CF1758495100489-tsm20250921191912

WWW.RTSAK.COM - malware.exchange

Search for IP or hostnames:

malware.exchange checked at 2025-09-21T22:51:40.472Z 183ms 98/98/98 100% R:10

malware.exchange

NSns11.domaincontrol.com
A2603:5:2190::6 🇺🇸 GODADDY-DNS
PTRns11.domaincontrol.com
A97.74.105.6🇺🇸 GODADDY-DNS
PTRns11.domaincontrol.com
NSns12.domaincontrol.com
A2603:5:2290::6 🇺🇸 GODADDY-DNS
PTRns12.domaincontrol.com
A173.201.73.6🇺🇸 GODADDY-DNS
PTRns12.domaincontrol.com
MXmailstore1.secureserver.net
A216.69.141.78🇺🇸 AS398101
PTRosplibsmtp01-v02.prod.phx3.secureserver.net
A216.69.141.114🇺🇸 AS398101
PTRosplibsmtp03-v02.prod.phx3.secureserver.net
A216.69.141.162🇺🇸 AS398101
PTRosplibsmtp02-v02.prod.phx3.secureserver.net
MXsmtp.secureserver.net
A216.69.141.71🇺🇸 AS398101
PTRosplibsmtp01-v01.prod.phx3.secureserver.net
A216.69.141.84🇺🇸 AS398101
PTRosplibsmtp02-v01.prod.phx3.secureserver.net
A216.69.141.113🇺🇸 AS398101
PTRosplibsmtp03-v01.prod.phx3.secureserver.net
A3.33.130.190🇺🇸 Amazon
PTRa2aa9ff50de748dbe.awsglobalaccelerator.com
A15.197.148.33🇺🇸 Amazon
PTRa2aa9ff50de748dbe.awsglobalaccelerator.com

exchange

NSv0n0.nic.exchange
NSv0n1.nic.exchange
NSv0n2.nic.exchange
NSv0n3.nic.exchange
NSv2n0.nic.exchange
NSv2n1.nic.exchange

Starts with same word

Starts similarily

AI analysis

malware.exchange points to two IP numbers: 3.33.130.190 and 15.197.148.33.

Other host names, for instance gcl.cc, fatipadi.com, ifurnishyourhome.com, hylamax.com and mockmyworld.com share IP numbers with malware.exchange.

malware.exchange's delegation is to two name servers ns11.domaincontrol.com and ns12.domaincontrol.com.

malware.exchange shares the same name server configuration as other domains, such as danburycremation.org, stickers4all.com, anteplisham.com, catastrophevolunteers.com and luxuryrealty-lajolla.com.

Host names with two IP numbers: ns11.domaincontrol.com points to 2603:5:2190::6 and 97.74.105.6; ns12.domaincontrol.com points to 2603:5:2290::6 and 173.201.73.6

Two mail servers mailstore1.secureserver.net and smtp.secureserver.net handle malware.exchange.

malware.exchange uses the same mail server setup as other domains such as capecodart.com, pauva.com, cannatoob.com, wwrepo.com and autoaids.com.

malware.exchange shares some mail servers with other domains at least partially, for example convert-to-3d.com.

Host names with three IP numbers

The host name mailstore1.secureserver.net points to 216.69.141.78, 216.69.141.114 and 216.69.141.162; the host name smtp.secureserver.net points to 216.69.141.71, 216.69.141.84 and 216.69.141.113

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

RMVjLtC CF johedugfp 2025-09-21