IOC Radar
DomainMediumSignal 63/100

email-protection.online

Location
Iran, Islamic Republic ofIran, Islamic Republic of
First Seen
Oct 2, 2024
Last Seen
Apr 21, 2026
Oct 2
First Seen
619d ago
Apr 21
Last Seen
53d ago
9
Reports
source reports
63%
Confidence
medium
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
63%
Signal Score
63 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

44 techniques

Feed Intelligence Summary

9 reports63% confidence
9
Source reports
63%
Confidence score
Category tags
active scanactive scanningaptasiabelleza equiposbotnetbotnet activitybrute forcecertciudadcivil servicescommand and controlcommunication protocolcredential accesscredential harvestingcredential stuffingcredential theftdata encryptiondata exfiltrationdata store exposuredatabase securityddosdenial of servicedistributed attacksencryptionexploitation activityfinftpftp brute forcegovernment technologyhttp brute forcehttp scanneridentity & access exploitationindicatorinitial accessinjection activityinjection attacksintrusion detectioniranirgclateral movementleer msmalicious softwaremalwaremediamobile threatnetworknetwork attacksnetwork intrusionnetwork probingnetwork protocolnetwork scanningnetwork securityngophishingphishing attackpolticaprocess injectionpublic administrationpublic infrastructurepublic policyreconnaissanceregulatory agenciesremote accessremote servicesresearchedsalascannersocial engineeringssh attacksynt1021t1021.001t1021.002t1040t1055t1059t1059.003t1059.004t1059.005t1071.001t1076t1077t1110t1110.001t1110.002t1110.003t1189t1190t1210t1486t1496t1499.001t1499.002t1499.003t1563t1565t1566.001t1566.002t1566.003t1589t1589.002t1590t1590.001t1590.002t1590.003t1590.004t1592t1592.001t1592.002t1592.003t1595t1595.001t1595.002t1595.003tcp protocolthreat actorthreat intelligencetor nodeturkeytwo-factor authenticationunauthorized access attemptutensiliosvaporalvistaweb loginweb trafficwishlist vistaxmas

Activity Timeline

1 total obs
Apr 21Apr 21

Threat Activity Heatmap

· Peak: 2026-04-21
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

The domain **email-protection.online** has emerged as a significant indicator of compromise (IOC) linked to multiple cyber threats originating from Iran. First observed on October

Threat ScoreMedium Risk
63
SIGNAL
Signal Score
63%
Confidence
9
Reports
First seenOct 2, 2024
Last seenApr 21, 2026

VirusTotal

Not checked

WHOIS

description
This is a pulse created to house CND internal IOCs that we want to monitor, please add title to explain what the IOC and a further description of if this is needed.
domain rank
-1
raw
Create date: 2022-12-07 00:00:00 Domain name: email-protection.online Domain registrar id: 1068 Domain registrar url: https://namecheap.com Expiry date: 2023-12-07 00:00:00 Name server 1: DNS2.NAMECHEAPHOSTING.COM Name server 2: DNS1.NAMECHEAPHOSTING.COM Query time: 2022-12-10 23:38:11 Registrant company: 4b7a0912c26a13e2 Registrant country: Iceland Registrant email: c3e4472e8f320a6ds@ Registrant state: 3e0204199d8ebf9c Update date: 2022-12-09 00:00:00
references
https://www.ic3.gov/Media/News/2024/240927.pdf
subdomains count
0

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 1 month ago
Appeared in 9 threat reports