rootkit.finance - dns.ninja

rootkit.finance

DNSSECโš ๏ธ Not signed
A157.90.33.73๐Ÿ‡ฉ๐Ÿ‡ช Hetzner157.90.0.0/16 HETZNER-DC
PTRold-psh4.1push.io
A157.90.33.74๐Ÿ‡ฉ๐Ÿ‡ช Hetzner157.90.0.0/16 HETZNER-DC
NSns1.park-my-domain.net โญ
A46.224.16.22๐Ÿ‡ฎ๐Ÿ‡ท Hetzner46.224.0.0/15 HETZNER-DC
PTRns1.park-my-domain.net
NSns2.park-my-domain.net
A65.108.243.18๐Ÿ‡ซ๐Ÿ‡ฎ Hetzner65.108.0.0/16 HETZNER-DC
PTRstatic.18.243.108.65.clients.your-server.de
SOAns1.park-my-domain.nethostmaster@rootkit.finance 2026-05-29 #5

finance

DNSSEC๐Ÿ”’ Signed (DS record present)
NSv0n0.nic.finance โญ
NSv0n1.nic.finance
NSv0n2.nic.finance
NSv0n3.nic.finance
NSv2n0.nic.finance
NSv2n1.nic.finance
SOAv0n0.nic.financehostmaster@donuts.email serial=1780960579

Same first word

Similar names

DNS History

22 records (4 active, 18 former)

NSns1.park-my-domain.netns2.park-my-domain.net5579.ns1.abovedomains.com5579.ns2.abovedomains.comns1.abovedomains.comns1.dns-redirect.comns2.abovedomains.comns2.dns-redirect.comMXpark-mx.above.comA157.90.33.73157.90.33.74103.224.212.200195.201.128.1792600:9000:a612:55d9:1b82:e963:5969:d2c72a01:4f8:1c1e:d6f1::12a01:4ff:1f0:dd50::12a01:4ff:f0:5f41::146.62.237.1385.161.230.875.161.47.865.78.156.5976.223.91.20
โ—‹NS5579.ns1.abovedomains.com2026-03-31 โ†’ 2026-03-31 ยท 3 obs
โ—‹ 2026-03-18 06:45:52
โ— 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹NS5579.ns2.abovedomains.com2026-03-31 โ†’ 2026-03-31 ยท 3 obs
โ—‹ 2026-03-18 06:45:52
โ— 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹NSns1.abovedomains.com2026-03-31 โ†’ 2026-03-31 ยท 3 obs
โ—‹ 2026-03-18 06:45:52
โ— 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹NSns1.dns-redirect.com2026-02-20 โ†’ 2026-03-18 ยท 4 obs
โ— 2026-02-20 01:30:14
โ— 2026-03-18 06:45:52
โ—‹ 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—NSns1.park-my-domain.net2026-06-09 โ†’ 2026-06-09 ยท 2 obs
โ—‹ 2026-03-31 02:29:52
โ— 2026-06-09 00:12:30
โ—‹NSns2.abovedomains.com2026-03-31 โ†’ 2026-03-31 ยท 3 obs
โ—‹ 2026-03-18 06:45:52
โ— 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹NSns2.dns-redirect.com2026-02-20 โ†’ 2026-03-18 ยท 4 obs
โ— 2026-02-20 01:30:14
โ— 2026-03-18 06:45:52
โ—‹ 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—NSns2.park-my-domain.net2026-06-09 โ†’ 2026-06-09 ยท 2 obs
โ—‹ 2026-03-31 02:29:52
โ— 2026-06-09 00:12:30
โ—‹MXpark-mx.above.com2026-03-31 โ†’ 2026-03-31 ยท 2 obs
โ— 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹A103.224.212.2002026-03-31 โ†’ 2026-03-31 ยท 3 obs
โ—‹ 2026-03-18 06:45:52
โ— 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—A157.90.33.732026-06-09 โ†’ 2026-06-09 ยท 2 obs
โ—‹ 2026-03-31 02:29:52
โ— 2026-06-09 00:12:30
โ—A157.90.33.742026-06-09 โ†’ 2026-06-09 ยท 2 obs
โ—‹ 2026-03-31 02:29:52
โ— 2026-06-09 00:12:30
โ—‹A195.201.128.1792026-02-20 โ†’ 2026-03-18 ยท 4 obs
โ— 2026-02-20 01:30:14
โ— 2026-03-18 06:45:52
โ—‹ 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹A2600:9000:a612:55d9:1b82:e963:5969:d2c72026-02-20 โ†’ 2026-03-18 ยท 4 obs
โ— 2026-02-20 01:30:14
โ— 2026-03-18 06:45:52
โ—‹ 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹A2a01:4f8:1c1e:d6f1::12026-02-20 โ†’ 2026-03-18 ยท 4 obs
โ— 2026-02-20 01:30:14
โ— 2026-03-18 06:45:52
โ—‹ 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹A2a01:4ff:1f0:dd50::12026-02-20 โ†’ 2026-03-18 ยท 4 obs
โ— 2026-02-20 01:30:14
โ— 2026-03-18 06:45:52
โ—‹ 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹A2a01:4ff:f0:5f41::12026-02-20 โ†’ 2026-03-18 ยท 4 obs
โ— 2026-02-20 01:30:14
โ— 2026-03-18 06:45:52
โ—‹ 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹A46.62.237.1382026-02-20 โ†’ 2026-03-18 ยท 4 obs
โ— 2026-02-20 01:30:14
โ— 2026-03-18 06:45:52
โ—‹ 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹A5.161.230.872026-02-20 โ†’ 2026-03-18 ยท 4 obs
โ— 2026-02-20 01:30:14
โ— 2026-03-18 06:45:52
โ—‹ 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹A5.161.47.862026-02-20 โ†’ 2026-03-18 ยท 4 obs
โ— 2026-02-20 01:30:14
โ— 2026-03-18 06:45:52
โ—‹ 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹A5.78.156.592026-02-20 โ†’ 2026-03-18 ยท 4 obs
โ— 2026-02-20 01:30:14
โ— 2026-03-18 06:45:52
โ—‹ 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30
โ—‹A76.223.91.202026-02-20 โ†’ 2026-03-18 ยท 4 obs
โ— 2026-02-20 01:30:14
โ— 2026-03-18 06:45:52
โ—‹ 2026-03-31 02:29:52
โ—‹ 2026-06-09 00:12:30

๐Ÿ” DNS Trace

๐Ÿ“‹ Delegation Chain

ZoneNameserversGlue
financev0n0.nic.finance, v0n1.nic.finance, v0n2.nic.finance, v0n3.nic.finance...12 records
rootkit.financens1.park-my-domain.net, ns2.park-my-domain.net-

โœ… Authoritative Response

Server:65.108.243.18

NS records: ns1.park-my-domain.net, ns2.park-my-domain.net

๐Ÿ”’ DNSSEC Status

โš ๏ธ Insecure (no DNSSEC)

No DS record for rootkit.finance (unsigned zone)

โฑ๏ธ Timing

Total: 1102ms | Queries: -

๐Ÿ“„ Records

TypeCountSample Data
A2157.90.33.74, 157.90.33.73
NS2ns2.park-my-domain.net, ns1.park-my-domain.net
SOA1ns1.park-my-domain.net hostmaster.rootki

๐Ÿ“Œ Glue Records Collected

Total: 12

In-bailiwick: 12 (v0n0.nic.finance, v0n0.nic.finance, v0n1.nic.finance...)

Analysis

IP Addresses

rootkit.finance points to two IP numbers: 157.90.33.73 and 157.90.33.74.

macedonia-young-(0x77686f7265)s-in-negotino.aijournal.top, k-zann.123rutor.su, b-cjw.123rutor.su plus two other host names have IP numbers in common with rootkit.finance.

Name Servers

rootkit.finance is delegated to two name servers: ns1.park-my-domain.net and ns2.park-my-domain.net.

The name server configuration of rootkit.finance is shared with other domains, for instance absolutesign.us, angelboot.com, sheam.mom and two others.

rootkit.finance shares at least some of its name servers with other domains, such as festup.es.

ns1.park-my-domain.net resolves to 46.224.16.22. ns2.park-my-domain.net resolves to 65.108.243.18. Both host names point to a single IP number.