IOC Radar
DomainHighVerifiedSignal 27/100

nhk-jpor.com

Location
JapanJapan
First Seen
Feb 16, 2025
Last Seen
Aug 15, 2025
Feb 16
First Seen
485d ago
Aug 15
Last Seen
306d ago
5
Reports
source reports
27%
Confidence
high
Found in 5 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
27%
Signal Score
27 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

37 techniques

Feed Intelligence Summary

5 reports27% confidence
5
Source reports
27%
Confidence score
Category tags
account enumerationactive scanningasiabotnetbotnet activitybrute forcecommand and controlcommunity managementcontent sharingcredential accesscredential harvestingcredential stuffingdata exfiltrationdata theftdgadigital platformsdistributed attacksftp brute forcehong kongindicatorinfrastructure acquisitionreconnaissancejapanmalicious softwaremalicious urlsmalwaremanualnetworknetwork probingnetwork scanningphishing attackprocess injectionreconnaissanceremote accessremote servicesresearchedresource enumerationsocial analyticssocial engineeringsocial mediasocial media marketingsocial media securitysocial networkingspamssh attackt1016t1021.001t1040t1055t1056t1056.001t1059t1059.004t1071.001t1076t1087t1087.001t1087.002t1087.003t1110t1110.001t1110.002t1133t1187t1190t1486t1496t1499.002t1499.003t1563t1565t1566.001t1566.002t1566.003t1583t1583.006t1587.001t1590.001t1595t1595.001t1595.002t1595.003twitteruser engagement

Activity Timeline

1 total obs
Aug 15Aug 15

Threat Activity Heatmap

· Peak: 2025-08-15
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated

The domain nhk-jpor.com, originating from Japan, has been identified as a significant indicator of compromise (IOC) associated with botnet, malware, and spam activities. First observed on February

Threat ScoreLow Risk
27
SIGNAL
Signal Score
27%
Confidence
5
Reports
First seenFeb 16, 2025
Last seenAug 15, 2025
Verified IOC

VirusTotal

Not checked

WHOIS

domain rank
-1
raw
Administrative city: San Mateo Administrative country: United States Administrative state: California Create date: 2025-02-13 00:00:00 Domain name: nhk-jpor.com Domain registrar id: 472 Domain registrar url: http://www.dynadot.com Expiry date: 2026-02-13 00:00:00 Name server 1: ns1.dyna-ns.net Name server 2: ns2.dyna-ns.net Query time: 2025-02-14 12:24:34 Registrant city: 3715f4e2b12e17cb Registrant company: 473daf17453d83cd Registrant country: United States Registrant email: 2eb9ca3c0e6269d2s@ Registrant name: 1f8f4166599d23ee Registrant phone: bd610aea3d112609 Registrant state: 77ab92f1911d7c5f Registrant zip: ae51fcfbe03bd2c4 Technical city: San Mateo Technical country: United States Technical state: California Update date: 2025-02-14 00:00:00
references
https://x.com/harugasumi/status/1890947197937537425, https://x.com/harugasumi/status/1890947376728187014, https://x.com/harugasumi/status/1890959539123691643, https://x.com/harugasumi/status/1890963029535207443, https://x.com/harugasumi/status/1890964209669718224, https://x.com/harugasumi/status/1891000348841566260, https://x.com/harugasumi/status/1891001556863943167, https://x.com/harugasumi/status/1891003942424752290, https://x.com/harugasumi/status/1891016813560860812, https://x.com/harugasumi/status/1891021249209339981, https://x.com/harugasumi/status/1891024866909831504, https://x.com/harugasumi/status/1891027392535154832, https://x.com/harugasumi/status/1891031174388015206, https://x.com/harugasumi/status/1891033408270209241, https://x.com/harugasumi/status/1891035208100544853, https://x.com/harugasumi/status/1891037016718012692, https://x.com/harugasumi/status/1891039180911751564, https://x.com/harugasumi/status/1891043311038697506, https://x.com/harugasumi/status/1891045021752742231, https://x.com/harugasumi/status/1891045887599628741, https://x.com/harugasumi/status/1891106538560831816, https://x.com/harugasumi/status/1891108107935203722
subdomains count
0

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 1 year ago · Last seen 10 months ago
Appeared in 5 threat reports