IOC Radar
DomainHighVerifiedSignal 74/100

xenosploit.com

Location
United StatesUnited States
First Seen
Mar 31, 2025
Last Seen
Apr 25, 2026
Mar 31
First Seen
451d ago
Apr 25
Last Seen
61d ago
6
Reports
source reports
74%
Confidence
high
Found in 6 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
74%
Signal Score
74 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

28 techniques

Feed Intelligence Summary

6 reports74% confidence
6
Source reports
74%
Confidence score
Category tags
active scanactive scanningauthentication attemptsbotnetbotnet activitybrute forcebrute force attackcommand and controlcommunication protocolcredential accesscredential stuffingdata exfiltrationdata store exposureddosdenial of servicedistributed attacksexploitation activityftpidentity & access exploitationindicatorinjection activitymalicious softwaremalwarenetworknetwork attacksnetwork enumerationnetwork protocolnetwork scanningnetwork securitynorth americapassword attacksprocess injectionprotocol exploitationreconnaissanceremote accessremote servicesresearchedself-signedssh attackt1018t1021t1021.001t1040t1046t1055t1059t1068t1071.001t1076t1078t1083t1110t1110.001t1110.002t1110.003t1110.004t1190t1486t1496t1499.002t1499.003t1563t1565t1595t1595.001t1595.002t1595.003tcp protocoltelnet threatunauthorized accessunited states

Activity Timeline

1 total obs
Apr 25Apr 25

Threat Activity Heatmap

· Peak: 2026-04-25
Less
More
Mon
Wed
Fri
Jun
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
1
Minimal
Intelligence SummaryAI Generated

The domain **xenosploit.com** has been identified as a critical indicator of compromise (IOC) associated with botnet and malware activities, originating from the United States. Security analysts should be aware that this domain has been actively involved in malicious IP scanning and authentication attempts, suggesting it may serve as a command and control (C

Threat ScoreHigh Risk
74
SIGNAL
Signal Score
74%
Confidence
6
Reports
First seenMar 31, 2025
Last seenApr 25, 2026
Verified IOC

VirusTotal

Not checked

WHOIS

domain rank
-1
raw
Administrative city: Reykjavik Administrative country: Iceland Administrative email: [email protected] Administrative state: Capital Region Create date: 2024-12-15 00:00:00 Domain name: xenosploit.com Domain registrar id: 1068 Domain registrar url: http://www.namecheap.com Expiry date: 2025-12-15 00:00:00 Name server 1: jason.ns.cloudflare.com Name server 2: maleah.ns.cloudflare.com Query time: 2024-12-16 18:21:25 Registrant city: ddbf76e4e8cee320 Registrant company: 4b7a0912c26a13e2 Registrant country: Iceland Registrant email: [email protected] Registrant name: 37bfbc24cafea5d2 Registrant phone: 8887f09f69a004c2 Registrant state: 3e0204199d8ebf9c Registrant zip: f206c9d9737ad45d Technical city: Reykjavik Technical country: Iceland Technical email: [email protected] Technical state: Capital Region Update date: 2024-12-15 00:00:00
references
https://www.virustotal.com/graph/gce5501b47e44440c8e4af5ea08e9a44055eb0f55cc2944bf8dd04cecf91a5098
subdomains count
0

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 1 year ago · Last seen 2 months ago
Appeared in 6 threat reports