CF1759518551536-tsm20251003185623

WWW.RTSAK.COM - malicious.me

Search for IP or hostnames:

malicious.me checked at 2025-10-03T19:09:11.519Z 267ms 148/148/148 100% R:17

malicious.me

NSns-206.awsdns-25.com
A2600:9000:5300:ce00::1 🇺🇸 Amazon
PTRns-206.awsdns-25.com
A205.251.192.206🇺🇸 Amazon
PTRns-206.awsdns-25.com
MXaspmx2.googlemail.com
A2a00:1450:4013:c1e::1b 🇳🇱 Google
PTRyugrqzs-in-f27.1e100.net
A192.178.213.27🇺🇸 Google
PTRyugrqzs-in-f27.1e100.net
MXaspmx3.googlemail.com
A2a00:1450:4025:c01::1b 🇵🇱 Google
PTRrd-in-f27.1e100.net
A142.250.147.26🇺🇸 Google
PTRrd-in-f26.1e100.net
NSns-645.awsdns-16.net
A2600:9000:5302:8500::1 🇺🇸 Amazon
PTRns-645.awsdns-16.net
A205.251.194.133🇺🇸 Amazon
PTRns-645.awsdns-16.net
NSns-1253.awsdns-28.org
A2600:9000:5304:e500::1 🇺🇸 Amazon
PTRns-1253.awsdns-28.org
A205.251.196.229🇺🇸 Amazon
PTRns-1253.awsdns-28.org
MXaspmx.l.google.com
A2607:f8b0:4023:c0b::1a 🇺🇸 Google
PTRdd-in-f26.1e100.net
A142.251.2.26🇺🇸 Google
PTRdl-in-f26.1e100.net
NSns-1549.awsdns-01.co.uk
A2600:9000:5306:d00::1 🇺🇸 Amazon
PTRns-1549.awsdns-01.co.uk
A205.251.198.13🇺🇸 Amazon
PTRns-1549.awsdns-01.co.uk
MXalt1.aspmx.l.google.com
A2607:f8b0:4023:100f::1b 🇺🇸 Google
PTRyudfwra-in-f27.1e100.net
A192.178.220.26🇺🇸 Google
PTRyudfwra-in-f26.1e100.net
MXalt2.aspmx.l.google.com
A2607:f8b0:4003:c30::1a 🇺🇸 Google
PTRyutulis-in-f26.1e100.net
A74.125.27.26🇺🇸 Google
PTRyutulis-in-f26.1e100.net
A3.221.27.20🇺🇸 Amazon
PTRec2-3-221-27-20.compute-1.amazonaws.com
A52.44.152.152🇺🇸 Amazon
PTRec2-52-44-152-152.compute-1.amazonaws.com
A52.70.109.128🇺🇸 Amazon
PTRec2-52-70-109-128.compute-1.amazonaws.com

me

NSa0.nic.me
NSa2.nic.me
NSb0.nic.me
NSb2.nic.me
NSc0.nic.me

Starts with same word

Starts similarily

AI analysis

malicious.me points to IPs: 3.221.27.20, 52.44.152.152 and 52.70.109.128.

Other host names for instance ec2-52-44-152-152.compute-1.amazonaws.com and ec2-3-221-27-20.compute-1.amazonaws.com share IP numbers with malicious.me.

malicious.me is delegated to four name servers: ns-206.awsdns-25.com, ns-645.awsdns-16.net, ns-1253.awsdns-28.org and ns-1549.awsdns-01.co.uk.

malicious.me at least partially shares name servers with other domains such as humanitiestexas.org, d25mv5u262gol2.cloudfront.net, stagepa.com, adaptiveaudience.com and boulderfreshgardenco.com.

these name servers are commonly used with ns-287.awsdns-35.com, ns-170.awsdns-21.com, ns-292.awsdns-36.com, ns-1173.awsdns-18.org, ns-284.awsdns-35.com and ns-434.awsdns-54.com.

Host names with two IP numbers:

ns-206.awsdns-25.com points to 2600:9000:5300:ce00::1 and 205.251.192.206

ns-645.awsdns-16.net points to 2600:9000:5302:8500::1 and 205.251.194.133

ns-1253.awsdns-28.org points to 2600:9000:5304:e500::1 and 205.251.196.229

ns-1549.awsdns-01.co.uk points to 2600:9000:5306:d00::1 and 205.251.198.13

malicious.me is handled by five mail servers: aspmx2.googlemail.com, aspmx3.googlemail.com, aspmx.l.google.com, alt1.aspmx.l.google.com and alt2.aspmx.l.google.com.

malicious.me shares mail servers with other domains at least in part, for instance ghumc.org, micatch.net, good-focus.com, bargainbooksy.com and slaveryfootprint.org.

These mail servers are often used together with aspmx4.googlemail.com, aspmx5.googlemail.com, alt3.aspmx.l.google.com and alt4.aspmx.l.google.com.

Two IPs per host name:

aspmx2.googlemail.com points to: 2a00:1450:4013:c1e::1b and 192.178.213.27

aspmx3.googlemail.com points to: 2a00:1450:4025:c01::1b and 142.250.147.26

aspmx.l.google.com points to: 2607:f8b0:4023:c0b::1a and 142.251.2.26

alt1.aspmx.l.google.com points to: 2607:f8b0:4023:100f::1b and 192.178.220.26

alt2.aspmx.l.google.com points to: 2607:f8b0:4003:c30::1a and 74.125.27.26

Pattern: left IDs ascend by 9 (12, 21, 30, 39, 48); each pair of targets ascend by 9 (15/18, 24/27, 33/36, 42/45, 51/54)

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

ygvQNvI CF johedugfp 2025-10-03