downloadmalware.net Threat Intelligence and Information

Screenshot

alt-text

Dig Results

  • Got answer:
  • -»HEADER«- opcode: QUERY, status: NOERROR, id: 28185
  • flags: qr rd ra QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
  • OPT PSEUDOSECTION:
  • EDNS: version: 0, flags: udp: 1432
  • QUESTION SECTION:
  • downloadmalware.net. IN A
  • ANSWER SECTION:
  • downloadmalware.net. 296 IN A 104.21.11.83
  • downloadmalware.net. 296 IN A 172.67.165.172
  • Query time: 4 msec
  • SERVER: 192.168.1.153(192.168.1.1) (UDP)
  • WHEN: Fri Jan 30 00:06:57 UTC 2026
  • MSG SIZE rcvd: 80

Whois Data

  • Domain Name: DOWNLOADMALWARE.NET
  • Registry Domain ID: 2672242766_DOMAIN_NET-VRSN
  • Registrar URL: http://www.namecheap.com
  • Updated Date: 2026-01-02T16:28:17Z
  • Creation Date: 2022-02-01T01:43:45Z
  • Registry Expiry Date: 2027-02-01T01:43:45Z
  • Registrar: NameCheap, Inc.
  • Registrar IANA ID: 1068
  • Registrar Abuse Contact Email: abuse@namecheap.com
  • Registrar Abuse Contact Phone: +1.6613102107
  • Name Server: TIM.NS.CLOUDFLARE.COM
  • Name Server: VERA.NS.CLOUDFLARE.COM
  • DNSSEC: unsigned
  • Domain name: downloadmalware.net
  • Registry Domain ID: 2672242766_DOMAIN_NET-VRSN
  • Registrar URL: http://www.namecheap.com
  • Updated Date: 2026-01-02T16:28:17.92Z
  • Creation Date: 2022-02-01T01:43:45.00Z
  • Registrar Registration Expiration Date: 2027-02-01T01:43:45.00Z
  • Registrar: NAMECHEAP INC
  • Registrar IANA ID: 1068
  • Registrar Abuse Contact Email: abuse@namecheap.com
  • Registrar Abuse Contact Phone: +1.9854014545
  • Reseller: NAMECHEAP INC
  • Registry Registrant ID:
  • Registrant Name: Redacted for Privacy
  • Registrant Organization: Privacy service provided by Withheld for Privacy ehf
  • Registrant Street: Kalkofnsvegur 2
  • Registrant City: Reykjavik
  • Registrant State/Province: Capital Region
  • Registrant Postal Code: 101
  • Registrant Country: IS
  • Registrant Phone: +354.4212434
  • Registrant Phone Ext:
  • Registrant Fax:
  • Registrant Fax Ext:
  • Registrant Email: c91bf7563de74edc8c2620d9ca5affa1.protect@withheldforprivacy.com
  • Registry Admin ID:
  • Admin Name: Redacted for Privacy
  • Admin Organization: Privacy service provided by Withheld for Privacy ehf
  • Admin Street: Kalkofnsvegur 2
  • Admin City: Reykjavik
  • Admin State/Province: Capital Region
  • Admin Postal Code: 101
  • Admin Country: IS
  • Admin Phone: +354.4212434
  • Admin Phone Ext:
  • Admin Fax:
  • Admin Fax Ext:
  • Admin Email: c91bf7563de74edc8c2620d9ca5affa1.protect@withheldforprivacy.com
  • Registry Tech ID:
  • Tech Name: Redacted for Privacy
  • Tech Organization: Privacy service provided by Withheld for Privacy ehf
  • Tech Street: Kalkofnsvegur 2
  • Tech City: Reykjavik
  • Tech State/Province: Capital Region
  • Tech Postal Code: 101
  • Tech Country: IS
  • Tech Phone: +354.4212434
  • Tech Phone Ext:
  • Tech Fax:
  • Tech Fax Ext:
  • Tech Email: c91bf7563de74edc8c2620d9ca5affa1.protect@withheldforprivacy.com
  • Name Server: tim.ns.cloudflare.com
  • Name Server: vera.ns.cloudflare.com
  • DNSSEC: unsigned

