Hostname
1ball.st
Last fetched
1ball.st resolves to 104.21.71.108, announced in 104.21.64.0/20 by CLOUDFLARENET - Cloudflare, Inc. in CA. 1ball.st is listed by 2 threat feeds; reconciled level HIGH.
Threat posture
40threat score (procedure-native scale)
HIGHListed by 2 threat feeds. At least one source recommends blocking.
Categories: Phishing
- Threat feeds listing this
- 2
- Verdict coverage
- malicious-evidenced
- First seen on a feed
- Wed, 26 Aug 2026 14:51:26 GMT
- Last seen on a feed
- Mon, 14 Sep 2026 00:15:52 GMT
Nutrition Label
Resolution chain
- 104.21.71.108
104.21.64.0/20 · CLOUDFLARENET - Cloudflare, Inc. · Toronto, CA
- 172.67.144.122
172.67.144.0/20 · CLOUDFLARENET - Cloudflare, Inc. · Toronto, CA
IPv6 resolution
Attribution
Cloudflare
cdn · ORIGIN_AS, CDN
WHOIS identity
WhisperGraph holds no WHOIS registrar, registrant organisation or contact email for 1ball.st. WHOIS is recorded against the registrable domain, so a subdomain such as a www. host carries none of its own — check the registrable domain for this name.
Subdomains
| Subdomain |
|---|
| autodiscover.1ball.st |
| cpanel.1ball.st |
| cpcalendars.1ball.st |
| cpcontacts.1ball.st |
| ftp.1ball.st |
| histats.1ball.st |
| mail.1ball.st |
| webdisk.1ball.st |
| webmail.1ball.st |
| ws.1ball.st |
| www.1ball.st |
Showing 11 of 11 subdomains (11 per page).
Mail and authentication
Nameservers
- beth.ns.cloudflare.com
- dell.ns.cloudflare.com
- pablo.ns.cloudflare.com
- rudy.ns.cloudflare.com
- dns-st.bahnhof.net
- ns1.bahnhof.net
- southeast-2.dns-au.st
- west-2.dns-us.st
MX records
- mx1-hosting.jellyfish.systems
- mx2-hosting.jellyfish.systems
- mx3-hosting.jellyfish.systems
SPF policy
- include: spf.web-hosting.com
- a: 1ball.st
- mx: 1ball.st
- ip: 162.213.255.2
- ip: 162.213.255.5
Threat-feed evidence
History
Related pages
Pivot from 1ball.st into the addresses, networks and registries it depends on.
Cypher and MCP
Reproduce this hostname's resolution chain against graph.whisper.security:
MATCH (h:HOSTNAME {name: "1ball.st"})-[:RESOLVES_TO]->(ip:IPV4)
-[:ANNOUNCED_BY]->(ap:ANNOUNCED_PREFIX)-[:ROUTES]->(a:ASN)
OPTIONAL MATCH (a)-[:HAS_NAME]->(n:ASN_NAME)
RETURN ip.name AS ip, ap.name AS prefix, a.name AS asn, n.name AS network
LIMIT 20Or query Whisper from your own LLM workflow via the Whisper MCP server.