URL / Domain Profile

🌐 eduspa.com

DOMAIN · host eduspa.com · threat 0.50 (HIGH) · Ransomware
First seen 2026-08-06 13:12:26 · last seen 2026-08-06 14:48:14
🔄 Pivot:📁 Ransomware

Threat score

0.50
MEDIUM

Sightings

3
2 sources

Subdomains (local)

0
from indicators

Related IPs

1
A/AAAA records

DNS records (local)

0
0 types

Reporting sources

2
0 enrichments

📡 Reporting-source breakdown

Ransomware
2
2 total source links on this indicator.

🏷 Tag breakdown (domain family)

ransomware
1
auto-tagged
1
medium-severity
1

📈 DNS record-type counts

No data.

📅 First-seen timeline (family)

2026-08
1

🏷 WHOIS / Registration (local cache)

No cached WHOIS for eduspa.com. Resolve & cache.

🏷 Tags

ransomware medium-severity auto-tagged
CategoryRansomware
SeverityMEDIUM

📡 DNS Records

Live (DNS-over-HTTPS · optional augmentation)

TypeValueTTL
A 211.245.24.140 600
MX 10 mail.eduspa.com. 600
NS ns1.eduspa.com. 600
NS ns2.eduspa.com. 600
TXT _03cl726stkb1tnit7urlnyoajlmn8qz 600
TXT google-site-verification=M2uzVpUtl5EsK8YPtGaW6zS2ImjY8x75b2MX60f0uZA 600
TXT _5lxe8cysj0r2vz1batncq2iuyw7im87 600
TXT _57a63hsa0ibdxps3usxq1b0a6uehb26 600
TXT google-site-verification=uMoQdB20MLruhYDrf1OuuKPLp2SkaK5nT5JaYWSe14E 600
TXT _b5lrbohip3jnm9wwk5k0ppvg4ubyn71 600
TXT v=spf1 ip4:211.245.24.133 ip4:211.245.24.134 ip4:211.245.24.135 ip4:211.202.0.188 ip4:211.202.0.187 ip4:211.202.0.182 ip4:211.202.0.179 ip4:211.202.0.190 mx:mail.pmg.co.kr mx:mail.parkmungak.com mx:mail.parkmungak.co.kr -allgoogle-site-verification=_-AoY8aDzeTVw087_2fO21Z2C5MvO_ZFanZH9IGUvjUgoogle-site-verification=1r_yZIWnaCBAsXNbXkpWh0u97xjEkd6JXoTqf4mJS00google-site-verification=QLjDyN1qJNPbu21XBAbkfPYBgxPRuoKW3es7MriXIqw 600
TXT _qlf3xfk198cp9rj67lip9a5huflbdfa 600

🖥 Related IPs (1)

Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.

211.245.24.140

🌐 Subdomains — local intel (0)

No subdomains of eduspa.com in local intel. Check crt.sh ↗

📡 Reporting Sources (2)

Ransomware.live recent victimsRansomware
Ransomware.live recentvictimsRansomware

🌐 Same-ASN domains (0)

No ASN linkage in local intel.

📁 Case Management

+ New case from this
Every panel resolves local-first: threat, category, first-seen & sightings from indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php

🔗 Related Tools