IOC Radar
DomainMediumSignal 30/100

diib.work

Location
BulgariaBulgaria
First Seen
Oct 13, 2025
Last Seen
Jun 1, 2026
Oct 13
First Seen
243d ago
Jun 1
Last Seen
12d ago
2
Reports
source reports
30%
Confidence
medium
Found in 2 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
30%
Signal Score
30 / 100
IDS Rule
No
Threat Context
Tags

Feed Intelligence Summary

2 reports30% confidence
2
Source reports
30%
Confidence score
Category tags
bulgariaeuropeindicatornetworkresearched

Activity Timeline

1 total obs
Jun 1Jun 1

Threat Activity Heatmap

· Peak: 2026-06-01
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Intelligence SummaryAI Generated

This Indicator of Compromise (IOC), `diib.work`, is a significant finding with a score of 30.26, suggesting a moderate risk to organizational security. Its identification in threat intelligence feeds, coupled with numerous associated subdomains like `akaunting.diib.work` and `webmail.diib.work`, strongly indicates its potential use as infrastructure for phishing campaigns, credential harvesting, or distributing malicious software. If successfully leveraged by adversaries, this IOC could lead to …

Threat ScoreLow Risk
30
SIGNAL
Signal Score
30%
Confidence
2
Reports
First seenOct 13, 2025
Last seenJun 1, 2026

VirusTotal

Not checked

WHOIS

registrar
PDR Ltd. d/b/a PublicDomainRegistry.com
domain rank
-1
raw
Admin City: GDPR Masked Admin City: REDACTED FOR PRIVACY Admin Country: GDPR Masked Admin Country: REDACTED FOR PRIVACY Admin Email: [email protected] Admin Organization: GDPR Masked Admin Organization: REDACTED FOR PRIVACY Admin Postal Code: GDPR Masked Admin Postal Code: REDACTED FOR PRIVACY Admin State/Province: GDPR Masked Admin State/Province: REDACTED FOR PRIVACY Creation Date: 2022-01-06T12:38:47Z DNSSEC: Unsigned DNSSEC: unsigned Domain Name: DIIB.WORK Domain Name: diib.work Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Name Server: ns10.jumpdns.net Name Server: ns9.jumpdns.net Registrant City: 1f8f4166599d23ee Registrant City: 7bc26f5a5e70d417 Registrant Country: BG Registrant Email: [email protected] Registrant Email: f651612a2f356ad3s@ Registrant Fax Ext: 1f8f4166599d23ee Registrant Fax Ext: 3432650ec337c945 Registrant Fax: 1f8f4166599d23ee Registrant Fax: 7bc26f5a5e70d417 Registrant Name: 1f8f4166599d23ee Registrant Name: 7bc26f5a5e70d417 Registrant Organization: 7bc26f5a5e70d417 Registrant Phone Ext: 1f8f4166599d23ee Registrant Phone Ext: 3432650ec337c945 Registrant Phone: 1f8f4166599d23ee Registrant Phone: 7bc26f5a5e70d417 Registrant Postal Code: 1f8f4166599d23ee Registrant Postal Code: 7bc26f5a5e70d417 Registrant State/Province: 3c3d6bdd6b97bf20 Registrant Street: 1f8f4166599d23ee Registrant Street: 7bc26f5a5e70d417 Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +1.2013775952 Registrar IANA ID: 303 Registrar Registration Expiration Date: 2025-01-06T12:38:47Z Registrar URL: publicdomainregistry.com Registrar URL: www.publicdomainregistry.com Registrar WHOIS Server: whois.publicdomainregistry.com Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com Registry Admin ID: GDPR Masked Registry Admin ID: REDACTED FOR PRIVACY Registry Domain ID: D_026885EE_3F69A4B653AD451A895D4941AE13C3E7_0000017E2F661B7FWORK-GDREG Registry Domain ID: Not Available From Registry Registry Expiry Date: 2025-01-06T12:38:47Z Registry Registrant ID: GDPR Masked Registry Registrant ID: REDACTED FOR PRIVACY Registry Tech ID: GDPR Masked Registry Tech ID: REDACTED FOR PRIVACY Tech City: GDPR Masked Tech City: REDACTED FOR PRIVACY Tech Country: GDPR Masked Tech Country: REDACTED FOR PRIVACY Tech Email: [email protected] Tech Organization: GDPR Masked Tech Organization: REDACTED FOR PRIVACY Tech Postal Code: GDPR Masked Tech Postal Code: REDACTED FOR PRIVACY Tech State/Province: GDPR Masked Tech State/Province: REDACTED FOR PRIVACY Updated Date: 2024-01-03T13:20:09Z Updated Date: 2024-01-08T13:20:08Z
subdomains count
40

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 8 months ago · Last seen 12 days ago
Appeared in 2 threat reports