Maltrail IOC for 2026-03-22
Maltrail IOC for 2026-03-22
AI Analysis
Technical Summary
This threat report details a Maltrail IOC dated March 22, 2026, classified as malware with medium severity. Maltrail is a network traffic detection system that identifies suspicious or malicious network activity by leveraging various threat intelligence sources. The IOC originates from the CIRCL OSINT Feed, indicating it is derived from open-source intelligence and manually collected data. The report lacks specific affected software versions, detailed technical indicators, or known exploits, which limits the granularity of analysis. No patches or remediation links are available, and no CWE identifiers are associated, suggesting this is an observational report rather than a vulnerability disclosure. The medium severity rating implies the malware or network activity detected may pose a moderate threat to confidentiality, integrity, or availability, but without evidence of active exploitation or widespread impact. The tags indicate this is an unsupervised automated observation, likely generated by automated systems monitoring network traffic for anomalies. The absence of indicators means defenders must rely on external Maltrail feeds and their own network monitoring to detect related activity. Overall, this IOC serves as a warning to maintain vigilance in network traffic analysis and threat intelligence integration.
Potential Impact
The potential impact of this threat is moderate, as indicated by the medium severity rating. Since it is categorized as malware related to network activity, it could lead to unauthorized data exfiltration, disruption of network services, or the establishment of command and control channels if exploited. However, the lack of known exploits in the wild and absence of specific technical details suggest that the immediate risk of widespread compromise is low. Organizations that do not monitor network traffic or integrate threat intelligence feeds like Maltrail may be less prepared to detect such activity, increasing their risk exposure. The impact on confidentiality could involve leakage of sensitive information, while integrity and availability impacts depend on the malware’s capabilities, which remain unspecified. Overall, the threat may cause moderate operational disruption or data loss if not detected and mitigated promptly.
Mitigation Recommendations
1. Integrate Maltrail or similar network traffic analysis tools into your security monitoring infrastructure to detect suspicious network activity. 2. Regularly update and tune network detection signatures and threat intelligence feeds to ensure timely identification of emerging threats. 3. Conduct continuous network traffic analysis focusing on unusual patterns, unexpected external connections, or anomalous data flows. 4. Implement network segmentation and strict access controls to limit the spread and impact of potential malware infections. 5. Establish incident response procedures that include investigation of alerts generated by Maltrail or other network monitoring tools. 6. Train security personnel to interpret OSINT-based threat intelligence and correlate it with internal telemetry for effective detection. 7. Maintain up-to-date asset inventories to quickly identify affected systems if indicators become available. 8. Collaborate with threat intelligence sharing communities to receive timely updates and share observations related to this IOC. These steps go beyond generic advice by emphasizing integration of specific network monitoring tools, tuning of detection capabilities, and active threat intelligence collaboration.
Affected Countries
United States, Germany, France, United Kingdom, Netherlands, Japan, South Korea, Australia, Canada, Switzerland
Indicators of Compromise
- url: https://api.github.com/repos/stamparm/maltrail/commits/b8598ae2a7f48d9dd07deef877b7ba423e52f925
- domain: 1drop.click
- domain: 1drop.digital
- domain: 1drop.life
- domain: freegift-pump.fun
- url: https://api.github.com/repos/stamparm/maltrail/commits/2940351bdcf45ee05c0f1276018d836bc073efa4
- domain: mywayfairconnect.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/cc7fc2a451c0994a0631b0d9ab377251fe8b753d
- domain: smokecar.space
- url: https://api.github.com/repos/stamparm/maltrail/commits/a5f3e76a3047ab073df91e23d07289ff38804523
- domain: exquens.world
- url: https://api.github.com/repos/stamparm/maltrail/commits/c76556b990b985fbae842bffd233c86c7b060759
- url: https://x.com/fbgwls245/status/2035499364895101187
- domain: b4riuxx7ypobdptctf6lyfcvgi6vn74iurzdh4kn2agbk7472dvywgyd.onion
- url: https://api.github.com/repos/stamparm/maltrail/commits/7982abae6217f51b8cb5264ff6b18709cf3e78ea
- domain: menchro.pro
- domain: deoft.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/b2f30daac80ac03f742c9ea32a7e8e150dd53096
- domain: 2vertexdy-namics.pics
- domain: aeronetworkinsight.click
- domain: ageustiaflow.digital
- domain: altaragehub.click
- domain: amadancore.digital
- domain: amarantlayer.click
- domain: anchor36industries.click
- domain: anglepodworks.digital
- domain: annerrestudio.digital
- domain: aphorialayerio.digital
- domain: auditivespaceco.click
- domain: bavaxiiaanalytics.digital
- domain: bazuxuumservices.sbs
- domain: beemanstackio.click
- domain: behedgelayer.click
- domain: berizenisconsultingnet.click
- domain: bertinbase.click
- domain: bibbleworks.click
- domain: biluzoumsystemsltd.digital
- domain: bisedulaisanalyticsinc.digital
- domain: blankestlabsco.click
- domain: borniticstudioio.digital
- domain: botalezidionmanagementco.click
- domain: boycelabs.digital
- domain: bufidixiaventures.click
- domain: bumpkinbase.click
- domain: burstyspace.click
- domain: busujuyubexsolutions.click
- domain: butleryhub.click
- domain: byzantcore.click
- domain: camitezurumresources16.click
- domain: caryocarspace.digital
- domain: cauraleworksco.click
- domain: caxeresibuonresources.click
- domain: chavicingrid.click
- domain: checkerworks.digital
- domain: cibiyeyusmanagement.digital
- domain: claycloud.digital
- domain: codebaseflow.pics
- domain: consentflow.digital
- domain: conusantgrid.digital
- domain: corexspacemesh.click
- domain: coribixabissystems.digital
- domain: crcaospace.click
- domain: creaticworks.digital
- domain: cufimenarumoperationsltd.digital
- domain: cytozymelayerio.digital
- domain: damoberaisindustries36.click
- domain: dankestworks.click
- domain: datafusionstack.digital
- domain: davidistworks.click
- domain: decrescflow.click
- domain: defekusiexanalytics.click
- domain: dendalayer.click
- domain: dentatestudio.digital
- domain: dinerotech.digital
- domain: dispostflowco.click
- domain: dollierstudio.digital
- domain: dopatixiriexanalyticsltd.forum
- domain: dronelflow.digital
- domain: dujamoviaholdings88.click
- domain: dukalemeraadvisoryco.digital
- domain: elev-ate2advisory.click
- domain: epiceletech.digital
- domain: exsertworksio.digital
- domain: fadiyucuhoumholdingsltd.digital
- domain: famelichub.click
- domain: faqageyivexresourcesco.digital
- domain: fevefeummanagement.click
- domain: finowunonadvisory21.click
- domain: flareedgemodule.sbs
- domain: flowoffcore.digital
- domain: focusedgenetwork.digital
- domain: forbathestack.click
- domain: furunclespace.click
- domain: fusesiroyuexsolutions.click
- domain: galleinstack.digital
- domain: gapudacorconsulting.click
- domain: garretflow.click
- domain: geoinvestzone.digital
- domain: geolspace.digital
- domain: gironworks.click
- domain: giuntalayerco.click
- domain: gixiqohutonsolutions.digital
- domain: gluontech.click
- domain: goadlikecore.click
- domain: gojabuexmanagement.digital
- domain: gonorecuismanagementnet.click
- domain: gougercore.digital
- domain: gubedehayeusmanagement.digital
- domain: hainchlayer.click
- domain: halyardlayer.digital
- domain: haperowifaamanagement.digital
- domain: hesperalayer.digital
- domain: hicozucuceiagroup.digital
- domain: hixuvodapiamanagement.digital
- domain: hocegijiispartners.digital
- domain: hodecaiamanagement.digital
- domain: hogiyuqizoumventures.click
- domain: hookletstackco.digital
- domain: horizon365pulse.sbs
- domain: hulloahub.digital
- domain: hupijulexmanagement.digital
- domain: impromptflowio.digital
- domain: incursegrid.click
- domain: infracapital247.com
- domain: inframetrics101.click
- domain: initialflow.digital
- domain: intratespace.digital
- domain: irrateworks.click
- domain: jahvecore.click
- domain: jaleloponmanagement.digital
- domain: japishlayer.digital
- domain: jellifycloud.digital
- domain: jeqatiiaoperations.digital
- domain: jexoziqesoorcapitalltd.click
- domain: jiyegeciscapital.pics
- domain: jododegiiaholdingsco.digital
- domain: judokastudio.digital
- domain: juvituseorinvestments.digital
- domain: kazoceyiapartners.digital
- domain: kineruboormanagement.click
- domain: kohencloud.digital
- domain: kopoluvokiscollective.digital
- domain: kronenhub.digital
- domain: lapidiststack.digital
- domain: lativpartners.click
- domain: lenagutulexadvisory.digital
- domain: lepeqoorinvestments.digital
- domain: lezaponiapartners.click
- domain: licakojuorsolutions.digital
- domain: lichhub.digital
- domain: liftmenlayer.click
- domain: lohosiiscollectiveinc.click
- domain: losezakaloroperationsco.click
- domain: lujulibonholdings64.digital
- domain: lumentrustsmart.click
- domain: luzegaximoexadvisory.click
- domain: macrostudioventures.click
- domain: magosuliexpartners.click
- domain: mansardlabs.digital
- domain: mappistcore.click
- domain: marseflow.digital
- domain: mawuviexcapital.click
- domain: meridian88analytics.digital
- domain: millsitecloud.digital
- domain: minkfishflow.click
- domain: missilecoin.lol
- domain: mitherstudio.digital
- domain: mivoliguloumresources.click
- domain: mobifamihoacollective99.click
- domain: moderaprimeresources.click
- domain: molecasthub.click
- domain: mowburncloud.click
- domain: moxodoboumcapitalinc.click
- domain: muddierspace.digital
- domain: myoedemaworks.click
- domain: myrmecialayer.click
- domain: nacixatizoexholdings.digital
- domain: nejiwoponsolutions.digital
- domain: nereitelabs.digital
- domain: neuralevolvenode.click
- domain: nexum8analytics.click
- domain: noseburnspace.click
- domain: outspellhub.click
- domain: oxhoftlayer.digital
- domain: pandagrid.click
- domain: parhelnmtech.click
- domain: parroketstack.click
- domain: pavannegrid.digital
- domain: paverstack.digital
- domain: pegijuxainvestments.digital
- domain: peqeqejumadvisory.click
- domain: petrelbase.digital
- domain: pewovubadexoperationsltd.click
- domain: pexihefazorindustries.click
- domain: piyotunuaoperations.click
- domain: plannerhub.click
- domain: plungecore.digital
- domain: pohitogusadvisory.digital
- domain: potojoisgroup.click
- domain: primealliance.sbs
- domain: primegammafactory.digital
- domain: pulpalcore.click
- domain: pyranosebase.digital
- domain: qegogonikuapartners21.digital
- domain: qetoxagiacapital.click
- domain: qezegaiaadvisory12.digital
- domain: qijayepexanalyticsnet.click
- domain: qikakowapartners.click
- domain: quaintstudio.digital
- domain: rattailcloud.click
- domain: realtorspace.digital
- domain: recommitflow.digital
- domain: regupagugaexindustries.click
- domain: resecatelabs.digital
- domain: retrainflow.click
- domain: rezemeacapital16.click
- domain: rihigogorgroupinc.click
- domain: rimiformcore.click
- domain: rinolajussolutions.digital
- domain: riretedijeaservicesinc.digital
- domain: riyuhoduzoumsolutions.digital
- domain: rowetstack.click
- domain: ruquxoniaventures.digital
- domain: ruxigefujiumsolutions.click
- domain: sayogibisoperations.digital
- domain: scutcherhub.digital
- domain: senatehub.digital
- domain: sepawnlayer.click
- domain: shadrachcloudio.click
- domain: sintoistbaseio.click
- domain: siwapacajaumcollective16.digital
- domain: skicehub.digital
- domain: snailerylayer.click
- domain: sneerfullayer.click
- domain: specietechco.click
- domain: startorbase.click
- domain: stationcorevertex.digital
- domain: stellardigitalcenter.sbs
- domain: strategymatrix.pics
- domain: sturtitelayer.digital
- domain: suhedahiumholdings64.digital
- domain: suiogothspace.digital
- domain: summitprimepartnersco.digital
- domain: surfmenlayer.digital
- domain: surreallayer.digital
- domain: suxisigiaadvisory8.digital
- domain: sweltrystudio.digital
- domain: symphysyspace.click
- domain: tackercloudio.click
- domain: taperstack.click
- domain: tecalistudio.digital
- domain: technonetcore.sbs
- domain: theismlabs.digital
- domain: tofinuwicexresources.click
- domain: tojasiluscapital.digital
- domain: tournantcloud.click
- domain: trinketsol.lol
- domain: trumptech.click
- domain: tupezuissystems.digital
