suspicious-coinbase.com - robtex.com
suspicious-coinbase.com
| DNSSEC | β οΈ Not signed | ||||||
| A | 2606:4700:3035::6815:205bπΊπΈ Cloudflare2606:4700:3035::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US β In HTTPS hints | ||||||
| A | 2606:4700:3037::ac43:b950πΊπΈ Cloudflare2606:4700:3037::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US β In HTTPS hints | ||||||
| A | 104.21.32.91Cloudflare104.21.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US β In HTTPS hints | ||||||
| A | 172.67.185.80πΊπΈ Cloudflare172.67.176.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US β In HTTPS hints | ||||||
| NS | ashley.ns.cloudflare.com β | ||||||
| A | 2606:4700:50::adf5:3a47πΊπΈ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | ashley.ns.cloudflare.com | ||||||
| A | 2803:f800:50::6ca2:c047π¨π· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L | ||||||
| PTR | ashley.ns.cloudflare.com | ||||||
| A | 2a06:98c1:50::ac40:2047πΊπΈ Cloudflare2a06:98c1:50::/45 | ||||||
| PTR | ashley.ns.cloudflare.com | ||||||
| A | 108.162.192.71πΊπΈ Cloudflare108.162.192.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | ashley.ns.cloudflare.com | ||||||
| A | 172.64.32.71πΊπΈ Cloudflare172.64.32.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | ashley.ns.cloudflare.com | ||||||
| A | 173.245.58.71πΊπΈ Cloudflare173.245.58.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | ashley.ns.cloudflare.com | ||||||
| NS | todd.ns.cloudflare.com | ||||||
| A | 2606:4700:58::adf5:3b92πΊπΈ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | todd.ns.cloudflare.com | ||||||
| A | 2803:f800:50::6ca2:c192π¨π· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L | ||||||
| PTR | todd.ns.cloudflare.com | ||||||
| A | 2a06:98c1:50::ac40:2192πΊπΈ Cloudflare2a06:98c1:50::/45 | ||||||
| PTR | todd.ns.cloudflare.com | ||||||
| A | 108.162.193.146πΊπΈ Cloudflare108.162.193.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | todd.ns.cloudflare.com | ||||||
| A | 172.64.33.146πΊπΈ Cloudflare172.64.33.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | todd.ns.cloudflare.com | ||||||
| A | 173.245.59.146πΊπΈ Cloudflare173.245.59.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | todd.ns.cloudflare.com | ||||||
| HTTPS | HTTP/3, HTTP/2 β hints match | ||||||
| IPv4 hints | 104.21.32.91, 172.67.185.80 | ||||||
| IPv6 hints | 2606:4700:3035::6815:205b, 2606:4700:3037::ac43:b950 | ||||||
| ECH | X25519, HKDF-SHA256 + AES-128-GCM draft, id=231, name=cloudflare-ech.com | ||||||
| SOA | ashley.ns.cloudflare.comdns@cloudflare.com serial=2400988430 | ||||||
com
| DNSSEC | π Signed (DS record present) | ||||||
| NS | a.gtld-servers.net β | ||||||
| NS | b.gtld-servers.net | ||||||
| NS | c.gtld-servers.net | ||||||
| NS | d.gtld-servers.net | ||||||
| NS | e.gtld-servers.net | ||||||
| NS | f.gtld-servers.net | ||||||
| NS | g.gtld-servers.net | ||||||
| NS | h.gtld-servers.net | ||||||
| NS | i.gtld-servers.net | ||||||
| NS | j.gtld-servers.net | ||||||
| NS | k.gtld-servers.net | ||||||
| NS | l.gtld-servers.net | ||||||
| NS | m.gtld-servers.net | ||||||
| SOA | a.gtld-servers.netnstld@verisign-grs.com serial=1778524296 | ||||||
Same first word
suspicious-coinbase.com |
DNS History
6 records (6 active, 0 former)
βNSashley.ns.cloudflare.com2026-04-12 β 2026-05-11 Β· 2 obs
β 2026-05-11 18:58:28
βNStodd.ns.cloudflare.com2026-04-12 β 2026-05-11 Β· 2 obs
β 2026-05-11 18:58:28
βA104.21.32.912026-04-12 β 2026-05-11 Β· 2 obs
β 2026-05-11 18:58:28
βA172.67.185.802026-04-12 β 2026-05-11 Β· 2 obs
β 2026-05-11 18:58:28
βA2606:4700:3035::6815:205b2026-04-12 β 2026-05-11 Β· 2 obs
β 2026-05-11 18:58:28
βA2606:4700:3037::ac43:b9502026-04-12 β 2026-05-11 Β· 2 obs
β 2026-05-11 18:58:28
π DNS Trace
π Delegation Chain
| Zone | Nameservers | Glue |
|---|---|---|
| com | a.gtld-servers.net, b.gtld-servers.net, c.gtld-servers.net, d.gtld-servers.net... | - |
| suspicious-coinbase.com | todd.ns.cloudflare.com, ashley.ns.cloudflare.com | 12 records |
β Authoritative Response
Server:108.162.192.71
NS records: todd.ns.cloudflare.com, ashley.ns.cloudflare.com
π DNSSEC Status
β οΈ Insecure (no DNSSEC)
No DS record for suspicious-coinbase.com (unsigned zone)
β±οΈ Timing
Total: 147ms | Queries: -
π Records
| Type | Count | Sample Data |
|---|---|---|
| A | 2 | 172.67.185.80, 104.21.32.91 |
| AAAA | 2 | 2606:4700:3035::6815:205b, 2606:4700:3037::ac43:b950 |
| NS | 2 | ashley.ns.cloudflare.com, todd.ns.cloudflare.com |
| HTTPS | 1 | {"priority":1,"target":".","alpn":["h3", |
| SOA | 1 | ashley.ns.cloudflare.com dns.cloudflare. |
π Glue Records Collected
Total: 12
Out-of-bailiwick: 12 (todd.ns.cloudflare.com, todd.ns.cloudflare.com, todd.ns.cloudflare.com...)
Analysis
IP Addresses
suspicious-coinbase.com maps to four IP numbers: 2606:4700:3035::6815:205b, 2606:4700:3037::ac43:b950, 104.21.32.91 and 172.67.185.80.
Other host names, for instance rickynunez.top, beubeu.fr, intellinet-network.com, adsservices.uk and ns2.armorcoded.net share IP numbers with suspicious-coinbase.com.
Name Servers
Two name servers ashley.ns.cloudflare.com and todd.ns.cloudflare.com are delegated to suspicious-coinbase.com.
suspicious-coinbase.com uses the same name server configuration as other domains, such as meta-adspro.com, pr-en1firstsecure.pages.dev, villamarketim.com.tr, thewordnerd.info and vang-24h.com.vn.
suspicious-coinbase.com at least partially shares name servers with other domains such as jig.media, casinospelare.nu, autino.pl, onequity.com and fantut.ru.
these name servers are commonly used with the name servers brodie.ns.cloudflare.com.
Host names with six IP numbers: Host name ashley.ns.cloudflare.com points to 2606:4700:50::adf5:3a47, 2803:f800:50::6ca2:c047, 2a06:98c1:50::ac40:2047, 108.162.192.71, 172.64.32.71 and 173.245.58.71; host name todd.ns.cloudflare.com points to 2606:4700:58::adf5:3b92, 2803:f800:50::6ca2:c192, 2a06:98c1:50::ac40:2192, 108.162.193.146, 172.64.33.146 and 173.245.59.146.