IOC Radar
DomainHighVerifiedSignal 37/100

duratel.net

First Seen
Nov 15, 2022
Last Seen
Mar 9, 2026
Nov 15
First Seen
1319d ago
Mar 9
Last Seen
108d ago
5
Reports
source reports
37%
Confidence
high
Found in 5 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
37%
Signal Score
37 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

46 techniques

Feed Intelligence Summary

5 reports37% confidence
5
Source reports
37%
Confidence score
Category tags
account discoveryaccount profilingaccount takeoveraccount takeover attemptactive scanningattachment phishingauthentication attackbecbotnetbrand impersonationbrute forcebusiness email compromisecommand and controlcompromised accountcredential accesscredential harvestingcredential phishingcredential stuffingcredential theftdata exfiltrationdata theftdenial of servicedistributed attacksfinancefraudftp brute forcehttp brute forcehydra attackindicatorlink injectionlink obfuscationlink redirectionlogin attacklogin attemptsmalicious attachmentmalicious linkmalicious linksmalicious softwaremalwaremalware deliverymalware distributionmalware phishingmedusa attacknetworknetwork attacksnetwork probingnetwork protocolnetwork scanningnetwork securitynetwork service scanningnmap scanphishingphishing activityphishing attackphishing campaignphishing-databaseprocess injectionprotocol exploitationrdp scanningreconnaissancereconnaissance activityremote accessremote servicesresearchedservice enumerationsmb scanningsmtp brute forcesocial engineeringssh attacksyn scant1018t1021t1021.001t1021.002t1040t1046t1055t1059t1059.001t1059.004t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1189t1190t1192t1204t1204.001t1486t1496t1499.002t1499.003t1534t1539t1563t1565t1566t1566.001t1566.002t1566.003t1566.004t1567t1567.001t1589t1589.002t1592t1595t1595.001t1595.002t1595.003t1598t1598.003tcp scantcp scanningtelnet threatudp scanurlhausvulnerability scanweb securitywebsite phishing

Activity Timeline

1 total obs
Mar 9Mar 9

Threat Activity Heatmap

· Peak: 2026-03-09
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreLow Risk
37
SIGNAL
Signal Score
37%
Confidence
5
Reports
First seenNov 15, 2022
Last seenMar 9, 2026
Verified IOC

VirusTotal

Not checked

WHOIS

registrar
Porkbun LLC
description
For POC
domain rank
-1
raw
Admin City: Sanford Admin Country: US Admin Organization: Private by Design, LLC Admin Postal Code: 27330 Admin State/Province: NC Created Date: 2021-07-09 19:19:32 Creation Date: 2021-07-09T19:19:32Z DNSSEC: unsigned Domain Name: DURATEL.NET Domain Status: clientDeleteProhibited http://icann.org/epp#clientDeleteProhibited Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited Domain Status: clientTransferProhibited http://icann.org/epp#clientTransferProhibited Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Name Server: CURITIBA.NS.PORKBUN.COM Name Server: FORTALEZA.NS.PORKBUN.COM Name Server: MACEIO.NS.PORKBUN.COM Name Server: SALVADOR.NS.PORKBUN.COM Name Server: curitiba.ns.porkbun.com Name Server: fortaleza.ns.porkbun.com Name Server: maceio.ns.porkbun.com Name Server: salvador.ns.porkbun.com Registrant City: 2ab5101c3c03a542 Registrant Country: US Registrant Email: 14f4c7e6ac87b455s@ Registrant Fax Ext: 3432650ec337c945 Registrant Fax: 3432650ec337c945 Registrant Name: 99f9e3def34088de Registrant Organization: 0c0ae3ca894d74a0 Registrant Phone Ext: 3432650ec337c945 Registrant Phone: cced364eac860795 Registrant Postal Code: 049e7ea575ee0e64 Registrant State/Province: b5ccaeb3c805e2cb Registrant Street: fd7c6dfcc1471820 Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +1.5038508351 Registrar Abuse Contact Phone: 5038508351 Registrar IANA ID: 1861 Registrar Registration Expiration Date: 2023-07-09 19:19:32 Registrar URL: http://porkbun.com Registrar URL: http://www.porkbun.com Registrar WHOIS Server: whois.porkbun.com Registrar: Porkbun LLC Registry Domain ID: 2625616209_DOMAIN_NET-VRSN Registry Expiry Date: 2023-07-09T19:19:32Z Tech City: Sanford Tech Country: US Tech Organization: Private by Design, LLC Tech Postal Code: 27330 Tech State/Province: NC Updated Date: 2022-07-11 04:21:38 Updated Date: 2023-05-29T12:12:37Z
references
https://urlhaus.abuse.ch/feeds/country/CA/
subdomains count
7

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 3 years ago · Last seen 3 months ago
Appeared in 5 threat reports