CF1759720016138-tsm20251005211530

DNSWHOIS.INFO - worm.sh

Search for IP or hostnames:

worm.sh checked at 2025-10-06T03:06:56.122Z 159ms 117/117/117 100% R:13

worm.sh

MXmx1.improvmx.com
A2a05:d012:412:e201:88aa:e7b9:7a43:12d7 🇫🇷 Amazon
A2a05:d012:412:e202:f36:2c1f:1a49:d38a 🇫🇷 Amazon
A2a05:d012:412:e203:373a:f51a:4a85:1d25 🇫🇷 Amazon
A13.37.195.136🇫🇷 Amazon
PTRec2-13-37-195-136.eu-west-3.compute.amazonaws.com
A15.236.236.160🇫🇷 Amazon
PTRec2-15-236-236-160.eu-west-3.compute.amazonaws.com
A35.181.18.45🇫🇷 Amazon
PTRec2-35-181-18-45.eu-west-3.compute.amazonaws.com
MXmx2.improvmx.com
A2a05:d012:412:e201:1f6e:f6e4:8fd7:4678 🇫🇷 Amazon
A2a05:d012:412:e202:e81e:cc44:3b53:8a3d 🇫🇷 Amazon
A2a05:d012:412:e203:7e33:3d9c:28d7:ee20 🇫🇷 Amazon
A13.36.107.63🇫🇷 Amazon
PTRec2-13-36-107-63.eu-west-3.compute.amazonaws.com
A13.36.222.39🇫🇷 Amazon
PTRec2-13-36-222-39.eu-west-3.compute.amazonaws.com
A15.236.61.92🇫🇷 Amazon
PTRec2-15-236-61-92.eu-west-3.compute.amazonaws.com
NSdns1.registrar-servers.com
A2610:a1:1024::200 🇺🇸 Neustar
PTRdns1.namecheaphosting.com
PTRdns1.registrar-servers.com
A156.154.132.200🇺🇸 Neustar
PTRdns1.namecheaphosting.com
PTRdns1.registrar-servers.com
NSdns2.registrar-servers.com
A2610:a1:1025::200 🇺🇸 Neustar
PTRdns2.namecheaphosting.com
PTRdns2.registrar-servers.com
A156.154.133.200🇺🇸 Neustar
PTRdns2.namecheaphosting.com
PTRdns2.registrar-servers.com
A34.61.160.136🇺🇸 Google
PTR136.160.61.34.bc.googleusercontent.com

sh

NSa0.nic.sh
NSa2.nic.sh
NSb0.nic.sh
NSc0.nic.sh

Starts with same word

Starts similarily

AI analysis

worm.sh points to a single IP number: 34.61.160.136.

Delegation for worm.sh rests with two name servers, dns1.registrar-servers.com and dns2.registrar-servers.com.

worm.sh shares the same name server setup as other domains, including jteus.org, pickaxis.net, xnxx.website, atmcache.com and boardpeel.com.

worm.sh shares name servers with other domains at least partially, for example codegreen.us.

Host names with two IP numbers: dns1.registrar-servers.com points to 2610:a1:1024::200 and 156.154.132.200; dns2.registrar-servers.com points to 2610:a1:1025::200 and 156.154.133.200.

worm.sh is handled by two mail servers: mx1.improvmx.com and mx2.improvmx.com.

worm.sh uses the same mail server configuration as other domains, such as mountkelvin.com, cafda.org, byutv.org, glenfair.com and pimyapi.com.

worm.sh shares some mail servers with other domains at least partially, for example lyziane.com.

Host names with six IP numbers: mx1.improvmx.com points to: 2a05:d012:412:e201:88aa:e7b9:7a43:12d7, 2a05:d012:412:e202:f36:2c1f:1a49:d38a, 2a05:d012:412:e203:373a:f51a:4a85:1d25, 13.37.195.136, 15.236.236.160 and 35.181.18.45. mx2.improvmx.com points to: 2a05:d012:412:e201:1f6e:f6e4:8fd7:4678, 2a05:d012:412:e202:e81e:cc44:3b53:8a3d, 2a05:d012:412:e203:7e33:3d9c:28d7:ee20, 13.36.107.63, 13.36.222.39 and 15.236.61.92.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

bnORruU CF johedugfp 2025-10-06