Maltrail IOC for 2026-05-18
This entry reports a medium-severity malware-related Indicator of Compromise (IOC) from the CIRCL OSINT Feed dated 2026-05-18. It is categorized as an external analysis of network activity but does not specify affected software versions or technical exploitation details. No known exploits in the wild or patches are available for this threat. The information is based on manual OSINT collection and is intended for ongoing observation rather than immediate remediation.
AI Analysis
Technical Summary
The report details a malware-related IOC identified on 2026-05-18 from the CIRCL OSINT Feed. It is classified as medium risk and involves network activity analysis. No specific affected product versions or vulnerabilities are listed, and no known active exploits have been reported. The threat intelligence is derived from manual collection and is intended to support situational awareness rather than indicate an active exploit requiring patching.
Potential Impact
The impact is currently limited to detection and observation of potentially malicious network activity. There is no evidence of active exploitation or direct compromise reported. No affected software versions or systems are identified, and no known exploits in the wild have been confirmed.
Mitigation Recommendations
No patch or official remediation is available or required at this time. Security teams should incorporate this IOC into their monitoring and detection tools as appropriate. Since this is an OSINT observation without active exploitation, no urgent action is mandated.
Indicators of Compromise
- url: https://api.github.com/repos/stamparm/maltrail/commits/887d6ed3812144cb654c58de5130a5bea81b3483
- domain: 1v.rvtootsad.com
- domain: 2a.rvtoolso.info
- domain: 2j.rvtoolsup.com
- domain: nexiqora.com
- domain: pacs4less.com
- domain: s.workbanch.com
- domain: workbecn.com
- domain: y0.workbecn.com
- domain: yr.rvtoolc.info
- url: https://api.github.com/repos/stamparm/maltrail/commits/063c7b18381113b77de37bf53a19ec50de70f5d9
- ip: 139.224.14.4
- ip: 154.193.246.65
- ip: 2.27.7.195
- ip: 38.76.198.132
- ip: 8.135.46.127
- ip: 91.92.243.190
- domain: 15-93-33-89.07internet.ro
- domain: drb420.ru
- domain: fortvector.vip
- domain: mangoworks.win
- domain: maolou.cn
- url: https://api.github.com/repos/stamparm/maltrail/commits/2bd6f8199383ee1f10be9e7516f80862fc79db39
- url: https://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here
- ip: 80.200.28.28
- domain: 87e0bbc636999b.lhr.life
- domain: b94b6bcfa27554.lhr.life
- url: https://api.github.com/repos/stamparm/maltrail/commits/389c8dab462f3fd730d35a0194541c6d7049f3ee
- url: https://www.virustotal.com/gui/ip-address/2.26.74.89/relations
- domain: brownhc.cyou
- domain: clamsal.cyou
- domain: diospfj.cyou
- domain: maenade.cyou
- domain: markzsa.cyou
- domain: shenyac.cyou
- domain: wifflvy.cyou
- url: https://api.github.com/repos/stamparm/maltrail/commits/e98dc3b2a6c7684965dbf490fd656c8ffc48dacc
- domain: astrealheaven.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/0fc87d9cf3bb20bb9e6d9c4290e870e49b546a55
- url: https://x.com/Fact_Finder03/status/2056203591447417249
- url: https://www.virustotal.com/gui/file/ab2df544db70a9af9ae70572c5eab2ec213a0e03544dca643719729f55f518c4/detection
- url: https://www.virustotal.com/gui/file/f1c55cbe1c6f840091aa44c4ecf58003915890a9ac834407fa3c4c77c4267709/detection
- ip: 212.193.3.220
- url: https://api.github.com/repos/stamparm/maltrail/commits/5aff9f0a0069b070721a4afafbd0e8667faf06ab
- url: https://redasgard.com/blog/hunting-lazarus-part5-eleven-hours-on-his-disk
