CF1760370980976-tsm20251012143351

MXLIST.NET - evil.cc

Search for IP or hostnames:

evil.cc checked at 2025-10-13T15:56:20.962Z 202ms 146/146/146 100% R:12

evil.cc

NSmoura.ns.cloudflare.com
A2606:4700:58::a29f:2cd9 🇺🇸 Cloudflare
PTRmoura.ns.cloudflare.com
A2803:f800:50::6ca2:c3d9 🇨🇷 Cloudflare
PTRmoura.ns.cloudflare.com
A2a06:98c1:50::ac40:23d9 🇺🇸 Cloudflare
PTRmoura.ns.cloudflare.com
A108.162.195.217🇺🇸 Cloudflare
PTRmoura.ns.cloudflare.com
A162.159.44.217 Cloudflare
PTRmoura.ns.cloudflare.com
A172.64.35.217🇺🇸 Cloudflare
PTRmoura.ns.cloudflare.com
NSullis.ns.cloudflare.com
A2606:4700:50::a29f:267f 🇺🇸 Cloudflare
PTRullis.ns.cloudflare.com
A2803:f800:50::6ca2:c27f 🇨🇷 Cloudflare
PTRullis.ns.cloudflare.com
A2a06:98c1:50::ac40:227f 🇺🇸 Cloudflare
PTRullis.ns.cloudflare.com
A108.162.194.127🇺🇸 Cloudflare
PTRullis.ns.cloudflare.com
A162.159.38.127 Cloudflare
PTRullis.ns.cloudflare.com
A172.64.34.127🇺🇸 Cloudflare
PTRullis.ns.cloudflare.com
MXevil-cc.mail.protection.outlook.com
A2a01:111:f403:c902::7 🇺🇸 Microsoft
PTRmail-sj0pr02cu00107.inbound.protection.outlook.com
A2a01:111:f403:c922:: 🇺🇸 Microsoft
PTRmail-bl0pr03cu00200.inbound.protection.outlook.com
A2a01:111:f403:c931::1 🇺🇸 Microsoft
PTRmail-sa9pr03cu00201.inbound.protection.outlook.com
A2a01:111:f403:f807::1 🇺🇸 Microsoft
PTRmail-co1pr21cu00101.inbound.protection.outlook.com
A52.101.8.46🇺🇸 Microsoft
PTRmail-dm6pr05cu00406.inbound.protection.outlook.com
A52.101.10.5🇺🇸 Microsoft
PTRmail-bn6pr04cu00105.inbound.protection.outlook.com
A52.101.42.10🇺🇸 Microsoft
PTRmail-co1pr21cu00102.inbound.protection.outlook.com
A52.101.194.19🇺🇸 Microsoft
PTRmail-ch5pr02cu00303.inbound.protection.outlook.com
A2606:4700:3032::ac43:d27c 🇺🇸 Cloudflare
A2606:4700:3036::6815:1059 🇺🇸 Cloudflare
A104.21.16.89 Cloudflare
A172.67.210.124🇺🇸 Cloudflare

cc

NSac1.nstld.com
NSac2.nstld.com
NSac3.nstld.com
NSac4.nstld.com

Starts with same word

Starts similarily

AI analysis

evil.cc maps to four IP numbers: 2606:4700:3032::ac43:d27c, 2606:4700:3036::6815:1059, 104.21.16.89 and 172.67.210.124.

Other host names such as 441nn.com, www.pakistanisexporn.com, idevi.com, www.socketloop.com and refillvitamin.com share IPs with evil.cc.

Two name servers moura.ns.cloudflare.com and ullis.ns.cloudflare.com handle the delegation for evil.cc.

evil.cc shares the same name server setup as other domains, for example bormay.com, oliviamark.com, poprose.com, zlily.com and exbass.com.

evil.cc at least partially shares name servers with other domains, for example innthegardens.com, kellerford.net, employeegifts.ca, sharptech.us and endocrine-abstracts.org.

These name servers are commonly used with rajeev.ns.cloudflare.com and benedict.ns.cloudflare.com and becky.ns.cloudflare.com.

Host names with six IP numbers:

moura.ns.cloudflare.com points to 2606:4700:58::a29f:2cd9, 2803:f800:50::6ca2:c3d9, 2a06:98c1:50::ac40:23d9, 108.162.195.217, 162.159.44.217 and 172.64.35.217.

ullis.ns.cloudflare.com points to 2606:4700:50::a29f:267f, 2803:f800:50::6ca2:c27f, 2a06:98c1:50::ac40:227f, 108.162.194.127, 162.159.38.127 and 172.64.34.127.

The evil-cc.mail.protection.outlook.com mail server handles evil.cc.

evil-cc.mail.protection.outlook.com points to eight IP numbers: 2a01:111:f403:c902::7, 2a01:111:f403:c922::, 2a01:111:f403:c931::1, 2a01:111:f403:f807::1, 52.101.8.46, 52.101.10.5, 52.101.42.10 and 52.101.194.19.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

EKMyZtw CF johedugfp 2025-10-13