DomainMediumSignal 65/100
www.web05meet.us
First Seen
Apr 17, 2026
Last Seen
Apr 30, 2026
Found in 4 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
65%
Signal Score
65 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK
MITRE ATT&CK TTPs
Feed Intelligence Summary
4 reports65% confidence
4
Source reports
65%
Confidence score
Category tags
abuseactive scanalienvault_ransomwarebad reputationbluenoroffc++c2 servercabbagecabbage ratcageychameleoncommand & controlcontactcopycryptocurrencydgadomainsdownloaderelfexecutable fileexploitation activityfake meetinghasheshelloindicatoripv4lazaruslinuxmachomalwarenetworkperlpowershellransomwareremote accessresearchedself-signedservicesnippett1008t1056t1059t1102t1123t1125t1176t1547t1557t1566terminatesthreat actortor nodevalidinvbsvbs payloadvoicezoom
Activity Timeline
Apr 30Apr 30
Threat Activity Heatmap
· Peak: 2026-04-30LessMore
Mon
Wed
Fri
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Threat ScoreMedium Risk
65
SIGNAL
Signal Score
65%
Confidence
4
Reports
First seenApr 17, 2026
Last seenApr 30, 2026
VirusTotal
Not checked
WHOIS
- description
- We expanded our research into the recent UNC1069 campaign, which targets individuals by luring them into fraudulent meetings hosted by fake companies. Our analysis focuses on the diverse attack chains employed by the threat actors, as well as the scale and sophistication of their supporting infrastructure.
- raw
- Administrative city: Los Angeles Administrative country: United States Administrative email: [email protected] Administrative state: CA Create date: 2026-02-04 00:00:00 Domain name: web05meet.us Domain registrar id: 1647.0 Expiry date: 2027-02-04 00:00:00 Name server 1: ns1.dns-parking.com Name server 2: ns2.dns-parking.com Query time: 2026-02-05 15:18:48 Registrant city: 14ac44352c27e121 Registrant country: United States Registrant email: [email protected] Registrant name: 784dce90361437a4 Registrant phone: 1619c67a67540e15 Registrant state: b1952dfc047df18a Registrant zip: 27e2b1a053049cfb Technical city: Los Angeles Technical country: United States Technical email: [email protected] Technical state: CA Update date: 2026-02-04 00:00:00
Export & API
STIX 2.1 Bundle
CSV Export
Permalink
IOC Journey
mediumFirst detected 1 month ago · Last seen 1 month ago
Appeared in 4 threat reports