CF1764301337542-tsm20251127221307

DNSWHOIS.INFO - malware.us-cert.gov

Search for IP or hostnames:

malware.us-cert.gov checked at 2025-11-28T03:42:17.525Z 264ms 170/170/170 100% R:11 allDone:true timedOut:false

malware.us-cert.gov

NSgold.foundationdns.com
A2606:4700:57::6ca2:c602 πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.com
A2803:f800:52::a29f:3c02 πŸ‡¨πŸ‡· Cloudflare
PTRgold.foundationdns.com
A2a06:98c1:56::ac40:2802 πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.com
A108.162.198.2πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.com
A162.159.60.2 Cloudflare
PTRgold.foundationdns.com
A172.64.40.2πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.com
NSgold.foundationdns.net
A2606:4700:57::6ca2:c620 πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.net
A2803:f800:52::a29f:3c20 πŸ‡¨πŸ‡· Cloudflare
PTRgold.foundationdns.net
A2a06:98c1:56::ac40:2820 πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.net
A108.162.198.32πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.net
A162.159.60.32 Cloudflare
PTRgold.foundationdns.net
A172.64.40.32πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.net
NSgold.foundationdns.org
A2606:4700:57::6ca2:c63e πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.org
A2803:f800:52::a29f:3c3e πŸ‡¨πŸ‡· Cloudflare
PTRgold.foundationdns.org
A2a06:98c1:56::ac40:283e πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.org
A108.162.198.62πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.org
A162.159.60.62 Cloudflare
PTRgold.foundationdns.org
A172.64.40.62πŸ‡ΊπŸ‡Έ Cloudflare
PTRgold.foundationdns.org
MXinbound-smtp.us-east-1.amazonaws.com
A3.211.210.226πŸ‡ΊπŸ‡Έ Amazon
PTRec2-3-211-210-226.compute-1.amazonaws.com
A44.206.9.87πŸ‡ΊπŸ‡Έ Amazon
PTRec2-44-206-9-87.compute-1.amazonaws.com
A44.210.166.32πŸ‡ΊπŸ‡Έ Amazon
PTRec2-44-210-166-32.compute-1.amazonaws.com
A54.164.173.191πŸ‡ΊπŸ‡Έ Amazon
PTRec2-54-164-173-191.compute-1.amazonaws.com
A54.197.5.236πŸ‡ΊπŸ‡Έ Amazon
PTRec2-54-197-5-236.compute-1.amazonaws.com
A2600:1408:c400:982::1955 πŸ‡ΊπŸ‡Έ AKAMAI-ASN1
PTRg2600-1408-c400-0982-0000-0000-0000-1955.deploy.static.akamaitechnologies.com
A2600:1408:c400:983::1955 πŸ‡ΊπŸ‡Έ AKAMAI-ASN1
PTRg2600-1408-c400-0983-0000-0000-0000-1955.deploy.static.akamaitechnologies.com
A23.54.221.71πŸ‡ΊπŸ‡Έ Akamai
PTRa23-54-221-71.deploy.static.akamaitechnologies.com

us-cert.gov

NSblue.foundationdns.com
NSblue.foundationdns.net
NSblue.foundationdns.org
A2600:1408:c400:982::1955 πŸ‡ΊπŸ‡Έ AKAMAI-ASN1
A2600:1408:c400:983::1955 πŸ‡ΊπŸ‡Έ AKAMAI-ASN1
A184.25.37.253πŸ‡ΊπŸ‡Έ Akamai
rank #4313 globally
rank #167 in the tld

Up

Starts with same word

Starts similarily

AI analysis

malware.us-cert.gov is parent of mail.malware.us-cert.gov, www.malware.us-cert.gov and ftp.malware.us-cert.gov.

Three IP numbers for malware.us-cert.gov are 2600:1408:c400:982::1955, 2600:1408:c400:983::1955 and 23.54.221.71.

Other host names such as a23-54-221-71.deploy.static.akamaitechnologies.com and g2600-1408-c400-0982-0000-0000-0000-1955.deploy.static.akamaitechnologies.com share IP numbers with malware.us-cert.gov.

malware.us-cert.gov is delegated to three name servers: gold.foundationdns.com, gold.foundationdns.net and gold.foundationdns.org.

malware.us-cert.gov at least partially shares its name servers with other domains, for instance micromotion.com, fixconnect.emx.co.uk, shopifysvc.com, elections.maryland.gov and senate.state.md.us.

Host names with six IP numbers:

gold.foundationdns.com has IPs 2606:4700:57::6ca2:c602, 2803:f800:52::a29f:3c02, 2a06:98c1:56::ac40:2802, 108.162.198.2, 162.159.60.2 and 172.64.40.2.

gold.foundationdns.net has IPs 2606:4700:57::6ca2:c620, 2803:f800:52::a29f:3c20, 2a06:98c1:56::ac40:2820, 108.162.198.32, 162.159.60.32 and 172.64.40.32.

gold.foundationdns.org has IPs 2606:4700:57::6ca2:c63e, 2803:f800:52::a29f:3c3e, 2a06:98c1:56::ac40:283e, 108.162.198.62, 162.159.60.62 and 172.64.40.62.

malware.us-cert.gov is served by a single mail server, inbound-smtp.us-east-1.amazonaws.com.

malware.us-cert.gov uses the same mail server setup as other domains such as xapi.ly, myfxmarkets.com, dcita.edu, taosconsulting.slack.com and domrachev.slack.com.

malware.us-cert.gov shares some mail servers with other domains, including combcomm.atlassian.net, transpais.com.mx, quedro.atlassian.net, sidus.link and royalmobile.atlassian.net.

these mail servers are commonly used with the mail servers inbound-smtp.us-west-2.amazonaws.com, aspmx.l.google.com, alt1.aspmx.l.google.com, alt2.aspmx.l.google.com, alt3.aspmx.l.google.com and alt4.aspmx.l.google.com.

Host inbound-smtp.us-east-1.amazonaws.com resolves to five IP numbers: 3.211.210.226, 44.206.9.87, 44.210.166.32, 54.164.173.191 and 54.197.5.236.