botnet.rip - dns.ninja

botnet.rip

DNSSEC⚠️ Not signed
A216.198.79.1🇺🇸 Amazon216.198.79.0/24 EC2 Prefix
NSmaisie.ns.cloudflare.com
A2606:4700:50::a29f:2659🇺🇸 Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmaisie.ns.cloudflare.com
A2803:f800:50::6ca2:c259🇨🇷 Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRmaisie.ns.cloudflare.com
A2a06:98c1:50::ac40:2259🇺🇸 Cloudflare2a06:98c1:50::/45
PTRmaisie.ns.cloudflare.com
A108.162.194.89🇺🇸 Cloudflare108.162.194.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmaisie.ns.cloudflare.com
A162.159.38.89Cloudflare162.159.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmaisie.ns.cloudflare.com
A172.64.34.89🇺🇸 Cloudflare172.64.34.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRmaisie.ns.cloudflare.com
NSroman.ns.cloudflare.com
A2606:4700:58::a29f:2c67🇺🇸 Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRroman.ns.cloudflare.com
A2803:f800:50::6ca2:c367🇨🇷 Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRroman.ns.cloudflare.com
A2a06:98c1:50::ac40:2367🇺🇸 Cloudflare2a06:98c1:50::/45
PTRroman.ns.cloudflare.com
A108.162.195.103🇺🇸 Cloudflare108.162.195.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRroman.ns.cloudflare.com
A162.159.44.103Cloudflare162.159.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRroman.ns.cloudflare.com
A172.64.35.103🇺🇸 Cloudflare172.64.35.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRroman.ns.cloudflare.com
SOAmaisie.ns.cloudflare.comdns@cloudflare.com serial=2406717364

rip

DNSSEC🔒 Signed (DS record present)
NSv0n0.nic.rip
NSv0n1.nic.rip
NSv0n2.nic.rip
NSv0n3.nic.rip
NSv2n0.nic.rip
NSv2n1.nic.rip
SOAv0n0.nic.riphostmaster@donuts.email serial=1782539448
⚠️ On DNS blocklist: tif

Same first word

Similar names

DNS History

3 records (3 active, 0 former)

NSmaisie.ns.cloudflare.comroman.ns.cloudflare.comA216.198.79.1
NSmaisie.ns.cloudflare.com2026-03-28 → 2026-06-27 · 2 obs
● 2026-03-28 15:41:20
● 2026-06-27 06:01:26
NSroman.ns.cloudflare.com2026-03-28 → 2026-06-27 · 2 obs
● 2026-03-28 15:41:20
● 2026-06-27 06:01:26
A216.198.79.12026-03-28 → 2026-06-27 · 2 obs
● 2026-03-28 15:41:20
● 2026-06-27 06:01:26

🔍 DNS Trace

📋 Delegation Chain

ZoneNameserversGlue
ripv0n0.nic.rip, v0n1.nic.rip, v0n2.nic.rip, v0n3.nic.rip...12 records
botnet.riproman.ns.cloudflare.com, maisie.ns.cloudflare.com-

✅ Authoritative Response

Server:108.162.194.89

NS records: roman.ns.cloudflare.com, maisie.ns.cloudflare.com

🔒 DNSSEC Status

❌ Bogus (DNSSEC validation failed)

Validation error at rip: Error: DNS query timeout: 65.22.32.22 for DNSKEY rip

⏱️ Timing

Total: 3458ms | Queries: -

📄 Records

TypeCountSample Data
A1216.198.79.1
NS2maisie.ns.cloudflare.com, roman.ns.cloudflare.com
SOA1maisie.ns.cloudflare.com dns.cloudflare.

📌 Glue Records Collected

Total: 12

In-bailiwick: 12 (v0n0.nic.rip, v0n1.nic.rip, v0n2.nic.rip...)

Analysis

IP Addresses

botnet.rip has exactly one IP address — 216.198.79.1.

www.codextechinnovations.com, quotespilot.com, cambrian.ventures plus two other host names have IP numbers in common with botnet.rip.

Name Servers

botnet.rip uses two name servers for its delegation: maisie.ns.cloudflare.com and roman.ns.cloudflare.com.

The name server configuration of botnet.rip is shared with other domains, for instance tool-it.com.au, pcakaimur.org, longlam.com and two others.

At least some of botnet.rip's name servers are shared with other domains, for example parkswilsonlaw.com, 636c6f7564666c617265.org, mega888malaysia.net and two more.

These name servers tend to be deployed in combination with the name servers jill.ns.cloudflare.com and molly.ns.cloudflare.com.

Hosts with 6 IP addresses each:

Hostname maisie.ns.cloudflare.com directs to 108.162.194.89, 162.159.38.89 and 172.64.34.89 along with 3 other IP addresses.

Hostname roman.ns.cloudflare.com directs to 108.162.195.103, 162.159.44.103 and 172.64.35.103 along with 3 other IP addresses.