DomainHighVerifiedSignal 64/100
txtag.org-dhus.vip
First Seen
Apr 10, 2025
Last Seen
May 11, 2026
Found in 5 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
64%
Signal Score
64 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
5 reports64% confidence
5
Source reports
64%
Confidence score
Category tags
botnetbotnet activitybrand impersonationbrute forcecommand and controlcredential harvestingcredential stuffingdata exfiltrationdata store exposuredeceptive contentdgadistributed attacksexploitation activityidentity & access exploitationindicatorinjection activitylink injectionmalicious domainsmalicious softwaremalwaremalware distributionnetworkphishingphishing attackphishing campaign detectedphishing campaign detectionprocess injectionresearchedsocial engineeringt1048t1055t1071t1071.001t1189t1192t1204t1204.001t1486t1496t1499.002t1499.003t1534t1565t1566t1566.001t1566.002t1566.003t1598t1598.003
Activity Timeline
May 11May 11
Threat Activity Heatmap
· Peak: 2026-05-11LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated
This Indicator of Compromise (IOC), a domain identified as `txtag.org-dhus.vip`, represents a significant threat primarily associated with phishing campaigns and potential delivery of various malware, including ransomware. Its high score of 64.18, coupled with its presence in multiple reputable threat intelligence feeds, underscores its malicious nature and potential for direct harm. If successfully leveraged, this IOC could lead to user compromise through drive-by downloads or credential theft,…
Threat ScoreMedium Risk
64
SIGNAL
Signal Score
64%
Confidence
5
Reports
First seenApr 10, 2025
Last seenMay 11, 2026
Verified IOC
VirusTotal
Not checked
WHOIS
- raw
- Administrative city: REDACTED FOR PRIVACY Administrative country: REDACTED FOR PRIVACY Administrative state: REDACTED FOR PRIVACY Create date: 2025-04-08 00:00:00 Domain name: org-dhus.vip Domain registrar id: 1479 Domain registrar url: www.namesilo.com Expiry date: 2026-04-08 00:00:00 Name server 1: ns2.dnsowl.com Name server 2: ns1.dnsowl.com Name server 3: ns3.dnsowl.com Query time: 2025-04-09 13:16:10 Registrant city: 1f8f4166599d23ee Registrant company: 566bb814321610e4 Registrant country: United States Registrant email: 29e2c061f3c9524es@ Registrant fax: 31d1617d95c9a75c Registrant name: 1f8f4166599d23ee Registrant phone: 31d1617d95c9a75c Registrant state: e1c7c1911395a3cf Registrant zip: 1f8f4166599d23ee Technical city: REDACTED FOR PRIVACY Technical country: REDACTED FOR PRIVACY Technical state: REDACTED FOR PRIVACY Update date: 2025-04-08 00:00:00
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
highFirst detected 1 year ago · Last seen 1 month ago
Appeared in 5 threat reports