IOC Radar
DomainMediumSignal 43/100

dubntbyo.guru

Location
United StatesUnited States
First Seen
Dec 3, 2024
Last Seen
Jun 12, 2026
Dec 3
First Seen
568d ago
Jun 12
Last Seen
12d ago
10
Reports
source reports
43%
Confidence
medium
Found in 10 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
43%
Signal Score
43 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

45 techniques

Feed Intelligence Summary

10 reports43% confidence
10
Source reports
43%
Confidence score
Category tags
active scanactive scanningattachment phishingattackauthentication attackbecbotnetbotnet activitybrand impersonationbrute forcecommand and controlcompromised accountcredential accesscredential harvestingcredential phishingcredential stuffingcredential theftdata exfiltrationdata store exposuredata theftddosdenial of servicedgadistributed attacksexploitation activityftp brute forcehttp brute forcehydra attackidentity & access exploitationimpersonation phishingindicatorinfrastructure acquisitionreconnaissanceinitial accessinjection activitylink injectionlink redirectionlogin attacklogin attemptsmalicious activitymalicious attachmentmalicious attachmentsmalicious linkmalicious linksmalicious softwaremalwaremalware deliverymalware distributionmalware phishingmedusa attacknetworknetwork attacksnetwork probingnetwork protocolnetwork scanningnetwork securitynetwork service scanningnmap scannorth americaphishingphishing activityphishing attackphishing campaignphishing-databaseprocess injectionprotocol exploitationransomwarerdp scanningreconnaissancereconnaissance activityremote accessremote servicesresearchedsecurity awarenessservice enumerationservice scansmb scanningsmtp brute forcesocial engineeringssh attacksyn scant1018t1021t1021.001t1021.002t1040t1046t1055t1059t1059.001t1059.004t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1189t1190t1192t1204t1204.001t1486t1496t1499.002t1499.003t1534t1563t1565t1566t1566.001t1566.002t1566.003t1566.004t1587.001t1589t1589.002t1590.001t1592t1595t1595.001t1595.002t1595.003t1598t1598.003tcp scantcp scanningtelnet threatthreat actortor nodeudp scanunited statesuser interactionvulnerability scanweb securitywebsite phishing

Activity Timeline

1 total obs
Jun 12Jun 12

Threat Activity Heatmap

· Peak: 2026-06-12
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Intelligence SummaryAI Generated

The domain **dubntbyo.guru** has emerged as a significant indicator of compromise (IOC) associated with multiple cyber threats, including botnets, malware, phishing, and ransomware. First observed on December

Threat ScoreMedium Risk
43
SIGNAL
Signal Score
43%
Confidence
10
Reports
First seenDec 3, 2024
Last seenJun 12, 2026

VirusTotal

Not checked

WHOIS

description
LTNA Cyber provides additional enrichment for domain and URL indicators, including RIR and DNS intelligence, domain registration context, routing verification, BGP stream visibility, and GeoIP/ISP attribution. Learn more: https://ltna.com.au/cyber
domain rank
-1
raw
Administrative city: REDACTED FOR PRIVACY Administrative country: REDACTED FOR PRIVACY Administrative state: REDACTED FOR PRIVACY Create date: 2024-12-01 00:00:00 Domain name: dubntbyo.guru Domain registrar id: 1556 Domain registrar url: http://www.west.cn Expiry date: 2025-12-01 00:00:00 Name server 1: alexandra.ns.cloudflare.com Name server 2: jacob.ns.cloudflare.com Query time: 2024-12-02 19:48:49 Registrant city: 1f8f4166599d23ee Registrant country: China Registrant email: 29e2c061f3c9524es@ Registrant fax: 1f8f4166599d23ee Registrant name: 1f8f4166599d23ee Registrant phone: 1f8f4166599d23ee Registrant state: f63cef604ce4bc90 Registrant zip: 1f8f4166599d23ee Technical city: REDACTED FOR PRIVACY Technical country: REDACTED FOR PRIVACY Technical state: REDACTED FOR PRIVACY Update date: 2024-12-01 00:00:00
subdomains count
0

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 12 days ago
Appeared in 10 threat reports