Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-05-20

0
Medium
Published: Tue May 19 2026 (05/19/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed
Vendor/Project: tlp
Product: clear

Description

Maltrail IOC for 2026-05-20

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/20/2026, 22:33:43 UTC

Technical Analysis

The report details a malware-related IOC published by CIRCL OSINT Feed on 2026-05-20. It is categorized under OSINT and network activity with medium risk but lacks specific technical indicators, affected versions, or exploit details. No patch or vendor remediation exists, and it is primarily an observational threat intelligence entry.

Potential Impact

The impact is medium risk based on the source classification, indicating potential malware activity detected in network traffic. However, no known exploits or direct vulnerabilities are identified, and no specific affected products or versions are listed. This suggests a general threat awareness rather than an immediate exploitable condition.

Mitigation Recommendations

No patch or official remediation is available or applicable for this IOC. Security teams should incorporate this IOC into their threat detection and monitoring systems as part of ongoing OSINT-based situational awareness. No urgent action is required beyond standard monitoring aligned with this intelligence.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
10c39115-7be2-45d1-884f-8125733c1b92
Original Timestamp
1779314408

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f9324a40cdba2fc8c6e71245aa98be2c0d17f04c
apt_kimsuky
urlhttps://x.com/skocherhan/status/2057172575889789202
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f20c6823363a1cd1b330b4b4a9891beec7f27aec
lummac2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/e202683c7f0d46980803d6b05a038f2b819a43b2
magentocore
urlhttps://api.github.com/repos/stamparm/maltrail/commits/581025fa091e6a2594d7a849980caa94b438a982
fakeapp
urlhttps://x.com/Malwarehunterr/status/2057196561172689389
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7f01ccd57edb32d4cbdc3b82f75dd5daccaa1d64
apt_unc6691
urlhttps://safedep.io/art-template-npm-supply-chain-compromise
apt_unc6691
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5fa2e456bfb5bd5aa84578ec621fd5d52a593d04
osx_atomic
urlhttps://www.virustotal.com/gui/file/759b99a5241122a5ae61dca204f7ec5659f2a7ca4b3201928dd9b95aa97d38ca/detection
osx_atomic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/19dcc8795f3227e2724772f197c298a5412ed826
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/8ae5a9b55d46fa5e8268e5d27f433aed80072c62
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/01e17915b0aa710b6a9297b6f2c7de339749b735
hacked_npmrepos
urlhttps://x.com/abh1sek/status/2057104532451307987
hacked_npmrepos
urlhttps://github.com/goofychris/art-template/issues/665
hacked_npmrepos
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ba2d5d19eab207a0f65214ec306a6a7370ac266c
hacked_npmrepos
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1589485ccaea4cf4742ed458a7df012c81528fde
hacked_npmrepos
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ea86f60b9b4becde86893138ba01436234f4829e
powershell_injector
urlhttps://www.virustotal.com/gui/file/0347783bb2984a9cd014e1f284b13fff0651eaa0d920851adf38643e178b60d6/detection
powershell_injector
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4730a1adcfa72c26f518abdb6ef503ca2e6ca925
remcos
