IOC Radar
DomainHighVerifiedSignal 86/100

s-h.4-.sakura

First Seen
Jun 5, 2026
Last Seen
Jul 1, 2026
Jun 5
First Seen
25d ago
Jul 1
Last Seen
today
351
Reports
source reports
95%
Confidence
high
Found in 351 reports. Confidence: high. · Confidence scores are heuristic. Verify before acting on results.
Domain Name
Malicious domain used for C2, phishing, or malware distribution.
MISP Category
Network Activity
Confidence
95%
Signal Score
86 / 100
IDS Rule
Yes

Feed Intelligence Summary

351 reports95% confidence
AU
Abuse.ch URLhaus
4936 IOCs in report
AU
Abuse.ch URLhaus
4935 IOCs in report
AU
Abuse.ch URLhaus
4935 IOCs in report
AU
Abuse.ch URLhaus
4935 IOCs in report
AU
Abuse.ch URLhaus
4934 IOCs in report
AU
Abuse.ch URLhaus
4935 IOCs in report
AU
Abuse.ch URLhaus
4935 IOCs in report
AU
Abuse.ch URLhaus
4934 IOCs in report
AU
Abuse.ch URLhaus
4936 IOCs in report
AU
Abuse.ch URLhaus
4959 IOCs in report

Activity Timeline

351 total obs
Jul 1Jun 5

Threat Activity Heatmap

· Peak: 2026-06-08
Less
More
Mon
Wed
Fri
Jun
Jul
·
·
·
Aug
·
·
·
Sep
·
·
·
·
Oct
·
·
·
Nov
·
·
·
Dec
·
·
·
·
Jan
·
·
·
Feb
·
·
·
Mar
·
·
·
·
Apr
·
·
·
May
·
·
·
Jun
·
·
·
24h
9
Elevated
7d
101
Critical
30d
351
Critical
3mo
351
Critical
Threat ScoreHigh Risk
86
SIGNAL
Signal Score
95%
Confidence
351
Reports
First seenJun 5, 2026
Last seenJul 1, 2026
Verified IOC

VirusTotal

Not checked

Export & API

STIX 2.1 Bundle
CSV Export
Permalink

IOC Journey

high
First detected 25 days ago · Last seen today
Appeared in 351 threat reports from 10 sources
Associated with: APT10, Kimsuky, Turla, Play, Sandworm
Used by malware: AsyncRAT, XMRig, NjRAT, FormBook, Frp, AgentTesla, Nanocore, XWorm, Nmap, Mozi, Aurora, Cobalt Strike, QuasarRAT, Sliver, Stealc, Mirai, Vidar, Fscan, META Stealer, Gh0st RAT, Play, Metasploit