mci.ejalase.org
Classification: Malicious
mci.ejalase.org is a malicious hostname. Linked to Backdoordiplomacy activity. Reported by 1 threat source, last seen 2023-01-21.
Current activity
- Offline — no longer resolving. Last online 2025-05-10 08:20:48.
MITRE ATT&CK associations
Intrusion sets: BACKDOORDIPLOMACY (G0135)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Backdoordiplomacy | Maltiverse | 2023-01-20 04:17:13 | 2023-01-21 17:51:48 | malicious-activity | G0135 BackdoorDiplomacy |
Tags
aptIP addresses resolved by this hostname
- 194.225.148.218 (2024-02-08 08:17:59)
- 160.16.200.77 (2025-04-28 12:56:52)
- 72.52.178.23 (2025-05-10 08:20:48)
Whois information
- AS name
- AS34592 Iranian Presidential Administration
- Domain
- ejalase.org
- TLD
- org
- DNSSEC
- ['unsigned']
- Nameservers
- ns11.value-domain.com, ns12.value-domain.com, ns13.value-domain.com
- Registrant
- GMO Internet Group, Inc. d/b/a Onamae.com
- Address
- REDACTED FOR PRIVACY
- City
- REDACTED FOR PRIVACY
- State
- Osaka
- Country
- JP — Japan 🇯🇵
- Contact email
- [email protected]
- Domain created
- 2024-03-29 07:38:34
- Domain expires
- 2026-03-29 07:38:34
- First indexed
- 2023-01-21 17:51:48
- Last updated
- 2026-07-12 11:56:21