IOC Radar
DomainMediumSignal 50/100

b7510.com

Location
United KingdomUnited Kingdom
First Seen
May 14, 2026
Last Seen
May 28, 2026
May 14
First Seen
38d ago
May 28
Last Seen
24d ago
4
Reports
source reports
50%
Confidence
medium
Found in 4 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
50%
Signal Score
50 / 100
IDS Rule
No
Threat Context
Tags

Feed Intelligence Summary

4 reports50% confidence
4
Source reports
50%
Confidence score
Category tags
androiddata-harvestingeuropeindicatorinfostealermalicious-scriptmalvertisingmobile threatnetworkpiracyransomwareresearchedside-loadstealerunited kingdom

Activity Timeline

1 total obs
May 28May 28

Threat Activity Heatmap

· Peak: 2026-05-28
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
50
SIGNAL
Signal Score
50%
Confidence
4
Reports
First seenMay 14, 2026
Last seenMay 28, 2026

VirusTotal

Not checked

WHOIS

registrar
NAMECHEAP INC
description
1flex.org is a piracy site (registered April 22, 2026) with a Netflix-quality interface offering theatrical releases in 1080p. Silently loads hidden script from fubuki-umami.space/api/script.js, mimicking analytics tool Umami as camouflage. Script returns 403 to non-browser requests indicating environment detection. fubuki-umami.space/stats is operator's data dashboard. Network IDS confirmed C2 beacon at regular intervals and large HTTP POST data exfiltration. Malicious JavaScript first observed January 2025, seen 2935 times globally, predating domain by 15 months. Console detection redirects to youtube.com/watch?v=jy4qYmf3TxA evading URL scanners. Related domains 1shows.ru and 1shows.org share identical toolkit per AdGuard GitHub #229672. Distributes Android APK outside Google Play. Confirmed multi-payload Trojan with cryptominer and C2 infrastructure.
domain rank
-1
raw
Admin City: Reykjavik Admin Country: IS Admin Email: [email protected] Admin Organization: Privacy service provided by Withheld for Privacy ehf Admin Postal Code: 101 Admin State/Province: Capital Region Creation Date: 2021-03-21T12:10:34.00Z Creation Date: 2021-03-21T12:10:34Z DNSSEC: unsigned Domain Name: B7510.COM Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Domain name: b7510.com Name Server: NS01.B7510.COM Name Server: NS11.B7510.COM Name Server: NS21.B7510.COM Name Server: ns01.b7510.com Name Server: ns11.b7510.com Name Server: ns21.b7510.com Registrant City: ddbf76e4e8cee320 Registrant Country: IS Registrant Email: [email protected] Registrant Fax Ext: 3432650ec337c945 Registrant Fax: 3432650ec337c945 Registrant Name: 37bfbc24cafea5d2 Registrant Organization: 4b7a0912c26a13e2 Registrant Phone Ext: 3432650ec337c945 Registrant Phone: 1c9a7bcdeaf95e9f Registrant Postal Code: f206c9d9737ad45d Registrant State/Province: 3e0204199d8ebf9c Registrant Street: c6523241936df1ba Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +1.6613102107 Registrar Abuse Contact Phone: +1.9854014545 Registrar IANA ID: 1068 Registrar Registration Expiration Date: 2027-03-21T12:10:34.00Z Registrar URL: http://www.namecheap.com Registrar WHOIS Server: whois.namecheap.com Registrar: NAMECHEAP INC Registrar: NameCheap, Inc. Registry Domain ID: 2599458152_DOMAIN_COM-VRSN Registry Expiry Date: 2027-03-21T12:10:34Z Tech City: Reykjavik Tech Country: IS Tech Email: [email protected] Tech Organization: Privacy service provided by Withheld for Privacy ehf Tech Postal Code: 101 Tech State/Province: Capital Region Updated Date: 2026-02-19T05:35:21.95Z Updated Date: 2026-03-27T11:56:27Z
references
https://github.com/AdguardTeam/AdguardFilters/issues/229672, https://hybrid-analysis.com/sample/87cb4edbfc8c1ae193bde7d4fe496ebb80d7402a652bb888e776b3029c792517
subdomains count
4

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 month ago · Last seen 24 days ago
Appeared in 4 threat reports