12 INTELSAT-IN.car1.NewYork1.Level3.net (64.156.82.14) 127.129 ms 121.898 ms 121.857 ms
13 209.159.170.215 (209.159.170.215) 214.763 ms 196.291 ms 210.602 ms
14 202.72.96.6 (202.72.96.6) 697.258 ms 711.336 ms 693.061 ms
15 175.45.177.217 (175.45.177.217) 696.368 ms 699.046 ms 702.013 ms
175.45.177.217 Seems to be an actual IP in NK[0] 'copyright': 'For use only by clients authorized in writing by IMDb. Authors and users of unauthorized clients accept full legal exposure/liability for their actions.'
as part of the json with every request made.
As far as I've been able to research, these typesquatting domain traps started at the same time as Spamhaus CSS blacklist which was actually a company called Deteque.
If the MX has a large number of Hetzner IPs as mailservers, then it's probably Spamhaus.