Indicator of Compromise Search
Bulk Lookup
✦ IPv4 Address ✦ Domain ✦ MD5/SHA1/SHA256 Hash ✦ URL
INDICATOR
busbytesadd.christmas
Domain ⚠ 9 PULSE HITS
↓ CSV ↓ JSON
55
/100
HIGH
CONFIDENCE LEVEL
THREAT CONFIDENCE ANALYSIS
HIGH 55/100 confidence
Strong evidence of malicious activity across multiple sources. Prioritise investigation.
CLEAN LOW MED HIGH CRIT
0 25 50 75 100
OTX
20/30
9 pulses
VIRUSTOTAL
25/35
14/91 detected
ABUSEIPDB
/25
IPv4 only
URLHAUS
10/10
LISTED
General Information
Indicatorbusbytesadd.christmas
Whois Domainhttp://whois.domaintools.com/busbytesadd.christmas
Typedomain
AlienVault OTX Analysis ↗ View on OTX
9
PULSE HITS
Pulse Hits 9
Indicator Type Domain
Threat Level
ASSOCIATED PULSES
PULSE NAMEDATE
Payload_Delivery | May 28, 2026 2026-05-27
Payload_Delivery | May 27, 2026 2026-05-26
Payload_Delivery | May 26, 2026 2026-05-25
Malware_Distribution | May 24, 2026 2026-05-23
Malware_Distribution | May 23, 2026 2026-05-22
VirusTotal Analysis ↗ View on VirusTotal
14/91
DETECTIONS
MALICIOUS
Malicious 14
Suspicious 3
Harmless 44
Undetected 30
Reputation 0
TOP DETECTIONS
VENDORRESULT
ADMINUSLabs malicious
BitDefender malware
CRDF malicious
Certego suspicious
Chong Lua Dao malicious
ESET malware
Forcepoint ThreatSeeker malicious
Fortinet malware
G-Data malware
Gridinsoft suspicious
URLhaus (abuse.ch) ↗ View on URLhaus
⚠ LISTED
URLHAUS
URLs Found 1
ASSOCIATED URLs
URL STATUS / TYPE DATE
https://busbytesadd.christmas/6464871c-26f3-41a... offline 2026-05-21