- domain: turboconsultingspace.digital
- domain: turfieststackco.click
- domain: ugariticcloud.digital
- domain: ungloomycloud.digital
- domain: unich-gateway.click
- domain: unloaderbase.digital
- domain: unlyricstudio.click
- domain: unmounthubio.click
- domain: uptimestudio.digital
- domain: urarticstudio.click
- domain: varasumorindustries.digital
- domain: vayanuummanagementco.click
- domain: venerygrid.digital
- domain: vetelupixaaventures.click
- domain: vetivertlabs.click
- domain: vevorolexiussystemsltd.digital
- domain: vexohejocumservices.click
- domain: visionxanalytics.click
- domain: vomavotunispartnersinc.digital
- domain: vopejiusoperations.click
- domain: vowunokexaisindustries16.digital
- domain: vurohiziexconsulting.digital
- domain: wabaniexinvestments.digital
- domain: wedijucayasolutions88.digital
- domain: wesagoiaresources.click
- domain: wesijezonservices.sbs
- domain: whyostackco.digital
- domain: wirucuronisanalytics.digital
- domain: wispbase.digital
- domain: woleaitech.digital
- domain: workpanlabs.click
- domain: wrestspaceio.digital
- domain: wulderlayer.digital
- domain: xinawezuhausmanagement.click
- domain: yabbletechco.click
- domain: yamogiverumoperations.click
- domain: yearbirdgrid.digital
- domain: yebozuispartnersinc.digital
- domain: yozepeagroup.digital
- domain: yurakhub.click
- domain: zaptiahflowco.click
- domain: zawokoummanagement.click
- domain: zebaxitevuiacapital.digital
- domain: zenithcapital247.sbs
- domain: zizugioncapital.click
- domain: zobohub.click
- domain: zokopifuxiumadvisory.click
- domain: zonupodaanalytics.click
- domain: zovexovuciamanagement8.digital
- url: https://api.github.com/repos/stamparm/maltrail/commits/1636f355b1689c890f0822ba0a5c36dd73633885
- domain: 78-153-140-17.cprapid.com
- domain: acube-contract.com
- domain: interactiveportraits.com
- domain: mymarathilearning.com
- domain: rencaihuainan.com
- domain: syhmen.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/d45289d7a4b010bac00d5ed35ed9b8e9bafcaff8
- domain: 0ak-plate.fileost.in.net
- domain: 0v6nu.tatneft.in.net
- domain: abhd27da.grovopen.in.net
- domain: activegateway.in.net
- domain: analyticalhubnode.in.net
- domain: analyticspipeline.in.net
- domain: analyticspoint.in.net
- domain: analyticsprocessing.in.net
- domain: app2steel.distributedmatrix.in.net
- domain: app3ghost.managementgateway.in.net
- domain: app4view.managementgateway.in.net
- domain: area3field.boundarygateway.in.net
- domain: area4space.boundarygateway.in.net
- domain: astropoint.in.net
- domain: bejont.in.net
- domain: boundarygateway.in.net
- domain: cfg1store.resourcebalancer.in.net
- domain: cfg2remote.resourcebalancer.in.net
- domain: cfg3ghost.interfacehandler.in.net
- domain: clocknet.in.net
- domain: connectivitybuffer.in.net
- domain: connectivitynode.in.net
- domain: coreconnectivity.in.net
- domain: cryptasol.in.net
- domain: cyberneticsystems.in.net
- domain: dark3view.remotediagnostic.in.net
- domain: dc1proc.platformendpoint.in.net
- domain: dc3edge.analyticspoint.in.net
- domain: deepglom.in.net
- domain: diagnosticendpoint.in.net
- domain: diagnosticresource.in.net
- domain: digitalfoundry.in.net
- domain: distributedledger.in.net
- domain: distributedmatrix.in.net
- domain: dynamictelemetry.in.net
- domain: entry2base.digitalfoundry.in.net
- domain: entry2proxy.secureterminal.in.net
- domain: entry4link.metravolta.in.net
- domain: ext1infra.operationalmatrix.in.net
- domain: ext1meta.analyticalhubnode.in.net
- domain: ext2outer.coreconnectivity.in.net
- domain: fileost.in.net
- domain: formaass.sleepbut.in.net
- domain: fotestat.in.net
- domain: grovopen.in.net
- domain: host3dev.quarzbase.in.net
- domain: infosafe.in.net
- domain: int1proc.virtualgatekeeper.in.net
- domain: int2core.virtualgatekeeper.in.net
- domain: int4view.virtualgatekeeper.in.net
- domain: integritychecker.in.net
- domain: interfacehandler.in.net
- domain: lb2point.cryptasol.in.net
- domain: lb2remote.quarzbase.in.net
- domain: linearductnode.in.net
- domain: loc2data.streamdatahandler.in.net
- domain: loc3dev.telemetryinterface.in.net
- domain: loc4view.managementresource.in.net
- domain: logicflowmanager.in.net
- domain: managementgateway.in.net
- domain: managementresource.in.net
- domain: metravolta.in.net
- domain: msk3edge.distributedledger.in.net
- domain: msk4static.distributedledger.in.net
- domain: networkobserver.in.net
- domain: networkoptimizer.in.net
- domain: node1sync.networkobserver.in.net
- domain: node2data.networkobserver.in.net
- domain: node4static.networkobserver.in.net
- domain: operationalgateway.in.net
- domain: operationalmatrix.in.net
- domain: orbit1proc.terminalvariable.in.net
- domain: orbit3core.terminalvariable.in.net
- domain: packetup.in.net
- domain: partne2-field.grovopen.in.net
- domain: platformendpoint.in.net
- domain: pnt2outer.connectivitybuffer.in.net
- domain: point2power.virtualresource.in.net
- domain: point3local.virtualresource.in.net
- domain: proc.networkoptimizer.in.net
- domain: proc1alpha.activegateway.in.net
- domain: protopathfinder.in.net
- domain: quarzbase.in.net
- domain: rack1node.astropoint.in.net
- domain: remotediagnostic.in.net
- domain: res2point.operationalgateway.in.net
- domain: resourcebalancer.in.net
- domain: rt3gate.integritychecker.in.net
- domain: secureterminal.in.net
- domain: securityprotocol.in.net
- domain: shell2core.veloxsite.in.net
- domain: sleepbut.in.net
- domain: snap2-phase.clocknet.in.net
- domain: sol-tideor.fotestat.in.net
- domain: spectrumdaemon.deepglom.in.net
- domain: stor4static.astropoint.in.net
- domain: streamdatahandler.in.net
- domain: sync4vision.veloxsite.in.net
- domain: tatneft.in.net
- domain: telemetryinterface.in.net
- domain: terminalvariable.in.net
- domain: unit2proc.securityprotocol.in.net
- domain: veloxsite.in.net
- domain: virtualgatekeeper.in.net
- domain: virtualresource.in.net
- domain: vld3data.logicflowmanager.in.net
- domain: vld3edge.cyberneticsystems.in.net
- domain: vld4static.cyberneticsystems.in.net
- domain: vol4link.diagnosticresource.in.net
- domain: vol4space.connectivitynode.in.net
- domain: xedbu.bejont.in.net
- domain: xgj9.fotestat.in.net
- domain: xpm713mg.deepglom.in.net
- url: https://api.github.com/repos/stamparm/maltrail/commits/a3c70fd9263c6efddcd9f8f0a2caddbd3f33c7d0
- domain: custosern.digital
