maliciouscode.net - dns.ninja

maliciouscode.net

DNSSECโš ๏ธ Not signed
A2606:4700:3031::ac43:d0ad๐Ÿ‡บ๐Ÿ‡ธ Cloudflare2606:4700:3031::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US โœ“ In HTTPS hints
A2606:4700:3036::6815:55af๐Ÿ‡บ๐Ÿ‡ธ Cloudflare2606:4700:3036::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US โœ“ In HTTPS hints
A104.21.85.175Cloudflare104.21.80.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US โœ“ In HTTPS hints
A172.67.208.173๐Ÿ‡บ๐Ÿ‡ธ Cloudflare172.67.208.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US โœ“ In HTTPS hints
NSmona.ns.cloudflare.com โญ
A2606:4700:50::adf5:3ace๐Ÿ‡บ๐Ÿ‡ธ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmona.ns.cloudflare.com
A2803:f800:50::6ca2:c0ce๐Ÿ‡จ๐Ÿ‡ท Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRmona.ns.cloudflare.com
A2a06:98c1:50::ac40:20ce๐Ÿ‡บ๐Ÿ‡ธ Cloudflare2a06:98c1:50::/45
PTRmona.ns.cloudflare.com
A108.162.192.206๐Ÿ‡บ๐Ÿ‡ธ Cloudflare108.162.192.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmona.ns.cloudflare.com
A172.64.32.206๐Ÿ‡บ๐Ÿ‡ธ Cloudflare172.64.32.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmona.ns.cloudflare.com
A173.245.58.206๐Ÿ‡บ๐Ÿ‡ธ Cloudflare173.245.58.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmona.ns.cloudflare.com
NStoby.ns.cloudflare.com
A2606:4700:58::adf5:3bef๐Ÿ‡บ๐Ÿ‡ธ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRtoby.ns.cloudflare.com
A2803:f800:50::6ca2:c1ef๐Ÿ‡จ๐Ÿ‡ท Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRtoby.ns.cloudflare.com
A2a06:98c1:50::ac40:21ef๐Ÿ‡บ๐Ÿ‡ธ Cloudflare2a06:98c1:50::/45
PTRtoby.ns.cloudflare.com
A108.162.193.239๐Ÿ‡บ๐Ÿ‡ธ Cloudflare108.162.193.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRtoby.ns.cloudflare.com
A172.64.33.239๐Ÿ‡บ๐Ÿ‡ธ Cloudflare172.64.33.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRtoby.ns.cloudflare.com
A173.245.59.239๐Ÿ‡บ๐Ÿ‡ธ Cloudflare173.245.59.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRtoby.ns.cloudflare.com
MXaspmx.l.google.com โญ
A2607:f8b0:4004:c27::1b๐Ÿ‡บ๐Ÿ‡ธ Google2607:f8b0:4004::/48
PTRyuiadsk-in-f27.1e100.net
A142.251.163.26๐Ÿ‡บ๐Ÿ‡ธ Google142.251.163.0/24
PTRwv-in-f26.1e100.net
MXalt1.aspmx.l.google.com(20)
A2800:3f0:4003:c0f::1a๐Ÿ‡จ๐Ÿ‡ฑ Google2800:3f0:4003::/48
A108.177.123.26๐Ÿ‡บ๐Ÿ‡ธ Google108.177.123.0/24
PTRlcscld-in-f26.1e100.net
MXalt2.aspmx.l.google.com(20)
A2a00:1450:400b:c02::1a๐Ÿ‡ฎ๐Ÿ‡ช Google2a00:1450:400b::/48
PTRdj-in-f26.1e100.net
A172.253.116.26๐Ÿ‡บ๐Ÿ‡ธ Google172.253.116.0/24
PTRdj-in-f26.1e100.net
MXaspmx2.googlemail.com(30)
A2800:3f0:4003:c0f::1b๐Ÿ‡จ๐Ÿ‡ฑ Google2800:3f0:4003::/48
A108.177.123.27๐Ÿ‡บ๐Ÿ‡ธ Google108.177.123.0/24
PTRlcscld-in-f27.1e100.net
MXaspmx3.googlemail.com(30)
A2a00:1450:400b:c02::1b๐Ÿ‡ฎ๐Ÿ‡ช Google2a00:1450:400b::/48
PTRdj-in-f27.1e100.net
A172.253.116.26๐Ÿ‡บ๐Ÿ‡ธ Google172.253.116.0/24
PTRdj-in-f26.1e100.net
MXaspmx4.googlemail.com(30)
A2a00:1450:4009:c0f::1b๐Ÿ‡ฌ๐Ÿ‡ง Google2a00:1450:4009::/48
PTRyulhrs-in-f27.1e100.net
A192.178.223.26๐Ÿ‡บ๐Ÿ‡ธ Google192.178.223.0/24
PTRyulhrs-in-f26.1e100.net
MXaspmx5.googlemail.com(30)
A2a00:1450:400c:c23::1a๐Ÿ‡ง๐Ÿ‡ช Google2a00:1450:400c::/48
PTRyubrupd-in-f26.1e100.net
A172.253.157.26๐Ÿ‡บ๐Ÿ‡ธ Google172.253.0.0/16
PTRyubrupd-in-f26.1e100.net
HTTPSHTTP/3, HTTP/2 โœ“ hints match
IPv4 hints104.21.85.175, 172.67.208.173
IPv6 hints2606:4700:3031::ac43:d0ad, 2606:4700:3036::6815:55af
ECHX25519, HKDF-SHA256 + AES-128-GCM draft, id=154, name=cloudflare-ech.com
SOAmona.ns.cloudflare.comdns@cloudflare.com serial=2405019973

net

Same first word

DNS History

23 records (13 active, 10 former)

20162017201820192020202120222023202420252026NSmona.ns.cloudflare.comtoby.ns.cloudflare.comns1.dreamhost.comns2.dreamhost.comns3.dreamhost.comMXalt1.aspmx.l.google.comalt2.aspmx.l.google.comaspmx.l.google.comaspmx2.googlemail.comaspmx3.googlemail.comaspmx4.googlemail.comaspmx5.googlemail.comA104.21.85.175172.67.208.1732606:4700:3031::ac43:d0ad2606:4700:3036::6815:55af188.114.96.0188.114.97.02606:4700:3030::6815:55af2606:4700:3033::ac43:d0ad2a06:98c1:3120::2a06:98c1:3121::66.240.204.223
โ—NSmona.ns.cloudflare.com2026-03-29 โ†’ 2026-06-28 ยท 3 obs
โ—‹ 2020-01-10 04:44:00
โ— 2026-03-29 05:35:58
โ— 2026-06-28 08:08:18
โ—‹NSns1.dreamhost.com2015-06-10 โ†’ 2020-01-10 ยท 4 obs
โ— 2015-06-10 02:18:26
โ— 2020-01-10 04:44:00
โ—‹ 2026-03-29 05:35:58
โ—‹ 2026-06-28 08:08:18
โ—‹NSns2.dreamhost.com2015-06-10 โ†’ 2020-01-10 ยท 4 obs
โ— 2015-06-10 02:18:26
โ— 2020-01-10 04:44:00
โ—‹ 2026-03-29 05:35:58
โ—‹ 2026-06-28 08:08:18
โ—‹NSns3.dreamhost.com2015-06-10 โ†’ 2020-01-10 ยท 4 obs
โ— 2015-06-10 02:18:26
โ— 2020-01-10 04:44:00
โ—‹ 2026-03-29 05:35:58
โ—‹ 2026-06-28 08:08:18
โ—NStoby.ns.cloudflare.com2026-03-29 โ†’ 2026-06-28 ยท 3 obs
โ—‹ 2020-01-10 04:44:00
โ— 2026-03-29 05:35:58
โ— 2026-06-28 08:08:18
โ—MXalt1.aspmx.l.google.com2015-06-10 โ†’ 2026-06-28 ยท 2 obs
โ— 2015-06-10 02:18:26
โ— 2026-06-28 08:08:18
โ—MXalt2.aspmx.l.google.com2015-06-10 โ†’ 2026-06-28 ยท 2 obs
โ— 2015-06-10 02:18:26
โ— 2026-06-28 08:08:18
โ—MXaspmx.l.google.com2015-06-10 โ†’ 2026-06-28 ยท 2 obs
โ— 2015-06-10 02:18:26
โ— 2026-06-28 08:08:18
โ—MXaspmx2.googlemail.com2015-06-10 โ†’ 2026-06-28 ยท 2 obs
โ— 2015-06-10 02:18:26
โ— 2026-06-28 08:08:18
โ—MXaspmx3.googlemail.com2015-06-10 โ†’ 2026-06-28 ยท 2 obs
โ— 2015-06-10 02:18:26
โ— 2026-06-28 08:08:18
โ—MXaspmx4.googlemail.com2015-06-10 โ†’ 2026-06-28 ยท 2 obs
โ— 2015-06-10 02:18:26
โ— 2026-06-28 08:08:18
โ—MXaspmx5.googlemail.com2015-06-10 โ†’ 2026-06-28 ยท 2 obs
โ— 2015-06-10 02:18:26
โ— 2026-06-28 08:08:18
