rootkit.cc - dns.ninja

rootkit.cc

DNSSECโš ๏ธ Not signed
NSdns7.register.com โญ
A162.159.27.248Cloudflare162.159.27.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
NSdns8.register.com
A162.159.26.197Cloudflare162.159.26.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
SOAdns7.register.comroot@register.com serial=200306134

cc

DNSSEC๐Ÿ”’ Signed (DS record present)
NSac1.nstld.com โญ
NSac2.nstld.com
NSac3.nstld.com
NSac4.nstld.com
SOAac1.nstld.cominfo@verisign-grs.com serial=1780971209

Same first word

Similar names

DNS History

3 records (2 active, 1 former)

20192020202120222023202420252026NSdns7.register.comdns8.register.comMXp.webcom.ctmail.com
โ—NSdns7.register.com2018-10-09 โ†’ 2026-06-09 ยท 2 obs
โ— 2018-10-09 04:55:00
โ— 2026-06-09 02:48:26
โ—NSdns8.register.com2018-10-09 โ†’ 2026-06-09 ยท 2 obs
โ— 2018-10-09 04:55:00
โ— 2026-06-09 02:48:26
โ—‹MXp.webcom.ctmail.com2018-10-09 โ†’ 2018-10-09 ยท 3 obs
โ— 2018-10-09 04:55:00
โ—‹ 2026-04-09 14:48:36
โ—‹ 2026-06-09 02:48:26

๐Ÿ” DNS Trace

๐Ÿ“‹ Delegation Chain

ZoneNameserversGlue
ccac1.nstld.com, ac2.nstld.com, ac3.nstld.com, ac4.nstld.com8 records
rootkit.ccdns7.register.com, dns8.register.com-

โœ… Authoritative Response

Server:162.159.27.248

NS records: dns7.register.com, dns8.register.com

๐Ÿ”’ DNSSEC Status

โš ๏ธ Insecure (no DNSSEC)

No DS record for rootkit.cc (unsigned zone)

โฑ๏ธ Timing

Total: 430ms | Queries: -

๐Ÿ“„ Records

TypeCountSample Data
NS2dns8.register.com, dns7.register.com
SOA1dns7.register.com root.register.com

๐Ÿ“Œ Glue Records Collected

Total: 8

Out-of-bailiwick: 8 (ac1.nstld.com, ac1.nstld.com, ac2.nstld.com...)

Analysis

Name Servers

rootkit.cc is served by two delegated name servers, dns7.register.com and dns8.register.com.

rootkit.cc uses the same name servers as several other domains โ€” among them latinbeats.com, email2u.net, abigail.alonso.name and two more.

There is at least partial name server overlap between rootkit.cc and other domains โ€” casinohostess.com, testregcom.justforme12nonsense.name, webairline.com and two more among them.

dns7.register.com โ†’ 162.159.27.248 and dns8.register.com โ†’ 162.159.26.197: one IP number per host name.