SSL Certificate Information

  • Certificate:
  • Data:
  • Version: 3 (0x2)
  • Serial Number:
  • 9f:34:a5:48:b3:09:14:2d:13:25:35:10:0a:02:f3:e7
  • Signature Algorithm: ecdsa-with-SHA256
  • Issuer: C = US, O = Google Trust Services, CN = WE1
  • Validity
  • Not Before: Jan 27 23:34:30 2026 GMT
  • Not After : Apr 28 00:31:55 2026 GMT
  • Subject: CN = downloadmalware.net
  • Subject Public Key Info:
  • Public Key Algorithm: id-ecPublicKey
  • Public-Key: (256 bit)
  • pub:
  • 04:b7:f7:50:bf:6d:24:92:2b:e4:bb:b7:55:91:32:
  • d7:5c:0d:4a:61:86:bd:ad:4d:27:21:85:e9:9b:7f:
  • 99:b8:c9:46:16:66:7f:b4:c4:6a:9f:a0:51:e2:53:
  • f1:d4:82:55:d2:91:16:ee:44:cc:30:6a:0a:d2:69:
  • 8c:b8:4a:84:56
  • ASN1 OID: prime256v1
  • NIST CURVE: P-256
  • X509v3 extensions:
  • X509v3 Key Usage: critical
  • Digital Signature
  • X509v3 Extended Key Usage:
  • TLS Web Server Authentication
  • X509v3 Basic Constraints: critical
  • CA:FALSE
  • X509v3 Subject Key Identifier:
  • 17:23:89:01:FA:FB:9F:1A:8B:FC:5D:67:74:6D:7C:FC:94:71:60:32
  • X509v3 Authority Key Identifier:
  • 90:77:92:35:67:C4:FF:A8:CC:A9:E6:7B:D9:80:79:7B:CC:93:F9:38
  • Authority Information Access:
  • OCSP - URI:http://o.pki.goog/s/we1/nzQ
  • CA Issuers - URI:http://i.pki.goog/we1.crt
  • X509v3 Subject Alternative Name:
  • DNS:downloadmalware.net, DNS:*.downloadmalware.net
  • X509v3 Certificate Policies:
  • Policy: 2.23.140.1.2.1
  • X509v3 CRL Distribution Points:
  • Full Name:
  • URI:http://c.pki.goog/we1/G0k-BqpOX8k.crl
  • CT Precertificate SCTs:
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 0E:57:94:BC:F3:AE:A9:3E:33:1B:2C:99:07:B3:F7:90:
  • DF:9B:C2:3D:71:32:25:DD:21:A9:25:AC:61:C5:4E:21
  • Timestamp : Jan 28 00:34:30.643 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:44:02:20:1F:D4:F4:18:9C:8C:4E:BE:8F:7A:9E:AA:
  • 50:D5:FB:8D:19:9A:27:15:01:34:5E:66:A2:D1:E6:9D:
  • 96:F6:AF:F9:02:20:78:EF:FE:54:93:6E:3E:CB:CB:76:
  • A4:E1:65:BA:A1:FB:D1:7E:F5:D9:66:AA:30:F2:6D:8B:
  • 16:C3:83:E9:A7:CD
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 16:83:2D:AB:F0:A9:25:0F:0F:F0:3A:A5:45:FF:C8:BF:
  • C8:23:D0:87:4B:F6:04:29:27:F8:E7:1F:33:13:F5:FA
  • Timestamp : Jan 28 00:34:30.653 2026 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:82:DF:1D:E1:3A:01:5C:BD:5F:00:07:
  • 4F:12:E6:FE:64:8D:75:4B:B3:6C:3D:84:19:F1:5C:79:
  • F7:C6:E2:6D:26:02:20:6B:A1:40:AE:B2:26:61:0A:DF:
  • 20:DE:0B:04:76:AB:7B:71:9A:36:D1:7C:94:63:CD:93:
  • C2:83:0F:00:F8:24:E4
  • Signature Algorithm: ecdsa-with-SHA256
  • Signature Value:
  • 30:45:02:21:00:8d:95:2d:d6:10:c1:46:91:08:1d:25:e7:c9:
  • c7:a5:71:0b:6c:6f:49:cd:b8:51:1f:ef:52:40:a9:f5:c5:61:
  • cc:02:20:30:5b:a5:3e:73:0c:8a:06:4f:70:2c:2b:09:e9:92:
  • 5f:f2:39:75:58:4b:25:a8:af:34:93:b7:7d:42:9e:36:53

*** Virustotal ***

*** WayBackMachine ***

Share on: