Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-05-17

0
Medium
Published: Sat May 16 2026 (05/16/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed
Vendor/Project: tlp
Product: clear

Description

Maltrail IOC for 2026-05-17

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/17/2026, 13:21:36 UTC

Technical Analysis

The report details a malware-related IOC detected by Maltrail on 2026-05-17, sourced from CIRCL OSINT Feed. It is classified as medium severity and relates to network activity observations. No affected versions or specific vulnerabilities are identified, and no exploits are known. The IOC serves as an open-source intelligence indicator for potential malware detection but lacks detailed technical or exploit information.

Potential Impact

The impact is currently limited to the identification of potential malware-related network activity. There is no evidence of active exploitation or direct compromise reported. Without specific affected versions or exploit details, the immediate risk to systems cannot be precisely determined.

Mitigation Recommendations

No patch or official remediation is available for this IOC. Security teams should consider integrating this IOC into their detection and monitoring tools to identify potential related activity. Since no active exploits are known, no urgent remediation is required beyond standard monitoring.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
6b353c07-62b4-4e43-8c4b-44bf0e52f2fe
Original Timestamp
1779019212

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f0dea21e80d782a39eefec8faa9aa4cf4324d930
donut
urlhttps://www.virustotal.com/gui/file/ef146f97c8fbc10e9ad485dbbf2227fa5943f62243c7a703c3900efbe700f6d8/detection
donut
urlhttps://api.github.com/repos/stamparm/maltrail/commits/75bb4db9c069c5e2d2a0a4de1c0545c0814c4021
osx_atomic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d6227508c5499bc99bd61aea832764e8899872a2
osx_atomic
urlhttps://x.com/brkalbyrk7/status/2055749987678486685
osx_atomic
urlhttps://gist.github.com/brkalbyrk/c7989c3d00a85bcfe0f3feaf4bf39e53
osx_atomic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/539bc996ac870ae74444463c1d89f597b8749089
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/0942591c7d5d50a60f3ea92611e38f166e54105b
powershell_injector
urlhttps://x.com/smica83/status/2055759040647495787
powershell_injector
urlhttps://www.virustotal.com/gui/file/efbbb83671301fa9e1fec081e4d943d8d180fa4e243ca16ba130099b2a158e88/detection
powershell_injector
urlhttps://www.virustotal.com/gui/file/ff69ca82c7e5d771b5da642b483683e852ed4d6facfc5c593e089480dc395a37/detection
powershell_injector
urlhttps://api.github.com/repos/stamparm/maltrail/commits/2f8cdfa5ce1e261e7dc4d361b656f2c08e331e86
magentocore
urlhttps://api.github.com/repos/stamparm/maltrail/commits/99fe77613fe75dd25ab06635f1b96a0b63751c52
android_fvncbot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ef5f2a3c1fa04d426c8ef0f811172498d8bd6a33
ek_landupdate808
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7ebbae992df17e6c24a22831db46f8646018568e
purelogs
urlhttps://www.virustotal.com/gui/file/8fffed6d1ce481d94a085b93ee5a553adb163c26c404548515b07b0a2392299c/detection
purelogs
urlhttps://api.github.com/repos/stamparm/maltrail/commits/6080cd76fc188313b793f085b1269006d0f540f8
android_joker

