windowsdriverupdate.com Threat Intelligence and Information

Host Location

Screenshot

alt-text

Dig Results

  • Got answer:
  • -»HEADER«- opcode: QUERY, status: NOERROR, id: 14063
  • flags: qr rd ra QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1
  • OPT PSEUDOSECTION:
  • EDNS: version: 0, flags: udp: 1232
  • QUESTION SECTION:
  • windowsdriverupdate.com. IN A
  • ANSWER SECTION:
  • windowsdriverupdate.com. 292 IN A 104.21.36.38
  • windowsdriverupdate.com. 292 IN A 172.67.184.182
  • Query time: 12 msec
  • SERVER: 192.168.1.153(192.168.1.1)
  • WHEN: Tue Apr 19 17:32:51 UTC 2022
  • MSG SIZE rcvd: 84

DNS Records

  • SOA nick.ns.cloudflare.com 108.162.193.213
  • SOA nick.ns.cloudflare.com 172.64.33.213
  • SOA nick.ns.cloudflare.com 173.245.59.213
  • SOA nick.ns.cloudflare.com 2606:4700:58::adf5:3bd5
  • SOA nick.ns.cloudflare.com 2803:f800:50::6ca2:c1d5
  • SOA nick.ns.cloudflare.com 2a06:98c1:50::ac40:21d5
  • NS nick.ns.cloudflare.com 108.162.193.213
  • NS nick.ns.cloudflare.com 172.64.33.213
  • NS nick.ns.cloudflare.com 173.245.59.213
  • NS nick.ns.cloudflare.com 2803:f800:50::6ca2:c1d5
  • NS nick.ns.cloudflare.com 2606:4700:58::adf5:3bd5
  • NS nick.ns.cloudflare.com 2a06:98c1:50::ac40:21d5
  • NS rafe.ns.cloudflare.com 108.162.192.216
  • NS rafe.ns.cloudflare.com 172.64.32.216
  • NS rafe.ns.cloudflare.com 173.245.58.216
  • NS rafe.ns.cloudflare.com 2606:4700:50::adf5:3ad8
  • NS rafe.ns.cloudflare.com 2803:f800:50::6ca2:c0d8
  • NS rafe.ns.cloudflare.com 2a06:98c1:50::ac40:20d8
  • MX eforward3.registrar-servers.com 162.255.118.51
  • MX eforward2.registrar-servers.com 162.255.118.52
  • MX eforward1.registrar-servers.com 162.255.118.51
  • MX eforward4.registrar-servers.com 162.255.118.52
  • MX eforward5.registrar-servers.com 162.255.118.51
  • A windowsdriverupdate.com 172.67.184.182
  • A windowsdriverupdate.com 104.21.36.38
  • AAAA windowsdriverupdate.com 2606:4700:3035::6815:2426
  • AAAA windowsdriverupdate.com 2606:4700:3037::ac43:b8b6
  • TXT windowsdriverupdate.com v=spf1 include:spf.efwd.registrar-servers.com ~all

Whois Data

  • Domain Name: WINDOWSDRIVERUPDATE.COM
  • Registry Domain ID: 2684143917_DOMAIN_COM-VRSN
  • Registrar URL: http://www.namecheap.com
  • Updated Date: 2022-03-24T20:11:19Z
  • Creation Date: 2022-03-24T20:02:58Z
  • Registry Expiry Date: 2023-03-24T20:02:58Z
  • Registrar: NameCheap, Inc.
  • Registrar IANA ID: 1068
  • Registrar Abuse Contact Email: abuse@namecheap.com
  • Registrar Abuse Contact Phone: +1.6613102107
  • Name Server: NICK.NS.CLOUDFLARE.COM
  • Name Server: RAFE.NS.CLOUDFLARE.COM
  • DNSSEC: unsigned
  • Domain name: windowsdriverupdate.com
  • Registry Domain ID: 2684143917_DOMAIN_COM-VRSN
  • Registrar URL: http://www.namecheap.com
  • Updated Date: 0001-01-01T00:00:00.00Z
  • Creation Date: 2022-03-24T20:02:58.00Z
  • Registrar Registration Expiration Date: 2023-03-24T20:02:58.00Z
  • Registrar: NAMECHEAP INC
  • Registrar IANA ID: 1068
  • Registrar Abuse Contact Email: abuse@namecheap.com
  • Registrar Abuse Contact Phone: +1.9854014545
  • Reseller: NAMECHEAP INC
  • Registry Registrant ID:
  • Registrant Name: Redacted for Privacy
  • Registrant Organization: Privacy service provided by Withheld for Privacy ehf
  • Registrant Street: Kalkofnsvegur 2
  • Registrant City: Reykjavik
  • Registrant State/Province: Capital Region
  • Registrant Postal Code: 101
  • Registrant Country: IS
  • Registrant Phone: +354.4212434
  • Registrant Phone Ext:
  • Registrant Fax:
  • Registrant Fax Ext:
  • Registrant Email: 42f438370bc048cc9c1314b1692b7880.protect@withheldforprivacy.com
  • Registry Admin ID:
  • Admin Name: Redacted for Privacy
  • Admin Organization: Privacy service provided by Withheld for Privacy ehf
  • Admin Street: Kalkofnsvegur 2
  • Admin City: Reykjavik
  • Admin State/Province: Capital Region
  • Admin Postal Code: 101
  • Admin Country: IS
  • Admin Phone: +354.4212434
  • Admin Phone Ext:
  • Admin Fax:
  • Admin Fax Ext:
  • Admin Email: 42f438370bc048cc9c1314b1692b7880.protect@withheldforprivacy.com
  • Registry Tech ID:
  • Tech Name: Redacted for Privacy
  • Tech Organization: Privacy service provided by Withheld for Privacy ehf
  • Tech Street: Kalkofnsvegur 2
  • Tech City: Reykjavik
  • Tech State/Province: Capital Region
  • Tech Postal Code: 101
  • Tech Country: IS
  • Tech Phone: +354.4212434
  • Tech Phone Ext:
  • Tech Fax:
  • Tech Fax Ext:
  • Tech Email: 42f438370bc048cc9c1314b1692b7880.protect@withheldforprivacy.com
  • Name Server: nick.ns.cloudflare.com
  • Name Server: rafe.ns.cloudflare.com
  • DNSSEC: unsigned

SSL Certificate Information

  • Certificate:
  • Data:
  • Version: 3 (0x2)
  • Serial Number:
  • 0e:47:73:58:b7:91:ed:86:7d:01:d6:c8:e9:70:1e:4c
  • Signature Algorithm: ecdsa-with-SHA256
  • Issuer: C = US, O = “Cloudflare, Inc.”, CN = Cloudflare Inc ECC CA-3
  • Validity
  • Not Before: Mar 24 00:00:00 2022 GMT
  • Not After : Mar 23 23:59:59 2023 GMT
  • Subject: C = US, ST = California, L = San Francisco, O = “Cloudflare, Inc.”, CN = sni.cloudflaressl.com
  • Subject Public Key Info:
  • Public Key Algorithm: id-ecPublicKey
  • Public-Key: (256 bit)
  • pub:
  • 04:05:1c:82:b8:80:0e:cf:89:2e:ca:e1:eb:91:45:
  • 81:bf:54:1a:5b:cd:1b:30:68:17:0b:9e:e1:eb:4e:
  • dd:90:97:5e:60:f9:82:43:89:5f:41:b1:3b:59:82:
  • 59:51:55:b7:13:1c:e8:34:e0:6f:ee:8c:82:28:6c:
  • 34:22:00:b1:60
  • ASN1 OID: prime256v1
  • NIST CURVE: P-256
  • X509v3 extensions:
  • X509v3 Authority Key Identifier:
  • keyid:A5:CE:37:EA:EB:B0:75:0E:94:67:88:B4:45:FA:D9:24:10:87:96:1F
  • X509v3 Subject Key Identifier:
  • 4E:78:B3:8A:7E:25:9B:D4:B9:06:18:C1:4F:FB:54:1B:06:3A:75:12
  • X509v3 Subject Alternative Name:
  • DNS:sni.cloudflaressl.com, DNS:*.windowsdriverupdate.com, DNS:windowsdriverupdate.com
  • X509v3 Key Usage: critical
  • Digital Signature
  • X509v3 Extended Key Usage:
  • TLS Web Server Authentication, TLS Web Client Authentication
  • X509v3 CRL Distribution Points:
  • Full Name:
  • URI:http://crl3.digicert.com/CloudflareIncECCCA-3.crl
  • Full Name:
  • URI:http://crl4.digicert.com/CloudflareIncECCCA-3.crl
  • X509v3 Certificate Policies:
  • Policy: 2.23.140.1.2.2
  • CPS: http://www.digicert.com/CPS
  • Authority Information Access:
  • OCSP - URI:http://ocsp.digicert.com
  • CA Issuers - URI:http://cacerts.digicert.com/CloudflareIncECCCA-3.crt
  • X509v3 Basic Constraints: critical
  • CA:FALSE
  • CT Precertificate SCTs:
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : E8:3E:D0:DA:3E:F5:06:35:32:E7:57:28:BC:89:6B:C9:
  • 03:D3:CB:D1:11:6B:EC:EB:69:E1:77:7D:6D:06:BD:6E
  • Timestamp : Mar 24 20:14:20.294 2022 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:A2:CE:0E:6A:F4:2C:3D:79:0D:6B:0D:
  • 90:1A:81:BB:CB:40:0B:99:D4:D7:84:7C:AE:EC:FA:3E:
  • F3:4E:64:C5:34:02:20:07:13:DC:86:CD:D1:A2:FD:79:
  • EC:64:57:BC:85:32:F7:74:99:9E:88:C0:EC:8F:64:54:
  • FF:93:8D:02:B1:1D:E9
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : 35:CF:19:1B:BF:B1:6C:57:BF:0F:AD:4C:6D:42:CB:BB:
  • B6:27:20:26:51:EA:3F:E1:2A:EF:A8:03:C3:3B:D6:4C
  • Timestamp : Mar 24 20:14:20.306 2022 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:46:02:21:00:9E:FE:EF:CB:44:B5:BC:44:4C:C0:DB:
  • 32:59:B5:96:64:49:D1:0F:C9:B1:F3:BA:90:25:23:8B:
  • 03:40:67:1A:73:02:21:00:B6:1E:86:F8:B9:27:1B:5D:
  • 2E:6E:AA:94:47:8C:0B:9A:F9:66:1E:96:A7:73:01:3B:
  • 5A:73:93:B3:87:6E:AB:42
  • Signed Certificate Timestamp:
  • Version : v1 (0x0)
  • Log ID : B3:73:77:07:E1:84:50:F8:63:86:D6:05:A9:DC:11:09:
  • 4A:79:2D:B1:67:0C:0B:87:DC:F0:03:0E:79:36:A5:9A
  • Timestamp : Mar 24 20:14:20.344 2022 GMT
  • Extensions: none
  • Signature : ecdsa-with-SHA256
  • 30:45:02:21:00:E7:6F:24:6D:41:94:33:42:3B:9E:D5:
  • F5:04:49:32:D5:42:E6:A5:EF:42:89:2C:E9:70:51:2E:
  • 27:21:01:A3:AD:02:20:70:79:29:14:77:DA:03:CE:F2:
  • B0:4D:53:61:EE:F3:BE:35:38:E1:3F:28:08:76:BB:4A:
  • 33:F7:18:33:D4:ED:A2
  • Signature Algorithm: ecdsa-with-SHA256
  • 30:45:02:20:22:34:5f:44:99:9c:ac:f3:c4:1c:61:8a:f3:38:
  • b6:84:d8:ba:88:a4:8a:43:ec:17:a1:b1:91:cc:e1:c9:92:15:
  • 02:21:00:e1:b9:6c:ef:d8:10:13:7f:89:3d:e3:3d:31:c8:61:
  • bf:52:df:2d:4c:27:ef:67:17:17:55:c9:7b:10:c8:1d:8d

Sitemap

Technologies

*** Virustotal ***

*** WayBackMachine ***

Share on: