DomainMediumSignal 42/100
bigcandywin.fr
Location
First Seen
Apr 16, 2026
Last Seen
Apr 23, 2026
Found in 4 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
42%
Signal Score
42 / 100
IDS Rule
No
Threat Context
Tags
Feed Intelligence Summary
4 reports42% confidence
4
Source reports
42%
Confidence score
Category tags
europefranceindicatornetworkresearched
Activity Timeline
Apr 23Apr 23
Threat Activity Heatmap
· Peak: 2026-04-23LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated
This indicator of compromise (IOC), `bigcandywin.fr`, represents a significant potential threat to organizational security. With a threat score of 41.76 and explicitly not whitelisted, this domain is highly suspicious and has been flagged by multiple reputable threat intelligence sources, including AlienVault OTX, SOCRadar, and ThreatHose. Its inclusion in a list of "French malicious domains" strongly suggests its involvement in illicit activities such as phishing, malware distribution, or comma…
Threat ScoreMedium Risk
42
SIGNAL
Signal Score
42%
Confidence
4
Reports
First seenApr 16, 2026
Last seenApr 23, 2026
VirusTotal
Not checked
WHOIS
- registrar
- Hosting Concepts B.V. d/b/a Openprovider
- description
- Entries from https://red.flag.domains/ - malicious domains targeting french citizens. Auto-updated each day.
- domain rank
- -1
- raw
- Expiry Date: 2027-04-14T15:08:18.549999Z changed: 2026-04-01T11:11:49.129696Z country: ES country: NL created: 2026-04-14T15:08:18.564667Z domain: bigcandywin.fr e-mail: [email protected] e-mail: [email protected] eligsource: REGISTRAR eligstatus: ok eppstatus: active eppstatus: associated last-update: 2026-04-15T05:04:19.907073Z nic-hdl: ANO00-FRNIC nic-hdl: CTC6828466-FRNIC nserver: craig.ns.cloudflare.com nserver: ophelia.ns.cloudflare.com reachsource: REGISTRAR reachstatus: ok registered: 2005-06-27T00:00:00Z registrar: Hosting Concepts B.V. d/b/a Openprovider source: FRNIC status: ACTIVE status: addPeriod type: PERSON
- subdomains count
- 0
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 month ago · Last seen 1 month ago
Appeared in 4 threat reports