Domain

ValueDescriptionCopy
domainkelemet.shop
donut
domainrpcsecnoweb.pro
donut
domainsynapseops.info
osx_atomic
domaincloudsendhub.com
osx_atomic
domainfastlinkstorage.com
osx_atomic
domainfileconnectdata.com
osx_atomic
domainfiledropvault.com
osx_atomic
domainfilehubconnect.com
osx_atomic
domainfilemarbleplanet.sbs
osx_atomic
domainfilepixelstudio.com
osx_atomic
domainfilesecurelink.com
osx_atomic
domainfilesyncarchive.com
osx_atomic
domainfiletigerrocket.sbs
osx_atomic
domainmacbitmint.com
osx_atomic
domainmacbitport.com
osx_atomic
domainmaccloudgrid.com
osx_atomic
domainmaccloudloop.com
osx_atomic
domainmaccloudport.com
osx_atomic
domainmaccodedock.com
osx_atomic
domainmaccorelane.com
osx_atomic
domainmacpulselane.com
osx_atomic
domainmacquantlane.com
osx_atomic
domainplombirsirni.com
osx_atomic
domainpr-otokoiaiep.info
osx_atomic
domainprotokoiiaiepoiicja.info
osx_atomic
domainshare2e32git.sbs
osx_atomic
domainsharelinkdata.com
osx_atomic
domainsmartfilevault.com
osx_atomic
domainsyncfolderhub.com
osx_atomic
domain0g25r94p96.v6.army
apt_kimsuky
domain40n0.uvtiwwmlrl.dns.army
apt_kimsuky
domain4vkc4fdduf.dns.navy
apt_kimsuky
domain5jeqr9bf89.dns.navy
apt_kimsuky
domainacaiqb90ql.v6.navy
apt_kimsuky
domainaji1dfsici.dns.army
apt_kimsuky
domainbkkug0us2sj.dns.navy
apt_kimsuky
domainbux-nid.ips-go.gleeze.com
apt_kimsuky
domaind0vtzpoxyw.dynv6.net
apt_kimsuky
domainda9dz.kpq8p1t81e.dns.army
apt_kimsuky
domaindocinfo.ndocline-st51s.dns.army
apt_kimsuky
domaing7slrbjt7j.dynv6.net
apt_kimsuky
domainhost-nid.mywire.org
apt_kimsuky
domaininfo.mois-go.bumbleshrimp.com
apt_kimsuky
domaininfo.naver-log.ddnsfree.com
apt_kimsuky
domaininvoice-doc.camdvr.org
apt_kimsuky
domainips-check.1cooldns.com
apt_kimsuky
domainips-go.gleeze.com
apt_kimsuky
domainips-nav.abrdns.com
apt_kimsuky
domainkpq8p1t81e.dns.army
apt_kimsuky
domainmois-go.bumbleshrimp.com
apt_kimsuky
domainmtf-nid.ips-go.gleeze.com
apt_kimsuky
domainnauthlogin.dns.army
apt_kimsuky
domainnav-log.ips-check.1cooldns.com
apt_kimsuky
domainnaver-log.ddnsfree.com
apt_kimsuky
domainndoc-void.kozow.com
apt_kimsuky
domainndocline-st51s.dns.army
apt_kimsuky
domainndocnid.da9dz.kpq8p1t81e.dns.army
apt_kimsuky
domainnid.nauthlogin.dns.army
apt_kimsuky
domainnidlog.40n0.uvtiwwmlrl.dns.army
apt_kimsuky
domainninvoice.nisdn.1cooldns.com
apt_kimsuky
domainnisdn.1cooldns.com
apt_kimsuky
domainntt-suggest.host-nid.mywire.org
apt_kimsuky
domainntt-suggest.river-connect.ddnsguru.com
apt_kimsuky
domainpc3vq8gte2.dynv6.net
apt_kimsuky
domainpzyyckwlqm.v6.army
apt_kimsuky
domainqlrkm553jk.v6.army
apt_kimsuky
domainr8mcc7z7jb.dynv6.net
apt_kimsuky
domainredirect.abrdns.com
apt_kimsuky
domainriver-connect.ddnsguru.com
apt_kimsuky
domaintdoc.cloud-ip.cc
apt_kimsuky
domainuvtiwwmlrl.dns.army
apt_kimsuky
domainv3i2rde2y5.v6.navy
apt_kimsuky
domainwgjngrxokv.v6.army
apt_kimsuky
domainx1prl5k1a2.v6.army
apt_kimsuky
domainx94z3llzz6d.v6.navy
apt_kimsuky
domainya7taxdm520.dns.army
apt_kimsuky
domainz330woigb3.dns.army
apt_kimsuky
domainphotobook-reserv.pro
powershell_injector
domain10.folklorea.lol
magentocore
domainrefreshwp.net
magentocore
domainrefreshwpws.com
magentocore
domainrefreshws.com
magentocore
domainrefreshwss.com
magentocore
domainwpwsconnect.com
magentocore
domainwss-cdn.org
magentocore
domainasubne.icu
android_fvncbot
domainiinemar.icu
android_fvncbot
domainiomnan.icu
android_fvncbot
domainoimane.icu
android_fvncbot
domainqervbae.icu
android_fvncbot
domainqevbae.icu
android_fvncbot
domainxavcbb.icu
android_fvncbot
domainytbna.icu
android_fvncbot
domainzwthbae.icu
android_fvncbot
domaincorreia.lol
ek_landupdate808
domainroterts.lol
ek_landupdate808
domainpeper.help
android_joker

Ip

ValueDescriptionCopy
ip15.235.149.6
purelogs

Threat ID: 6a09bd56ec166c07b0c72dca

Added to database: 5/17/2026, 1:06:30 PM

Last enriched: 5/17/2026, 1:21:36 PM

Last updated: 5/20/2026, 7:48:55 PM

Views: 36

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses