CF1759871732793-tsm20251005211530

WWW.ROBTEX.COM - malicious.group

Search for IP or hostnames:

malicious.group checked at 2025-10-07T21:15:32.750Z 222ms 226/226/226 100% R:5

malicious.group

MXmail.protonmail.ch
A176.119.200.128🇨🇭 Proton AG
PTRmail.protonmail.ch
A185.70.42.128🇨🇭 Proton AG
PTRmail.protonmail.ch
A185.205.70.128🇫🇷 Proton AG
PTRmail.protonmail.ch
MXmailsec.protonmail.ch
A176.119.200.129🇨🇭 Proton AG
PTRmailsec.protonmail.ch
A185.70.42.129🇨🇭 Proton AG
PTRmailsec.protonmail.ch
A185.205.70.129🇫🇷 Proton AG
PTRmailsec.protonmail.ch
NShal.ns.cloudflare.com
A2606:4700:58::adf5:3bae🇺🇸 Cloudflare
PTRhal.ns.cloudflare.com
A2803:f800:50::6ca2:c1ae🇨🇷 Cloudflare
PTRhal.ns.cloudflare.com
A2a06:98c1:50::ac40:21ae🇺🇸 Cloudflare
PTRhal.ns.cloudflare.com
A108.162.193.174🇺🇸 Cloudflare
PTRhal.ns.cloudflare.com
A172.64.33.174🇺🇸 Cloudflare
PTRhal.ns.cloudflare.com
A173.245.59.174🇺🇸 Cloudflare
PTRhal.ns.cloudflare.com
NSingrid.ns.cloudflare.com
A2606:4700:50::adf5:3aa5🇺🇸 Cloudflare
PTRingrid.ns.cloudflare.com
A2803:f800:50::6ca2:c0a5🇨🇷 Cloudflare
PTRingrid.ns.cloudflare.com
A2a06:98c1:50::ac40:20a5🇺🇸 Cloudflare
PTRingrid.ns.cloudflare.com
A108.162.192.165🇺🇸 Cloudflare
PTRingrid.ns.cloudflare.com
A172.64.32.165🇺🇸 Cloudflare
PTRingrid.ns.cloudflare.com
A173.245.58.165🇺🇸 Cloudflare
PTRingrid.ns.cloudflare.com
A178.128.137.126🇳🇱 DigitalOcean

group

NSv0n0.nic.group
NSv0n1.nic.group
NSv0n2.nic.group
NSv0n3.nic.group
NSv2n0.nic.group
NSv2n1.nic.group

Starts with same word

Starts similarily

AI analysis

malicious.group resolves to a single IP: 178.128.137.126.

Other host names, for instance mail.jodiecook.com, coles.codes, upfront.no, karingarcia.com and afripreneurial.com share IP numbers with malicious.group.

malicious.group has two name servers: hal.ns.cloudflare.com and ingrid.ns.cloudflare.com.

malicious.group shares the same name server setup as other domains, for example surge.tools, globalsugarart.com, bolt.tw, virala.in and st-by.com.

malicious.group shares some name servers with other domains, for example florisrobbemont.nl, bymybay.com, compassioninternational.com, haftaninfirsaturunu.com and tendancemag.com.

These name servers are commonly used with the name servers alla.ns.cloudflare.com.

Host names with six IP numbers: hal.ns.cloudflare.com points to: 2606:4700:58::adf5:3bae, 2803:f800:50::6ca2:c1ae, 2a06:98c1:50::ac40:21ae, 108.162.193.174, 172.64.33.174 and 173.245.59.174; ingrid.ns.cloudflare.com points to: 2606:4700:50::adf5:3aa5, 2803:f800:50::6ca2:c0a5, 2a06:98c1:50::ac40:20a5, 108.162.192.165, 172.64.32.165 and 173.245.58.165.

malicious.group is served by two mail servers: mail.protonmail.ch and mailsec.protonmail.ch.

malicious.group shares the mail server setup with other domains, for example dtmh.dk, sourcemonkey.com, areskicapital.com, cheapnews.eu and vulkancasino.ua.

malicious.group shares some mail servers with other domains, at least partially; for instance dynsec.org, atxsec.com, mgoldschmidt.de, icob.org and batsnake.com.

Host names with three IP numbers: mail.protonmail.ch points to 176.119.200.128, 185.70.42.128 and 185.205.70.128; mailsec.protonmail.ch points to 176.119.200.129, 185.70.42.129 and 185.205.70.129.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

RGwRbOk CF johedugfp 2025-10-07