sh-bank.com Threat Intelligence and Information

Host Location

Screenshot

alt-text

Dig Results

  • Got answer:
  • -»HEADER«- opcode: QUERY, status: NOERROR, id: 38062
  • flags: qr rd ra QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
  • OPT PSEUDOSECTION:
  • EDNS: version: 0, flags: udp: 1232
  • QUESTION SECTION:
  • sh-bank.com. IN A
  • ANSWER SECTION:
  • sh-bank.com. 290 IN A 172.67.219.238
  • sh-bank.com. 290 IN A 104.21.75.97
  • Query time: 48 msec
  • SERVER: 192.168.1.153(192.168.1.1) (UDP)
  • WHEN: Sat Nov 05 10:56:56 UTC 2022
  • MSG SIZE rcvd: 72

DNS Records

Whois Data

  • Domain Name: SH-BANK.COM
  • Registry Domain ID: 2730410309_DOMAIN_COM-VRSN
  • Registrar URL: http://www.publicdomainregistry.com
  • Updated Date: 2022-10-07T04:36:48Z
  • Creation Date: 2022-10-07T04:34:28Z
  • Registry Expiry Date: 2023-10-07T04:34:28Z
  • Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
  • Registrar IANA ID: 303
  • Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
  • Registrar Abuse Contact Phone: +1.2013775952
  • Name Server: NOLA.NS.CLOUDFLARE.COM
  • Name Server: NORMAN.NS.CLOUDFLARE.COM
  • DNSSEC: unsigned
  • Domain Name: SH-BANK.COM
  • Registry Domain ID: 2730410309_DOMAIN_COM-VRSN
  • Registrar URL: www.publicdomainregistry.com
  • Updated Date: 2022-10-07T04:36:49Z
  • Creation Date: 2022-10-07T04:34:28Z
  • Registrar Registration Expiration Date: 2023-10-07T04:34:28Z
  • Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
  • Registrar IANA ID: 303
  • Registry Registrant ID: Not Available From Registry
  • Registrant Name: INFRAFIX
  • Registrant Organization: INFRAFIX
  • Registrant Street: 1077, Hancheon-ro, Gangbuk-gu, Seoul, Korea none
  • Registrant City: none
  • Registrant State/Province: 1
  • Registrant Postal Code: 01070
  • Registrant Country: KR
  • Registrant Phone: +82.0147414852
  • Registrant Phone Ext:
  • Registrant Fax:
  • Registrant Fax Ext:
  • Registrant Email: yiwon7@infrafix.com
  • Registry Admin ID: Not Available From Registry
  • Admin Name: INFRAFIX
  • Admin Organization: INFRAFIX
  • Admin Street: 1077, Hancheon-ro, Gangbuk-gu, Seoul, Korea none
  • Admin City: none
  • Admin State/Province: 1
  • Admin Postal Code: 01070
  • Admin Country: KR
  • Admin Phone: +82.0147414852
  • Admin Phone Ext:
  • Admin Fax:
  • Admin Fax Ext:
  • Admin Email: yiwon7@infrafix.com
  • Registry Tech ID: Not Available From Registry
  • Tech Name: INFRAFIX
  • Tech Organization: INFRAFIX
  • Tech Street: 1077, Hancheon-ro, Gangbuk-gu, Seoul, Korea none
  • Tech City: none
  • Tech State/Province: 1
  • Tech Postal Code: 01070
  • Tech Country: KR
  • Tech Phone: +82.0147414852
  • Tech Phone Ext:
  • Tech Fax:
  • Tech Fax Ext:
  • Tech Email: yiwon7@infrafix.com
  • Name Server: nola.ns.cloudflare.com
  • Name Server: norman.ns.cloudflare.com
  • DNSSEC: Unsigned
  • Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
  • Registrar Abuse Contact Phone: +1.2013775952
  • Registration Service Provided By: MAILPLUG

SSL Certificate Information

  • Certificate:
  • Data:
  • Version: 3 (0x2)
  • Serial Number:
  • 04:00:03:45:3a:ac:15:91:cc:cf:71:ca:67:d2:33:d1:4c:c0
  • Signature Algorithm: ecdsa-with-SHA384
  • Issuer: C = US, O = Let’s Encrypt, CN = E1
  • Validity
  • Not Before: Oct 7 03:41:24 2022 GMT
  • Not After : Jan 5 03:41:23 2023 GMT
  • Subject: CN = *.sh-bank.com
  • Subject Public Key Info:
  • Public Key Algorithm: id-ecPublicKey
  • Public-Key: (256 bit)
  • pub:
  • 04:e2:1d:a3:e7:f1:e7:06:15:05:e7:1c:00:03:89:
  • fb:2f:b3:fa:ee:2b:00:ba:f2:de:fe:6e:3d:12:0a:
  • 47:e0:f1:0f:73:a6:ce:fc:a5:b8:39:46:b7:db:2b:
  • e8:f0:c5:d4:b9:5b:82:24:96:8a:73:65:92:4d:02:
  • 4d:31:46:b0:18
  • ASN1 OID: prime256v1
  • NIST CURVE: P-256
  • X509v3 extensions:
  • X509v3 Key Usage: critical
  • Digital Signature
  • X509v3 Extended Key Usage:
  • TLS Web Server Authentication, TLS Web Client Authentication
  • X509v3 Basic Constraints: critical
  • CA:FALSE
  • X509v3 Subject Key Identifier:
  • 0C:D0:BD:A3:55:94:7A:0B:55:EC:01:70:A7:DD:68:68:57:F7:F9:FE
  • X509v3 Authority Key Identifier:
  • 5A:F3:ED:2B:FC:36:C2:37:79:B9:52:30:EA:54:6F:CF:55:CB:2E:AC
  • Authority Information Access:
  • OCSP - URI:http://e1.o.lencr.org
  • CA Issuers - URI:http://e1.i.lencr.org/
  • X509v3 Subject Alternative Name:
  • DNS:*.sh-bank.com, DNS:sh-bank.com
  • X509v3 Certificate Policies:
  • Policy: 2.23.140.1.2.1
  • Policy: 1.3.6.1.4.1.44947.1.1.1
  • CPS: http://cps.letsencrypt.org
  • CT Precertificate SCTs:
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 7A:32:8C:54:D8:B7:2D:B6:20:EA:38:E0:52:1E:E9:84:
  • 16:70:32:13:85:4D:3B:D2:2B:C1:3A:57:A3:52:EB:52
  • Timestamp : Oct 7 04:41:24.297 2022 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:B5:44:4B:65:47:5E:9E:3A:72:08:3E:
  • 2C:33:3C:84:DC:72:BD:A4:82:E8:72:CD:53:E3:C0:B0:
  • 4A:2F:3D:5C:C1:02:20:78:E2:86:5F:20:FC:97:36:19:
  • D8:78:E8:75:B3:3F:6E:E1:6F:76:39:9C:58:CB:1B:E9:
  • 35:C2:7C:F1:6B:09:9A
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : E8:3E:D0:DA:3E:F5:06:35:32:E7:57:28:BC:89:6B:C9:
  • 03:D3:CB:D1:11:6B:EC:EB:69:E1:77:7D:6D:06:BD:6E
  • Timestamp : Oct 7 04:41:24.249 2022 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:93:99:35:7B:BB:A7:C7:51:FE:2C:AF:
  • 6C:E9:41:E1:46:F4:86:01:CC:27:14:A5:FF:D8:C1:5A:
  • C4:F5:5F:9E:DE:02:21:00:FD:2A:D0:14:BC:11:03:7D:
  • FB:5B:2F:A4:5E:02:27:77:99:85:4E:C3:B2:57:49:C0:
  • EE:36:F4:6D:FC:E4:AD:C7
  • Signature Algorithm: ecdsa-with-SHA384
  • Signature Value:
  • 30:64:02:30:3a:cd:a0:cc:f6:a0:3f:92:c0:25:50:b7:7d:a9:
  • 3a:c1:bb:f5:68:ff:33:f3:cf:40:44:cb:79:b4:59:f6:ad:63:
  • 84:aa:24:19:36:a1:fd:23:4d:b1:4c:0a:29:10:9a:b3:02:30:
  • 79:55:ef:86:db:38:c6:33:91:58:b6:b8:c7:48:4a:2f:b3:39:
  • 4e:d1:63:79:4b:a5:06:af:3f:ed:e2:86:be:9d:f8:55:4e:36:
  • 82:5b:d8:db:70:b7:d9:6f:5a:2b:f8:99

Sitemap

Technologies

*** Virustotal ***

*** WayBackMachine ***

Share on: