DomainMediumSignal 84/100
chat-gpt-5.ai
Location
First Seen
Jun 26, 2025
Last Seen
Jun 9, 2026
Found in 10 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
84%
Signal Score
84 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
10 reports84% confidence
10
Source reports
84%
Confidence score
Category tags
ai themed attackbat fileblack hat seobrand abusebrowser fingerprintingc2 communicationc2 serverchatgptchatgpt exploitationcode injectioncredential theftdgaeuropeget requestindicatorinformation stealinglegion loaderlegionloaderluma ailuma ai exploitationlummalumma ailumma stealermalware distributionmsi filenetworknsis installerphishingresearchedsearch engine poisoningseostealer malwaret1003t1041t1049t1055t1057t1059t1059.007t1071t1083t1102t1104t1140t1176t1189t1190t1204t1204.001t1217t1496t1547t1560t1566t1573t1574t1588t1598takeaways threattraffic redirectionunited kingdomvidarvidar stealerweb exploitation
Activity Timeline
Jun 9Jun 9
Threat Activity Heatmap
LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
1
Minimal
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
84
SIGNAL
Signal Score
84%
Confidence
10
Reports
First seenJun 26, 2025
Last seenJun 9, 2026
VirusTotal
Not checked
WHOIS
- registrar
- Key-Systems GmbH
- domain rank
- -1
- raw
- Admin City: Nikopol Admin Country: UA Admin Email: [email protected] Admin Organization: monolab Admin Postal Code: 53210 Admin State/Province: Dnipro region Creation Date: 2023-05-09T07:53:35Z DNSSEC: unsigned Domain Name: chat-gpt-5.ai Domain Status: redemptionPeriod https://icann.org/epp#redemptionPeriod Name Server: ns1.onlydomains.com Name Server: ns2.onlydomains.com Name Server: ns3.onlydomains.com Registrant City: 97573c3c472e603b Registrant Country: UA Registrant Email: [email protected] Registrant Fax Ext: 3432650ec337c945 Registrant Fax: 3432650ec337c945 Registrant Name: d7bc7fb3af6f7005 Registrant Organization: 7862231f180a7610 Registrant Phone Ext: 3432650ec337c945 Registrant Phone: 9a080622b533cf9d Registrant Postal Code: 1ae7c7060822e8e6 Registrant State/Province: 3230529ce5813c9b Registrant Street: 4c6a1b8af0cd8a66 Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +49.68949396850 Registrar IANA ID: 269 Registrar URL: http://key-systems.net Registrar WHOIS Server: whois.rrpproxy.net Registrar: Key-Systems GmbH Registry Admin ID: dba63a650f2c4aea9d9329623d136b26-DONUTS Registry Domain ID: 2922f294ef7d4dbc8a4ba938c1af0efe-DONUTS Registry Expiry Date: 2025-05-09T07:53:35Z Registry Registrant ID: b7540918a5c24c68bff94d7e8d63a40f-DONUTS Registry Tech ID: b05564db9b594fc0b355283b525d7f41-DONUTS Tech City: Nikopol Tech Country: UA Tech Email: [email protected] Tech Organization: monolab Tech Postal Code: 53210 Tech State/Province: Dnipro region Updated Date: 2025-06-21T13:38:06Z
- references
- https://www.zscaler.com/blogs/security-research/black-hat-seo-poisoning-search-engine-results-ai-distribute-malware
- subdomains count
- 6
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 11 months ago · Last seen 1 day ago
Appeared in 10 threat reports