IOC Radar
DomainMediumSignal 42/100

ebtgbxrs.blue

Location
United StatesUnited States
First Seen
Dec 27, 2024
Last Seen
Jun 4, 2026
Dec 27
First Seen
534d ago
Jun 4
Last Seen
9d ago
10
Reports
source reports
42%
Confidence
medium
Found in 10 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
42%
Signal Score
42 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

44 techniques

Feed Intelligence Summary

10 reports42% confidence
10
Source reports
42%
Confidence score
Category tags
active scanactive scanningattachment phishingattackauthentication attackbecbec attackbotnetbotnet activitybrand impersonationbrute forcebusiness email compromisebusiness_email_compromisecommand and controlcredential accesscredential harvestingcredential phishingcredential stuffingcredential theftcredential_harvestingdata exfiltrationdata store exposureddosdenial of servicedgadistributed attacksemail-based attackexploitation activityfraudulent websiteftp brute forcehttp brute forcehydra attackidentity & access exploitationindicatorinitial accessinjection activityiocslink injectionlink manipulationlink obfuscationlogin attacklogin attemptsmalicious activitymalicious attachmentmalicious attachmentsmalicious domainmalicious linksmalicious softwaremalwaremalware deliverymalware distributionmedusa attacknetworknetwork attacksnetwork probingnetwork protocolnetwork scanningnetwork securitynetwork service scanningnmap scannorth americaphishingphishing attackphishing-databaseprocess injectionprotocol exploitationransomwarerdp scanningreconnaissancereconnaissance activityremote accessremote servicesresearchedscams & fraudservice enumerationservice scansmb scanningsmtp brute forcesocial engineeringssh attacksyn scant1018t1021t1021.001t1021.002t1040t1046t1055t1059t1059.001t1059.004t1071.001t1076t1078t1110t1110.001t1110.002t1110.003t1189t1190t1192t1204t1204.001t1486t1496t1499.002t1499.003t1534t1552.001t1563t1565t1566t1566.001t1566.002t1566.003t1588.002t1589t1589.002t1592t1595t1595.001t1595.002t1595.003t1598t1598.003tcp scantcp scanningtelnet threatthreat actorthreat intelligence feedthreat_actor_activitytor nodeudp scanunited statesvulnerability scanweb securitywhaling attack

Activity Timeline

1 total obs
Jun 4Jun 4

Threat Activity Heatmap

· Peak: 2026-06-04
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreMedium Risk
42
SIGNAL
Signal Score
42%
Confidence
10
Reports
First seenDec 27, 2024
Last seenJun 4, 2026

VirusTotal

Not checked

WHOIS

description
LTNA Cyber provides additional enrichment for domain and URL indicators, including RIR and DNS intelligence, domain registration context, routing verification, BGP stream visibility, and GeoIP/ISP attribution. Learn more: https://ltna.com.au/cyber
domain rank
-1
raw
Administrative city: REDACTED FOR PRIVACY Administrative country: REDACTED FOR PRIVACY Administrative state: REDACTED FOR PRIVACY Create date: 2024-11-20 00:00:00 Domain name: ebtgbxrs.blue Domain registrar id: 1556 Domain registrar url: http://www.west.cn Expiry date: 2025-11-20 00:00:00 Name server 1: ara.ns.cloudflare.com Name server 2: elijah.ns.cloudflare.com Query time: 2024-11-21 11:49:50 Registrant city: 1f8f4166599d23ee Registrant company: a860c6cfd02f2ec2 Registrant country: China Registrant email: 29e2c061f3c9524es@ Registrant fax: 1f8f4166599d23ee Registrant name: 1f8f4166599d23ee Registrant phone: 1f8f4166599d23ee Registrant state: 18b3ed01d3bce948 Registrant zip: 1f8f4166599d23ee Technical city: REDACTED FOR PRIVACY Technical country: REDACTED FOR PRIVACY Technical state: REDACTED FOR PRIVACY Update date: 2024-11-20 00:00:00
references
https://malware-filter.gitlab.io/malware-filter/phishing-filter-domains.txt
subdomains count
0

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 9 days ago
Appeared in 10 threat reports