🌐 https://threatpost.com/linux-variant-ransomware-vmwares-nas/167511/
URL
· host
threatpost.com
· threat 0.50 (HIGH)
· Ransomware Actors · Regional Network Information Center, JSC dba RU-CENTER First seen 2026-08-06 13:13:01 · last seen 2026-08-06 13:13:01
🔄 Pivot:📁 Ransomware Actors
Threat score
0.50
MEDIUM
Sightings
1
1 sources
Subdomains (local)
0
from indicators
Related IPs
1
A/AAAA records
DNS records (local)
13
5 types
Reporting sources
1
0 enrichments
📡 Reporting-source breakdown
1
1 total source links on this indicator.
🏷 Tag breakdown (domain family)
1
1
1
1
📈 DNS record-type counts
8
2
1
1
1
📅 First-seen timeline (family)
1
🏷 WHOIS / Registration (local cache)
| Registrar | Regional Network Information Center, JSC dba RU-CENTER |
| Registrant Org | JS "LABORATORIIA KASPERSKOGO" |
| Country | RU |
| Abuse Email | tld-abuse@nic.ru |
📡 DNS Records
Stored (local dns_records) — 13
| Type | Value | TTL | Checked |
|---|---|---|---|
| A | 82.202.190.241 |
152 | 2026-09-04 |
| MX | threatpost-com.mail.protection.outlook.com |
3600 | 2026-09-04 |
| NS | ns1.yandexcloud.net |
2646 | 2026-09-04 |
| NS | ns2.yandexcloud.net |
2646 | 2026-09-04 |
| SOA | ns1.yandexcloud.net |
3600 | 2026-09-04 |
| TXT | google-site-verification=IAC53QOVd-CRvhQSmvtMwg2rfhe3Ku8AcQW-_TUue5U |
3600 | 2026-09-04 |
| TXT | MS=ms46391769 |
3600 | 2026-09-04 |
| TXT | y7ksf87msb7d4tbrkncvg7c1v09s5mqq |
3600 | 2026-09-04 |
| TXT | vwy3przbhtm2gg0ybwdcs5j2lx3cy1tv |
3600 | 2026-09-04 |
| TXT | v=spf1 include:spf.protection.outlook.com -all,3600 |
3600 | 2026-09-04 |
| TXT | yandex-verification: d2cfa297d6302d69 |
3600 | 2026-09-04 |
| TXT | _txtgz6goyzdtxawkcq5is98p30s2z88 |
3600 | 2026-09-04 |
| TXT | mailru-verification: 37d00c741a9b052a |
3600 | 2026-09-04 |
Live (DNS-over-HTTPS · optional augmentation)
| Type | Value | TTL |
|---|---|---|
| A | 82.202.190.241 |
174 |
| MX | 0 threatpost-com.mail.protection.outlook.com. |
3600 |
| NS | ns1.yandexcloud.net. |
3600 |
| NS | ns2.yandexcloud.net. |
3600 |
| TXT | vwy3przbhtm2gg0ybwdcs5j2lx3cy1tv |
3600 |
| TXT | MS=ms46391769 |
3600 |
| TXT | yandex-verification: d2cfa297d6302d69 |
3600 |
| TXT | google-site-verification=IAC53QOVd-CRvhQSmvtMwg2rfhe3Ku8AcQW-_TUue5U |
3600 |
| TXT | v=spf1 include:spf.protection.outlook.com -all,3600 |
3600 |
| TXT | y7ksf87msb7d4tbrkncvg7c1v09s5mqq |
3600 |
| TXT | mailru-verification: 37d00c741a9b052a |
3600 |
| TXT | _txtgz6goyzdtxawkcq5is98p30s2z88 |
3600 |
🖥 Related IPs (1)
Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.
🌐 Subdomains — local intel (0)
No subdomains of threatpost.com in local intel. Check crt.sh ↗
📡 Reporting Sources (1)
MISP Galaxy Ransomware | Ransomware Actors |
🌐 Same-ASN domains (0)
No ASN linkage in local intel.
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
📁 Case Management
Every panel resolves local-first: threat, category, first-seen & sightings from
indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Audit DNS to build passive history
- Pivot resolved IPs to their dossiers
- Report phishing to registrar/host