IOC Radar
DomainMediumSignal 100/100

cdn.gridgatecloud.com

Location
United StatesUnited States
First Seen
Feb 14, 2025
Last Seen
Feb 15, 2026
Feb 14
First Seen
482d ago
Feb 15
Last Seen
116d ago
15
Reports
source reports
99%
Confidence
medium
14/91
VirusTotal
detections
Found in 15 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

31 techniques

Feed Intelligence Summary

15 reports99% confidence
15
Source reports
99%
Confidence score
Category tags
abuseaptasyncratattackbotnetc2cobaltstrikecommand and controlcredential harvestingctadanabotdata exfiltrationdeimosdistributed attackshak5_cloud_c2havocindicatorinfrastructure acquisitionreconnaissanceiocmalicious activitymalicious softwaremalwaremanualmythicnetsupportratnetworknorth americaopen source intelligenceosintphishing attackprocess injectionremcos trojanremote accessremote servicesresearchedsliversocial engineeringsupershellt1005t1016t1021.001t1027t1036t1053t1055t1059t1059.003t1071t1071.001t1078t1083t1105t1189t1190t1204t1486t1496t1499.002t1499.003t1547t1565t1566t1566.001t1566.002t1566.003t1573t1587.001t1590.001t1598threat actorthreat intelligenceunited states

Activity Timeline

1 total obs
Feb 15Feb 15

Threat Activity Heatmap

· Peak: 2026-02-15
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated

The domain **cdn.gridgatecloud.com** has emerged as a significant indicator of compromise (IOC) associated with advanced persistent threat (APT) activities, specifically linked to the AsyncRAT malware. First observed on February

Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
15
Reports
First seenFeb 14, 2025
Last seenFeb 15, 2026

VirusTotal

14/ 91vendors flagged
15% detection rateJun 8, 2026

WHOIS

raw
Administrative city: REDACTED FOR PRIVACY Administrative country: REDACTED FOR PRIVACY Administrative state: REDACTED FOR PRIVACY Create date: 2025-01-30 00:00:00 Domain name: gridgatecloud.com Domain registrar id: 69 Domain registrar url: http://tucowsdomains.com Expiry date: 2026-01-30 00:00:00 Name server 1: jonah.ns.cloudflare.com Name server 2: georgia.ns.cloudflare.com Query time: 2025-01-31 13:01:29 Registrant city: 1f8f4166599d23ee Registrant company: 1f8f4166599d23ee Registrant country: Saint Kitts and Nevis Registrant email: 279f179cd58d5582s@ Registrant fax: 1f8f4166599d23ee Registrant name: 1f8f4166599d23ee Registrant phone: 1f8f4166599d23ee Registrant state: 5c1896d54f3bb30d Registrant zip: 1f8f4166599d23ee Technical city: REDACTED FOR PRIVACY Technical country: REDACTED FOR PRIVACY Technical state: REDACTED FOR PRIVACY Update date: 2025-01-30 00:00:00

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 3 months ago
Appeared in 15 threat reports