IOC Radar
DomainHighVerifiedSignal 100/100

zxufw.cn

Location
United StatesUnited States
First Seen
Apr 10, 2025
Last Seen
Feb 14, 2026
Apr 10
First Seen
431d ago
Feb 14
Last Seen
121d ago
6
Reports
source reports
99%
Confidence
high
Found in 6 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
99%
Signal Score
100 / 100
IDS Rule
No
Threat Context
Tags
MITRE ATT&CK

MITRE ATT&CK TTPs

20 techniques

Feed Intelligence Summary

6 reports99% confidence
6
Source reports
99%
Confidence score
Category tags
botnetbrand impersonationcommand and controlcredential harvestingdata exfiltrationdeceptive contentdistributed attacksindicatorlink injectionmalicious domainsmalicious softwaremalwaremalware distributionnetworknorth americaphishing attackphishing campaign detectedphishing campaign detectionprocess injectionresearchedsocial engineeringt1048t1055t1071t1071.001t1189t1192t1204t1204.001t1486t1496t1499.002t1499.003t1534t1565t1566t1566.001t1566.002t1566.003t1598t1598.003united states

Activity Timeline

1 total obs
Feb 14Feb 14

Threat Activity Heatmap

· Peak: 2026-02-14
Less
More
Mon
Wed
Fri
Jun
·
·
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
24h
0
Dormant
7d
0
Dormant
30d
0
Dormant
3mo
0
Dormant
Intelligence SummaryAI Generated

The domain **zxufw.cn** has been identified as a critical indicator of compromise (IOC) associated with sophisticated botnet and malware activities. Originating from the United States, this malicious domain has been active since April

Threat ScoreHigh Risk
100
SIGNAL
Signal Score
99%
Confidence
6
Reports
First seenApr 10, 2025
Last seenFeb 14, 2026
Verified IOC

VirusTotal

Not checked

WHOIS

domain rank
-1
raw
DNSSEC: unsigned Domain Name: zxufw.cn Domain Status: clientHold Domain Status: clientTransferProhibited Domain Status: clientUpdateProhibited Domain Status: inactive Domain Status: pendingDelete Expiration Time: 2025-06-17 01:45:30 Registrant Contact Email: [email protected] Registrant: 12ad5870ed2db721 Registration Time: 2024-06-17 01:45:30 Sponsoring Registrar: 阿里云计算有限公司(万网)
references
https://malware-filter.gitlab.io/malware-filter/phishing-filter-domains.txt
subdomains count
0

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 1 year ago · Last seen 4 months ago
Appeared in 6 threat reports