Skip to content

Instantly share code, notes, and snippets.

@409H
Last active September 7, 2017 18:49
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save 409H/69f41ddc9c12bc7ae665f6b2bbfed5f8 to your computer and use it in GitHub Desktop.
Save 409H/69f41ddc9c12bc7ae665f6b2bbfed5f8 to your computer and use it in GitHub Desktop.
Phishing domains going through domain_analyzer 2017/09/07
@409H
Copy link
Author

409H commented Sep 7, 2017

monetha.ltd

Analysing domain : monetha.ltd
	Output directory name: monetha.ltd
	Output summary file: monetha.ltd/monetha.ltd.txt
	Checking NameServers using system default resolver...
			HostName: dns1.namecheaphosting.com			Type: NS
			HostName: dns1.registrar-servers.com			Type: PTR
			HostName: dns2.namecheaphosting.com			Type: NS
			HostName: d3.verisigndns.com			Type: PTR

	Checking MailServers using system default resolver...
			HostName: mail.monetha.ltd			Type: MX
			HostName: business34-2.web-hosting.com			Type: PTR

	Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
		No zone transfer found on nameserver 216.87.155.33
		No zone transfer found on nameserver 216.87.152.33

	Checking SPF record...
		No SPF record

	Checking 192 most common hostnames using system default resolver...
			HostName: mail.monetha.ltd			Type: MX
			HostName: business34-2.web-hosting.com			Type: PTR
			HostName: www.monetha.ltd			Type: A
			HostName: mail.monetha.ltd			Type: MX
			HostName: business34-2.web-hosting.com			Type: PTR
			HostName: www.monetha.ltd			Type: A
			HostName: ftp.monetha.ltd			Type: A
			HostName: mail.monetha.ltd			Type: MX
			HostName: business34-2.web-hosting.com			Type: PTR
			HostName: www.monetha.ltd			Type: A
			HostName: ftp.monetha.ltd			Type: A
			HostName: mail.monetha.ltd			Type: A
			HostName: mail.monetha.ltd			Type: MX
			HostName: business34-2.web-hosting.com			Type: PTR
			HostName: www.monetha.ltd			Type: A
			HostName: ftp.monetha.ltd			Type: A
			HostName: mail.monetha.ltd			Type: A
			HostName: webmail.monetha.ltd			Type: A


--Finished--
Summary information for domain monetha.ltd
-----------------------------------------

	Domain Ips Information:
		IP: 198.54.115.57
			HostName: mail.monetha.ltd			Type: MX
			HostName: business34-2.web-hosting.com			Type: PTR
			HostName: www.monetha.ltd			Type: A
			HostName: ftp.monetha.ltd			Type: A
			HostName: mail.monetha.ltd			Type: A
			HostName: webmail.monetha.ltd			Type: A
		IP: 216.87.155.33
			HostName: dns1.namecheaphosting.com			Type: NS
			HostName: dns1.registrar-servers.com			Type: PTR
		IP: 216.87.152.33
			HostName: dns2.namecheaphosting.com			Type: NS
			HostName: d3.verisigndns.com			Type: PTR

--------------End  Summary --------------
-----------------------------------------

@409H
Copy link
Author

409H commented Sep 7, 2017

myaetherwallet.com

Analysing domain : myaetherwallet.com
	Output directory name: myaetherwallet.com
	Output summary file: myaetherwallet.com/myaetherwallet.com.txt
	Checking NameServers using system default resolver...
		IP: 194.58.117.11 (Russian Federation)
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
		IP: 194.58.117.13 (Russian Federation)
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
		IP: 176.99.13.11 (Russian Federation)
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
		IP: 176.99.13.17 (Russian Federation)
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
		IP: 176.99.13.13 (Russian Federation)
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
		IP: 176.99.13.15 (Russian Federation)
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
		IP: 194.58.117.17 (Russian Federation)
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
		IP: 194.58.117.15 (Russian Federation)
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
		IP: 176.99.13.14 (Russian Federation)
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
		IP: 194.58.117.14 (Russian Federation)
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
		IP: 194.58.117.12 (Russian Federation)
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
		IP: 194.58.117.18 (Russian Federation)
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
		IP: 194.58.117.16 (Russian Federation)
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
		IP: 176.99.13.12 (Russian Federation)
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
		IP: 176.99.13.16 (Russian Federation)
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
		IP: 176.99.13.18 (Russian Federation)
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR

	Checking MailServers using system default resolver...
		WARNING!! There are no MX records for this domain

	Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
		No zone transfer found on nameserver 194.58.117.18
		No zone transfer found on nameserver 194.58.117.11
		No zone transfer found on nameserver 194.58.117.12
		No zone transfer found on nameserver 194.58.117.13
		No zone transfer found on nameserver 194.58.117.14
		No zone transfer found on nameserver 194.58.117.15
		No zone transfer found on nameserver 194.58.117.16
		No zone transfer found on nameserver 194.58.117.17
		No zone transfer found on nameserver 176.99.13.15
		No zone transfer found on nameserver 176.99.13.14
		No zone transfer found on nameserver 176.99.13.17
		No zone transfer found on nameserver 176.99.13.16
		No zone transfer found on nameserver 176.99.13.11
		No zone transfer found on nameserver 176.99.13.13
		No zone transfer found on nameserver 176.99.13.12
		No zone transfer found on nameserver 176.99.13.18

	Checking SPF record...
		No SPF record

	Checking 192 most common hostnames using system default resolver...


--Finished--
Summary information for domain myaetherwallet.com
-----------------------------------------

	Domain Ips Information:
		IP: 194.58.117.18
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 194.58.117.11
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 194.58.117.12
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 194.58.117.13
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 194.58.117.14
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 194.58.117.15
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 194.58.117.16
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 194.58.117.17
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 176.99.13.15
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 176.99.13.14
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 176.99.13.17
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 176.99.13.16
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 176.99.13.11
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 176.99.13.13
			HostName: ns1.reg.ru			Type: NS
			HostName: ns1.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 176.99.13.12
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 176.99.13.18
			HostName: ns2.reg.ru			Type: NS
			HostName: ns2.reg.ru			Type: PTR
			Country: Russian Federation

--------------End  Summary --------------
-----------------------------------------

@409H
Copy link
Author

409H commented Sep 7, 2017

myetherwatlet.com

Analysing domain : myetherwatlet.com
	Output directory name: myetherwatlet.com
	Output summary file: myetherwatlet.com/myetherwatlet.com.txt
	Checking NameServers using system default resolver...
		IP: 31.31.194.2 (Russian Federation)
			HostName: ns1.hosting.reg.ru			Type: NS
			HostName: ns1.hosting.reg.ru			Type: PTR
		IP: 31.31.198.6 (Russian Federation)
			HostName: ns1.hosting.reg.ru			Type: NS
			HostName: ns1.hosting.reg.ru			Type: PTR
		IP: 31.31.198.7 (Russian Federation)
			HostName: ns2.hosting.reg.ru			Type: NS
			HostName: ns2.hosting.reg.ru			Type: PTR
		IP: 31.31.194.3 (Russian Federation)
			HostName: ns2.hosting.reg.ru			Type: NS
			HostName: ns2.hosting.reg.ru			Type: PTR

	Checking MailServers using system default resolver...
		IP: 31.31.194.101 (Russian Federation)
			HostName: mx1.hosting.reg.ru			Type: MX
			HostName: relay7.hosting.reg.ru			Type: PTR
		IP: 31.31.194.100 (Russian Federation)
			HostName: mx1.hosting.reg.ru			Type: MX
			HostName: relay6.hosting.reg.ru			Type: PTR
		IP: 31.31.194.101 (Russian Federation)
			HostName: mx1.hosting.reg.ru			Type: MX
			HostName: relay7.hosting.reg.ru			Type: PTR
			HostName: mx2.hosting.reg.ru			Type: MX
		IP: 31.31.194.100 (Russian Federation)
			HostName: mx1.hosting.reg.ru			Type: MX
			HostName: relay6.hosting.reg.ru			Type: PTR
			HostName: mx2.hosting.reg.ru			Type: MX

	Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
		No zone transfer found on nameserver 31.31.198.7
		No zone transfer found on nameserver 31.31.198.6
		No zone transfer found on nameserver 31.31.194.3
		No zone transfer found on nameserver 31.31.194.2

	Checking SPF record...

