CF1761944335891-tsm20251029173950

WWW.RTSAK.COM - russianmalware.com

Search for IP or hostnames:

russianmalware.com checked at 2025-10-31T20:58:55.787Z 1165ms 105/105/105 100% R:14

russianmalware.com

NSns-40.awsdns-05.com
A2600:9000:5300:2800::1 🇺🇸 Amazon
PTRns-40.awsdns-05.com
A205.251.192.40🇺🇸 Amazon
PTRns-40.awsdns-05.com
NSns-608.awsdns-12.net
A2600:9000:5302:6000::1 🇺🇸 Amazon
PTRns-608.awsdns-12.net
A205.251.194.96🇺🇸 Amazon
PTRns-608.awsdns-12.net
NSns-1104.awsdns-10.org
A2600:9000:5304:5000::1 🇺🇸 Amazon
PTRns-1104.awsdns-10.org
A205.251.196.80🇺🇸 Amazon
PTRns-1104.awsdns-10.org
NSns-1705.awsdns-21.co.uk
A2600:9000:5306:a900::1 🇺🇸 Amazon
PTRns-1705.awsdns-21.co.uk
A205.251.198.169🇺🇸 Amazon
PTRns-1705.awsdns-21.co.uk
MXrussianmalware-com.mail.protection.outlook.com
A2a01:111:f403:c803:: 🇺🇸 Microsoft
PTRmail-bn1pr21cu00200.inbound.protection.outlook.com
A2a01:111:f403:c922::2 🇺🇸 Microsoft
PTRmail-bl0pr02cu00702.inbound.protection.outlook.com
A2a01:111:f403:c92c:: 🇺🇸 Microsoft
PTRmail-dm5pr02cu00100.inbound.protection.outlook.com
A2a01:111:f403:f805::1 🇺🇸 Microsoft
PTRmail-co1pr03cu00301.inbound.protection.outlook.com
A52.101.9.2🇺🇸 Microsoft
PTRmail-mn2pr02cu00202.inbound.protection.outlook.com
A52.101.10.5🇺🇸 Microsoft
PTRmail-bn6pr04cu00105.inbound.protection.outlook.com
A52.101.11.2🇺🇸 Microsoft
PTRmail-sn1pr03cu00102.inbound.protection.outlook.com
A52.101.194.13🇺🇸 Microsoft
PTRmail-ch0pr04cu00605.inbound.protection.outlook.com

com

NSa.gtld-servers.net
NSb.gtld-servers.net
NSc.gtld-servers.net
NSd.gtld-servers.net
NSe.gtld-servers.net
NSf.gtld-servers.net
NSg.gtld-servers.net
NSh.gtld-servers.net
NSi.gtld-servers.net
NSj.gtld-servers.net
NSk.gtld-servers.net
NSl.gtld-servers.net
NSm.gtld-servers.net

Starts with same word

Starts similarily

AI analysis

russianmalware.com delegates to four name servers: ns-40.awsdns-05.com, ns-608.awsdns-12.net, ns-1104.awsdns-10.org and ns-1705.awsdns-21.co.uk.

russianmalware.com at least partially shares name servers with other domains, including d25iu6foaj00gh.cloudfront.net, egeappliances.com, collegely.io, murabahasaleplatform.com and carissbrain.jp.

these name servers are commonly used alongside the name servers ns-1465.awsdns-55.org, ns-1763.awsdns-28.co.uk, ns-1498.awsdns-59.org, ns-964.awsdns-56.net and ns-1199.awsdns-21.org.

Host names with two IP numbers: ns-40.awsdns-05.com points to 2600:9000:5300:2800::1 and 205.251.192.40; ns-608.awsdns-12.net points to 2600:9000:5302:6000::1 and 205.251.194.96; ns-1104.awsdns-10.org points to 2600:9000:5304:5000::1 and 205.251.196.80; ns-1705.awsdns-21.co.uk points to 2600:9000:5306:a900::1 and 205.251.198.169.

A single mail server handles russianmalware.com, russianmalware-com.mail.protection.outlook.com.

Host russianmalware-com.mail.protection.outlook.com points to eight IPs: 2a01:111:f403:c803::, 2a01:111:f403:c922::2, 2a01:111:f403:c92c::, 2a01:111:f403:f805::1, 52.101.9.2, 52.101.10.5, 52.101.11.2 and 52.101.194.13.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

nXORasa CF johedugfp 2025-10-31