IOC Radar
DomainMediumSignal 84/100

auth-rev.en-id.cc

First Seen
Apr 17, 2026
Last Seen
Apr 28, 2026
Apr 17
First Seen
58d ago
Apr 28
Last Seen
47d ago
7
Reports
source reports
84%
Confidence
medium
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
84%
Signal Score
84 / 100
IDS Rule
No
Threat Context
Tags

Feed Intelligence Summary

7 reports84% confidence
7
Source reports
84%
Confidence score
Category tags
indicatormalwaremanual-collectionmedium-risknetworkresearchedtype osint

Activity Timeline

1 total obs
Apr 28Apr 28

Threat Activity Heatmap

· Peak: 2026-04-28
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

The identification of `auth-rev.en-id.cc` as a high-scoring Indicator of Compromise (IOC) carries significant implications for our organization's security posture. With a robust threat score of 83.83, this domain is not merely a data point but a direct link to a sophisticated "CROSS-BORDER HACK-FOR-HIRE CAMPAIGN TARGETING CIVIL SOCIETY IN MENA." Its presence in our environment strongly indicates potential involvement in espionage, credential harvesting, or other malicious activities designed for…

Threat ScoreHigh Risk
84
SIGNAL
Signal Score
84%
Confidence
7
Reports
First seenApr 17, 2026
Last seenApr 28, 2026

VirusTotal

Not checked

WHOIS

registrar
NameSilo, LLC
description
The following is the full list of names given to Vye32GsS2g38eKhmaKrLdDjgrnf2YBT4/FGx8SNCa4txePA
raw
Creation Date: 2024-04-16T07:39:37Z DNSSEC: unsigned Domain Name: EN-ID.CC Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Domain Status: redemptionPeriod https://icann.org/epp#redemptionPeriod Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +1.4805240066 Registrar IANA ID: 1479 Registrar URL: http://www.namesilo.com Registrar WHOIS Server: whois.namesilo.com Registrar: NameSilo, LLC Registry Domain ID: 200187348_DOMAIN_CC-VRSN Registry Expiry Date: 2025-04-16T07:39:37Z Updated Date: 2025-05-21T13:07:05Z

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 month ago · Last seen 1 month ago
Appeared in 7 threat reports