IOC Radar
DomainMediumSignal 12/100

englishminute.net

First Seen
Mar 4, 2025
Last Seen
Aug 31, 2025
Mar 4
First Seen
471d ago
Aug 31
Last Seen
291d ago
3
Reports
source reports
12%
Confidence
medium
Found in 3 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
12%
Signal Score
12 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

18 techniques

Feed Intelligence Summary

3 reports12% confidence
3
Source reports
12%
Confidence score
Category tags
anna paulabotnetc2c2 communicationc2 domainscommand and controldata exfiltrationdgadistributed attacksfrom emailheadersindicatorinfrastructure acquisitionreconnaissancemachine learning detectionmalicious softwaremalspam emailmalwaremalware family: nivdortmalware trafficmsi filenetworknivdortpotential-c2process injectionresearchedt1001t1001.001t1041t1055t1071t1071.001t1105t1486t1496t1499.002t1499.003t1565t1568t1568.002t1573t1573.001t1587.001t1590.001zip archive

Activity Timeline

1 total obs
Aug 31Aug 31

Threat Activity Heatmap

· Peak: 2025-08-31
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated

The domain **englishminute.net** has been identified as a critical indicator of compromise (IOC) associated with botnet and command-and-control (C

Threat ScoreLow Risk
12
SIGNAL
Signal Score
12%
Confidence
3
Reports
First seenMar 4, 2025
Last seenAug 31, 2025

VirusTotal

Not checked

WHOIS

registrar
Squarespace Domains II LLC
description
Command and Control domains for malware known as Nivdort. These domains are extracted from malware sandbox reports using a Machine Learning model trained on a corpus of good and bad domains.
domain rank
-1
raw
Admin City: REDACTED FOR PRIVACY Admin Country: US Admin Postal Code: REDACTED FOR PRIVACY Admin State/Province: CA Creation Date: 2022-06-30T00:55:34Z DNSSEC: signedDelegation Domain Name: ENGLISHMINUTE.NET Domain Name: englishminute.net Domain Status: clientDeleteProhibited http://www.icann.org/epp#clientDeleteProhibited Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited Domain Status: clientHold http://www.icann.org/epp#clientHold Domain Status: clientHold https://icann.org/epp#clientHold Domain Status: clientTransferProhibited http://www.icann.org/epp#clientTransferProhibited Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Name Server: NS-CLOUD-D1.GOOGLEDOMAINS.COM Name Server: NS-CLOUD-D2.GOOGLEDOMAINS.COM Name Server: NS-CLOUD-D3.GOOGLEDOMAINS.COM Name Server: NS-CLOUD-D4.GOOGLEDOMAINS.COM Name Server: ns-cloud-d1.googledomains.com Name Server: ns-cloud-d2.googledomains.com Name Server: ns-cloud-d3.googledomains.com Name Server: ns-cloud-d4.googledomains.com Registrant City: 1f8f4166599d23ee Registrant Country: US Registrant Email: 3bae71a42530df7ds@ Registrant Fax Ext: 3432650ec337c945 Registrant Fax: 1f8f4166599d23ee Registrant Name: 1f8f4166599d23ee Registrant Organization: 3432650ec337c945 Registrant Phone Ext: 3432650ec337c945 Registrant Phone: 1f8f4166599d23ee Registrant Postal Code: 1f8f4166599d23ee Registrant State/Province: b1952dfc047df18a Registrant Street: 1f8f4166599d23ee Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +1.646-693-5324 Registrar Abuse Contact Phone: +1.6466935324 Registrar IANA ID: 895 Registrar Registration Expiration Date: 2024-06-30T00:55:34Z Registrar URL: http://domains2.squarespace.com Registrar URL: https://domains2.squarespace.com Registrar WHOIS Server: whois.squarespace.domains Registrar: Squarespace Domains II LLC Registry Domain ID: 2707562928_DOMAIN_NET-VRSN Registry Expiry Date: 2025-06-30T00:55:34Z Tech City: REDACTED FOR PRIVACY Tech Country: US Tech Postal Code: REDACTED FOR PRIVACY Tech State/Province: CA Updated Date: 2024-06-30T01:11:23.831432Z Updated Date: 2024-06-30T07:49:06Z
references
2021-09-21-Curriculo-IOCs.txt
subdomains count
6

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 9 months ago
Appeared in 3 threat reports