exploit.sh - dns.ninja

exploit.sh

DNSSECโš ๏ธ Not signed
A2600:3c01::f03c:91ff:fe96:92ea๐Ÿ‡บ๐Ÿ‡ธ AKAMAI-LINODE-AP2600:3c01::/32 Akamai Technologies
PTRus.exploit.sh
A178.79.129.224๐Ÿ‡ฌ๐Ÿ‡ง AKAMAI-LINODE-AP178.79.128.0/18 Akamai Technologies
NSexploit.sh โญ
A2600:3c01::f03c:91ff:fe96:92ea๐Ÿ‡บ๐Ÿ‡ธ AKAMAI-LINODE-AP2600:3c01::/32 Akamai Technologies
PTRus.exploit.sh
A178.79.129.224๐Ÿ‡ฌ๐Ÿ‡ง AKAMAI-LINODE-AP178.79.128.0/18 Akamai Technologies
PTRuk.exploit.sh
NSns.exploit.sh
A2a01:7e00::f03c:91ff:fe96:bc4d๐Ÿ‡ฌ๐Ÿ‡ง AKAMAI-LINODE-AP2a01:7e00::/32 Akamai Technologies
PTRuk.exploit.sh
A178.79.129.224๐Ÿ‡ฌ๐Ÿ‡ง AKAMAI-LINODE-AP178.79.128.0/18 Akamai Technologies
PTRuk.exploit.sh
NSns.upthere.info
A2a01:7e00::f03c:91ff:fe96:bc4d๐Ÿ‡ฌ๐Ÿ‡ง AKAMAI-LINODE-AP2a01:7e00::/32 Akamai Technologies
PTRuk.exploit.sh
A178.79.129.224๐Ÿ‡ฌ๐Ÿ‡ง AKAMAI-LINODE-AP178.79.128.0/18 Akamai Technologies
PTRuk.exploit.sh
MXaspmx.l.google.com โญ
A2607:f8b0:4004:c17::1a๐Ÿ‡บ๐Ÿ‡ธ Google2607:f8b0:4004::/48
PTRbl-in-f26.1e100.net
A142.251.179.27๐Ÿ‡บ๐Ÿ‡ธ Google142.251.179.0/24
PTRpd-in-f27.1e100.net
MXalt1.aspmx.l.google.com(20)
A2800:3f0:4003:c0f::1b๐Ÿ‡จ๐Ÿ‡ฑ Google2800:3f0:4003::/48
A108.177.123.27๐Ÿ‡บ๐Ÿ‡ธ Google108.177.123.0/24
PTRlcscld-in-f27.1e100.net
MXalt2.aspmx.l.google.com(20)
A2a00:1450:400b:c02::1b๐Ÿ‡ฎ๐Ÿ‡ช Google2a00:1450:400b::/48
PTRdj-in-f27.1e100.net
A172.253.116.26๐Ÿ‡บ๐Ÿ‡ธ Google172.253.116.0/24
PTRdj-in-f26.1e100.net
MXaspmx2.googlemail.com(30)
A2800:3f0:4003:c0f::1b๐Ÿ‡จ๐Ÿ‡ฑ Google2800:3f0:4003::/48
A108.177.123.26๐Ÿ‡บ๐Ÿ‡ธ Google108.177.123.0/24
PTRlcscld-in-f26.1e100.net
MXaspmx3.googlemail.com(30)
A2a00:1450:400b:c02::1a๐Ÿ‡ฎ๐Ÿ‡ช Google2a00:1450:400b::/48
PTRdj-in-f26.1e100.net
A172.253.116.26๐Ÿ‡บ๐Ÿ‡ธ Google172.253.116.0/24
PTRdj-in-f26.1e100.net
TXTv=spf1 a mx a:fr.exploit.sh ip4:212.47.250.127 ip6:2001:bc8:65c:1247::1 inclu...
SOAexploit.shadmin@exploit.sh 2026-03-03 #31

sh

DNSSEC๐Ÿ”’ Signed (DS record present)
NSa0.nic.sh โญ
NSa2.nic.sh
NSb0.nic.sh
NSc0.nic.sh
SOAa0.nic.shhostmaster@donuts.email serial=1780795214

Previously NS for

Subdomains

Same first word

Similar names

DNS History

13 records (10 active, 3 former)

