CF1760792143458-tsm20251017082432

MXLIST.NET - worm.sh

Search for IP or hostnames:

worm.sh checked at 2025-10-18T12:55:43.411Z 1215ms 117/117/117 100% R:10

worm.sh

MXmx1.improvmx.com
A2a05:d012:412:e201:88aa:e7b9:7a43:12d7 πŸ‡«πŸ‡· Amazon
A2a05:d012:412:e202:f36:2c1f:1a49:d38a πŸ‡«πŸ‡· Amazon
A2a05:d012:412:e203:373a:f51a:4a85:1d25 πŸ‡«πŸ‡· Amazon
A13.37.195.136πŸ‡«πŸ‡· Amazon
PTRec2-13-37-195-136.eu-west-3.compute.amazonaws.com
A15.236.236.160πŸ‡«πŸ‡· Amazon
PTRec2-15-236-236-160.eu-west-3.compute.amazonaws.com
A35.181.18.45πŸ‡«πŸ‡· Amazon
PTRec2-35-181-18-45.eu-west-3.compute.amazonaws.com
MXmx2.improvmx.com
A2a05:d012:412:e201:1f6e:f6e4:8fd7:4678 πŸ‡«πŸ‡· Amazon
A2a05:d012:412:e202:e81e:cc44:3b53:8a3d πŸ‡«πŸ‡· Amazon
A2a05:d012:412:e203:7e33:3d9c:28d7:ee20 πŸ‡«πŸ‡· Amazon
A13.36.107.63πŸ‡«πŸ‡· Amazon
PTRec2-13-36-107-63.eu-west-3.compute.amazonaws.com
A13.36.222.39πŸ‡«πŸ‡· Amazon
PTRec2-13-36-222-39.eu-west-3.compute.amazonaws.com
A15.236.61.92πŸ‡«πŸ‡· Amazon
PTRec2-15-236-61-92.eu-west-3.compute.amazonaws.com
NSdns1.registrar-servers.com
A2610:a1:1024::200 πŸ‡ΊπŸ‡Έ Neustar
PTRdns1.namecheaphosting.com
PTRdns1.registrar-servers.com
A156.154.132.200πŸ‡ΊπŸ‡Έ Neustar
PTRdns1.namecheaphosting.com
PTRdns1.registrar-servers.com
NSdns2.registrar-servers.com
A2610:a1:1025::200 πŸ‡ΊπŸ‡Έ Neustar
PTRdns2.namecheaphosting.com
PTRdns2.registrar-servers.com
A156.154.133.200πŸ‡ΊπŸ‡Έ Neustar
PTRdns2.namecheaphosting.com
PTRdns2.registrar-servers.com
A34.61.160.136πŸ‡ΊπŸ‡Έ Google
PTR136.160.61.34.bc.googleusercontent.com

sh

NSa0.nic.sh
NSa2.nic.sh
NSb0.nic.sh
NSc0.nic.sh

Starts with same word

Starts similarily

AI analysis

worm.sh points to a single IP number: 34.61.160.136.

worm.sh is delegated to two name servers: dns1.registrar-servers.com and dns2.registrar-servers.com.

worm.sh shares the same name server setup as other domains, for example jteus.org, pickaxis.net, xnxx.website, atmcache.com and boardpeel.com.

worm.sh at least partially shares its name servers with other domains, for instance codegreen.us.

Host names with two IP numbers:

dns1.registrar-servers.com points to 2610:a1:1024::200 and 156.154.132.200

dns2.registrar-servers.com points to 2610:a1:1025::200 and 156.154.133.200

worm.sh is handled by two mail servers: mx1.improvmx.com and mx2.improvmx.com.

worm.sh shares the same mail server setup as other domains, for instance itstudio.ca, mountkelvin.com, cafda.org, byutv.org and glenfair.com.

worm.sh shares some mail servers with other domains at least partially, for example lyziane.com.

Host names with six IP numbers:

mx1.improvmx.com points to: 2a05:d012:412:e201:88aa:e7b9:7a43:12d7, 2a05:d012:412:e202:f36:2c1f:1a49:d38a, 2a05:d012:412:e203:373a:f51a:4a85:1d25, 13.37.195.136, 15.236.236.160 and 35.181.18.45; mx2.improvmx.com points to: 2a05:d012:412:e201:1f6e:f6e4:8fd7:4678, 2a05:d012:412:e202:e81e:cc44:3b53:8a3d, 2a05:d012:412:e203:7e33:3d9c:28d7:ee20, 13.36.107.63, 13.36.222.39 and 15.236.61.92.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

BDbrhYV CF johedugfp 2025-10-18