bitcoin-scam.net Threat Intelligence and Information
Apr 25, 2022
domainpage
Host Location
Dig Results
- Got answer:
- -»HEADER«- opcode: QUERY, status: NOERROR, id: 32772
- flags: qr rd ra QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
- OPT PSEUDOSECTION:
- EDNS: version: 0, flags: udp: 1232
- QUESTION SECTION:
- bitcoin-scam.net. IN A
- ANSWER SECTION:
- bitcoin-scam.net. 300 IN A 172.67.217.205
- bitcoin-scam.net. 300 IN A 104.21.94.7
- Query time: 12 msec
- SERVER: 192.168.1.153(192.168.1.1)
- WHEN: Thu May 05 00:49:20 UTC 2022
- MSG SIZE rcvd: 77
DNS Records
- SOA malavika.ns.cloudflare.com 108.162.194.165
- SOA malavika.ns.cloudflare.com 162.159.38.165
- SOA malavika.ns.cloudflare.com 172.64.34.165
- NS malavika.ns.cloudflare.com 172.64.34.165
- NS malavika.ns.cloudflare.com 162.159.38.165
- NS malavika.ns.cloudflare.com 108.162.194.165
- NS malavika.ns.cloudflare.com 2606:4700:50::a29f:26a5
- NS malavika.ns.cloudflare.com 2803:f800:50::6ca2:c2a5
- NS malavika.ns.cloudflare.com 2a06:98c1:50::ac40:22a5
- NS peter.ns.cloudflare.com 108.162.195.3
- NS peter.ns.cloudflare.com 162.159.44.3
- NS peter.ns.cloudflare.com 172.64.35.3
- NS peter.ns.cloudflare.com 2606:4700:58::a29f:2c03
- NS peter.ns.cloudflare.com 2803:f800:50::6ca2:c303
- NS peter.ns.cloudflare.com 2a06:98c1:50::ac40:2303
- MX amir.mx.cloudflare.net 162.159.205.11
- MX amir.mx.cloudflare.net 162.159.205.12
- MX amir.mx.cloudflare.net 162.159.205.13
- MX linda.mx.cloudflare.net 162.159.205.23
- MX linda.mx.cloudflare.net 162.159.205.24
- MX linda.mx.cloudflare.net 162.159.205.25
- MX isaac.mx.cloudflare.net 162.159.205.17
- MX isaac.mx.cloudflare.net 162.159.205.18
- MX isaac.mx.cloudflare.net 162.159.205.19
- MX amir.mx.cloudflare.net 2606:4700:f5::11
- MX amir.mx.cloudflare.net 2606:4700:f5::12
- MX amir.mx.cloudflare.net 2606:4700:f5::13
- MX linda.mx.cloudflare.net 2606:4700:f5::b
- MX linda.mx.cloudflare.net 2606:4700:f5::c
- MX linda.mx.cloudflare.net 2606:4700:f5::d
- MX isaac.mx.cloudflare.net 2606:4700:f5::e
- MX isaac.mx.cloudflare.net 2606:4700:f5::f
- MX isaac.mx.cloudflare.net 2606:4700:f5::10
- A bitcoin-scam.net 172.67.217.205
- A bitcoin-scam.net 104.21.94.7
- AAAA bitcoin-scam.net 2606:4700:3034::ac43:d9cd
- AAAA bitcoin-scam.net 2606:4700:3037::6815:5e07
Whois Data
- Domain Name: BITCOIN-SCAM.NET
- Registry Domain ID: 2645217808_DOMAIN_NET-VRSN
- Registrar URL: http://www.namecheap.com
- Updated Date: 2021-10-05T17:39:05Z
- Creation Date: 2021-10-03T09:16:49Z
- Registry Expiry Date: 2022-10-03T09:16:49Z
- Registrar: NameCheap, Inc.
- Registrar IANA ID: 1068
- Registrar Abuse Contact Email: abuse@namecheap.com
- Registrar Abuse Contact Phone: +1.6613102107
- Name Server: MALAVIKA.NS.CLOUDFLARE.COM
- Name Server: PETER.NS.CLOUDFLARE.COM
- DNSSEC: unsigned
- Domain name: bitcoin-scam.net
- Registry Domain ID: 2645217808_DOMAIN_NET-VRSN
- Registrar URL: http://www.namecheap.com
- Updated Date: 0001-01-01T00:00:00.00Z
- Creation Date: 2021-10-03T09:16:49.00Z
- Registrar Registration Expiration Date: 2022-10-03T09:16:49.00Z
- Registrar: NAMECHEAP INC
- Registrar IANA ID: 1068
- Registrar Abuse Contact Email: abuse@namecheap.com
- Registrar Abuse Contact Phone: +1.9854014545
- Reseller: NAMECHEAP INC
- Registry Registrant ID:
- Registrant Name: Redacted for Privacy
- Registrant Organization: Privacy service provided by Withheld for Privacy ehf
- Registrant Street: Kalkofnsvegur 2
- Registrant City: Reykjavik
- Registrant State/Province: Capital Region
- Registrant Postal Code: 101
- Registrant Country: IS
- Registrant Phone: +354.4212434
- Registrant Phone Ext:
- Registrant Fax:
- Registrant Fax Ext:
- Registrant Email: 631d3fb18d6d49bd8dbd4b95de740a58.protect@withheldforprivacy.com
- Registry Admin ID:
- Admin Name: Redacted for Privacy
- Admin Organization: Privacy service provided by Withheld for Privacy ehf
- Admin Street: Kalkofnsvegur 2
- Admin City: Reykjavik
- Admin State/Province: Capital Region
- Admin Postal Code: 101
- Admin Country: IS
- Admin Phone: +354.4212434
- Admin Phone Ext:
- Admin Fax:
- Admin Fax Ext:
- Admin Email: 631d3fb18d6d49bd8dbd4b95de740a58.protect@withheldforprivacy.com
- Registry Tech ID:
- Tech Name: Redacted for Privacy
- Tech Organization: Privacy service provided by Withheld for Privacy ehf
- Tech Street: Kalkofnsvegur 2
- Tech City: Reykjavik
- Tech State/Province: Capital Region
- Tech Postal Code: 101
- Tech Country: IS
- Tech Phone: +354.4212434
- Tech Phone Ext:
- Tech Fax:
- Tech Fax Ext:
- Tech Email: 631d3fb18d6d49bd8dbd4b95de740a58.protect@withheldforprivacy.com
- Name Server: malavika.ns.cloudflare.com
- Name Server: peter.ns.cloudflare.com
- DNSSEC: unsigned
SSL Certificate Information
- Certificate:
- Data:
- Version: 3 (0x2)
- Serial Number:
- 01:2e:94:8b:dd:07:08:05:7e:fc:db:dd:28:53:a5:b4
- Signature Algorithm: ecdsa-with-SHA256
- Issuer: C = US, O = “Cloudflare, Inc.”, CN = Cloudflare Inc ECC CA-3
- Validity
- Not Before: Oct 6 00:00:00 2021 GMT
- Not After : Oct 5 23:59:59 2022 GMT
- Subject: C = US, ST = California, L = San Francisco, O = “Cloudflare, Inc.”, CN = sni.cloudflaressl.com
- Subject Public Key Info:
- Public Key Algorithm: id-ecPublicKey
- Public-Key: (256 bit)
- pub:
- 04:bc:ac:19:9d:ec:38:0f:83:85:c0:95:72:c0:cf:
- 9a:2d:21:04:43:df:c4:64:89:c7:d9:9e:82:97:3f:
- 3f:8b:d4:b3:99:42:41:0b:6e:25:70:79:a1:87:bc:
- bc:75:98:26:2e:75:36:99:b3:31:20:54:5a:a3:3f:
- af:c0:5f:a2:1a
- ASN1 OID: prime256v1
- NIST CURVE: P-256
- X509v3 extensions:
- X509v3 Authority Key Identifier:
- keyid:A5:CE:37:EA:EB:B0:75:0E:94:67:88:B4:45:FA:D9:24:10:87:96:1F
- X509v3 Subject Key Identifier:
- 75:1A:27:09:8F:B8:81:DD:2F:A9:2E:E3:1B:4E:67:A7:B7:99:E1:99
- X509v3 Subject Alternative Name:
- DNS:bitcoin-scam.net, DNS:sni.cloudflaressl.com, DNS:*.bitcoin-scam.net
- X509v3 Key Usage: critical
- Digital Signature
- X509v3 Extended Key Usage:
- TLS Web Server Authentication, TLS Web Client Authentication
- X509v3 CRL Distribution Points:
- Full Name:
- URI:http://crl3.digicert.com/CloudflareIncECCCA-3.crl
- Full Name:
- URI:http://crl4.digicert.com/CloudflareIncECCCA-3.crl
- X509v3 Certificate Policies:
- Policy: 2.23.140.1.2.2
- CPS: http://www.digicert.com/CPS
- Authority Information Access:
- OCSP - URI:http://ocsp.digicert.com
- CA Issuers - URI:http://cacerts.digicert.com/CloudflareIncECCCA-3.crt
- X509v3 Basic Constraints: critical
- CA:FALSE
- CT Precertificate SCTs:
- Signed Certificate Timestamp:
- Version : v1 (0x0)
- Log ID : 29:79:BE:F0:9E:39:39:21:F0:56:73:9F:63:A5:77:E5:
- BE:57:7D:9C:60:0A:F8:F9:4D:5D:26:5C:25:5D:C7:84
- Timestamp : Oct 6 13:54:21.945 2021 GMT
- Extensions: none
- Signature : ecdsa-with-SHA256
- 30:44:02:20:62:9A:73:2B:BB:94:A4:DF:AC:42:CE:85:
- 4F:12:94:43:66:68:8D:C0:FE:31:1F:78:92:84:DB:FC:
- 3C:C8:B2:A1:02:20:03:2C:B2:67:D3:13:EA:07:03:66:
- AC:C0:69:E7:87:AD:17:BD:3A:1D:37:01:AA:02:A9:B8:
- 24:1C:7C:29:D1:21
- Signed Certificate Timestamp:
- Version : v1 (0x0)
- Log ID : 51:A3:B0:F5:FD:01:79:9C:56:6D:B8:37:78:8F:0C:A4:
- 7A:CC:1B:27:CB:F7:9E:88:42:9A:0D:FE:D4:8B:05:E5
- Timestamp : Oct 6 13:54:22.045 2021 GMT
- Extensions: none
- Signature : ecdsa-with-SHA256
- 30:45:02:20:61:07:8D:7B:DE:F6:CA:11:F5:90:D5:CE:
- 16:D4:B6:AE:8D:71:2C:A5:99:4B:E4:D8:B9:2F:E0:07:
- 12:F6:A3:F9:02:21:00:D9:62:EA:60:B6:37:34:1E:85:
- 5C:F2:4B:6A:E6:92:66:DE:CA:59:0A:2E:AA:18:27:F9:
- 47:8A:89:73:E8:C7:A2
- Signed Certificate Timestamp:
- Version : v1 (0x0)
- Log ID : 41:C8:CA:B1:DF:22:46:4A:10:C6:A1:3A:09:42:87:5E:
- 4E:31:8B:1B:03:EB:EB:4B:C7:68:F0:90:62:96:06:F6
- Timestamp : Oct 6 13:54:21.963 2021 GMT
- Extensions: none
- Signature : ecdsa-with-SHA256
- 30:44:02:20:1F:42:38:C5:35:82:CF:F7:FE:47:30:35:
- 62:12:E0:00:B9:B3:A4:1A:26:47:A9:1E:F7:4E:70:31:
- F3:DF:78:43:02:20:16:2C:82:71:AE:A8:DA:67:01:FF:
- 02:B3:7B:92:AA:C3:8C:F0:7B:D4:DF:D0:DD:2B:DB:79:
- 03:39:65:F6:A8:6D
- Signature Algorithm: ecdsa-with-SHA256
- 30:45:02:20:2f:7c:d6:cf:4b:75:67:b5:18:1c:93:85:07:71:
- 96:a5:df:16:b1:5b:28:a1:6a:05:97:bc:cb:24:34:d1:0c:80:
- 02:21:00:80:0e:25:ff:1f:a4:70:94:c3:68:29:85:59:14:7d:
- 84:9e:b0:c8:eb:dc:5c:43:66:73:a5:78:41:c7:0f:9c:d2