All I know, is that “ipvolume.net” is a known problem (AS202425), and currently being blocked by various blacklists, currently being hosted at Incrediserve Ltd (Netherlands or UK, not sure).
What is interesting, is their MX domain points to an IP being used by:
– ecatel.info (https://korea-dpr.com)
– ecatel.net (https://korea-dpr.com)
– incrediserve.net
– ipvolume.net
– sunsetnet.io
Also, novogara.com seems to be redirecting via a Russian front.
Have fun with your investigation