CF1757800584799-tsm20250912070358

DNSWHOIS.INFO - evil.wtf

Search for IP or hostnames:

evil.wtf checked at 2025-09-13T21:56:24.769Z 228ms 165/165/165 100% R:16

evil.wtf

NSfay.ns.cloudflare.com
A2606:4700:50::adf5:3a73 🇺🇸 Cloudflare
PTRfay.ns.cloudflare.com
A2803:f800:50::6ca2:c073 🇨🇷 Cloudflare
PTRfay.ns.cloudflare.com
A2a06:98c1:50::ac40:2073 🇺🇸 Cloudflare
PTRfay.ns.cloudflare.com
A108.162.192.115🇺🇸 Cloudflare
PTRfay.ns.cloudflare.com
A172.64.32.115🇺🇸 Cloudflare
PTRfay.ns.cloudflare.com
A173.245.58.115🇺🇸 Cloudflare
PTRfay.ns.cloudflare.com
NSlee.ns.cloudflare.com
A2606:4700:58::adf5:3b81 🇺🇸 Cloudflare
PTRlee.ns.cloudflare.com
A2803:f800:50::6ca2:c181 🇨🇷 Cloudflare
PTRlee.ns.cloudflare.com
A2a06:98c1:50::ac40:2181 🇺🇸 Cloudflare
PTRlee.ns.cloudflare.com
A108.162.193.129🇺🇸 Cloudflare
PTRlee.ns.cloudflare.com
A172.64.33.129🇺🇸 Cloudflare
PTRlee.ns.cloudflare.com
A173.245.59.129🇺🇸 Cloudflare
PTRlee.ns.cloudflare.com
MX_dc-mx.482147edf1f7.evil.wtf
A159.65.179.220🇺🇸 DigitalOcean
A2606:4700:3030::6815:1001 🇺🇸 Cloudflare
A2606:4700:3030::6815:2001 🇺🇸 Cloudflare
A2606:4700:3030::6815:3001 🇺🇸 Cloudflare
A2606:4700:3030::6815:4001 🇺🇸 Cloudflare
A2606:4700:3030::6815:5001 🇺🇸 Cloudflare
A2606:4700:3030::6815:6001 🇺🇸 Cloudflare
A2606:4700:3030::6815:7001 🇺🇸 Cloudflare
A104.21.16.1 Cloudflare
A104.21.32.1 Cloudflare
A104.21.48.1 Cloudflare
A104.21.64.1 Cloudflare
A104.21.80.1 Cloudflare
A104.21.96.1 Cloudflare
A104.21.112.1 Cloudflare

wtf

NSv0n0.nic.wtf
NSv0n1.nic.wtf
NSv0n2.nic.wtf
NSv0n3.nic.wtf
NSv2n0.nic.wtf
NSv2n1.nic.wtf

Starts with same word

Starts similarily

AI analysis

evil.wtf points to a total of fourteen IP numbers, including: 2606:4700:3030::6815:1001, 2606:4700:3030::6815:2001, 2606:4700:3030::6815:3001, 2606:4700:3030::6815:4001, 2606:4700:3030::6815:5001, 2606:4700:3030::6815:6001, 2606:4700:3030::6815:7001, 104.21.16.1, 104.21.32.1, 104.21.48.1, 104.21.64.1, 104.21.80.1, 104.21.96.1, and 104.21.112.1.

The IP numbers of evil.wtf are also shared with other host names such as parhaatuudetkasinot.com, grisini.com, dhr.com.br, lilymemo.com, and texasetn.com.

Two name servers, fay.ns.cloudflare.com and lee.ns.cloudflare.com, are assigned for evil.wtf.

Other domains such as yurlkink.ru, gopro-forum.ru, niteteam4.com, mach-b.com, and housedavenport.com, share the same name server setup as evil.wtf.

Other domains, such as hi-techautomotive.com, adk-media.net, baptist100.org, troygrille.com, and griot.fr, share at least a part of their name servers with evil.wtf.

fay.ns.cloudflare.com and lee.ns.cloudflare.com each point to six IP numbers respectively: 2606:4700:50::adf5:3a73, 2803:f800:50::6ca2:c073, 2a06:98c1:50::ac40:2073, 108.162.192.115, 172.64.32.115, 173.245.58.115 and 2606:4700:58::adf5:3b81, 2803:f800:50::6ca2:c181, 2a06:98c1:50::ac40:2181, 108.162.193.129, 172.64.33.129, 173.245.59.129.

The mail server, _dc-mx.482147edf1f7.evil.wtf, manages evil.wtf.

_dc-mx.482147edf1f7.evil.wtf is associated with the IP address 159.65.179.220.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

ByEGYgf CF johedugfp 2025-09-13