IOC Radar
DomainHighVerifiedSignal 48/100

buyahref.com

Location
United StatesUnited States
First Seen
Oct 13, 2025
Last Seen
Jun 19, 2026
Oct 13
First Seen
255d ago
Jun 19
Last Seen
5d ago
5
Reports
source reports
48%
Confidence
high
Found in 5 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
48%
Signal Score
48 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

3 techniques

Feed Intelligence Summary

5 reports48% confidence
5
Source reports
48%
Confidence score
Category tags
activeblockchainblocklistbrute forcecontentcredential harvestingcredential stuffingcryptocrypto scamcryptocurrencydestroylist_phishingdomainsdrainerfraudidentity & access exploitationindicatorlivemonthlynetworknorth americaphishingphishing attackresearchedscamscams & fraudsocial engineeringt1566.001t1566.002t1566.003united states

Activity Timeline

1 total obs
Jun 19Jun 19

Threat Activity Heatmap

· Peak: 2026-06-19
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Intelligence SummaryAI Generated

The domain **buyahref.com**, originating from the United States, has been identified as an active indicator of compromise (IOC) associated with phishing activities. First observed on October

Threat ScoreMedium Risk
48
SIGNAL
Signal Score
48%
Confidence
5
Reports
First seenOct 13, 2025
Last seenJun 19, 2026
Verified IOC

VirusTotal

Not checked

WHOIS

registrar
NAMECHEAP INC
description
Live feed of phishing and crypto scam domains with ACTIVE malicious content from PhishDestroy. These domains are verified to have live phishing/scam pages. Updated hourly. Source: github.com/phishdestroy/destroylist/dns/content_active.json
domain rank
-1
raw
Admin City: Reykjavik Admin Country: IS Admin Email: [email protected] Admin Organization: Privacy service provided by Withheld for Privacy ehf Admin Postal Code: 101 Admin State/Province: Capital Region Creation Date: 2024-08-03T17:04:26.00Z Creation Date: 2024-08-03T17:04:26Z DNSSEC: unsigned Domain Name: BUYAHREF.COM Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Domain name: buyahref.com Name Server: JUNE.NS.CLOUDFLARE.COM Name Server: SANTINO.NS.CLOUDFLARE.COM Name Server: june.ns.cloudflare.com Name Server: santino.ns.cloudflare.com Registrant City: ddbf76e4e8cee320 Registrant Country: IS Registrant Email: [email protected] Registrant Fax Ext: 3432650ec337c945 Registrant Fax: 3432650ec337c945 Registrant Name: 37bfbc24cafea5d2 Registrant Organization: 4b7a0912c26a13e2 Registrant Phone Ext: 3432650ec337c945 Registrant Phone: 1c9a7bcdeaf95e9f Registrant Postal Code: f206c9d9737ad45d Registrant State/Province: 3e0204199d8ebf9c Registrant Street: c6523241936df1ba Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +1.6613102107 Registrar Abuse Contact Phone: +1.9854014545 Registrar IANA ID: 1068 Registrar Registration Expiration Date: 2026-08-03T17:04:26.00Z Registrar URL: http://www.namecheap.com Registrar WHOIS Server: whois.namecheap.com Registrar: NAMECHEAP INC Registrar: NameCheap, Inc. Registry Domain ID: 2904994837_DOMAIN_COM-VRSN Registry Expiry Date: 2026-08-03T17:04:26Z Tech City: Reykjavik Tech Country: IS Tech Email: [email protected] Tech Organization: Privacy service provided by Withheld for Privacy ehf Tech Postal Code: 101 Tech State/Province: Capital Region Updated Date: 2025-07-27T03:34:14.27Z Updated Date: 2025-07-27T03:34:14Z
subdomains count
13

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 8 months ago · Last seen 5 days ago
Appeared in 5 threat reports