DomainMediumSignal 37/100
dwrf.org.np
Location
First Seen
Jun 5, 2020
Last Seen
Jun 12, 2026
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
37%
Signal Score
37 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
7 reports37% confidence
7
Source reports
37%
Confidence score
Category tags
account discoveryaccount profilingaccount takeoveraccount takeover attemptactive scanactive scanningasiaattachment basedattachment phishingauthentication attackbecbotnetbotnet activitybrand impersonationbrute forcebusiness email compromisecommand and controlcredential accesscredential harvestingcredential phishingcredential stuffingcredential theftdata exfiltrationdata store exposuredata theftddosdenial of servicedistributed attacksexploitation activityfinancefraudftp brute forcehttp brute forcehydra attackidentity & access exploitationindicatorinjection activitylink injectionlink obfuscationlink redirectionlogin attacklogin attemptsmalicious attachmentmalicious linkmalicious linksmalicious softwaremalwaremalware deliverymalware distributionmalware phishingmedusa attacknetworknetwork attacksnetwork probingnetwork protocolnetwork scanningnetwork securitynetwork service scanningnmap scanphishingphishing attackphishing kitphishing-databaseprocess injectionprotocol exploitationransomwarerdp scanningreconnaissancereconnaissance activityremote accessremote servicesresearchedscams & fraudservice enumerationservice scansingaporesmb scanningsmtp brute forcesocial engineeringssh attacksyn scant1018t1021t1021.001t1021.002t1040t1046t1055t1059t1059.001t1059.004t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1189t1190t1192t1204t1204.001t1486t1496t1499.002t1499.003t1539t1563t1565t1566t1566.001t1566.002t1566.003t1566.004t1567t1567.001t1589t1589.002t1592t1595t1595.001t1595.002t1595.003t1598t1598.003tcp scantcp scanningtelnet threatudp scanvulnerability scanweb security
Activity Timeline
Jun 12Jun 12
Threat Activity Heatmap
· Peak: 2026-06-12LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Intelligence SummaryAI Generated
The domain **dwrf.org.np** has been identified as a significant indicator of compromise (IOC) associated with multiple cyber threats, including botnets, malware, phishing, and ransomware activities. First observed on June
Threat ScoreLow Risk
37
SIGNAL
Signal Score
37%
Confidence
7
Reports
First seenJun 5, 2020
Last seenJun 12, 2026
VirusTotal
Not checked
WHOIS
- description
- LTNA Cyber provides additional enrichment for domain and URL indicators, including RIR and DNS intelligence, domain registration context, routing verification, BGP stream visibility, and GeoIP/ISP attribution. Learn more: https://ltna.com.au/cyber
- domain rank
- -1
- subdomains count
- 10
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 6 years ago · Last seen 13 days ago
Appeared in 7 threat reports