CF1760867344950-tsm20251017082432

NSLIST.NET - attacker.so

Search for IP or hostnames:

attacker.so checked at 2025-10-19T09:49:04.937Z 353ms 68/68/68 100% R:12

attacker.so

MXpark-mx.above.com
A103.224.212.34🇦🇺 TRELLIAN-AS-AP
PTRpark-mx.above.com
NSns1.abovedomains.com
A103.224.182.9🇦🇺 TRELLIAN-AS-AP
PTRns1.above.com
A103.224.212.9🇦🇺 TRELLIAN-AS-AP
PTRns1.above.com
NSns2.abovedomains.com
A103.224.182.10🇦🇺 TRELLIAN-AS-AP
PTRns2.above.com
A103.224.212.10🇦🇺 TRELLIAN-AS-AP
PTRns2.above.com
A103.224.182.210🇦🇺 TRELLIAN-AS-AP
PTRlb-182-210.above.com

so

NSd.nic.so
NSe.nic.so

Starts with same word

Starts similarily

AI analysis

attacker.so points to a single IP number: 103.224.182.210.

Other host names, for instance mail.ghettocraft.ru, uret.online, ekohidrotechnika.com, www.urzhum.japrodam.com and dogfart.network share IP numbers with attacker.so.

attacker.so is delegated to two name servers: ns1.abovedomains.com and ns2.abovedomains.com.

attacker.so uses the same name server setup as other domains, for instance email2.goyeah.com, worldfree4u.blog, trueba.es, ubf.in and adsl201.buffnet.net.

Host names with two IP numbers:

The host ns1.abovedomains.com points to 103.224.182.9 and 103.224.212.9.

The host ns2.abovedomains.com points to 103.224.182.10 and 103.224.212.10.

The mail server for attacker.so is park-mx.above.com.

attacker.so shares the same mail server setup as other domains, including www.goles.com, me.pronhub.me, ns2.efactura.net, jimsseptic.net and tudinero.es.

Host name park-mx.above.com resolves to IP 103.224.212.34.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

jJkSYoP CF johedugfp 2025-10-19