- ip: 144.172.89.198
- ip: 195.201.104.53
- ip: 216.126.227.239
- url: https://api.github.com/repos/stamparm/maltrail/commits/a7e6d2ac76cbb41fd09a44a23934b191b58e7254
- url: https://x.com/G60930953/status/2056141941515899146
- url: https://www.virustotal.com/gui/file/4fd1303c5e3b5c9449df85c127e4bcfc68eceac912136e7539898b24d0064e58/detection
- domain: alidoh.com
- domain: dns1.alidoh.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/f86fbecefd0c6b47eb29a440cd7ff45e4f87be67
- ip: 86.48.17.18
- url: https://api.github.com/repos/stamparm/maltrail/commits/cfb474117887a87c5f62650d2a0ba361ddf1f774
- domain: bnaneui.icu
- domain: eqavbd.icu
- domain: etbabn.icu
- domain: ibbatrt.icu
- domain: iuyebn.icu
- url: https://api.github.com/repos/stamparm/maltrail/commits/78e2c0f6c37c386c878e9ae3c2637759f95e82d6
- ip: 188.137.178.24
- ip: 212.43.148.105
- ip: 212.43.148.167
- ip: 212.43.148.237
- ip: 89.105.213.149
- ip: 89.110.68.28
- url: https://api.github.com/repos/stamparm/maltrail/commits/65d551c4d69970618e9f68cef244b4a98853dd2a
- domain: chtyu.uno
Maltrail IOC for 2026-05-18
Description
This entry reports a medium-severity malware-related Indicator of Compromise (IOC) from the CIRCL OSINT Feed dated 2026-05-18. It is categorized as an external analysis of network activity but does not specify affected software versions or technical exploitation details. No known exploits in the wild or patches are available for this threat. The information is based on manual OSINT collection and is intended for ongoing observation rather than immediate remediation.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The report details a malware-related IOC identified on 2026-05-18 from the CIRCL OSINT Feed. It is classified as medium risk and involves network activity analysis. No specific affected product versions or vulnerabilities are listed, and no known active exploits have been reported. The threat intelligence is derived from manual collection and is intended to support situational awareness rather than indicate an active exploit requiring patching.
Potential Impact
The impact is currently limited to detection and observation of potentially malicious network activity. There is no evidence of active exploitation or direct compromise reported. No affected software versions or systems are identified, and no known exploits in the wild have been confirmed.
Mitigation Recommendations
No patch or official remediation is available or required at this time. Security teams should incorporate this IOC into their monitoring and detection tools as appropriate. Since this is an OSINT observation without active exploitation, no urgent action is mandated.
Technical Details
- Uuid
- 50844ee8-3e79-4e60-a7c4-a98f68856e9b
- Original Timestamp
- 1779094815
Indicators of Compromise
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://api.github.com/repos/stamparm/maltrail/commits/887d6ed3812144cb654c58de5130a5bea81b3483 | apt_unc2465 | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/063c7b18381113b77de37bf53a19ec50de70f5d9 | cyberstrikeai | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/2bd6f8199383ee1f10be9e7516f80862fc79db39 | hacked_npmrepos | |
urlhttps://www.ox.security/blog/new-actors-deploy-shai-hulud-clones-teampcp-copycats-are-here | hacked_npmrepos | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/389c8dab462f3fd730d35a0194541c6d7049f3ee | lummac2 | |
urlhttps://www.virustotal.com/gui/ip-address/2.26.74.89/relations | lummac2 | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/e98dc3b2a6c7684965dbf490fd656c8ffc48dacc | microstealer | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/0fc87d9cf3bb20bb9e6d9c4290e870e49b546a55 | discordgrabber | |
