rokhelper.com Threat Intelligence and Information

Host Location

Screenshot

alt-text

Dig Results

  • Got answer:
  • -»HEADER«- opcode: QUERY, status: NOERROR, id: 54972
  • flags: qr rd ra QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
  • OPT PSEUDOSECTION:
  • EDNS: version: 0, flags: udp: 1432
  • QUESTION SECTION:
  • rokhelper.com. IN A
  • ANSWER SECTION:
  • rokhelper.com. 299 IN A 104.21.86.252
  • rokhelper.com. 299 IN A 172.67.138.221
  • Query time: 4 msec
  • SERVER: 192.168.1.153(192.168.1.1) (UDP)
  • WHEN: Tue Dec 30 00:16:38 UTC 2025
  • MSG SIZE rcvd: 74

Whois Data

  • Domain Name: ROKHELPER.COM
  • Registry Domain ID: 3031818202_DOMAIN_COM-VRSN
  • Registrar URL: http://www.namecheap.com
  • Updated Date: 2025-12-14T02:54:27Z
  • Creation Date: 2025-10-23T03:50:16Z
  • Registry Expiry Date: 2026-10-23T03:50:16Z
  • Registrar: NameCheap, Inc.
  • Registrar IANA ID: 1068
  • Registrar Abuse Contact Email: abuse@namecheap.com
  • Registrar Abuse Contact Phone: +1.6613102107
  • Name Server: CAROL.NS.CLOUDFLARE.COM
  • Name Server: DAVID.NS.CLOUDFLARE.COM
  • DNSSEC: unsigned
  • Domain name: rokhelper.com
  • Registry Domain ID: 3031818202_DOMAIN_COM-VRSN
  • Registrar URL: http://www.namecheap.com
  • Updated Date: 0001-01-01T00:00:00.00Z
  • Creation Date: 2025-10-23T03:50:16.00Z
  • Registrar Registration Expiration Date: 2026-10-23T03:50:16.00Z
  • Registrar: NAMECHEAP INC
  • Registrar IANA ID: 1068
  • Registrar Abuse Contact Email: abuse@namecheap.com
  • Registrar Abuse Contact Phone: +1.9854014545
  • Reseller: NAMECHEAP INC
  • Registry Registrant ID:
  • Registrant Name: Redacted for Privacy
  • Registrant Organization: Privacy service provided by Withheld for Privacy ehf
  • Registrant Street: Kalkofnsvegur 2
  • Registrant City: Reykjavik
  • Registrant State/Province: Capital Region
  • Registrant Postal Code: 101
  • Registrant Country: IS
  • Registrant Phone: +354.4212434
  • Registrant Phone Ext:
  • Registrant Fax:
  • Registrant Fax Ext:
  • Registrant Email: 4a76ba5f995c4b89a8cc1fc6c56fb6d0.protect@withheldforprivacy.com
  • Registry Admin ID:
  • Admin Name: Redacted for Privacy
  • Admin Organization: Privacy service provided by Withheld for Privacy ehf
  • Admin Street: Kalkofnsvegur 2
  • Admin City: Reykjavik
  • Admin State/Province: Capital Region
  • Admin Postal Code: 101
  • Admin Country: IS
  • Admin Phone: +354.4212434
  • Admin Phone Ext:
  • Admin Fax:
  • Admin Fax Ext:
  • Admin Email: 4a76ba5f995c4b89a8cc1fc6c56fb6d0.protect@withheldforprivacy.com
  • Registry Tech ID:
  • Tech Name: Redacted for Privacy
  • Tech Organization: Privacy service provided by Withheld for Privacy ehf
  • Tech Street: Kalkofnsvegur 2
  • Tech City: Reykjavik
  • Tech State/Province: Capital Region
  • Tech Postal Code: 101
  • Tech Country: IS
  • Tech Phone: +354.4212434
  • Tech Phone Ext:
  • Tech Fax:
  • Tech Fax Ext:
  • Tech Email: 4a76ba5f995c4b89a8cc1fc6c56fb6d0.protect@withheldforprivacy.com
  • Name Server: carol.ns.cloudflare.com
  • Name Server: david.ns.cloudflare.com
  • DNSSEC: unsigned