โ—A104.21.85.1752026-04-24 โ†’ 2026-06-28 ยท 6 obs
โ—‹ 2026-03-29 05:35:58
โ— 2026-04-24 10:42:24
โ— 2026-06-12 18:59:12
โ—‹ 2026-06-16 11:52:26
โ— 2026-06-28 07:09:32
โ— 2026-06-28 08:08:18
โ—A172.67.208.1732026-04-24 โ†’ 2026-06-28 ยท 6 obs
โ—‹ 2026-03-29 05:35:58
โ— 2026-04-24 10:42:24
โ— 2026-06-12 18:59:12
โ—‹ 2026-06-16 11:52:26
โ— 2026-06-28 07:09:32
โ— 2026-06-28 08:08:18
โ—‹A188.114.96.02026-03-29 โ†’ 2026-06-16 ยท 7 obs
โ—‹ 2020-01-10 04:44:00
โ— 2026-03-29 05:35:58
โ—‹ 2026-04-24 10:42:24
โ—‹ 2026-06-12 18:59:12
โ— 2026-06-16 11:52:26
โ—‹ 2026-06-28 07:09:32
โ—‹ 2026-06-28 08:08:18
โ—‹A188.114.97.02026-03-29 โ†’ 2026-06-16 ยท 7 obs
โ—‹ 2020-01-10 04:44:00
โ— 2026-03-29 05:35:58
โ—‹ 2026-04-24 10:42:24
โ—‹ 2026-06-12 18:59:12
โ— 2026-06-16 11:52:26
โ—‹ 2026-06-28 07:09:32
โ—‹ 2026-06-28 08:08:18
โ—‹A2606:4700:3030::6815:55af2026-04-24 โ†’ 2026-06-12 ยท 5 obs
โ—‹ 2026-03-29 05:35:58
โ— 2026-04-24 10:42:24
โ— 2026-06-12 18:59:12
โ—‹ 2026-06-16 11:52:26
โ—‹ 2026-06-28 08:08:18
โ—A2606:4700:3031::ac43:d0ad2026-06-28 โ†’ 2026-06-28 ยท 3 obs
โ—‹ 2026-06-16 11:52:26
โ— 2026-06-28 07:09:32
โ— 2026-06-28 08:08:18
โ—‹A2606:4700:3033::ac43:d0ad2026-04-24 โ†’ 2026-06-12 ยท 5 obs
โ—‹ 2026-03-29 05:35:58
โ— 2026-04-24 10:42:24
โ— 2026-06-12 18:59:12
โ—‹ 2026-06-16 11:52:26
โ—‹ 2026-06-28 08:08:18
โ—A2606:4700:3036::6815:55af2026-06-28 โ†’ 2026-06-28 ยท 3 obs
โ—‹ 2026-06-16 11:52:26
โ— 2026-06-28 07:09:32
โ— 2026-06-28 08:08:18
โ—‹A2a06:98c1:3120::2026-03-29 โ†’ 2026-06-16 ยท 7 obs
โ—‹ 2020-01-10 04:44:00
โ— 2026-03-29 05:35:58
โ—‹ 2026-04-24 10:42:24
โ—‹ 2026-06-12 18:59:12
โ— 2026-06-16 11:52:26
โ—‹ 2026-06-28 07:09:32
โ—‹ 2026-06-28 08:08:18
โ—‹A2a06:98c1:3121::2026-03-29 โ†’ 2026-06-16 ยท 7 obs
โ—‹ 2020-01-10 04:44:00
โ— 2026-03-29 05:35:58
โ—‹ 2026-04-24 10:42:24
โ—‹ 2026-06-12 18:59:12
โ— 2026-06-16 11:52:26
โ—‹ 2026-06-28 07:09:32
โ—‹ 2026-06-28 08:08:18
โ—‹A66.240.204.2232015-06-10 โ†’ 2020-01-10 ยท 4 obs
โ— 2015-06-10 02:18:26
โ— 2020-01-10 04:44:00
โ—‹ 2026-03-29 05:35:58
โ—‹ 2026-06-28 08:08:18

