CF1760329495237-tsm20251012143351

MXLIST.NET - evil.wtf

Search for IP or hostnames:

evil.wtf checked at 2025-10-13T04:24:55.218Z 322ms 118/118/118 100% R:16

evil.wtf

NSfay.ns.cloudflare.com
A2606:4700:50::adf5:3a73 🇺🇸 Cloudflare
PTRfay.ns.cloudflare.com
A2803:f800:50::6ca2:c073 🇨🇷 Cloudflare
PTRfay.ns.cloudflare.com
A2a06:98c1:50::ac40:2073 🇺🇸 Cloudflare
PTRfay.ns.cloudflare.com
A108.162.192.115🇺🇸 Cloudflare
PTRfay.ns.cloudflare.com
A172.64.32.115🇺🇸 Cloudflare
PTRfay.ns.cloudflare.com
A173.245.58.115🇺🇸 Cloudflare
PTRfay.ns.cloudflare.com
NSlee.ns.cloudflare.com
A2606:4700:58::adf5:3b81 🇺🇸 Cloudflare
PTRlee.ns.cloudflare.com
A2803:f800:50::6ca2:c181 🇨🇷 Cloudflare
PTRlee.ns.cloudflare.com
A2a06:98c1:50::ac40:2181 🇺🇸 Cloudflare
PTRlee.ns.cloudflare.com
A108.162.193.129🇺🇸 Cloudflare
PTRlee.ns.cloudflare.com
A172.64.33.129🇺🇸 Cloudflare
PTRlee.ns.cloudflare.com
A173.245.59.129🇺🇸 Cloudflare
PTRlee.ns.cloudflare.com
MX_dc-mx.482147edf1f7.evil.wtf
A96.234.162.10🇺🇸 Verizon
PTRstatic-96-234-162-10.bltmmd.fios.verizon.net
A2606:4700:3032::ac43:bc0e 🇺🇸 Cloudflare
A2606:4700:3033::6815:7d9 🇺🇸 Cloudflare
A104.21.7.217 Cloudflare
A172.67.188.14🇺🇸 Cloudflare

wtf

NSv0n0.nic.wtf
NSv0n1.nic.wtf
NSv0n2.nic.wtf
NSv0n3.nic.wtf
NSv2n0.nic.wtf
NSv2n1.nic.wtf

Starts with same word

Starts similarily

AI analysis

evil.wtf points to four IP numbers: 2606:4700:3032::ac43:bc0e, 2606:4700:3033::6815:7d9, 104.21.7.217 and 172.67.188.14.

Other host names including miriamofficial.com, pengruntugs.com, coinsacargo.com, www.paginadigital.com.br and mnym.cn share IP numbers with evil.wtf.

evil.wtf's delegation uses two name servers, fay.ns.cloudflare.com and lee.ns.cloudflare.com.

evil.wtf shares the same name server setup as other domains, for example yurlkink.ru, gopro-forum.ru, niteteam4.com, mach-b.com and housedavenport.com.

evil.wtf at least partially shares name servers with other domains, including hi-techautomotive.com, adk-media.net, baptist100.org, troygrille.com and griot.fr.

These name servers are often used together with neil.ns.cloudflare.com.

Host names with six IP numbers:

fay.ns.cloudflare.com points to: 2606:4700:50::adf5:3a73, 2803:f800:50::6ca2:c073, 2a06:98c1:50::ac40:2073, 108.162.192.115, 172.64.32.115 and 173.245.58.115.

lee.ns.cloudflare.com points to: 2606:4700:58::adf5:3b81, 2803:f800:50::6ca2:c181, 2a06:98c1:50::ac40:2181, 108.162.193.129, 172.64.33.129 and 173.245.59.129.

evil.wtf is handled by a single mail server, _dc-mx.482147edf1f7.evil.wtf.

_dc-mx.482147edf1f7.evil.wtf points to a single IP: 96.234.162.10.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

NaGoTLh CF johedugfp 2025-10-13