	Checking SPF record...
		New IP found: 31.31.196.5
		New IP found: 31.31.194.24
		New IP found: 194.58.93.99
		New IP found: 31.31.194.22
		New IP found: 31.31.194.33
		New IP found: 5.63.156.42
		New IP found: 5.63.156.93
		New IP found: 5.63.158.43
		New IP found: 31.31.193.94
		New IP found: 31.31.192.11
		New IP found: 31.31.193.92
		New IP found: 5.63.155.173
		New IP found: 37.140.192.127

	Checking 192 most common hostnames using system default resolver...
		IP: 37.140.192.127 (Russian Federation)
			Type: SPF
			HostName: www.myetherwatlet.com			Type: A
			HostName: scp18.hosting.reg.ru			Type: PTR
		IP: 37.140.192.127 (Russian Federation)
			Type: SPF
			HostName: www.myetherwatlet.com			Type: A
			HostName: scp18.hosting.reg.ru			Type: PTR
			HostName: ftp.myetherwatlet.com			Type: A
		IP: 37.140.192.127 (Russian Federation)
			Type: SPF
			HostName: www.myetherwatlet.com			Type: A
			HostName: scp18.hosting.reg.ru			Type: PTR
			HostName: ftp.myetherwatlet.com			Type: A
			HostName: mail.myetherwatlet.com			Type: A
		IP: 37.140.192.127 (Russian Federation)
			Type: SPF
			HostName: www.myetherwatlet.com			Type: A
			HostName: scp18.hosting.reg.ru			Type: PTR
			HostName: ftp.myetherwatlet.com			Type: A
			HostName: mail.myetherwatlet.com			Type: A
			HostName: webmail.myetherwatlet.com			Type: A


--Finished--
Summary information for domain myetherwatlet.com
-----------------------------------------

	Domain Ips Information:
		IP: 31.31.198.7
			HostName: ns2.hosting.reg.ru			Type: NS
			HostName: ns2.hosting.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 31.31.198.6
			HostName: ns1.hosting.reg.ru			Type: NS
			HostName: ns1.hosting.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 5.63.158.43
			Type: SPF
		IP: 31.31.194.22
			Type: SPF
		IP: 31.31.196.5
			Type: SPF
		IP: 31.31.193.94
			Type: SPF
		IP: 5.63.156.42
			Type: SPF
		IP: 31.31.192.11
			Type: SPF
		IP: 5.63.156.93
			Type: SPF
		IP: 31.31.194.100
			HostName: mx1.hosting.reg.ru			Type: MX
			HostName: relay6.hosting.reg.ru			Type: PTR
			HostName: mx2.hosting.reg.ru			Type: MX
			Country: Russian Federation
		IP: 31.31.194.101
			HostName: mx1.hosting.reg.ru			Type: MX
			HostName: relay7.hosting.reg.ru			Type: PTR
			HostName: mx2.hosting.reg.ru			Type: MX
			Country: Russian Federation
		IP: 31.31.194.33
			Type: SPF
		IP: 31.31.194.3
			HostName: ns2.hosting.reg.ru			Type: NS
			HostName: ns2.hosting.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 31.31.194.2
			HostName: ns1.hosting.reg.ru			Type: NS
			HostName: ns1.hosting.reg.ru			Type: PTR
			Country: Russian Federation
		IP: 31.31.194.24
			Type: SPF
		IP: 37.140.192.127
			Type: SPF
			HostName: www.myetherwatlet.com			Type: A
			HostName: scp18.hosting.reg.ru			Type: PTR
			HostName: ftp.myetherwatlet.com			Type: A
			HostName: mail.myetherwatlet.com			Type: A
			HostName: webmail.myetherwatlet.com			Type: A
			Country: Russian Federation
		IP: 31.31.193.92
			Type: SPF
		IP: 194.58.93.99
			Type: SPF
		IP: 5.63.155.173
			Type: SPF

--------------End  Summary --------------
-----------------------------------------

@409H
Copy link
Author

409H commented Sep 7, 2017

statustoken.im

Analysing domain : statustoken.im
	Output directory name: statustoken.im
	Output summary file: statustoken.im/statustoken.im.txt
	Checking NameServers using system default resolver...
		IP: 94.250.248.160 (Russian Federation)
			HostName: ns2.firstvds.ru			Type: NS
			HostName: ns2.firstvds.ru			Type: PTR
		IP: 82.146.43.2 (Russian Federation)
			HostName: ns1.firstvds.ru			Type: NS
			HostName: ns1.firstvds.ru			Type: PTR

	Checking MailServers using system default resolver...
		IP: 213.159.210.98 (Russian Federation)
			HostName: mail.statustoken.im			Type: MX
			HostName: terranceb0s.fvds.ru			Type: PTR
		IP: 213.159.210.98 (Russian Federation)
			HostName: mail.statustoken.im			Type: MX
			HostName: terranceb0s.fvds.ru			Type: PTR
			HostName: mail.statustoken.im			Type: MX

	Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
		No zone transfer found on nameserver 82.146.43.2
		No zone transfer found on nameserver 94.250.248.160

	Checking SPF record...

