fraudster.org - robtex.com

fraudster.org

DNSSEC⚠️ Not signed
A64.190.63.222πŸ‡©πŸ‡ͺ SEDO64.190.62.0/23 -NET2-PI
PTRip-64-190-63-222.defastlink.net
NSns1.sedoparking.com ⭐
A3.130.216.63πŸ‡ΊπŸ‡Έ Amazon3.130.0.0/16 EC2 CMH prefix
PTRec2-3-130-216-63.us-east-2.compute.amazonaws.com
A91.195.241.8πŸ‡©πŸ‡ͺ SEDO91.195.240.0/23 -NET-PI
PTRip-91-195-241-8.defastlink.net
NSns2.sedoparking.com
A34.211.188.210πŸ‡ΊπŸ‡Έ Amazon34.208.0.0/12 EC2 PDX prefix
PTRec2-34-211-188-210.us-west-2.compute.amazonaws.com
A91.195.240.8πŸ‡©πŸ‡ͺ SEDO91.195.240.0/23 -NET-PI
PTRip-91-195-240-8.defastlink.net
MXlocalhost ⭐ πŸ”’
A::1
A127.0.0.1
TXTv=spf1 -all
SOAns1.sedoparking.comhostmaster@sedo.de 2018-05-16 #1

org

DNSSECπŸ”’ Signed (DS record present)
NSa0.org.afilias-nst.info ⭐ ⚠️ Not in parent delegation
NSa2.org.afilias-nst.info ⚠️ Not in parent delegation
NSb0.org.afilias-nst.org
NSb2.org.afilias-nst.org
NSc0.org.afilias-nst.info ⚠️ Not in parent delegation
NSd0.org.afilias-nst.org
SOAa0.org.afilias-nst.infohostmaster@donuts.email serial=1773551953

Subdomains

Same first word

Similar names

DNS History

8 records (4 active, 4 former)

20162017201820192020202120222023202420252026NSns1.sedoparking.comns2.sedoparking.coma.dns.hostway.netb.dns.hostway.netMXlocalhostA64.190.63.22266.113.136.11974.220.199.6
β—‹NSa.dns.hostway.net2016-02-26 β†’ 2018-11-01 Β· 4 obs
● 2016-02-26 14:33:32
● 2018-11-01 10:52:46
β—‹ 2026-03-06 07:05:56
β—‹ 2026-03-24 08:04:58
β—‹NSb.dns.hostway.net2016-02-26 β†’ 2018-11-01 Β· 4 obs
● 2016-02-26 14:33:32
● 2018-11-01 10:52:46
β—‹ 2026-03-06 07:05:56
β—‹ 2026-03-24 08:04:58
●NSns1.sedoparking.com2026-03-06 β†’ 2026-03-24 Β· 3 obs
β—‹ 2018-11-01 10:52:46
● 2026-03-06 07:05:56
● 2026-03-24 08:04:58
●NSns2.sedoparking.com2026-03-06 β†’ 2026-03-24 Β· 3 obs
β—‹ 2018-11-01 10:52:46
● 2026-03-06 07:05:56
● 2026-03-24 08:04:58
●MXlocalhost2026-03-06 β†’ 2026-03-24 Β· 2 obs
● 2026-03-06 07:05:56
● 2026-03-24 08:04:58
●A64.190.63.2222026-03-06 β†’ 2026-03-24 Β· 3 obs
β—‹ 2018-11-01 10:52:46
● 2026-03-06 07:05:56
● 2026-03-24 08:04:58
β—‹A66.113.136.1192016-02-26 β†’ 2018-11-01 Β· 5 obs
β—‹ 2015-11-24 20:09:02
● 2016-02-26 14:33:32
● 2018-11-01 10:52:46
β—‹ 2026-03-06 07:05:56
β—‹ 2026-03-24 08:04:58
β—‹A74.220.199.62015-08-03 β†’ 2015-08-03 Β· 3 obs
● 2015-08-03 19:30:20
β—‹ 2015-11-24 20:09:02
β—‹ 2026-03-24 08:04:58

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
orgb0.org.afilias-nst.org, b2.org.afilias-nst.org, d0.org.afilias-nst.org-
fraudster.orgns2.sedoparking.com, ns1.sedoparking.com-

βœ… Authoritative Response

Server:3.130.216.63

NS records: ns2.sedoparking.com, ns1.sedoparking.com

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for fraudster.org (unsigned zone)

⏱️ Timing

Total: 464ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A164.190.63.222
NS2ns2.sedoparking.com, ns1.sedoparking.com
MX1localhost (pri: 0)
TXT1v=spf1 -all
SOA1ns1.sedoparking.com hostmaster.sedo.de

Analysis

Hierarchy

fraudster.org is the parent of mel-fabregas-malware-clickfraud-cybercrime-money-laundry.fraudster.org.

IP Addresses

fraudster.org resolves to a single IP: 64.190.63.222.

Other host names, for instance newdream.de, yr.cl, angel.am, poliserv.com and support.wild(0x6269746368)es.com share IP numbers with fraudster.org.

Name Servers

fraudster.org has two name servers: ns1.sedoparking.com and ns2.sedoparking.com.

fraudster.org shares the same name server setup as other domains, for example eurobrake.de, canariasdigital.com, rdrf.de, whitemountainguides.com and mx.wissenswandel.de.

fraudster.org shares some name servers with other domains, for instance cloudygpt.com, auto-naijasniffer.blogspot.com.ua and auto-die-studio.blogspot.com.ua.

Host names with two IP numbers:

ns1.sedoparking.com points to: 3.130.216.63 and 91.195.241.8; ns2.sedoparking.com points to: 34.211.188.210 and 91.195.240.8.

Mail Servers

fraudster.org is handled by a single mail server, localhost.

fraudster.org shares the mail server setup with other domains, for example gpjv.com, deepforest.eu, vobe.de, nordsee-nordstrand.de and condiments.eu.

localhost resolves to two IPs: ::1 and 127.0.0.1.