CF1759194072298-tsm20250929235914

NSLIST.NET - malicious.group

Search for IP or hostnames:

malicious.group checked at 2025-09-30T01:01:12.271Z 191ms 131/131/131 100% R:12

malicious.group

MXmail.protonmail.ch
A176.119.200.128🇨🇭 Proton AG
PTRmail.protonmail.ch
A185.70.42.128🇨🇭 Proton AG
PTRmail.protonmail.ch
A185.205.70.128🇫🇷 Proton AG
PTRmail.protonmail.ch
MXmailsec.protonmail.ch
A176.119.200.129🇨🇭 Proton AG
PTRmailsec.protonmail.ch
A185.70.42.129🇨🇭 Proton AG
PTRmailsec.protonmail.ch
A185.205.70.129🇫🇷 Proton AG
PTRmailsec.protonmail.ch
NShal.ns.cloudflare.com
A2606:4700:58::adf5:3bae 🇺🇸 Cloudflare
PTRhal.ns.cloudflare.com
A2803:f800:50::6ca2:c1ae 🇨🇷 Cloudflare
PTRhal.ns.cloudflare.com
A2a06:98c1:50::ac40:21ae 🇺🇸 Cloudflare
PTRhal.ns.cloudflare.com
A108.162.193.174🇺🇸 Cloudflare
PTRhal.ns.cloudflare.com
A172.64.33.174🇺🇸 Cloudflare
PTRhal.ns.cloudflare.com
A173.245.59.174🇺🇸 Cloudflare
PTRhal.ns.cloudflare.com
NSingrid.ns.cloudflare.com
A2606:4700:50::adf5:3aa5 🇺🇸 Cloudflare
PTRingrid.ns.cloudflare.com
A2803:f800:50::6ca2:c0a5 🇨🇷 Cloudflare
PTRingrid.ns.cloudflare.com
A2a06:98c1:50::ac40:20a5 🇺🇸 Cloudflare
PTRingrid.ns.cloudflare.com
A108.162.192.165🇺🇸 Cloudflare
PTRingrid.ns.cloudflare.com
A172.64.32.165🇺🇸 Cloudflare
PTRingrid.ns.cloudflare.com
A173.245.58.165🇺🇸 Cloudflare
PTRingrid.ns.cloudflare.com
A178.128.137.126🇳🇱 DigitalOcean

group

NSv0n0.nic.group
NSv0n1.nic.group
NSv0n2.nic.group
NSv0n3.nic.group
NSv2n0.nic.group
NSv2n1.nic.group

Starts with same word

Starts similarily

AI analysis

malicious.group points to a single IP number: 178.128.137.126.

other host names for instance mail.jodiecook.com, coles.codes, upfront.no, karingarcia.com and afripreneurial.com share IP numbers with malicious.group.

malicious.group is delegated to two name servers: hal.ns.cloudflare.com and ingrid.ns.cloudflare.com.

malicious.group shares the same name server setup as other domains, for example surge.tools, globalsugarart.com, bolt.tw, virala.in and st-by.com.

malicious.group at least partially shares name servers with other domains, for instance florisrobbemont.nl, bymybay.com, compassioninternational.com, haftaninfirsaturunu.com and tendancemag.com.

These name servers are commonly used with alla.ns.cloudflare.com, noel.ns.cloudflare.com and treasure.ns.cloudflare.com.

Host names with six IP numbers:

hal.ns.cloudflare.com points to: 2606:4700:58::adf5:3bae, 2803:f800:50::6ca2:c1ae, 2a06:98c1:50::ac40:21ae, 108.162.193.174, 172.64.33.174 and 173.245.59.174; ingrid.ns.cloudflare.com points to: 2606:4700:50::adf5:3aa5, 2803:f800:50::6ca2:c0a5, 2a06:98c1:50::ac40:20a5, 108.162.192.165, 172.64.32.165 and 173.245.58.165.

malicious.group is handled by two mail servers: mail.protonmail.ch and mailsec.protonmail.ch.

malicious.group shares the same mail server setup as other domains, for instance dtmh.dk, sourcemonkey.com, areskicapital.com, cheapnews.eu and vulkancasino.ua.

malicious.group shares mail servers with other domains at least partially, including dynsec.org, atxsec.com, mgoldschmidt.de, icob.org and batsnake.com.

Host names with three IP numbers:

mail.protonmail.ch points to: 176.119.200.128, 185.70.42.128 and 185.205.70.128.

mailsec.protonmail.ch points to: 176.119.200.129, 185.70.42.129 and 185.205.70.129.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

cRnrDOx CF johedugfp 2025-09-30