	Checking 192 most common hostnames using system default resolver...
		IP: 213.159.210.98 (Russian Federation)
			HostName: mail.statustoken.im			Type: MX
			HostName: terranceb0s.fvds.ru			Type: PTR
			HostName: mail.statustoken.im			Type: MX
			Type: SPF
			HostName: www.statustoken.im			Type: A
		IP: 213.159.210.98 (Russian Federation)
			HostName: mail.statustoken.im			Type: MX
			HostName: terranceb0s.fvds.ru			Type: PTR
			HostName: mail.statustoken.im			Type: MX
			Type: SPF
			HostName: www.statustoken.im			Type: A
			HostName: ftp.statustoken.im			Type: A
		IP: 213.159.210.98 (Russian Federation)
			HostName: mail.statustoken.im			Type: MX
			HostName: terranceb0s.fvds.ru			Type: PTR
			HostName: mail.statustoken.im			Type: MX
			Type: SPF
			HostName: www.statustoken.im			Type: A
			HostName: ftp.statustoken.im			Type: A
			HostName: mail.statustoken.im			Type: A
		IP: 213.159.210.98 (Russian Federation)
			HostName: mail.statustoken.im			Type: MX
			HostName: terranceb0s.fvds.ru			Type: PTR
			HostName: mail.statustoken.im			Type: MX
			Type: SPF
			HostName: www.statustoken.im			Type: A
			HostName: ftp.statustoken.im			Type: A
			HostName: mail.statustoken.im			Type: A
			HostName: smtp.statustoken.im			Type: A
		IP: 213.159.210.98 (Russian Federation)
			HostName: mail.statustoken.im			Type: MX
			HostName: terranceb0s.fvds.ru			Type: PTR
			HostName: mail.statustoken.im			Type: MX
			Type: SPF
			HostName: www.statustoken.im			Type: A
			HostName: ftp.statustoken.im			Type: A
			HostName: mail.statustoken.im			Type: A
			HostName: smtp.statustoken.im			Type: A
			HostName: pop.statustoken.im			Type: A


--Finished--
Summary information for domain statustoken.im
-----------------------------------------

	Domain Ips Information:
		IP: 82.146.43.2
			HostName: ns1.firstvds.ru			Type: NS
			HostName: ns1.firstvds.ru			Type: PTR
			Country: Russian Federation
		IP: 94.250.248.160
			HostName: ns2.firstvds.ru			Type: NS
			HostName: ns2.firstvds.ru			Type: PTR
			Country: Russian Federation
		IP: 213.159.210.98
			HostName: mail.statustoken.im			Type: MX
			HostName: terranceb0s.fvds.ru			Type: PTR
			HostName: mail.statustoken.im			Type: MX
			Type: SPF
			HostName: www.statustoken.im			Type: A
			HostName: ftp.statustoken.im			Type: A
			HostName: mail.statustoken.im			Type: A
			HostName: smtp.statustoken.im			Type: A
			HostName: pop.statustoken.im			Type: A
			Country: Russian Federation

--------------End  Summary --------------
-----------------------------------------

@409H
Copy link
Author

409H commented Sep 7, 2017

aventus.pro

Analysing domain : aventus.pro
	Output directory name: aventus.pro
	Output summary file: aventus.pro/aventus.pro.txt
	Checking NameServers using system default resolver...
		IP: 216.87.152.33 (United States)
			HostName: dns2.registrar-servers.com			Type: NS
			HostName: d33.verisigndns.com			Type: PTR
		IP: 216.87.155.33 (United States)
			HostName: dns1.registrar-servers.com			Type: NS
			HostName: dns5.registrar-servers.com			Type: PTR

	Checking MailServers using system default resolver...
		IP: 162.255.118.61 (United States)
			HostName: eforward1.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
		IP: 162.255.118.62 (United States)
			HostName: eforward2.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
		IP: 162.255.118.61 (United States)
			HostName: eforward1.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
			HostName: eforward3.registrar-servers.com			Type: MX
		IP: 162.255.118.62 (United States)
			HostName: eforward2.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
			HostName: eforward4.registrar-servers.com			Type: MX
		IP: 162.255.118.62 (United States)
			HostName: eforward2.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
			HostName: eforward4.registrar-servers.com			Type: MX
			HostName: eforward5.registrar-servers.com			Type: MX

	Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
		No zone transfer found on nameserver 216.87.155.33
		No zone transfer found on nameserver 216.87.152.33

	Checking SPF record...

	Checking SPF record...
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 38.101.213.192/28, but only the network IP
		New IP found: 38.101.213.192
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 209.105.246.192/28, but only the network IP
		New IP found: 209.105.246.192
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 199.229.254.192/27, but only the network IP
		New IP found: 199.229.254.192
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 198.54.122.192/26, but only the network IP
		New IP found: 198.54.122.192
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 162.255.118.0/26, but only the network IP
		New IP found: 162.255.118.0
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 198.54.122.0/28, but only the network IP
		New IP found: 198.54.122.0
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 162.255.118.240/29, but only the network IP
		New IP found: 162.255.118.240

	Checking 192 most common hostnames using system default resolver...
		IP: 190.115.18.41 (Belize)
			HostName: www.aventus.pro			Type: A


--Finished--
Summary information for domain aventus.pro
-----------------------------------------

	Domain Ips Information:
		IP: 216.87.152.33
			HostName: dns2.registrar-servers.com			Type: NS
			HostName: d33.verisigndns.com			Type: PTR
			Country: United States
		IP: 162.255.118.62
			HostName: eforward2.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
			HostName: eforward4.registrar-servers.com			Type: MX
			HostName: eforward5.registrar-servers.com			Type: MX
			Country: United States
		IP: 162.255.118.61
			HostName: eforward1.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
			HostName: eforward3.registrar-servers.com			Type: MX
			Country: United States
		IP: 199.229.254.192
			Type: SPF
		IP: 38.101.213.192
			Type: SPF
		IP: 162.255.118.240
			Type: SPF
		IP: 190.115.18.41
			HostName: www.aventus.pro			Type: A
			Country: Belize
		IP: 162.255.118.0
			Type: SPF
		IP: 198.54.122.192
			Type: SPF
		IP: 216.87.155.33
			HostName: dns1.registrar-servers.com			Type: NS
			HostName: dns5.registrar-servers.com			Type: PTR
			Country: United States
		IP: 198.54.122.0
			Type: SPF
		IP: 209.105.246.192
			Type: SPF

--------------End  Summary --------------
-----------------------------------------

@409H
Copy link
Author

409H commented Sep 7, 2017

herotoken.co

Analysing domain : herotoken.co
	Output directory name: herotoken.co
	Output summary file: herotoken.co/herotoken.co.txt
	Checking NameServers using system default resolver...
		IP: 94.250.248.160 (Russian Federation)
			HostName: ns2.firstvds.ru			Type: NS
			HostName: ns2.firstvds.ru			Type: PTR
		IP: 82.146.43.2 (Russian Federation)
			HostName: ns1.firstvds.ru			Type: NS
			HostName: ns1.firstvds.ru			Type: PTR

	Checking MailServers using system default resolver...
		IP: 213.159.210.213 (Russian Federation)
			HostName: mail.herotoken.co			Type: MX
			HostName: herotoken.co			Type: PTR
		IP: 213.159.210.213 (Russian Federation)
			HostName: mail.herotoken.co			Type: MX
			HostName: herotoken.co			Type: PTR
			HostName: mail.herotoken.co			Type: MX

	Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
		No zone transfer found on nameserver 82.146.43.2
		No zone transfer found on nameserver 94.250.248.160

	Checking SPF record...

