CF1757700257493-tsm20250912070358

IPLIST.NET - malware.zip

Search for IP or hostnames:

malware.zip checked at 2025-09-12T18:04:17.449Z 751ms 90/90/90 100% R:10

malware.zip

NSsandy.ns.cloudflare.com
A2606:4700:50::adf5:3adb 🇺🇸 Cloudflare
PTRsandy.ns.cloudflare.com
A2803:f800:50::6ca2:c0db 🇨🇷 Cloudflare
PTRsandy.ns.cloudflare.com
A2a06:98c1:50::ac40:20db 🇺🇸 Cloudflare
PTRsandy.ns.cloudflare.com
A108.162.192.219🇺🇸 Cloudflare
PTRsandy.ns.cloudflare.com
A172.64.32.219🇺🇸 Cloudflare
PTRsandy.ns.cloudflare.com
A173.245.58.219🇺🇸 Cloudflare
PTRsandy.ns.cloudflare.com
NStrace.ns.cloudflare.com
A2606:4700:58::a29f:2cac 🇺🇸 Cloudflare
PTRtrace.ns.cloudflare.com
A2803:f800:50::6ca2:c3ac 🇨🇷 Cloudflare
PTRtrace.ns.cloudflare.com
A2a06:98c1:50::ac40:23ac 🇺🇸 Cloudflare
PTRtrace.ns.cloudflare.com
A108.162.195.172🇺🇸 Cloudflare
PTRtrace.ns.cloudflare.com
A162.159.44.172 Cloudflare
PTRtrace.ns.cloudflare.com
A172.64.35.172🇺🇸 Cloudflare
PTRtrace.ns.cloudflare.com
A88.198.57.211🇩🇪 Hetzner
PTRstatic.88-198-57-211.clients.your-server.de

zip

NSns-tld1.charlestonroadregistry.com
NSns-tld2.charlestonroadregistry.com
NSns-tld3.charlestonroadregistry.com
NSns-tld4.charlestonroadregistry.com
NSns-tld5.charlestonroadregistry.com

Starts with same word

Starts similarily

AI analysis

IP number 88.198.57.211 is pointed to by malware.zip.

The IP numbers are shared between other host names like static.88-198-57-211.clients.your-server.de and malware.zip.

Two name servers, sandy.ns.cloudflare.com and trace.ns.cloudflare.com, are the delegation for malware.zip.

Other domains, such as ownaship.co.nz, have the same name server setup as malware.zip.

The name servers of malware.zip are at least partially shared with other domains such as gading.de, ok-bus.com, physicsinventions.com, gutscheincode12.de, and shenzhentiebiaoji.com.

The name servers becky.ns.cloudflare.com and jerry.ns.cloudflare.com are frequently utilized in conjunction with these name servers.

sandy.ns.cloudflare.com and trace.ns.cloudflare.com each point to six IP numbers: 2606:4700:50::adf5:3adb, 2803:f800:50::6ca2:c0db, 2a06:98c1:50::ac40:20db, 108.162.192.219, 172.64.32.219, and 173.245.58.219 for sandy.ns.cloudflare.com, and 2606:4700:58::a29f:2cac, 2803:f800:50::6ca2:c3ac, 2a06:98c1:50::ac40:23ac, 108.162.195.172, 162.159.44.172, and 172.64.35.172 for trace.ns.cloudflare.com.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

PIXXSmP CF johedugfp 2025-09-12