1. Seems like all the registrations are made from AS45727 (PT Hutchison CP Telecommunications), - if
- Seems like all the registrations are made from AS45727 (PT Hutchison CP Telecommunications), - if you're not otherwise seeing legitimate traffic from that ISP, you could filter on the AS number.
- A quick glance makes all the IP addresses appear to be from Indonesia, if you're not otherwise seeing (or expecting) legitimate traffic from Indonesia, you could filter traffic from Indonesia away.
- Searching
"fextemp.com"(including the quotes), on Google, leads to various sites confirming as you say, that they (@fextemp.com) are disposable emails.
One result that search is bringing, would be https://github.com/MISP/misp-warninglists/blob/main/lists/disposable-email/list.json, which seem to contain a few thousand domains, that are apparently disposable email address domains.
