Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-03-22

0
Medium
Published: Sun Mar 22 2026 (03/22/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed
Vendor/Project: tlp
Product: clear

Description

Maltrail IOC for 2026-03-22

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 03/22/2026, 15:45:55 UTC

Technical Analysis

This threat report details a Maltrail IOC dated March 22, 2026, classified as malware with medium severity. Maltrail is a network traffic detection system that identifies suspicious or malicious network activity by leveraging various threat intelligence sources. The IOC originates from the CIRCL OSINT Feed, indicating it is derived from open-source intelligence and manually collected data. The report lacks specific affected software versions, detailed technical indicators, or known exploits, which limits the granularity of analysis. No patches or remediation links are available, and no CWE identifiers are associated, suggesting this is an observational report rather than a vulnerability disclosure. The medium severity rating implies the malware or network activity detected may pose a moderate threat to confidentiality, integrity, or availability, but without evidence of active exploitation or widespread impact. The tags indicate this is an unsupervised automated observation, likely generated by automated systems monitoring network traffic for anomalies. The absence of indicators means defenders must rely on external Maltrail feeds and their own network monitoring to detect related activity. Overall, this IOC serves as a warning to maintain vigilance in network traffic analysis and threat intelligence integration.

Potential Impact

The potential impact of this threat is moderate, as indicated by the medium severity rating. Since it is categorized as malware related to network activity, it could lead to unauthorized data exfiltration, disruption of network services, or the establishment of command and control channels if exploited. However, the lack of known exploits in the wild and absence of specific technical details suggest that the immediate risk of widespread compromise is low. Organizations that do not monitor network traffic or integrate threat intelligence feeds like Maltrail may be less prepared to detect such activity, increasing their risk exposure. The impact on confidentiality could involve leakage of sensitive information, while integrity and availability impacts depend on the malware’s capabilities, which remain unspecified. Overall, the threat may cause moderate operational disruption or data loss if not detected and mitigated promptly.

Mitigation Recommendations

1. Integrate Maltrail or similar network traffic analysis tools into your security monitoring infrastructure to detect suspicious network activity. 2. Regularly update and tune network detection signatures and threat intelligence feeds to ensure timely identification of emerging threats. 3. Conduct continuous network traffic analysis focusing on unusual patterns, unexpected external connections, or anomalous data flows. 4. Implement network segmentation and strict access controls to limit the spread and impact of potential malware infections. 5. Establish incident response procedures that include investigation of alerts generated by Maltrail or other network monitoring tools. 6. Train security personnel to interpret OSINT-based threat intelligence and correlate it with internal telemetry for effective detection. 7. Maintain up-to-date asset inventories to quickly identify affected systems if indicators become available. 8. Collaborate with threat intelligence sharing communities to receive timely updates and share observations related to this IOC. These steps go beyond generic advice by emphasizing integration of specific network monitoring tools, tuning of detection capabilities, and active threat intelligence collaboration.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
21303d8f-49bc-4516-9fc4-39d829d7c08e
Original Timestamp
1774191603

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/b8598ae2a7f48d9dd07deef877b7ba423e52f925
osx_nova
urlhttps://api.github.com/repos/stamparm/maltrail/commits/2940351bdcf45ee05c0f1276018d836bc073efa4
0ktapus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/cc7fc2a451c0994a0631b0d9ab377251fe8b753d
offloader
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a5f3e76a3047ab073df91e23d07289ff38804523
android_joker
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c76556b990b985fbae842bffd233c86c7b060759
alp001_ransomware
urlhttps://x.com/fbgwls245/status/2035499364895101187
alp001_ransomware
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7982abae6217f51b8cb5264ff6b18709cf3e78ea
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/b2f30daac80ac03f742c9ea32a7e8e150dd53096
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1636f355b1689c890f0822ba0a5c36dd73633885
powershell_injector
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d45289d7a4b010bac00d5ed35ed9b8e9bafcaff8
ek_clearfake
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a3c70fd9263c6efddcd9f8f0a2caddbd3f33c7d0
ek_clearfake
urlhttps://api.github.com/repos/stamparm/maltrail/commits/347c83eb6a02f30344d1f55a5a15419feb78b11f
ek_clearfake
urlhttps://api.github.com/repos/stamparm/maltrail/commits/efe789b6127078cb67672635d458f4e1ca8522e8
osx_atomic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1a854ae6c3e0205d0601d4e95e7030396063f05e
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7ae50d770ede8ccaddb5b05b49d89f7b3b8f3c82
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ed86ae4f2ae6257e767454822132b0f9d780b180
lummac2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/976896f59119127995a5f5a73b95540e59098f4d
osx_nova
urlhttps://api.github.com/repos/stamparm/maltrail/commits/23de3b32551c24629294f7d93cc3157dfdc72b41
fakeapp
urlhttps://github.com/hagezi/dns-blocklists/issues/9474
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c0d4f2f111dac637c9be694a94ff6f7ed23e6527
hacked_trivy
urlhttps://www.aikido.dev/blog/teampcp-stage-payload-canisterworm-iran
hacked_trivy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c85a2388034a303c9b2c8f7f6593bea6e3374702
fakeapp

Domain

ValueDescriptionCopy
domain1drop.click
osx_nova
domain1drop.digital
osx_nova
domain1drop.life
osx_nova
domainfreegift-pump.fun
osx_nova
domainmywayfairconnect.com
0ktapus
domainsmokecar.space
offloader
domainexquens.world
android_joker
domainb4riuxx7ypobdptctf6lyfcvgi6vn74iurzdh4kn2agbk7472dvywgyd.onion
alp001_ransomware
domainmenchro.pro
apt_lazarus
domaindeoft.com
apt_lazarus
domain2vertexdy-namics.pics
domainaeronetworkinsight.click
domainageustiaflow.digital
domainaltaragehub.click
domainamadancore.digital
domainamarantlayer.click
domainanchor36industries.click
domainanglepodworks.digital
domainannerrestudio.digital
domainaphorialayerio.digital
domainauditivespaceco.click
domainbavaxiiaanalytics.digital
domainbazuxuumservices.sbs
domainbeemanstackio.click
domainbehedgelayer.click
domainberizenisconsultingnet.click
domainbertinbase.click
domainbibbleworks.click
domainbiluzoumsystemsltd.digital
domainbisedulaisanalyticsinc.digital
domainblankestlabsco.click
domainborniticstudioio.digital
domainbotalezidionmanagementco.click
domainboycelabs.digital
domainbufidixiaventures.click
domainbumpkinbase.click
domainburstyspace.click
domainbusujuyubexsolutions.click
domainbutleryhub.click
domainbyzantcore.click
domaincamitezurumresources16.click
domaincaryocarspace.digital
domaincauraleworksco.click
domaincaxeresibuonresources.click
domainchavicingrid.click
domaincheckerworks.digital
domaincibiyeyusmanagement.digital
domainclaycloud.digital
domaincodebaseflow.pics
domainconsentflow.digital
domainconusantgrid.digital
domaincorexspacemesh.click
domaincoribixabissystems.digital
domaincrcaospace.click
domaincreaticworks.digital
domaincufimenarumoperationsltd.digital
domaincytozymelayerio.digital
domaindamoberaisindustries36.click
domaindankestworks.click
domaindatafusionstack.digital
domaindavidistworks.click
domaindecrescflow.click
domaindefekusiexanalytics.click
domaindendalayer.click
domaindentatestudio.digital
domaindinerotech.digital
domaindispostflowco.click
domaindollierstudio.digital
domaindopatixiriexanalyticsltd.forum
domaindronelflow.digital
domaindujamoviaholdings88.click
domaindukalemeraadvisoryco.digital
domainelev-ate2advisory.click
domainepiceletech.digital
domainexsertworksio.digital
domainfadiyucuhoumholdingsltd.digital
domainfamelichub.click
domainfaqageyivexresourcesco.digital
domainfevefeummanagement.click
domainfinowunonadvisory21.click
domainflareedgemodule.sbs
domainflowoffcore.digital
domainfocusedgenetwork.digital
domainforbathestack.click
domainfurunclespace.click
domainfusesiroyuexsolutions.click
domaingalleinstack.digital
domaingapudacorconsulting.click
domaingarretflow.click
domaingeoinvestzone.digital
domaingeolspace.digital
domaingironworks.click
domaingiuntalayerco.click
domaingixiqohutonsolutions.digital
domaingluontech.click
domaingoadlikecore.click
domaingojabuexmanagement.digital
domaingonorecuismanagementnet.click
domaingougercore.digital
domaingubedehayeusmanagement.digital
domainhainchlayer.click
domainhalyardlayer.digital
domainhaperowifaamanagement.digital
domainhesperalayer.digital
domainhicozucuceiagroup.digital
domainhixuvodapiamanagement.digital
domainhocegijiispartners.digital
domainhodecaiamanagement.digital
domainhogiyuqizoumventures.click
domainhookletstackco.digital
domainhorizon365pulse.sbs
domainhulloahub.digital
domainhupijulexmanagement.digital
domainimpromptflowio.digital
domainincursegrid.click
domaininfracapital247.com
domaininframetrics101.click
domaininitialflow.digital
domainintratespace.digital
domainirrateworks.click
domainjahvecore.click
domainjaleloponmanagement.digital
domainjapishlayer.digital
domainjellifycloud.digital
domainjeqatiiaoperations.digital
domainjexoziqesoorcapitalltd.click
domainjiyegeciscapital.pics
domainjododegiiaholdingsco.digital
domainjudokastudio.digital
domainjuvituseorinvestments.digital
domainkazoceyiapartners.digital
domainkineruboormanagement.click
domainkohencloud.digital
domainkopoluvokiscollective.digital
domainkronenhub.digital
domainlapidiststack.digital
domainlativpartners.click
domainlenagutulexadvisory.digital
domainlepeqoorinvestments.digital
domainlezaponiapartners.click
domainlicakojuorsolutions.digital
domainlichhub.digital
domainliftmenlayer.click
domainlohosiiscollectiveinc.click
domainlosezakaloroperationsco.click
domainlujulibonholdings64.digital
domainlumentrustsmart.click
domainluzegaximoexadvisory.click
domainmacrostudioventures.click
domainmagosuliexpartners.click
domainmansardlabs.digital
domainmappistcore.click
domainmarseflow.digital
domainmawuviexcapital.click
domainmeridian88analytics.digital
domainmillsitecloud.digital
domainminkfishflow.click
domainmissilecoin.lol
domainmitherstudio.digital
domainmivoliguloumresources.click
domainmobifamihoacollective99.click
domainmoderaprimeresources.click
domainmolecasthub.click
domainmowburncloud.click
domainmoxodoboumcapitalinc.click
domainmuddierspace.digital
domainmyoedemaworks.click
domainmyrmecialayer.click
domainnacixatizoexholdings.digital
domainnejiwoponsolutions.digital
domainnereitelabs.digital
domainneuralevolvenode.click
domainnexum8analytics.click
domainnoseburnspace.click
domainoutspellhub.click
domainoxhoftlayer.digital
domainpandagrid.click
domainparhelnmtech.click
domainparroketstack.click
domainpavannegrid.digital
domainpaverstack.digital
domainpegijuxainvestments.digital
domainpeqeqejumadvisory.click
domainpetrelbase.digital
domainpewovubadexoperationsltd.click
domainpexihefazorindustries.click
domainpiyotunuaoperations.click
domainplannerhub.click
domainplungecore.digital
domainpohitogusadvisory.digital
domainpotojoisgroup.click
domainprimealliance.sbs
domainprimegammafactory.digital
domainpulpalcore.click
domainpyranosebase.digital
domainqegogonikuapartners21.digital
domainqetoxagiacapital.click
domainqezegaiaadvisory12.digital
domainqijayepexanalyticsnet.click
domainqikakowapartners.click
domainquaintstudio.digital
domainrattailcloud.click
domainrealtorspace.digital
domainrecommitflow.digital
domainregupagugaexindustries.click
domainresecatelabs.digital
domainretrainflow.click
domainrezemeacapital16.click
domainrihigogorgroupinc.click
domainrimiformcore.click
domainrinolajussolutions.digital
domainriretedijeaservicesinc.digital
domainriyuhoduzoumsolutions.digital
domainrowetstack.click
domainruquxoniaventures.digital
domainruxigefujiumsolutions.click
domainsayogibisoperations.digital
domainscutcherhub.digital
domainsenatehub.digital
domainsepawnlayer.click
domainshadrachcloudio.click
domainsintoistbaseio.click
domainsiwapacajaumcollective16.digital
domainskicehub.digital
domainsnailerylayer.click
