CF1761373551122-tsm20251024211356

MXLIST.NET - malware.farm

Search for IP or hostnames:

malware.farm checked at 2025-10-25T06:25:51.102Z 263ms 138/138/138 100% R:12

malware.farm

MXmail.protonmail.ch
A176.119.200.128๐Ÿ‡จ๐Ÿ‡ญ Proton AG
PTRmail.protonmail.ch
A185.70.42.128๐Ÿ‡จ๐Ÿ‡ญ Proton AG
PTRmail.protonmail.ch
A185.205.70.128๐Ÿ‡ซ๐Ÿ‡ท Proton AG
PTRmail.protonmail.ch
MXmailsec.protonmail.ch
A176.119.200.129๐Ÿ‡จ๐Ÿ‡ญ Proton AG
PTRmailsec.protonmail.ch
A185.70.42.129๐Ÿ‡จ๐Ÿ‡ญ Proton AG
PTRmailsec.protonmail.ch
A185.205.70.129๐Ÿ‡ซ๐Ÿ‡ท Proton AG
PTRmailsec.protonmail.ch
NSns1.digitalocean.com
A2606:4700:52::ac40:34d2 ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRns1.digitalocean.com
A172.64.52.210๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRns1.digitalocean.com
NSns2.digitalocean.com
A2606:4700:5a::ac40:3515 ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRns2.digitalocean.com
A172.64.53.21๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRns2.digitalocean.com
NSns3.digitalocean.com
A2606:4700:52::ac40:31d1 ๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRns3.digitalocean.com
A172.64.49.209๐Ÿ‡บ๐Ÿ‡ธ Cloudflare
PTRns3.digitalocean.com
A2606:50c0:8000::153 ๐Ÿ‡บ๐Ÿ‡ธ Fastly
A2606:50c0:8001::153 ๐Ÿ‡บ๐Ÿ‡ธ Fastly
A2606:50c0:8002::153 ๐Ÿ‡บ๐Ÿ‡ธ Fastly
A2606:50c0:8003::153 ๐Ÿ‡บ๐Ÿ‡ธ Fastly
A185.199.108.153๐Ÿ‡บ๐Ÿ‡ธ Fastly
PTRcdn-185-199-108-153.github.com
A185.199.109.153๐Ÿ‡บ๐Ÿ‡ธ Fastly
PTRcdn-185-199-109-153.github.com
A185.199.110.153๐Ÿ‡บ๐Ÿ‡ธ Fastly
PTRcdn-185-199-110-153.github.com
A185.199.111.153๐Ÿ‡บ๐Ÿ‡ธ Fastly
PTRcdn-185-199-111-153.github.com

farm

NSv0n0.nic.farm
NSv0n1.nic.farm
NSv0n2.nic.farm
NSv0n3.nic.farm
NSv2n0.nic.farm
NSv2n1.nic.farm

Starts with same word

Starts similarily

AI analysis

Eight IP numbers are pointed to by malware.farm: 2606:50c0:8000::153, 2606:50c0:8001::153, 2606:50c0:8002::153, 2606:50c0:8003::153, 185.199.108.153, 185.199.109.153, 185.199.110.153 and 185.199.111.153.

other host names for instance laravisma.com, chulminy.github.io, ruairigriffin.com, jacobwilliams.github.io and semind.github.io share IP numbers with malware.farm.

malware.farm is delegated to three name servers: ns1.digitalocean.com, ns2.digitalocean.com and ns3.digitalocean.com.

malware.farm at least partially shares name servers with other domains, for instance myceschool.com, yonorenuncio.com, 226.170.107.in-addr.arpa, expandja.com and synappsehealth.com.

Host names with two IP numbers:

Host ns1.digitalocean.com points to 2606:4700:52::ac40:34d2 and 172.64.52.210.

Host ns2.digitalocean.com points to 2606:4700:5a::ac40:3515 and 172.64.53.21.

Host ns3.digitalocean.com points to 2606:4700:52::ac40:31d1 and 172.64.49.209.

malware.farm is handled by two mail servers: mail.protonmail.ch and mailsec.protonmail.ch.

malware.farm shares the same mail server setup as other domains, for instance sizer99.com, zahnarzt-drvogel-rosenheim.de, fahie.com, yemayasolutions.com and historykat.com.

malware.farm shares mail servers with other domains at least partially, including pagefault.se, drygast.nu, celea.org, safe-mail.me and chaos.hu.

Host names with three IP numbers:

mail.protonmail.ch points to: 176.119.200.128, 185.70.42.128 and 185.205.70.128.

mailsec.protonmail.ch points to: 176.119.200.129, 185.70.42.129 and 185.205.70.129.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

iemIdGB CF johedugfp 2025-10-25