urlhttps://x.com/Fact_Finder03/status/2056203591447417249 | discordgrabber | |
urlhttps://www.virustotal.com/gui/file/ab2df544db70a9af9ae70572c5eab2ec213a0e03544dca643719729f55f518c4/detection | discordgrabber | |
urlhttps://www.virustotal.com/gui/file/f1c55cbe1c6f840091aa44c4ecf58003915890a9ac834407fa3c4c77c4267709/detection | discordgrabber | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5aff9f0a0069b070721a4afafbd0e8667faf06ab | apt_lazarus | |
urlhttps://redasgard.com/blog/hunting-lazarus-part5-eleven-hours-on-his-disk | apt_lazarus | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a7e6d2ac76cbb41fd09a44a23934b191b58e7254 | vshell | |
urlhttps://x.com/G60930953/status/2056141941515899146 | vshell | |
urlhttps://www.virustotal.com/gui/file/4fd1303c5e3b5c9449df85c127e4bcfc68eceac912136e7539898b24d0064e58/detection | vshell | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f86fbecefd0c6b47eb29a440cd7ff45e4f87be67 | vacbot | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/cfb474117887a87c5f62650d2a0ba361ddf1f774 | android_fvncbot | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/78e2c0f6c37c386c878e9ae3c2637759f95e82d6 | sectoprat | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/65d551c4d69970618e9f68cef244b4a98853dd2a | android_joker |
Domain
| Value | Description | Copy |
|---|---|---|
domain1v.rvtootsad.com | apt_unc2465 | |
domain2a.rvtoolso.info | apt_unc2465 | |
domain2j.rvtoolsup.com | apt_unc2465 | |
domainnexiqora.com | apt_unc2465 | |
domainpacs4less.com | apt_unc2465 | |
domains.workbanch.com | apt_unc2465 | |
domainworkbecn.com | apt_unc2465 | |
domainy0.workbecn.com | apt_unc2465 | |
domainyr.rvtoolc.info | apt_unc2465 | |
domain15-93-33-89.07internet.ro | cyberstrikeai | |
domaindrb420.ru | cyberstrikeai | |
domainfortvector.vip | cyberstrikeai | |
domainmangoworks.win | cyberstrikeai | |
domainmaolou.cn | cyberstrikeai | |
domain87e0bbc636999b.lhr.life | hacked_npmrepos | |
domainb94b6bcfa27554.lhr.life | hacked_npmrepos | |
domainbrownhc.cyou | lummac2 | |
domainclamsal.cyou | lummac2 | |
domaindiospfj.cyou | lummac2 | |
domainmaenade.cyou | lummac2 | |
domainmarkzsa.cyou | lummac2 | |
domainshenyac.cyou | lummac2 | |
domainwifflvy.cyou | lummac2 | |
domainastrealheaven.com | microstealer | |
domainalidoh.com | vshell | |
domaindns1.alidoh.com | vshell | |
domainbnaneui.icu | android_fvncbot | |
domaineqavbd.icu | android_fvncbot | |
domainetbabn.icu | android_fvncbot | |
domainibbatrt.icu | android_fvncbot | |
domainiuyebn.icu | android_fvncbot | |
domainchtyu.uno | android_joker |
Ip
| Value | Description | Copy |
|---|---|---|
ip139.224.14.4 | cyberstrikeai | |
ip154.193.246.65 | cyberstrikeai | |
ip2.27.7.195 | cyberstrikeai | |
ip38.76.198.132 | cyberstrikeai | |
ip8.135.46.127 | cyberstrikeai | |
ip91.92.243.190 | cyberstrikeai | |
ip80.200.28.28 | hacked_npmrepos | |
ip212.193.3.220 | discordgrabber | |
ip144.172.89.198 | apt_lazarus | |
ip195.201.104.53 | apt_lazarus | |
ip216.126.227.239 | apt_lazarus | |
ip86.48.17.18 | vacbot | |
ip188.137.178.24 | sectoprat | |
ip212.43.148.105 | sectoprat | |
ip212.43.148.167 | sectoprat | |
ip212.43.148.237 | sectoprat | |
ip89.105.213.149 | sectoprat | |
ip89.110.68.28 | sectoprat |
Threat ID: 6a0ada1aec166c07b0993e88
Added to database: 05/18/2026, 09:21:30 UTC
Last enriched: 05/25/2026, 19:32:26 UTC
Last updated: 07/31/2026, 11:15:59 UTC
Views: 267
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.