- url: https://api.github.com/repos/stamparm/maltrail/commits/347c83eb6a02f30344d1f55a5a15419feb78b11f
- domain: auth08-websec8-w10.center
- url: https://api.github.com/repos/stamparm/maltrail/commits/efe789b6127078cb67672635d458f4e1ca8522e8
- domain: clambjjiskasf.pages.dev
- domain: mac-1rytr3oucv-hi.pages.dev
- domain: mac-1rytr3oucv-sl.pages.dev
- domain: mac-1rytr3oucv-st.pages.dev
- domain: mac-523jk1nkj12k51-stor.pages.dev
- domain: 1analyzer.com
- domain: 1chamber.com
- domain: a1hospitals.com
- domain: a1massager.com
- domain: a1mobilephone.com
- domain: biosungardens.com
- domain: cbtaxohio.net
- domain: ggbuyjunkcartowing.com
- domain: herbalkitchenchronicles.com
- domain: madartrades.com
- domain: markkortnik.com
- domain: pumpsseller.com
- domain: pyarkidukan.com
- domain: ragemonkeydesigns.com
- domain: realsteelcoltd.com
- domain: sportschuckles.com
- domain: sumuualajyal.com
- domain: taylorsversionrecords.com
- domain: theauthorofmystory.com
- domain: willowsandwheatfields.com
- domain: xamartaxi.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/1a854ae6c3e0205d0601d4e95e7030396063f05e
- domain: 9m.as-whatsapp.hl.cn
- domain: as-whatsapp.hl.cn
- url: https://api.github.com/repos/stamparm/maltrail/commits/7ae50d770ede8ccaddb5b05b49d89f7b3b8f3c82
- domain: datasetdoc.mydns.bz
- domain: investinfdoc.mydns.bz
- domain: invoice.datasetdoc.mydns.bz
- domain: invoice.memberlogcheck.mydns.bz
- domain: memberlogcheck.mydns.bz
- domain: ndocaipass.dynv6.net
- domain: ndocampass.dynv6.net
- domain: ndocaopass.dynv6.net
- domain: usr.investinfdoc.mydns.bz
- url: https://api.github.com/repos/stamparm/maltrail/commits/ed86ae4f2ae6257e767454822132b0f9d780b180
- domain: webdriver-terminal.vg
- url: https://api.github.com/repos/stamparm/maltrail/commits/976896f59119127995a5f5a73b95540e59098f4d
- domain: 1drop.cfd
- url: https://api.github.com/repos/stamparm/maltrail/commits/23de3b32551c24629294f7d93cc3157dfdc72b41
- url: https://github.com/hagezi/dns-blocklists/issues/9474
- domain: apd-todesk.com.cn
- domain: cn-google-ch.com.cn
- domain: cn-google-google-zh.hl.cn
- domain: cn-www-google.com.cn
- domain: qishui0.com
- domain: sodamusic-app.com
- domain: torproject.org.cn
- url: https://api.github.com/repos/stamparm/maltrail/commits/c0d4f2f111dac637c9be694a94ff6f7ed23e6527
- url: https://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran
- domain: championships-peoples-point-cassette.trycloudflare.com
- domain: investigation-launches-hearings-copying.trycloudflare.com
- domain: souls-entire-defined-routes.trycloudflare.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/c85a2388034a303c9b2c8f7f6593bea6e3374702
- domain: wasafaisalabad.gop.pk
Maltrail IOC for 2026-03-22
Description
Maltrail IOC for 2026-03-22
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat report details a Maltrail IOC dated March 22, 2026, classified as malware with medium severity. Maltrail is a network traffic detection system that identifies suspicious or malicious network activity by leveraging various threat intelligence sources. The IOC originates from the CIRCL OSINT Feed, indicating it is derived from open-source intelligence and manually collected data. The report lacks specific affected software versions, detailed technical indicators, or known exploits, which limits the granularity of analysis. No patches or remediation links are available, and no CWE identifiers are associated, suggesting this is an observational report rather than a vulnerability disclosure. The medium severity rating implies the malware or network activity detected may pose a moderate threat to confidentiality, integrity, or availability, but without evidence of active exploitation or widespread impact. The tags indicate this is an unsupervised automated observation, likely generated by automated systems monitoring network traffic for anomalies. The absence of indicators means defenders must rely on external Maltrail feeds and their own network monitoring to detect related activity. Overall, this IOC serves as a warning to maintain vigilance in network traffic analysis and threat intelligence integration.
Potential Impact
The potential impact of this threat is moderate, as indicated by the medium severity rating. Since it is categorized as malware related to network activity, it could lead to unauthorized data exfiltration, disruption of network services, or the establishment of command and control channels if exploited. However, the lack of known exploits in the wild and absence of specific technical details suggest that the immediate risk of widespread compromise is low. Organizations that do not monitor network traffic or integrate threat intelligence feeds like Maltrail may be less prepared to detect such activity, increasing their risk exposure. The impact on confidentiality could involve leakage of sensitive information, while integrity and availability impacts depend on the malware’s capabilities, which remain unspecified. Overall, the threat may cause moderate operational disruption or data loss if not detected and mitigated promptly.
Mitigation Recommendations
1. Integrate Maltrail or similar network traffic analysis tools into your security monitoring infrastructure to detect suspicious network activity. 2. Regularly update and tune network detection signatures and threat intelligence feeds to ensure timely identification of emerging threats. 3. Conduct continuous network traffic analysis focusing on unusual patterns, unexpected external connections, or anomalous data flows. 4. Implement network segmentation and strict access controls to limit the spread and impact of potential malware infections. 5. Establish incident response procedures that include investigation of alerts generated by Maltrail or other network monitoring tools. 6. Train security personnel to interpret OSINT-based threat intelligence and correlate it with internal telemetry for effective detection. 7. Maintain up-to-date asset inventories to quickly identify affected systems if indicators become available. 8. Collaborate with threat intelligence sharing communities to receive timely updates and share observations related to this IOC. These steps go beyond generic advice by emphasizing integration of specific network monitoring tools, tuning of detection capabilities, and active threat intelligence collaboration.
Technical Details
- Uuid
- 21303d8f-49bc-4516-9fc4-39d829d7c08e
- Original Timestamp
- 1774191603
Indicators of Compromise
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://api.github.com/repos/stamparm/maltrail/commits/b8598ae2a7f48d9dd07deef877b7ba423e52f925 | osx_nova | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/2940351bdcf45ee05c0f1276018d836bc073efa4 | 0ktapus | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/cc7fc2a451c0994a0631b0d9ab377251fe8b753d | offloader | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a5f3e76a3047ab073df91e23d07289ff38804523 | android_joker | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c76556b990b985fbae842bffd233c86c7b060759 | alp001_ransomware | |
urlhttps://x.com/fbgwls245/status/2035499364895101187 | alp001_ransomware | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7982abae6217f51b8cb5264ff6b18709cf3e78ea | apt_lazarus | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/b2f30daac80ac03f742c9ea32a7e8e150dd53096 | — | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1636f355b1689c890f0822ba0a5c36dd73633885 | powershell_injector | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d45289d7a4b010bac00d5ed35ed9b8e9bafcaff8 | ek_clearfake | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a3c70fd9263c6efddcd9f8f0a2caddbd3f33c7d0 | ek_clearfake | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/347c83eb6a02f30344d1f55a5a15419feb78b11f | ek_clearfake | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/efe789b6127078cb67672635d458f4e1ca8522e8 | osx_atomic | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1a854ae6c3e0205d0601d4e95e7030396063f05e | fakeapp | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7ae50d770ede8ccaddb5b05b49d89f7b3b8f3c82 | apt_kimsuky | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ed86ae4f2ae6257e767454822132b0f9d780b180 | lummac2 | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/976896f59119127995a5f5a73b95540e59098f4d | osx_nova | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/23de3b32551c24629294f7d93cc3157dfdc72b41 | fakeapp | |
urlhttps://github.com/hagezi/dns-blocklists/issues/9474 | fakeapp | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c0d4f2f111dac637c9be694a94ff6f7ed23e6527 | hacked_trivy | |
urlhttps://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran | hacked_trivy | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c85a2388034a303c9b2c8f7f6593bea6e3374702 | fakeapp |
Domain
| Value | Description | Copy |
|---|---|---|
domain1drop.click | osx_nova | |
domain1drop.digital | osx_nova | |
domain1drop.life | osx_nova | |
domainfreegift-pump.fun | osx_nova | |
domainmywayfairconnect.com | 0ktapus | |
domainsmokecar.space | offloader | |
domainexquens.world | android_joker | |
domainb4riuxx7ypobdptctf6lyfcvgi6vn74iurzdh4kn2agbk7472dvywgyd.onion | alp001_ransomware | |
domainmenchro.pro | apt_lazarus | |
domaindeoft.com | apt_lazarus | |
domain2vertexdy-namics.pics | — | |
domainaeronetworkinsight.click | — | |
domainageustiaflow.digital | — | |
domainaltaragehub.click | — | |
domainamadancore.digital | — | |
domainamarantlayer.click | — | |
domainanchor36industries.click | — | |
domainanglepodworks.digital | — | |
domainannerrestudio.digital | — | |
domainaphorialayerio.digital | — | |
domainauditivespaceco.click | — | |
domainbavaxiiaanalytics.digital | — | |
domainbazuxuumservices.sbs | — | |
domainbeemanstackio.click | — | |
domainbehedgelayer.click | — | |
domainberizenisconsultingnet.click | — | |
domainbertinbase.click | — | |
domainbibbleworks.click | — | |
domainbiluzoumsystemsltd.digital | — | |
domainbisedulaisanalyticsinc.digital | — | |
domainblankestlabsco.click | — | |
domainborniticstudioio.digital | — | |
domainbotalezidionmanagementco.click | — | |
domainboycelabs.digital | — | |
domainbufidixiaventures.click | — | |
domainbumpkinbase.click | — | |
domainburstyspace.click | — | |
domainbusujuyubexsolutions.click | — | |
domainbutleryhub.click | — | |
domainbyzantcore.click | — | |
domaincamitezurumresources16.click | — | |
domaincaryocarspace.digital | — | |
domaincauraleworksco.click | — | |
domaincaxeresibuonresources.click | — | |
domainchavicingrid.click | — | |
domaincheckerworks.digital | — | |
domaincibiyeyusmanagement.digital | — | |
domainclaycloud.digital | — | |
domaincodebaseflow.pics | — | |
domainconsentflow.digital | — | |
domainconusantgrid.digital | — | |
domaincorexspacemesh.click | — | |
domaincoribixabissystems.digital | — | |
domaincrcaospace.click | — | |
domaincreaticworks.digital | — | |
domaincufimenarumoperationsltd.digital | — | |
domaincytozymelayerio.digital | — | |
domaindamoberaisindustries36.click | — | |
domaindankestworks.click | — | |
domaindatafusionstack.digital | — | |
domaindavidistworks.click | — | |
domaindecrescflow.click | — | |
domaindefekusiexanalytics.click | — | |
domaindendalayer.click | — | |
domaindentatestudio.digital | — | |
domaindinerotech.digital | — | |
domaindispostflowco.click | — | |
domaindollierstudio.digital | — | |
domaindopatixiriexanalyticsltd.forum | — | |
domaindronelflow.digital | — | |
domaindujamoviaholdings88.click | — | |
domaindukalemeraadvisoryco.digital | — | |
domainelev-ate2advisory.click | — | |
domainepiceletech.digital | — | |
domainexsertworksio.digital | — | |
domainfadiyucuhoumholdingsltd.digital | — | |
domainfamelichub.click | — | |
domainfaqageyivexresourcesco.digital | — | |
domainfevefeummanagement.click | — | |
domainfinowunonadvisory21.click | — | |
domainflareedgemodule.sbs | — | |
domainflowoffcore.digital | — | |
domainfocusedgenetwork.digital | — | |
