CF1761355587300-tsm20251024211356

DNSWHOIS.INFO - shutdown-r.wtf

Search for IP or hostnames:

shutdown-r.wtf checked at 2025-10-25T01:26:27.284Z 207ms 146/146/146 100% R:16

shutdown-r.wtf

MXmail.protonmail.ch
A176.119.200.128๐Ÿ‡จ๐Ÿ‡ญ Proton AG
PTRmail.protonmail.ch
A185.70.42.128๐Ÿ‡จ๐Ÿ‡ญ Proton AG
PTRmail.protonmail.ch
A185.205.70.128๐Ÿ‡ซ๐Ÿ‡ท Proton AG
PTRmail.protonmail.ch
MXmailsec.protonmail.ch
A176.119.200.129๐Ÿ‡จ๐Ÿ‡ญ Proton AG
PTRmailsec.protonmail.ch
A185.70.42.129๐Ÿ‡จ๐Ÿ‡ญ Proton AG
PTRmailsec.protonmail.ch
A185.205.70.129๐Ÿ‡ซ๐Ÿ‡ท Proton AG
PTRmailsec.protonmail.ch
NSernest.ns.cloudflare.com
A2606:4700:58::adf5:3ba4 ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRernest.ns.cloudflare.com
A2803:f800:50::6ca2:c1a4 ๐Ÿ‡จ๐Ÿ‡ท Cloudflare
PTRernest.ns.cloudflare.com
A2a06:98c1:50::ac40:21a4 ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRernest.ns.cloudflare.com
A108.162.193.164๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRernest.ns.cloudflare.com
A172.64.33.164๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRernest.ns.cloudflare.com
A173.245.59.164๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRernest.ns.cloudflare.com
NSlia.ns.cloudflare.com
A2606:4700:50::adf5:3ab9 ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRlia.ns.cloudflare.com
A2803:f800:50::6ca2:c0b9 ๐Ÿ‡จ๐Ÿ‡ท Cloudflare
PTRlia.ns.cloudflare.com
A2a06:98c1:50::ac40:20b9 ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRlia.ns.cloudflare.com
A108.162.192.185๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRlia.ns.cloudflare.com
A172.64.32.185๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRlia.ns.cloudflare.com
A173.245.58.185๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRlia.ns.cloudflare.com
A2606:4700:3033::ac43:d531 ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
A2606:4700:3035::6815:232c ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
A104.21.35.44 Cloudflare
A172.67.213.49๐Ÿ‡บ๐Ÿ‡ธ Cloudflare

wtf

NSv0n0.nic.wtf
NSv0n1.nic.wtf
NSv0n2.nic.wtf
NSv0n3.nic.wtf
NSv2n0.nic.wtf
NSv2n1.nic.wtf

Starts with same word

Starts similarily

AI analysis

shutdown-r.wtf points to four IP numbers: 2606:4700:3033::ac43:d531, 2606:4700:3035::6815:232c, 104.21.35.44 and 172.67.213.49.

Other host names, for instance utters.io, borostyanapartmanok.hu, www.jsminjuryfirm.com, carpaine.cn and bhadra.net share IP numbers with shutdown-r.wtf.

shutdown-r.wtf's delegation is to two name servers ernest.ns.cloudflare.com and lia.ns.cloudflare.com.

shutdown-r.wtf shares the same name server configuration as other domains, such as faharas.net, covue.cloud, ithotdesk.com, uaveditor.com and covueit.com.

shutdown-r.wtf at least partially shares its name servers with other domains, for instance aad67.com, icas.es, animalsaustralia-media.org, silencertalk.com and gifts4promo.co.uk.

These name servers are often used together with the name servers coco.ns.cloudflare.com.

Host names with six IP numbers:

ernest.ns.cloudflare.com points to: 2606:4700:58::adf5:3ba4, 2803:f800:50::6ca2:c1a4, 2a06:98c1:50::ac40:21a4, 108.162.193.164, 172.64.33.164 and 173.245.59.164.

lia.ns.cloudflare.com points to: 2606:4700:50::adf5:3ab9, 2803:f800:50::6ca2:c0b9, 2a06:98c1:50::ac40:20b9, 108.162.192.185, 172.64.32.185 and 173.245.58.185.

Two mail servers mail.protonmail.ch and mailsec.protonmail.ch handle shutdown-r.wtf.

shutdown-r.wtf uses the same mail server setup as other domains such as lamia.nl, stoneveden.com, base-six.com, drone404.com and gendarling.com.

shutdown-r.wtf shares some mail servers with other domains, including tannartconsulting.com, teledisc.com, apgef.com, jsiegel.org and modolo.fr.

Host names with three IP numbers

The host name mail.protonmail.ch points to 176.119.200.128, 185.70.42.128 and 185.205.70.128; the host name mailsec.protonmail.ch points to 176.119.200.129, 185.70.42.129 and 185.205.70.129

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

sbwVvUm CF johedugfp 2025-10-25