s3.kefel.tech
Classification: Malicious
s3.kefel.tech is a malicious hostname. Linked to Spica malware. Reported by 1 threat source, last seen 2025-07-26.
Current activity
- Offline — no longer resolving. Last online 2025-07-26 06:17:57.
MITRE ATT&CK associations
Malware families: SPICA (S1140)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| SPICA | ThreatFox Abuse.ch | 2025-07-24 06:28:41 | 2025-07-26 06:17:57 | malicious-activity | S1140 Spica |
Tags
apk apt c2 cryptoscam exe fakecryptodashboard fast-flux nodejs pq-hosting russianapt sslreuseIP addresses resolved by this hostname
- 185.234.247.27 (2025-07-24 07:17:13)
- 185.234.247.29 (2025-07-24 07:17:13)
- 185.234.247.19 (2025-07-24 07:17:13)
- 185.234.247.20 (2025-07-24 07:17:13)
- 185.234.247.25 (2025-07-24 07:17:13)
- 185.234.247.22 (2025-07-24 07:17:13)
Whois information
- Domain
- kefel.tech
- TLD
- tech
- DNSSEC
- ['unsigned']
- Nameservers
- NS1.REG.RU, NS2.REG.RU, ns1.reg.ru, ns2.reg.ru
- Registrant
- Registrar of Domain Names REG.RU LLC
- Address
- Personal data, can not be publicly disclosed according to applicable laws.
- City
- Personal data, can not be publicly disclosed according to applicable laws.
- State
- Moscow
- Contact email
- [email protected], [email protected]
- Domain created
- 2023-01-27 17:35:23
- Domain expires
- 2026-01-27 23:59:59
- First indexed
- 2025-07-24 07:17:11
- Last updated
- 2025-07-26 06:17:58