20162017201820192020202120222023202420252026NSexploit.shns.exploit.shns.upthere.infons1.exploit.shnsv6.exploit.shMXalt1.aspmx.l.google.comalt2.aspmx.l.google.comaspmx.l.google.comaspmx2.googlemail.comaspmx3.googlemail.comA178.79.129.2242600:3c01::f03c:91ff:fe96:92ea74.207.243.207
โ—NSexploit.sh2015-06-01 โ†’ 2026-06-07 ยท 4 obs
โ— 2015-06-01 15:39:50
โ— 2026-06-04 22:51:42
โ—‹ 2026-06-06 09:21:28
โ— 2026-06-07 01:29:02
โ—NSns.exploit.sh2015-06-01 โ†’ 2026-06-07 ยท 2 obs
โ— 2015-06-01 15:39:50
โ— 2026-06-07 01:29:02
โ—NSns.upthere.info2015-06-01 โ†’ 2026-06-07 ยท 5 obs
โ— 2015-06-01 15:39:50
โ— 2016-10-03 00:16:48
โ—‹ 2017-08-13 17:56:20
โ— 2026-02-17 21:05:56
โ— 2026-06-07 01:29:02
โ—‹NSns1.exploit.sh2017-08-13 โ†’ 2017-08-13 ยท 4 obs
โ—‹ 2016-10-03 00:16:48
โ— 2017-08-13 17:56:20
โ—‹ 2026-02-17 21:05:56
โ—‹ 2026-06-07 01:29:02
โ—‹NSnsv6.exploit.sh2015-06-01 โ†’ 2017-08-13 ยท 4 obs
โ— 2015-06-01 15:39:50
โ— 2017-08-13 17:56:20
โ—‹ 2026-02-17 21:05:56
โ—‹ 2026-06-07 01:29:02
โ—MXalt1.aspmx.l.google.com2015-06-01 โ†’ 2026-06-07 ยท 4 obs
โ— 2015-06-01 15:39:50
โ— 2026-06-04 22:51:42
โ—‹ 2026-06-06 09:21:28
โ— 2026-06-07 01:29:02
โ—MXalt2.aspmx.l.google.com2015-06-01 โ†’ 2026-06-07 ยท 4 obs
โ— 2015-06-01 15:39:50
โ— 2026-06-04 22:51:42
โ—‹ 2026-06-06 09:21:28
โ— 2026-06-07 01:29:02
โ—MXaspmx.l.google.com2015-06-01 โ†’ 2026-06-07 ยท 4 obs
โ— 2015-06-01 15:39:50
โ— 2026-06-04 22:51:42
โ—‹ 2026-06-06 09:21:28
โ— 2026-06-07 01:29:02
โ—MXaspmx2.googlemail.com2015-06-01 โ†’ 2026-06-07 ยท 4 obs
โ— 2015-06-01 15:39:50
โ— 2026-06-04 22:51:42
โ—‹ 2026-06-06 09:21:28
โ— 2026-06-07 01:29:02
โ—MXaspmx3.googlemail.com2015-06-01 โ†’ 2026-06-07 ยท 4 obs
โ— 2015-06-01 15:39:50
โ— 2026-06-04 22:51:42
โ—‹ 2026-06-06 09:21:28
โ— 2026-06-07 01:29:02
โ—A178.79.129.2242017-08-13 โ†’ 2026-06-07 ยท 5 obs
โ—‹ 2016-10-03 00:16:48
โ— 2017-08-13 17:56:20
โ— 2026-06-04 22:51:42
โ—‹ 2026-06-06 09:21:28
โ— 2026-06-07 01:29:02
โ—A2600:3c01::f03c:91ff:fe96:92ea2015-06-01 โ†’ 2026-06-07 ยท 4 obs
โ— 2015-06-01 15:39:50
โ— 2026-06-04 22:51:42
โ—‹ 2026-06-06 09:21:28
โ— 2026-06-07 01:29:02
โ—‹A74.207.243.2072015-06-01 โ†’ 2016-10-03 ยท 4 obs
โ— 2015-06-01 15:39:50
โ— 2016-10-03 00:16:48
โ—‹ 2017-08-13 17:56:20
โ—‹ 2026-06-07 01:29:02

๐Ÿ” DNS Trace

๐Ÿ“‹ Delegation Chain

ZoneNameserversGlue
shb0.nic.sh, a0.nic.sh, c0.nic.sh, a2.nic.sh8 records
exploit.shns.upthere.info, ns.exploit.sh1 record

