DomainMediumSignal 100/100
cantomus.com
First Seen
Aug 4, 2023
Last Seen
Apr 12, 2026
Found in 3 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
3 reports99% confidence
3
Source reports
99%
Confidence score
Category tags
abuseactive scanactive scanningalienvault_ransomwareauthentication attacksbad reputationbrute forcecommunication protocolddosdenial of serviceidentity & access exploitationindicatornetworknetwork attacksnetwork probingnetwork protocolnetwork scanningransomwarereconnaissanceresearchedt1021t1040t1059t1078t1110t1499.002t1499.003t1595t1595.001t1595.002t1595.003tcp protocolunauthorized login attemptsuser
Activity Timeline
Apr 12Apr 12
Threat Activity Heatmap
· Peak: 2026-04-12LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated
The domain **cantomus.com** has emerged as a significant indicator of compromise (IOC) associated with ransomware activities, first observed on August
Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
3
Reports
First seenAug 4, 2023
Last seenApr 12, 2026
VirusTotal
Not checked
WHOIS
- registrar
- DYNADOT LLC
- creation date
- 2023-11-15T22:11:51
- expiration date
- 2026-11-15T22:11:51
- updated date
- 2025-10-19T10:20:29
- name servers
- NS1.CSOF.NET, NS2.CSOF.NET, NS3.CSOF.NET, NS4.CSOF.NET
- country
- US
- emails
- [email protected]
- org
- Super Privacy Service LTD c/o Dynadot
- status
- clientTransferProhibited https://icann.org/epp#clientTransferProhibited
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 2 years ago · Last seen 1 month ago
Appeared in 3 threat reports