DomainMediumSignal 79/100
windows-update.site
Location
First Seen
Feb 28, 2025
Last Seen
May 20, 2026
Found in 8 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
79%
Signal Score
79 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
8 reports79% confidence
8
Source reports
79%
Confidence score
Category tags
active scanbotnetbotnet activitybrute forceclick fixcommand and controlcopy-paste attackcredential harvestingcredential stealingcredential stuffingdata exfiltrationdata store exposuredistributed attacksdomainsdomains hostingexploitation activitygoogle meet scamidentity & access exploitationindicatorinformation theftinfostealerinfrastructure acquisitionreconnaissanceinjection activityjavascript injectionlumma stealermalicious pagesmalicious softwaremalicious websitemalwarenetworknorth americaphishingphishing attackprocess injectionresearchedscams & fraudsocial engineeringt1055t1059.001t1071.001t1189t1204.002t1486t1496t1499.002t1499.003t1565t1566t1566.001t1566.002t1566.003t1587.001t1590.001threat actortor nodeunited stateswindows update scam
Activity Timeline
May 20May 20
Threat Activity Heatmap
· Peak: 2026-05-20LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Threat ScoreHigh Risk
79
SIGNAL
Signal Score
79%
Confidence
8
Reports
First seenFeb 28, 2025
Last seenMay 20, 2026
VirusTotal
Not checked
WHOIS
- registrar
- Registrar of Domain Names REG.RU LLC
- domain rank
- -1
- raw
- Creation Date: 2025-02-19T12:16:28.000Z DNSSEC: unsigned Domain Name: windows-update.site Domain Status: autoRenewPeriod https://icann.org/epp#autoRenewPeriod Domain Status: clientHold https://icann.org/epp#clientHold Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Domain Status: serverHold https://icann.org/epp#serverHold Name Server: dion.ns.cloudflare.com Name Server: kehlani.ns.cloudflare.com Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +7.9295340334 Registrar IANA ID: 1606 Registrar URL: https://reg.ru Registrar WHOIS Server: https://whois.nic.love Registrar: Registrar of Domain Names REG.RU LLC Registry Domain ID: D528386772-CNIC Registry Expiry Date: 2027-02-19T23:59:59.000Z Updated Date: 2026-03-17T11:58:03.747Z
- references
- https://cybersecuritynews.com/lumma-stealer-launch-click-fix-style-attack/
- subdomains count
- 3
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 24 days ago
Appeared in 8 threat reports