domainforbathestack.click | — | |
domainfurunclespace.click | — | |
domainfusesiroyuexsolutions.click | — | |
domaingalleinstack.digital | — | |
domaingapudacorconsulting.click | — | |
domaingarretflow.click | — | |
domaingeoinvestzone.digital | — | |
domaingeolspace.digital | — | |
domaingironworks.click | — | |
domaingiuntalayerco.click | — | |
domaingixiqohutonsolutions.digital | — | |
domaingluontech.click | — | |
domaingoadlikecore.click | — | |
domaingojabuexmanagement.digital | — | |
domaingonorecuismanagementnet.click | — | |
domaingougercore.digital | — | |
domaingubedehayeusmanagement.digital | — | |
domainhainchlayer.click | — | |
domainhalyardlayer.digital | — | |
domainhaperowifaamanagement.digital | — | |
domainhesperalayer.digital | — | |
domainhicozucuceiagroup.digital | — | |
domainhixuvodapiamanagement.digital | — | |
domainhocegijiispartners.digital | — | |
domainhodecaiamanagement.digital | — | |
domainhogiyuqizoumventures.click | — | |
domainhookletstackco.digital | — | |
domainhorizon365pulse.sbs | — | |
domainhulloahub.digital | — | |
domainhupijulexmanagement.digital | — | |
domainimpromptflowio.digital | — | |
domainincursegrid.click | — | |
domaininfracapital247.com | — | |
domaininframetrics101.click | — | |
domaininitialflow.digital | — | |
domainintratespace.digital | — | |
domainirrateworks.click | — | |
domainjahvecore.click | — | |
domainjaleloponmanagement.digital | — | |
domainjapishlayer.digital | — | |
domainjellifycloud.digital | — | |
domainjeqatiiaoperations.digital | — | |
domainjexoziqesoorcapitalltd.click | — | |
domainjiyegeciscapital.pics | — | |
domainjododegiiaholdingsco.digital | — | |
domainjudokastudio.digital | — | |
domainjuvituseorinvestments.digital | — | |
domainkazoceyiapartners.digital | — | |
domainkineruboormanagement.click | — | |
domainkohencloud.digital | — | |
domainkopoluvokiscollective.digital | — | |
domainkronenhub.digital | — | |
domainlapidiststack.digital | — | |
domainlativpartners.click | — | |
domainlenagutulexadvisory.digital | — | |
domainlepeqoorinvestments.digital | — | |
domainlezaponiapartners.click | — | |
domainlicakojuorsolutions.digital | — | |
domainlichhub.digital | — | |
domainliftmenlayer.click | — | |
domainlohosiiscollectiveinc.click | — | |
domainlosezakaloroperationsco.click | — | |
domainlujulibonholdings64.digital | — | |
domainlumentrustsmart.click | — | |
domainluzegaximoexadvisory.click | — | |
domainmacrostudioventures.click | — | |
domainmagosuliexpartners.click | — | |
domainmansardlabs.digital | — | |
domainmappistcore.click | — | |
domainmarseflow.digital | — | |
domainmawuviexcapital.click | — | |
domainmeridian88analytics.digital | — | |
domainmillsitecloud.digital | — | |
domainminkfishflow.click | — | |
domainmissilecoin.lol | — | |
domainmitherstudio.digital | — | |
domainmivoliguloumresources.click | — | |
domainmobifamihoacollective99.click | — | |
domainmoderaprimeresources.click | — | |
domainmolecasthub.click | — | |
domainmowburncloud.click | — | |
domainmoxodoboumcapitalinc.click | — | |
domainmuddierspace.digital | — | |
domainmyoedemaworks.click | — | |
domainmyrmecialayer.click | — | |
domainnacixatizoexholdings.digital | — | |
domainnejiwoponsolutions.digital | — | |
domainnereitelabs.digital | — | |
domainneuralevolvenode.click | — | |
domainnexum8analytics.click | — | |
domainnoseburnspace.click | — | |
domainoutspellhub.click | — | |
domainoxhoftlayer.digital | — | |
domainpandagrid.click | — | |
domainparhelnmtech.click | — | |
domainparroketstack.click | — | |
domainpavannegrid.digital | — | |
domainpaverstack.digital | — | |
domainpegijuxainvestments.digital | — | |
domainpeqeqejumadvisory.click | — | |
domainpetrelbase.digital | — | |
domainpewovubadexoperationsltd.click | — | |
domainpexihefazorindustries.click | — | |
domainpiyotunuaoperations.click | — | |
domainplannerhub.click | — | |
domainplungecore.digital | — | |
domainpohitogusadvisory.digital | — | |
domainpotojoisgroup.click | — | |
domainprimealliance.sbs | — | |
domainprimegammafactory.digital | — | |
domainpulpalcore.click | — | |
domainpyranosebase.digital | — | |
domainqegogonikuapartners21.digital | — | |
domainqetoxagiacapital.click | — | |
domainqezegaiaadvisory12.digital | — | |
domainqijayepexanalyticsnet.click | — | |
domainqikakowapartners.click | — | |
domainquaintstudio.digital | — | |
domainrattailcloud.click | — | |
domainrealtorspace.digital | — | |
domainrecommitflow.digital | — | |
domainregupagugaexindustries.click | — | |
domainresecatelabs.digital | — | |
domainretrainflow.click | — | |
domainrezemeacapital16.click | — | |
domainrihigogorgroupinc.click | — | |
domainrimiformcore.click | — | |
domainrinolajussolutions.digital | — | |
domainriretedijeaservicesinc.digital | — | |
domainriyuhoduzoumsolutions.digital | — | |
domainrowetstack.click | — | |
domainruquxoniaventures.digital | — | |
domainruxigefujiumsolutions.click | — | |
domainsayogibisoperations.digital | — | |
domainscutcherhub.digital | — | |
domainsenatehub.digital | — | |
domainsepawnlayer.click | — | |
domainshadrachcloudio.click | — | |
domainsintoistbaseio.click | — | |
domainsiwapacajaumcollective16.digital | — | |
domainskicehub.digital | — | |
domainsnailerylayer.click | — | |
domainsneerfullayer.click | — | |
domainspecietechco.click | — | |
domainstartorbase.click | — | |
domainstationcorevertex.digital | — | |
domainstellardigitalcenter.sbs | — | |
domainstrategymatrix.pics | — | |
domainsturtitelayer.digital | — | |
domainsuhedahiumholdings64.digital | — | |
domainsuiogothspace.digital | — | |
