citibank-login.com Threat Intelligence and Information

Host Location

Dig Results

  • Got answer:
  • -»HEADER«- opcode: QUERY, status: NOERROR, id: 29668
  • flags: qr rd ra QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
  • OPT PSEUDOSECTION:
  • EDNS: version: 0, flags: udp: 1232
  • QUESTION SECTION:
  • citibank-login.com. IN A
  • ANSWER SECTION:
  • citibank-login.com. 293 IN A 104.21.45.111
  • citibank-login.com. 293 IN A 172.67.213.144
  • Query time: 20 msec
  • SERVER: 192.168.1.153(192.168.1.1)
  • WHEN: Mon Apr 18 02:34:10 UTC 2022
  • MSG SIZE rcvd: 79

DNS Records

  • SOA guy.ns.cloudflare.com 108.162.193.173
  • SOA guy.ns.cloudflare.com 172.64.33.173
  • SOA guy.ns.cloudflare.com 173.245.59.173
  • SOA guy.ns.cloudflare.com 2606:4700:58::adf5:3bad
  • SOA guy.ns.cloudflare.com 2803:f800:50::6ca2:c1ad
  • SOA guy.ns.cloudflare.com 2a06:98c1:50::ac40:21ad
  • NS guy.ns.cloudflare.com 172.64.33.173
  • NS guy.ns.cloudflare.com 108.162.193.173
  • NS guy.ns.cloudflare.com 173.245.59.173
  • NS guy.ns.cloudflare.com 2a06:98c1:50::ac40:21ad
  • NS guy.ns.cloudflare.com 2803:f800:50::6ca2:c1ad
  • NS guy.ns.cloudflare.com 2606:4700:58::adf5:3bad
  • NS jacqueline.ns.cloudflare.com 108.162.194.132
  • NS jacqueline.ns.cloudflare.com 162.159.38.132
  • NS jacqueline.ns.cloudflare.com 172.64.34.132
  • NS jacqueline.ns.cloudflare.com 2606:4700:50::a29f:2684
  • NS jacqueline.ns.cloudflare.com 2803:f800:50::6ca2:c284
  • NS jacqueline.ns.cloudflare.com 2a06:98c1:50::ac40:2284
  • A citibank-login.com 172.67.213.144
  • A citibank-login.com 104.21.45.111
  • AAAA citibank-login.com 2606:4700:3037::ac43:d590
  • AAAA citibank-login.com 2606:4700:3031::6815:2d6f

Whois Data

  • Domain Name: CITIBANK-LOGIN.COM
  • Registry Domain ID: 2688976301_DOMAIN_COM-VRSN
  • Registrar URL: http://www.publicdomainregistry.com
  • Updated Date: 2022-04-15T08:52:58Z
  • Creation Date: 2022-04-13T17:19:20Z
  • Registry Expiry Date: 2023-04-13T17:19:20Z
  • Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
  • Registrar IANA ID: 303
  • Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
  • Registrar Abuse Contact Phone: +1.2013775952
  • Name Server: GUY.NS.CLOUDFLARE.COM
  • Name Server: JACQUELINE.NS.CLOUDFLARE.COM
  • DNSSEC: unsigned

SSL Certificate Information

  • Certificate:
  • Data:
  • Version: 3 (0x2)
  • Serial Number:
  • 05:77:0f:aa:6a:0d:d3:9e:8b:39:fa:2b:97:18:7f:c5
  • Signature Algorithm: ecdsa-with-SHA256
  • Issuer: C = US, O = “Cloudflare, Inc.”, CN = Cloudflare Inc ECC CA-3
  • Validity
  • Not Before: Apr 15 00:00:00 2022 GMT
  • Not After : Apr 14 23:59:59 2023 GMT
  • Subject: C = US, ST = California, L = San Francisco, O = “Cloudflare, Inc.”, CN = sni.cloudflaressl.com
  • Subject Public Key Info:
  • Public Key Algorithm: id-ecPublicKey
  • Public-Key: (256 bit)
  • pub:
  • 04:51:b6:37:cd:e6:aa:64:a9:c6:5e:ea:6a:f1:60:
  • d6:57:6b:f3:ad:9c:96:3d:cc:c7:c3:bb:cf:b3:30:
  • e8:ad:8d:53:27:b9:c8:8f:10:13:ee:aa:ac:59:92:
  • 8d:b5:ed:f1:02:4f:93:b8:7d:91:5c:5c:4a:c6:79:
  • 17:89:68:6d:83
  • ASN1 OID: prime256v1
  • NIST CURVE: P-256
  • X509v3 extensions:
  • X509v3 Authority Key Identifier:
  • keyid:A5:CE:37:EA:EB:B0:75:0E:94:67:88:B4:45:FA:D9:24:10:87:96:1F
  • X509v3 Subject Key Identifier:
  • 96:4B:F3:1A:D7:FE:24:A0:29:5B:23:DF:02:9C:68:E8:23:E2:05:73
  • X509v3 Subject Alternative Name:
  • DNS:*.citibank-login.com, DNS:citibank-login.com, DNS:sni.cloudflaressl.com
  • X509v3 Key Usage: critical
  • Digital Signature
  • X509v3 Extended Key Usage:
  • TLS Web Server Authentication, TLS Web Client Authentication
  • X509v3 CRL Distribution Points:
  • Full Name:
  • URI:http://crl3.digicert.com/CloudflareIncECCCA-3.crl
  • Full Name:
  • URI:http://crl4.digicert.com/CloudflareIncECCCA-3.crl
  • X509v3 Certificate Policies:
  • Policy: 2.23.140.1.2.2
  • CPS: http://www.digicert.com/CPS
  • Authority Information Access:
  • OCSP - URI:http://ocsp.digicert.com
  • CA Issuers - URI:http://cacerts.digicert.com/CloudflareIncECCCA-3.crt
  • X509v3 Basic Constraints: critical
  • CA:FALSE
  • CT Precertificate SCTs:
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : E8:3E:D0:DA:3E:F5:06:35:32:E7:57:28:BC:89:6B:C9:
  • 03:D3:CB:D1:11:6B:EC:EB:69:E1:77:7D:6D:06:BD:6E
  • Timestamp : Apr 15 08:53:28.613 2022 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:87:28:03:28:6C:EC:90:53:56:83:5C:
  • FD:B3:2B:F3:23:26:88:68:1D:00:B4:DC:DD:19:7F:9E:
  • 20:C8:F4:86:AF:02:21:00:DF:8D:B1:BC:C1:15:A8:33:
  • 65:D5:FC:95:06:92:61:A1:7B:B5:C7:73:45:A9:5A:3F:
  • 63:C4:C6:0B:17:50:F0:10
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 35:CF:19:1B:BF:B1:6C:57:BF:0F:AD:4C:6D:42:CB:BB:
  • B6:27:20:26:51:EA:3F:E1:2A:EF:A8:03:C3:3B:D6:4C
  • Timestamp : Apr 15 08:53:28.638 2022 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:0B:8A:6B:A5:F7:50:23:84:D6:3E:9D:05:
  • 86:7B:D1:99:AA:C6:6F:30:35:41:87:02:6B:F8:BC:6C:
  • 41:30:73:2B:02:21:00:DB:68:D8:58:41:DC:59:51:A3:
  • E9:BF:34:85:4E:5A:00:47:E8:7A:21:D4:91:9A:A2:28:
  • 5E:B0:3E:E8:00:37:37
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : B3:73:77:07:E1:84:50:F8:63:86:D6:05:A9:DC:11:09:
  • 4A:79:2D:B1:67:0C:0B:87:DC:F0:03:0E:79:36:A5:9A
  • Timestamp : Apr 15 08:53:28.669 2022 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:3A:A9:6E:B2:45:99:D1:4C:27:04:45:3C:
  • D5:4A:A6:21:63:4C:C9:F7:0D:1D:47:08:95:AF:21:F5:
  • 85:42:3A:81:02:20:1B:19:B3:70:80:A7:4A:A9:00:63:
  • 7C:14:6B:4F:72:F8:15:81:97:2A:52:C3:2C:72:23:30:
  • F1:04:38:C2:E7:9B
  • Signature Algorithm: ecdsa-with-SHA256
  • 30:45:02:21:00:a0:ca:90:5d:81:23:e0:ee:9a:9b:c6:5b:2a:
  • 70:b8:28:7f:45:b9:8a:04:94:0f:a7:21:9e:5d:5a:67:80:04:
  • c3:02:20:18:d4:32:ea:30:8a:1f:a6:50:9f:9b:c3:26:37:5b:
  • b2:c3:34:c6:6a:be:18:07:a4:8f:cc:3e:bd:f7:c8:44:c8

Sitemap

Technologies

*** Virustotal ***

*** WayBackMachine ***

Share on: