URL / Domain Profile

🌐 ASP.NET

DOMAIN · host asp.net · threat 0.50 (HIGH) · Vulnerabilities
First seen 2026-08-06 13:10:28 · last seen 2026-08-06 14:48:26

Threat score

0.50
MEDIUM

Sightings

8
5 sources

Subdomains (local)

0
from indicators

Related IPs

5
A/AAAA records

DNS records (local)

14
5 types

Reporting sources

5
0 enrichments

📡 Reporting-source breakdown

Vulnerabilities
3
Malware Families
1
Vulnerability
1
5 total source links on this indicator.

🏷 Tag breakdown (domain family)

medium-severity
1
malware
1
auto-tagged
1

📈 DNS record-type counts

A
5
NS
4
TXT
3
SOA
1
MX
1

📅 First-seen timeline (family)

2026-08
1

🏷 WHOIS / Registration (local cache)

No cached WHOIS for asp.net. Resolve & cache.

🏷 Tags

malware medium-severity auto-tagged
CategoryVulnerabilities
SeverityMEDIUM

📡 DNS Records

Stored (local dns_records) — 14

TypeValueTTLChecked
A 20.70.246.20 1928 2026-08-06
A 20.112.250.133 1928 2026-08-06
A 20.231.239.246 1928 2026-08-06
A 20.236.44.162 1928 2026-08-06
A 20.76.201.171 1928 2026-08-06
MX asp-net.mail.protection.outlook.com 3600 2026-08-06
NS ns4-04.azure-dns.info 5342 2026-08-06
NS ns3-04.azure-dns.org 5342 2026-08-06
NS ns1-04.azure-dns.com 5342 2026-08-06
NS ns2-04.azure-dns.net 5342 2026-08-06
SOA ns1-04.azure-dns.com 3600 2026-08-06
TXT MS=ms47371022 3600 2026-08-06
TXT v=DMARC1; p=none pct=100; rua=mailto:d@rua.agari.com; ruf=mailto:d@ruf.agari.com; fo=1 3600 2026-08-06
TXT v=spf1 include:spf.mandrillapp.com include:spf.protection.outlook.com ip4:64.34.80.172 -all 3600 2026-08-06

Live (DNS-over-HTTPS · optional augmentation)

TypeValueTTL
A 20.112.250.133 3272
A 20.70.246.20 3272
A 20.231.239.246 3272
A 20.76.201.171 3272
A 20.236.44.162 3272
MX 1 asp-net.mail.protection.outlook.com. 3600
NS ns4-04.azure-dns.info. 21600
NS ns2-04.azure-dns.net. 21600
NS ns1-04.azure-dns.com. 21600
NS ns3-04.azure-dns.org. 21600
TXT v=spf1 include:spf.mandrillapp.com include:spf.protection.outlook.com ip4:64.34.80.172 -all 3600
TXT MS=ms47371022 3600
TXT v=DMARC1; p=none pct=100; rua=mailto:d@rua.agari.com; ruf=mailto:d@ruf.agari.com; fo=1 3600

🖥 Related IPs (5)

Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.

20.70.246.20 20.112.250.133 20.231.239.246 20.236.44.162 20.76.201.171

🌐 Subdomains — local intel (0)

No subdomains of asp.net in local intel. Check crt.sh ↗

📡 Reporting Sources (5)

CISA Known Exploited VulnsVulnerabilities
CISA Known Exploited Vulns (KEV)Vulnerabilities
MISP Galaxy Tools/MalwareMalware Families
CISA KEV (JSON)Vulnerabilities
CISA Known Exploited VulnerabilitiesVulnerability

🌐 Same-ASN domains (0)

No ASN linkage in local intel.

📁 Case Management

+ New case from this
Every panel resolves local-first: threat, category, first-seen & sightings from indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php

🔗 Related Tools