domainsummitprimepartnersco.digital | — | |
domainsurfmenlayer.digital | — | |
domainsurreallayer.digital | — | |
domainsuxisigiaadvisory8.digital | — | |
domainsweltrystudio.digital | — | |
domainsymphysyspace.click | — | |
domaintackercloudio.click | — | |
domaintaperstack.click | — | |
domaintecalistudio.digital | — | |
domaintechnonetcore.sbs | — | |
domaintheismlabs.digital | — | |
domaintofinuwicexresources.click | — | |
domaintojasiluscapital.digital | — | |
domaintournantcloud.click | — | |
domaintrinketsol.lol | — | |
domaintrumptech.click | — | |
domaintupezuissystems.digital | — | |
domainturboconsultingspace.digital | — | |
domainturfieststackco.click | — | |
domainugariticcloud.digital | — | |
domainungloomycloud.digital | — | |
domainunich-gateway.click | — | |
domainunloaderbase.digital | — | |
domainunlyricstudio.click | — | |
domainunmounthubio.click | — | |
domainuptimestudio.digital | — | |
domainurarticstudio.click | — | |
domainvarasumorindustries.digital | — | |
domainvayanuummanagementco.click | — | |
domainvenerygrid.digital | — | |
domainvetelupixaaventures.click | — | |
domainvetivertlabs.click | — | |
domainvevorolexiussystemsltd.digital | — | |
domainvexohejocumservices.click | — | |
domainvisionxanalytics.click | — | |
domainvomavotunispartnersinc.digital | — | |
domainvopejiusoperations.click | — | |
domainvowunokexaisindustries16.digital | — | |
domainvurohiziexconsulting.digital | — | |
domainwabaniexinvestments.digital | — | |
domainwedijucayasolutions88.digital | — | |
domainwesagoiaresources.click | — | |
domainwesijezonservices.sbs | — | |
domainwhyostackco.digital | — | |
domainwirucuronisanalytics.digital | — | |
domainwispbase.digital | — | |
domainwoleaitech.digital | — | |
domainworkpanlabs.click | — | |
domainwrestspaceio.digital | — | |
domainwulderlayer.digital | — | |
domainxinawezuhausmanagement.click | — | |
domainyabbletechco.click | — | |
domainyamogiverumoperations.click | — | |
domainyearbirdgrid.digital | — | |
domainyebozuispartnersinc.digital | — | |
domainyozepeagroup.digital | — | |
domainyurakhub.click | — | |
domainzaptiahflowco.click | — | |
domainzawokoummanagement.click | — | |
domainzebaxitevuiacapital.digital | — | |
domainzenithcapital247.sbs | — | |
domainzizugioncapital.click | — | |
domainzobohub.click | — | |
domainzokopifuxiumadvisory.click | — | |
domainzonupodaanalytics.click | — | |
domainzovexovuciamanagement8.digital | — | |
domain78-153-140-17.cprapid.com | powershell_injector | |
domainacube-contract.com | powershell_injector | |
domaininteractiveportraits.com | powershell_injector | |
domainmymarathilearning.com | powershell_injector | |
domainrencaihuainan.com | powershell_injector | |
domainsyhmen.com | powershell_injector | |
domain0ak-plate.fileost.in.net | ek_clearfake | |
domain0v6nu.tatneft.in.net | ek_clearfake | |
domainabhd27da.grovopen.in.net | ek_clearfake | |
domainactivegateway.in.net | ek_clearfake | |
domainanalyticalhubnode.in.net | ek_clearfake | |
domainanalyticspipeline.in.net | ek_clearfake | |
domainanalyticspoint.in.net | ek_clearfake | |
domainanalyticsprocessing.in.net | ek_clearfake | |
domainapp2steel.distributedmatrix.in.net | ek_clearfake | |
domainapp3ghost.managementgateway.in.net | ek_clearfake | |
domainapp4view.managementgateway.in.net | ek_clearfake | |
domainarea3field.boundarygateway.in.net | ek_clearfake | |
domainarea4space.boundarygateway.in.net | ek_clearfake | |
domainastropoint.in.net | ek_clearfake | |
domainbejont.in.net | ek_clearfake | |
domainboundarygateway.in.net | ek_clearfake | |
domaincfg1store.resourcebalancer.in.net | ek_clearfake | |
domaincfg2remote.resourcebalancer.in.net | ek_clearfake | |
domaincfg3ghost.interfacehandler.in.net | ek_clearfake | |
domainclocknet.in.net | ek_clearfake | |
domainconnectivitybuffer.in.net | ek_clearfake | |
domainconnectivitynode.in.net | ek_clearfake | |
domaincoreconnectivity.in.net | ek_clearfake | |
domaincryptasol.in.net | ek_clearfake | |
domaincyberneticsystems.in.net | ek_clearfake | |
domaindark3view.remotediagnostic.in.net | ek_clearfake | |
domaindc1proc.platformendpoint.in.net | ek_clearfake | |
domaindc3edge.analyticspoint.in.net | ek_clearfake | |
domaindeepglom.in.net | ek_clearfake | |
domaindiagnosticendpoint.in.net | ek_clearfake | |
domaindiagnosticresource.in.net | ek_clearfake | |
domaindigitalfoundry.in.net | ek_clearfake | |
domaindistributedledger.in.net | ek_clearfake | |
domaindistributedmatrix.in.net | ek_clearfake | |
domaindynamictelemetry.in.net | ek_clearfake | |
domainentry2base.digitalfoundry.in.net | ek_clearfake | |
domainentry2proxy.secureterminal.in.net | ek_clearfake | |
domainentry4link.metravolta.in.net | ek_clearfake | |
domainext1infra.operationalmatrix.in.net | ek_clearfake | |
domainext1meta.analyticalhubnode.in.net | ek_clearfake | |
domainext2outer.coreconnectivity.in.net | ek_clearfake | |
domainfileost.in.net | ek_clearfake | |
domainformaass.sleepbut.in.net | ek_clearfake | |
domainfotestat.in.net | ek_clearfake | |
domaingrovopen.in.net | ek_clearfake | |
domainhost3dev.quarzbase.in.net | ek_clearfake | |
domaininfosafe.in.net | ek_clearfake | |
domainint1proc.virtualgatekeeper.in.net | ek_clearfake | |
domainint2core.virtualgatekeeper.in.net | ek_clearfake | |
domainint4view.virtualgatekeeper.in.net | ek_clearfake | |
domainintegritychecker.in.net | ek_clearfake | |
domaininterfacehandler.in.net | ek_clearfake | |
domainlb2point.cryptasol.in.net | ek_clearfake | |
domainlb2remote.quarzbase.in.net | ek_clearfake | |
domainlinearductnode.in.net | ek_clearfake | |
domainloc2data.streamdatahandler.in.net | ek_clearfake | |
