malware.stope40.org - robtex.com

malware.stope40.org

DNSSEC⚠️ Not signed
A2606:4700::6812:e1πŸ‡ΊπŸ‡Έ Cloudflare2606:4700::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A2606:4700::6812:1e1πŸ‡ΊπŸ‡Έ Cloudflare2606:4700::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A104.18.0.225Cloudflare104.18.0.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A104.18.1.225Cloudflare104.18.0.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
HTTPSHTTP/3, HTTP/2 βœ“ hints match
IPv4 hints104.18.0.225, 104.18.1.225
IPv6 hints2606:4700::6812:e1, 2606:4700::6812:1e1
ECHX25519, HKDF-SHA256 + AES-128-GCM draft, id=198, name=cloudflare-ech.com

stope40.org

DNSSEC⚠️ Not signed
A2606:4700::6812:e1πŸ‡ΊπŸ‡Έ Cloudflare2606:4700::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A2606:4700::6812:1e1πŸ‡ΊπŸ‡Έ Cloudflare2606:4700::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A104.18.0.225Cloudflare104.18.0.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A104.18.1.225Cloudflare104.18.0.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
NSharley.ns.cloudflare.com ⭐
NSrihana.ns.cloudflare.com
HTTPSHTTP/3, HTTP/2 βœ“ hints match
IPv4 hints104.18.0.225, 104.18.1.225
IPv6 hints2606:4700::6812:e1, 2606:4700::6812:1e1
ECHX25519, HKDF-SHA256 + AES-128-GCM draft, id=198, name=cloudflare-ech.com
SOAharley.ns.cloudflare.comdns@cloudflare.com serial=2403563111
⚠️ On DNS blocklist: tif
⚠️ On DNS blocklist: tif

Same first word

Similar names

DNS History

4 records (4 active, 0 former)

A104.18.0.225104.18.1.2252606:4700::6812:1e12606:4700::6812:e1
●A104.18.0.2252026-03-12 β†’ 2026-05-13 Β· 2 obs
● 2026-03-12 20:50:06
● 2026-05-13 07:50:16
●A104.18.1.2252026-03-12 β†’ 2026-05-13 Β· 2 obs
● 2026-03-12 20:50:06
● 2026-05-13 07:50:16
●A2606:4700::6812:1e12026-03-12 β†’ 2026-05-13 Β· 2 obs
● 2026-03-12 20:50:06
● 2026-05-13 07:50:16
●A2606:4700::6812:e12026-03-12 β†’ 2026-05-13 Β· 2 obs
● 2026-03-12 20:50:06
● 2026-05-13 07:50:16

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
orgb0.org.afilias-nst.org, b2.org.afilias-nst.org, d0.org.afilias-nst.org-
stope40.orgharley.ns.cloudflare.com, rihana.ns.cloudflare.com-

βœ… Authoritative Response

Server:172.64.32.244

NS records: harley.ns.cloudflare.com, rihana.ns.cloudflare.com

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for stope40.org (unsigned zone)

⏱️ Timing

Total: 1152ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A2104.18.0.225, 104.18.1.225
AAAA22606:4700::6812:1e1, 2606:4700::6812:e1
HTTPS1{"priority":1,"target":".","alpn":["h3",

Analysis

IP Addresses

malware.stope40.org maps to four IP numbers: 2606:4700::6812:e1, 2606:4700::6812:1e1, 104.18.0.225 and 104.18.1.225.

other host names include grg5f8g7eewf8.com, stope40.org, login.tide.co, www.scp-ks.org and web.tide.co; they share IP numbers with malware.stope40.org.