Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-05-01

0
Medium
Published: Thu Apr 30 2026 (04/30/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed
Vendor/Project: tlp
Product: clear

Description

Maltrail IOC for 2026-05-01

Technical Details

Uuid
f9186f67-0632-4896-865a-6d5892a87f84
Original Timestamp
1777629615

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/46801441ea42e785687fd534cd810beee9f6e21d
teampcp
urlhttps://www.virustotal.com/gui/domain/masscan.cloud/relations
teampcp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/222deae65909c2808c6ab97a34d9684b8ec1d565
hacked_npmrepos
urlhttps://socket.dev/blog/mini-shai-hulud-packagist-malicious-intercom-php-package-compromise
hacked_npmrepos
urlhttps://api.github.com/repos/stamparm/maltrail/commits/0e98a857d596c67c4f2b01c898a60b23160e7ede
lummac2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/85fcaf583286e24a3b835cf1c44944f5ec222426
vacbot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/e38508d9e7a37175386205c07138fc2f4796f040
hacked_npmrepos
urlhttps://api.github.com/repos/stamparm/maltrail/commits/335e222de35d8c2ef0793ac74f7d5977f40beef9
offloader
urlhttps://api.github.com/repos/stamparm/maltrail/commits/436ea056c68107f613643ebfb569ebc4b5a033ba
lummac2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/bdf51145ee9c98071817eb06b317ab045797604d
android_fvncbot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ec2515e2df46dc2f981469bb1634e9d99b1b01cc
apt_donot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/eb8a00390eeb3647ad9b461128d38306424ffe60
apt_patchwork
urlhttps://api.github.com/repos/stamparm/maltrail/commits/422c4c85ec3595c66199b0dfe0efc5330408a27e
cyberstrikeai
urlhttps://api.github.com/repos/stamparm/maltrail/commits/bbdcbdbdf36572344b3e839439f1d252cd0f5c23
georgeginx
urlhttps://api.github.com/repos/stamparm/maltrail/commits/80c946b7a8c54b76258d5393d0c1796f4db83775
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/b000f54b9bf5e4be68912b912705af2a81a6a5c5
santa
urlhttps://api.github.com/repos/stamparm/maltrail/commits/091605c5554c87e249106d23559eab7ab84d93aa
hacked_cpanel
urlhttps://x.com/ctrlaltintel/status/2050143909209317439
hacked_cpanel
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a33da780b38a3a52d770016fbd36dd115d3f2537
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c1e4624c076b0054512776eb8a02b7f708eed126
lummac2

Domain

ValueDescriptionCopy
domainpcp.masscan.cloud
teampcp
domainzero.masscan.cloud
hacked_npmrepos
domainmoderxdrsolution.vg
lummac2
domaindomainzero.masscan.cloud
hacked_npmrepos
domainpicturemotion.info
offloader
domainspademen.cfd
offloader
domaintreesbrass.info
offloader
domainamericoq.cyou
lummac2
domainabnem.icu
android_fvncbot
domainertbane.icu
android_fvncbot
domainertdaep.icu
android_fvncbot
domainertvba.icu
android_fvncbot
domainfbneame.icu
android_fvncbot
domaininname.icu
android_fvncbot
domainpobne.icu
android_fvncbot
domainqexabe.icu
android_fvncbot
domainvbikea.icu
android_fvncbot
domainsolutionpelle.info
apt_donot
domainliststernia.com
apt_patchwork
domaingigvault.one
santa
domainwindowsupdate.sh
hacked_cpanel
domainfsecurity.ink
apt_kimsuky
domainmembership.ink
apt_kimsuky
domainncodcepass.dynv6.net
apt_kimsuky
domainnid-naverefo.serveftp.com
apt_kimsuky
domainnid-naverirv.servehalflife.com
apt_kimsuky
domainbahaisda.cyou
lummac2
domainbalvlqts.cyou
lummac2
domainbrakyfaw.cyou
lummac2
domaincudbweeo.cyou
lummac2
domainfourdigs.cyou
lummac2
domaingenxetia.cyou
lummac2
domainhonceybl.cyou
lummac2
domainmaloneyr.cyou
lummac2
domainmexzicaj.cyou
lummac2
domainmilnleny.cyou
lummac2
domainmistjlep.cyou
lummac2
domainprivahtc.cyou
lummac2
domainraventixa24.top
lummac2
domainstrainug.cyou
lummac2
domainwoshidashuaige.sbs
lummac2

Ip

ValueDescriptionCopy
ip82.39.109.55
vacbot
ip85.239.231.63
vacbot
ip178.156.132.188
cyberstrikeai
ip195.133.145.56
cyberstrikeai
ip206.119.173.47
cyberstrikeai
ip45.147.253.14
cyberstrikeai
ip47.79.34.97
cyberstrikeai
ip136.0.10.116
georgeginx
ip23.27.140.251
georgeginx
ip23.27.142.233
georgeginx
ip23.27.202.108
georgeginx
ip23.27.50.184
georgeginx
ip23.27.51.11
georgeginx
ip198.135.55.67
apt_lazarus
ip154.18.187.239
hacked_cpanel
ip154.18.239.238
hacked_cpanel

Threat ID: 69f48926cbff5d8610b69ae5

Added to database: 5/1/2026, 11:06:14 AM

Last updated: 5/1/2026, 11:06:26 AM

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses