URL / Domain Profile

🌐 https://thecyberexpress.com/cyberattacks-on-jordan/

URL · host thecyberexpress.com · threat 0.50 (HIGH) · Threat Actors
First seen 2026-08-06 13:13:00 · last seen 2026-08-06 14:45:34

Threat score

0.50
MEDIUM

Sightings

2
1 sources

Subdomains (local)

0
from indicators

Related IPs

6
A/AAAA records

DNS records (local)

0
0 types

Reporting sources

1
0 enrichments

📡 Reporting-source breakdown

Threat Actors
1
1 total source links on this indicator.

🏷 Tag breakdown (domain family)

auto-tagged
1
medium-severity
1
url
1

📈 DNS record-type counts

No data.

📅 First-seen timeline (family)

2026-08
1

🏷 WHOIS / Registration (local cache)

No cached WHOIS for thecyberexpress.com. Resolve & cache.

🏷 Tags

url medium-severity auto-tagged
CategoryThreat Actors
SeverityMEDIUM

📡 DNS Records

Live (DNS-over-HTTPS · optional augmentation)

TypeValueTTL
A 104.26.1.138 300
A 172.67.73.48 300
A 104.26.0.138 300
AAAA 2606:4700:20::681a:8a 300
AAAA 2606:4700:20::681a:18a 300
AAAA 2606:4700:20::ac43:4930 300
MX 10 usb-smtp-inbound-1.mimecast.com. 1800
MX 20 thecyberexpress-com.mail.protection.outlook.com. 1800
MX 10 usb-smtp-inbound-2.mimecast.com. 1800
NS sydney.ns.cloudflare.com. 21600
NS eric.ns.cloudflare.com. 21600
TXT MS=ms18651503 300
TXT MS=ms56871555 300
TXT v=spf1 include:usb._netblocks.mimecast.com include:secureserver.net include:spf.protection.outlook.com include:zcsend.net include:21289959.spf05.hubspotemail.net ~all 300
TXT 0ed1fe018ac85589e08ab34e7999a27a66ba4dd4bf 300

🖥 Related IPs (6)

Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.

104.26.1.138 172.67.73.48 104.26.0.138 2606:4700:20::681a:8a 2606:4700:20::681a:18a 2606:4700:20::ac43:4930

🌐 Subdomains — local intel (0)

No subdomains of thecyberexpress.com in local intel. Check crt.sh ↗

📡 Reporting Sources (1)

MISP Galaxy Threat ActorsThreat Actors

🌐 Same-ASN domains (0)

No ASN linkage in local intel.

📁 Case Management

+ New case from this
Every panel resolves local-first: threat, category, first-seen & sightings from indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php

🔗 Related Tools