CF1760699647555-tsm20251017082432

WWW.ROBTEX.COM - attacker.so

Search for IP or hostnames:

attacker.so checked at 2025-10-17T11:14:07.532Z 549ms 98/98/98 100% R:11

attacker.so

MXpark-mx.above.com
A103.224.212.34🇦🇺 TRELLIAN-AS-AP
PTRpark-mx.above.com
NSns1.abovedomains.com
A103.224.182.9🇦🇺 TRELLIAN-AS-AP
PTRns1.above.com
A103.224.212.9🇦🇺 TRELLIAN-AS-AP
PTRns1.above.com
NSns2.abovedomains.com
A103.224.182.10🇦🇺 TRELLIAN-AS-AP
PTRns2.above.com
A103.224.212.10🇦🇺 TRELLIAN-AS-AP
PTRns2.above.com
A103.224.182.210🇦🇺 TRELLIAN-AS-AP
PTRlb-182-210.above.com

so

NSd.nic.so
NSe.nic.so

Starts with same word

Starts similarily

AI analysis

attacker.so points to IP number: 103.224.182.210.

Other host names such as mail.ghettocraft.ru, uret.online, ekohidrotechnika.com, www.urzhum.japrodam.com and dogfart.network share IPs with attacker.so.

attacker.so is delegated to two name servers: ns1.abovedomains.com and ns2.abovedomains.com.

attacker.so shares the same name server setup as email2.goyeah.com, worldfree4u.blog, trueba.es, ubf.in and adsl201.buffnet.net.

Host names with two IP numbers: ns1.abovedomains.com points to: 103.224.182.9 and 103.224.212.9; ns2.abovedomains.com points to: 103.224.182.10 and 103.224.212.10.

attacker.so is handled by a single mail server, park-mx.above.com.

The mail server setup for attacker.so matches that of other domains, for instance www.goles.com, me.pronhub.me, ns2.efactura.net, jimsseptic.net and tudinero.es.

park-mx.above.com points to a single IP: 103.224.212.34.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

OMHTbvp CF johedugfp 2025-10-17