DomainHighVerifiedSignal 69/100
e5.malaymoil.com
Location
First Seen
Mar 18, 2026
Last Seen
May 22, 2026
Found in 6 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
69%
Signal Score
69 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
6 reports69% confidence
6
Source reports
69%
Confidence score
Category tags
abusealienvault_ransomwareaptasiabad reputationbodybrute forcec2 servercastleratchlg urlcivil servicescode executioncode injectioncommand & controlcommand executioncommercial surveillancecontactcorunacredential harvestingcredential stuffingdarksworddata encryptiondata exfiltrationdata store exposureelectronic health recordsencryptioneuropeeurope/asiaexploitexploit chainexploitation activityextortionfake claude codefigureghostbladeghostknifeghostsabergovernment technologygtighealth care and social assistancehealth information technologyhealthcare information systemshospital managementidentity & access exploitationiframeindicatoringress tool transferinjection activityioslifeloaderlookmalaysiamalicious linksmalicious softwaremalwaremalware family: ghostblademalware family: ghostknifemalware family: ghostsabermedical servicesmetadata analysismobile securitymobile threatnation-state activitynetworknextoperation ghostmailpars defensepatchedpatient carephishingphishing attackprocess injectionpublic administrationpublic infrastructurepublic policyransomwareratregulatory agenciesresearchedsaudi arabiascams & fraudsocial engineeringsocial media securitystate-sponsoredstrongsystem disruptiont1005t1027t1027.002t1033t1036t1041t1047t1055t1056.001t1057t1059t1059.007t1068t1071t1071.001t1083t1095t1105t1113t1120t1123t1176t1189t1190t1203t1204.001t1210t1213t1486t1490t1547t1562.004t1565t1566t1566.001t1566.002t1566.003t1566.004t1588.006threat actortitletor nodetrojan malwareturkeyukraineunc6353unc6748unk_nightowlvulnerability scanwatering holeweb securityzero-day exploitationzero-day vulnerability
Activity Timeline
May 22May 22
Threat Activity Heatmap
· Peak: 2026-05-22LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
69
SIGNAL
Signal Score
69%
Confidence
6
Reports
First seenMar 18, 2026
Last seenMay 22, 2026
Verified IOC
VirusTotal
Not checked
WHOIS
- raw
- Administrative city: Berlin Administrative country: Germany Administrative email: [email protected] Administrative state: Brandenburg Billing city: Berlin Billing country: Germany Billing email: [email protected] Billing state: Brandenburg Create date: 2025-12-09 00:00:00 Domain name: malaymoil.com Domain registrar id: 4147.0 Expiry date: 2026-12-09 00:00:00 Name server 1: ns1.blnwx.com Name server 2: ns3.blnwx.com Name server 3: ns4.blnwx.com Name server 4: ns2.blnwx.com Query time: 2025-12-10 15:56:57 Registrant address: c048f3231f586ca1 Registrant city: 1e3cbbd11982ab31 Registrant country: Germany Registrant email: [email protected] Registrant name: b8d9c80cfabec490 Registrant phone: 7bcd3f26fb994193 Registrant state: 3124a84464d1c661 Registrant zip: 0ca9e0650a790deb Technical city: Berlin Technical country: Germany Technical email: [email protected] Technical state: Brandenburg Update date: 2025-12-09 00:00:00
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
highFirst detected 3 months ago · Last seen 1 month ago
Appeared in 6 threat reports