Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-03-24

0
Medium
Published: 03/24/2026 (03/24/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed
Vendor/Project: tlp
Product: clear

Description

Maltrail IOC for 2026-03-24

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/10/2026, 02:23:51 UTC

Technical Analysis

The report details a malware-related IOC identified on 2026-03-24 from the CIRCL OSINT Feed. It is classified as medium risk and relates to network activity observed externally. No affected product versions or specific vulnerabilities are listed, and no exploit details or indicators of compromise are included. The threat is documented as an observation without actionable technical specifics or remediation options.

Potential Impact

The impact is currently limited to awareness of a medium-risk malware-related IOC. There are no known active exploits or vulnerabilities associated with this report, and no direct patch or mitigation is available. Organizations should consider this information as part of their threat intelligence but no immediate operational impact is indicated.

Mitigation Recommendations

No patch or official remediation is available for this IOC. Since it is an observational report without specific actionable indicators, no direct mitigation steps can be recommended. Security teams should monitor relevant threat intelligence sources for updates and incorporate this IOC into their detection capabilities if applicable.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
d1412427-b81f-4ad5-be0f-bb404d448aeb
Original Timestamp
1774339205

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/fc3d78d0db5e6d4006442ee4ae23d4c57f719fcf
apt_sidewinder
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d5a6e55d210c3077141509cb8200294d8d9f5709
android_fakeapp
urlhttps://x.com/SpiderLabs/status/2036076835889418406
android_fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/63e908ab0abb9fcf04c0a393485987abe1bb44ec
hacked_trivy
urlhttps://www.wiz.io/blog/teampcp-attack-kics-github-action
hacked_trivy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d4de73afbc24cd0d0b70fe788392232acb486051
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/77996e570aefc5688a3af37c05e9094059462cbd
android_joker
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4c86bbe470655e943b2c95c484d943f874e440f1
apt_unc2465
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f0f25f3b92bbc48018825d984d6d32ebbf333a5e
fakeapp

Domain

ValueDescriptionCopy
domaindp.islamic-finder.org
apt_sidewinder
domaindisanviet.homes
android_fakeapp
domainitrekker.space
android_fakeapp
domainmoitasec.com
android_fakeapp
domainocngongiare.com
android_fakeapp
domainthcsmyxa-nd.com
android_fakeapp
domaintourmini.site
android_fakeapp
domaincheckmarx.zone
hacked_trivy
domainhtax-store.dns.navy
apt_kimsuky
domainmtnvs.dynv6.net
apt_kimsuky
domainn-cloud.htax-store.dns.navy
apt_kimsuky
domainnid-user.tax-loadoc.dns.army
apt_kimsuky
domainntsncorp.dynv6.net
apt_kimsuky
domaintax-loadoc.dns.army
apt_kimsuky
domainahaw.pw
android_joker
domainrvtoollsa.com
apt_unc2465
domainrvtoollsi.com
apt_unc2465
domainchromium-report-tech-31as-2s1-tc2d-h143.redticker-ctft.com
fakeapp
domainredticker-ctft.com
fakeapp

Threat ID: 69c2482ff4197a8e3b034543

Added to database: 03/24/2026, 08:15:43 UTC

Last enriched: 05/10/2026, 02:23:51 UTC

Last updated: 07/24/2026, 16:57:53 UTC

Views: 187

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses