rootkit.ru - dns.ninja

rootkit.ru

DNSSECโš ๏ธ Not signed
NSns0.ixi.ru โญ โš ๏ธ Not in parent delegation
A95.143.183.42๐Ÿ‡ท๐Ÿ‡บ SELECTEL95.143.180.0/22 Selectel Route Object
NSns.ixi.ru โš ๏ธ Not in parent delegation
NSns1.ixi.ru โš ๏ธ Not in zone NS records
A85.195.105.238๐Ÿ‡ฉ๐Ÿ‡ช VELIANET-AS85.195.64.0/18 velia.net
NSns2.ixi.ru โš ๏ธ Not in zone NS records
A93.115.95.198๐Ÿ‡ฌ๐Ÿ‡ง VOXILITY93.115.92.0/22 Voxility SRL
MXflt0.md.ixi.ru โญ
A85.195.105.240๐Ÿ‡ฉ๐Ÿ‡ช VELIANET-AS85.195.64.0/18 velia.net
PTRflt0.md.ixi.ru
MXflt1.md.ixi.ru(20)
A95.143.183.43๐Ÿ‡ท๐Ÿ‡บ SELECTEL95.143.180.0/22 Selectel Route Object
PTRflt1.md.ixi.ru
SOAns.ixi.runoc@ixi.ru serial=2008048007

ru

DNSSEC๐Ÿ”’ Signed (DS record present)
NSa.dns.ripn.net โญ
NSb.dns.ripn.net
NSd.dns.ripn.net
NSe.dns.ripn.net
NSf.dns.ripn.net
SOAa.dns.ripn.nethostmaster@ripn.net serial=4069228

Same first word

Similar names

DNS History

10 records (6 active, 4 former)

20162017201820192020202120222023202420252026NSns.ixi.runs0.ixi.runs1.ixi.runs2.ixi.ruMXflt0.md.ixi.ruflt1.md.ixi.rurootkit.ru.s200a1.psmtp.comrootkit.ru.s200a2.psmtp.comrootkit.ru.s200b1.psmtp.comrootkit.ru.s200b2.psmtp.com
โ—NSns.ixi.ru2015-06-05 โ†’ 2026-06-12 ยท 2 obs
โ— 2015-06-05 01:39:30
โ— 2026-06-12 15:00:34
โ—NSns0.ixi.ru2026-03-21 โ†’ 2026-06-12 ยท 3 obs
โ—‹ 2015-06-05 01:39:30
โ— 2026-03-21 10:02:44
โ— 2026-06-12 15:00:34
โ—NSns1.ixi.ru2026-03-21 โ†’ 2026-06-12 ยท 3 obs
โ—‹ 2015-06-05 01:39:30
โ— 2026-03-21 10:02:44
โ— 2026-06-12 15:00:34
โ—NSns2.ixi.ru2015-06-05 โ†’ 2026-06-12 ยท 2 obs
โ— 2015-06-05 01:39:30
โ— 2026-06-12 15:00:34
โ—MXflt0.md.ixi.ru2026-03-21 โ†’ 2026-06-12 ยท 3 obs
โ—‹ 2018-10-09 05:15:52
โ— 2026-03-21 10:02:44
โ— 2026-06-12 15:00:34
โ—MXflt1.md.ixi.ru2026-03-21 โ†’ 2026-06-12 ยท 3 obs
โ—‹ 2018-10-09 05:15:52
โ— 2026-03-21 10:02:44
โ— 2026-06-12 15:00:34
โ—‹MXrootkit.ru.s200a1.psmtp.com2015-06-05 โ†’ 2018-10-09 ยท 4 obs
โ— 2015-06-05 01:39:30
โ— 2018-10-09 05:15:52
โ—‹ 2026-03-21 10:02:44
โ—‹ 2026-06-12 15:00:34
โ—‹MXrootkit.ru.s200a2.psmtp.com2015-06-05 โ†’ 2018-10-09 ยท 4 obs
โ— 2015-06-05 01:39:30
โ— 2018-10-09 05:15:52
โ—‹ 2026-03-21 10:02:44
โ—‹ 2026-06-12 15:00:34
โ—‹MXrootkit.ru.s200b1.psmtp.com2015-06-05 โ†’ 2018-10-09 ยท 4 obs
โ— 2015-06-05 01:39:30
โ— 2018-10-09 05:15:52
โ—‹ 2026-03-21 10:02:44
โ—‹ 2026-06-12 15:00:34
โ—‹MXrootkit.ru.s200b2.psmtp.com2015-06-05 โ†’ 2018-10-09 ยท 4 obs
โ— 2015-06-05 01:39:30
โ— 2018-10-09 05:15:52
โ—‹ 2026-03-21 10:02:44
โ—‹ 2026-06-12 15:00:34

๐Ÿ” DNS Trace

๐Ÿ“‹ Delegation Chain

ZoneNameserversGlue
ruf.dns.ripn.net, a.dns.ripn.net, b.dns.ripn.net, d.dns.ripn.net...-
rootkit.runs0.ixi.ru, ns1.ixi.ru2 records

โœ… Authoritative Response

Server:85.195.105.238

NS records: ns0.ixi.ru, ns1.ixi.ru

๐Ÿ”’ DNSSEC Status

โš ๏ธ Insecure (no DNSSEC)

No DS record for rootkit.ru (unsigned zone)

โฑ๏ธ Timing

Total: 746ms | Queries: -

๐Ÿ“„ Records

TypeCountSample Data
NS2ns.ixi.ru, ns2.ixi.ru
MX2flt0.md.ixi.ru (pri: 10), flt1.md.ixi.ru (pri: 20)
SOA1ns.ixi.ru noc.ixi.ru

๐Ÿ“Œ Glue Records Collected

Total: 2

Out-of-bailiwick: 2 (ns0.ixi.ru, ns1.ixi.ru)

Analysis

Name Servers

rootkit.ru is delegated to four name servers, ns0.ixi.ru, ns1.ixi.ru, ns2.ixi.ru and ns.ixi.ru.

The name servers of rootkit.ru overlap at least partially with those of other domains โ€” among them ixi.ru, stoic-store.ru, rusbrokcom.ru and two more.

These name servers commonly co-occur with the name servers ns4-l2.nic.ru, ns8-l2.nic.ru, ns4-cloud.nic.ru and ns8-cloud.nic.ru.

The hostnames ns0.ixi.ru, ns1.ixi.ru and ns2.ixi.ru each resolve to a single IP: ns0.ixi.ru โ†’ 95.143.183.42, ns1.ixi.ru โ†’ 85.195.105.238, ns2.ixi.ru โ†’ 93.115.95.198.

Mail Servers

rootkit.ru uses two mail servers, flt0.md.ixi.ru and flt1.md.ixi.ru.

The mail server setup of rootkit.ru matches that of other domains such as cable-import.ru, restore-retail-group.ru, imtrade.ru and two others.

At least some of the mail servers used by rootkit.ru are shared with other domains: ixi.su, android-plaza.ru, pre-set.ru and two others among them.

These mail servers tend to be used in conjunction with the mail servers mail.ixi.su.

Both flt0.md.ixi.ru and flt1.md.ixi.ru have a single IP address each โ€” flt0.md.ixi.ru resolves to 85.195.105.240 while flt1.md.ixi.ru resolves to 95.143.183.43.