covid.wtf Threat Intelligence and Information

Host Location

Screenshot

alt-text

Dig Results

  • Got answer:
  • -»HEADER«- opcode: QUERY, status: NOERROR, id: 26565
  • flags: qr rd ra QUERY: 1, ANSWER: 6, AUTHORITY: 0, ADDITIONAL: 1
  • OPT PSEUDOSECTION:
  • EDNS: version: 0, flags: udp: 1432
  • QUESTION SECTION:
  • covid.wtf. IN A
  • ANSWER SECTION:
  • covid.wtf. 3596 IN A 5.78.156.59
  • covid.wtf. 3596 IN A 5.161.230.87
  • covid.wtf. 3596 IN A 5.161.47.86
  • covid.wtf. 3596 IN A 195.201.128.179
  • covid.wtf. 3596 IN A 46.62.237.138
  • covid.wtf. 3596 IN A 76.223.91.20
  • Query time: 0 msec
  • SERVER: 192.168.1.153(192.168.1.1) (UDP)
  • WHEN: Mon Feb 02 00:05:24 UTC 2026
  • MSG SIZE rcvd: 134

Whois Data

SSL Certificate Information

  • Certificate:
  • Data:
  • Version: 3 (0x2)
  • Serial Number:
  • 06:91:51:4b:86:92:00:e4:74:dd:ed:ca:07:b9:ca:ef:97:3e
  • Signature Algorithm: ecdsa-with-SHA384
  • Issuer: C = US, O = Let’s Encrypt, CN = E8
  • Validity
  • Not Before: Dec 12 01:03:46 2025 GMT
  • Not After : Mar 12 01:03:45 2026 GMT
  • Subject: CN = covid.wtf
  • Subject Public Key Info:
  • Public Key Algorithm: id-ecPublicKey
  • Public-Key: (384 bit)
  • pub:
  • 04:36:46:1a:c3:b8:1b:58:e4:65:4a:95:04:6e:07:
  • 02:ce:f5:8d:9f:7a:b4:17:81:6c:5f:bc:96:94:64:
  • 68:a5:da:7e:60:bc:c8:d0:6a:fd:69:64:68:b4:ec:
  • c1:b9:6f:19:d0:d2:d0:2d:e9:96:1c:70:1d:bf:de:
  • 5a:ef:bb:c5:ec:96:1b:41:ed:59:e7:72:74:cf:58:
  • a6:c2:17:76:6e:58:15:b0:41:44:a3:62:9e:0f:68:
  • 88:f1:60:4a:f6:e6:b0
  • ASN1 OID: secp384r1
  • NIST CURVE: P-384
  • X509v3 extensions:
  • X509v3 Key Usage: critical
  • Digital Signature
  • X509v3 Extended Key Usage:
  • TLS Web Server Authentication, TLS Web Client Authentication
  • X509v3 Basic Constraints: critical
  • CA:FALSE
  • X509v3 Subject Key Identifier:
  • 29:FB:97:C7:89:76:75:FF:4D:B1:4D:7C:FC:D3:04:55:6F:BB:80:48
  • X509v3 Authority Key Identifier:
  • 8F:0D:13:A2:F6:2E:7E:D1:50:6C:33:18:38:5D:59:8E:23:72:91:CA
  • Authority Information Access:
  • CA Issuers - URI:http://e8.i.lencr.org/
  • X509v3 Subject Alternative Name:
  • DNS:covid.wtf, DNS:www.covid.wtf
  • X509v3 Certificate Policies:
  • Policy: 2.23.140.1.2.1
  • X509v3 CRL Distribution Points:
  • Full Name:
  • URI:http://e8.c.lencr.org/63.crl
  • CT Precertificate SCTs:
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 49:9C:9B:69:DE:1D:7C:EC:FC:36:DE:CD:87:64:A6:B8:
  • 5B:AF:0A:87:80:19:D1:55:52:FB:E9:EB:29:DD:F8:C3
  • Timestamp : Dec 12 02:02:16.679 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:61:8D:39:05:20:BF:F1:17:32:00:0E:0C:
  • A6:0C:4D:AC:63:D8:98:82:32:82:F7:97:0F:16:A5:F4:
  • C7:84:BC:EF:02:20:72:1D:16:6D:55:E8:23:30:4B:19:
  • 1E:20:C5:E5:C5:1B:FF:62:83:3F:4B:A6:AC:92:B2:DA:
  • 16:D5:09:BB:FE:1A
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 96:97:64:BF:55:58:97:AD:F7:43:87:68:37:08:42:77:
  • E9:F0:3A:D5:F6:A4:F3:36:6E:46:A4:3F:0F:CA:A9:C6
  • Timestamp : Dec 12 02:02:16.756 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:45:5B:96:97:53:05:A6:79:9C:67:81:38:
  • 13:7D:41:05:FF:30:19:37:A2:5B:CD:C5:6C:7F:D4:7F:
  • 6D:74:D7:E5:02:20:53:DC:5D:A3:16:4D:2D:57:B8:67:
  • B7:CC:59:25:0E:64:49:43:A7:1A:40:B9:3B:B1:E0:71:
  • 10:99:66:53:D2:05
  • Signature Algorithm: ecdsa-with-SHA384
  • Signature Value:
  • 30:65:02:30:65:02:5f:77:ae:b7:c6:97:03:1e:2a:06:0a:23:
  • 88:e9:2c:0c:e7:9b:25:91:7a:f4:f7:c5:06:8f:42:cb:99:e3:
  • 27:8e:b1:5e:3b:cc:4d:e6:0d:a2:9f:61:00:d0:eb:ee:02:31:
  • 00:fc:2a:dd:52:2d:42:21:b5:21:88:8b:0e:d5:e8:61:f1:51:
  • 9c:b6:47:68:98:b8:b5:2e:43:10:6e:a0:af:33:f1:e4:53:b9:
  • 00:9a:0b:af:cb:64:cb:9a:eb:96:e2:33:64

*** Virustotal ***

*** WayBackMachine ***

Share on: