DomainMediumSignal 63/100
email-protection.online
Location
First Seen
Oct 2, 2024
Last Seen
Apr 21, 2026
Found in 9 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
63%
Signal Score
63 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
9 reports63% confidence
9
Source reports
63%
Confidence score
Category tags
active scanactive scanningaptasiabelleza equiposbotnetbotnet activitybrute forcecertciudadcivil servicescommand and controlcommunication protocolcredential accesscredential harvestingcredential stuffingcredential theftdata encryptiondata exfiltrationdata store exposuredatabase securityddosdenial of servicedistributed attacksencryptionexploitation activityfinftpftp brute forcegovernment technologyhttp brute forcehttp scanneridentity & access exploitationindicatorinitial accessinjection activityinjection attacksintrusion detectioniranirgclateral movementleer msmalicious softwaremalwaremediamobile threatnetworknetwork attacksnetwork intrusionnetwork probingnetwork protocolnetwork scanningnetwork securityngophishingphishing attackpolticaprocess injectionpublic administrationpublic infrastructurepublic policyreconnaissanceregulatory agenciesremote accessremote servicesresearchedsalascannersocial engineeringssh attacksynt1021t1021.001t1021.002t1040t1055t1059t1059.003t1059.004t1059.005t1071.001t1076t1077t1110t1110.001t1110.002t1110.003t1189t1190t1210t1486t1496t1499.001t1499.002t1499.003t1563t1565t1566.001t1566.002t1566.003t1589t1589.002t1590t1590.001t1590.002t1590.003t1590.004t1592t1592.001t1592.002t1592.003t1595t1595.001t1595.002t1595.003tcp protocolthreat actorthreat intelligencetor nodeturkeytwo-factor authenticationunauthorized access attemptutensiliosvaporalvistaweb loginweb trafficwishlist vistaxmas
Activity Timeline
Apr 21Apr 21
Threat Activity Heatmap
· Peak: 2026-04-21LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated
The domain **email-protection.online** has emerged as a significant indicator of compromise (IOC) linked to multiple cyber threats originating from Iran. First observed on October
Threat ScoreMedium Risk
63
SIGNAL
Signal Score
63%
Confidence
9
Reports
First seenOct 2, 2024
Last seenApr 21, 2026
VirusTotal
Not checked
WHOIS
- description
- This is a pulse created to house CND internal IOCs that we want to monitor, please add title to explain what the IOC and a further description of if this is needed.
- domain rank
- -1
- raw
- Create date: 2022-12-07 00:00:00 Domain name: email-protection.online Domain registrar id: 1068 Domain registrar url: https://namecheap.com Expiry date: 2023-12-07 00:00:00 Name server 1: DNS2.NAMECHEAPHOSTING.COM Name server 2: DNS1.NAMECHEAPHOSTING.COM Query time: 2022-12-10 23:38:11 Registrant company: 4b7a0912c26a13e2 Registrant country: Iceland Registrant email: c3e4472e8f320a6ds@ Registrant state: 3e0204199d8ebf9c Update date: 2022-12-09 00:00:00
- references
- https://www.ic3.gov/Media/News/2024/240927.pdf
- subdomains count
- 0
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 1 month ago
Appeared in 9 threat reports