URL / Domain Profile

🌐 https://redcanary.com/blog/grief-ransomware/

URL · host redcanary.com · threat 0.50 (HIGH) · Ransomware Actors
First seen 2026-08-06 13:13:01 · last seen 2026-08-06 13:13:01

Threat score

0.50
MEDIUM

Sightings

1
1 sources

Subdomains (local)

0
from indicators

Related IPs

1
A/AAAA records

DNS records (local)

0
0 types

Reporting sources

1
0 enrichments

📡 Reporting-source breakdown

Ransomware Actors
1
1 total source links on this indicator.

🏷 Tag breakdown (domain family)

medium-severity
1
url
1
auto-tagged
1
ransomware
1

📈 DNS record-type counts

No data.

📅 First-seen timeline (family)

2026-08
1

🏷 WHOIS / Registration (local cache)

No cached WHOIS for redcanary.com. Resolve & cache.

🏷 Tags

ransomware url medium-severity auto-tagged
CategoryRansomware Actors
SeverityMEDIUM

📡 DNS Records

Live (DNS-over-HTTPS · optional augmentation)

TypeValueTTL
A 104.198.136.223 60
MX 20 alt1.aspmx.l.google.com. 3600
MX 50 aspmx3.googlemail.com. 3600
MX 30 alt2.aspmx.l.google.com. 3600
MX 40 aspmx2.googlemail.com. 3600
MX 10 aspmx.l.google.com. 3600
NS ns13.dnsmadeeasy.com. 21600
NS ns15.dnsmadeeasy.com. 21600
NS ns10.dnsmadeeasy.com. 21600
NS ns14.dnsmadeeasy.com. 21600
NS ns12.dnsmadeeasy.com. 21600
NS ns11.dnsmadeeasy.com. 21600
TXT drift-domain-verification=53ce70fc5236b2cee2a61822bf9af35d95ae7c130cf4402e33668d1782218b86 3600
TXT google-site-verification=HV_P9w9Xa7Mo1cUNEzNC0zegEnLij9VHPUdSvm5sK60 3600
TXT 00DU0000000Lyeu=1TBTP00000009Mf 3600
TXT google-site-verification=2bwXDjSmYK1ighcDO_4pxZ-48ES4lfI4gCLiZVgM4gk 3600
TXT MS=414A20A34D923FA816892A92BE284057918DB43E 3600
TXT google-site-verification=M3Wl9ybPu861fWigQkWKurVdAMXtztKuwF5Txeh53Jg 3600
TXT google-site-verification=fj36aAnfUreVGk-rhCteMWjG-Pd90NcgYngeGdlqS_s 3600
TXT intacct-esk=93953F1D4A5F8F0BE053AA06A8C0BC4B 3600
TXT zapier-domain-verification-challenge=f2d6d111-56d7-4c93-8ffc-2ac7d7cb9a40 3600
TXT apple-domain-verification=PIglY2pnpLjKl2gc 3600
TXT google-site-verification=y3r_YcRkh79sTeT4PBKewcnj_2172BCzoN7kHEbPqZU 3600
TXT canva-site-verification=beDVUW_zNK3b1jDH4h0Iig 3600
TXT atlassian-domain-verification=O7mAxzqn/YuYaGhDjpmhB5bM0GnA626LhU3XLAHyJhXc0H6dTGUOF026R6LK/3w/ 3600
TXT v=spf1 include:_spf.google.com include:_spf.salesforce.com include:mktomail.com include:mail.zendesk.com include:_spf.intacct.com ~all 3600
TXT stripe-verification=D862CA04F88E53B3CF032CE87E750F113F6E89882435F443703BEF4F222D36F8 3600
TXT docusign=a2644096-6ba4-4102-88b0-80cd0c015208 3600
TXT atlassian-sending-domain-verification=4879176f-e06e-44e4-b000-8f3c8e0215da 3600
TXT onetrust-domain-verification=cb6f1419299e4a70bf2d8abe12601eef 3600
TXT atlassian-domain-verification=hVmjGas5xRuPw4/P01BBRLYTjeHSSUhDxOMsZmvYZaKWRUnHUyNFvNBIEUkNww7O 3600

🖥 Related IPs (1)

Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.

104.198.136.223

🌐 Subdomains — local intel (0)

No subdomains of redcanary.com in local intel. Check crt.sh ↗

📡 Reporting Sources (1)

MISP Galaxy RansomwareRansomware Actors

🌐 Same-ASN domains (0)

No ASN linkage in local intel.

📁 Case Management

+ New case from this
Every panel resolves local-first: threat, category, first-seen & sightings from indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php

🔗 Related Tools