CF1759544021738-tsm20251003185623

WWW.ROBTEX.COM - malware.builders

Search for IP or hostnames:

malware.builders checked at 2025-10-04T02:13:41.701Z 334ms 158/158/158 100% R:9

malware.builders

NSns45.domaincontrol.com
A2603:5:2162::17🇺🇸 GODADDY-DNS
PTRns45.domaincontrol.com
A97.74.102.23🇺🇸 GODADDY-DNS
PTRns45.domaincontrol.com
NSns46.domaincontrol.com
A2603:5:2262::17🇺🇸 GODADDY-DNS
PTRns46.domaincontrol.com
A173.201.70.23🇺🇸 GODADDY-DNS
PTRns46.domaincontrol.com
MXmailstore1.secureserver.net
A216.69.141.78🇺🇸 AS398101
PTRosplibsmtp01-v02.prod.phx3.secureserver.net
A216.69.141.114🇺🇸 AS398101
PTRosplibsmtp03-v02.prod.phx3.secureserver.net
A216.69.141.162🇺🇸 AS398101
PTRosplibsmtp02-v02.prod.phx3.secureserver.net
MXsmtp.secureserver.net
A216.69.141.71🇺🇸 AS398101
PTRosplibsmtp01-v01.prod.phx3.secureserver.net
A216.69.141.84🇺🇸 AS398101
PTRosplibsmtp02-v01.prod.phx3.secureserver.net
A216.69.141.113🇺🇸 AS398101
PTRosplibsmtp03-v01.prod.phx3.secureserver.net
A3.33.130.190🇺🇸 Amazon
PTRa2aa9ff50de748dbe.awsglobalaccelerator.com
A15.197.148.33🇺🇸 Amazon
PTRa2aa9ff50de748dbe.awsglobalaccelerator.com

builders

NSv0n0.nic.builders
NSv0n1.nic.builders
NSv0n2.nic.builders
NSv0n3.nic.builders
NSv2n0.nic.builders
NSv2n1.nic.builders

Starts with same word

Starts similarily

AI analysis

malware.builders points to two IP numbers: 3.33.130.190 and 15.197.148.33.

Other host names, for instance snappowerx.com, pncn.me, bbc-llc.com, storwins.com and livezonavillage.com share IP numbers with malware.builders.

malware.builders is delegated to two name servers: ns45.domaincontrol.com and ns46.domaincontrol.com.

malware.builders uses the same name server setup as other domains, for instance imagine-books.com, cartes-na.com, myttax.com, internetautosalesinc.net and jkornfeld.net.

Host names with two IP numbers:

The host ns45.domaincontrol.com points to 2603:5:2162::17 and 97.74.102.23.

The host ns46.domaincontrol.com points to 2603:5:2262::17 and 173.201.70.23.

malware.builders is handled by two mail servers: mailstore1.secureserver.net and smtp.secureserver.net.

malware.builders shares the same mail server setup as other domains, including artlist.info, top10smbloans.com, new-oem-parts.com, aevalouise.com and jamesbakey.com.

At least part of malware.builders's mail servers are shared with other domains, for instance bismarckyouthbaseball.org and imjj.photography.

Host names with three IP numbers: mailstore1.secureserver.net points to 216.69.141.78, 216.69.141.114 and 216.69.141.162; smtp.secureserver.net points to 216.69.141.71, 216.69.141.84 and 216.69.141.113.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

KDQlTgp CF johedugfp 2025-10-04