malware.guide - dns.ninja

malware.guide

DNSSEC⚠️ Not signed
A2606:4700:3032::6815:2bfcπŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3032::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A2606:4700:3033::ac43:c045πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3033::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A104.21.43.252Cloudflare104.21.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A172.67.192.69πŸ‡ΊπŸ‡Έ Cloudflare172.67.192.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
NSbrad.ns.cloudflare.com ⭐
A2606:4700:58::adf5:3b69πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRbrad.ns.cloudflare.com
A2803:f800:50::6ca2:c169πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRbrad.ns.cloudflare.com
A2a06:98c1:50::ac40:2169πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRbrad.ns.cloudflare.com
A108.162.193.105πŸ‡ΊπŸ‡Έ Cloudflare108.162.193.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRbrad.ns.cloudflare.com
A172.64.33.105πŸ‡ΊπŸ‡Έ Cloudflare172.64.33.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRbrad.ns.cloudflare.com
A173.245.59.105πŸ‡ΊπŸ‡Έ Cloudflare173.245.59.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRbrad.ns.cloudflare.com
NSkay.ns.cloudflare.com
A2606:4700:50::adf5:3a7dπŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRkay.ns.cloudflare.com
A2803:f800:50::6ca2:c07dπŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRkay.ns.cloudflare.com
A2a06:98c1:50::ac40:207dπŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRkay.ns.cloudflare.com
A108.162.192.125πŸ‡ΊπŸ‡Έ Cloudflare108.162.192.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRkay.ns.cloudflare.com
A172.64.32.125πŸ‡ΊπŸ‡Έ Cloudflare172.64.32.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRkay.ns.cloudflare.com
A173.245.58.125πŸ‡ΊπŸ‡Έ Cloudflare173.245.58.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRkay.ns.cloudflare.com
TXTgoogle-site-verification=QT17bmAIF-sweQn89HL-zE7MCxM7ZRsMic6oAvrpCp4
HTTPSHTTP/3, HTTP/2 βœ“ hints match
IPv4 hints104.21.43.252, 172.67.192.69
IPv6 hints2606:4700:3032::6815:2bfc, 2606:4700:3033::ac43:c045
ECHX25519, HKDF-SHA256 + AES-128-GCM draft, id=222, name=cloudflare-ech.com
SOAbrad.ns.cloudflare.comdns@cloudflare.com serial=2406278308

guide

DNSSECπŸ”’ Signed (DS record present)
NSv0n0.nic.guide ⭐
NSv0n1.nic.guide
NSv0n2.nic.guide
NSv0n3.nic.guide
NSv2n0.nic.guide
NSv2n1.nic.guide
SOAv0n0.nic.guidehostmaster@donuts.email serial=1781957787

Same first word

Similar names

DNS History

10 records (6 active, 4 former)

NSbrad.ns.cloudflare.comkay.ns.cloudflare.comns1.digitalocean.comns2.digitalocean.comns3.digitalocean.comA104.21.43.252172.67.192.692606:4700:3032::6815:2bfc2606:4700:3033::ac43:c045143.110.147.109
●NSbrad.ns.cloudflare.com2026-04-30 β†’ 2026-06-20 Β· 3 obs
β—‹ 2026-03-27 09:36:50
● 2026-04-30 23:51:58
● 2026-06-20 12:57:50
●NSkay.ns.cloudflare.com2026-04-30 β†’ 2026-06-20 Β· 3 obs
β—‹ 2026-03-27 09:36:50
● 2026-04-30 23:51:58
● 2026-06-20 12:57:50
β—‹NSns1.digitalocean.com2026-03-20 β†’ 2026-03-27 Β· 4 obs
● 2026-03-20 16:53:34
● 2026-03-27 09:36:50
β—‹ 2026-04-30 23:51:58
β—‹ 2026-06-20 12:57:50
β—‹NSns2.digitalocean.com2026-03-20 β†’ 2026-03-27 Β· 4 obs
● 2026-03-20 16:53:34
● 2026-03-27 09:36:50
β—‹ 2026-04-30 23:51:58
β—‹ 2026-06-20 12:57:50
β—‹NSns3.digitalocean.com2026-03-20 β†’ 2026-03-27 Β· 4 obs
● 2026-03-20 16:53:34
● 2026-03-27 09:36:50
β—‹ 2026-04-30 23:51:58
β—‹ 2026-06-20 12:57:50
●A104.21.43.2522026-04-30 β†’ 2026-06-20 Β· 3 obs
β—‹ 2026-03-27 09:36:50
● 2026-04-30 23:51:58
● 2026-06-20 12:57:50
β—‹A143.110.147.1092026-03-20 β†’ 2026-03-27 Β· 4 obs
● 2026-03-20 16:53:34
● 2026-03-27 09:36:50
β—‹ 2026-04-30 23:51:58
β—‹ 2026-06-20 12:57:50
●A172.67.192.692026-04-30 β†’ 2026-06-20 Β· 3 obs
β—‹ 2026-03-27 09:36:50
● 2026-04-30 23:51:58
● 2026-06-20 12:57:50
●A2606:4700:3032::6815:2bfc2026-04-30 β†’ 2026-06-20 Β· 3 obs
β—‹ 2026-03-27 09:36:50
● 2026-04-30 23:51:58
● 2026-06-20 12:57:50
●A2606:4700:3033::ac43:c0452026-04-30 β†’ 2026-06-20 Β· 3 obs
β—‹ 2026-03-27 09:36:50
● 2026-04-30 23:51:58
● 2026-06-20 12:57:50

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
guidev0n0.nic.guide, v0n1.nic.guide, v0n2.nic.guide, v0n3.nic.guide...12 records
malware.guidekay.ns.cloudflare.com, brad.ns.cloudflare.com-

βœ… Authoritative Response

Server:172.64.32.125

NS records: kay.ns.cloudflare.com, brad.ns.cloudflare.com

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for malware.guide (unsigned zone)

⏱️ Timing

Total: 244ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A2104.21.43.252, 172.67.192.69
AAAA22606:4700:3033::ac43:c045, 2606:4700:3032::6815:2bfc
NS2brad.ns.cloudflare.com, kay.ns.cloudflare.com
TXT1google-site-verification=QT17bmAIF-sweQn
HTTPS1{"priority":1,"target":".","alpn":["h3",
SOA1brad.ns.cloudflare.com dns.cloudflare.co

πŸ“Œ Glue Records Collected

Total: 12

In-bailiwick: 12 (v0n0.nic.guide, v0n0.nic.guide, v0n1.nic.guide...)

Analysis

IP Addresses

malware.guide points to the four IP addresses 104.21.43.252, 172.67.192.69, 2606:4700:3032::6815:2bfc and 2606:4700:3033::ac43:c045.

blog.synthetic-turf.ca, bootietech.digital, www.fusp.org plus two other host names have IP numbers in common with malware.guide.

Name Servers

The NS records for malware.guide delegate to brad.ns.cloudflare.com and kay.ns.cloudflare.com.

The name server configuration of malware.guide is shared with other domains, for instance virsec.org, fusetv.co.uk, keralawebdesigncompany.co.in and two others.

There is at least partial name server overlap between malware.guide and other domains β€” super-lotto.com, vitrotek.com.tr, saltworld.net and two more among them.

These name servers frequently co-occur with the name servers trevor.ns.cloudflare.com and emma.ns.cloudflare.com.

Hosts with 6 IP addresses each:

brad.ns.cloudflare.com maps to 108.162.193.105, 172.64.33.105, 173.245.59.105 and 3 additional IP addresses.

kay.ns.cloudflare.com maps to 108.162.192.125, 172.64.32.125, 173.245.58.125 and 3 additional IP addresses.