🌐 https://medium.com/@Sebdraven/unpacking-clop-416b83718e0f
URL
· host
medium.com
· threat 0.50 (HIGH)
· Ransomware Actors First seen 2026-08-06 13:13:01 · last seen 2026-08-06 13:13:01
🔄 Pivot:📁 Ransomware Actors
Threat score
0.50
MEDIUM
Sightings
1
1 sources
Subdomains (local)
0
from indicators
Related IPs
4
A/AAAA records
DNS records (local)
0
0 types
Reporting sources
1
0 enrichments
📡 Reporting-source breakdown
1
1 total source links on this indicator.
🏷 Tag breakdown (domain family)
1
1
1
1
📈 DNS record-type counts
No data.
📅 First-seen timeline (family)
1
🏷 WHOIS / Registration (local cache)
No cached WHOIS for medium.com. Resolve & cache.
📡 DNS Records
Live (DNS-over-HTTPS · optional augmentation)
| Type | Value | TTL |
|---|---|---|
| A | 162.159.153.4 |
300 |
| A | 162.159.152.4 |
300 |
| AAAA | 2606:4700:7::a29f:9904 |
300 |
| AAAA | 2606:4700:7::a29f:9804 |
300 |
| MX | 5 alt1.aspmx.l.google.com. |
300 |
| MX | 10 aspmx3.googlemail.com. |
300 |
| MX | 1 aspmx.l.google.com. |
300 |
| MX | 10 aspmx2.googlemail.com. |
300 |
| MX | 5 alt2.aspmx.l.google.com. |
300 |
| NS | alina.ns.cloudflare.com. |
21600 |
| NS | kip.ns.cloudflare.com. |
21600 |
| TXT | apple-domain-verification=Ls6JkesM8aOd8xyQ |
300 |
| TXT | google-site-verification=QuRrrbvTtvFC0uq2BLr_CcuuuDEiNGDJjI7XkPV3s60 |
300 |
| TXT | v=spf1 include:amazonses.com include:_spf.google.com include:mail.zendesk.com include:sendgrid.net include:spf.tipalti.com include:_spf.psm.knowbe4.com ~all |
300 |
| TXT | cursor-domain-verification-54pwxn=8yHL5J3FELu0JwETv8iGeZt4A |
300 |
| TXT | yahoo-verification-key=nOxcdTfSy6txWr8ZAJ8EevOZHdrxuX4qFKljmgTLsu8= |
300 |
| TXT | google-site-verification=jUulFqySbosf7Fvi1pvOm1KL3AeQ5L5s18CDIU30xek |
300 |
| TXT | 07ecf60c9da442a9b3bcce99190ff60a |
300 |
| TXT | google-site-verification=TUaeSBwTARWW1ntR_TLK0FwD5WKnFCpB5gYVuXkBmlg |
300 |
| TXT | notion-domain-verification=FPUVTTLhldYnVqE4496kGbBhDpf54Y4O7eA8SxkbAHk |
300 |
| TXT | openai-domain-verification=dv-G8sPcKCsIq9tKkWTNFJZh3RE |
300 |
| TXT | google-site-verification=nlPBDLGxOufYa5DdXnQ8d28h5dJjwy0bSakZq-tSios |
300 |
| TXT | linear-domain-verification=tyjcyfd4thj2 |
300 |
| TXT | facebook-domain-verification=eqviiajbkkhum35vciytgngt69oan0 |
300 |
| TXT | anthropic-domain-verification-p32bnn=TlzaDtedEYyM5ccLdU8NsQIPP |
300 |
| TXT | Domain Verification for Digicert (10/05/2022)y7ncgbyk39tw482zsbwcnfx0t775d85j |
300 |
| TXT | dropbox-domain-verification=d7wsnlvbz6l3 |
300 |
🖥 Related IPs (4)
Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.
🌐 Subdomains — local intel (0)
No subdomains of medium.com in local intel. Check crt.sh ↗
📡 Reporting Sources (1)
MISP Galaxy Ransomware | Ransomware Actors |
🌐 Same-ASN domains (0)
No ASN linkage in local intel.
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
📁 Case Management
Every panel resolves local-first: threat, category, first-seen & sightings from
indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Audit DNS to build passive history
- Pivot resolved IPs to their dossiers
- Report phishing to registrar/host