malwarebytes.ir - dns.ninja

malwarebytes.ir

DNSSEC⚠️ Not signed
A2606:4700:3034::ac43:b8edπŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3034::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A2606:4700:3035::6815:1320πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3035::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A104.21.19.32Cloudflare104.21.16.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A172.67.184.237πŸ‡ΊπŸ‡Έ Cloudflare172.67.176.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
NSbart.ns.cloudflare.com ⭐
A2606:4700:58::adf5:3b47πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRbart.ns.cloudflare.com
A2803:f800:50::6ca2:c147πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRbart.ns.cloudflare.com
A2a06:98c1:50::ac40:2147πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRbart.ns.cloudflare.com
A108.162.193.71πŸ‡ΊπŸ‡Έ Cloudflare108.162.193.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRbart.ns.cloudflare.com
A172.64.33.71πŸ‡ΊπŸ‡Έ Cloudflare172.64.33.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRbart.ns.cloudflare.com
A173.245.59.71πŸ‡ΊπŸ‡Έ Cloudflare173.245.59.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRbart.ns.cloudflare.com
NSsue.ns.cloudflare.com
A2606:4700:50::adf5:3a91πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRsue.ns.cloudflare.com
A2803:f800:50::6ca2:c091πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRsue.ns.cloudflare.com
A2a06:98c1:50::ac40:2091πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRsue.ns.cloudflare.com
A108.162.192.145πŸ‡ΊπŸ‡Έ Cloudflare108.162.192.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRsue.ns.cloudflare.com
A172.64.32.145πŸ‡ΊπŸ‡Έ Cloudflare172.64.32.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRsue.ns.cloudflare.com
A173.245.58.145πŸ‡ΊπŸ‡Έ Cloudflare173.245.58.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRsue.ns.cloudflare.com
MXmail.malwarebytes.ir ⭐
A2606:4700:3034::ac43:b8edπŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3034::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US
A2606:4700:3035::6815:1320πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3035::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US
A104.21.19.32Cloudflare104.21.16.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US
A172.67.184.237πŸ‡ΊπŸ‡Έ Cloudflare172.67.176.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US
TXTv=spf1 a:mailgw-m.getway.biz mx a:mailgw.getway.biz a:mailgw2.getway.biz ip4:...
HTTPSHTTP/3, HTTP/2 βœ“ hints match
IPv4 hints104.21.19.32, 172.67.184.237
IPv6 hints2606:4700:3034::ac43:b8ed, 2606:4700:3035::6815:1320
ECHX25519, HKDF-SHA256 + AES-128-GCM draft, id=74, name=cloudflare-ech.com
SOAbart.ns.cloudflare.comdns@cloudflare.com serial=2405658500

ir

DNSSEC⚠️ Not signed
NSa.nic.ir ⭐
NSb.nic.ir
NSc.nic.ir
NSd.nic.ir
SOAa.nic.irinfo@nic.ir serial=2606260145

Subdomains

Same first word

Similar names

DNS History

18 records (7 active, 11 former)

NSbart.ns.cloudflare.comsue.ns.cloudflare.comfog.parspack.nethill.parspack.netns1.parspack.cons1box207.parsvds.comns2.parspack.cons2box207.parsvds.comns3.parspack.cons4.parspack.coMXmail.malwarebytes.irA104.21.19.32172.67.184.2372606:4700:3034::ac43:b8ed2606:4700:3035::6815:1320185.164.72.226185.208.173.16185.208.173.3
●NSbart.ns.cloudflare.com2026-06-15 β†’ 2026-06-25 Β· 3 obs
β—‹ 2026-06-08 21:20:46
● 2026-06-15 09:05:32
● 2026-06-25 23:02:52
β—‹NSfog.parspack.net2026-02-26 β†’ 2026-04-29 Β· 4 obs
● 2026-02-26 15:09:34
● 2026-04-29 00:37:28
β—‹ 2026-06-08 21:20:46
β—‹ 2026-06-25 23:02:52
β—‹NShill.parspack.net2026-02-26 β†’ 2026-04-29 Β· 4 obs
● 2026-02-26 15:09:34
● 2026-04-29 00:37:28
β—‹ 2026-06-08 21:20:46
β—‹ 2026-06-25 23:02:52
β—‹NSns1.parspack.co2026-02-26 β†’ 2026-06-25 Β· 2 obs
β—‹ 2026-02-26 15:09:34
β—‹ 2026-06-25 23:02:52
β—‹NSns1box207.parsvds.com2026-06-08 β†’ 2026-06-08 Β· 4 obs
β—‹ 2026-04-29 00:37:28
● 2026-06-08 21:20:46
β—‹ 2026-06-15 09:05:32
β—‹ 2026-06-25 23:02:52
β—‹NSns2.parspack.co2026-02-26 β†’ 2026-06-25 Β· 2 obs
β—‹ 2026-02-26 15:09:34
β—‹ 2026-06-25 23:02:52
β—‹NSns2box207.parsvds.com2026-06-08 β†’ 2026-06-08 Β· 4 obs
β—‹ 2026-04-29 00:37:28
● 2026-06-08 21:20:46
β—‹ 2026-06-15 09:05:32
β—‹ 2026-06-25 23:02:52
β—‹NSns3.parspack.co2026-02-26 β†’ 2026-06-25 Β· 2 obs
β—‹ 2026-02-26 15:09:34
β—‹ 2026-06-25 23:02:52
β—‹NSns4.parspack.co2026-02-26 β†’ 2026-06-25 Β· 2 obs
β—‹ 2026-02-26 15:09:34
β—‹ 2026-06-25 23:02:52
●NSsue.ns.cloudflare.com2026-06-15 β†’ 2026-06-25 Β· 3 obs
β—‹ 2026-06-08 21:20:46
● 2026-06-15 09:05:32
● 2026-06-25 23:02:52
●MXmail.malwarebytes.ir2026-02-26 β†’ 2026-06-25 Β· 5 obs
● 2026-02-26 15:09:34
● 2026-04-29 00:37:28
β—‹ 2026-06-08 21:20:46
● 2026-06-25 23:02:50
● 2026-06-25 23:02:52
●A104.21.19.322026-06-25 β†’ 2026-06-25 Β· 3 obs
β—‹ 2026-06-08 21:20:46
● 2026-06-25 23:02:50
● 2026-06-25 23:02:52
●A172.67.184.2372026-06-25 β†’ 2026-06-25 Β· 3 obs
β—‹ 2026-06-08 21:20:46
● 2026-06-25 23:02:50
● 2026-06-25 23:02:52
β—‹A185.164.72.2262026-02-26 β†’ 2026-06-25 Β· 2 obs
β—‹ 2026-02-26 15:09:34
β—‹ 2026-06-25 23:02:52
β—‹A185.208.173.162026-04-29 β†’ 2026-04-29 Β· 4 obs
β—‹ 2026-02-26 15:09:34
● 2026-04-29 00:37:28
β—‹ 2026-06-08 21:20:46
β—‹ 2026-06-25 23:02:52
β—‹A185.208.173.32026-02-26 β†’ 2026-02-26 Β· 3 obs
● 2026-02-26 15:09:34
β—‹ 2026-04-29 00:37:28
β—‹ 2026-06-25 23:02:52
●A2606:4700:3034::ac43:b8ed2026-06-25 β†’ 2026-06-25 Β· 3 obs
β—‹ 2026-06-08 21:20:46
● 2026-06-25 23:02:50
● 2026-06-25 23:02:52
●A2606:4700:3035::6815:13202026-06-25 β†’ 2026-06-25 Β· 3 obs
β—‹ 2026-06-08 21:20:46
● 2026-06-25 23:02:50
● 2026-06-25 23:02:52

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
ira.nic.ir, b.nic.ir, c.nic.ir, d.nic.ir8 records
malwarebytes.irbart.ns.cloudflare.com, sue.ns.cloudflare.com-

βœ… Authoritative Response

Server:108.162.193.71

NS records: bart.ns.cloudflare.com, sue.ns.cloudflare.com

πŸ”’ DNSSEC Status

❌ Bogus (DNSSEC validation failed)

Validation error at ir: Error: DNS query timeout: 193.189.123.2 for DNSKEY ir

⏱️ Timing

Total: 3451ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A2104.21.19.32, 172.67.184.237
AAAA22606:4700:3034::ac43:b8ed, 2606:4700:3035::6815:1320
NS2bart.ns.cloudflare.com, sue.ns.cloudflare.com
MX1mail.malwarebytes.ir (pri: 10)
TXT1v=spf1 a:mailgw-m.getway.biz mx a:mailgw
HTTPS1{"priority":1,"target":".","alpn":["h3",
SOA1bart.ns.cloudflare.com dns.cloudflare.co

πŸ“Œ Glue Records Collected

Total: 8

In-bailiwick: 8 (a.nic.ir, b.nic.ir, c.nic.ir...)

Analysis

Hierarchy

mail.malwarebytes.ir is delegated beneath malwarebytes.ir.

IP Addresses

malwarebytes.ir points to the four IP addresses 104.21.19.32, 172.67.184.237, 2606:4700:3034::ac43:b8ed and 2606:4700:3035::6815:1320.

Among the host names that share IP numbers with malwarebytes.ir are cedarcityhospitalfoundation.net, livecam007.com, purplebike.de and two others.

Name Servers

malwarebytes.ir is served by two delegated name servers, bart.ns.cloudflare.com and sue.ns.cloudflare.com.

malwarebytes.ir has the same name server delegation as a number of other domains, such as innercompassmasterclass.com, licenco.com, ride-app.net and two more.

There is at least partial name server overlap between malwarebytes.ir and other domains β€” prostocopy.ru, fxsignals.com, bridgematrix.pics and two more among them.

The name servers nile.ns.cloudflare.com, hera.ns.cloudflare.com and maria.ns.cloudflare.com are often found in combination with these name servers.

Host names resolving to 6 IP numbers:

bart.ns.cloudflare.com carries IP addresses 108.162.193.71, 172.64.33.71 and 173.245.59.71, with 3 other addresses beyond those.

sue.ns.cloudflare.com carries IP addresses 108.162.192.145, 172.64.32.145 and 173.245.58.145, with 3 other addresses beyond those.

Mail Servers

malwarebytes.ir routes its mail through a single mail server, mail.malwarebytes.ir.

The host mail.malwarebytes.ir directs to four IP numbers: 104.21.19.32, 172.67.184.237, 2606:4700:3034::ac43:b8ed and 2606:4700:3035::6815:1320.