IOC Radar
DomainMediumSignal 84/100

auth-rev.id-en.me

First Seen
Apr 17, 2026
Last Seen
Apr 28, 2026
Apr 17
First Seen
59d ago
Apr 28
Last Seen
48d ago
7
Reports
source reports
84%
Confidence
medium
11/91
VirusTotal
detections
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
84%
Signal Score
84 / 100
IDS Rule
No
Threat Context
Tags

Feed Intelligence Summary

7 reports84% confidence
7
Source reports
84%
Confidence score
Category tags
indicatormalwaremanual-collectionmedium-risknetworkresearchedtype osint

Activity Timeline

1 total obs
Apr 28Apr 28

Threat Activity Heatmap

· Peak: 2026-04-28
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

This Indicator of Compromise (IOC), the domain `auth-rev.id-en.me`, is critically significant as it has been directly linked to a sophisticated cross-border hack-for-hire campaign targeting civil society organizations in the MENA region. With a high threat score of 83.83, this IOC represents a severe and immediate threat, indicating potential involvement in espionage, data exfiltration, or system compromise. If left unaddressed, its presence within an organizational environment could lead to the…

Threat ScoreHigh Risk
84
SIGNAL
Signal Score
84%
Confidence
7
Reports
First seenApr 17, 2026
Last seenApr 28, 2026

VirusTotal

11/ 91vendors flagged
12% detection rateJun 3, 2026

WHOIS

description
The following is the full list of names given to Vye32GsS2g38eKhmaKrLdDjgrnf2YBT4/FGx8SNCa4txePA
raw
Administrative city: REDACTED FOR PRIVACY Administrative country: REDACTED FOR PRIVACY Administrative state: REDACTED FOR PRIVACY Create date: 2024-07-25 00:00:00 Domain name: id-en.me Domain registrar id: 1636 Domain registrar url: http://www.hostinger.com Expiry date: 2025-07-25 00:00:00 Name server 1: ns1.dns-parking.com Name server 2: ns2.dns-parking.com Query time: 2024-07-26 22:02:46 Registrant city: 1f8f4166599d23ee Registrant company: b61af69881455ade Registrant country: United States Registrant email: f651612a2f356ad3s@ Registrant fax: 1f8f4166599d23ee Registrant name: 1f8f4166599d23ee Registrant phone: 1f8f4166599d23ee Registrant state: 36e414cc8874c746 Registrant zip: 1f8f4166599d23ee Technical city: REDACTED FOR PRIVACY Technical country: REDACTED FOR PRIVACY Technical state: REDACTED FOR PRIVACY Update date: 2024-07-25 00:00:00

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 month ago · Last seen 1 month ago
Appeared in 7 threat reports