IOC Radar
DomainMediumSignal 100/100

verificationservice.online

Location
Iran, Islamic Republic ofIran, Islamic Republic of
First Seen
Oct 2, 2024
Last Seen
Feb 19, 2026
Oct 2
First Seen
627d ago
Feb 19
Last Seen
122d ago
10
Reports
source reports
99%
Confidence
medium
Found in 10 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

44 techniques

Feed Intelligence Summary

10 reports99% confidence
10
Source reports
99%
Confidence score
Category tags
active scanningaptasiabelleza equiposbotnetbrute forceciudadcivil servicescommand and controlcommunication protocolcredential accesscredential harvestingcredential stuffingcredential theftdata encryptiondata exfiltrationdatabase securitydenial of servicedistributed attacksfinftpftp brute forcegovernment technologyhttp brute forcehttp scannerindicatorinitial accessinjection attacksintrusion detectioniranirgclateral movementleer msmalicious softwaremalwaremedianetworknetwork attacksnetwork intrusionnetwork probingnetwork protocolnetwork scanningnetwork securityngophishing attackpolticaprocess injectionpublic administrationpublic infrastructurepublic policyreconnaissanceregulatory agenciesremote accessremote servicesresearchedsalascannersocial engineeringssh attacksynt1021t1021.001t1021.002t1040t1055t1059t1059.003t1059.004t1059.005t1071.001t1076t1077t1110t1110.001t1110.002t1110.003t1189t1190t1210t1486t1496t1499.001t1499.002t1499.003t1563t1565t1566.001t1566.002t1566.003t1589t1589.002t1590t1590.001t1590.002t1590.003t1590.004t1592t1592.001t1592.002t1592.003t1595t1595.001t1595.002t1595.003tcp protocolthreat intelligencetwo-factor authenticationunauthorized access attemptutensiliosvaporalvistaweb loginweb trafficwishlist vistaxmas

Activity Timeline

1 total obs
Feb 19Feb 19

Threat Activity Heatmap

· Peak: 2026-02-19
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated

The domain **verificationservice.online** has emerged as a significant indicator of compromise (IOC) linked to malicious activities originating from Iran. First observed on October

Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
10
Reports
First seenOct 2, 2024
Last seenFeb 19, 2026

VirusTotal

Not checked

WHOIS

description
This is a pulse created to house CND internal IOCs that we want to monitor, please add title to explain what the IOC and a further description of if this is needed.
domain rank
-1
raw
Create date: 2021-12-14 Domain name: verificationservice.online Domain registrar id: 1068 Domain registrar url: http://www.namecheap.com Expiry date: 2022-12-14 Name server 1: dns1.namecheaphosting.com Name server 2: dns2.namecheaphosting.com Query time: 2021-12-16 15:47:58 Registrant address: 3267309318f7846c Registrant city: 3267309318f7846c Registrant company: 67f6e15f0fdcbd1c Registrant country: Iceland Registrant email: 3267309318f7846cs@ Registrant fax: 3267309318f7846c Registrant name: 67f6e15f0fdcbd1c Registrant phone: 3267309318f7846c Registrant state: 84287fd769bfb9b0 Registrant zip: 3267309318f7846c Update date: 2021-12-14
references
https://www.ic3.gov/Media/News/2024/240927.pdf
subdomains count
1

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 4 months ago
Appeared in 10 threat reports