CF1758869476430-tsm20250925114901

NSLIST.NET - attacker.host

Search for IP or hostnames:

attacker.host checked at 2025-09-26T06:51:16.310Z 1794ms 90/90/90 100% R:7

attacker.host

NSdns1.registrar-servers.com
A2610:a1:1024::200 🇺🇸 Neustar
PTRdns1.namecheaphosting.com
PTRdns1.registrar-servers.com
A156.154.132.200🇺🇸 Neustar
PTRdns1.namecheaphosting.com
PTRdns1.registrar-servers.com
NSdns2.registrar-servers.com
A2610:a1:1025::200 🇺🇸 Neustar
PTRdns2.namecheaphosting.com
PTRdns2.registrar-servers.com
A156.154.133.200🇺🇸 Neustar
PTRdns2.namecheaphosting.com
PTRdns2.registrar-servers.com
MXeforward1.registrar-servers.com
A162.255.118.51🇺🇸 Namecheap
PTReforward1.registrar-servers.com
PTReforward3.registrar-servers.com
MXeforward2.registrar-servers.com
A162.255.118.52🇺🇸 Namecheap
PTReforward2.registrar-servers.com
MXeforward3.registrar-servers.com
A162.255.118.51🇺🇸 Namecheap
PTReforward1.registrar-servers.com
PTReforward3.registrar-servers.com
MXeforward4.registrar-servers.com
A162.255.118.52🇺🇸 Namecheap
PTReforward2.registrar-servers.com
MXeforward5.registrar-servers.com
A162.255.118.51🇺🇸 Namecheap
PTReforward1.registrar-servers.com
PTReforward3.registrar-servers.com

host

NSa.nic.host
NSb.nic.host
NSe.nic.host
NSf.nic.host

Starts with same word

Starts similarily

AI analysis

Two name servers dns1.registrar-servers.com and dns2.registrar-servers.com handle delegation for attacker.host.

attacker.host uses the same name server setup as other domains, for example dbuilt.com, hollywoodearth.com, fuckable.net, chengduxx.com and carrotseo.com.

attacker.host partially shares name servers with other domains; examples include sofiecat.com, hotforexoffers.com, kovak.net, eartx.com and kathleenhenderson.com.

These name servers are commonly used with dns3.registrar-servers.com, dns4.registrar-servers.com and dns5.registrar-servers.com.

Host names with two IP numbers:

dns1.registrar-servers.com points to: 2610:a1:1024::200 and 156.154.132.200

dns2.registrar-servers.com points to: 2610:a1:1025::200 and 156.154.133.200

Five mail servers handle attacker.host: eforward1.registrar-servers.com, eforward2.registrar-servers.com, eforward3.registrar-servers.com, eforward4.registrar-servers.com and eforward5.registrar-servers.com.

attacker.host shares some mail servers with other domains, at least partially, such as logicart.biz, acfi.info, frencharrow.com, veonaskinbeauty.com and livehklotto.store.

These mail servers are often used together with eforward6.registrar-servers.com and eforward7.registrar-servers.com.

Hostnames with a single IP:

eforward1.registrar-servers.com points to: 162.255.118.51

eforward2.registrar-servers.com points to: 162.255.118.52

eforward3.registrar-servers.com points to: 162.255.118.51

eforward4.registrar-servers.com points to: 162.255.118.52

eforward5.registrar-servers.com points to: 162.255.118.51

Hostnames pointing to 162.255.118.51: eforward1.registrar-servers.com, eforward3.registrar-servers.com and eforward5.registrar-servers.com

Hostnames pointing to 162.255.118.52: eforward2.registrar-servers.com and eforward4.registrar-servers.com

Common pattern: three hostnames point to 162.255.118.51 and two point to 162.255.118.52.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

SEIhyKm CF johedugfp 2025-09-26