CF1759298646501-tsm20250929235914

IPLIST.NET - worm.sh

Search for IP or hostnames:

worm.sh checked at 2025-10-01T06:04:06.479Z 167ms 117/117/117 100% R:12

worm.sh

MXmx1.improvmx.com
A2a05:d012:412:e201:88aa:e7b9:7a43:12d7 🇫🇷 Amazon
A2a05:d012:412:e202:f36:2c1f:1a49:d38a 🇫🇷 Amazon
A2a05:d012:412:e203:373a:f51a:4a85:1d25 🇫🇷 Amazon
A13.37.195.136🇫🇷 Amazon
PTRec2-13-37-195-136.eu-west-3.compute.amazonaws.com
A15.236.236.160🇫🇷 Amazon
PTRec2-15-236-236-160.eu-west-3.compute.amazonaws.com
A35.181.18.45🇫🇷 Amazon
PTRec2-35-181-18-45.eu-west-3.compute.amazonaws.com
MXmx2.improvmx.com
A2a05:d012:412:e201:1f6e:f6e4:8fd7:4678 🇫🇷 Amazon
A2a05:d012:412:e202:e81e:cc44:3b53:8a3d 🇫🇷 Amazon
A2a05:d012:412:e203:7e33:3d9c:28d7:ee20 🇫🇷 Amazon
A13.36.107.63🇫🇷 Amazon
PTRec2-13-36-107-63.eu-west-3.compute.amazonaws.com
A13.36.222.39🇫🇷 Amazon
PTRec2-13-36-222-39.eu-west-3.compute.amazonaws.com
A15.236.61.92🇫🇷 Amazon
PTRec2-15-236-61-92.eu-west-3.compute.amazonaws.com
NSdns1.registrar-servers.com
A2610:a1:1024::200 🇺🇸 Neustar
PTRdns1.namecheaphosting.com
PTRdns1.registrar-servers.com
A156.154.132.200🇺🇸 Neustar
PTRdns1.namecheaphosting.com
PTRdns1.registrar-servers.com
NSdns2.registrar-servers.com
A2610:a1:1025::200 🇺🇸 Neustar
PTRdns2.namecheaphosting.com
PTRdns2.registrar-servers.com
A156.154.133.200🇺🇸 Neustar
PTRdns2.namecheaphosting.com
PTRdns2.registrar-servers.com
A34.61.160.136🇺🇸 Google
PTR136.160.61.34.bc.googleusercontent.com

sh

NSa0.nic.sh
NSa2.nic.sh
NSb0.nic.sh
NSc0.nic.sh

Starts with same word

Starts similarily

AI analysis

worm.sh points to a single IP address: 34.61.160.136.

Two name servers dns1.registrar-servers.com and dns2.registrar-servers.com handle the delegation for worm.sh.

worm.sh shares the same name server setup as other domains, for example jteus.org, pickaxis.net, xnxx.website, atmcache.com and boardpeel.com.

worm.sh shares name servers with other domains at least partially, for instance codegreen.us.

Host names with two IP numbers:

dns1.registrar-servers.com points to 2610:a1:1024::200 and 156.154.132.200.

dns2.registrar-servers.com points to 2610:a1:1025::200 and 156.154.133.200.

Two mail servers handle worm.sh: mx1.improvmx.com and mx2.improvmx.com.

worm.sh shares the same mail server setup as other domains, including mountkelvin.com, cafda.org, byutv.org, glenfair.com and pimyapi.com.

worm.sh shares some mail servers with other domains, for example lyziane.com.

Host names with six IP numbers:

mx1.improvmx.com points to 2a05:d012:412:e201:88aa:e7b9:7a43:12d7, 2a05:d012:412:e202:f36:2c1f:1a49:d38a, 2a05:d012:412:e203:373a:f51a:4a85:1d25, 13.37.195.136, 15.236.236.160 and 35.181.18.45.

mx2.improvmx.com points to 2a05:d012:412:e201:1f6e:f6e4:8fd7:4678, 2a05:d012:412:e202:e81e:cc44:3b53:8a3d, 2a05:d012:412:e203:7e33:3d9c:28d7:ee20, 13.36.107.63, 13.36.222.39 and 15.236.61.92.

Perform reverse DNS lookup as well as normal forward DNS. Check Autonomous System Numbers (ASNs) and BGP connections between Internet Service Providers.
dbq

KGxilVm CF johedugfp 2025-10-01