CF1759715688635-tsm20251005211530

WWW.ROBTEX.COM - shutdown-r.wtf

Search for IP or hostnames:

shutdown-r.wtf checked at 2025-10-06T01:54:48.617Z 215ms 259/259/259 100% R:13

shutdown-r.wtf

MXmail.protonmail.ch
A176.119.200.128🇨🇭 Proton AG
PTRmail.protonmail.ch
A185.70.42.128🇨🇭 Proton AG
PTRmail.protonmail.ch
A185.205.70.128🇫🇷 Proton AG
PTRmail.protonmail.ch
MXmailsec.protonmail.ch
A176.119.200.129🇨🇭 Proton AG
PTRmailsec.protonmail.ch
A185.70.42.129🇨🇭 Proton AG
PTRmailsec.protonmail.ch
A185.205.70.129🇫🇷 Proton AG
PTRmailsec.protonmail.ch
NSernest.ns.cloudflare.com
A2606:4700:58::adf5:3ba4🇺🇸 Cloudflare
PTRernest.ns.cloudflare.com
A2803:f800:50::6ca2:c1a4🇨🇷 Cloudflare
PTRernest.ns.cloudflare.com
A2a06:98c1:50::ac40:21a4🇺🇸 Cloudflare
PTRernest.ns.cloudflare.com
A108.162.193.164🇺🇸 Cloudflare
PTRernest.ns.cloudflare.com
A172.64.33.164🇺🇸 Cloudflare
PTRernest.ns.cloudflare.com
A173.245.59.164🇺🇸 Cloudflare
PTRernest.ns.cloudflare.com
NSlia.ns.cloudflare.com
A2606:4700:50::adf5:3ab9🇺🇸 Cloudflare
PTRlia.ns.cloudflare.com
A2803:f800:50::6ca2:c0b9🇨🇷 Cloudflare
PTRlia.ns.cloudflare.com
A2a06:98c1:50::ac40:20b9🇺🇸 Cloudflare
PTRlia.ns.cloudflare.com
A108.162.192.185🇺🇸 Cloudflare
PTRlia.ns.cloudflare.com
A172.64.32.185🇺🇸 Cloudflare
PTRlia.ns.cloudflare.com
A173.245.58.185🇺🇸 Cloudflare
PTRlia.ns.cloudflare.com
A2606:4700:3033::ac43:d531🇺🇸 Cloudflare
A2606:4700:3035::6815:232c🇺🇸 Cloudflare
A104.21.35.44Cloudflare
A172.67.213.49🇺🇸 Cloudflare

wtf

NSv0n0.nic.wtf
NSv0n1.nic.wtf
NSv0n2.nic.wtf
NSv0n3.nic.wtf
NSv2n0.nic.wtf
NSv2n1.nic.wtf

Starts with same word

Starts similarily

AI analysis

Four IP numbers are pointed to by shutdown-r.wtf: 2606:4700:3033::ac43:d531, 2606:4700:3035::6815:232c, 104.21.35.44 and 172.67.213.49.

other host names including utters.io, borostyanapartmanok.hu, cleanenergytraining.org, www.jsminjuryfirm.com and carpaine.cn share IP numbers with shutdown-r.wtf.

shutdown-r.wtf is delegated to two name servers ernest.ns.cloudflare.com and lia.ns.cloudflare.com.

shutdown-r.wtf shares the same name server setup as other domains, for instance faharas.net, covue.cloud, ithotdesk.com, uaveditor.com and covueit.com.

shutdown-r.wtf at least partially shares name servers with other domains, for instance aad67.com, icas.es, animalsaustralia-media.org, silencertalk.com and gifts4promo.co.uk.

these name servers are commonly used alongside coco.ns.cloudflare.com.

Host names with six IP numbers:

Host name ernest.ns.cloudflare.com points to: 2606:4700:58::adf5:3ba4, 2803:f800:50::6ca2:c1a4, 2a06:98c1:50::ac40:21a4, 108.162.193.164, 172.64.33.164 and 173.245.59.164.

Host name lia.ns.cloudflare.com points to: 2606:4700:50::adf5:3ab9, 2803:f800:50::6ca2:c0b9, 2a06:98c1:50::ac40:20b9, 108.162.192.185, 172.64.32.185 and 173.245.58.185.

Two mail servers handle shutdown-r.wtf: mail.protonmail.ch and mailsec.protonmail.ch.

shutdown-r.wtf shares the same mail server setup as other domains, for instance lamia.nl, stoneveden.com, base-six.com, drone404.com and gendarling.com.

shutdown-r.wtf shares some mail servers with other domains, at least partially, for instance tannartconsulting.com, teledisc.com, apgef.com, jsiegel.org and modolo.fr.

these mail servers are commonly used with the mail servers mx2.zoho.com.

Host names with three IPs:

mail.protonmail.ch points to 176.119.200.128, 185.70.42.128 and 185.205.70.128.

mailsec.protonmail.ch points to 176.119.200.129, 185.70.42.129 and 185.205.70.129.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

whOMslV CF johedugfp 2025-10-06