malwarewatch.org - robtex.com

malwarewatch.org

DNSSEC⚠️ Not signed
A2606:4700:3034::6815:2eb0πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3034::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A2606:4700:3035::ac43:a8cfπŸ‡ΊπŸ‡Έ Cloudflare2606:4700:3035::/48 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A104.21.46.176Cloudflare104.21.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
A172.67.168.207πŸ‡ΊπŸ‡Έ Cloudflare172.67.160.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US βœ“ In HTTPS hints
NSelliott.ns.cloudflare.com ⭐
A2606:4700:58::a29f:2ce4πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRelliott.ns.cloudflare.com
A2803:f800:50::6ca2:c3e4πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRelliott.ns.cloudflare.com
A2a06:98c1:50::ac40:23e4πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRelliott.ns.cloudflare.com
A108.162.195.228πŸ‡ΊπŸ‡Έ Cloudflare108.162.195.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRelliott.ns.cloudflare.com
A162.159.44.228Cloudflare162.159.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRelliott.ns.cloudflare.com
A172.64.35.228πŸ‡ΊπŸ‡Έ Cloudflare172.64.35.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRelliott.ns.cloudflare.com
NSfrida.ns.cloudflare.com
A2606:4700:50::a29f:2689πŸ‡ΊπŸ‡Έ Cloudflare2606:4700:50::/44 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRfrida.ns.cloudflare.com
A2803:f800:50::6ca2:c289πŸ‡¨πŸ‡· Cloudflare2803:f800:50::/45 LACNIC generated route6 for CloudFlare Latin America S.R.L
PTRfrida.ns.cloudflare.com
A2a06:98c1:50::ac40:2289πŸ‡ΊπŸ‡Έ Cloudflare2a06:98c1:50::/45
PTRfrida.ns.cloudflare.com
A108.162.194.137πŸ‡ΊπŸ‡Έ Cloudflare108.162.194.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRfrida.ns.cloudflare.com
A162.159.38.137Cloudflare162.159.32.0/20 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRfrida.ns.cloudflare.com
A172.64.34.137πŸ‡ΊπŸ‡Έ Cloudflare172.64.34.0/24 , Inc. 101 Townsend Street, San Francisco, California 94107, US
PTRfrida.ns.cloudflare.com
MXwitcher-relay.mxrouting.net ⭐
A45.43.208.43πŸ‡ΊπŸ‡Έ QUICKPACKET45.43.208.0/24 QuickPacket LLC
PTRwitcher.mxrouting.net
MXwitcher.mxrouting.net(20)
A45.43.208.43πŸ‡ΊπŸ‡Έ QUICKPACKET45.43.208.0/24 QuickPacket LLC
PTRwitcher.mxrouting.net
TXTgoogle-site-verification=wIwN7OHZfkO1G-eLMhQ_VsfEdlDMFrXXgqLZJWj1PBI
TXTv=spf1 include:mxlogin.com -all
HTTPSHTTP/3, HTTP/2 βœ“ hints match
IPv4 hints104.21.46.176, 172.67.168.207
IPv6 hints2606:4700:3034::6815:2eb0, 2606:4700:3035::ac43:a8cf
ECHX25519, HKDF-SHA256 + AES-128-GCM draft, id=45, name=cloudflare-ech.com
SOAelliott.ns.cloudflare.comdns@cloudflare.com serial=2401652103

org

DNSSECπŸ”’ Signed (DS record present)
NSa0.org.afilias-nst.info ⭐ ⚠️ Not in parent delegation
NSa2.org.afilias-nst.info ⚠️ Not in parent delegation
NSb0.org.afilias-nst.org
NSb2.org.afilias-nst.org
NSc0.org.afilias-nst.info ⚠️ Not in parent delegation
NSd0.org.afilias-nst.org
SOAa0.org.afilias-nst.infohostmaster@donuts.email serial=1778828170
WOT: SAFE (50/100)

Same first word

DNS History

8 records (8 active, 0 former)

