IOC Radar
DomainMediumSignal 76/100

sdfhhh.janaarr.web.id

First Seen
Apr 10, 2025
Last Seen
Apr 6, 2026
Apr 10
First Seen
441d ago
Apr 6
Last Seen
81d ago
6
Reports
source reports
76%
Confidence
medium
Found in 6 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
76%
Signal Score
76 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

24 techniques

Feed Intelligence Summary

6 reports76% confidence
6
Source reports
76%
Confidence score
Category tags
becbec attackbotnetbotnet activitybrand impersonationbrute forcebusiness email compromisecommand and controlcredential harvestingcredential stuffingcredential theftdata exfiltrationdata store exposuredata theftdeceptive contentdgadistributed attacksexploitation activityidentity & access exploitationindicatorinjection activitylink injectionlink redirectionmalicious domainsmalicious emailmalicious linksmalicious softwaremalwaremalware deliverymalware distributionnetworkphishingphishing attackphishing campaign detectedphishing campaign detectionphishing-databaseprocess injectionresearchedsocial engineeringt1048t1055t1071t1071.001t1078t1189t1192t1204t1204.001t1486t1496t1499.002t1499.003t1534t1550.002t1565t1566t1566.001t1566.002t1566.003t1566.004t1583.001t1598t1598.003web securitywhaling attack

Activity Timeline

1 total obs
Apr 6Apr 6

Threat Activity Heatmap

· Peak: 2026-04-06
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

The domain **sdfhhh.janaarr.web.id** has been identified as an active indicator of compromise (IOC) associated with multiple cyber threats, including botnet activity, malware distribution, and phishing campaigns. First observed on April

Threat ScoreHigh Risk
76
SIGNAL
Signal Score
76%
Confidence
6
Reports
First seenApr 10, 2025
Last seenApr 6, 2026

VirusTotal

Not checked

WHOIS

raw
DNSSEC: Unsigned Domain ID: PANDI-DO13136223 Domain Name: janaarr.web.id Expiration Date: 2026-03-01 23:59:59 Last Updated On: 2025-03-01 10:41:45 Name Server: newt.ns.cloudflare.com Name Server: sasha.ns.cloudflare.com Sponsoring Registrar City: Jakarta Pusat Sponsoring Registrar Country: ID Sponsoring Registrar Email: [email protected] Sponsoring Registrar Organization: PT Cloud Hosting Indonesia Sponsoring Registrar Postal Code: 10270 Sponsoring Registrar State/Province: DKI Jakarta Sponsoring Registrar URL: https://idcloudhost.co.id Status: serverTransferProhibited

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 2 months ago
Appeared in 6 threat reports