URL / Domain Profile

🌐 https://securelist.com/bad-rabbit-ransomware/82851/

URL · host securelist.com · threat 0.50 (HIGH) · ATT&CK
First seen 2026-08-06 13:09:17 · last seen 2026-08-06 14:48:30
🔄 Pivot:📁 ATT&CK

Threat score

0.50
MEDIUM

Sightings

7
5 sources

Subdomains (local)

0
from indicators

Related IPs

1
A/AAAA records

DNS records (local)

8
4 types

Reporting sources

5
0 enrichments

📡 Reporting-source breakdown

Framework
1
ICS ATT&CK
1
Ransomware Actors
1
ATT&CK
1
ATT&CK Actors
1
5 total source links on this indicator.

🏷 Tag breakdown (domain family)

medium-severity
1
url
1
auto-tagged
1

📈 DNS record-type counts

TXT
4
NS
2
SOA
1
A
1

📅 First-seen timeline (family)

2026-08
1

🏷 WHOIS / Registration (local cache)

No cached WHOIS for securelist.com. Resolve & cache.

🏷 Tags

url medium-severity auto-tagged
CategoryATT&CK
SeverityMEDIUM

📡 DNS Records

Stored (local dns_records) — 8

TypeValueTTLChecked
A 82.202.190.93 243 2026-08-06
NS ns2.yandexcloud.net 3600 2026-08-06
NS ns1.yandexcloud.net 3600 2026-08-06
SOA ns1.yandexcloud.net 3600 2026-08-06
TXT _w0ca9l3o36sq5mkm3ult8qeylp4j0si 2899 2026-08-06
TXT r309w15sl4tw74r5ztxbx3r3rkfy2bqm 2899 2026-08-06
TXT v=spf1 redirect=kaspersky.com 2899 2026-08-06
TXT _q0wncgv3se5piqrgn4h0ze10mu43g0b 2899 2026-08-06

Live (DNS-over-HTTPS · optional augmentation)

TypeValueTTL
A 82.202.190.93 78
NS ns2.yandexcloud.net. 3600
NS ns1.yandexcloud.net. 3600
TXT _w0ca9l3o36sq5mkm3ult8qeylp4j0si 3600
TXT _q0wncgv3se5piqrgn4h0ze10mu43g0b 3600
TXT v=spf1 redirect=kaspersky.com 3600
TXT r309w15sl4tw74r5ztxbx3r3rkfy2bqm 3600

🖥 Related IPs (1)

Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.

82.202.190.93

🌐 Subdomains — local intel (0)

No subdomains of securelist.com in local intel. Check crt.sh ↗

📡 Reporting Sources (5)

MITRE ATT&CK EnterpriseATT&CK
MITRE ATT&CK ICSICS ATT&CK
MITRE ATT&CK Groups (STIX)ATT&CK Actors
MISP Galaxy RansomwareRansomware Actors
MITRE ATT&CK (STIX)Framework

🌐 Same-ASN domains (0)

No ASN linkage in local intel.

Every panel resolves local-first: threat, category, first-seen & sightings from indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php

🔗 Related Tools