redteam-ioc-test.com - robtex.com

redteam-ioc-test.com

DNSSECπŸ”’ Signed (DS record present)
A2606:4700:3034::6815:fb9πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3034::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A2606:4700:3037::ac43:a3c4πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3037::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A104.21.15.185Cloudflare104.21.0.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A172.67.163.196πŸ‡ΊπŸ‡Έ Cloudflare172.67.160.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
NSjill.ns.cloudflare.com ⭐
A2606:4700:50::adf5:3a7aπŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRjill.ns.cloudflare.com
A2803:f800:50::6ca2:c07aπŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRjill.ns.cloudflare.com
A2a06:98c1:50::ac40:207aπŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRjill.ns.cloudflare.com
A108.162.192.122πŸ‡ΊπŸ‡Έ Cloudflare108.162.192.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRjill.ns.cloudflare.com
A172.64.32.122πŸ‡ΊπŸ‡Έ Cloudflare172.64.32.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRjill.ns.cloudflare.com
A173.245.58.122πŸ‡ΊπŸ‡Έ Cloudflare173.245.58.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRjill.ns.cloudflare.com
NSkip.ns.cloudflare.com
A2606:4700:58::adf5:3b80πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRkip.ns.cloudflare.com
A2803:f800:50::6ca2:c180πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRkip.ns.cloudflare.com
A2a06:98c1:50::ac40:2180πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRkip.ns.cloudflare.com
A108.162.193.128πŸ‡ΊπŸ‡Έ Cloudflare108.162.193.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRkip.ns.cloudflare.com
A172.64.33.128πŸ‡ΊπŸ‡Έ Cloudflare172.64.33.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRkip.ns.cloudflare.com
A173.245.59.128πŸ‡ΊπŸ‡Έ Cloudflare173.245.59.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRkip.ns.cloudflare.com
TXTca3-91871583c7b94975aa068c6d25b56494
HTTPSHTTP/3, HTTP/2 βœ“ hints match
IPv4 hints104.21.15.185, 172.67.163.196
IPv6 hints2606:4700:3034::6815:fb9, 2606:4700:3037::ac43:a3c4
ECHX25519, HKDF-SHA256 + AES-128-GCM draft, id=91, name=cloudflare-ech.com
SOAjill.ns.cloudflare.comdns@cloudflare.com serial=2403527750

com

Same first word

DNS History

6 records (6 active, 0 former)

NSjill.ns.cloudflare.comkip.ns.cloudflare.comA104.21.15.185172.67.163.1962606:4700:3034::6815:fb92606:4700:3037::ac43:a3c4
●NSjill.ns.cloudflare.com2026-04-10 β†’ 2026-05-11 Β· 2 obs
● 2026-04-10 11:54:06
● 2026-05-11 02:23:52
●NSkip.ns.cloudflare.com2026-04-10 β†’ 2026-05-11 Β· 2 obs
● 2026-04-10 11:54:06
● 2026-05-11 02:23:52
●A104.21.15.1852026-04-10 β†’ 2026-05-11 Β· 2 obs
● 2026-04-10 11:54:06
● 2026-05-11 02:23:52
●A172.67.163.1962026-04-10 β†’ 2026-05-11 Β· 2 obs
● 2026-04-10 11:54:06
● 2026-05-11 02:23:52
●A2606:4700:3034::6815:fb92026-04-10 β†’ 2026-05-11 Β· 2 obs
● 2026-04-10 11:54:06
● 2026-05-11 02:23:52
●A2606:4700:3037::ac43:a3c42026-04-10 β†’ 2026-05-11 Β· 2 obs
● 2026-04-10 11:54:06
● 2026-05-11 02:23:52

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
coml.gtld-servers.net, j.gtld-servers.net, h.gtld-servers.net, d.gtld-servers.net...-
redteam-ioc-test.comjill.ns.cloudflare.com, kip.ns.cloudflare.com12 records

βœ… Authoritative Response

Server:108.162.192.122

NS records: jill.ns.cloudflare.com, kip.ns.cloudflare.com

πŸ”’ DNSSEC Status

πŸ” Secure (DNSSEC validated)

Chain of trust verified from root to domain

⏱️ Timing

Total: 255ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A2104.21.15.185, 172.67.163.196
AAAA22606:4700:3037::ac43:a3c4, 2606:4700:3034::6815:fb9
NS2jill.ns.cloudflare.com, kip.ns.cloudflare.com
TXT1ca3-91871583c7b94975aa068c6d25b56494
HTTPS1{"priority":1,"target":".","alpn":["h3",
SOA1jill.ns.cloudflare.com dns.cloudflare.co

πŸ“Œ Glue Records Collected

Total: 12

Out-of-bailiwick: 12 (jill.ns.cloudflare.com, jill.ns.cloudflare.com, jill.ns.cloudflare.com...)

Analysis

IP Addresses

redteam-ioc-test.com maps to four IP numbers: 2606:4700:3034::6815:fb9, 2606:4700:3037::ac43:a3c4, 104.21.15.185 and 172.67.163.196.

other host names include nikioporsesh.tatblog.ir, ns1.misr365.net, chasebet-au.net, olx.pi-32656433.rest and pppcouncil.ca; they share IP numbers with redteam-ioc-test.com.

Name Servers

Two name servers jill.ns.cloudflare.com and kip.ns.cloudflare.com handle the delegation for redteam-ioc-test.com.

redteam-ioc-test.com shares the same name server setup as other domains, for instance geoisp.com, eatseasonably.co.uk, opentibia.pl, kdkschickenandwaffles.com and culthub.com.

redteam-ioc-test.com at least partially shares name servers with other domains, for instance blackhandmusic.net, apodacapromotions.com, ncev.com.au, abea.co.jp and 90866.cc.

These name servers are commonly used alongside roman.ns.cloudflare.com, andy.ns.cloudflare.com and cody.ns.cloudflare.com.

Six IP addresses per host:

jill.ns.cloudflare.com points to 2606:4700:50::adf5:3a7a, 2803:f800:50::6ca2:c07a, 2a06:98c1:50::ac40:207a, 108.162.192.122, 172.64.32.122 and 173.245.58.122; kip.ns.cloudflare.com points to 2606:4700:58::adf5:3b80, 2803:f800:50::6ca2:c180, 2a06:98c1:50::ac40:2180, 108.162.193.128, 172.64.33.128 and 173.245.59.128