	Checking 192 most common hostnames using system default resolver...
		IP: 213.159.210.213 (Russian Federation)
			HostName: mail.herotoken.co			Type: MX
			HostName: herotoken.co			Type: PTR
			HostName: mail.herotoken.co			Type: MX
			Type: SPF
			HostName: www.herotoken.co			Type: A
		IP: 213.159.210.213 (Russian Federation)
			HostName: mail.herotoken.co			Type: MX
			HostName: herotoken.co			Type: PTR
			HostName: mail.herotoken.co			Type: MX
			Type: SPF
			HostName: www.herotoken.co			Type: A
			HostName: ftp.herotoken.co			Type: A
		IP: 213.159.210.213 (Russian Federation)
			HostName: mail.herotoken.co			Type: MX
			HostName: herotoken.co			Type: PTR
			HostName: mail.herotoken.co			Type: MX
			Type: SPF
			HostName: www.herotoken.co			Type: A
			HostName: ftp.herotoken.co			Type: A
			HostName: mail.herotoken.co			Type: A
		IP: 213.159.210.213 (Russian Federation)
			HostName: mail.herotoken.co			Type: MX
			HostName: herotoken.co			Type: PTR
			HostName: mail.herotoken.co			Type: MX
			Type: SPF
			HostName: www.herotoken.co			Type: A
			HostName: ftp.herotoken.co			Type: A
			HostName: mail.herotoken.co			Type: A
			HostName: smtp.herotoken.co			Type: A
		IP: 213.159.210.213 (Russian Federation)
			HostName: mail.herotoken.co			Type: MX
			HostName: herotoken.co			Type: PTR
			HostName: mail.herotoken.co			Type: MX
			Type: SPF
			HostName: www.herotoken.co			Type: A
			HostName: ftp.herotoken.co			Type: A
			HostName: mail.herotoken.co			Type: A
			HostName: smtp.herotoken.co			Type: A
			HostName: pop.herotoken.co			Type: A


--Finished--
Summary information for domain herotoken.co
-----------------------------------------

	Domain Ips Information:
		IP: 82.146.43.2
			HostName: ns1.firstvds.ru			Type: NS
			HostName: ns1.firstvds.ru			Type: PTR
			Country: Russian Federation
		IP: 94.250.248.160
			HostName: ns2.firstvds.ru			Type: NS
			HostName: ns2.firstvds.ru			Type: PTR
			Country: Russian Federation
		IP: 213.159.210.213
			HostName: mail.herotoken.co			Type: MX
			HostName: herotoken.co			Type: PTR
			HostName: mail.herotoken.co			Type: MX
			Type: SPF
			HostName: www.herotoken.co			Type: A
			HostName: ftp.herotoken.co			Type: A
			HostName: mail.herotoken.co			Type: A
			HostName: smtp.herotoken.co			Type: A
			HostName: pop.herotoken.co			Type: A
			Country: Russian Federation

--------------End  Summary --------------
-----------------------------------------

@409H
Copy link
Author

409H commented Sep 7, 2017

myethernwallet.com

Analysing domain : myethernwallet.com
	Output directory name: myethernwallet.com
	Output summary file: myethernwallet.com/myethernwallet.com.txt
	Checking NameServers using system default resolver...
		IP: 80.82.77.87 (Netherlands)
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
		IP: 80.82.77.88 (Netherlands)
			HostName: ns4.libertyvps.net			Type: NS

	Checking MailServers using system default resolver...
		IP: 80.82.77.87 (Netherlands)
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
			HostName: myethernwallet.com			Type: MX

	Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
		No zone transfer found on nameserver 80.82.77.88
		No zone transfer found on nameserver 80.82.77.87

	Checking SPF record...
		No SPF record

	Checking 192 most common hostnames using system default resolver...
		IP: 80.82.77.87 (Netherlands)
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
			HostName: myethernwallet.com			Type: MX
			HostName: www.myethernwallet.com			Type: A
		IP: 80.82.77.87 (Netherlands)
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
			HostName: myethernwallet.com			Type: MX
			HostName: www.myethernwallet.com			Type: A
			HostName: ftp.myethernwallet.com			Type: A
		IP: 80.82.77.87 (Netherlands)
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
			HostName: myethernwallet.com			Type: MX
			HostName: www.myethernwallet.com			Type: A
			HostName: ftp.myethernwallet.com			Type: A
			HostName: mail.myethernwallet.com			Type: A
		IP: 80.82.77.87 (Netherlands)
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
			HostName: myethernwallet.com			Type: MX
			HostName: www.myethernwallet.com			Type: A
			HostName: ftp.myethernwallet.com			Type: A
			HostName: mail.myethernwallet.com			Type: A
			HostName: webmail.myethernwallet.com			Type: A


--Finished--
Summary information for domain myethernwallet.com
-----------------------------------------

