CF1761679295612-tsm20251027103946

NSLIST.NET - malware.us-cert.gov

Search for IP or hostnames:

malware.us-cert.gov checked at 2025-10-28T19:21:35.596Z 360ms 170/170/170 100% R:15

malware.us-cert.gov

NSgold.foundationdns.com
A2606:4700:57::6ca2:c602 πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.com
A2803:f800:52::a29f:3c02 πŸ‡¨πŸ‡· Cloudflare
PTRgold.foundationdns.com
A2a06:98c1:56::ac40:2802 πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.com
A108.162.198.2πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.com
A162.159.60.2 Cloudflare
PTRgold.foundationdns.com
A172.64.40.2πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.com
NSgold.foundationdns.net
A2606:4700:57::6ca2:c620 πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.net
A2803:f800:52::a29f:3c20 πŸ‡¨πŸ‡· Cloudflare
PTRgold.foundationdns.net
A2a06:98c1:56::ac40:2820 πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.net
A108.162.198.32πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.net
A162.159.60.32 Cloudflare
PTRgold.foundationdns.net
A172.64.40.32πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.net
NSgold.foundationdns.org
A2606:4700:57::6ca2:c63e πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.org
A2803:f800:52::a29f:3c3e πŸ‡¨πŸ‡· Cloudflare
PTRgold.foundationdns.org
A2a06:98c1:56::ac40:283e πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.org
A108.162.198.62πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.org
A162.159.60.62 Cloudflare
PTRgold.foundationdns.org
A172.64.40.62πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.org
MXinbound-smtp.us-east-1.amazonaws.com
A3.211.210.226πŸ‡ΊπŸ‡Έ Amazon
PTRec2-3-211-210-226.compute-1.amazonaws.com
A44.206.9.87πŸ‡ΊπŸ‡Έ Amazon
PTRec2-44-206-9-87.compute-1.amazonaws.com
A44.210.166.32πŸ‡ΊπŸ‡Έ Amazon
PTRec2-44-210-166-32.compute-1.amazonaws.com
A54.164.173.191πŸ‡ΊπŸ‡Έ Amazon
PTRec2-54-164-173-191.compute-1.amazonaws.com
A54.197.5.236πŸ‡ΊπŸ‡Έ Amazon
PTRec2-54-197-5-236.compute-1.amazonaws.com
A2600:1408:c400:138d::1955 πŸ‡ΊπŸ‡Έ AKAMAI-ASN1
PTRg2600-1408-c400-138d-0000-0000-0000-1955.deploy.static.akamaitechnologies.com
A2600:1408:c400:1393::1955 πŸ‡ΊπŸ‡Έ AKAMAI-ASN1
PTRg2600-1408-c400-1393-0000-0000-0000-1955.deploy.static.akamaitechnologies.com
A23.204.213.105πŸ‡¦πŸ‡Ί Akamai
PTRa23-204-213-105.deploy.static.akamaitechnologies.com

us-cert.gov

NSblue.foundationdns.com
NSblue.foundationdns.net
NSblue.foundationdns.org
A2600:1408:c400:389::1955 πŸ‡ΊπŸ‡Έ AKAMAI-ASN1
A2600:1408:c400:38a::1955 πŸ‡ΊπŸ‡Έ AKAMAI-ASN1
A23.204.213.105πŸ‡¦πŸ‡Ί Akamai
rank #4313 globally
rank #167 in the tld

Up

Starts with same word

Starts similarily

AI analysis

malware.us-cert.gov is a parent of mail.malware.us-cert.gov, www.malware.us-cert.gov and ftp.malware.us-cert.gov.

malware.us-cert.gov points to IPs: 2600:1408:c400:138d::1955, 2600:1408:c400:1393::1955 and 23.204.213.105.

Other host names for instance homelandsecurity.gov and a23-204-213-105.deploy.static.akamaitechnologies.com share IP numbers with malware.us-cert.gov.

malware.us-cert.gov is delegated to name servers gold.foundationdns.com, gold.foundationdns.net and gold.foundationdns.org.

malware.us-cert.gov at least partially shares name servers with other domains such as micromotion.com, fixconnect.emx.co.uk, shopifysvc.com, elections.maryland.gov and senate.state.md.us.

Host names with six IP numbers:

gold.foundationdns.com points to: 2606:4700:57::6ca2:c602, 2803:f800:52::a29f:3c02, 2a06:98c1:56::ac40:2802, 108.162.198.2, 162.159.60.2 and 172.64.40.2.

gold.foundationdns.net points to: 2606:4700:57::6ca2:c620, 2803:f800:52::a29f:3c20, 2a06:98c1:56::ac40:2820, 108.162.198.32, 162.159.60.32 and 172.64.40.32.

gold.foundationdns.org points to: 2606:4700:57::6ca2:c63e, 2803:f800:52::a29f:3c3e, 2a06:98c1:56::ac40:283e, 108.162.198.62, 162.159.60.62 and 172.64.40.62.

malware.us-cert.gov is handled by a single mail server, inbound-smtp.us-east-1.amazonaws.com.

malware.us-cert.gov shares the same mail server setup as other domains, including xapi.ly, myfxmarkets.com, dcita.edu, taosconsulting.slack.com and domrachev.slack.com.

malware.us-cert.gov shares mail servers with other domains at least in part, for instance combcomm.atlassian.net, transpais.com.mx, quedro.atlassian.net, sidus.link and royalmobile.atlassian.net.

These mail servers are commonly used alongside inbound-smtp.us-west-2.amazonaws.com, aspmx.l.google.com, alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, alt3.aspmx.l.google.com and alt4.aspmx.l.google.com.

The host name inbound-smtp.us-east-1.amazonaws.com points to five IP numbers: 3.211.210.226, 44.206.9.87, 44.210.166.32, 54.164.173.191 and 54.197.5.236.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

zlfUqTe CF johedugfp 2025-10-28