🌐 https://heimdalsecurity.com/blog/cheerscrypt-ransomware-strain-attributed-to-chinese-hacking-group/
URL
· host
heimdalsecurity.com
· threat 0.50 (HIGH)
· Ransomware Actors First seen 2026-08-06 13:13:01 · last seen 2026-08-06 13:13:01
🔄 Pivot:📁 Ransomware Actors
Threat score
0.50
MEDIUM
Sightings
1
1 sources
Subdomains (local)
0
from indicators
Related IPs
1
A/AAAA records
DNS records (local)
0
0 types
Reporting sources
1
1 enrichments
📡 Reporting-source breakdown
1
1 total source links on this indicator.
🏷 Tag breakdown (domain family)
1
1
1
1
📈 DNS record-type counts
No data.
📅 First-seen timeline (family)
1
🏷 WHOIS / Registration (local cache)
No cached WHOIS for heimdalsecurity.com. Resolve & cache.
📡 DNS Records
Live (DNS-over-HTTPS · optional augmentation)
| Type | Value | TTL |
|---|---|---|
| A | 192.124.249.38 |
26 |
| MX | 10 heimdalsecurity-com.mail.protection.outlook.com. |
3600 |
| MX | 0 eu-esec-01.heimdalsecurity.com. |
3600 |
| MX | 0 eu-esec-02.heimdalsecurity.com. |
3600 |
| NS | ns-721.awsdns-26.net. |
21600 |
| NS | ns-1860.awsdns-40.co.uk. |
21600 |
| NS | ns-1414.awsdns-48.org. |
21600 |
| NS | ns-74.awsdns-09.com. |
21600 |
| TXT | pardot1016482=90beaa389a62c425b89f18c7f5d61e45e44e95575f8bc5044e1feb68815eaf09 |
3600 |
| TXT | ms-domain-verification=e6b137c5-15d7-455b-a3f2-fa23acd0261c |
3600 |
| TXT | sending_domain1016482=a9d01345d2f1eebefe9052fd1f660d1a83c151fe0fb058576d33bfe58a15974b |
3600 |
| TXT | bw=gEnVxb9RvVEHnhjuE7j3kspEBObMwYIGcOkpr8qZ7g1M |
3600 |
| TXT | v=spf1 include:spf.protection.outlook.com include:mail.zendesk.com include:servers.mcsv.net include:tools-spf.heimdalsecurity.com include:spf-esec.heimdalsecurity.com include:internal-spf.heimdalsecurity.com include:internal-spf2.heimdalsecurity.com -all |
3600 |
🖥 Related IPs (1)
Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.
🌐 Subdomains — local intel (0)
No subdomains of heimdalsecurity.com in local intel. Check crt.sh ↗
📡 Reporting Sources (1)
MISP Galaxy Ransomware | Ransomware Actors |
🌐 Same-ASN domains (0)
No ASN linkage in local intel.
🧩 Enrichment Data (1 records)
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
📁 Case Management
Every panel resolves local-first: threat, category, first-seen & sightings from
indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Audit DNS to build passive history
- Pivot resolved IPs to their dossiers
- Report phishing to registrar/host