Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-03-21

0
Medium
Published: Sat Mar 21 2026 (03/21/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed
Vendor/Project: tlp
Product: clear

Description

Maltrail IOC for 2026-03-21

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 04/08/2026, 04:20:15 UTC

Technical Analysis

The report identifies a malware-related IOC detected by Maltrail on 2026-03-21, sourced from CIRCL OSINT Feed. It is categorized under network activity and external analysis with a medium severity rating. No specific software versions or vulnerabilities are detailed, and no known exploits or patches exist. The IOC is intended for threat intelligence and observation purposes rather than indicating a direct vulnerability or exploit.

Potential Impact

The impact is limited to the detection of potentially malicious network activity associated with malware. There is no indication of a vulnerability or exploit affecting specific products or versions. The medium severity suggests a moderate risk level for network security monitoring but does not imply active exploitation or system compromise.

Mitigation Recommendations

No patch or official remediation is available or required as this is an IOC for monitoring purposes. Security teams should incorporate this IOC into their detection and monitoring tools to identify related malicious activity. No urgent action is mandated by the vendor or source.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
b8ef1b56-3e16-4f06-9c11-d1e0a7586332
Original Timestamp
1774080012

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/bb17ae03e79565a2bd38f301410ccb87c6de5c78
0ktapus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/9a4b811044c06c664f6c5239de239e2b452cef42
apt_kimsuky
urlhttps://x.com/skocherhan/status/2035212493694406693
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/b2906f66cce576d98a881e718d84b08ff400c332
vshell
urlhttps://x.com/smica83/status/2035101635261714558
vshell
urlhttps://www.virustotal.com/gui/file/2f28ee264c23671661f57ab5a0f16941190af60232919dcbdfc9a3bb2669c82d/detection
vshell
urlhttps://www.virustotal.com/gui/file/c42ba1a03d8593f84246e27e1730f8d353d29f1b94738e079fbbf9673319848a/detection
vshell
urlhttps://www.virustotal.com/gui/file/c6c28cd300143b20a0728a96bfc9098749d97871dbe8a85a7a507f97b23cc60c/detection
vshell
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4b2213c6833e2cbcc972a0d886bc25d41788e739
android_bankbot
urlhttps://x.com/KesaGataMe0/status/2034532860066243028
android_bankbot
urlhttps://x.com/nahamike01/status/2035193335141306650
android_bankbot
urlhttps://www.virustotal.com/gui/file/564b381dc3e6fc737fd9b46fb5ee1e06f4e333d2886f0805514af44947a4c271/detection
android_bankbot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/93c7688c5237b41d1a29d99a3c71e6857c1a583a
apt_lazarus

Domain

ValueDescriptionCopy
domainaccount-ndax.com
0ktapus
domainmykkrconnect.com
0ktapus
domainmynikemanager.com
0ktapus
domainndocacverify.dynv6.net
apt_kimsuky
domainndocadcheck.dynv6.net
apt_kimsuky
domainndocaeverify.dynv6.net
apt_kimsuky
domainndocafverify.dynv6.net
apt_kimsuky
domainndocagverify.dynv6.net
apt_kimsuky
domainndocahverify.dynv6.net
apt_kimsuky
domainndocakverify.dynv6.net
apt_kimsuky
domainndocalverify.dynv6.net
apt_kimsuky
domainndocamverify.dynv6.net
apt_kimsuky
domainndocaoverify.dynv6.net
apt_kimsuky
domainndocapverify.dynv6.net
apt_kimsuky
domainndocaqverify.dynv6.net
apt_kimsuky
domainndocarverify.dynv6.net
apt_kimsuky
domainndocasverify.dynv6.net
apt_kimsuky
domainnid.ndocaqverify.dynv6.net
apt_kimsuky
domainkaquanhao.oss-cn-hongkong.aliyuncs.com
vshell
domainandroid-protect.com
android_bankbot
domainapplesecurity.pro
android_bankbot
domaindevicesecurity.pro
android_bankbot
domaininfo-payeasy.com
android_bankbot
domainios-deviceprotect.com
android_bankbot
domainios-inc.app
android_bankbot
domainiosdevicepolicy.app
android_bankbot
domainmodelatelier.club
apt_lazarus

Ip

ValueDescriptionCopy
ip45.78.53.77
vshell
ip161.33.154.144
android_bankbot

Threat ID: 69be5ab7f4197a8e3bb06acb

Added to database: 3/21/2026, 8:45:43 AM

Last enriched: 4/8/2026, 4:20:15 AM

Last updated: 5/7/2026, 5:33:20 AM

Views: 129

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses