malware.guide - dns.ninja
malware.guide
| DNSSEC | β οΈ Not signed | ||||||
| A | 2606:4700:3032::6815:2bfcπΊπΈ Cloudflare2606:4700:3032::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US β In HTTPS hints | ||||||
| A | 2606:4700:3033::ac43:c045πΊπΈ Cloudflare2606:4700:3033::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US β In HTTPS hints | ||||||
| A | 104.21.43.252Cloudflare104.21.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US β In HTTPS hints | ||||||
| A | 172.67.192.69πΊπΈ Cloudflare172.67.192.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US β In HTTPS hints | ||||||
| NS | brad.ns.cloudflare.com β | ||||||
| A | 2606:4700:58::adf5:3b69πΊπΈ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | brad.ns.cloudflare.com | ||||||
| A | 2803:f800:50::6ca2:c169π¨π· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L | ||||||
| PTR | brad.ns.cloudflare.com | ||||||
| A | 2a06:98c1:50::ac40:2169πΊπΈ Cloudflare2a06:98c1:50::/45 | ||||||
| PTR | brad.ns.cloudflare.com | ||||||
| A | 108.162.193.105πΊπΈ Cloudflare108.162.193.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | brad.ns.cloudflare.com | ||||||
| A | 172.64.33.105πΊπΈ Cloudflare172.64.33.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | brad.ns.cloudflare.com | ||||||
| A | 173.245.59.105πΊπΈ Cloudflare173.245.59.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | brad.ns.cloudflare.com | ||||||
| NS | kay.ns.cloudflare.com | ||||||
| A | 2606:4700:50::adf5:3a7dπΊπΈ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | kay.ns.cloudflare.com | ||||||
| A | 2803:f800:50::6ca2:c07dπ¨π· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L | ||||||
| PTR | kay.ns.cloudflare.com | ||||||
| A | 2a06:98c1:50::ac40:207dπΊπΈ Cloudflare2a06:98c1:50::/45 | ||||||
| PTR | kay.ns.cloudflare.com | ||||||
| A | 108.162.192.125πΊπΈ Cloudflare108.162.192.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | kay.ns.cloudflare.com | ||||||
| A | 172.64.32.125πΊπΈ Cloudflare172.64.32.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | kay.ns.cloudflare.com | ||||||
| A | 173.245.58.125πΊπΈ Cloudflare173.245.58.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US | ||||||
| PTR | kay.ns.cloudflare.com | ||||||
| TXT | google-site-verification=QT17bmAIF-sweQn89HL-zE7MCxM7ZRsMic6oAvrpCp4 | ||||||
| HTTPS | HTTP/3, HTTP/2 β hints match | ||||||
| IPv4 hints | 104.21.43.252, 172.67.192.69 | ||||||
| IPv6 hints | 2606:4700:3032::6815:2bfc, 2606:4700:3033::ac43:c045 | ||||||
| ECH | X25519, HKDF-SHA256 + AES-128-GCM draft, id=222, name=cloudflare-ech.com | ||||||
| SOA | brad.ns.cloudflare.comdns@cloudflare.com serial=2406278308 | ||||||
guide
| DNSSEC | π Signed (DS record present) | ||||||
| NS | v0n0.nic.guide β | ||||||
| NS | v0n1.nic.guide | ||||||
| NS | v0n2.nic.guide | ||||||
| NS | v0n3.nic.guide | ||||||
| NS | v2n0.nic.guide | ||||||
| NS | v2n1.nic.guide | ||||||
| SOA | v0n0.nic.guidehostmaster@donuts.email serial=1781957787 | ||||||
Same first word
Similar names
meralaw.com |
walmare.com |
marwael.fr |
malwear.wtf |
amlware.com |
elmarwa.com |
malwear.com |
amrelaw.com |
rawmale.com |
lawream.com |
mawlare.net |
wealarm.com |
malwear.co |
malwear.org |
realawm.com |
amerlaw.com |
reamlaw.net |
reamlaw.com |
DNS History
10 records (6 active, 4 former)
βNSbrad.ns.cloudflare.com2026-04-30 β 2026-06-20 Β· 3 obs
β 2026-04-30 23:51:58
β 2026-06-20 12:57:50
βNSkay.ns.cloudflare.com2026-04-30 β 2026-06-20 Β· 3 obs
β 2026-04-30 23:51:58
β 2026-06-20 12:57:50
βNSns1.digitalocean.com2026-03-20 β 2026-03-27 Β· 4 obs
β 2026-03-27 09:36:50
β 2026-04-30 23:51:58
β 2026-06-20 12:57:50
βNSns2.digitalocean.com2026-03-20 β 2026-03-27 Β· 4 obs
β 2026-03-27 09:36:50
β 2026-04-30 23:51:58
β 2026-06-20 12:57:50
βNSns3.digitalocean.com2026-03-20 β 2026-03-27 Β· 4 obs
β 2026-03-27 09:36:50
β 2026-04-30 23:51:58
β 2026-06-20 12:57:50
βA104.21.43.2522026-04-30 β 2026-06-20 Β· 3 obs
β 2026-04-30 23:51:58
β 2026-06-20 12:57:50
βA143.110.147.1092026-03-20 β 2026-03-27 Β· 4 obs
β 2026-03-27 09:36:50
β 2026-04-30 23:51:58
β 2026-06-20 12:57:50
βA172.67.192.692026-04-30 β 2026-06-20 Β· 3 obs
β 2026-04-30 23:51:58
β 2026-06-20 12:57:50
βA2606:4700:3032::6815:2bfc2026-04-30 β 2026-06-20 Β· 3 obs
β 2026-04-30 23:51:58
β 2026-06-20 12:57:50
βA2606:4700:3033::ac43:c0452026-04-30 β 2026-06-20 Β· 3 obs
β 2026-04-30 23:51:58
β 2026-06-20 12:57:50
π DNS Trace
π Delegation Chain
| Zone | Nameservers | Glue |
|---|---|---|
| guide | v0n0.nic.guide, v0n1.nic.guide, v0n2.nic.guide, v0n3.nic.guide... | 12 records |
| malware.guide | kay.ns.cloudflare.com, brad.ns.cloudflare.com | - |
β Authoritative Response
Server:172.64.32.125
NS records: kay.ns.cloudflare.com, brad.ns.cloudflare.com
π DNSSEC Status
β οΈ Insecure (no DNSSEC)
No DS record for malware.guide (unsigned zone)
β±οΈ Timing
Total: 244ms | Queries: -
π Records
| Type | Count | Sample Data |
|---|---|---|
| A | 2 | 104.21.43.252, 172.67.192.69 |
| AAAA | 2 | 2606:4700:3033::ac43:c045, 2606:4700:3032::6815:2bfc |
| NS | 2 | brad.ns.cloudflare.com, kay.ns.cloudflare.com |
| TXT | 1 | google-site-verification=QT17bmAIF-sweQn |
| HTTPS | 1 | {"priority":1,"target":".","alpn":["h3", |
| SOA | 1 | brad.ns.cloudflare.com dns.cloudflare.co |
π Glue Records Collected
Total: 12
In-bailiwick: 12 (v0n0.nic.guide, v0n0.nic.guide, v0n1.nic.guide...)
Analysis
IP Addresses
malware.guide points to the four IP addresses 104.21.43.252, 172.67.192.69, 2606:4700:3032::6815:2bfc and 2606:4700:3033::ac43:c045.
blog.synthetic-turf.ca, bootietech.digital, www.fusp.org plus two other host names have IP numbers in common with malware.guide.
Name Servers
The NS records for malware.guide delegate to brad.ns.cloudflare.com and kay.ns.cloudflare.com.
The name server configuration of malware.guide is shared with other domains, for instance virsec.org, fusetv.co.uk, keralawebdesigncompany.co.in and two others.
There is at least partial name server overlap between malware.guide and other domains β super-lotto.com, vitrotek.com.tr, saltworld.net and two more among them.
These name servers frequently co-occur with the name servers trevor.ns.cloudflare.com and emma.ns.cloudflare.com.
Hosts with 6 IP addresses each:
brad.ns.cloudflare.com maps to 108.162.193.105, 172.64.33.105, 173.245.59.105 and 3 additional IP addresses.
kay.ns.cloudflare.com maps to 108.162.192.125, 172.64.32.125, 173.245.58.125 and 3 additional IP addresses.