IOC Radar
DomainMediumSignal 79/100

windows-update.site

Location
United StatesUnited States
First Seen
Feb 28, 2025
Last Seen
May 20, 2026
Feb 28
First Seen
469d ago
May 20
Last Seen
24d ago
8
Reports
source reports
79%
Confidence
medium
Found in 8 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
79%
Signal Score
79 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

16 techniques

Feed Intelligence Summary

8 reports79% confidence
8
Source reports
79%
Confidence score
Category tags
active scanbotnetbotnet activitybrute forceclick fixcommand and controlcopy-paste attackcredential harvestingcredential stealingcredential stuffingdata exfiltrationdata store exposuredistributed attacksdomainsdomains hostingexploitation activitygoogle meet scamidentity & access exploitationindicatorinformation theftinfostealerinfrastructure acquisitionreconnaissanceinjection activityjavascript injectionlumma stealermalicious pagesmalicious softwaremalicious websitemalwarenetworknorth americaphishingphishing attackprocess injectionresearchedscams & fraudsocial engineeringt1055t1059.001t1071.001t1189t1204.002t1486t1496t1499.002t1499.003t1565t1566t1566.001t1566.002t1566.003t1587.001t1590.001threat actortor nodeunited stateswindows update scam

Activity Timeline

1 total obs
May 20May 20

Threat Activity Heatmap

· Peak: 2026-05-20
Less
More
Mon
Wed
Fri
Jun
·
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
79
SIGNAL
Signal Score
79%
Confidence
8
Reports
First seenFeb 28, 2025
Last seenMay 20, 2026

VirusTotal

Not checked

WHOIS

registrar
Registrar of Domain Names REG.RU LLC
domain rank
-1
raw
Creation Date: 2025-02-19T12:16:28.000Z DNSSEC: unsigned Domain Name: windows-update.site Domain Status: autoRenewPeriod https://icann.org/epp#autoRenewPeriod Domain Status: clientHold https://icann.org/epp#clientHold Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Domain Status: serverHold https://icann.org/epp#serverHold Name Server: dion.ns.cloudflare.com Name Server: kehlani.ns.cloudflare.com Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +7.9295340334 Registrar IANA ID: 1606 Registrar URL: https://reg.ru Registrar WHOIS Server: https://whois.nic.love Registrar: Registrar of Domain Names REG.RU LLC Registry Domain ID: D528386772-CNIC Registry Expiry Date: 2027-02-19T23:59:59.000Z Updated Date: 2026-03-17T11:58:03.747Z
references
https://cybersecuritynews.com/lumma-stealer-launch-click-fix-style-attack/
subdomains count
3

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 1 year ago · Last seen 24 days ago
Appeared in 8 threat reports