DomainHighVerifiedSignal 53/100
vop.sed-i.org
Location
First Seen
Sep 10, 2025
Last Seen
May 13, 2026
Found in 6 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
53%
Signal Score
53 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
6 reports53% confidence
6
Source reports
53%
Confidence score
Category tags
access attemptsactive scanactive scanningauthentication attacksauthentication attemptsauthentication failurebad reputationbiological research threatsbiosecuritybrute forcebrute force attackbrute force attemptcloud infrastructurecode executioncommand and controlcommand executioncommunication protocolcommunity managementcompromised hostcontent sharingcredential accesscredential brute forcingcredential stuffingdata breachdata encryptiondata securitydata store exposureddosdenial of servicedenial-of-service attemptdigital platformsdisinformation campaignsdnsdns attackencryptionenumerationeu cyber policieseu economyeuropeeuropean union politicsexfiltrationexploitexploit attemptexploitationexploitation activityexploitation attemptsexploitation of privilegefin scanfinancial motivationfirewall alertftpftp brute forcegeneral cyber attackgovernment reporthealth securityhttp brute forcehttp scannerhttpsidentity & access exploitationindicatorinformation disseminationinformation securityinitial accessiociot securitylateral movementlogin attacklogin attemptlogin brute-forcemalicious activitymalicious ip blockingmalicious login attemptsmalwaremalware communicationmobile threatnetworknetwork activitynetwork attacksnetwork enumerationnetwork intrusionnetwork intrusion attemptnetwork intrusion attemptsnetwork intrusion detectionnetwork intrusionsnetwork probingnetwork protocolnetwork reconnaissancenetwork scannetwork scanningnetwork securitynetwork service scanningnetwork trafficnull scanos credential dumpingpassword attackpassword attackspasswordattackphishingpopulation studiespossible ddos preparationpossible malicious activityprotocol exploitationpublic awareness reportransomwarereconnaissancereconnaissance activityreferendum analysisregional securityremote accessremote access attemptsremote servicesresearchedresource developmentscientific research vulnerabilitiesservice discoveryservice scansmb brute forcesmb scanningsocial analyticssocial engineeringsocial mediasocial media marketingsocial media securitysocial networkingsoftware exploitationssh attackstatistical analysissyn scansystem discoveryt1016t1018t1021t1021.001t1021.002t1027t1040t1046t1047t1053t1056t1059t1059.004t1068t1071.001t1076t1077t1078t1083t1087t1110t1110.001t1110.002t1110.003t1110.004t1133t1187t1190t1203t1210t1486t1499.002t1499.003t1563t1566t1583t1588t1589t1591t1595t1595.001t1595.002t1595.003t1598tcp protocoltcp scantcp scanningtelnet threattftp brute forcethreat actorthreat actorstor nodetrend analysistwitterudp scanunauthorized access attemptunauthorized access attemptsunited kingdomuser engagementvalid accountsvulnerability scanweb trafficxamzexpires300xmas scanyoutube
Activity Timeline
May 13May 13
Threat Activity Heatmap
· Peak: 2026-05-13LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
53
SIGNAL
Signal Score
53%
Confidence
6
Reports
First seenSep 10, 2025
Last seenMay 13, 2026
Verified IOC
VirusTotal
Not checked
WHOIS
- raw
- Administrative city: REDACTED FOR PRIVACY Administrative country: REDACTED FOR PRIVACY Administrative state: REDACTED FOR PRIVACY Create date: 2024-10-29 00:00:00 Domain name: sed-i.org Domain registrar id: 1910 Domain registrar url: http://www.cloudflare.com Expiry date: 2025-10-29 00:00:00 Name server 1: kiki.ns.cloudflare.com Name server 2: ignacio.ns.cloudflare.com Query time: 2024-10-30 13:57:57 Registrant city: 1f8f4166599d23ee Registrant country: China Registrant email: 29e2c061f3c9524es@ Registrant fax: 1f8f4166599d23ee Registrant name: 1f8f4166599d23ee Registrant phone: 1f8f4166599d23ee Registrant state: f7a5b4ad41f22a3f Registrant zip: 1f8f4166599d23ee Technical city: REDACTED FOR PRIVACY Technical country: REDACTED FOR PRIVACY Technical state: REDACTED FOR PRIVACY Update date: 2024-10-29 00:00:00
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
highFirst detected 9 months ago · Last seen 1 month ago
Appeared in 6 threat reports