CF1759650471298-tsm20251004101907

IPLIST.NET - backdoor.rs

Search for IP or hostnames:

backdoor.rs checked at 2025-10-05T07:47:51.281Z 182ms 70/70/70 100% R:15

backdoor.rs

NSdns1.dwhost.net
A2a01:7e00:e000:fa::2 🇬🇧 Linode AS63949
PTRdns1.dwhost.net
A85.159.213.38🇬🇧 Linode AS63949
PTRdns1.dwhost.net
NSdns2.dwhost.net
A94.237.111.102🇳🇱 UpCloud
PTRdns2.dwhost.net
NSdns3.dwhost.net
A162.55.68.152🇩🇪 Hetzner
PTRdns3.dwhost.net
MXmail.backdoor.rs
A138.199.137.102🇩🇪 Hetzner
PTRhost127.dwhost.net
A138.199.137.102🇩🇪 Hetzner
PTRhost127.dwhost.net

rs

NSa.nic.rs
NSb.nic.rs
NSc.nic.rs
NSf.nic.rs
NSh.nic.rs
NSl.nic.rs

Up

Starts with same word

Starts similarily

AI analysis

The parent of mail.backdoor.rs is backdoor.rs.

backdoor.rs points to IP number: 138.199.137.102.

Other host names such as hba.rs, zorantodorovic.com, mail.unijasprs.org.rs, ukns.org and resnik.rs share IPs with backdoor.rs.

backdoor.rs is delegated to three name servers: dns1.dwhost.net, dns2.dwhost.net and dns3.dwhost.net.

backdoor.rs at least partially shares name servers with other domains, for instance finishsistem.rs, medalex.rs, finegraf.rs, dwalati.com and jugoprevozks.rs.

Hostnames with two IPs:

Hostname dns1.dwhost.net points to 2a01:7e00:e000:fa::2 and 85.159.213.38.

Hostnames with one IP:

Hostname dns2.dwhost.net points to 94.237.111.102.

Hostname dns3.dwhost.net points to 162.55.68.152.

backdoor.rs is handled by a single mail server, mail.backdoor.rs.

mail.backdoor.rs points to a single IP: 138.199.137.102.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

TowjHdx CF johedugfp 2025-10-05