๐Ÿ” DNS Trace

๐Ÿ“‹ Delegation Chain

ZoneNameserversGlue
netc.gtld-servers.net, b.gtld-servers.net, l.gtld-servers.net, j.gtld-servers.net...-
maliciouscode.nettoby.ns.cloudflare.com, mona.ns.cloudflare.com-

โœ… Authoritative Response

Server:173.245.59.239

NS records: toby.ns.cloudflare.com, mona.ns.cloudflare.com

๐Ÿ”’ DNSSEC Status

โš ๏ธ Insecure (no DNSSEC)

No DS record for maliciouscode.net (unsigned zone)

โฑ๏ธ Timing

Total: 366ms | Queries: -

๐Ÿ“„ Records

TypeCountSample Data
A2172.67.208.173, 104.21.85.175
AAAA22606:4700:3031::ac43:d0ad, 2606:4700:3036::6815:55af
NS2mona.ns.cloudflare.com, toby.ns.cloudflare.com
MX7ASPMX.L.GOOGLE.COM (pri: 10), ALT1.ASPMX.L.GOOGLE.COM (pri: 20)...
HTTPS1{"priority":1,"target":".","alpn":["h3",
SOA1mona.ns.cloudflare.com dns.cloudflare.co

Analysis

IP Addresses

maliciouscode.net resolves to four IP addresses: 104.21.85.175, 172.67.208.173, 2606:4700:3031::ac43:d0ad and 2606:4700:3036::6815:55af.

Two other host names, along with glorianastore.blog, palfinger.lv and pcall.net, also share IP numbers with maliciouscode.net.

Name Servers

The NS records for maliciouscode.net delegate to mona.ns.cloudflare.com and toby.ns.cloudflare.com.

maliciouscode.net shares its NS records with other domains, for example aptgame.com, kin.today, drfereydooni.ir and two others.

maliciouscode.net has at least partial name server overlap with other domains, such as primeonenova2.pics, xn--jpqx4qfn0a405a.com, apvg.org and two others.

It is common to see these name servers used together with name servers ollie.ns.cloudflare.com and lia.ns.cloudflare.com.

DNS names with 6 IP addresses:

mona.ns.cloudflare.com maps to 108.162.192.206, 172.64.32.206, 173.245.58.206 and 3 additional IP addresses.

toby.ns.cloudflare.com maps to 108.162.193.239, 172.64.33.239, 173.245.59.239 and 3 additional IP addresses.

Mail Servers

Mail for maliciouscode.net is routed through 7 mail servers, including aspmx2.googlemail.com, aspmx3.googlemail.com, aspmx4.googlemail.com and 4 other.

There is at least a partial MX overlap between maliciouscode.net and other domains, including ns500731.ns500671.ns500671.ns500754.ns500704.ns500742.ns500705.ns500678.ns500705.ns500678.ns500649.tenderladiesbz.com, ns500759.ns500759.ns500759.ns500698.ns500736.ns500735.ns500698.ns500735.ns500576.ns500708.ns500576.ns500698.ns500619.ns500619.ns500576.trackreceptor.com, ns500754.ns500742.ns500742.ns500742.ns500742.ns500705.ns500688.ns500291.ns500678.lusty(0x736c7574)z.com and two others.

These mail servers tend to appear in combination with mail servers alt1.aspmx.l.google.com, aspmx.l.google.com, alt2.aspmx.l.google.com and 3 others.

Host names that have two IP addresses:

The A records for aspmx2.googlemail.com return 108.177.123.27 and 2800:3f0:4003:c0f::1b.

The A records for aspmx3.googlemail.com return 172.253.116.26 and 2a00:1450:400b:c02::1b.

The A records for aspmx4.googlemail.com return 192.178.223.26 and 2a00:1450:4009:c0f::1b.

The A records for aspmx5.googlemail.com return 172.253.157.26 and 2a00:1450:400c:c23::1a.

The A records for aspmx.l.google.com return 142.251.163.26 and 2607:f8b0:4004:c27::1b.

The A records for alt1.aspmx.l.google.com return 108.177.123.26 and 2800:3f0:4003:c0f::1a.

The A records for alt2.aspmx.l.google.com return 172.253.116.26 and 2a00:1450:400b:c02::1a.

aspmx3.googlemail.com and alt2.aspmx.l.google.com each have 172.253.116.26 IP addresses.