IOC Radar
DomainMediumSignal 76/100

uk03.web-zoom.uk

First Seen
Apr 17, 2026
Last Seen
Apr 30, 2026
Apr 17
First Seen
59d ago
Apr 30
Last Seen
45d ago
4
Reports
source reports
76%
Confidence
medium
Found in 4 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
76%
Signal Score
76 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

10 techniques

Feed Intelligence Summary

4 reports76% confidence
4
Source reports
76%
Confidence score
Category tags
abuseactive scanalienvault_ransomwarebad reputationbluenoroffc++c2 servercabbagecabbage ratcageychameleoncommand & controlcontactcopycryptocurrencydomainsdownloaderelfexecutable fileexploitation activityfake meetinghasheshelloindicatoripv4lazaruslinuxmachomalwarenetworkperlpowershellransomwareremote accessresearchedself-signedservicesnippett1008t1056t1059t1102t1123t1125t1176t1547t1557t1566terminatesthreat actortor nodevalidinvbsvbs payloadvoicezoom

Activity Timeline

1 total obs
Apr 30Apr 30

Threat Activity Heatmap

· Peak: 2026-04-30
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreHigh Risk
76
SIGNAL
Signal Score
76%
Confidence
4
Reports
First seenApr 17, 2026
Last seenApr 30, 2026

VirusTotal

Not checked

WHOIS

description
We expanded our research into the recent UNC1069 campaign, which targets individuals by luring them into fraudulent meetings hosted by fake companies. Our analysis focuses on the diverse attack chains employed by the threat actors, as well as the scale and sophistication of their supporting infrastructure.
raw
Create date: 2026-02-09 00:00:00 Domain name: web-zoom.uk Expiry date: 2027-02-09 00:00:00 Name server 1: ns1.dns-parking.com Name server 2: ns2.dns-parking.com Query time: 2026-02-11 21:17:21 Registrant email: [email protected] Update date: 2026-02-09 00:00:00

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 month ago · Last seen 1 month ago
Appeared in 4 threat reports