NSelliott.ns.cloudflare.comfrida.ns.cloudflare.comMXwitcher-relay.mxrouting.netwitcher.mxrouting.netA104.21.46.176172.67.168.2072606:4700:3034::6815:2eb02606:4700:3035::ac43:a8cf
●NSelliott.ns.cloudflare.com2026-05-12 β†’ 2026-05-15 Β· 2 obs
● 2026-05-12 06:09:06
● 2026-05-15 07:07:36
●NSfrida.ns.cloudflare.com2026-05-12 β†’ 2026-05-15 Β· 2 obs
● 2026-05-12 06:09:06
● 2026-05-15 07:07:36
●MXwitcher-relay.mxrouting.net2026-05-12 β†’ 2026-05-15 Β· 2 obs
● 2026-05-12 06:09:06
● 2026-05-15 07:07:36
●MXwitcher.mxrouting.net2026-05-12 β†’ 2026-05-15 Β· 2 obs
● 2026-05-12 06:09:06
● 2026-05-15 07:07:36
●A104.21.46.1762026-05-12 β†’ 2026-05-15 Β· 2 obs
● 2026-05-12 06:09:06
● 2026-05-15 07:07:36
●A172.67.168.2072026-05-12 β†’ 2026-05-15 Β· 2 obs
● 2026-05-12 06:09:06
● 2026-05-15 07:07:36
●A2606:4700:3034::6815:2eb02026-05-12 β†’ 2026-05-15 Β· 2 obs
● 2026-05-12 06:09:06
● 2026-05-15 07:07:36
●A2606:4700:3035::ac43:a8cf2026-05-12 β†’ 2026-05-15 Β· 2 obs
● 2026-05-12 06:09:06
● 2026-05-15 07:07:36

πŸ” DNS Trace

πŸ“‹ Delegation Chain

ZoneNameserversGlue
orgb0.org.afilias-nst.org, b2.org.afilias-nst.org, d0.org.afilias-nst.org-
malwarewatch.orgelliott.ns.cloudflare.com, frida.ns.cloudflare.com-

βœ… Authoritative Response

Server:108.162.194.137

NS records: elliott.ns.cloudflare.com, frida.ns.cloudflare.com

πŸ”’ DNSSEC Status

⚠️ Insecure (no DNSSEC)

No DS record for malwarewatch.org (unsigned zone)

⏱️ Timing

Total: 591ms | Queries: -

πŸ“„ Records

TypeCountSample Data
A2172.67.168.207, 104.21.46.176
AAAA22606:4700:3034::6815:2eb0, 2606:4700:3035::ac43:a8cf
NS2elliott.ns.cloudflare.com, frida.ns.cloudflare.com
MX2witcher.mxrouting.net (pri: 10), witcher-relay.mxrouting.net (pri: 20)
TXT2google-site-verification=wIwN7OHZfkO1G-e, v=spf1 include:mxlogin.com -all
HTTPS1{"priority":1,"target":".","alpn":["h3",
SOA1elliott.ns.cloudflare.com dns.cloudflare

Analysis

IP Addresses

malwarewatch.org maps to four IP numbers: 2606:4700:3034::6815:2eb0, 2606:4700:3035::ac43:a8cf, 104.21.46.176 and 172.67.168.207.

Other host names such as toto-dagim.co.il, infowebworld.com, confirmation-id38247.com, www.pfc.co.za and 3core.net share IPs with malwarewatch.org.

Name Servers

Two name servers elliott.ns.cloudflare.com and frida.ns.cloudflare.com handle the delegation for malwarewatch.org.

malwarewatch.org shares the same name server setup as other domains, for example balloonlane.com, budase.com, skygod.com, camalolo.com and bricomarche.pl.

malwarewatch.org at least partially shares name servers with other domains, for example gachmen.io.vn, fcspartak.tv, paris-tickets.net, gutenberg.gr and realizeparadise.com.

These name servers are commonly used with emma.ns.cloudflare.com and anton.ns.cloudflare.com and evelyn.ns.cloudflare.com.

Host names with six IP numbers:

elliott.ns.cloudflare.com points to 2606:4700:58::a29f:2ce4, 2803:f800:50::6ca2:c3e4, 2a06:98c1:50::ac40:23e4, 108.162.195.228, 162.159.44.228 and 172.64.35.228.

frida.ns.cloudflare.com points to 2606:4700:50::a29f:2689, 2803:f800:50::6ca2:c289, 2a06:98c1:50::ac40:2289, 108.162.194.137, 162.159.38.137 and 172.64.34.137.

Mail Servers

Two mail servers handle malwarewatch.org: witcher-relay.mxrouting.net and witcher.mxrouting.net.

malwarewatch.org shares the same mail server setup as other domains, including breefer.dk, protectkiwi.net, xuyh0120.win, perbenaemas.com.my and salvagestore.com.

malwarewatch.org shares at least partially some mail servers with other domains, for instance thomasdefler.com, hands.poker, cidadewap.mobi, ceprep.mx and jouwvoedingsplan.nl.

Host names with a single IP:

witcher-relay.mxrouting.net points to 45.43.208.43.

witcher.mxrouting.net points to 45.43.208.43.

Host names pointing to 45.43.208.43: witcher-relay.mxrouting.net and witcher.mxrouting.net.