IOC Radar
DomainHighVerifiedSignal 69/100

e5.malaymoil.com

Location
TurkeyTurkey
First Seen
Mar 18, 2026
Last Seen
May 22, 2026
Mar 18
First Seen
99d ago
May 22
Last Seen
34d ago
6
Reports
source reports
69%
Confidence
high
Found in 6 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
69%
Signal Score
69 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

39 techniques

Feed Intelligence Summary

6 reports69% confidence
6
Source reports
69%
Confidence score
Category tags
abusealienvault_ransomwareaptasiabad reputationbodybrute forcec2 servercastleratchlg urlcivil servicescode executioncode injectioncommand & controlcommand executioncommercial surveillancecontactcorunacredential harvestingcredential stuffingdarksworddata encryptiondata exfiltrationdata store exposureelectronic health recordsencryptioneuropeeurope/asiaexploitexploit chainexploitation activityextortionfake claude codefigureghostbladeghostknifeghostsabergovernment technologygtighealth care and social assistancehealth information technologyhealthcare information systemshospital managementidentity & access exploitationiframeindicatoringress tool transferinjection activityioslifeloaderlookmalaysiamalicious linksmalicious softwaremalwaremalware family: ghostblademalware family: ghostknifemalware family: ghostsabermedical servicesmetadata analysismobile securitymobile threatnation-state activitynetworknextoperation ghostmailpars defensepatchedpatient carephishingphishing attackprocess injectionpublic administrationpublic infrastructurepublic policyransomwareratregulatory agenciesresearchedsaudi arabiascams & fraudsocial engineeringsocial media securitystate-sponsoredstrongsystem disruptiont1005t1027t1027.002t1033t1036t1041t1047t1055t1056.001t1057t1059t1059.007t1068t1071t1071.001t1083t1095t1105t1113t1120t1123t1176t1189t1190t1203t1204.001t1210t1213t1486t1490t1547t1562.004t1565t1566t1566.001t1566.002t1566.003t1566.004t1588.006threat actortitletor nodetrojan malwareturkeyukraineunc6353unc6748unk_nightowlvulnerability scanwatering holeweb securityzero-day exploitationzero-day vulnerability

Activity Timeline

1 total obs
May 22May 22

Threat Activity Heatmap

· Peak: 2026-05-22
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
69
SIGNAL
Signal Score
69%
Confidence
6
Reports
First seenMar 18, 2026
Last seenMay 22, 2026
Verified IOC

VirusTotal

Not checked

WHOIS

raw
Administrative city: Berlin Administrative country: Germany Administrative email: [email protected] Administrative state: Brandenburg Billing city: Berlin Billing country: Germany Billing email: [email protected] Billing state: Brandenburg Create date: 2025-12-09 00:00:00 Domain name: malaymoil.com Domain registrar id: 4147.0 Expiry date: 2026-12-09 00:00:00 Name server 1: ns1.blnwx.com Name server 2: ns3.blnwx.com Name server 3: ns4.blnwx.com Name server 4: ns2.blnwx.com Query time: 2025-12-10 15:56:57 Registrant address: c048f3231f586ca1 Registrant city: 1e3cbbd11982ab31 Registrant country: Germany Registrant email: [email protected] Registrant name: b8d9c80cfabec490 Registrant phone: 7bcd3f26fb994193 Registrant state: 3124a84464d1c661 Registrant zip: 0ca9e0650a790deb Technical city: Berlin Technical country: Germany Technical email: [email protected] Technical state: Brandenburg Update date: 2025-12-09 00:00:00

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 3 months ago · Last seen 1 month ago
Appeared in 6 threat reports