	Domain Ips Information:
		IP: 80.82.77.88
			HostName: ns4.libertyvps.net			Type: NS
			Country: Netherlands
		IP: 80.82.77.87
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
			HostName: myethernwallet.com			Type: MX
			HostName: www.myethernwallet.com			Type: A
			HostName: ftp.myethernwallet.com			Type: A
			HostName: mail.myethernwallet.com			Type: A
			HostName: webmail.myethernwallet.com			Type: A
			Country: Netherlands

--------------End  Summary --------------
-----------------------------------------

@409H
Copy link
Author

409H commented Sep 7, 2017

myetherwaltet.com

Analysing domain : myetherwaltet.com
	Output directory name: myetherwaltet.com
	Output summary file: myetherwaltet.com/myetherwaltet.com.txt
	Checking NameServers using system default resolver...
		IP: 80.82.77.88 (Netherlands)
			HostName: ns4.libertyvps.net			Type: NS
		IP: 80.82.77.87 (Netherlands)
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR

	Checking MailServers using system default resolver...
		IP: 80.82.77.87 (Netherlands)
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
			HostName: myetherwaltet.com			Type: MX

	Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
		No zone transfer found on nameserver 80.82.77.88
		No zone transfer found on nameserver 80.82.77.87

	Checking SPF record...
		No SPF record

	Checking 192 most common hostnames using system default resolver...
		IP: 80.82.77.87 (Netherlands)
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
			HostName: myetherwaltet.com			Type: MX
			HostName: www.myetherwaltet.com			Type: A
		IP: 80.82.77.87 (Netherlands)
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
			HostName: myetherwaltet.com			Type: MX
			HostName: www.myetherwaltet.com			Type: A
			HostName: ftp.myetherwaltet.com			Type: A
		IP: 80.82.77.87 (Netherlands)
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
			HostName: myetherwaltet.com			Type: MX
			HostName: www.myetherwaltet.com			Type: A
			HostName: ftp.myetherwaltet.com			Type: A
			HostName: mail.myetherwaltet.com			Type: A
		IP: 80.82.77.87 (Netherlands)
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
			HostName: myetherwaltet.com			Type: MX
			HostName: www.myetherwaltet.com			Type: A
			HostName: ftp.myetherwaltet.com			Type: A
			HostName: mail.myetherwaltet.com			Type: A
			HostName: webmail.myetherwaltet.com			Type: A


--Finished--
Summary information for domain myetherwaltet.com
-----------------------------------------

	Domain Ips Information:
		IP: 80.82.77.88
			HostName: ns4.libertyvps.net			Type: NS
			Country: Netherlands
		IP: 80.82.77.87
			HostName: ns3.libertyvps.net			Type: NS
			HostName: shark2.libertyvps.net			Type: PTR
			HostName: myetherwaltet.com			Type: MX
			HostName: www.myetherwaltet.com			Type: A
			HostName: ftp.myetherwaltet.com			Type: A
			HostName: mail.myetherwaltet.com			Type: A
			HostName: webmail.myetherwaltet.com			Type: A
			Country: Netherlands

--------------End  Summary --------------
-----------------------------------------

@409H
Copy link
Author

409H commented Sep 7, 2017

myethterwallet.co

Analysing domain : myethterwallet.co
	Output directory name: myethterwallet.co
	Output summary file: myethterwallet.co/myethterwallet.co.txt
	Checking NameServers using system default resolver...
		IP: 216.87.155.33 (United States)
			HostName: dns1.registrar-servers.com			Type: NS
			HostName: dns1.namecheaphosting.com			Type: PTR
		IP: 216.87.152.33 (United States)
			HostName: dns2.registrar-servers.com			Type: NS
			HostName: dns4.registrar-servers.com			Type: PTR

	Checking MailServers using system default resolver...
		IP: 162.255.118.61 (United States)
			HostName: eforward1.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
		IP: 162.255.118.62 (United States)
			HostName: eforward4.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
		IP: 162.255.118.62 (United States)
			HostName: eforward4.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
			HostName: eforward2.registrar-servers.com			Type: MX
		IP: 162.255.118.62 (United States)
			HostName: eforward4.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
			HostName: eforward2.registrar-servers.com			Type: MX
			HostName: eforward5.registrar-servers.com			Type: MX
		IP: 162.255.118.61 (United States)
			HostName: eforward1.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
			HostName: eforward3.registrar-servers.com			Type: MX

	Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
		No zone transfer found on nameserver 216.87.155.33
		No zone transfer found on nameserver 216.87.152.33

	Checking SPF record...

	Checking SPF record...
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 38.101.213.192/28, but only the network IP
		New IP found: 38.101.213.192
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 209.105.246.192/28, but only the network IP
		New IP found: 209.105.246.192
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 199.229.254.192/27, but only the network IP
		New IP found: 199.229.254.192
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 198.54.122.192/26, but only the network IP
		New IP found: 198.54.122.192
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 162.255.118.0/26, but only the network IP
		New IP found: 162.255.118.0
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 198.54.122.0/28, but only the network IP
		New IP found: 198.54.122.0
		WARNING! SPF record allows an entire network to send mails. Probably an ISP network. We are not going to check the entire network by now: 162.255.118.240/29, but only the network IP
		New IP found: 162.255.118.240

	Checking 192 most common hostnames using system default resolver...


--Finished--
Summary information for domain myethterwallet.co
-----------------------------------------

	Domain Ips Information:
		IP: 216.87.152.33
			HostName: dns2.registrar-servers.com			Type: NS
			HostName: dns4.registrar-servers.com			Type: PTR
			Country: United States
		IP: 162.255.118.62
			HostName: eforward4.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
			HostName: eforward2.registrar-servers.com			Type: MX
			HostName: eforward5.registrar-servers.com			Type: MX
			Country: United States
		IP: 162.255.118.61
			HostName: eforward1.registrar-servers.com			Type: MX
			HostName: eforward.web-hosting.com			Type: PTR
			HostName: eforward3.registrar-servers.com			Type: MX
			Country: United States
		IP: 199.229.254.192
			Type: SPF
		IP: 38.101.213.192
			Type: SPF
		IP: 162.255.118.240
			Type: SPF
		IP: 162.255.118.0
			Type: SPF
		IP: 198.54.122.192
			Type: SPF
		IP: 216.87.155.33
			HostName: dns1.registrar-servers.com			Type: NS
			HostName: dns1.namecheaphosting.com			Type: PTR
			Country: United States
		IP: 198.54.122.0
			Type: SPF
		IP: 209.105.246.192
			Type: SPF

--------------End  Summary --------------
-----------------------------------------

@409H
Copy link
Author

409H commented Sep 7, 2017

kirkik.com

Analysing domain : kirkik.com
	Output directory name: kirkik.com
	Output summary file: kirkik.com/kirkik.com.txt
	Checking NameServers using system default resolver...
			HostName: ns1.rivalhost.com			Type: NS
			HostName: ns2.rivalhost.com			Type: NS
			HostName: la10g001.rivalserver.com			Type: PTR

	Checking MailServers using system default resolver...
			HostName: kirkik.com			Type: MX

	Checking the zone transfer for each NS... (if this takes more than 10 seconds, just hit CTRL-C and it will continue. Bug in the libs)
		No zone transfer found on nameserver 191.101.26.67
		No zone transfer found on nameserver 45.63.62.195

	Checking SPF record...
		New IP found: 181.215.235.4

	Checking 192 most common hostnames using system default resolver...
			HostName: kirkik.com			Type: MX
			Type: SPF
			HostName: www.kirkik.com			Type: A
			HostName: kirkik.com			Type: MX
			Type: SPF
			HostName: www.kirkik.com			Type: A
			HostName: ftp.kirkik.com			Type: A
			HostName: kirkik.com			Type: MX
			Type: SPF
			HostName: www.kirkik.com			Type: A
			HostName: ftp.kirkik.com			Type: A
			HostName: mail.kirkik.com			Type: A


--Finished--
Summary information for domain kirkik.com
-----------------------------------------

	Domain Ips Information:
		IP: 191.101.26.67
			HostName: ns1.rivalhost.com			Type: NS
		IP: 45.63.62.195
			HostName: ns2.rivalhost.com			Type: NS
			HostName: la10g001.rivalserver.com			Type: PTR
		IP: 181.215.235.240
			HostName: kirkik.com			Type: MX
			Type: SPF
			HostName: www.kirkik.com			Type: A
			HostName: ftp.kirkik.com			Type: A
			HostName: mail.kirkik.com			Type: A
		IP: 181.215.235.4
			Type: SPF

--------------End  Summary --------------
-----------------------------------------

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment