IOC Radar
DomainMediumSignal 68/100

karaleaks.com

Location
SwedenSweden
First Seen
Jan 19, 2025
Last Seen
Feb 19, 2026
Jan 19
First Seen
520d ago
Feb 19
Last Seen
124d ago
4
Reports
source reports
68%
Confidence
medium
Found in 4 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
68%
Signal Score
68 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

69 techniques

Feed Intelligence Summary

4 reports68% confidence
4
Source reports
68%
Confidence score
Category tags
active relatedadd indicatoradded activeagent teslaalerts idsall t8america malwareandroid10applearkei stealerasiaattacks saaustraliaavtratazorultbandit stealerbofabotnetbrashears lesbrashears pornbrazilcanadacapturechinacidrcnc beaconco sheriffcobalt strikecommand and controlcommunication protocolcommunication technologiescomspecconfigcontroversial techcookiecostcpccredential harvestingcredential theftdailydarkdata analysisdata exfiltrationdata mining softwaredata uploaddays agodeletedelete cdicator roledicators japandiri typedishdistributed attacksdjvudom hosdouglas countydownloaderdron aewdynamicloaderemotetenter senter scenter soenter soufenter sourceentriesethical hackingeuropeeurope/asiaexclude dataexclude suggesexclude suggestexclude toosrouexcluded dataexcludel suggesextr dataextr extractextr pleaseextraextra dataextra pleaseextrac dataextractextraction dataextraction failextreextre dataextre pleaseextriextri datafailedfalcon sandboxfanecfileh filehfilepath httpsfind sfind suggefirmipflubotfolderfoundryfoundry createdfoundry techfoundry twitterfree porngovernment usegreenharmfulhighhigh priorityhostname datahostname enumerationhttp attackhttp scannerhttpshybridhybrid analysisic excludedidn1includeinclude datainclude failedinclude outroovinclude reviewincludec reviewincluded iocsincluded reviewindiaindicatorindicators hongindicators showinformation gatheringinformation technologyinfrastructure acquisitionreconnaissanceingress tool transferinstallinteliocsipv4irelandit infrastructurejul allkarakurtkeyloggerkhtmlkonglearn morelinuxlovelynn brashearsmafiamalicious downloadmalicious linksmalicious softwaremalwaremalware distributionmanaiv addmazemediamedia centermitre att&ck frameworkmobile carriersmobile networksmonths agomost relevantmsienetherlandsnetworknetwork scanningnjratno entdino entrieno expirationnorth americaobjectoceaniaoctoseek publicofficeopen threatoperating systemous upackingpegasus attacksphishingphishing attackpleaseplease subplease subrpornporn videospornhub httpspornhub pagepriority alertsprivacyprocess injectionpulsepulse datapulsespulses hostnamepulses urlqakbotqbotquackbotransomexxreconnaissancerefts0related pulsesremoteremote accessremote keyloggerremote keylogger installationreport externalreport spamresearchedreviewreview datareview excludereview icreview iocsreview lacereview loccrole titlerun keysrussiasa victimsc datasc typescanse extrase extractionse reviewsearchsearchtsarshowshowingslcc2social engineeringsoftware developmentsouth americaspanspicestartupstatus nostopstop datastreamsuggessugges datasuggestsuggest dataswedent1005t1021.001t1027t1035t1036t1041t1043t1045t1051t1053t1055t1056t1056.001t1057t1059t1059.001t1060t1065t1068t1069.001t1071t1071.001t1078t1080t1082t1083t1085t1105t1106t1110t1110.002t1113t1114t1119t1123t1125t1129t1133t1140t1143t1155t1179t1190t1199t1204.001t1210t1486t1496t1499.002t1499.003t1506t1546t1564t1565t1566t1566.001t1566.002t1566.003t1569.002t1583t1586t1587t1587.001t1588t1589t1589.001t1590.001t1595t1598telecom servicestelecommunicationsthreat networktitle addedtmobiletop tsaratrojan malwaretsaratsara brashearstsara lynntyp datatyp hosttypetype filehtype indicatortype notypestypes ofu extractioukraineunitedunited statesuniyunruyuny inuuueur extractionurior exiragursnifuserosandroidvideosvmwarewatch tsaraweb securityweb trafficwhitewhite keyloggerwindows ntwinverwriteyara ruleyears ago

Activity Timeline

1 total obs
Feb 19Feb 19

Threat Activity Heatmap

· Peak: 2026-02-19
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated

The domain **karaleaks.com**, originating from Sweden, has been identified as a significant indicator of compromise (IOC) associated with multiple cyber threats. First observed on January

Threat ScoreMedium Risk
68
SIGNAL
Signal Score
68%
Confidence
4
Reports
First seenJan 19, 2025
Last seenFeb 19, 2026

VirusTotal

Not checked

WHOIS

registrar
NAMECHEAP INC
creation date
2022-05-08T00:24:24
expiration date
2027-05-08T00:24:24
updated date
2026-05-11T04:23:34
name servers
NS1.BRAINYDNS.COM, NS2.BRAINYDNS.COM
country
IS
org
Privacy service provided by Withheld for Privacy ehf
status
clientTransferProhibited https://icann.org/epp#clientTransferProhibited

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 4 months ago
Appeared in 4 threat reports