cryptomining-ltd.com Threat Intelligence and Information

Screenshot

alt-text

Dig Results

  • Got answer:
  • -»HEADER«- opcode: QUERY, status: NOERROR, id: 19185
  • flags: qr rd ra QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
  • OPT PSEUDOSECTION:
  • EDNS: version: 0, flags: udp: 1432
  • QUESTION SECTION:
  • cryptomining-ltd.com. IN A
  • ANSWER SECTION:
  • cryptomining-ltd.com. 292 IN A 104.21.30.139
  • cryptomining-ltd.com. 292 IN A 172.67.172.248
  • Query time: 4 msec
  • SERVER: 192.168.1.153(192.168.1.1) (UDP)
  • WHEN: Tue Feb 17 00:09:37 UTC 2026
  • MSG SIZE rcvd: 81

Whois Data

  • Domain Name: CRYPTOMINING-LTD.COM
  • Registry Domain ID: 2973681352_DOMAIN_COM-VRSN
  • Registrar URL: http://www.namecheap.com
  • Updated Date: 2025-04-11T09:21:16Z
  • Creation Date: 2025-04-09T11:47:42Z
  • Registry Expiry Date: 2026-04-09T11:47:42Z
  • Registrar: NameCheap, Inc.
  • Registrar IANA ID: 1068
  • Registrar Abuse Contact Email: abuse@namecheap.com
  • Registrar Abuse Contact Phone: +1.6613102107
  • Name Server: LINA.NS.CLOUDFLARE.COM
  • Name Server: RIDGE.NS.CLOUDFLARE.COM
  • DNSSEC: unsigned
  • Domain name: cryptomining-ltd.com
  • Registry Domain ID: 2973681352_DOMAIN_COM-VRSN
  • Registrar URL: http://www.namecheap.com
  • Updated Date: 0001-01-01T00:00:00.00Z
  • Creation Date: 2025-04-09T11:47:42.00Z
  • Registrar Registration Expiration Date: 2026-04-09T11:47:42.00Z
  • Registrar: NAMECHEAP INC
  • Registrar IANA ID: 1068
  • Registrar Abuse Contact Email: abuse@namecheap.com
  • Registrar Abuse Contact Phone: +1.9854014545
  • Reseller: NAMECHEAP INC
  • Registry Registrant ID:
  • Registrant Name: Redacted for Privacy
  • Registrant Organization: Privacy service provided by Withheld for Privacy ehf
  • Registrant Street: Kalkofnsvegur 2
  • Registrant City: Reykjavik
  • Registrant State/Province: Capital Region
  • Registrant Postal Code: 101
  • Registrant Country: IS
  • Registrant Phone: +354.4212434
  • Registrant Phone Ext:
  • Registrant Fax:
  • Registrant Fax Ext:
  • Registrant Email: ac392b1a6a89434bb78d8da9450d750d.protect@withheldforprivacy.com
  • Registry Admin ID:
  • Admin Name: Redacted for Privacy
  • Admin Organization: Privacy service provided by Withheld for Privacy ehf
  • Admin Street: Kalkofnsvegur 2
  • Admin City: Reykjavik
  • Admin State/Province: Capital Region
  • Admin Postal Code: 101
  • Admin Country: IS
  • Admin Phone: +354.4212434
  • Admin Phone Ext:
  • Admin Fax:
  • Admin Fax Ext:
  • Admin Email: ac392b1a6a89434bb78d8da9450d750d.protect@withheldforprivacy.com
  • Registry Tech ID:
  • Tech Name: Redacted for Privacy
  • Tech Organization: Privacy service provided by Withheld for Privacy ehf
  • Tech Street: Kalkofnsvegur 2
  • Tech City: Reykjavik
  • Tech State/Province: Capital Region
  • Tech Postal Code: 101
  • Tech Country: IS
  • Tech Phone: +354.4212434
  • Tech Phone Ext:
  • Tech Fax:
  • Tech Fax Ext:
  • Tech Email: ac392b1a6a89434bb78d8da9450d750d.protect@withheldforprivacy.com
  • Name Server: lina.ns.cloudflare.com
  • Name Server: ridge.ns.cloudflare.com
  • DNSSEC: unsigned

SSL Certificate Information

  • Certificate:
  • Data:
  • Version: 3 (0x2)
  • Serial Number:
  • 93:55:87:76:b9:56:6e:e4:13:aa:07:a7:ef:9d:52:ee
  • Signature Algorithm: ecdsa-with-SHA256
  • Issuer: C = US, O = Google Trust Services, CN = WE1
  • Validity
  • Not Before: Jan 31 12:57:10 2026 GMT
  • Not After : May 1 13:54:49 2026 GMT
  • Subject: CN = cryptomining-ltd.com
  • Subject Public Key Info:
  • Public Key Algorithm: id-ecPublicKey
  • Public-Key: (256 bit)
  • pub:
  • 04:bf:48:72:8a:1f:4e:ec:c6:28:aa:d2:e4:a1:64:
  • cd:44:e7:a9:67:b5:46:89:5f:6a:cd:01:4e:0f:a8:
  • c0:e6:95:d0:6e:fb:25:bc:30:d8:9d:6f:51:ec:b5:
  • 2f:3f:ac:6b:1d:4b:50:2b:95:40:70:72:f6:e1:c9:
  • ac:cd:22:4c:d1
  • ASN1 OID: prime256v1
  • NIST CURVE: P-256
  • X509v3 extensions:
  • X509v3 Key Usage: critical
  • Digital Signature
  • X509v3 Extended Key Usage:
  • TLS Web Server Authentication
  • X509v3 Basic Constraints: critical
  • CA:FALSE
  • X509v3 Subject Key Identifier:
  • 69:36:33:42:B0:89:87:6E:B7:0C:EC:68:4A:40:D2:AF:77:0A:F6:E2
  • X509v3 Authority Key Identifier:
  • 90:77:92:35:67:C4:FF:A8:CC:A9:E6:7B:D9:80:79:7B:CC:93:F9:38
  • Authority Information Access:
  • OCSP - URI:http://o.pki.goog/s/we1/k1U
  • CA Issuers - URI:http://i.pki.goog/we1.crt
  • X509v3 Subject Alternative Name:
  • DNS:cryptomining-ltd.com, DNS:*.cryptomining-ltd.com
  • X509v3 Certificate Policies:
  • Policy: 2.23.140.1.2.1
  • X509v3 CRL Distribution Points:
  • Full Name:
  • URI:http://c.pki.goog/we1/_hiyWRttjyM.crl
  • CT Precertificate SCTs:
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 96:97:64:BF:55:58:97:AD:F7:43:87:68:37:08:42:77:
  • E9:F0:3A:D5:F6:A4:F3:36:6E:46:A4:3F:0F:CA:A9:C6
  • Timestamp : Jan 31 13:57:11.461 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:60:FD:41:D0:B4:61:E3:4F:18:3E:4A:FD:
  • C2:79:41:61:75:FC:2B:A3:78:47:38:66:18:8F:CF:55:
  • 18:56:62:BD:02:21:00:8D:5B:8F:3B:82:53:04:E1:7B:
  • 82:2B:2D:C1:AB:C1:3F:D0:81:05:E6:3F:8A:A7:73:3C:
  • 99:EE:E8:73:2D:B0:DC
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : CB:38:F7:15:89:7C:84:A1:44:5F:5B:C1:DD:FB:C9:6E:
  • F2:9A:59:CD:47:0A:69:05:85:B0:CB:14:C3:14:58:E7
  • Timestamp : Jan 31 13:57:11.476 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:D5:58:95:51:57:EE:97:B7:7A:0C:76:
  • 2D:17:30:D5:89:35:3F:44:D1:CD:8F:70:10:20:0B:8F:
  • 04:EE:7E:1A:2A:02:20:6E:4A:83:55:AC:B2:D0:89:9B:
  • EC:4C:8B:F1:8A:9A:F5:DA:4A:D0:FF:9E:BA:36:0B:C0:
  • 6E:DF:8F:8F:07:CC:CA
  • Signature Algorithm: ecdsa-with-SHA256
  • Signature Value:
  • 30:45:02:20:01:91:1c:9e:1f:54:f6:67:23:72:76:b1:a0:ab:
  • 5b:a4:d8:66:2e:c1:ba:e5:2f:85:b2:93:ab:ec:1e:23:52:88:
  • 02:21:00:b3:4e:98:7e:eb:52:44:a8:dc:16:3b:cc:b2:8c:de:
  • 72:56:ee:ea:8a:a8:5e:87:43:9b:25:31:a1:f9:da:45:8f

Technologies

Socks4A nginx

*** Virustotal ***

*** WayBackMachine ***

Share on: