IOC Radar
DomainMediumSignal 77/100

ywbook.com

Location
GermanyGermany
First Seen
Apr 15, 2026
Last Seen
Jun 5, 2026
Apr 15
First Seen
60d ago
Jun 5
Last Seen
10d ago
8
Reports
source reports
77%
Confidence
medium
Found in 8 reports. Confidence: medium. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
77%
Signal Score
77 / 100
IDS Rule
No
Threat Context
Tags

Feed Intelligence Summary

8 reports77% confidence
8
Source reports
77%
Confidence score
Category tags
europegermanyindicatornetworkphishpolandpolcertresearched

Activity Timeline

1 total obs
Jun 5Jun 5

Threat Activity Heatmap

· Peak: 2026-06-05
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
1
Minimal
3mo
1
Minimal
Intelligence SummaryAI Generated

The domain ywbook.com, originating from Germany, has been identified as an active indicator of compromise (IOC) associated with phishing campaigns. First observed on April

Threat ScoreHigh Risk
77
SIGNAL
Signal Score
77%
Confidence
8
Reports
First seenApr 15, 2026
Last seenJun 5, 2026

VirusTotal

Not checked

WHOIS

registrar
Gname.com Pte. Ltd.
description
See: https://cert.pl/en/warning-list/ (archived version here: https://web.archive.org/web/20231029161224/https://cert.pl/en/posts/2020/03/malicious_domains/)
domain rank
-1
raw
Admin City: Redacted for privacy Admin Country: Redacted for privacy Admin Organization: Redacted for privacy Admin Postal Code: Redacted for privacy Admin State/Province: Redacted for privacy Creation Date: 2011-05-20T19:17:25Z DNSSEC: unsigned Domain Name: YWBOOK.COM Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited Name Server: NS7.ALIDNS.COM Name Server: NS8.ALIDNS.COM Registrant City: ddb75a553547a419 Registrant Country: CN Registrant Email: 95f5f973e14934aas@ Registrant Fax: ddb75a553547a419 Registrant Name: ddb75a553547a419 Registrant Organization: ddb75a553547a419 Registrant Phone: ddb75a553547a419 Registrant Postal Code: ddb75a553547a419 Registrant State/Province: ddb75a553547a419 Registrant Street: ddb75a553547a419 Registrar Abuse Contact Email: [email protected] Registrar Abuse Contact Phone: +65.31581931 Registrar Abuse Contact Phone: +65.65189986 Registrar IANA ID: 1923 Registrar Registration Expiration Date: 2026-05-20T19:17:25Z Registrar URL: http://www.gname.com Registrar URL: www.gname.com Registrar WHOIS Server: whois.gname.com Registrar: Gname.com Pte. Ltd. Registry Domain ID: 1657235231_DOMAIN_COM-VRSN Registry Expiry Date: 2026-05-20T19:17:25Z Registry Registrant ID: Redacted for privacy Tech City: Redacted for privacy Tech Country: Redacted for privacy Tech Organization: Redacted for privacy Tech Postal Code: Redacted for privacy Tech State/Province: Redacted for privacy Updated Date: 2024-11-28T18:46:47Z Updated Date: 2026-03-25T00:24:17Z
subdomains count
1

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

medium
First detected 2 months ago · Last seen 10 days ago
Appeared in 8 threat reports