domainsneerfullayer.click
domainspecietechco.click
domainstartorbase.click
domainstationcorevertex.digital
domainstellardigitalcenter.sbs
domainstrategymatrix.pics
domainsturtitelayer.digital
domainsuhedahiumholdings64.digital
domainsuiogothspace.digital
domainsummitprimepartnersco.digital
domainsurfmenlayer.digital
domainsurreallayer.digital
domainsuxisigiaadvisory8.digital
domainsweltrystudio.digital
domainsymphysyspace.click
domaintackercloudio.click
domaintaperstack.click
domaintecalistudio.digital
domaintechnonetcore.sbs
domaintheismlabs.digital
domaintofinuwicexresources.click
domaintojasiluscapital.digital
domaintournantcloud.click
domaintrinketsol.lol
domaintrumptech.click
domaintupezuissystems.digital
domainturboconsultingspace.digital
domainturfieststackco.click
domainugariticcloud.digital
domainungloomycloud.digital
domainunich-gateway.click
domainunloaderbase.digital
domainunlyricstudio.click
domainunmounthubio.click
domainuptimestudio.digital
domainurarticstudio.click
domainvarasumorindustries.digital
domainvayanuummanagementco.click
domainvenerygrid.digital
domainvetelupixaaventures.click
domainvetivertlabs.click
domainvevorolexiussystemsltd.digital
domainvexohejocumservices.click
domainvisionxanalytics.click
domainvomavotunispartnersinc.digital
domainvopejiusoperations.click
domainvowunokexaisindustries16.digital
domainvurohiziexconsulting.digital
domainwabaniexinvestments.digital
domainwedijucayasolutions88.digital
domainwesagoiaresources.click
domainwesijezonservices.sbs
domainwhyostackco.digital
domainwirucuronisanalytics.digital
domainwispbase.digital
domainwoleaitech.digital
domainworkpanlabs.click
domainwrestspaceio.digital
domainwulderlayer.digital
domainxinawezuhausmanagement.click
domainyabbletechco.click
domainyamogiverumoperations.click
domainyearbirdgrid.digital
domainyebozuispartnersinc.digital
domainyozepeagroup.digital
domainyurakhub.click
domainzaptiahflowco.click
domainzawokoummanagement.click
domainzebaxitevuiacapital.digital
domainzenithcapital247.sbs
domainzizugioncapital.click
domainzobohub.click
domainzokopifuxiumadvisory.click
domainzonupodaanalytics.click
domainzovexovuciamanagement8.digital
domain78-153-140-17.cprapid.com
powershell_injector
domainacube-contract.com
powershell_injector
domaininteractiveportraits.com
powershell_injector
domainmymarathilearning.com
powershell_injector
domainrencaihuainan.com
powershell_injector
domainsyhmen.com
powershell_injector
domain0ak-plate.fileost.in.net
ek_clearfake
domain0v6nu.tatneft.in.net
ek_clearfake
domainabhd27da.grovopen.in.net
ek_clearfake
domainactivegateway.in.net
ek_clearfake
domainanalyticalhubnode.in.net
ek_clearfake
domainanalyticspipeline.in.net
ek_clearfake
domainanalyticspoint.in.net
ek_clearfake
domainanalyticsprocessing.in.net
ek_clearfake
domainapp2steel.distributedmatrix.in.net
ek_clearfake
domainapp3ghost.managementgateway.in.net
ek_clearfake
domainapp4view.managementgateway.in.net
ek_clearfake
domainarea3field.boundarygateway.in.net
ek_clearfake
domainarea4space.boundarygateway.in.net
ek_clearfake
domainastropoint.in.net
ek_clearfake
domainbejont.in.net
ek_clearfake
domainboundarygateway.in.net
ek_clearfake
domaincfg1store.resourcebalancer.in.net
ek_clearfake
domaincfg2remote.resourcebalancer.in.net
ek_clearfake
domaincfg3ghost.interfacehandler.in.net
ek_clearfake
domainclocknet.in.net
ek_clearfake
domainconnectivitybuffer.in.net
ek_clearfake
domainconnectivitynode.in.net
ek_clearfake
domaincoreconnectivity.in.net
ek_clearfake
domaincryptasol.in.net
ek_clearfake
domaincyberneticsystems.in.net
ek_clearfake
domaindark3view.remotediagnostic.in.net
ek_clearfake
domaindc1proc.platformendpoint.in.net
ek_clearfake
domaindc3edge.analyticspoint.in.net
ek_clearfake
domaindeepglom.in.net
ek_clearfake
domaindiagnosticendpoint.in.net
ek_clearfake
domaindiagnosticresource.in.net
ek_clearfake
domaindigitalfoundry.in.net
ek_clearfake
domaindistributedledger.in.net
ek_clearfake
domaindistributedmatrix.in.net
ek_clearfake
domaindynamictelemetry.in.net
ek_clearfake
domainentry2base.digitalfoundry.in.net
ek_clearfake
domainentry2proxy.secureterminal.in.net
ek_clearfake
domainentry4link.metravolta.in.net
ek_clearfake
domainext1infra.operationalmatrix.in.net
ek_clearfake
domainext1meta.analyticalhubnode.in.net
ek_clearfake
domainext2outer.coreconnectivity.in.net
ek_clearfake
domainfileost.in.net
ek_clearfake
domainformaass.sleepbut.in.net
ek_clearfake
domainfotestat.in.net
ek_clearfake
domaingrovopen.in.net
ek_clearfake
domainhost3dev.quarzbase.in.net
ek_clearfake
domaininfosafe.in.net
ek_clearfake
domainint1proc.virtualgatekeeper.in.net
ek_clearfake
domainint2core.virtualgatekeeper.in.net
ek_clearfake
domainint4view.virtualgatekeeper.in.net
ek_clearfake
domainintegritychecker.in.net
ek_clearfake
domaininterfacehandler.in.net
ek_clearfake
domainlb2point.cryptasol.in.net
ek_clearfake
domainlb2remote.quarzbase.in.net
ek_clearfake
domainlinearductnode.in.net
ek_clearfake
domainloc2data.streamdatahandler.in.net
ek_clearfake
domainloc3dev.telemetryinterface.in.net
ek_clearfake
domainloc4view.managementresource.in.net
ek_clearfake
domainlogicflowmanager.in.net
ek_clearfake
domainmanagementgateway.in.net
ek_clearfake
domainmanagementresource.in.net
ek_clearfake
domainmetravolta.in.net
ek_clearfake
domainmsk3edge.distributedledger.in.net
ek_clearfake
domainmsk4static.distributedledger.in.net
ek_clearfake
domainnetworkobserver.in.net
ek_clearfake
domainnetworkoptimizer.in.net
ek_clearfake
domainnode1sync.networkobserver.in.net
ek_clearfake
domainnode2data.networkobserver.in.net
ek_clearfake
domainnode4static.networkobserver.in.net
ek_clearfake
domainoperationalgateway.in.net
ek_clearfake
domainoperationalmatrix.in.net
ek_clearfake
domainorbit1proc.terminalvariable.in.net
ek_clearfake
domainorbit3core.terminalvariable.in.net
ek_clearfake
domainpacketup.in.net
ek_clearfake
domainpartne2-field.grovopen.in.net
ek_clearfake
domainplatformendpoint.in.net
ek_clearfake
domainpnt2outer.connectivitybuffer.in.net
ek_clearfake
domainpoint2power.virtualresource.in.net
ek_clearfake
domainpoint3local.virtualresource.in.net
ek_clearfake
domainproc.networkoptimizer.in.net
ek_clearfake
domainproc1alpha.activegateway.in.net
ek_clearfake
domainprotopathfinder.in.net
ek_clearfake
domainquarzbase.in.net
ek_clearfake
domainrack1node.astropoint.in.net
ek_clearfake
domainremotediagnostic.in.net
ek_clearfake
domainres2point.operationalgateway.in.net
ek_clearfake
domainresourcebalancer.in.net
ek_clearfake
domainrt3gate.integritychecker.in.net
ek_clearfake
domainsecureterminal.in.net
ek_clearfake
domainsecurityprotocol.in.net
ek_clearfake
domainshell2core.veloxsite.in.net
ek_clearfake
domainsleepbut.in.net
ek_clearfake
domainsnap2-phase.clocknet.in.net
ek_clearfake
domainsol-tideor.fotestat.in.net
ek_clearfake
domainspectrumdaemon.deepglom.in.net
ek_clearfake
domainstor4static.astropoint.in.net
ek_clearfake
domainstreamdatahandler.in.net
ek_clearfake
domainsync4vision.veloxsite.in.net
ek_clearfake
domaintatneft.in.net
ek_clearfake
domaintelemetryinterface.in.net
ek_clearfake
domainterminalvariable.in.net
ek_clearfake
domainunit2proc.securityprotocol.in.net
ek_clearfake
domainveloxsite.in.net
ek_clearfake
domainvirtualgatekeeper.in.net
ek_clearfake
domainvirtualresource.in.net
ek_clearfake
domainvld3data.logicflowmanager.in.net
ek_clearfake
domainvld3edge.cyberneticsystems.in.net
ek_clearfake
domainvld4static.cyberneticsystems.in.net
ek_clearfake
domainvol4link.diagnosticresource.in.net
ek_clearfake
domainvol4space.connectivitynode.in.net
ek_clearfake
domainxedbu.bejont.in.net
ek_clearfake
domainxgj9.fotestat.in.net
ek_clearfake
domainxpm713mg.deepglom.in.net
ek_clearfake
domaincustosern.digital
ek_clearfake
domainauth08-websec8-w10.center
ek_clearfake
domainclambjjiskasf.pages.dev
osx_atomic
domainmac-1rytr3oucv-hi.pages.dev
osx_atomic
domainmac-1rytr3oucv-sl.pages.dev
osx_atomic
domainmac-1rytr3oucv-st.pages.dev
osx_atomic
domainmac-523jk1nkj12k51-stor.pages.dev
osx_atomic
domain1analyzer.com
osx_atomic
domain1chamber.com
osx_atomic
domaina1hospitals.com
osx_atomic
domaina1massager.com
osx_atomic
domaina1mobilephone.com
osx_atomic
domainbiosungardens.com
osx_atomic
domaincbtaxohio.net
osx_atomic
domainggbuyjunkcartowing.com
osx_atomic
domainherbalkitchenchronicles.com
osx_atomic
domainmadartrades.com
osx_atomic
domainmarkkortnik.com
osx_atomic
domainpumpsseller.com
osx_atomic
domainpyarkidukan.com
osx_atomic
domainragemonkeydesigns.com
osx_atomic
domainrealsteelcoltd.com
osx_atomic
domainsportschuckles.com
osx_atomic
domainsumuualajyal.com
osx_atomic
domaintaylorsversionrecords.com
osx_atomic
domaintheauthorofmystory.com
osx_atomic
domainwillowsandwheatfields.com
osx_atomic
domainxamartaxi.com
osx_atomic
domain9m.as-whatsapp.hl.cn
fakeapp
domainas-whatsapp.hl.cn
fakeapp
domaindatasetdoc.mydns.bz
apt_kimsuky
domaininvestinfdoc.mydns.bz
apt_kimsuky
domaininvoice.datasetdoc.mydns.bz
apt_kimsuky
domaininvoice.memberlogcheck.mydns.bz
apt_kimsuky
domainmemberlogcheck.mydns.bz
apt_kimsuky
domainndocaipass.dynv6.net
apt_kimsuky
domainndocampass.dynv6.net
apt_kimsuky
domainndocaopass.dynv6.net
apt_kimsuky
domainusr.investinfdoc.mydns.bz
apt_kimsuky
domainwebdriver-terminal.vg
lummac2
domain1drop.cfd
osx_nova
domainapd-todesk.com.cn
fakeapp
domaincn-google-ch.com.cn
fakeapp
domaincn-google-google-zh.hl.cn
fakeapp
domaincn-www-google.com.cn
fakeapp
domainqishui0.com
fakeapp
domainsodamusic-app.com
fakeapp
domaintorproject.org.cn
fakeapp
domainchampionships-peoples-point-cassette.trycloudflare.com
hacked_trivy
domaininvestigation-launches-hearings-copying.trycloudflare.com
hacked_trivy
domainsouls-entire-defined-routes.trycloudflare.com
hacked_trivy
domainwasafaisalabad.gop.pk
fakeapp

Threat ID: 69c00b23f4197a8e3b82758b

Added to database: 3/22/2026, 3:30:43 PM

Last enriched: 3/22/2026, 3:45:55 PM

Last updated: 3/23/2026, 1:02:56 AM

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses