Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-03-24

0
Medium
Published: Tue Mar 24 2026 (03/24/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed
Vendor/Project: tlp
Product: clear

Description

Maltrail IOC for 2026-03-24

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 04/08/2026, 04:19:40 UTC

Technical Analysis

The provided data describes a malware-related IOC published on 2026-03-24 by the CIRCL OSINT Feed. It is categorized as medium risk and is based on manual collection of open-source intelligence. There are no affected software versions identified, no known exploits, and no available patches. The IOC is primarily an observational report of suspicious network activity without further technical details or actionable indicators.

Potential Impact

The impact is currently limited to awareness of a medium-risk malware IOC without confirmed exploitation or direct vulnerability to specific software versions. No active exploits or patches are reported, indicating no immediate technical impact requiring remediation.

Mitigation Recommendations

No patch or official remediation is available for this IOC. Security teams should incorporate this IOC into their threat detection and monitoring systems as appropriate. No urgent action is required based on the current information.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
d1412427-b81f-4ad5-be0f-bb404d448aeb
Original Timestamp
1774339205

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/fc3d78d0db5e6d4006442ee4ae23d4c57f719fcf
apt_sidewinder
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d5a6e55d210c3077141509cb8200294d8d9f5709
android_fakeapp
urlhttps://x.com/SpiderLabs/status/2036076835889418406
android_fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/63e908ab0abb9fcf04c0a393485987abe1bb44ec
hacked_trivy
urlhttps://www.wiz.io/blog/teampcp-attack-kics-github-action
hacked_trivy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d4de73afbc24cd0d0b70fe788392232acb486051
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/77996e570aefc5688a3af37c05e9094059462cbd
android_joker
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4c86bbe470655e943b2c95c484d943f874e440f1
apt_unc2465
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f0f25f3b92bbc48018825d984d6d32ebbf333a5e
fakeapp

Domain

ValueDescriptionCopy
domaindp.islamic-finder.org
apt_sidewinder
domaindisanviet.homes
android_fakeapp
domainitrekker.space
android_fakeapp
domainmoitasec.com
android_fakeapp
domainocngongiare.com
android_fakeapp
domainthcsmyxa-nd.com
android_fakeapp
domaintourmini.site
android_fakeapp
domaincheckmarx.zone
hacked_trivy
domainhtax-store.dns.navy
apt_kimsuky
domainmtnvs.dynv6.net
apt_kimsuky
domainn-cloud.htax-store.dns.navy
apt_kimsuky
domainnid-user.tax-loadoc.dns.army
apt_kimsuky
domainntsncorp.dynv6.net
apt_kimsuky
domaintax-loadoc.dns.army
apt_kimsuky
domainahaw.pw
android_joker
domainrvtoollsa.com
apt_unc2465
domainrvtoollsi.com
apt_unc2465
domainchromium-report-tech-31as-2s1-tc2d-h143.redticker-ctft.com
fakeapp
domainredticker-ctft.com
fakeapp

Threat ID: 69c2482ff4197a8e3b034543

Added to database: 3/24/2026, 8:15:43 AM

Last enriched: 4/8/2026, 4:19:40 AM

Last updated: 5/7/2026, 5:33:34 AM

Views: 95

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses