ybupdate.me
Classification: Malicious
ybupdate.me is a malicious hostname. Linked to Apt27 activity. Reported by 2 threat sources, last seen 2023-11-19.
Current activity
- Offline — no longer resolving. Last online 2025-11-29 16:08:53.
MITRE ATT&CK associations
Intrusion sets: APT27 (G0027)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Malicious URL | Hybrid-Analysis | 2023-11-19 11:00:04 | 2023-11-19 11:00:04 | ||
| Emissary Panda | Maltiverse | 2023-03-02 04:14:48 | 2023-03-03 14:23:03 | malicious-activity | G0027 APT27 |
| APT27 | Maltiverse | 2023-03-03 14:06:50 | 2023-03-03 14:06:50 | G0027 Threat Group-3390 G0027 Threat Group-3390 |
Tags
apt apt27 emissary pandaIP addresses resolved by this hostname
- 15.197.212.58 (2024-05-14 00:31:18)
- 15.197.172.60 (2024-04-18 04:27:21)
- 103.79.79.55 (2024-04-03 00:23:28)
- 160.16.200.77 (2025-10-20 20:09:14)
- 54.65.172.3 (2025-11-28 12:02:44)
- 52.25.92.0 (2025-11-29 16:08:53)
Whois information
- AS name
- AS8100 QuadraNet, Inc
- Domain
- ybupdate.me
- TLD
- me
- Registrant
- GMO Internet, Inc.
- City
- REDACTED, Kita-ku Osaka-shi
- Domain created
- 2024-10-20 01:18:35
- Domain expires
- 2025-10-20 01:18:35
- First indexed
- 2023-03-03 14:06:50
- Last updated
- 2025-12-16 22:55:56