ransomleak.com - robtex.com
ransomleak.com
com
| DNSSEC | π Signed (DS record present) | ||||||
| NS | a.gtld-servers.net β | ||||||
| NS | b.gtld-servers.net | ||||||
| NS | c.gtld-servers.net | ||||||
| NS | d.gtld-servers.net | ||||||
| NS | e.gtld-servers.net | ||||||
| NS | f.gtld-servers.net | ||||||
| NS | g.gtld-servers.net | ||||||
| NS | h.gtld-servers.net | ||||||
| NS | i.gtld-servers.net | ||||||
| NS | j.gtld-servers.net | ||||||
| NS | k.gtld-servers.net | ||||||
| NS | l.gtld-servers.net | ||||||
| NS | m.gtld-servers.net | ||||||
| SOA | a.gtld-servers.netnstld@verisign-grs.com serial=1776135792 | ||||||
Same first word
ransomleak.com |
Similar names
salonmaker.com |
manorlakes.com |
loanmakers.co.uk |
manorlakes.com.au |
keramsalon.ru |
lakeonmars.com |
kosmalenar.com |
losakerman.com.ar |
loansmaker.com |
loanmakers.com |
DNS History
9 records (9 active, 0 former)
βNSns-1230.awsdns-25.org2026-04-13 β 2026-04-14 Β· 2 obs
β 2026-04-14 03:19:12
βNSns-139.awsdns-17.com2026-04-13 β 2026-04-14 Β· 2 obs
β 2026-04-14 03:19:12
βNSns-1716.awsdns-22.co.uk2026-04-13 β 2026-04-14 Β· 2 obs
β 2026-04-14 03:19:12
βNSns-902.awsdns-48.net2026-04-13 β 2026-04-14 Β· 2 obs
β 2026-04-14 03:19:12
βMXsmtp.google.com2026-04-13 β 2026-04-14 Β· 2 obs
β 2026-04-14 03:19:12
βA3.166.152.1032026-04-13 β 2026-04-14 Β· 2 obs
β 2026-04-14 03:19:12
βA3.166.152.642026-04-13 β 2026-04-14 Β· 2 obs
β 2026-04-14 03:19:12
βA3.166.152.732026-04-13 β 2026-04-14 Β· 2 obs
β 2026-04-14 03:19:12
βA3.166.152.872026-04-13 β 2026-04-14 Β· 2 obs
β 2026-04-14 03:19:12
π DNS Trace
π Delegation Chain
| Zone | Nameservers | Glue |
|---|---|---|
| com | a.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net... | - |
| ransomleak.com | ns-139.awsdns-17.com, ns-902.awsdns-48.net, ns-1716.awsdns-22.co.uk, ns-1230.awsdns-25.org | 1 record |
β Authoritative Response
Server:205.251.196.206
NS records: ns-139.awsdns-17.com, ns-902.awsdns-48.net, ns-1716.awsdns-22.co.uk, ns-1230.awsdns-25.org
π DNSSEC Status
β οΈ Insecure (no DNSSEC)
No DS record for ransomleak.com (unsigned zone)
β±οΈ Timing
Total: 288ms | Queries: -
π Records
| Type | Count | Sample Data |
|---|---|---|
| A | 4 | 3.166.152.64, 3.166.152.103... |
| NS | 4 | ns-1230.awsdns-25.org, ns-139.awsdns-17.com... |
| MX | 1 | smtp.google.com (pri: 1) |
| TXT | 2 | google-site-verification=cDRwtChUVvaBRE_, v=spf1 include:_spf.google.com include:s |
| SOA | 1 | ns-1230.awsdns-25.org awsdns-hostmaster. |
π Glue Records Collected
Total: 1
Out-of-bailiwick: 1 (ns-139.awsdns-17.com)
Analysis
IP Addresses
ransomleak.com points to four IP numbers: 3.166.152.64, 3.166.152.73, 3.166.152.87 and 3.166.152.103.
Other host names, for instance atsod.launch.liveramp.com, proofrog.cloud, d2gd5aww7f0uvr.cloudfront.net, vault.zip and gamevox.com share IP numbers with ransomleak.com.
Name Servers
ransomleak.com is delegated to four name servers: ns-139.awsdns-17.com, ns-902.awsdns-48.net, ns-1230.awsdns-25.org and ns-1716.awsdns-22.co.uk.
ransomleak.com at least partially shares its name servers with other domains, for instance zyxel-ls.com, jimmoorecadillac.com, newplanexcel.com, cbtrk73.com and sandbox.timeoutkorea.kr.
These name servers are commonly used together with ns-334.awsdns-41.com, ns-944.awsdns-54.net, ns-1955.awsdns-52.co.uk, ns-1306.awsdns-35.org, ns1.americaneagle.com, ns2.americaneagle.com, ns-204.awsdns-25.com and ns-761.awsdns-31.net.
Host names with two IPs: ns-139.awsdns-17.com points to 2600:9000:5300:8b00::1 and 205.251.192.139; ns-902.awsdns-48.net points to 2600:9000:5303:8600::1 and 205.251.195.134; ns-1230.awsdns-25.org points to 2600:9000:5304:ce00::1 and 205.251.196.206; ns-1716.awsdns-22.co.uk points to 2600:9000:5306:b400::1 and 205.251.198.180.
Mail Servers
ransomleak.com is served by a single mail server, smtp.google.com.
ransomleak.com uses the same mail server setup as other domains such as qaxal.com, apexaerospacecorp.com, trevorras.com, kitsapcreate.org and maestre.eu.
ransomleak.com shares some mail servers with other domains, including crowdspark.com, neeramahajan.com, adamfarris.net, healthmate.co and vitality.com.au.
smtp.google.com points to nine IP numbers: 2607:f8b0:4004:c23::1a, 2607:f8b0:4004:c23::1b, 2607:f8b0:4004:c27::1a, 2607:f8b0:4004:c27::1b, 142.251.179.26, 172.253.139.26, 172.253.139.27, 192.178.155.26 and 192.178.155.27.