CF1761319566477-tsm20251017082432

MXLIST.NET - attacker.so

Search for IP or hostnames:

attacker.so checked at 2025-10-24T15:26:06.465Z 497ms 68/68/68 100% R:15

attacker.so

MXpark-mx.above.com
A103.224.212.34🇦🇺 TRELLIAN-AS-AP
PTRpark-mx.above.com
NSns1.abovedomains.com
A103.224.182.9🇦🇺 TRELLIAN-AS-AP
PTRns1.above.com
A103.224.212.9🇦🇺 TRELLIAN-AS-AP
PTRns1.above.com
NSns2.abovedomains.com
A103.224.182.10🇦🇺 TRELLIAN-AS-AP
PTRns2.above.com
A103.224.212.10🇦🇺 TRELLIAN-AS-AP
PTRns2.above.com
A103.224.182.210🇦🇺 TRELLIAN-AS-AP
PTRlb-182-210.above.com

so

NSd.nic.so
NSe.nic.so

Starts with same word

Starts similarily

AI analysis

attacker.so points to a single IP number: 103.224.182.210.

other host names for instance mail.ghettocraft.ru, uret.online, www.urzhum.japrodam.com, dogfart.network and teenporn18.pro share IP numbers with attacker.so.

attacker.so is delegated to two name servers: ns1.abovedomains.com and ns2.abovedomains.com.

attacker.so shares the same name server setup as other domains, for example email2.goyeah.com, worldfree4u.blog, trueba.es, ubf.in and adsl201.buffnet.net.

Host names with two IP numbers:

ns1.abovedomains.com points to 103.224.182.9 and 103.224.212.9

ns2.abovedomains.com points to 103.224.182.10 and 103.224.212.10

attacker.so is handled by a single mail server, park-mx.above.com.

attacker.so shares the same mail server setup as other domains, for instance www.goles.com, me.pronhub.me, ns2.efactura.net, jimsseptic.net and tudinero.es.

Host name park-mx.above.com points to IP address 103.224.212.34.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

uwbplfr CF johedugfp 2025-10-24