CF1760815522266-tsm20251017082432

MXLIST.NET - malicious.group

Search for IP or hostnames:

malicious.group checked at 2025-10-18T19:25:22.254Z 265ms 131/131/131 100% R:15

malicious.group

MXmail.protonmail.ch
A176.119.200.128๐Ÿ‡จ๐Ÿ‡ญ Proton AG
PTRmail.protonmail.ch
A185.70.42.128๐Ÿ‡จ๐Ÿ‡ญ Proton AG
PTRmail.protonmail.ch
A185.205.70.128๐Ÿ‡ซ๐Ÿ‡ท Proton AG
PTRmail.protonmail.ch
MXmailsec.protonmail.ch
A176.119.200.129๐Ÿ‡จ๐Ÿ‡ญ Proton AG
PTRmailsec.protonmail.ch
A185.70.42.129๐Ÿ‡จ๐Ÿ‡ญ Proton AG
PTRmailsec.protonmail.ch
A185.205.70.129๐Ÿ‡ซ๐Ÿ‡ท Proton AG
PTRmailsec.protonmail.ch
NShal.ns.cloudflare.com
A2606:4700:58::adf5:3bae ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRhal.ns.cloudflare.com
A2803:f800:50::6ca2:c1ae ๐Ÿ‡จ๐Ÿ‡ท Cloudflare
PTRhal.ns.cloudflare.com
A2a06:98c1:50::ac40:21ae ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRhal.ns.cloudflare.com
A108.162.193.174๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRhal.ns.cloudflare.com
A172.64.33.174๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRhal.ns.cloudflare.com
A173.245.59.174๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRhal.ns.cloudflare.com
NSingrid.ns.cloudflare.com
A2606:4700:50::adf5:3aa5 ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRingrid.ns.cloudflare.com
A2803:f800:50::6ca2:c0a5 ๐Ÿ‡จ๐Ÿ‡ท Cloudflare
PTRingrid.ns.cloudflare.com
A2a06:98c1:50::ac40:20a5 ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRingrid.ns.cloudflare.com
A108.162.192.165๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRingrid.ns.cloudflare.com
A172.64.32.165๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRingrid.ns.cloudflare.com
A173.245.58.165๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRingrid.ns.cloudflare.com
A178.128.137.126๐Ÿ‡ณ๐Ÿ‡ฑ DigitalOcean

group

NSv0n0.nic.group
NSv0n1.nic.group
NSv0n2.nic.group
NSv0n3.nic.group
NSv2n0.nic.group
NSv2n1.nic.group

Starts with same word

Starts similarily

AI analysis

malicious.group points to an IP address: 178.128.137.126.

other host names include mail.jodiecook.com, coles.codes, upfront.no, karingarcia.com and afripreneurial.com; they share IP numbers with malicious.group.

Two name servers hal.ns.cloudflare.com and ingrid.ns.cloudflare.com handle the delegation for malicious.group.

malicious.group shares the same name server setup as other domains, for instance surge.tools, globalsugarart.com, bolt.tw, virala.in and st-by.com.

malicious.group at least partially shares name servers with other domains, for instance florisrobbemont.nl, bymybay.com, compassioninternational.com, haftaninfirsaturunu.com and tendancemag.com.

These name servers are commonly used alongside alla.ns.cloudflare.com.

Six IP addresses per host:

hal.ns.cloudflare.com points to 2606:4700:58::adf5:3bae, 2803:f800:50::6ca2:c1ae, 2a06:98c1:50::ac40:21ae, 108.162.193.174, 172.64.33.174 and 173.245.59.174; ingrid.ns.cloudflare.com points to 2606:4700:50::adf5:3aa5, 2803:f800:50::6ca2:c0a5, 2a06:98c1:50::ac40:20a5, 108.162.192.165, 172.64.32.165 and 173.245.58.165

malicious.group is handled by two mail servers: mail.protonmail.ch and mailsec.protonmail.ch.

malicious.group uses the same mail server setup as other domains, for instance dtmh.dk, sourcemonkey.com, areskicapital.com, cheapnews.eu and vulkancasino.ua.

malicious.group shares at least partially some mail servers with other domains, for instance dynsec.org, atxsec.com, jandillenberger.com, mgoldschmidt.de and icob.org.

Host names with three IP numbers:

mail.protonmail.ch points to: 176.119.200.128, 185.70.42.128 and 185.205.70.128.

mailsec.protonmail.ch points to: 176.119.200.129, 185.70.42.129 and 185.205.70.129.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

WrQgMJA CF johedugfp 2025-10-18