DomainMediumSignal 0/100
fjcad.com
Location
First Seen
Apr 16, 2025
Last Seen
Feb 12, 2026
Found in 1 report. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
0%
Signal Score
0 / 100
IDS Rule
No
Threat Context
Tags
Feed Intelligence Summary
1 report0% confidence
1
Source reports
0%
Confidence score
Category tags
indicatornetworkresearched
Activity Timeline
Feb 12Feb 12
Threat Activity Heatmap
· Peak: 2026-02-12LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Threat ScoreLow Risk
0
SIGNAL
Signal Score
0%
Confidence
1
Reports
First seenApr 16, 2025
Last seenFeb 12, 2026
VirusTotal
Not checked
WHOIS
- description
- CyberCX has discovered a sophisticated phishing campaign named DarkEngine, which targets users of WP Engine, a managed WordPress hosting platform, and has been active since at least June 2024. The campaign employs SEO poisoning to lure victims to phishing sites mimicking the WP Engine login interface, enabling attackers to steal credentials and gain unauthorized access to WP Engine accounts and their associated WordPress sites. Once compromised, the attackers inject backdoors via malicious plugins and execute harmful JavaScript, affecting over 2,353 unique sites primarily in Australia and New Zealand, while also utilizing techniques like ClickFix to manipulate visitors into executing harmful commands. The operation employs a headless browser automation tool for exploitation, maintaining persistence through various backdoors and SFTP accounts..
- domain rank
- -1
- raw
- Administrative city: Kuala Lumpur Administrative country: Malaysia Administrative email: [email protected] Administrative state: Wilayah Persekutuan Create date: 2025-04-15 00:00:00 Domain name: fjcad.com Domain registrar id: 460 Domain registrar url: http://www.webnic.cc Expiry date: 2026-04-15 00:00:00 Name server 1: jaziel.ns.cloudflare.com Name server 2: evangeline.ns.cloudflare.com Query time: 2025-04-16 14:35:08 Registrant city: d622b1166b297bee Registrant company: 20c6e82190de8bc4 Registrant country: Malaysia Registrant email: [email protected] Registrant fax: c3344f80ad4a9c61 Registrant name: edeae57e15fec50a Registrant phone: c3344f80ad4a9c61 Registrant state: f4e528a4fdf624a9 Registrant zip: eff8e039538ef902 Technical city: Kuala Lumpur Technical country: Malaysia Technical email: [email protected] Technical state: Wilayah Persekutuan Update date: 2025-04-15 00:00:00
- references
- https://connect.cybercx.com.au/dark-engine, https://storage.pardot.com/1069042/1748905703CCn8f7sn/CyberCX___WP_Engine_Report.pdf, https://threatfox.abuse.ch/export/csv/recent/
- subdomains count
- 3
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 4 months ago
Appeared in 1 threat report