🌐 https://redcanary.com/blog/grief-ransomware/
URL
· host
redcanary.com
· threat 0.50 (HIGH)
· Ransomware Actors First seen 2026-08-06 13:13:01 · last seen 2026-08-06 13:13:01
🔄 Pivot:📁 Ransomware Actors
Threat score
0.50
MEDIUM
Sightings
1
1 sources
Subdomains (local)
0
from indicators
Related IPs
1
A/AAAA records
DNS records (local)
0
0 types
Reporting sources
1
0 enrichments
📡 Reporting-source breakdown
1
1 total source links on this indicator.
🏷 Tag breakdown (domain family)
1
1
1
1
📈 DNS record-type counts
No data.
📅 First-seen timeline (family)
1
🏷 WHOIS / Registration (local cache)
No cached WHOIS for redcanary.com. Resolve & cache.
📡 DNS Records
Live (DNS-over-HTTPS · optional augmentation)
| Type | Value | TTL |
|---|---|---|
| A | 104.198.136.223 |
60 |
| MX | 20 alt1.aspmx.l.google.com. |
3600 |
| MX | 50 aspmx3.googlemail.com. |
3600 |
| MX | 30 alt2.aspmx.l.google.com. |
3600 |
| MX | 40 aspmx2.googlemail.com. |
3600 |
| MX | 10 aspmx.l.google.com. |
3600 |
| NS | ns13.dnsmadeeasy.com. |
21600 |
| NS | ns15.dnsmadeeasy.com. |
21600 |
| NS | ns10.dnsmadeeasy.com. |
21600 |
| NS | ns14.dnsmadeeasy.com. |
21600 |
| NS | ns12.dnsmadeeasy.com. |
21600 |
| NS | ns11.dnsmadeeasy.com. |
21600 |
| TXT | drift-domain-verification=53ce70fc5236b2cee2a61822bf9af35d95ae7c130cf4402e33668d1782218b86 |
3600 |
| TXT | google-site-verification=HV_P9w9Xa7Mo1cUNEzNC0zegEnLij9VHPUdSvm5sK60 |
3600 |
| TXT | 00DU0000000Lyeu=1TBTP00000009Mf |
3600 |
| TXT | google-site-verification=2bwXDjSmYK1ighcDO_4pxZ-48ES4lfI4gCLiZVgM4gk |
3600 |
| TXT | MS=414A20A34D923FA816892A92BE284057918DB43E |
3600 |
| TXT | google-site-verification=M3Wl9ybPu861fWigQkWKurVdAMXtztKuwF5Txeh53Jg |
3600 |
| TXT | google-site-verification=fj36aAnfUreVGk-rhCteMWjG-Pd90NcgYngeGdlqS_s |
3600 |
| TXT | intacct-esk=93953F1D4A5F8F0BE053AA06A8C0BC4B |
3600 |
| TXT | zapier-domain-verification-challenge=f2d6d111-56d7-4c93-8ffc-2ac7d7cb9a40 |
3600 |
| TXT | apple-domain-verification=PIglY2pnpLjKl2gc |
3600 |
| TXT | google-site-verification=y3r_YcRkh79sTeT4PBKewcnj_2172BCzoN7kHEbPqZU |
3600 |
| TXT | canva-site-verification=beDVUW_zNK3b1jDH4h0Iig |
3600 |
| TXT | atlassian-domain-verification=O7mAxzqn/YuYaGhDjpmhB5bM0GnA626LhU3XLAHyJhXc0H6dTGUOF026R6LK/3w/ |
3600 |
| TXT | v=spf1 include:_spf.google.com include:_spf.salesforce.com include:mktomail.com include:mail.zendesk.com include:_spf.intacct.com ~all |
3600 |
| TXT | stripe-verification=D862CA04F88E53B3CF032CE87E750F113F6E89882435F443703BEF4F222D36F8 |
3600 |
| TXT | docusign=a2644096-6ba4-4102-88b0-80cd0c015208 |
3600 |
| TXT | atlassian-sending-domain-verification=4879176f-e06e-44e4-b000-8f3c8e0215da |
3600 |
| TXT | onetrust-domain-verification=cb6f1419299e4a70bf2d8abe12601eef |
3600 |
| TXT | atlassian-domain-verification=hVmjGas5xRuPw4/P01BBRLYTjeHSSUhDxOMsZmvYZaKWRUnHUyNFvNBIEUkNww7O |
3600 |
🖥 Related IPs (1)
Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.
🌐 Subdomains — local intel (0)
No subdomains of redcanary.com in local intel. Check crt.sh ↗
📡 Reporting Sources (1)
MISP Galaxy Ransomware | Ransomware Actors |
🌐 Same-ASN domains (0)
No ASN linkage in local intel.
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
📁 Case Management
Every panel resolves local-first: threat, category, first-seen & sightings from
indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Audit DNS to build passive history
- Pivot resolved IPs to their dossiers
- Report phishing to registrar/host