🌐 https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage
URL
· host
www.security.com
· threat 0.50 (HIGH)
· Threat Reports First seen 2026-08-23 12:47:34 · last seen 2026-08-23 13:09:22
🔄 Pivot:📁 Threat Reports
Threat score
0.50
MEDIUM
Sightings
2
2 sources
Subdomains (local)
0
from indicators
Related IPs
20
A/AAAA records
DNS records (local)
18
5 types
Reporting sources
2
0 enrichments
📡 Reporting-source breakdown
1
1
2 total source links on this indicator.
🏷 Tag breakdown (domain family)
No data.
📈 DNS record-type counts
8
4
4
1
1
📅 First-seen timeline (family)
1
🏷 WHOIS / Registration (local cache)
No cached WHOIS for www.security.com. Resolve & cache.
📡 DNS Records
Stored (local dns_records) — 18
| Type | Value | TTL | Checked |
|---|---|---|---|
| A | 65.8.20.81 |
60 | 2026-08-08 |
| A | 65.8.20.49 |
60 | 2026-08-08 |
| A | 65.8.20.118 |
60 | 2026-08-08 |
| A | 65.8.20.89 |
60 | 2026-08-08 |
| AAAA | 2600:9000:2105:7c00:6:3b97:c640:93a1 |
60 | 2026-08-08 |
| AAAA | 2600:9000:2105:9e00:6:3b97:c640:93a1 |
60 | 2026-08-08 |
| AAAA | 2600:9000:2105:7a00:6:3b97:c640:93a1 |
60 | 2026-08-08 |
| AAAA | 2600:9000:2105:a00:6:3b97:c640:93a1 |
60 | 2026-08-08 |
| AAAA | 2600:9000:2105:3a00:6:3b97:c640:93a1 |
60 | 2026-08-08 |
| AAAA | 2600:9000:2105:d800:6:3b97:c640:93a1 |
60 | 2026-08-08 |
| AAAA | 2600:9000:2105:a000:6:3b97:c640:93a1 |
60 | 2026-08-08 |
| AAAA | 2600:9000:2105:6a00:6:3b97:c640:93a1 |
60 | 2026-08-08 |
| CNAME | d2zt1ux5rj6eqh.cloudfront.net |
300 | 2026-08-08 |
| NS | ns-1889.awsdns-44.co.uk |
1831 | 2026-08-08 |
| NS | ns-741.awsdns-28.net |
1831 | 2026-08-08 |
| NS | ns-113.awsdns-14.com |
1831 | 2026-08-08 |
| NS | ns-1483.awsdns-57.org |
1831 | 2026-08-08 |
| SOA | ns-1483.awsdns-57.org |
60 | 2026-08-08 |
Live (DNS-over-HTTPS · optional augmentation)
| Type | Value | TTL |
|---|---|---|
| A | d2zt1ux5rj6eqh.cloudfront.net. |
300 |
| A | 65.8.20.118 |
60 |
| A | 65.8.20.49 |
60 |
| A | 65.8.20.89 |
60 |
| A | 65.8.20.81 |
60 |
| AAAA | d2zt1ux5rj6eqh.cloudfront.net. |
300 |
| AAAA | 2600:9000:2105:be00:6:3b97:c640:93a1 |
60 |
| AAAA | 2600:9000:2105:5800:6:3b97:c640:93a1 |
60 |
| AAAA | 2600:9000:2105:6200:6:3b97:c640:93a1 |
60 |
| AAAA | 2600:9000:2105:6800:6:3b97:c640:93a1 |
60 |
| AAAA | 2600:9000:2105:3800:6:3b97:c640:93a1 |
60 |
| AAAA | 2600:9000:2105:e400:6:3b97:c640:93a1 |
60 |
| AAAA | 2600:9000:2105:c00:6:3b97:c640:93a1 |
60 |
| AAAA | 2600:9000:2105:1c00:6:3b97:c640:93a1 |
60 |
| MX | d2zt1ux5rj6eqh.cloudfront.net. |
300 |
| NS | d2zt1ux5rj6eqh.cloudfront.net. |
35 |
| NS | ns-1483.awsdns-57.org. |
21600 |
| NS | ns-1889.awsdns-44.co.uk. |
21600 |
| NS | ns-113.awsdns-14.com. |
21600 |
| NS | ns-741.awsdns-28.net. |
21600 |
| TXT | d2zt1ux5rj6eqh.cloudfront.net. |
300 |
| CNAME | d2zt1ux5rj6eqh.cloudfront.net. |
300 |
🖥 Related IPs (20)
Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.
65.8.20.81 →
65.8.20.49 →
65.8.20.118 →
65.8.20.89 →
2600:9000:2105:7c00:6:3b97:c640:93a1 →
2600:9000:2105:9e00:6:3b97:c640:93a1 →
2600:9000:2105:7a00:6:3b97:c640:93a1 →
2600:9000:2105:a00:6:3b97:c640:93a1 →
2600:9000:2105:3a00:6:3b97:c640:93a1 →
2600:9000:2105:d800:6:3b97:c640:93a1 →
2600:9000:2105:a000:6:3b97:c640:93a1 →
2600:9000:2105:6a00:6:3b97:c640:93a1 →
2600:9000:2105:be00:6:3b97:c640:93a1 →
2600:9000:2105:5800:6:3b97:c640:93a1 →
2600:9000:2105:6200:6:3b97:c640:93a1 →
2600:9000:2105:6800:6:3b97:c640:93a1 →
2600:9000:2105:3800:6:3b97:c640:93a1 →
2600:9000:2105:e400:6:3b97:c640:93a1 →
2600:9000:2105:c00:6:3b97:c640:93a1 →
2600:9000:2105:1c00:6:3b97:c640:93a1 →
🌐 Subdomains — local intel (0)
No subdomains of www.security.com in local intel. Check crt.sh ↗
📡 Reporting Sources (2)
ORKL Threat Reports API | Threat Reports |
MISP Galaxy Threat Actors | Threat Actors |
🌐 Same-ASN domains (0)
No ASN linkage in local intel.
🔍 OSINT pivots — external lookups
🔗 Internal pivots & actions
📁 Case Management
Every panel resolves local-first: threat, category, first-seen & sightings from
indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Audit DNS to build passive history
- Pivot resolved IPs to their dossiers
- Report phishing to registrar/host