URL / Domain Profile

🌐 https://blog.malwarebytes.com/cybercrime/2013/10/hiding-in-plain-sight/

URL · host blog.malwarebytes.com · threat 0.50 (HIGH) · ATT&CK
First seen 2026-08-06 13:09:18 · last seen 2026-08-23 13:09:21
🔄 Pivot:📁 ATT&CK

Threat score

0.50
MEDIUM

Sightings

6
3 sources

Subdomains (local)

0
from indicators

Related IPs

2
A/AAAA records

DNS records (local)

3
3 types

Reporting sources

3
1 enrichments

📡 Reporting-source breakdown

Framework
1
ATT&CK Actors
1
ATT&CK
1
3 total source links on this indicator.

🏷 Tag breakdown (domain family)

auto-tagged
1
medium-severity
1
url
1

📈 DNS record-type counts

AAAA
1
CNAME
1
A
1

📅 First-seen timeline (family)

2026-08
1

🏷 WHOIS / Registration (local cache)

No cached WHOIS for blog.malwarebytes.com. Resolve & cache.

🏷 Tags

url medium-severity auto-tagged
CategoryATT&CK
SeverityMEDIUM

📡 DNS Records

Stored (local dns_records) — 3

TypeValueTTLChecked
A 192.0.66.233 60 2026-09-06
AAAA 2a04:fa87:fffd::c000:42e9 60 2026-09-06
CNAME malwarebytes.go-vip.net 1701 2026-09-06

Live (DNS-over-HTTPS · optional augmentation)

TypeValueTTL
A malwarebytes.go-vip.net. 7200
A 192.0.66.233 3600
AAAA malwarebytes.go-vip.net. 7200
AAAA 2a04:fa87:fffd::c000:42e9 3600
MX malwarebytes.go-vip.net. 3779
NS malwarebytes.go-vip.net. 6362
TXT malwarebytes.go-vip.net. 7200
CNAME malwarebytes.go-vip.net. 7200

🖥 Related IPs (2)

Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.

192.0.66.233 2a04:fa87:fffd::c000:42e9

🌐 Subdomains — local intel (0)

No subdomains of blog.malwarebytes.com in local intel. Check crt.sh ↗

📡 Reporting Sources (3)

MITRE ATT&CK EnterpriseATT&CK
MITRE ATT&CK Groups (STIX)ATT&CK Actors
MITRE ATT&CK (STIX)Framework

🌐 Same-ASN domains (0)

No ASN linkage in local intel.

🧩 Enrichment Data (1 records)

classification Aug 31, 2026
{
    "ioc_type": "url",
    "category": "ATT&CK",
    "threat_score": 0.5
}

📁 Case Management

+ New case from this
Every panel resolves local-first: threat, category, first-seen & sightings from indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php

🔗 Related Tools