🌐 https://pushsecurity.com/blog/scattered-lapsus-hunters/
URL
· host
pushsecurity.com
· threat 0.50 (HIGH)
· Threat Actors First seen 2026-08-06 13:13:00 · last seen 2026-08-06 14:45:34
🔄 Pivot:📁 Threat Actors
Threat score
0.50
MEDIUM
Sightings
2
1 sources
Subdomains (local)
0
from indicators
Related IPs
4
A/AAAA records
DNS records (local)
0
0 types
Reporting sources
1
0 enrichments
📡 Reporting-source breakdown
1
1 total source links on this indicator.
🏷 Tag breakdown (domain family)
1
1
1
📈 DNS record-type counts
No data.
📅 First-seen timeline (family)
1
🏷 WHOIS / Registration (local cache)
No cached WHOIS for pushsecurity.com. Resolve & cache.
📡 DNS Records
Live (DNS-over-HTTPS · optional augmentation)
| Type | Value | TTL |
|---|---|---|
| A | 18.238.109.40 |
60 |
| A | 18.238.109.125 |
60 |
| A | 18.238.109.119 |
60 |
| A | 18.238.109.22 |
60 |
| MX | 5 alt2.aspmx.l.google.com. |
3600 |
| MX | 5 alt1.aspmx.l.google.com. |
3600 |
| MX | 10 aspmx3.googlemail.com. |
3600 |
| MX | 10 aspmx2.googlemail.com. |
3600 |
| MX | 1 aspmx.l.google.com. |
3600 |
| NS | ns-1178.awsdns-19.org. |
21600 |
| NS | ns-1016.awsdns-63.net. |
21600 |
| NS | ns-240.awsdns-30.com. |
21600 |
| NS | ns-1881.awsdns-43.co.uk. |
21600 |
| TXT | stripe-verification=bbde66131d7d1536ecfdd01d3b14e381ac55e92dec88280f25a911501db9d1c6 |
3600 |
| TXT | google-site-verification=MyCTLv7Jx1rQw4aCSxrRPqh855F5GaMdwDEcRZC17xU |
3600 |
| TXT | canva-site-verification=EyTDPxmWTmLZFD-GVcUYbQ |
3600 |
| TXT | anthropic-domain-verification-jjcw45=tEOvB4yxB9dnBxj7PNI6nLt29 |
3600 |
| TXT | google-site-verification=NPs-EQZ3ejdog8yADz3eiz8vK8FInYu7T-hanAB_8is |
3600 |
| TXT | atlassian-domain-verification=azClNX0xtqeZs8uYkBdHzL5y2NPL7dVPB40dHphazYiZ9Mxla/0go72/DXOXQUx8 |
3600 |
| TXT | reachdesk-verification=TQ5sgzJQBgQlN0uMRDqloTj6Xz08HjR43BsDRMoYA43YSrvtle9tT97qOOtYbFzC |
3600 |
| TXT | notion-domain-verification=RlGeCEunLnckfdnEqT5LASqtbyZyEgnEbM5YqQC6gTt |
3600 |
| TXT | slack-domain-verification=3KIGf2LeWNTAn8e5TcIbh84SHUnjlKGUs5mnus4U |
3600 |
| TXT | v=spf1 include:_spf.google.com include:mail.pushsecurity.com include:amazonses.com include:6692773.spf07.hubspotemail.net include:mailgun.org ip4:54.240.88.8 ~all |
3600 |
| TXT | apple-domain-verification=fUFIW7dv91N8hxmW |
3600 |
| TXT | google-site-verification=m16lmA1P8m-BwVdqQbYYWd2TPSay2CfuufWxlJMn2hE |
3600 |
| TXT | google-site-verification=D89PEReDnCzlG0vDoVcXAUE_EZyB15i0nG9HctYIJTk |
3600 |
🖥 Related IPs (4)
Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.
🌐 Subdomains — local intel (0)
No subdomains of pushsecurity.com in local intel. Check crt.sh ↗
📡 Reporting Sources (1)
MISP Galaxy Threat Actors | Threat Actors |
🌐 Same-ASN domains (0)
No ASN linkage in local intel.
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
📁 Case Management
Every panel resolves local-first: threat, category, first-seen & sightings from
indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Audit DNS to build passive history
- Pivot resolved IPs to their dossiers
- Report phishing to registrar/host