DomainHighVerifiedSignal 65/100
opkmo.com
Location
First Seen
Jun 4, 2025
Last Seen
Apr 20, 2026
Jun 4
First Seen
371d ago
Apr 20
Last Seen
51d ago
5
Reports
source reports
65%
Confidence
high
13/91
VirusTotal
detections
Found in 5 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
65%
Signal Score
65 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
5 reports65% confidence
5
Source reports
65%
Confidence score
Category tags
aptbotnetbotnet activitybrute forcecommand and controlcommunity managementcontent sharingcredential harvestingcredential stealingcredential stuffingdata exfiltrationdata store exposuredigital platformsdistributed attacksexploitation activityidentity & access exploitationindicatorinfostealerinjection activityiot securitykimsukylummalumma stealermalicious softwaremalwarenetworknorth americaphishingphishing attackprocess injectionratremcos trojanremote accessremote servicesresearchedsocial analyticssocial engineeringsocial mediasocial media marketingsocial media securitysocial networkingstealert1003t1003.001t1003.006t1021.001t1055t1059t1059.003t1059.005t1071t1071.001t1078t1078.001t1083t1105t1189t1192t1486t1496t1499.002t1499.003t1555t1555.003t1565t1566t1566.001t1566.002t1566.003t1573t1588t1588.006t1598t1598.003threat actortor nodetwitterunited statesuser engagement
Activity Timeline
Apr 20Apr 20
Threat Activity Heatmap
· Peak: 2026-04-20LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated
The domain **opkmo.com**, originating from the United States, has been identified as a critical indicator of compromise (IOC) associated with advanced persistent threat (APT) activities. First observed on June
Threat ScoreMedium Risk
65
SIGNAL
Signal Score
65%
Confidence
5
Reports
First seenJun 4, 2025
Last seenApr 20, 2026
Verified IOC
WHOIS
- domain rank
- -1
- raw
- Administrative city: REDACTED FOR PRIVACY Administrative country: REDACTED FOR PRIVACY Administrative state: REDACTED FOR PRIVACY Create date: 2025-06-02 00:00:00 Domain name: opkmo.com Domain registrar id: 49 Domain registrar url: http://www.onamae.com Expiry date: 2026-06-02 00:00:00 Name server 1: ns4.1domainregistry.com Name server 2: ns2.1domainregistry.com Name server 3: ns1.1domainregistry.com Name server 4: ns3.1domainregistry.com Query time: 2025-06-03 11:40:19 Registrant city: 1f8f4166599d23ee Registrant company: 1f8f4166599d23ee Registrant country: United Kingdom Registrant email: a3175443114ee916s@ Registrant fax: 31d1617d95c9a75c Registrant name: 1f8f4166599d23ee Registrant phone: 31d1617d95c9a75c Registrant state: a4f9e7881d4498e5 Registrant zip: 1f8f4166599d23ee Technical city: REDACTED FOR PRIVACY Technical country: REDACTED FOR PRIVACY Technical state: REDACTED FOR PRIVACY Update date: 2025-06-02 00:00:00
- references
- https://x.com/skocherhan/status/1930063917289467978, https://x.com/skocherhan/status/1930066668283191736, https://x.com/skocherhan/status/1930075415072113113, https://x.com/skocherhan/status/1930089890026533063, https://x.com/skocherhan/status/1930093699528093955, https://x.com/skocherhan/status/1930099238211305769, https://x.com/skocherhan/status/1930101673516548144, https://x.com/skocherhan/status/1930105007619072231, https://x.com/skocherhan/status/1930107326280741253, https://x.com/skocherhan/status/1930115123613495333, https://x.com/skocherhan/status/1930116342679552417, https://x.com/skocherhan/status/1930118901150384435, https://x.com/skocherhan/status/1930121288871284991, https://x.com/skocherhan/status/1930269748937306142, https://x.com/skocherhan/status/1930319560055415221, https://x.com/skocherhan/status/1930329052809703557, https://x.com/skocherhan/status/1930330951047156102, https://x.com/skocherhan/status/1930332754107085245, https://x.com/skocherhan/status/1930342198664671598, https://x.com/skocherhan/status/1930357312092549547, https://x.com/skocherhan/status/1930369350302650565, https://x.com/skocherhan/status/1930371313144594891, https://x.com/skocherhan/status/1930375168674705518, https://x.com/skocherhan/status/1930386442963779889
- subdomains count
- 0
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
highFirst detected 1 year ago · Last seen 1 month ago
Appeared in 5 threat reports