URL / Domain Profile

🌐 malrok.com

DOMAIN · host malrok.com · threat 0.50 (HIGH) · Malware Attribution · INTERNET INVEST, LTD. DBA IMENA.UA
First seen 2026-08-06 13:07:44 · last seen 2026-08-12 00:08:24

Threat score

0.50
MEDIUM

Sightings

7
4 sources

Subdomains (local)

0
from indicators

Related IPs

1
A/AAAA records

DNS records (local)

8
5 types

Reporting sources

4
0 enrichments

📡 Reporting-source breakdown

C2 Attribution
2
Malware Attribution
1
Malware
1
4 total source links on this indicator.

🏷 Tag breakdown (domain family)

auto-tagged
1
medium-severity
1

📈 DNS record-type counts

NS
3
TXT
2
SOA
1
A
1
MX
1

📅 First-seen timeline (family)

2026-08
1

🏷 WHOIS / Registration (local cache)

RegistrarINTERNET INVEST, LTD. DBA IMENA.UA
Registrant OrgWhois privacy protection service
CountryUk
Abuse Emailabuse@imena.ua

🏷 Tags

medium-severity auto-tagged
CategoryMalware Attribution
SeverityMEDIUM

📡 DNS Records

Stored (local dns_records) — 8

TypeValueTTLChecked
A 77.87.193.88 3600 2026-08-15
MX pmx.mirohost.net 3600 2026-08-15
NS ns3.mirohost.net 3600 2026-08-15
NS ns1.mirohost.net 3600 2026-08-15
NS ns2.mirohost.net 3600 2026-08-15
SOA ns1.mirohost.net 3600 2026-08-15
TXT v=spf1 +a +mx ip4:78.27.225.0/24 ~all 3600 2026-08-15
TXT google-site-verification=1jc6R0Sr1uVXN3pT4rwydneIy2pwRbCZWs8jBzTaiCQ 3600 2026-08-15

Live (DNS-over-HTTPS · optional augmentation)

TypeValueTTL
A 77.87.193.88 3600
MX 10 pmx.mirohost.net. 3600
NS ns3.mirohost.net. 3600
NS ns2.mirohost.net. 3600
NS ns1.mirohost.net. 3600
TXT v=spf1 +a +mx ip4:78.27.225.0/24 ~all 3600
TXT google-site-verification=1jc6R0Sr1uVXN3pT4rwydneIy2pwRbCZWs8jBzTaiCQ 3600

🖥 Related IPs (1)

Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.

77.87.193.88

🌐 Subdomains — local intel (0)

No subdomains of malrok.com in local intel. Check crt.sh ↗

📡 Reporting Sources (4)

ThreatFox RecentMalware Attribution
ThreatView C2 HuntingC2 Attribution
ThreatView C2 Cobalt StrikeC2 Attribution
abuse.ch ThreatFox (CSV)Malware

🌐 Same-ASN domains (0)

No ASN linkage in local intel.

📁 Case Management

+ New case from this
Every panel resolves local-first: threat, category, first-seen & sightings from indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php

🔗 Related Tools