โœ… Authoritative Response

Server:178.79.129.224

NS records: ns.upthere.info, ns.exploit.sh

๐Ÿ”’ DNSSEC Status

โš ๏ธ Insecure (no DNSSEC)

No DS record for exploit.sh (unsigned zone)

โฑ๏ธ Timing

Total: 573ms | Queries: -

๐Ÿ“„ Records

TypeCountSample Data
A1178.79.129.224
AAAA12600:3c01::f03c:91ff:fe96:92ea
NS2ns.exploit.sh, ns.upthere.info
MX5ASPMX2.GOOGLEMAIL.COM (pri: 30), ALT2.ASPMX.L.GOOGLE.COM (pri: 20)...
TXT1v=spf1 a mx a:fr.exploit.sh ip4:212.47.2
SOA1exploit.sh admin.exploit.sh

๐Ÿ“Œ Glue Records Collected

Total: 9

In-bailiwick: 9 (b0.nic.sh, b0.nic.sh, a0.nic.sh...)

Analysis

Hierarchy

nsv6.exploit.sh, mx.exploit.sh and ns1.exploit.sh each fall under the parent domain exploit.sh.

IP Addresses

exploit.sh points to two IP numbers: 178.79.129.224 and 2600:3c01::f03c:91ff:fe96:92ea.

ns.upthere.info and ns.exploit.sh, along with other host names, share IP addresses with exploit.sh.

Name Servers

Three name servers handle the delegation for exploit.sh: exploit.sh, ns.upthere.info and ns.exploit.sh.

At least some of exploit.sh's name servers are also used by other domains, among them upthere.info.

exploit.sh, ns.upthere.info and ns.exploit.sh each resolve to two IP addresses. exploit.sh resolves to 178.79.129.224 and 2600:3c01::f03c:91ff:fe96:92ea. ns.upthere.info resolves to 178.79.129.224 and 2a01:7e00::f03c:91ff:fe96:bc4d. ns.exploit.sh resolves to 178.79.129.224 and 2a01:7e00::f03c:91ff:fe96:bc4d.

exploit.sh, ns.upthere.info and ns.exploit.sh are host names that all point to 178.79.129.224.

Both ns.upthere.info and ns.exploit.sh resolve to 2a01:7e00::f03c:91ff:fe96:bc4d IP addresses each.

Mail Servers

exploit.sh is handled by 5 mail servers: aspmx2.googlemail.com, aspmx3.googlemail.com, aspmx.l.google.com and two others.

exploit.sh shares mail servers โ€” at least in part โ€” with other domains, including ns500693.ns500699.ns500734.ns500734.ns500734.ns500734.ns500693.ns500699.ns500588.ns500588.ns500588.ns500683.ns500588.ns500632.dtrkdll.com, ns500765.ns500765.ns500693.ns500734.ns500699.ns500693.ns500693.ns500693.ns500588.ns500693.ns500588.ns500588.ns500588.ns500632.ns500612.ns500602.dtrkdll.com, ns500759.ns500698.ns500759.ns500698.ns500758.ns500698.ns500736.ns500698.ns500698.ns500576.ns500708.ns500698.ns500619.ns500698.ns500576.ns500619.ns500576.trackreceptor.com and two others.

These mail servers are frequently used alongside mail servers alt2.aspmx.l.google.com, alt1.aspmx.l.google.com, alt3.aspmx.l.google.com and three others.

Host names with two IP numbers:

aspmx2.googlemail.com directs traffic to 108.177.123.26 and 2800:3f0:4003:c0f::1b.

aspmx3.googlemail.com directs traffic to 172.253.116.26 and 2a00:1450:400b:c02::1a.

aspmx.l.google.com directs traffic to 142.251.179.27 and 2607:f8b0:4004:c17::1a.

alt1.aspmx.l.google.com directs traffic to 108.177.123.27 and 2800:3f0:4003:c0f::1b.

alt2.aspmx.l.google.com directs traffic to 172.253.116.26 and 2a00:1450:400b:c02::1b.

Both aspmx2.googlemail.com and alt1.aspmx.l.google.com resolve to 2800:3f0:4003:c0f::1b IP addresses each.

Both aspmx3.googlemail.com and alt2.aspmx.l.google.com resolve to 172.253.116.26 IP addresses each.