🌐 https://phishme.com/loki-bot-malware/
URL
· host
phishme.com
· threat 0.50 (HIGH)
· Malware Families First seen 2026-08-06 13:13:03 · last seen 2026-08-06 14:45:34
🔄 Pivot:📁 Malware Families
Threat score
0.50
MEDIUM
Sightings
2
1 sources
Subdomains (local)
0
from indicators
Related IPs
2
A/AAAA records
DNS records (local)
0
0 types
Reporting sources
1
0 enrichments
📡 Reporting-source breakdown
1
1 total source links on this indicator.
🏷 Tag breakdown (domain family)
1
1
1
📈 DNS record-type counts
No data.
📅 First-seen timeline (family)
1
🏷 WHOIS / Registration (local cache)
No cached WHOIS for phishme.com. Resolve & cache.
📡 DNS Records
Live (DNS-over-HTTPS · optional augmentation)
| Type | Value | TTL |
|---|---|---|
| A | 3.228.57.38 |
60 |
| A | 100.51.18.27 |
60 |
| MX | 0 phishme-com.mail.protection.outlook.com. |
3600 |
| NS | ns-1559.awsdns-02.co.uk. |
21600 |
| NS | ns-417.awsdns-52.com. |
21600 |
| NS | ns-643.awsdns-16.net. |
21600 |
| NS | ns-1054.awsdns-03.org. |
21600 |
| TXT | anthropic-domain-verification-v0q2s2=zbAmdrUiN5r7Y8CinJpQu9iRc |
300 |
| TXT | v=spf1 ip4:23.101.139.239 ip4:34.197.180.129 ip4:185.12.5.30 ip4:52.6.142.78 ip4:52.22.128.9 ip4:52.70.33.20 ip4:52.71.92.53 ip4:52.1.96.230 ip4:52.28.182.143 ip4:199.91.168.231 ip4:66.155.100.241 ip4:166.78.235.183 ip4:52.222.32.235 ip4:71.171.86.210/28 ip4:13.113.166.58 ip4:54.163.238.183 ip4:52.62.59.61 ip4:208.74.204.5 ip4:52.7.203.225 ip4:107.6.43.18 ip4:178.22.65.193 ip4:52.203.249.185 ip4:52.87.141.94 ip4:52.87.143.220 ip4:52.71.186.165 ip4:52.7.164.165 ip4:52.28.134.198 ip4:52.28.190.192 ip4:52.64.192.32 ip4:52.64.199.149 ip4:52.54.245.239 ip4:52.57.123.222 ip4:52.5.119.169 ip4:52.20.128.29 ip4:52.20.155.14 ip4:13.59.88.250 ip4:35.182.57.68 ip4:35.77.163.199 include:spf.pmops.net include:_spf.salesforce.com ip4:54.164.219.64 ip4:54.85.210.194 ip4:54.84.153.58 ip4:107.21.104.73 ip4:213.86.162.68 ip4:98.82.73.109 ip4:98.85.48.230 ip4:54.162.96.89 ip4:54.221.78.72 ip4:34.235.255.88 ip4:34.239.82.44 ip4:44.194.235.51 ip4:44.219.46.116 include:_spf-fedramp.phishme.com include:mail.zendesk.com include:spf.protection.outlook.com include:amazonses.com include:sendgrid.net include:spfa.cpmails.com -all |
300 |
🖥 Related IPs (2)
Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.
🌐 Subdomains — local intel (0)
No subdomains of phishme.com in local intel. Check crt.sh ↗
📡 Reporting Sources (1)
MISP Galaxy Tools/Malware | Malware Families |
🌐 Same-ASN domains (0)
No ASN linkage in local intel.
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
📁 Case Management
Every panel resolves local-first: threat, category, first-seen & sightings from
indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Audit DNS to build passive history
- Pivot resolved IPs to their dossiers
- Report phishing to registrar/host