malware.forum - robtex.com

malware.forum

DNSSEC⚠️ Not signed
A2606:4700:3030::ac43:b2fcπŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3030::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A2606:4700:3031::6815:485aπŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3031::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A104.21.72.90Cloudflare104.21.64.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A172.67.178.252πŸ‡ΊπŸ‡Έ Cloudflare172.67.176.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
NSsavanna.ns.cloudflare.com ⭐
A2606:4700:50::a29f:2688πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRsavanna.ns.cloudflare.com
A2803:f800:50::6ca2:c288πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRsavanna.ns.cloudflare.com
A2a06:98c1:50::ac40:2288πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRsavanna.ns.cloudflare.com
A108.162.194.136πŸ‡ΊπŸ‡Έ Cloudflare108.162.194.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRsavanna.ns.cloudflare.com
A162.159.38.136Cloudflare162.159.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRsavanna.ns.cloudflare.com
A172.64.34.136πŸ‡ΊπŸ‡Έ Cloudflare172.64.34.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRsavanna.ns.cloudflare.com
NStadeo.ns.cloudflare.com
A2606:4700:58::a29f:2cc5πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRtadeo.ns.cloudflare.com
A2803:f800:50::6ca2:c3c5πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRtadeo.ns.cloudflare.com
A2a06:98c1:50::ac40:23c5πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRtadeo.ns.cloudflare.com
A108.162.195.197πŸ‡ΊπŸ‡Έ Cloudflare108.162.195.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRtadeo.ns.cloudflare.com
A162.159.44.197Cloudflare162.159.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRtadeo.ns.cloudflare.com
A172.64.35.197πŸ‡ΊπŸ‡Έ Cloudflare172.64.35.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRtadeo.ns.cloudflare.com
HTTPSHTTP/3, HTTP/2 βœ“ hints match
IPv4104.21.72.90, 172.67.178.252
IPv62606:4700:3030::ac43:b2fc, 2606:4700:3031::6815:485a
SOAsavanna.ns.cloudflare.comdns@cloudflare.com serial=2398883325

forum

DNSSECπŸ”’ Signed (DS record present)
NSns01.trs-dns.com ⭐
NSns.trs-dns.com
NSns01.trs-dns.net
NSns10.trs-dns.info
NSns10.trs-dns.org
SOAns.trs-dns.comtrs-ops@tucows.com serial=1774370118

Same first word

Similar names

DNS History

6 records (6 active, 0 former)

NSsavanna.ns.cloudflare.comtadeo.ns.cloudflare.comA104.21.72.90172.67.178.2522606:4700:3030::ac43:b2fc2606:4700:3031::6815:485a
●NSsavanna.ns.cloudflare.com2026-03-20 β†’ 2026-03-24 Β· 2 obs
● 2026-03-20 19:30:56
● 2026-03-24 16:36:38
●NStadeo.ns.cloudflare.com2026-03-20 β†’ 2026-03-24 Β· 2 obs
● 2026-03-20 19:30:56
● 2026-03-24 16:36:38
●A104.21.72.902026-03-20 β†’ 2026-03-24 Β· 2 obs
● 2026-03-20 19:30:56
● 2026-03-24 16:36:38
●A172.67.178.2522026-03-20 β†’ 2026-03-24 Β· 2 obs
● 2026-03-20 19:30:56
● 2026-03-24 16:36:38
●A2606:4700:3030::ac43:b2fc2026-03-20 β†’ 2026-03-24 Β· 2 obs
● 2026-03-20 19:30:56
● 2026-03-24 16:36:38
●A2606:4700:3031::6815:485a2026-03-20 β†’ 2026-03-24 Β· 2 obs
● 2026-03-20 19:30:56
● 2026-03-24 16:36:38

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
forumns01.trs-dns.com, ns01.trs-dns.net, ns10.trs-dns.org, ns10.trs-dns.info8 records
malware.forumtadeo.ns.cloudflare.com, savanna.ns.cloudflare.com-

βœ… Authoritative Response

Server:172.64.35.197

NS records: tadeo.ns.cloudflare.com, savanna.ns.cloudflare.com

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for malware.forum (unsigned zone)

⏱️ Timing

Total: 659ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A2172.67.178.252, 104.21.72.90
AAAA22606:4700:3030::ac43:b2fc, 2606:4700:3031::6815:485a
NS2savanna.ns.cloudflare.com, tadeo.ns.cloudflare.com
HTTPS1{"priority":1,"target":".","alpn":["h3",
SOA1savanna.ns.cloudflare.com dns.cloudflare

πŸ“Œ Glue Records Collected

Total: 8

Out-of-bailiwick: 8 (ns01.trs-dns.com, ns01.trs-dns.com, ns01.trs-dns.net...)

Analysis

IP Addresses

Four IP numbers are pointed to by malware.forum: 2606:4700:3030::ac43:b2fc, 2606:4700:3031::6815:485a, 104.21.72.90 and 172.67.178.252.

other host names including emilyhaasch.com, storagevessels.com, mail.networkdestek.gen.tr, nicklopezstudio.com and sofia-obuv.com share IP numbers with malware.forum.

Name Servers

malware.forum is delegated to two name servers savanna.ns.cloudflare.com and tadeo.ns.cloudflare.com.

malware.forum shares the same name server setup as other domains, for instance dostbeykoz.com, kavacikmangal.com, 1001sanat.com, tiyatronline.com and kumlucalalebahcesi.com.

malware.forum at least partially shares name servers with other domains, for instance 4ajersey.com, wdydns.com, kabriproducts.com, infopensii.ro and it-nytt.nu.

these name servers are commonly used alongside shaz.ns.cloudflare.com.

Host names with six IP numbers:

Host name savanna.ns.cloudflare.com points to: 2606:4700:50::a29f:2688, 2803:f800:50::6ca2:c288, 2a06:98c1:50::ac40:2288, 108.162.194.136, 162.159.38.136 and 172.64.34.136.

Host name tadeo.ns.cloudflare.com points to: 2606:4700:58::a29f:2cc5, 2803:f800:50::6ca2:c3c5, 2a06:98c1:50::ac40:23c5, 108.162.195.197, 162.159.44.197 and 172.64.35.197.