domainloc3dev.telemetryinterface.in.net | ek_clearfake | |
domainloc4view.managementresource.in.net | ek_clearfake | |
domainlogicflowmanager.in.net | ek_clearfake | |
domainmanagementgateway.in.net | ek_clearfake | |
domainmanagementresource.in.net | ek_clearfake | |
domainmetravolta.in.net | ek_clearfake | |
domainmsk3edge.distributedledger.in.net | ek_clearfake | |
domainmsk4static.distributedledger.in.net | ek_clearfake | |
domainnetworkobserver.in.net | ek_clearfake | |
domainnetworkoptimizer.in.net | ek_clearfake | |
domainnode1sync.networkobserver.in.net | ek_clearfake | |
domainnode2data.networkobserver.in.net | ek_clearfake | |
domainnode4static.networkobserver.in.net | ek_clearfake | |
domainoperationalgateway.in.net | ek_clearfake | |
domainoperationalmatrix.in.net | ek_clearfake | |
domainorbit1proc.terminalvariable.in.net | ek_clearfake | |
domainorbit3core.terminalvariable.in.net | ek_clearfake | |
domainpacketup.in.net | ek_clearfake | |
domainpartne2-field.grovopen.in.net | ek_clearfake | |
domainplatformendpoint.in.net | ek_clearfake | |
domainpnt2outer.connectivitybuffer.in.net | ek_clearfake | |
domainpoint2power.virtualresource.in.net | ek_clearfake | |
domainpoint3local.virtualresource.in.net | ek_clearfake | |
domainproc.networkoptimizer.in.net | ek_clearfake | |
domainproc1alpha.activegateway.in.net | ek_clearfake | |
domainprotopathfinder.in.net | ek_clearfake | |
domainquarzbase.in.net | ek_clearfake | |
domainrack1node.astropoint.in.net | ek_clearfake | |
domainremotediagnostic.in.net | ek_clearfake | |
domainres2point.operationalgateway.in.net | ek_clearfake | |
domainresourcebalancer.in.net | ek_clearfake | |
domainrt3gate.integritychecker.in.net | ek_clearfake | |
domainsecureterminal.in.net | ek_clearfake | |
domainsecurityprotocol.in.net | ek_clearfake | |
domainshell2core.veloxsite.in.net | ek_clearfake | |
domainsleepbut.in.net | ek_clearfake | |
domainsnap2-phase.clocknet.in.net | ek_clearfake | |
domainsol-tideor.fotestat.in.net | ek_clearfake | |
domainspectrumdaemon.deepglom.in.net | ek_clearfake | |
domainstor4static.astropoint.in.net | ek_clearfake | |
domainstreamdatahandler.in.net | ek_clearfake | |
domainsync4vision.veloxsite.in.net | ek_clearfake | |
domaintatneft.in.net | ek_clearfake | |
domaintelemetryinterface.in.net | ek_clearfake | |
domainterminalvariable.in.net | ek_clearfake | |
domainunit2proc.securityprotocol.in.net | ek_clearfake | |
domainveloxsite.in.net | ek_clearfake | |
domainvirtualgatekeeper.in.net | ek_clearfake | |
domainvirtualresource.in.net | ek_clearfake | |
domainvld3data.logicflowmanager.in.net | ek_clearfake | |
domainvld3edge.cyberneticsystems.in.net | ek_clearfake | |
domainvld4static.cyberneticsystems.in.net | ek_clearfake | |
domainvol4link.diagnosticresource.in.net | ek_clearfake | |
domainvol4space.connectivitynode.in.net | ek_clearfake | |
domainxedbu.bejont.in.net | ek_clearfake | |
domainxgj9.fotestat.in.net | ek_clearfake | |
domainxpm713mg.deepglom.in.net | ek_clearfake | |
domaincustosern.digital | ek_clearfake | |
domainauth08-websec8-w10.center | ek_clearfake | |
domainclambjjiskasf.pages.dev | osx_atomic | |
domainmac-1rytr3oucv-hi.pages.dev | osx_atomic | |
domainmac-1rytr3oucv-sl.pages.dev | osx_atomic | |
domainmac-1rytr3oucv-st.pages.dev | osx_atomic | |
domainmac-523jk1nkj12k51-stor.pages.dev | osx_atomic | |
domain1analyzer.com | osx_atomic | |
domain1chamber.com | osx_atomic | |
domaina1hospitals.com | osx_atomic | |
domaina1massager.com | osx_atomic | |
domaina1mobilephone.com | osx_atomic | |
domainbiosungardens.com | osx_atomic | |
domaincbtaxohio.net | osx_atomic | |
domainggbuyjunkcartowing.com | osx_atomic | |
domainherbalkitchenchronicles.com | osx_atomic | |
domainmadartrades.com | osx_atomic | |
domainmarkkortnik.com | osx_atomic | |
domainpumpsseller.com | osx_atomic | |
domainpyarkidukan.com | osx_atomic | |
domainragemonkeydesigns.com | osx_atomic | |
domainrealsteelcoltd.com | osx_atomic | |
domainsportschuckles.com | osx_atomic | |
domainsumuualajyal.com | osx_atomic | |
domaintaylorsversionrecords.com | osx_atomic | |
domaintheauthorofmystory.com | osx_atomic | |
domainwillowsandwheatfields.com | osx_atomic | |
domainxamartaxi.com | osx_atomic | |
domain9m.as-whatsapp.hl.cn | fakeapp | |
domainas-whatsapp.hl.cn | fakeapp | |
domaindatasetdoc.mydns.bz | apt_kimsuky | |
domaininvestinfdoc.mydns.bz | apt_kimsuky | |
domaininvoice.datasetdoc.mydns.bz | apt_kimsuky | |
domaininvoice.memberlogcheck.mydns.bz | apt_kimsuky | |
domainmemberlogcheck.mydns.bz | apt_kimsuky | |
domainndocaipass.dynv6.net | apt_kimsuky | |
domainndocampass.dynv6.net | apt_kimsuky | |
domainndocaopass.dynv6.net | apt_kimsuky | |
domainusr.investinfdoc.mydns.bz | apt_kimsuky | |
domainwebdriver-terminal.vg | lummac2 | |
domain1drop.cfd | osx_nova | |
domainapd-todesk.com.cn | fakeapp | |
domaincn-google-ch.com.cn | fakeapp | |
domaincn-google-google-zh.hl.cn | fakeapp | |
domaincn-www-google.com.cn | fakeapp | |
domainqishui0.com | fakeapp | |
domainsodamusic-app.com | fakeapp | |
domaintorproject.org.cn | fakeapp | |
domainchampionships-peoples-point-cassette.trycloudflare.com | hacked_trivy | |
domaininvestigation-launches-hearings-copying.trycloudflare.com | hacked_trivy | |
domainsouls-entire-defined-routes.trycloudflare.com | hacked_trivy | |
domainwasafaisalabad.gop.pk | fakeapp |
Threat ID: 69c00b23f4197a8e3b82758b
Added to database: 3/22/2026, 3:30:43 PM
Last enriched: 3/22/2026, 3:45:55 PM
Last updated: 3/23/2026, 1:02:56 AM
Views: 13
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.