CF1757741826698-tsm20250912070358

IPLIST.NET - shutdown-r.wtf

Search for IP or hostnames:

shutdown-r.wtf checked at 2025-09-13T05:37:06.626Z 756ms 143/143/143 100% R:11

shutdown-r.wtf

MXmail.protonmail.ch
A176.119.200.128🇨🇭 Proton AG
PTRmail.protonmail.ch
A185.70.42.128🇨🇭 Proton AG
PTRmail.protonmail.ch
A185.205.70.128🇫🇷 Proton AG
PTRmail.protonmail.ch
MXmailsec.protonmail.ch
A176.119.200.129🇨🇭 Proton AG
PTRmailsec.protonmail.ch
A185.70.42.129🇨🇭 Proton AG
PTRmailsec.protonmail.ch
A185.205.70.129🇫🇷 Proton AG
PTRmailsec.protonmail.ch
NSernest.ns.cloudflare.com
A2606:4700:58::adf5:3ba4 🇺🇸 Cloudflare
PTRernest.ns.cloudflare.com
A2803:f800:50::6ca2:c1a4 🇨🇷 Cloudflare
PTRernest.ns.cloudflare.com
A2a06:98c1:50::ac40:21a4 🇺🇸 Cloudflare
PTRernest.ns.cloudflare.com
A108.162.193.164🇺🇸 Cloudflare
PTRernest.ns.cloudflare.com
A172.64.33.164🇺🇸 Cloudflare
PTRernest.ns.cloudflare.com
A173.245.59.164🇺🇸 Cloudflare
PTRernest.ns.cloudflare.com
NSlia.ns.cloudflare.com
A2606:4700:50::adf5:3ab9 🇺🇸 Cloudflare
PTRlia.ns.cloudflare.com
A2803:f800:50::6ca2:c0b9 🇨🇷 Cloudflare
PTRlia.ns.cloudflare.com
A2a06:98c1:50::ac40:20b9 🇺🇸 Cloudflare
PTRlia.ns.cloudflare.com
A108.162.192.185🇺🇸 Cloudflare
PTRlia.ns.cloudflare.com
A172.64.32.185🇺🇸 Cloudflare
PTRlia.ns.cloudflare.com
A173.245.58.185🇺🇸 Cloudflare
PTRlia.ns.cloudflare.com
A2606:4700:3033::ac43:d531 🇺🇸 Cloudflare
A2606:4700:3035::6815:232c 🇺🇸 Cloudflare
A104.21.35.44 Cloudflare
A172.67.213.49🇺🇸 Cloudflare

wtf

NSv0n0.nic.wtf
NSv0n1.nic.wtf
NSv0n2.nic.wtf
NSv0n3.nic.wtf
NSv2n0.nic.wtf
NSv2n1.nic.wtf

Starts with same word

Starts similarily

AI analysis

The DNS record shutdown-r.wtf resolves to the following IP addresses: 2606:4700:3033::ac43:d531, 2606:4700:3035::6815:232c, 104.21.35.44, and 172.67.213.49.

IP numbers are shared between shutdown-r.wtf and other host names like cleanenergytraining.org, www.jsminjuryfirm.com, essentialsandextras.no1ppt.com, carpaine.cn, and softechnocon.com.

Two name servers, ernest.ns.cloudflare.com and lia.ns.cloudflare.com, are delegated to shutdown-r.wtf.

The name server setup of shutdown-r.wtf is shared with other domains such as faharas.net, covue.cloud, ithotdesk.com, uaveditor.com, and covueit.com.

The domain shutdown-r.wtf shares its name servers, at least partially, with other domains such as aad67.com, icas.es, animalsaustralia-media.org, silencertalk.com, and gifts4promo.co.uk.

ernest.ns.cloudflare.com and lia.ns.cloudflare.com both point to six IP numbers each: 2606:4700:58::adf5:3ba4, 2803:f800:50::6ca2:c1a4, 2a06:98c1:50::ac40:21a4, 108.162.193.164, 172.64.33.164, 173.245.59.164 and 2606:4700:50::adf5:3ab9, 2803:f800:50::6ca2:c0b9, 2a06:98c1:50::ac40:20b9, 108.162.192.185, 172.64.32.185, 173.245.58.185 respectively.

Two mail servers, mail.protonmail.ch and mailsec.protonmail.ch, manage shutdown-r.wtf.

Just like other domains such as lamia.nl, stoneveden.com, drone404.com, gendarling.com, and blackhelmetapparel.com, shutdown-r.wtf also has the same mail server setup.

Other domains such as tannartconsulting.com, teledisc.com, apgef.com, jsiegel.org, and modolo.fr share some mail servers, at least partially, with shutdown-r.wtf.

mail.protonmail.ch and mailsec.protonmail.ch each point to three IP numbers: 176.119.200.128, 185.70.42.128, 185.205.70.128 and 176.119.200.129, 185.70.42.129, 185.205.70.129 respectively.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

JHNKHvm CF johedugfp 2025-09-13