DomainMediumSignal 17/100
www.hehuanfx.com
First Seen
Mar 31, 2025
Last Seen
May 10, 2025
Found in 2 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
17%
Signal Score
17 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
2 reports17% confidence
2
Source reports
17%
Confidence score
Category tags
bankingbotnetclone firmcommand and controlcredential harvestingcredential theftcredit card servicescyber threatsdata exfiltrationdistributed attacksfakefake investment opportunityfinancefinance and insurancefinancial crimefinancial servicesfinancial technologyfraudindicatorinvestment fraudinvestment scammalicious softwaremalwarenetworkpayment processingphishingphishing attackprocess injectionrecovery fraudregulatory alertresearchedscamsocial engineeringt1055t1071t1071.001t1078t1192t1204.002t1486t1496t1499.001t1499.002t1499.003t1565t1566t1566.001t1566.002t1566.003t1567.001t1598t1598.003warning listwealth management
Activity Timeline
May 10May 10
Threat Activity Heatmap
LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated
The domain www.hehuanfx.com has emerged as a significant indicator of compromise (IOC) associated with multiple cyber threats, including botnet activity, malware distribution, and phishing campaigns. First observed on March
Threat ScoreLow Risk
17
SIGNAL
Signal Score
17%
Confidence
2
Reports
First seenMar 31, 2025
Last seenMay 10, 2025
VirusTotal
Not checked
WHOIS
- registrar
- GoDaddy.com, LLC
- description
- The IOSCO platform "https://www.iosco.org/i-scan/" consolidates scam/fraud warnings and IoC from worldwide financial regulators.
- raw
- Creation Date: 2022-04-11T04:34:45Z DNSSEC: unsigned Domain Name: HEHUANFX.COM Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited Name Server: NS65.DOMAINCONTROL.COM Name Server: NS66.DOMAINCONTROL.COM Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: 480-624-2505 Registrar IANA ID: 146 Registrar URL: http://www.godaddy.com Registrar WHOIS Server: whois.godaddy.com Registrar: GoDaddy.com, LLC Registry Domain ID: 2688383258_DOMAIN_COM-VRSN Registry Expiry Date: 2023-04-11T04:34:45Z Updated Date: 2022-09-30T19:37:12Z
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 year ago · Last seen 1 year ago
Appeared in 2 threat reports