Disposable Domains, Durable Hosting
Over five months, four distinct malicious chains operated through the same bulletproof hosting provider, AS202412 registered to OMEGATECH LTD in Seychelles. All chains began with fake CAPTCHA pages (ClickFix technique) that instructed victims to paste commands into Windows Run dialogs. The campaigns used disposable domains with similar naming patterns, compromised legitimate websites, and varied infrastructure including cloud storage, blockchain-resolved C2 addresses, and trojanized installers. Despite different payloads and staging methods, every chain initiated contact through AS202412. The provider expanded from initial allocations to announcing twenty-four /24 prefixes during the observation period. Most browser contacts ended at the lure page without execution, but successful compromises deployed stealers and remote access tools with persistence mechanisms surviving system reboots.
Indicators of Compromise
- ip: 91.92.240.127
- ip: 91.92.243.161
- ip: 178.16.55.232
- ip: 178.16.54.40
- ip: 158.94.208.213
- ip: 158.94.208.104
- ip: 178.16.52.101
- domain: alianzeg.shop
- ip: 178.16.54.253
- ip: 158.94.211.76
- domain: newtdsone.shop
- ip: 130.12.180.174
- domain: ai-nexora.sbs
- ip: 178.16.53.137
- domain: cdn-2faclov.sbs
- domain: lcates-vs.beer
- ip: 130.12.180.63
- domain: capcha-cdn-js.beer
- domain: cdn-plugin-js.beer
- domain: carrotbunnies.com
- hash: d77bc0bb3018b6cc834c1af1eefaa1c0b906314308d6ab88588f8d41eb62090c
- hash: a410c89db9140ed9dff55bff00b0338fbdffcc709490782c7b28e8a10c11eb3b
- domain: sdntds.shop
- domain: nttdss.shop
- domain: dnsnewtds.shop
- domain: ntdnewtds.shop
- domain: mnoskemp.beer
- domain: bnsclod.beer
- domain: clnsdns.beer
- domain: bootstrap-maxcdn.beer
- domain: marketing080company.one
- ip: 158.94.211.92
- ip: 193.202.84.17
- domain: clacndjsvulnarbi.beer
- domain: chekbrow.beer
- domain: biyaconserver.beer
- domain: pilotkadomen.club
- domain: framework-css-styles-js.beer
- domain: idverification-code.beer
- hash: 9a736f4812b485f9cf5b1332a791b205b5135a4b3a0c41f473ad9cc9fbe2d75c
- domain: trunnsns.beer
- domain: codeverificatrorcl.info
- domain: authorization-code.info
- ip: 176.65.144.127
- hash: b42854b7d8f7f27771ef4b97a61c94a1
- hash: 2243b21636f705acc327d26e06ff26bfdf3a6e6d
- domain: auth-code-check.info
- domain: authorization-press-enter.info
- domain: authorization-cdn-press-enter.info
- domain: catholicsma.com
- domain: auth-id-browser.info
- domain: enter-pverif-code.info
- domain: id-verif-code.info
- domain: enter-press-code.info
- domain: approvalrequest-api.com
- domain: cdn.claritydelivr.com
- domain: verico-de-id.beer
- domain: kerosand.net
- ip: 91.92.241.111
- domain: fraudtechnology.com
- domain: rsvpopenh.one
- domain: thegreenfortune.com
- domain: lockpopclickgetfile.monster
- domain: pcapps.my
- domain: gettrack.my
- domain: securecab.fit
- domain: uruvita.com
- hash: b004acacd8ef5d7e8a2fd99a7931af0ced87b280d5acd2fde499da4a8f24e916
- hash: 81ecbf004dc9dbf8ea4c50bde1ed55806fb5fdf689d165856112ea9f4d5021e0
- hash: 07efd816a182a5f8e3533b5479126b67
- hash: 154c3aac0d5c91e18fce029a12fb5750
- hash: 0aca41982db2140f9b4bf8a6fcfe3949856642fe
- hash: bf0fcb2034fc7384cf1a295c5bda00dcc13b8a24
- url: http://approvalrequest-api.com
Disposable Domains, Durable Hosting
Description
Over five months, four distinct malicious chains operated through the same bulletproof hosting provider, AS202412 registered to OMEGATECH LTD in Seychelles. All chains began with fake CAPTCHA pages (ClickFix technique) that instructed victims to paste commands into Windows Run dialogs. The campaigns used disposable domains with similar naming patterns, compromised legitimate websites, and varied infrastructure including cloud storage, blockchain-resolved C2 addresses, and trojanized installers. Despite different payloads and staging methods, every chain initiated contact through AS202412. The provider expanded from initial allocations to announcing twenty-four /24 prefixes during the observation period. Most browser contacts ended at the lure page without execution, but successful compromises deployed stealers and remote access tools with persistence mechanisms surviving system reboots.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://activesoc.blackhillsinfosec.com/blog/disposable-domains-durable-hosting"]
- Pulse Id
- 6ab3c34aada48d498bcb50af
Indicators of Compromise
Ip
| Value | Description | Copy |
|---|---|---|
ip91.92.240.127 | — | |
ip91.92.243.161 | — | |
ip178.16.55.232 | — | |
ip178.16.54.40 | — | |
ip158.94.208.213 | — | |
ip158.94.208.104 | — | |
ip178.16.52.101 | — | |
ip178.16.54.253 | — | |
ip158.94.211.76 | — | |
ip130.12.180.174 | — | |
ip178.16.53.137 | — | |
ip130.12.180.63 | — | |
ip158.94.211.92 | — | |
ip193.202.84.17 | — | |
ip176.65.144.127 | — | |
ip91.92.241.111 | — |
Domain
| Value | Description | Copy |
|---|---|---|
domainalianzeg.shop | — | |
domainnewtdsone.shop | — | |
domainai-nexora.sbs | — | |
domaincdn-2faclov.sbs | — | |
domainlcates-vs.beer | — | |
domaincapcha-cdn-js.beer | — | |
domaincdn-plugin-js.beer | — | |
domaincarrotbunnies.com | — | |
domainsdntds.shop | — | |
domainnttdss.shop | — | |
domaindnsnewtds.shop | — | |
domainntdnewtds.shop | — | |
domainmnoskemp.beer | — | |
domainbnsclod.beer | — | |
domainclnsdns.beer | — | |
domainbootstrap-maxcdn.beer | — | |
domainmarketing080company.one | — | |
domainclacndjsvulnarbi.beer | — | |
domainchekbrow.beer | — | |
domainbiyaconserver.beer | — | |
domainpilotkadomen.club | — | |
domainframework-css-styles-js.beer | — | |
domainidverification-code.beer | — | |
domaintrunnsns.beer | — | |
domaincodeverificatrorcl.info | — | |
domainauthorization-code.info | — | |
domainauth-code-check.info | — | |
domainauthorization-press-enter.info | — | |
domainauthorization-cdn-press-enter.info | — | |
domaincatholicsma.com | — | |
domainauth-id-browser.info | — | |
domainenter-pverif-code.info | — | |
domainid-verif-code.info | — | |
domainenter-press-code.info | — | |
domainapprovalrequest-api.com | — | |
domaincdn.claritydelivr.com | — | |
domainverico-de-id.beer | — | |
domainkerosand.net | — | |
domainfraudtechnology.com | — | |
domainrsvpopenh.one | — | |
domainthegreenfortune.com | — | |
domainlockpopclickgetfile.monster | — | |
domainpcapps.my | — | |
domaingettrack.my | — | |
domainsecurecab.fit | — | |
domainuruvita.com | — |
Hash
| Value | Description | Copy |
|---|---|---|
hashd77bc0bb3018b6cc834c1af1eefaa1c0b906314308d6ab88588f8d41eb62090c | — | |
hasha410c89db9140ed9dff55bff00b0338fbdffcc709490782c7b28e8a10c11eb3b | — | |
hash9a736f4812b485f9cf5b1332a791b205b5135a4b3a0c41f473ad9cc9fbe2d75c | — | |
hashb42854b7d8f7f27771ef4b97a61c94a1 | — | |
hash2243b21636f705acc327d26e06ff26bfdf3a6e6d | — | |
hashb004acacd8ef5d7e8a2fd99a7931af0ced87b280d5acd2fde499da4a8f24e916 | — | |
hash81ecbf004dc9dbf8ea4c50bde1ed55806fb5fdf689d165856112ea9f4d5021e0 | — | |
hash07efd816a182a5f8e3533b5479126b67 | — | |
hash154c3aac0d5c91e18fce029a12fb5750 | — | |
hash0aca41982db2140f9b4bf8a6fcfe3949856642fe | — | |
hashbf0fcb2034fc7384cf1a295c5bda00dcc13b8a24 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://approvalrequest-api.com | — |
Threat ID: 6ab3d886f7a7c54106da30b3
Added to database: 09/23/2026, 13:47:50 UTC
Last updated: 09/23/2026, 13:47:50 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.