🌐 https://securelist.com/sodin-ransomware/91473/
URL
· host
securelist.com
· threat 0.50 (HIGH)
· ATT&CK First seen 2026-08-06 13:09:17 · last seen 2026-08-06 14:48:30
🔄 Pivot:📁 ATT&CK
Threat score
0.50
MEDIUM
Sightings
7
5 sources
Subdomains (local)
1
from indicators
Related IPs
1
A/AAAA records
DNS records (local)
8
4 types
Reporting sources
5
0 enrichments
📡 Reporting-source breakdown
1
1
1
1
1
5 total source links on this indicator.
🏷 Tag breakdown (domain family)
No data.
📈 DNS record-type counts
4
2
1
1
📅 First-seen timeline (family)
2
🏷 WHOIS / Registration (local cache)
No cached WHOIS for securelist.com. Resolve & cache.
📡 DNS Records
Stored (local dns_records) — 8
| Type | Value | TTL | Checked |
|---|---|---|---|
| A | 82.202.190.93 |
68 | 2026-08-06 |
| NS | ns2.yandexcloud.net |
2547 | 2026-08-06 |
| NS | ns1.yandexcloud.net |
2547 | 2026-08-06 |
| SOA | ns1.yandexcloud.net |
3600 | 2026-08-06 |
| TXT | _w0ca9l3o36sq5mkm3ult8qeylp4j0si |
3600 | 2026-08-06 |
| TXT | r309w15sl4tw74r5ztxbx3r3rkfy2bqm |
3600 | 2026-08-06 |
| TXT | v=spf1 redirect=kaspersky.com |
3600 | 2026-08-06 |
| TXT | _q0wncgv3se5piqrgn4h0ze10mu43g0b |
3600 | 2026-08-06 |
Live (DNS-over-HTTPS · optional augmentation)
| Type | Value | TTL |
|---|---|---|
| A | 82.202.190.93 |
78 |
| NS | ns2.yandexcloud.net. |
3600 |
| NS | ns1.yandexcloud.net. |
3600 |
| TXT | _w0ca9l3o36sq5mkm3ult8qeylp4j0si |
3600 |
| TXT | _q0wncgv3se5piqrgn4h0ze10mu43g0b |
3600 |
| TXT | v=spf1 redirect=kaspersky.com |
3600 |
| TXT | r309w15sl4tw74r5ztxbx3r3rkfy2bqm |
3600 |
🖥 Related IPs (1)
Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.
🌐 Subdomains — local intel (1)
Domains/URLs in the local DB ending in .securelist.com (bounded to 200). Each links to its own dossier.
📡 Reporting Sources (5)
MITRE ATT&CK Enterprise | ATT&CK |
MITRE ATT&CK ICS | ICS ATT&CK |
MITRE ATT&CK Groups (STIX) | ATT&CK Actors |
MISP Galaxy Ransomware | Ransomware Actors |
MITRE ATT&CK (STIX) | Framework |
🌐 Same-ASN domains (0)
No ASN linkage in local intel.
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
Every panel resolves local-first: threat, category, first-seen & sightings from
indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Audit DNS to build passive history
- Pivot resolved IPs to their dossiers
- Report phishing to registrar/host