urlhttps://www.virustotal.com/gui/file/0434b0a1e55bf612d4ee50d1b851b6d0c560a27c3e88136dd71cc550b15b9813/detection
remcos
urlhttps://api.github.com/repos/stamparm/maltrail/commits/376216e20f61e4500902e65e60674a54639af843
hacked_npmrepos
urlhttps://x.com/tuckner/status/2056826907421823231
hacked_npmrepos
urlhttps://x.com/tuckner/status/2057078903663993343
hacked_npmrepos
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a5be430ba36aef737add06115d8ad9bdc7e0d66b
fakeapp
urlhttps://x.com/_tdatwja/status/2056980156372398281
fakeapp
urlhttps://www.virustotal.com/gui/file/e7ea5eb83bf6e9b1cc603ca13c0f363b164ccb712fbf90300cc52e91c53e2e08/detection
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5b542169c0cbc2f6ed45e796a8121f22b9755b6e
fakeapp
urlhttps://www.virustotal.com/gui/file/7ef770d7f400e4cb20ee98f64841f772e6f2238f13c93080e55beb1ff767dd03/detection
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/887cb6c98b4772ba25a189311283c50486a1d53c
fakeapp
urlhttps://x.com/_tdatwja/status/2056597011395404036
fakeapp
urlhttps://www.virustotal.com/gui/file/8d4674d062877c3a0177b4b0deff8b344794ed58d857b98f831a3abb0b797187/detection
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/823076797ad2ba5b2bfdca1ff111e5b4eb89a9a3
offloader
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f3d0cd8be91b67e7ae15bc7a87f7e8e9c810dc0a
vacbot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d3f231e64d61e7c11ffe6f8c93ecd678c038ebdf
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1cdab403dccdf53633ab6df0739ea2927239c54c
quasarrat
urlhttps://x.com/smica83/status/2057057509479727194
quasarrat
urlhttps://www.virustotal.com/gui/file/ffcee98683cf69d52232ceb890a778ec958b861509bdc55561ffe6b0a421afa8/detection
quasarrat
urlhttps://www.virustotal.com/gui/file/afbc44948f92625a926ef370192294cc30b303f0476656002f990e9506defa83/detection
quasarrat
urlhttps://www.virustotal.com/gui/file/631170f9174d4c21df4d14027de4a18459f64ac70a8c2dce3459c334433a0f31/detection
quasarrat
urlhttps://www.virustotal.com/gui/file/437461c3abc56cf90c1d460bb18e8420e077d0a36d16e3fa9ab7d22c324183df/detection
quasarrat
urlhttps://api.github.com/repos/stamparm/maltrail/commits/8c0e045295729c1a987f24b5ad570f7e75695d12
hacked_npmrepos
urlhttps://github.com/nrwl/nx-console/issues/3139
hacked_npmrepos
urlhttps://api.github.com/repos/stamparm/maltrail/commits/dc8c6c38063ac2d2ea4fe76179e719b40e629ca5
magentocore
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c5e91bb54bb3a6c60971030645fcf177e6b4ae58
android_fvncbot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/677b7967f8ebea3c9f3a2b386305ea88738f8e7e
apt_unc2465
urlhttps://api.github.com/repos/stamparm/maltrail/commits/3ea392d3640ac44520eb4fddb233743bdb903b10
mythic
urlhttps://x.com/malwrhunterteam/status/2057044039728324798
mythic
urlhttps://www.virustotal.com/gui/file/daced91764437bd79a5e4fb1ce568f4657b78fc11fb20e22d19c22f4eb7095bf/detection
mythic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/92971ada2cf5bcbc0efff429a60587e6389343c3
magentocore
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7e0bd4669de7117d399d538a58a24a341ae7c752
magentocore
urlhttps://x.com/sdcyberresearch/status/2056323429779886349
magentocore
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ec32238ca53275db805fc4f2fc14846b8a94267d
powershell_injector
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7fb07001b702b96e6cde55d3ee4b8bb0a940a249
fakeapp
urlhttps://x.com/skocherhan/status/2057207628711821594
fakeapp

Domain

ValueDescriptionCopy
domain2u9f.2usrmmwwduz.dns.navy
apt_kimsuky
domain2usrmmwwduz.dns.navy
apt_kimsuky
domain6td4w.mj9tqlj86sz.dns.navy
apt_kimsuky
domain923h5qvvzq2.v6.navy
apt_kimsuky
domainflbsbn.zsf31ayvobt.dns.navy
apt_kimsuky
domainguidetx.suredoc.net
apt_kimsuky
domainmareqsutxn.v6.navy
apt_kimsuky
domainmj9tqlj86sz.dns.navy
apt_kimsuky
domainncloud.casacam.net
apt_kimsuky
domainndoc.ncloud.casacam.net
apt_kimsuky
domainnid-log-pl.2u9f.2usrmmwwduz.dns.navy
apt_kimsuky
domainnid-token.tkho.mareqsutxn.v6.navy
apt_kimsuky
domainnidmois.p0fx8.923h5qvvzq2.v6.navy
apt_kimsuky
domainnidsign.mylogisoft.com
apt_kimsuky
domainninvoice.parentinvolvement.in
apt_kimsuky
domainninvoice.taxcloud.kro.kr
apt_kimsuky
domainp0fx8.923h5qvvzq2.v6.navy
apt_kimsuky
domainpol-go-nid.6td4w.mj9tqlj86sz.dns.navy
apt_kimsuky
domainpol-go-nid.flbsbn.zsf31ayvobt.dns.navy
apt_kimsuky
domaintaxcloud.kro.kr
apt_kimsuky
domaintkho.mareqsutxn.v6.navy
apt_kimsuky
domaintoxcloud.dns.army
apt_kimsuky
domainvvg1ylsb4a7.dns.navy
apt_kimsuky
domainzsf31ayvobt.dns.navy
apt_kimsuky
domainpantofr.cyou
lummac2
domainwpcdnwsswp.com
magentocore
domainainalapitool.online
fakeapp
domainasifapi.xyz
fakeapp
domainbiplobapi.xyz
fakeapp
domainhasanapi.xyz
fakeapp
domainjasimapi.xyz
fakeapp
domainlahinapi.xyz
fakeapp
domainmilonapi.xyz
fakeapp
domainronyapi.xyz
fakeapp
domainsohanapi.xyz
fakeapp
domainsohelapitool.online
fakeapp
domaintmrlapi.xyz
fakeapp
domaintoolapipanel.online
fakeapp
domaincall-video.website
fakeapp
domaindue-chat.call-video.website
fakeapp
domaindue-live-call.online
fakeapp
domaindue.live-video-call.my.id
fakeapp
domainduolivecall-googel.com
fakeapp
domainecortbabylon.site
fakeapp
domaingiooga.com
fakeapp
domaingoogle-meets.videos-chat.my.id
fakeapp
domaingooglemeetjoin.live
fakeapp
domaingooglemeetjoin.site
fakeapp
domaingooqle-duo.my.id
fakeapp
domaingooqle-live.com
fakeapp
domaingooqle-mapa.com
fakeapp
domaingooqle-mapsse.com
fakeapp
domaingooqle-meet-call-join.4-aa.com
fakeapp
domaingooqle-meet-call-live.1-a5.com
fakeapp
domaingooqle-meet-call.com
fakeapp
domaingooqle-meet-live-call.0-1h.com
fakeapp
domaingooqle-meet-live-call.com
fakeapp
domaingooqle-meet-live-call.my.id
fakeapp
domaingooqle-meet-live-call.s-81.com
fakeapp
domaingooqle-meet-live-call.shop
fakeapp
domaingooqle-meet-live-join.0-8a.com
fakeapp
domaingooqle-meet-live.2-1x.com
fakeapp
domaingooqle-meet-lives-call.my.id
fakeapp
domaingooqle-meet-lives-calls.my.id
fakeapp
domaingooqle-meet.live-join.com
fakeapp
domaingooqle-meet.view-chats.com
fakeapp
domaingooqle-meet.view-lives.com
fakeapp
domaingooqlemeet-livecall.com
fakeapp
domaingooqles-meet-live-call.my.id
fakeapp
domainjob-application.advice4.net
fakeapp
domainjoin-gooqle-meet.my.id
fakeapp
domainjoin-meet-gooqle.com
fakeapp
domainlive-call-chat.com
fakeapp
domainlive-gooqle-due-online.com
fakeapp
domainlive-join-gooqle-meet.4-c4.com
fakeapp
domainlive-join-gooqle-meet.4-c5.com
fakeapp
domainlive-join-gooqle-meet.4-c7.com
fakeapp
domainlive-join-gooqle-meet.my.id
fakeapp
domainlive-join.com
fakeapp
domainlive-video-call.my.id
fakeapp
domainlive-view-join.com
fakeapp
domainlive.gooqle-due-online.com
fakeapp
domainlivemeetcall.xyz
fakeapp
domainmeet-auto-live.0-la.com
fakeapp
domainmeet-auto-live.website
fakeapp
domainmeet-auto.demo-links.shop
fakeapp
domainmeet-gooqle-call.online
fakeapp
domainmeet-gooqle-live.online
fakeapp
domainmeet-live-call-chat.store
fakeapp
domainmeet-live-view-join.shop
fakeapp
domainmeet-video-calls.1-l8.com
fakeapp
domainmeet-video-calls.live
fakeapp
domainmeet.giooga.com
fakeapp
domainmeet.gooqle-live.com
fakeapp
domainmeet.gooqle-mapa.com
fakeapp
domainmeet.gooqle-mapaps.my.id
fakeapp
domainmeet.gooqle-mapsse.com
fakeapp
domainmeet.live-call-chat.com
fakeapp
domainmeet.live-view-join.com
fakeapp
domainruhol.advice4.net
fakeapp
domainvideo-call-meet.my.id
fakeapp
domainvideo-call.my.id
fakeapp
domainvideos-chat.my.id
fakeapp
domainview-chats.com
fakeapp
domainview-lives.com
fakeapp
domaincfww.shop
apt_unc6691
domainutaq.cfww.shop
apt_unc6691
domain0fx7qmdggegytul.xyz
apt_unc6691
domain1an94xtp37j04rh.xyz
apt_unc6691
domain23hs16uua03wc37.xyz
apt_unc6691
domain2n8psx9r4rbu4ym.xyz
apt_unc6691
domain4laqouz21lrm4qa.xyz
apt_unc6691
domain4z1jn2d6f95ab6o.xyz
apt_unc6691
domain5hz5vevyy0sccxx.xyz
apt_unc6691
domain6y3r7895ec4ucxd.xyz
apt_unc6691
domain7kvgccspqu66khd.xyz
apt_unc6691
domain82lqwfoid9uh03u.xyz
apt_unc6691
domain8d3x413aph9yel4.xyz
apt_unc6691
domain93ulni68qu7fkqt.xyz
apt_unc6691
domain9pzx64gxoro0o8t.xyz
apt_unc6691
domaina1t5ps59bvg58nl.xyz
apt_unc6691
domainaygd82dymm4kpw4.xyz
apt_unc6691
domainc3atzhavt9t3drw.xyz
apt_unc6691
domaincb6b06ev3e789cy.xyz
apt_unc6691
domainct1boy78fhhbi7b.xyz
apt_unc6691
domaind1q2kfw4wj6a1p0.xyz
apt_unc6691
domaind95l3efcegbrma2.xyz
apt_unc6691
domaing3knq19zsveuvux.xyz
apt_unc6691
domaingkxtguomb5mrs16.xyz
apt_unc6691
domainhivkaimrsrbnuek.xyz
apt_unc6691
domainisllczzovdlvg5s.xyz
apt_unc6691
domainj7bvmd04ttsyua6.xyz
apt_unc6691
domainje43wrtxf8j27rm.xyz
apt_unc6691
domainkm974980kv49sf2.xyz
apt_unc6691
domainl1ewsu3yjkqeroy.xyz
apt_unc6691
domainmxjht88dwegvaku.xyz
apt_unc6691
domainned0e3bwqooh4kz.xyz
apt_unc6691
domainnpihetcniyq5ymb.xyz
apt_unc6691
domainodntitrx9mulxf0.xyz
apt_unc6691
domainog2yyl3vgizq6rx.xyz
apt_unc6691
domainq6762dzwtgypc80.xyz
apt_unc6691
domainq6ouy6sewocm3sy.xyz
apt_unc6691
domainqcpujc0ep5ujntz.xyz
apt_unc6691
domaint6ptmj5tay5s5p8.xyz
apt_unc6691
domaintpl09o77v75fygn.xyz
apt_unc6691
domainukgwi7hotwlzpnp.xyz
apt_unc6691
domainwvd1u78mc4tvk1l.xyz
apt_unc6691
domainx2wy5e652cjcmvl.xyz
apt_unc6691
domainx8fdyv0vp4txtfi.xyz
apt_unc6691
domainxjclgn6ospcjvci.xyz
