CF1759783380334-tsm20251005211530

WWW.ROBTEX.COM - malware.win

Search for IP or hostnames:

malware.win checked at 2025-10-06T20:43:00.307Z 1227ms 121/121/121 100% R:17

malware.win

NSdns1.registrar-servers.com
A2610:a1:1024::200🇺🇸 Neustar
PTRdns1.namecheaphosting.com
PTRdns1.registrar-servers.com
A156.154.132.200🇺🇸 Neustar
PTRdns1.namecheaphosting.com
PTRdns1.registrar-servers.com
NSdns2.registrar-servers.com
A2610:a1:1025::200🇺🇸 Neustar
PTRdns2.namecheaphosting.com
PTRdns2.registrar-servers.com
A156.154.133.200🇺🇸 Neustar
PTRdns2.namecheaphosting.com
PTRdns2.registrar-servers.com
MXmail.sicher.me
Afe80::9400:ff:fe30:7682
A116.203.104.172🇩🇪 Hetzner
PTRmail.sicher.me
Afe80::9400:ff:fe30:7682
A116.203.104.172🇩🇪 Hetzner
PTRmail.sicher.me

win

NSa.nic.win
NSb.nic.win
NSc.nic.win
NSns1.dns.nic.win
NSns2.dns.nic.win
NSns3.dns.nic.win

Starts with same word

Starts similarily

AI analysis

malware.win resolves to two IP numbers: fe80::9400:ff:fe30:7682 and 116.203.104.172.

Other host names such as sicher.me and mail.sicher.me share IP numbers with malware.win.

malware.win is delegated to two name servers dns1.registrar-servers.com and dns2.registrar-servers.com.

malware.win shares the same name server setup as other domains, for instance blockchainatberkeley.blog, robveres.com, patapon-game.com, packetexpress.net and velop.me.

malware.win at least partially shares name servers with other domains, for instance nerd.supply, mbpeters.com, rodmantech.co, domethunder.com and bcnpool.com.

These name servers are commonly used with dns3.registrar-servers.com, dns4.registrar-servers.com and dns5.registrar-servers.com.

Host names with two IP numbers:

The host name dns1.registrar-servers.com points to 2610:a1:1024::200 and 156.154.132.200; the host name dns2.registrar-servers.com points to 2610:a1:1025::200 and 156.154.133.200.

malware.win is handled by a single mail server, mail.sicher.me.

malware.win shares the same mail server setup as other domains, for instance sicher.me.

mail.sicher.me resolves to two IP numbers: fe80::9400:ff:fe30:7682 and 116.203.104.172.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

hDxAWSO CF johedugfp 2025-10-06