to 46.4.10.173