malware.lu - dns.ninja

malware.lu

DNSSECโš ๏ธ Not signed
A213.167.245.235๐Ÿ‡ซ๐Ÿ‡ท GANDI-AS213.167.240.0/20 GANDI is an ICANN accredited registrar and Cloud services provider
PTRxvm-245-235.dc2.ghst.net
NSns1.root.lu โญ
A2a01:608::3๐Ÿ‡ฑ๐Ÿ‡บ ROOT2a01:608::/32 root SA
PTRa.root.lu
A195.26.4.3๐Ÿ‡ฑ๐Ÿ‡บ ROOT195.26.4.0/23 root SA
PTRa.root.lu
NSalpha.ns.network.lu
A2a05:93c0:1006:1010:f816:3eff:fe2e:1e52๐Ÿ‡ณ๐Ÿ‡ฑ SERVERS2a05:93c0::/32 .COM NL01
A213.196.40.85๐Ÿ‡ณ๐Ÿ‡ฑ SERVERS213.196.40.0/24 .COM AMS1 CLOUD COMPUTING
PTRalpha.ns.network.lu
NSns2.root.lu
A83.243.8.3๐Ÿ‡ฑ๐Ÿ‡บ ROOT83.243.8.0/21 root SA
PTRb.root.lu
MXmalware-lu.mail.protection.outlook.com(100)
A2a01:111:f403:ca04::10๐Ÿ‡ฎ๐Ÿ‡ช Microsoft2a01:111:f000::/36
PTRmail-dbapr03cu00100.inbound.protection.outlook.com
A2a01:111:f403:ca09::7๐Ÿ‡ณ๐Ÿ‡ฑ Microsoft2a01:111:f000::/36
PTRmail-am9pr04cu00107.inbound.protection.outlook.com
A2a01:111:f403:ca09::c๐Ÿ‡ณ๐Ÿ‡ฑ Microsoft2a01:111:f000::/36
PTRmail-as8pr05cu00304.inbound.protection.outlook.com
A2a01:111:f403:ca09::f๐Ÿ‡ณ๐Ÿ‡ฑ Microsoft2a01:111:f000::/36
PTRmail-am7pr05cu00307.inbound.protection.outlook.com
A52.101.68.5๐Ÿ‡ฎ๐Ÿ‡ช Microsoft52.96.0.0/12 MICROSOFT
PTRmail-du2pr03cu00105.inbound.protection.outlook.com
A52.101.68.15๐Ÿ‡ฎ๐Ÿ‡ช Microsoft52.96.0.0/12 MICROSOFT
PTRmail-db6pr03cu00107.inbound.protection.outlook.com
A52.101.68.29๐Ÿ‡ฎ๐Ÿ‡ช Microsoft52.96.0.0/12 MICROSOFT
PTRmail-dbapr03cu00105.inbound.protection.outlook.com
A52.101.68.32๐Ÿ‡ฎ๐Ÿ‡ช Microsoft52.96.0.0/12 MICROSOFT
PTRmail-db3pr0202cu00200.inbound.protection.outlook.com
TXTv=spf1 include:spf.protection.outlook.com -all
TXTMS=ms64462126
SOAns1.root.luadmin@root.lu serial=1690228057

lu

DNSSEC๐Ÿ”’ Signed (DS record present)
NS1.ns.lu โญ
NSg.dns.lu
NSi.dns.lu
NSj.dns.lu
NSk.dns.lu
NSp.dns.lu
NSr.ns.lu
TXTExported: 2026-06-21 15:01:02
SOA1.ns.lunoc@restena.lu serial=1782046872
๐Ÿ”’ HSTS Preload (+subdomains)

Subdomains

Same first word

Similar names

DNS History

8 records (5 active, 3 former)

20162017201820192020202120222023202420252026NSalpha.ns.network.luns1.root.luns2.root.luMXmalware-lu.mail.protection.outlook.comb.mx.root.luA213.167.245.235213.135.240.5031.22.124.18
โ—NSalpha.ns.network.lu2026-02-16 โ†’ 2026-06-21 ยท 3 obs
โ—‹ 2015-07-09 06:05:46
โ— 2026-02-16 12:58:46
โ— 2026-06-21 13:10:58
โ—NSns1.root.lu2015-07-09 โ†’ 2026-06-21 ยท 2 obs
โ— 2015-07-09 06:05:46
โ— 2026-06-21 13:10:58
โ—NSns2.root.lu2015-07-09 โ†’ 2026-06-21 ยท 2 obs
โ— 2015-07-09 06:05:46
โ— 2026-06-21 13:10:58
โ—‹MXb.mx.root.lu2015-07-09 โ†’ 2018-07-08 ยท 4 obs
โ— 2015-07-09 06:05:46
โ— 2018-07-08 23:20:58
โ—‹ 2026-02-16 12:58:46
โ—‹ 2026-06-21 13:10:58
โ—MXmalware-lu.mail.protection.outlook.com2026-02-16 โ†’ 2026-06-21 ยท 3 obs
โ—‹ 2018-07-08 23:20:58
โ— 2026-02-16 12:58:46
โ— 2026-06-21 13:10:58
โ—‹A213.135.240.502017-11-02 โ†’ 2018-07-08 ยท 5 obs
โ—‹ 2016-12-28 15:55:14
โ— 2017-11-02 13:34:58
โ— 2018-07-08 23:20:58
โ—‹ 2026-02-16 12:58:46
โ—‹ 2026-06-21 13:10:58
โ—A213.167.245.2352026-02-16 โ†’ 2026-06-21 ยท 3 obs
โ—‹ 2018-07-08 23:20:58
โ— 2026-02-16 12:58:46
โ— 2026-06-21 13:10:58
โ—‹A31.22.124.182015-07-09 โ†’ 2016-12-28 ยท 4 obs
โ— 2015-07-09 06:05:46
โ— 2016-12-28 15:55:14
โ—‹ 2017-11-02 13:34:58
โ—‹ 2026-06-21 13:10:58

๐Ÿ” DNS Trace

๐Ÿ“‹ Delegation Chain

ZoneNameserversGlue
lug.dns.lu, i.dns.lu, j.dns.lu, k.dns.lu...14 records
malware.luns1.root.lu, ns2.root.lu, alpha.ns.network.lu2 records

โœ… Authoritative Response

Server:213.196.40.85

NS records: ns1.root.lu, ns2.root.lu, alpha.ns.network.lu

๐Ÿ”’ DNSSEC Status

โš ๏ธ Insecure (no DNSSEC)

No DS record for malware.lu (unsigned zone)

โฑ๏ธ Timing

Total: 1136ms | Queries: -

๐Ÿ“„ Records

TypeCountSample Data
A1213.167.245.235
NS3ns2.root.lu, ns1.root.lu...
MX2malware-lu.mail.protection.outlook.com (, malware-lu.mail.protection.outlook.com (
TXT2v=spf1 include:spf.protection.outlook.co, MS=ms64462126
SOA1ns1.root.lu admin.root.lu

๐Ÿ“Œ Glue Records Collected

Total: 16

In-bailiwick: 14 (g.dns.lu, i.dns.lu, j.dns.lu...)

Out-of-bailiwick: 2 (alpha.ns.network.lu, alpha.ns.network.lu)

Analysis

Hierarchy

avcaesar.malware.lu and www.malware.lu each fall under malware.lu as their parent domain.

IP Addresses

malware.lu resolves to just one IP address, 213.167.245.235.

Two other host names, along with avcaesar.malware.lu, www.itrust.lu and www.malware.lu, also share IP numbers with malware.lu.

Name Servers

The authoritative name servers for malware.lu are ns1.root.lu, ns2.root.lu and alpha.ns.network.lu โ€” three in total.

There is at least partial name server overlap between malware.lu and other domains โ€” alformec.lu, vermoplast.de, prestaplanning.com and two more among them.

These name servers frequently co-occur with the name servers ns1.fcs-it.com and ns2.fcs-it.com.

Host names that have two IP addresses:

ns1.root.lu directs traffic to 195.26.4.3 and 2a01:608::3.

alpha.ns.network.lu directs traffic to 213.196.40.85 and 2a05:93c0:1006:1010:f816:3eff:fe2e:1e52.

Host names that point to one IP address:

ns2.root.lu has the IP address 83.243.8.3.

Mail Servers

The sole mail server for malware.lu is malware-lu.mail.protection.outlook.com.

With 8 IP addresses total, malware-lu.mail.protection.outlook.com resolves to 52.101.68.5, 52.101.68.15, 52.101.68.29 and 5 others.