apt_unc6691
domainxy7bhvf7s4fiz42.xyz
apt_unc6691
domainyagy548ag5zlsrf.xyz
apt_unc6691
domainyauo3bdp0fqu9hb.xyz
apt_unc6691
domainyw5jbbhgzqe3gnq.xyz
apt_unc6691
domainzu44xabg5ak3pxt.xyz
apt_unc6691
domaindrivinguber.com
osx_atomic
domainyouzzjizz.com
hacked_npmrepos
domaingit.youzzjizz.com
hacked_npmrepos
domainv3.jiathis.com
hacked_npmrepos
domainkarasb.com
hacked_npmrepos
domainapp-wendinggo.com
fakeapp
domainearthstring.space
offloader
domainselectionaftermath.xyz
offloader
domaink1be.yu95pzwvz84.dns.navy
apt_kimsuky
domainndocsuppport.dns.army
apt_kimsuky
domainnid-naverdlc.servequake.com
apt_kimsuky
domainnid.ndocsuppport.dns.army
apt_kimsuky
domainnidsec.dns.army
apt_kimsuky
domainnidsign.k1be.yu95pzwvz84.dns.navy
apt_kimsuky
domainnopts.xubi.org
apt_kimsuky
domainopenuasermdoc19s.dns.army
apt_kimsuky
domainopenuasermdoc21s.dns.army
apt_kimsuky
domainopenuasermdoc34s.dns.army
apt_kimsuky
domainyu95pzwvz84.dns.navy
apt_kimsuky
domainslsa-framework.github.io
hacked_npmrepos
domain9i.campdevanolg.lol
magentocore
domainsocket-analytics.org
magentocore
domainyo.exiverse.lol
magentocore
domaineefage.icu
android_fvncbot
domainiimna.icu
android_fvncbot
domainionnemt.icu
android_fvncbot
domainoirnme.icu
android_fvncbot
domain40.workbencse.com
apt_unc2465
domain4l.rvtoolslab.com
apt_unc2465
domainfluxelyx.com
apt_unc2465
domainorlandoapt.com
apt_unc2465
domainrychlereseni.com
apt_unc2465
domainsubito-fatto.com
apt_unc2465
domainvert-feu.com
apt_unc2465
domainworkbencse.com
apt_unc2465
domainyx.rvtooli.info
apt_unc2465
domainteenvogue.icu
mythic
domain11.fastcdnjs.net
magentocore
domainjartrack.com
magentocore
domainxr.jartrack.com
magentocore
domainb2banalytics.org
magentocore
domaincertanalytics.com
magentocore
domaincommerce-flow.net
magentocore
domaincrmflow24.com
magentocore
domaincrmflow365.com
magentocore
domainecomm365.net
magentocore
domainfastcdnjs.net
magentocore
domainarendje.jsdelive.com
magentocore
domainshop.jsdelive.com
magentocore
domaincloudevos.xyz
powershell_injector
domaintrustnewusacool.xyz
powershell_injector
domainconnectnowlives.vercel.app
fakeapp
domainliveconnetionow.vercel.app
fakeapp
domainlivlocationow.netlify.app
fakeapp
domainmyliveloationnow.vercel.app
fakeapp
domainteal-chimera-f00ab1.netlify.app
fakeapp
domainview-location-for-us.link
fakeapp

Ip

ValueDescriptionCopy
ip195.201.194.107
apt_lazarus
ip23.254.203.244
hacked_npmrepos
ip23.254.164.61
hacked_npmrepos
ip23.254.164.92
hacked_npmrepos
ip151.243.109.130
powershell_injector
ip38.47.227.212
fakeapp
ip43.165.179.173
fakeapp
ip157.173.113.151
vacbot
ip103.45.66.52
quasarrat

Threat ID: 6a0e332fba1db47362b04512

Added to database: 5/20/2026, 10:18:23 PM

Last enriched: 5/20/2026, 10:33:43 PM

Last updated: 5/21/2026, 4:26:07 AM

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses