URL / Domain Profile

🌐 static.topxgun.com

DOMAIN · host static.topxgun.com · threat 0.50 (HIGH) · Ransomware
First seen 2026-08-06 13:10:23 · last seen 2026-08-24 01:43:14
🔄 Pivot:📁 Ransomware

Threat score

0.50
MEDIUM

Sightings

3
1 sources

Subdomains (local)

0
from indicators

Related IPs

5
A/AAAA records

DNS records (local)

0
0 types

Reporting sources

1
1 enrichments

📡 Reporting-source breakdown

Ransomware
1
1 total source links on this indicator.

🏷 Tag breakdown (domain family)

medium-severity
1
ransomware
1
auto-tagged
1

📈 DNS record-type counts

No data.

📅 First-seen timeline (family)

2026-08
1

🏷 WHOIS / Registration (local cache)

No cached WHOIS for static.topxgun.com. Resolve & cache.

🏷 Tags

ransomware medium-severity auto-tagged
CategoryRansomware
SeverityMEDIUM

📡 DNS Records

Live (DNS-over-HTTPS · optional augmentation)

TypeValueTTL
A iduwtbm.qiniudns.com. 3600
A allcdn.china.qiniu.qnydns.com. 300
A allcdn.lv2.qnydns.com. 600
A 183.60.150.16 139
A 122.228.207.51 139
AAAA iduwtbm.qiniudns.com. 3600
AAAA allcdn.china.qiniu.qnydns.com. 300
AAAA allcdn.lv2.qnydns.com. 600
AAAA 240e:f7:c000:317::13 139
AAAA 240e:974:eb00:110c::105 139
AAAA 240e:97d:10:1401::40f 139
MX iduwtbm.qiniudns.com. 385
MX allcdn.china.qiniu.qnydns.com. 300
MX allcdn.lv2.qnydns.com. 600
NS iduwtbm.qiniudns.com. 3600
NS allcdn.china.qiniu.qnydns.com. 300
NS allcdn.lv2.qnydns.com. 600
TXT iduwtbm.qiniudns.com. 3599
TXT allcdn.china.qiniu.qnydns.com. 299
TXT allcdn.lv2.qnydns.com. 599
CNAME iduwtbm.qiniudns.com. 3600

🖥 Related IPs (5)

Resolved from local A/AAAA records (augmented with live DoH when reachable). Each pivots to its IP dossier.

183.60.150.16 122.228.207.51 240e:f7:c000:317::13 240e:974:eb00:110c::105 240e:97d:10:1401::40f

🌐 Subdomains — local intel (0)

No subdomains of static.topxgun.com in local intel. Check crt.sh ↗

📡 Reporting Sources (1)

Ransomware Abuse DomainsRansomware

🌐 Same-ASN domains (0)

No ASN linkage in local intel.

🧩 Enrichment Data (1 records)

classification 6d ago
{
    "ioc_type": "other",
    "category": "Ransomware",
    "threat_score": 0.5
}

📁 Case Management

+ New case from this
Every panel resolves local-first: threat, category, first-seen & sightings from indicators; DNS from dns_records; WHOIS from whois_cache; subdomains via bounded suffix match on indicators; related IPs from A/AAAA records; tags, reporting sources and the link graph from the local relations. Live OTX pulses and DNS-over-HTTPS are optional augmentation and their absence never blanks the dossier.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php

🔗 Related Tools