SSL Certificate Information

  • Certificate:
  • Data:
  • Version: 3 (0x2)
  • Serial Number:
  • 46:27:b7:cc:42:ad:ae:c1:0e:0d:0e:85:6b:a8:b2:f8
  • Signature Algorithm: ecdsa-with-SHA256
  • Issuer: C = US, O = Google Trust Services, CN = WE1
  • Validity
  • Not Before: Dec 14 02:13:29 2025 GMT
  • Not After : Mar 14 03:11:02 2026 GMT
  • Subject: CN = rokhelper.com
  • Subject Public Key Info:
  • Public Key Algorithm: id-ecPublicKey
  • Public-Key: (256 bit)
  • pub:
  • 04:52:83:45:90:d5:60:c2:8c:92:9e:69:34:a4:b9:
  • 73:85:3c:b3:43:66:f3:71:4c:db:56:3e:b3:b4:2b:
  • 6a:ad:57:7a:35:2b:cf:56:bc:f7:a2:a0:25:99:13:
  • d7:fd:89:d9:d9:6e:37:c4:43:d7:c7:38:8c:a7:46:
  • 43:e5:10:5b:9c
  • ASN1 OID: prime256v1
  • NIST CURVE: P-256
  • X509v3 extensions:
  • X509v3 Key Usage: critical
  • Digital Signature
  • X509v3 Extended Key Usage:
  • TLS Web Server Authentication
  • X509v3 Basic Constraints: critical
  • CA:FALSE
  • X509v3 Subject Key Identifier:
  • AC:99:34:70:98:BD:60:47:CC:03:90:A7:C6:78:1D:57:93:20:FE:FB
  • X509v3 Authority Key Identifier:
  • 90:77:92:35:67:C4:FF:A8:CC:A9:E6:7B:D9:80:79:7B:CC:93:F9:38
  • Authority Information Access:
  • OCSP - URI:http://o.pki.goog/s/we1/Ric
  • CA Issuers - URI:http://i.pki.goog/we1.crt
  • X509v3 Subject Alternative Name:
  • DNS:rokhelper.com, DNS:*.rokhelper.com
  • X509v3 Certificate Policies:
  • Policy: 2.23.140.1.2.1
  • X509v3 CRL Distribution Points:
  • Full Name:
  • URI:http://c.pki.goog/we1/LTZ9nL9sQRA.crl
  • CT Precertificate SCTs:
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 0E:57:94:BC:F3:AE:A9:3E:33:1B:2C:99:07:B3:F7:90:
  • DF:9B:C2:3D:71:32:25:DD:21:A9:25:AC:61:C5:4E:21
  • Timestamp : Dec 14 03:13:29.988 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:CF:5C:6D:27:DB:51:C4:89:B0:07:22:
  • 33:39:6B:4A:24:9B:E4:2C:7D:B4:4A:20:15:8A:60:0B:
  • 54:FE:58:EE:26:02:20:48:87:B9:15:E6:31:33:CB:E4:
  • CB:2E:00:4F:3C:37:31:81:BD:65:96:C4:47:40:06:34:
  • BC:8B:CC:BD:E0:AB:A3
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : D1:6E:A9:A5:68:07:7E:66:35:A0:3F:37:A5:DD:BC:03:
  • A5:3C:41:12:14:D4:88:18:F5:E9:31:B3:23:CB:95:04
  • Timestamp : Dec 14 03:13:30.207 2025 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:20:74:6F:79:55:DA:E6:0E:E5:6B:7F:D6:DA:
  • 5C:20:3E:0C:2E:7F:B1:CB:00:5F:9C:36:41:CD:04:C0:
  • 87:4A:C5:49:02:21:00:88:38:D6:AB:A5:08:44:EF:39:
  • 08:4C:73:67:F6:00:C1:C7:DD:34:5D:83:5B:FD:C9:FA:
  • 8C:34:C3:71:86:11:FE
  • Signature Algorithm: ecdsa-with-SHA256
  • Signature Value:
  • 30:46:02:21:00:f0:ce:29:3d:b4:56:aa:97:8c:15:12:0a:ee:
  • 3e:bd:f0:b5:0a:e9:28:2f:12:af:aa:de:85:69:6a:1d:7c:26:
  • 58:02:21:00:91:f4:07:06:ec:14:fc:d2:d6:fe:43:7c:b0:24:
  • 56:33:d9:f4:eb:a9:bd:0e:0f:5b:0e:31:f0:b2:c8:bd:2f:5b

Technologies

CloudFlare

*** Virustotal ***

*** WayBackMachine ***

Share on: