IOC Radar
DomainMediumSignal 60/100

rw-walhain.be

Location
United StatesUnited States
First Seen
Apr 17, 2026
Last Seen
Apr 17, 2026
Apr 17
First Seen
64d ago
Apr 17
Last Seen
64d ago
4
Reports
source reports
60%
Confidence
medium
Found in 4 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
60%
Signal Score
60 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

8 techniques

Feed Intelligence Summary

4 reports60% confidence
4
Source reports
60%
Confidence score
Category tags
indicatornetworknorth americaresearchedt1018t1056t1071t1082t1095t1105t1497t1518united states

Activity Timeline

1 total obs
Apr 17Apr 17

Threat Activity Heatmap

· Peak: 2026-04-17
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

This Indicator of Compromise (IOC), rw-walhain.be, represents a significant threat to organizational security, evidenced by its high score of 60.47 and a non-whitelisted status. Its association with techniques such as Ingress Tool Transfer, Input Capture, Remote System Discovery, and Command and Control over Windows suggests its potential use in sophisticated attack stages. If left unaddressed, this domain could facilitate malware delivery, credential harvesting, data exfiltration, or the establ…

Threat ScoreMedium Risk
60
SIGNAL
Signal Score
60%
Confidence
4
Reports
First seenApr 17, 2026
Last seenApr 17, 2026

VirusTotal

Not checked

WHOIS

description
hive
domain rank
-1
raw
Domain: rw-walhain.be Organisation: Realtime Register B.V. Registered: Thu Feb 10 2022 Registrant: 3432650ec337c945 Status: NOT AVAILABLE
subdomains count
2

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 2 months ago
Appeared in 4 threat reports