DomainMediumSignal 40/100
ip-51-222-241.net
Location
First Seen
Mar 3, 2025
Last Seen
Jun 7, 2026
Found in 7 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
40%
Signal Score
40 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
7 reports40% confidence
7
Source reports
40%
Confidence score
Category tags
application layer ddosbotnetbotnet activitycacanadacommand and controlcryptocurrencycryptocurrency threatscryptojackingcyber threatddosdenial of servicedistributed attackseuropefinancefranceindicatoriockillnetmalwarenetworknetwork intrusionnorth americaproxiesransomwareresearchedresource hijackingt1090t1486t1496t1498t1498.001t1499.002t1499.003t1592t1592.001t1592.002t1592.004t1595threat actorthreat actor: killnettor nodevolumetric ddos
Activity Timeline
Jun 7Jun 7
Threat Activity Heatmap
· Peak: 2026-06-07LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreLow Risk
40
SIGNAL
Signal Score
40%
Confidence
7
Reports
First seenMar 3, 2025
Last seenJun 7, 2026
VirusTotal
Not checked
WHOIS
- domain rank
- -1
- raw
- Administrative country: France Create date: 2020-04-02 00:00:00 Domain name: ip-51-222-241.net Domain registrar id: 433.0 Domain registrar url: https://rdap.ovh.com/ Expiry date: 2027-04-02 00:00:00 Name server 1: dns10.ovh.ca Name server 2: ns10.ovh.ca Query time: 2026-04-06 02:18:59 Registrant country: France Technical country: France Update date: 2026-04-03 00:00:00
- subdomains count
- 235
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 7 days ago
Appeared in 7 threat reports