CF1758639985873-tsm20250923150555

WWW.RTSAK.COM - malware.farm

Search for IP or hostnames:

malware.farm checked at 2025-09-23T15:06:25.865Z 251ms 138/138/138 100% R:14

malware.farm

MXmail.protonmail.ch
A176.119.200.128🇨🇭 Proton AG
PTRmail.protonmail.ch
A185.70.42.128🇨🇭 Proton AG
PTRmail.protonmail.ch
A185.205.70.128🇫🇷 Proton AG
PTRmail.protonmail.ch
MXmailsec.protonmail.ch
A176.119.200.129🇨🇭 Proton AG
PTRmailsec.protonmail.ch
A185.70.42.129🇨🇭 Proton AG
PTRmailsec.protonmail.ch
A185.205.70.129🇫🇷 Proton AG
PTRmailsec.protonmail.ch
NSns1.digitalocean.com
A2606:4700:52::ac40:34d2 🇺🇸 Cloudflare
PTRns1.digitalocean.com
A172.64.52.210🇺🇸 Cloudflare
PTRns1.digitalocean.com
NSns2.digitalocean.com
A2606:4700:5a::ac40:3515 🇺🇸 Cloudflare
PTRns2.digitalocean.com
A172.64.53.21🇺🇸 Cloudflare
PTRns2.digitalocean.com
NSns3.digitalocean.com
A2606:4700:52::ac40:31d1 🇺🇸 Cloudflare
PTRns3.digitalocean.com
A172.64.49.209🇺🇸 Cloudflare
PTRns3.digitalocean.com
A2606:50c0:8000::153 🇺🇸 Fastly
A2606:50c0:8001::153 🇺🇸 Fastly
A2606:50c0:8002::153 🇺🇸 Fastly
A2606:50c0:8003::153 🇺🇸 Fastly
A185.199.108.153🇺🇸 Fastly
PTRcdn-185-199-108-153.github.com
A185.199.109.153🇺🇸 Fastly
PTRcdn-185-199-109-153.github.com
A185.199.110.153🇺🇸 Fastly
PTRcdn-185-199-110-153.github.com
A185.199.111.153🇺🇸 Fastly
PTRcdn-185-199-111-153.github.com

farm

NSv0n0.nic.farm
NSv0n1.nic.farm
NSv0n2.nic.farm
NSv0n3.nic.farm
NSv2n0.nic.farm
NSv2n1.nic.farm

Starts with same word

Starts similarily

AI analysis

Eight IP numbers are pointed to by malware.farm: 2606:50c0:8000::153, 2606:50c0:8001::153, 2606:50c0:8002::153, 2606:50c0:8003::153, 185.199.108.153, 185.199.109.153, 185.199.110.153 and 185.199.111.153.

other host names include laravisma.com, chulminy.github.io, ruairigriffin.com, jacobwilliams.github.io and semind.github.io; they share IP numbers with malware.farm.

malware.farm is delegated to three name servers ns1.digitalocean.com, ns2.digitalocean.com and ns3.digitalocean.com.

malware.farm at least partially shares name servers with other domains, for instance myceschool.com, yonorenuncio.com, 226.170.107.in-addr.arpa, expandja.com and synappsehealth.com.

Host names with two IP numbers:

ns1.digitalocean.com points to 2606:4700:52::ac40:34d2 and 172.64.52.210; ns2.digitalocean.com points to 2606:4700:5a::ac40:3515 and 172.64.53.21; ns3.digitalocean.com points to 2606:4700:52::ac40:31d1 and 172.64.49.209.

malware.farm is handled by two mail servers: mail.protonmail.ch and mailsec.protonmail.ch.

malware.farm uses the same mail server setup as other domains, for instance sizer99.com, zahnarzt-drvogel-rosenheim.de, fahie.com, yemayasolutions.com and historykat.com.

malware.farm shares at least partially some mail servers with other domains, for instance pagefault.se, drygast.nu, celea.org, safe-mail.me and chaos.hu.

Host names with three IP numbers:

mail.protonmail.ch points to: 176.119.200.128, 185.70.42.128 and 185.205.70.128.

mailsec.protonmail.ch points to: 176.119.200.129, 185.70.42.129 and 185.205.70.129.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

nXsNtqs CF johedugfp 2025-09-23