Google DNS is reporting back a different IP for me when I query perl.com (same subnet though). It's all part of the Google Cloud /13 block.
Sure it may have been used for malware, but given those IPs float between ephemeral cloud instances, it does not mean it is currently being used for malware.