CF1763264015036-tsm20251109205412

DNSWHOIS.INFO - randy-maugans-enterprisephishingbotnet-theartophraud.buttcam.com

Search for IP or hostnames:

randy-maugans-enterprisephishingbotnet-theartophraud.buttcam.com checked at 2025-11-16T03:33:35.021Z 159ms 71/71/71 100% R:11 allDone:true timedOut:false

randy-maugans-enterprisephishingbotnet-theartophraud.buttcam.com

MXpark-mx.above.com
A103.224.212.34🇦🇺 TRELLIAN-AS-AP
PTRpark-mx.above.com
NSns1.abovedomains.com
A103.224.182.9🇦🇺 TRELLIAN-AS-AP
PTRns1.above.com
A103.224.212.9🇦🇺 TRELLIAN-AS-AP
PTRns1.above.com
NSns2.abovedomains.com
A103.224.182.10🇦🇺 TRELLIAN-AS-AP
PTRns2.above.com
A103.224.212.10🇦🇺 TRELLIAN-AS-AP
PTRns2.above.com
A103.224.182.243🇦🇺 TRELLIAN-AS-AP
PTRlb-182-243.above.com

buttcam.com

MXpark-mx.above.com
NSns1.abovedomains.com
NSns2.abovedomains.com
A103.224.182.243🇦🇺 TRELLIAN-AS-AP

AI analysis

randy-maugans-enterprisephishingbotnet-theartophraud.buttcam.com points to a single IP: 103.224.182.243.

Other host names, for instance 124.234-191.tatanova.com, a17-250-248-101.kampusagi.com, 201.211-45.tatanova.com, youngsters-teens.ucgalleries.com and conepolis.com share IP numbers with randy-maugans-enterprisephishingbotnet-theartophraud.buttcam.com.

Two name servers ns1.abovedomains.com and ns2.abovedomains.com handle delegation for randy-maugans-enterprisephishingbotnet-theartophraud.buttcam.com.

randy-maugans-enterprisephishingbotnet-theartophraud.buttcam.com uses the same name server setup as other domains, for example webbox1099.server-home.net, 999999999mp3.wapka.mobi, accuwea.com, layandrama.info and iff-til-amv.nl.eqip.net.

Host names with two IP numbers:

ns1.abovedomains.com points to: 103.224.182.9 and 103.224.212.9

ns2.abovedomains.com points to: 103.224.182.10 and 103.224.212.10

randy-maugans-enterprisephishingbotnet-theartophraud.buttcam.com is handled by a single mail server, park-mx.above.com.

randy-maugans-enterprisephishingbotnet-theartophraud.buttcam.com has the same mail server setup as other domains, including dcx2.dcxestore.com, muffling.com, smtp.oulook.com, 3327cc.com and notebools.de.

park-mx.above.com points to a single IP: 103.224.212.34.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq