DomainMediumSignal 60/100
winshelter.com
Location
First Seen
Apr 17, 2026
Last Seen
Apr 17, 2026
Found in 4 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
60%
Signal Score
60 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
4 reports60% confidence
4
Source reports
60%
Confidence score
Category tags
indicatornetworknorth americaresearchedt1018t1056t1071t1082t1095t1105t1497t1518united states
Activity Timeline
Apr 17Apr 17
Threat Activity Heatmap
· Peak: 2026-04-17LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
60
SIGNAL
Signal Score
60%
Confidence
4
Reports
First seenApr 17, 2026
Last seenApr 17, 2026
VirusTotal
Not checked
WHOIS
- description
- hive
- domain rank
- -1
- raw
- Administrative city: Harlow Administrative country: United Kingdom Administrative email: [email protected] Administrative state: England Billing city: Harlow Billing country: United Kingdom Billing email: [email protected] Billing state: England Create date: 2025-12-02 00:00:00 Domain name: winshelter.com Domain registrar id: 1861.0 Domain registrar url: https://cart-before.porkbun.horse/rdap/ Expiry date: 2026-12-02 00:00:00 Name server 1: frank.ns.cloudflare.com Name server 2: gracie.ns.cloudflare.com Query time: 2026-04-06 13:18:08 Registrant city: 78eeb9001b78d1c0 Registrant country: United Kingdom Registrant email: [email protected] Registrant name: 0203a3796593e458 Registrant phone: b7a1014f0ec0de89 Registrant state: 146a288819b5e682 Registrant zip: 2b79e12aae7500b5 Technical city: Harlow Technical country: United Kingdom Technical email: [email protected] Technical state: England Update date: 2026-04-06 00:00:00
- subdomains count
- 0
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 2 months ago · Last seen 2 months ago
Appeared in 4 threat reports