IOC Radar
DomainMediumSignal 65/100

verification-login.com

Location
TurkeyTurkey
First Seen
Jul 23, 2020
Last Seen
Apr 28, 2026
Jul 23
First Seen
2161d ago
Apr 28
Last Seen
55d ago
8
Reports
source reports
65%
Confidence
medium
Found in 8 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
65%
Signal Score
65 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

28 techniques

Feed Intelligence Summary

8 reports65% confidence
8
Source reports
65%
Confidence score
Category tags
abuseabuse reportactive scanaerospace & defenseattackautomotive manufacturingbad reputationbotnetbotnet activitybrand abusebrand impersonationbrute forcecertcivil servicescommand and controlcredential harvestingcredential stuffingcredential theftcyber securitydata exfiltrationdata store exposuredeceptive marketingdefensedefense contractingdefense logisticsdefense systemsdefense technologydistributed attackselectronics manufacturingexploitation activityfraudfraudulent websitegovernment technologyidentity & access exploitationindicatorindustrial automationindustrial iotindustrial productioninfrastructure acquisitionreconnaissanceingress tool transferinjection activityiociot securitymalicious activitymalicious downloadmalicious linkmalicious linksmalicious softwaremalwaremalware deliverymalware distributionmalware hostingmanufacturing technologymilitary operationsnational securitynetworknextraynorth americaphishingphishing attackphishing campaignphishing domain detectionphishing kitprocess injectionprocess manufacturingpublic administrationpublic infrastructurepublic policyquality controlregulatory agenciesresearchedrogue domainscamscams & fraudsecurity operationssocial engineeringsocial engineering attackspamspam campaignsupply chain attacksupply chain managementt1055t1071t1071.001t1078t1105t1189t1192t1204t1204.001t1204.002t1486t1496t1499.002t1499.003t1565t1566t1566.001t1566.002t1566.003t1566.004t1583t1583.001t1587.001t1588t1588.002t1590.001t1598t1598.003threat actorthreat intelligencetor nodeturkeytyposquattingunited statesweb security

Activity Timeline

1 total obs
Apr 28Apr 28

Threat Activity Heatmap

· Peak: 2026-04-28
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

The domain **verification-login.com**, originating from Turkey, has been identified as a significant indicator of compromise (IOC) associated with multiple cyber threats. First observed on July

Threat ScoreMedium Risk
65
SIGNAL
Signal Score
65%
Confidence
8
Reports
First seenJul 23, 2020
Last seenApr 28, 2026

VirusTotal

Not checked

WHOIS

registrar
ENOM, INC.
description
Phishing, scams, all junk goes here.
domain rank
-1
raw
Admin City: REDACTED FOR PRIVACY Admin Country: REDACTED FOR PRIVACY Admin Organization: REDACTED FOR PRIVACY Admin Postal Code: REDACTED FOR PRIVACY Admin State/Province: REDACTED FOR PRIVACY Creation Date: 2023-10-07T06:23:00.00Z Creation Date: 2023-10-07T06:23:53Z DNSSEC: unsigned Domain Name: VERIFICATION-LOGIN.COM Domain Name: verification-login.com Domain Status: pendingDelete https://www.icann.org/epp#pendingDelete Domain Status: redemptionPeriod https://icann.org/epp#redemptionPeriod Domain Status: redemptionPeriod https://www.icann.org/epp#redemptionPeriod Name Server: DNS1.NAME-SERVICES.COM Name Server: DNS2.NAME-SERVICES.COM Name Server: DNS3.NAME-SERVICES.COM Name Server: DNS4.NAME-SERVICES.COM Name Server: DNS5.NAME-SERVICES.COM Registrant City: 1f8f4166599d23ee Registrant Country: US Registrant Email: 7b3f90a587b661bcs@ Registrant Fax: 1f8f4166599d23ee Registrant Name: 1f8f4166599d23ee Registrant Organization: 1f8f4166599d23ee Registrant Phone Ext: 3432650ec337c945 Registrant Phone: 1f8f4166599d23ee Registrant Postal Code: 1f8f4166599d23ee Registrant State/Province: 5909b98f8d0e7f8a Registrant Street: 1f8f4166599d23ee Registrant Street: 3432650ec337c945 Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +1.4259744689 Registrar IANA ID: 48 Registrar Registration Expiration Date: 2024-10-07T06:23:53.00Z Registrar URL: WWW.ENOMDOMAINS.COM Registrar URL: http://www.enomdomains.com Registrar WHOIS Server: WHOIS.ENOM.COM Registrar WHOIS Server: whois.enom.com Registrar: ENOM, INC. Registrar: eNom, LLC Registry Domain ID: 2819921458_DOMAIN_COM-VRSN Registry Expiry Date: 2024-10-07T06:23:53Z Tech City: REDACTED FOR PRIVACY Tech Country: REDACTED FOR PRIVACY Tech Organization: REDACTED FOR PRIVACY Tech Postal Code: REDACTED FOR PRIVACY Tech State/Province: REDACTED FOR PRIVACY Updated Date: 2024-11-18T21:00:32.00Z Updated Date: 2024-11-18T21:00:32Z
references
https://twitter.com/c9lab_soc/status/1552067355554877440, https://twitter.com/c9lab_soc/status/1552069908036341760, https://twitter.com/c9lab_soc/status/1552071709083045889, https://twitter.com/c9lab_soc/status/1552073405221941249
subdomains count
8

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 6 years ago · Last seen 1 month ago
Appeared in 8 threat reports