CF1757295119539-tsm20250907181809

NSLIST.NET - malware.net

Search for IP or hostnames:

malware.net checked at 2025-09-08T01:31:59.523Z 151ms 114/114/114 100% R:12

malware.net

NSns15.domaincontrol.com
A2603:5:21b0::8 🇺🇸 GODADDY-DNS
PTRns15.domaincontrol.com
A97.74.107.8🇺🇸 GODADDY-DNS
PTRns15.domaincontrol.com
NSns16.domaincontrol.com
A2603:5:22b0::8 🇺🇸 GODADDY-DNS
PTRns16.domaincontrol.com
A173.201.75.8🇺🇸 GODADDY-DNS
PTRns16.domaincontrol.com
MXin1-smtp.messagingengine.com
A103.168.172.216🇺🇸 Cloudflare London
PTRphl-mx-01.messagingengine.com
A103.168.172.217🇺🇸 Cloudflare London
PTRphl-mx-02.messagingengine.com
A103.168.172.218🇺🇸 Cloudflare London
PTRphl-mx-03.messagingengine.com
A103.168.172.219🇺🇸 Cloudflare London
PTRphl-mx-04.messagingengine.com
A103.168.172.220🇺🇸 Cloudflare London
PTRphl-mx-05.messagingengine.com
A103.168.172.221🇺🇸 Cloudflare London
PTRphl-mx-06.messagingengine.com
A103.168.172.222🇺🇸 Cloudflare London
PTRphl-mx-07.messagingengine.com
A103.168.172.223🇺🇸 Cloudflare London
PTRphl-mx-08.messagingengine.com
MXin2-smtp.messagingengine.com
A202.12.124.216 AS5716
PTRstl-mx-01.messagingengine.com
A202.12.124.217 AS5716
PTRstl-mx-02.messagingengine.com
A23.21.157.88🇺🇸 Amazon
PTRec2-23-21-157-88.compute-1.amazonaws.com
A23.21.234.173🇺🇸 Amazon
PTRec2-23-21-234-173.compute-1.amazonaws.com

net

NSa.gtld-servers.net
NSb.gtld-servers.net
NSc.gtld-servers.net
NSd.gtld-servers.net
NSe.gtld-servers.net
NSf.gtld-servers.net
NSg.gtld-servers.net
NSh.gtld-servers.net
NSi.gtld-servers.net
NSj.gtld-servers.net
NSk.gtld-servers.net
NSl.gtld-servers.net
NSm.gtld-servers.net

AI analysis

malware.net is configured to point to two IP addresses: 23.21.157.88 and 23.21.234.173.

The IP numbers of malware.net are also shared by other host names such as cloud.coffee, xoscientific.com, imaginationresorts.com, sidehustlezine.com, and n43.me.

Two name servers, ns15.domaincontrol.com and ns16.domaincontrol.com, are delegated for malware.net.

The name server setup for malware.net is shared with other domains such as zasba.com, mega128.com, therapymatters.org, quick-cash.ca, and fairlytradedamericancoop.com.

ns15.domaincontrol.com and ns16.domaincontrol.com both point to two IP numbers each: 2603:5:21b0::8, 97.74.107.8 for ns15.domaincontrol.com and 2603:5:22b0::8, 173.201.75.8 for ns16.domaincontrol.com.

Two mail servers, in1-smtp.messagingengine.com and in2-smtp.messagingengine.com, are responsible for handling malware.net.

Like the domains potts.es, cc-lp.com, forthefree.com, camby.me, and ictus.dk, malware.net also has the same mail server setup.

Other domains such as dailyzen.com and uithack.no share at least some mail servers with malware.net.

in1-smtp.messagingengine.com is configured to point to eight IP numbers: 103.168.172.216, 103.168.172.217, 103.168.172.218, 103.168.172.219, 103.168.172.220, 103.168.172.221, 103.168.172.222, and 103.168.172.223.

Similarly, in2-smtp.messagingengine.com is set to point to two IP numbers: 202.12.124.216 and 202.12.124.217.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

tHgfxEA CF johedugfp 2025-09-08