CF1761628246745-tsm20251027103946

DNSWHOIS.INFO - suspicious.application-alert.com

Search for IP or hostnames:

suspicious.application-alert.com checked at 2025-10-28T05:10:46.729Z 434ms 57/57/57 100% R:12

AI analysis

suspicious.application-alert.com points to two IPs: 3.124.60.251 and 52.57.214.142.

Other host names including apple.confirmation-orders.com, cert-sha256.org, web.cert-sha256.org, payment-details-info.com and azure.http-connection.net share IP numbers with suspicious.application-alert.com.

suspicious.application-alert.com is handled by a single mail server, inbound-smtp.eu-west-1.amazonaws.com.

suspicious.application-alert.com shares its mail server setup with other domains, including opticsalomon.com, derubinat.com, flirtstar.at, novacstore.com and rcodigital-uk.360siteview-export.com.

The mail servers for suspicious.application-alert.com are shared with other domains, for instance hart-vangoud.com, admiralautomatklub.hr, geosolutions.nl, activia.sk and pda.in.ua.

these mail servers are often used with aspmx.l.google.com, alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, aspmx2.googlemail.com, aspmx3.googlemail.com, aspmx4.googlemail.com and aspmx5.googlemail.com.

inbound-smtp.eu-west-1.amazonaws.com points to three IPs: 18.200.203.69, 54.76.31.185 and 54.155.140.59.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

rZlFBAP CF johedugfp 2025-10-28