Maltrail IOC for 2026-05-20
Maltrail IOC for 2026-05-20
AI Analysis
Technical Summary
The report details a malware-related IOC published by CIRCL OSINT Feed on 2026-05-20. It is categorized under OSINT and network activity with medium risk but lacks specific technical indicators, affected versions, or exploit details. No patch or vendor remediation exists, and it is primarily an observational threat intelligence entry.
Potential Impact
The impact is medium risk based on the source classification, indicating potential malware activity detected in network traffic. However, no known exploits or direct vulnerabilities are identified, and no specific affected products or versions are listed. This suggests a general threat awareness rather than an immediate exploitable condition.
Mitigation Recommendations
No patch or official remediation is available or applicable for this IOC. Security teams should incorporate this IOC into their threat detection and monitoring systems as part of ongoing OSINT-based situational awareness. No urgent action is required beyond standard monitoring aligned with this intelligence.
Indicators of Compromise
- url: https://api.github.com/repos/stamparm/maltrail/commits/f9324a40cdba2fc8c6e71245aa98be2c0d17f04c
- url: https://x.com/skocherhan/status/2057172575889789202
- domain: 2u9f.2usrmmwwduz.dns.navy
- domain: 2usrmmwwduz.dns.navy
- domain: 6td4w.mj9tqlj86sz.dns.navy
- domain: 923h5qvvzq2.v6.navy
- domain: flbsbn.zsf31ayvobt.dns.navy
- domain: guidetx.suredoc.net
- domain: mareqsutxn.v6.navy
- domain: mj9tqlj86sz.dns.navy
- domain: ncloud.casacam.net
- domain: ndoc.ncloud.casacam.net
- domain: nid-log-pl.2u9f.2usrmmwwduz.dns.navy
- domain: nid-token.tkho.mareqsutxn.v6.navy
- domain: nidmois.p0fx8.923h5qvvzq2.v6.navy
- domain: nidsign.mylogisoft.com
- domain: ninvoice.parentinvolvement.in
- domain: ninvoice.taxcloud.kro.kr
- domain: p0fx8.923h5qvvzq2.v6.navy
- domain: pol-go-nid.6td4w.mj9tqlj86sz.dns.navy
- domain: pol-go-nid.flbsbn.zsf31ayvobt.dns.navy
- domain: taxcloud.kro.kr
- domain: tkho.mareqsutxn.v6.navy
- domain: toxcloud.dns.army
- domain: vvg1ylsb4a7.dns.navy
- domain: zsf31ayvobt.dns.navy
- url: https://api.github.com/repos/stamparm/maltrail/commits/f20c6823363a1cd1b330b4b4a9891beec7f27aec
- domain: pantofr.cyou
- url: https://api.github.com/repos/stamparm/maltrail/commits/e202683c7f0d46980803d6b05a038f2b819a43b2
- domain: wpcdnwsswp.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/581025fa091e6a2594d7a849980caa94b438a982
- url: https://x.com/Malwarehunterr/status/2057196561172689389
- domain: ainalapitool.online
- domain: asifapi.xyz
- domain: biplobapi.xyz
- domain: hasanapi.xyz
- domain: jasimapi.xyz
- domain: lahinapi.xyz
- domain: milonapi.xyz
- domain: ronyapi.xyz
- domain: sohanapi.xyz
- domain: sohelapitool.online
- domain: tmrlapi.xyz
- domain: toolapipanel.online
- domain: call-video.website
- domain: due-chat.call-video.website
- domain: due-live-call.online
- domain: due.live-video-call.my.id
- domain: duolivecall-googel.com
- domain: ecortbabylon.site
- domain: giooga.com
- domain: google-meets.videos-chat.my.id
- domain: googlemeetjoin.live
- domain: googlemeetjoin.site
- domain: gooqle-duo.my.id
- domain: gooqle-live.com
- domain: gooqle-mapa.com
- domain: gooqle-mapsse.com
- domain: gooqle-meet-call-join.4-aa.com
- domain: gooqle-meet-call-live.1-a5.com
- domain: gooqle-meet-call.com
- domain: gooqle-meet-live-call.0-1h.com
- domain: gooqle-meet-live-call.com
- domain: gooqle-meet-live-call.my.id
- domain: gooqle-meet-live-call.s-81.com
- domain: gooqle-meet-live-call.shop
- domain: gooqle-meet-live-join.0-8a.com
- domain: gooqle-meet-live.2-1x.com
- domain: gooqle-meet-lives-call.my.id
- domain: gooqle-meet-lives-calls.my.id
- domain: gooqle-meet.live-join.com
- domain: gooqle-meet.view-chats.com
- domain: gooqle-meet.view-lives.com
- domain: gooqlemeet-livecall.com
- domain: gooqles-meet-live-call.my.id
- domain: job-application.advice4.net
- domain: join-gooqle-meet.my.id
- domain: join-meet-gooqle.com
- domain: live-call-chat.com
- domain: live-gooqle-due-online.com
- domain: live-join-gooqle-meet.4-c4.com
- domain: live-join-gooqle-meet.4-c5.com
- domain: live-join-gooqle-meet.4-c7.com
- domain: live-join-gooqle-meet.my.id
- domain: live-join.com
- domain: live-video-call.my.id
- domain: live-view-join.com
- domain: live.gooqle-due-online.com
- domain: livemeetcall.xyz
- domain: meet-auto-live.0-la.com
- domain: meet-auto-live.website
- domain: meet-auto.demo-links.shop
- domain: meet-gooqle-call.online
- domain: meet-gooqle-live.online
- domain: meet-live-call-chat.store
- domain: meet-live-view-join.shop
- domain: meet-video-calls.1-l8.com
- domain: meet-video-calls.live
- domain: meet.giooga.com
- domain: meet.gooqle-live.com
- domain: meet.gooqle-mapa.com
- domain: meet.gooqle-mapaps.my.id
- domain: meet.gooqle-mapsse.com
- domain: meet.live-call-chat.com
- domain: meet.live-view-join.com
- domain: ruhol.advice4.net
- domain: video-call-meet.my.id
- domain: video-call.my.id
- domain: videos-chat.my.id
- domain: view-chats.com
- domain: view-lives.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/7f01ccd57edb32d4cbdc3b82f75dd5daccaa1d64
- url: https://safedep.io/art-template-npm-supply-chain-compromise
- domain: cfww.shop
- domain: utaq.cfww.shop
- domain: 0fx7qmdggegytul.xyz
- domain: 1an94xtp37j04rh.xyz
- domain: 23hs16uua03wc37.xyz
- domain: 2n8psx9r4rbu4ym.xyz
- domain: 4laqouz21lrm4qa.xyz
- domain: 4z1jn2d6f95ab6o.xyz
- domain: 5hz5vevyy0sccxx.xyz
- domain: 6y3r7895ec4ucxd.xyz
- domain: 7kvgccspqu66khd.xyz
- domain: 82lqwfoid9uh03u.xyz
- domain: 8d3x413aph9yel4.xyz
- domain: 93ulni68qu7fkqt.xyz
- domain: 9pzx64gxoro0o8t.xyz
- domain: a1t5ps59bvg58nl.xyz
- domain: aygd82dymm4kpw4.xyz
- domain: c3atzhavt9t3drw.xyz
- domain: cb6b06ev3e789cy.xyz
- domain: ct1boy78fhhbi7b.xyz
- domain: d1q2kfw4wj6a1p0.xyz
- domain: d95l3efcegbrma2.xyz
- domain: g3knq19zsveuvux.xyz
- domain: gkxtguomb5mrs16.xyz
- domain: hivkaimrsrbnuek.xyz
- domain: isllczzovdlvg5s.xyz
- domain: j7bvmd04ttsyua6.xyz
- domain: je43wrtxf8j27rm.xyz
- domain: km974980kv49sf2.xyz
- domain: l1ewsu3yjkqeroy.xyz
- domain: mxjht88dwegvaku.xyz
- domain: ned0e3bwqooh4kz.xyz
- domain: npihetcniyq5ymb.xyz
- domain: odntitrx9mulxf0.xyz
- domain: og2yyl3vgizq6rx.xyz
- domain: q6762dzwtgypc80.xyz
- domain: q6ouy6sewocm3sy.xyz
- domain: qcpujc0ep5ujntz.xyz
- domain: t6ptmj5tay5s5p8.xyz
- domain: tpl09o77v75fygn.xyz
- domain: ukgwi7hotwlzpnp.xyz
- domain: wvd1u78mc4tvk1l.xyz
- domain: x2wy5e652cjcmvl.xyz
- domain: x8fdyv0vp4txtfi.xyz
- domain: xjclgn6ospcjvci.xyz
- domain: xy7bhvf7s4fiz42.xyz
- domain: yagy548ag5zlsrf.xyz
- domain: yauo3bdp0fqu9hb.xyz
- domain: yw5jbbhgzqe3gnq.xyz
- domain: zu44xabg5ak3pxt.xyz
- url: https://api.github.com/repos/stamparm/maltrail/commits/5fa2e456bfb5bd5aa84578ec621fd5d52a593d04
- url: https://www.virustotal.com/gui/file/759b99a5241122a5ae61dca204f7ec5659f2a7ca4b3201928dd9b95aa97d38ca/detection
- domain: drivinguber.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/19dcc8795f3227e2724772f197c298a5412ed826
- ip: 195.201.194.107
- url: https://api.github.com/repos/stamparm/maltrail/commits/8ae5a9b55d46fa5e8268e5d27f433aed80072c62
- url: https://api.github.com/repos/stamparm/maltrail/commits/01e17915b0aa710b6a9297b6f2c7de339749b735
- url: https://x.com/abh1sek/status/2057104532451307987
- url: https://github.com/goofychris/art-template/issues/665
- domain: youzzjizz.com
- domain: git.youzzjizz.com
- domain: v3.jiathis.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/ba2d5d19eab207a0f65214ec306a6a7370ac266c
- ip: 23.254.203.244
- url: https://api.github.com/repos/stamparm/maltrail/commits/1589485ccaea4cf4742ed458a7df012c81528fde
- ip: 23.254.164.61
- ip: 23.254.164.92
- url: https://api.github.com/repos/stamparm/maltrail/commits/ea86f60b9b4becde86893138ba01436234f4829e
- url: https://www.virustotal.com/gui/file/0347783bb2984a9cd014e1f284b13fff0651eaa0d920851adf38643e178b60d6/detection
- ip: 151.243.109.130
- url: https://api.github.com/repos/stamparm/maltrail/commits/4730a1adcfa72c26f518abdb6ef503ca2e6ca925
- url: https://www.virustotal.com/gui/file/0434b0a1e55bf612d4ee50d1b851b6d0c560a27c3e88136dd71cc550b15b9813/detection
- url: https://api.github.com/repos/stamparm/maltrail/commits/376216e20f61e4500902e65e60674a54639af843
- url: https://x.com/tuckner/status/2056826907421823231
- url: https://x.com/tuckner/status/2057078903663993343
- domain: karasb.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/a5be430ba36aef737add06115d8ad9bdc7e0d66b
- url: https://x.com/_tdatwja/status/2056980156372398281
- url: https://www.virustotal.com/gui/file/e7ea5eb83bf6e9b1cc603ca13c0f363b164ccb712fbf90300cc52e91c53e2e08/detection
- ip: 38.47.227.212
- url: https://api.github.com/repos/stamparm/maltrail/commits/5b542169c0cbc2f6ed45e796a8121f22b9755b6e
- url: https://www.virustotal.com/gui/file/7ef770d7f400e4cb20ee98f64841f772e6f2238f13c93080e55beb1ff767dd03/detection
- ip: 43.165.179.173
- url: https://api.github.com/repos/stamparm/maltrail/commits/887cb6c98b4772ba25a189311283c50486a1d53c
- url: https://x.com/_tdatwja/status/2056597011395404036
- url: https://www.virustotal.com/gui/file/8d4674d062877c3a0177b4b0deff8b344794ed58d857b98f831a3abb0b797187/detection
- domain: app-wendinggo.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/823076797ad2ba5b2bfdca1ff111e5b4eb89a9a3
- domain: earthstring.space
- domain: selectionaftermath.xyz
- url: https://api.github.com/repos/stamparm/maltrail/commits/f3d0cd8be91b67e7ae15bc7a87f7e8e9c810dc0a
- ip: 157.173.113.151
- url: https://api.github.com/repos/stamparm/maltrail/commits/d3f231e64d61e7c11ffe6f8c93ecd678c038ebdf
- domain: k1be.yu95pzwvz84.dns.navy
- domain: ndocsuppport.dns.army
- domain: nid-naverdlc.servequake.com
- domain: nid.ndocsuppport.dns.army
- domain: nidsec.dns.army
- domain: nidsign.k1be.yu95pzwvz84.dns.navy
- domain: nopts.xubi.org
- domain: openuasermdoc19s.dns.army
- domain: openuasermdoc21s.dns.army
- domain: openuasermdoc34s.dns.army
- domain: yu95pzwvz84.dns.navy
- url: https://api.github.com/repos/stamparm/maltrail/commits/1cdab403dccdf53633ab6df0739ea2927239c54c
- url: https://x.com/smica83/status/2057057509479727194
- url: https://www.virustotal.com/gui/file/ffcee98683cf69d52232ceb890a778ec958b861509bdc55561ffe6b0a421afa8/detection
- url: https://www.virustotal.com/gui/file/afbc44948f92625a926ef370192294cc30b303f0476656002f990e9506defa83/detection
- url: https://www.virustotal.com/gui/file/631170f9174d4c21df4d14027de4a18459f64ac70a8c2dce3459c334433a0f31/detection
- url: https://www.virustotal.com/gui/file/437461c3abc56cf90c1d460bb18e8420e077d0a36d16e3fa9ab7d22c324183df/detection
- ip: 103.45.66.52
- url: https://api.github.com/repos/stamparm/maltrail/commits/8c0e045295729c1a987f24b5ad570f7e75695d12
- url: https://github.com/nrwl/nx-console/issues/3139
- domain: slsa-framework.github.io
- url: https://api.github.com/repos/stamparm/maltrail/commits/dc8c6c38063ac2d2ea4fe76179e719b40e629ca5
- domain: 9i.campdevanolg.lol
- domain: socket-analytics.org
- domain: yo.exiverse.lol
- url: https://api.github.com/repos/stamparm/maltrail/commits/c5e91bb54bb3a6c60971030645fcf177e6b4ae58
- domain: eefage.icu
- domain: iimna.icu
- domain: ionnemt.icu
- domain: oirnme.icu
- url: https://api.github.com/repos/stamparm/maltrail/commits/677b7967f8ebea3c9f3a2b386305ea88738f8e7e
- domain: 40.workbencse.com
- domain: 4l.rvtoolslab.com
- domain: fluxelyx.com
- domain: orlandoapt.com
- domain: rychlereseni.com
- domain: subito-fatto.com
- domain: vert-feu.com
- domain: workbencse.com
- domain: yx.rvtooli.info
- url: https://api.github.com/repos/stamparm/maltrail/commits/3ea392d3640ac44520eb4fddb233743bdb903b10
- url: https://x.com/malwrhunterteam/status/2057044039728324798
- url: https://www.virustotal.com/gui/file/daced91764437bd79a5e4fb1ce568f4657b78fc11fb20e22d19c22f4eb7095bf/detection
- domain: teenvogue.icu
- url: https://api.github.com/repos/stamparm/maltrail/commits/92971ada2cf5bcbc0efff429a60587e6389343c3
- domain: 11.fastcdnjs.net
- domain: jartrack.com
- domain: xr.jartrack.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/7e0bd4669de7117d399d538a58a24a341ae7c752
- url: https://x.com/sdcyberresearch/status/2056323429779886349
- domain: b2banalytics.org
- domain: certanalytics.com
- domain: commerce-flow.net
- domain: crmflow24.com
- domain: crmflow365.com
- domain: ecomm365.net
- domain: fastcdnjs.net
- domain: arendje.jsdelive.com
- domain: shop.jsdelive.com
- url: https://api.github.com/repos/stamparm/maltrail/commits/ec32238ca53275db805fc4f2fc14846b8a94267d
- domain: cloudevos.xyz
- domain: trustnewusacool.xyz
- url: https://api.github.com/repos/stamparm/maltrail/commits/7fb07001b702b96e6cde55d3ee4b8bb0a940a249
- url: https://x.com/skocherhan/status/2057207628711821594
- domain: connectnowlives.vercel.app
- domain: liveconnetionow.vercel.app
- domain: livlocationow.netlify.app
- domain: myliveloationnow.vercel.app
- domain: teal-chimera-f00ab1.netlify.app
- domain: view-location-for-us.link
Maltrail IOC for 2026-05-20
Description
Maltrail IOC for 2026-05-20
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The report details a malware-related IOC published by CIRCL OSINT Feed on 2026-05-20. It is categorized under OSINT and network activity with medium risk but lacks specific technical indicators, affected versions, or exploit details. No patch or vendor remediation exists, and it is primarily an observational threat intelligence entry.
Potential Impact
The impact is medium risk based on the source classification, indicating potential malware activity detected in network traffic. However, no known exploits or direct vulnerabilities are identified, and no specific affected products or versions are listed. This suggests a general threat awareness rather than an immediate exploitable condition.
Mitigation Recommendations
No patch or official remediation is available or applicable for this IOC. Security teams should incorporate this IOC into their threat detection and monitoring systems as part of ongoing OSINT-based situational awareness. No urgent action is required beyond standard monitoring aligned with this intelligence.
Technical Details
- Uuid
- 10c39115-7be2-45d1-884f-8125733c1b92
- Original Timestamp
- 1779314408
Indicators of Compromise
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f9324a40cdba2fc8c6e71245aa98be2c0d17f04c | apt_kimsuky | |
urlhttps://x.com/skocherhan/status/2057172575889789202 | apt_kimsuky | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f20c6823363a1cd1b330b4b4a9891beec7f27aec | lummac2 | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/e202683c7f0d46980803d6b05a038f2b819a43b2 | magentocore | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/581025fa091e6a2594d7a849980caa94b438a982 | fakeapp | |
urlhttps://x.com/Malwarehunterr/status/2057196561172689389 | fakeapp | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7f01ccd57edb32d4cbdc3b82f75dd5daccaa1d64 | apt_unc6691 | |
urlhttps://safedep.io/art-template-npm-supply-chain-compromise | apt_unc6691 | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5fa2e456bfb5bd5aa84578ec621fd5d52a593d04 | osx_atomic | |
urlhttps://www.virustotal.com/gui/file/759b99a5241122a5ae61dca204f7ec5659f2a7ca4b3201928dd9b95aa97d38ca/detection | osx_atomic | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/19dcc8795f3227e2724772f197c298a5412ed826 | apt_lazarus | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/8ae5a9b55d46fa5e8268e5d27f433aed80072c62 | apt_lazarus | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/01e17915b0aa710b6a9297b6f2c7de339749b735 | hacked_npmrepos | |
urlhttps://x.com/abh1sek/status/2057104532451307987 | hacked_npmrepos | |
urlhttps://github.com/goofychris/art-template/issues/665 | hacked_npmrepos | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ba2d5d19eab207a0f65214ec306a6a7370ac266c | hacked_npmrepos | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1589485ccaea4cf4742ed458a7df012c81528fde | hacked_npmrepos | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ea86f60b9b4becde86893138ba01436234f4829e | powershell_injector | |
urlhttps://www.virustotal.com/gui/file/0347783bb2984a9cd014e1f284b13fff0651eaa0d920851adf38643e178b60d6/detection | powershell_injector | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4730a1adcfa72c26f518abdb6ef503ca2e6ca925 | remcos | |
urlhttps://www.virustotal.com/gui/file/0434b0a1e55bf612d4ee50d1b851b6d0c560a27c3e88136dd71cc550b15b9813/detection | remcos | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/376216e20f61e4500902e65e60674a54639af843 | hacked_npmrepos | |
urlhttps://x.com/tuckner/status/2056826907421823231 | hacked_npmrepos | |
urlhttps://x.com/tuckner/status/2057078903663993343 | hacked_npmrepos | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a5be430ba36aef737add06115d8ad9bdc7e0d66b | fakeapp | |
urlhttps://x.com/_tdatwja/status/2056980156372398281 | fakeapp | |
urlhttps://www.virustotal.com/gui/file/e7ea5eb83bf6e9b1cc603ca13c0f363b164ccb712fbf90300cc52e91c53e2e08/detection | fakeapp | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5b542169c0cbc2f6ed45e796a8121f22b9755b6e | fakeapp | |
urlhttps://www.virustotal.com/gui/file/7ef770d7f400e4cb20ee98f64841f772e6f2238f13c93080e55beb1ff767dd03/detection | fakeapp | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/887cb6c98b4772ba25a189311283c50486a1d53c | fakeapp | |
urlhttps://x.com/_tdatwja/status/2056597011395404036 | fakeapp | |
urlhttps://www.virustotal.com/gui/file/8d4674d062877c3a0177b4b0deff8b344794ed58d857b98f831a3abb0b797187/detection | fakeapp | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/823076797ad2ba5b2bfdca1ff111e5b4eb89a9a3 | offloader | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f3d0cd8be91b67e7ae15bc7a87f7e8e9c810dc0a | vacbot | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d3f231e64d61e7c11ffe6f8c93ecd678c038ebdf | apt_kimsuky | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1cdab403dccdf53633ab6df0739ea2927239c54c | quasarrat | |
urlhttps://x.com/smica83/status/2057057509479727194 | quasarrat | |
urlhttps://www.virustotal.com/gui/file/ffcee98683cf69d52232ceb890a778ec958b861509bdc55561ffe6b0a421afa8/detection | quasarrat | |
urlhttps://www.virustotal.com/gui/file/afbc44948f92625a926ef370192294cc30b303f0476656002f990e9506defa83/detection | quasarrat | |
urlhttps://www.virustotal.com/gui/file/631170f9174d4c21df4d14027de4a18459f64ac70a8c2dce3459c334433a0f31/detection | quasarrat | |
urlhttps://www.virustotal.com/gui/file/437461c3abc56cf90c1d460bb18e8420e077d0a36d16e3fa9ab7d22c324183df/detection | quasarrat | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/8c0e045295729c1a987f24b5ad570f7e75695d12 | hacked_npmrepos | |
urlhttps://github.com/nrwl/nx-console/issues/3139 | hacked_npmrepos | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/dc8c6c38063ac2d2ea4fe76179e719b40e629ca5 | magentocore | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c5e91bb54bb3a6c60971030645fcf177e6b4ae58 | android_fvncbot | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/677b7967f8ebea3c9f3a2b386305ea88738f8e7e | apt_unc2465 | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/3ea392d3640ac44520eb4fddb233743bdb903b10 | mythic | |
urlhttps://x.com/malwrhunterteam/status/2057044039728324798 | mythic | |
urlhttps://www.virustotal.com/gui/file/daced91764437bd79a5e4fb1ce568f4657b78fc11fb20e22d19c22f4eb7095bf/detection | mythic | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/92971ada2cf5bcbc0efff429a60587e6389343c3 | magentocore | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7e0bd4669de7117d399d538a58a24a341ae7c752 | magentocore | |
urlhttps://x.com/sdcyberresearch/status/2056323429779886349 | magentocore | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ec32238ca53275db805fc4f2fc14846b8a94267d | powershell_injector | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7fb07001b702b96e6cde55d3ee4b8bb0a940a249 | fakeapp | |
urlhttps://x.com/skocherhan/status/2057207628711821594 | fakeapp |
Domain
| Value | Description | Copy |
|---|---|---|
domain2u9f.2usrmmwwduz.dns.navy | apt_kimsuky | |
domain2usrmmwwduz.dns.navy | apt_kimsuky | |
domain6td4w.mj9tqlj86sz.dns.navy | apt_kimsuky | |
domain923h5qvvzq2.v6.navy | apt_kimsuky | |
domainflbsbn.zsf31ayvobt.dns.navy | apt_kimsuky | |
domainguidetx.suredoc.net | apt_kimsuky | |
domainmareqsutxn.v6.navy | apt_kimsuky | |
domainmj9tqlj86sz.dns.navy | apt_kimsuky | |
domainncloud.casacam.net | apt_kimsuky | |
domainndoc.ncloud.casacam.net | apt_kimsuky | |
domainnid-log-pl.2u9f.2usrmmwwduz.dns.navy | apt_kimsuky | |
domainnid-token.tkho.mareqsutxn.v6.navy | apt_kimsuky | |
domainnidmois.p0fx8.923h5qvvzq2.v6.navy | apt_kimsuky | |
domainnidsign.mylogisoft.com | apt_kimsuky | |
domainninvoice.parentinvolvement.in | apt_kimsuky | |
domainninvoice.taxcloud.kro.kr | apt_kimsuky | |
domainp0fx8.923h5qvvzq2.v6.navy | apt_kimsuky | |
domainpol-go-nid.6td4w.mj9tqlj86sz.dns.navy | apt_kimsuky | |
domainpol-go-nid.flbsbn.zsf31ayvobt.dns.navy | apt_kimsuky | |
domaintaxcloud.kro.kr | apt_kimsuky | |
domaintkho.mareqsutxn.v6.navy | apt_kimsuky | |
domaintoxcloud.dns.army | apt_kimsuky | |
domainvvg1ylsb4a7.dns.navy | apt_kimsuky | |
domainzsf31ayvobt.dns.navy | apt_kimsuky | |
domainpantofr.cyou | lummac2 | |
domainwpcdnwsswp.com | magentocore | |
domainainalapitool.online | fakeapp | |
domainasifapi.xyz | fakeapp | |
domainbiplobapi.xyz | fakeapp | |
domainhasanapi.xyz | fakeapp | |
domainjasimapi.xyz | fakeapp | |
domainlahinapi.xyz | fakeapp | |
domainmilonapi.xyz | fakeapp | |
domainronyapi.xyz | fakeapp | |
domainsohanapi.xyz | fakeapp | |
domainsohelapitool.online | fakeapp | |
domaintmrlapi.xyz | fakeapp | |
domaintoolapipanel.online | fakeapp | |
domaincall-video.website | fakeapp | |
domaindue-chat.call-video.website | fakeapp | |
domaindue-live-call.online | fakeapp | |
domaindue.live-video-call.my.id | fakeapp | |
domainduolivecall-googel.com | fakeapp | |
domainecortbabylon.site | fakeapp | |
domaingiooga.com | fakeapp | |
domaingoogle-meets.videos-chat.my.id | fakeapp | |
domaingooglemeetjoin.live | fakeapp | |
domaingooglemeetjoin.site | fakeapp | |
domaingooqle-duo.my.id | fakeapp | |
domaingooqle-live.com | fakeapp | |
domaingooqle-mapa.com | fakeapp | |
domaingooqle-mapsse.com | fakeapp | |
domaingooqle-meet-call-join.4-aa.com | fakeapp | |
domaingooqle-meet-call-live.1-a5.com | fakeapp | |
domaingooqle-meet-call.com | fakeapp | |
domaingooqle-meet-live-call.0-1h.com | fakeapp | |
domaingooqle-meet-live-call.com | fakeapp | |
domaingooqle-meet-live-call.my.id | fakeapp | |
domaingooqle-meet-live-call.s-81.com | fakeapp | |
domaingooqle-meet-live-call.shop | fakeapp | |
domaingooqle-meet-live-join.0-8a.com | fakeapp | |
domaingooqle-meet-live.2-1x.com | fakeapp | |
domaingooqle-meet-lives-call.my.id | fakeapp | |
domaingooqle-meet-lives-calls.my.id | fakeapp | |
domaingooqle-meet.live-join.com | fakeapp | |
domaingooqle-meet.view-chats.com | fakeapp | |
domaingooqle-meet.view-lives.com | fakeapp | |
domaingooqlemeet-livecall.com | fakeapp | |
domaingooqles-meet-live-call.my.id | fakeapp | |
domainjob-application.advice4.net | fakeapp | |
domainjoin-gooqle-meet.my.id | fakeapp | |
domainjoin-meet-gooqle.com | fakeapp | |
domainlive-call-chat.com | fakeapp | |
domainlive-gooqle-due-online.com | fakeapp | |
domainlive-join-gooqle-meet.4-c4.com | fakeapp | |
domainlive-join-gooqle-meet.4-c5.com | fakeapp | |
domainlive-join-gooqle-meet.4-c7.com | fakeapp | |
domainlive-join-gooqle-meet.my.id | fakeapp | |
domainlive-join.com | fakeapp | |
domainlive-video-call.my.id | fakeapp | |
domainlive-view-join.com | fakeapp | |
domainlive.gooqle-due-online.com | fakeapp | |
domainlivemeetcall.xyz | fakeapp | |
domainmeet-auto-live.0-la.com | fakeapp | |
domainmeet-auto-live.website | fakeapp | |
domainmeet-auto.demo-links.shop | fakeapp | |
domainmeet-gooqle-call.online | fakeapp | |
domainmeet-gooqle-live.online | fakeapp | |
domainmeet-live-call-chat.store | fakeapp | |
domainmeet-live-view-join.shop | fakeapp | |
domainmeet-video-calls.1-l8.com | fakeapp | |
domainmeet-video-calls.live | fakeapp | |
domainmeet.giooga.com | fakeapp | |
domainmeet.gooqle-live.com | fakeapp | |
domainmeet.gooqle-mapa.com | fakeapp | |
domainmeet.gooqle-mapaps.my.id | fakeapp | |
domainmeet.gooqle-mapsse.com | fakeapp | |
domainmeet.live-call-chat.com | fakeapp | |
domainmeet.live-view-join.com | fakeapp | |
domainruhol.advice4.net | fakeapp | |
domainvideo-call-meet.my.id | fakeapp | |
domainvideo-call.my.id | fakeapp | |
domainvideos-chat.my.id | fakeapp | |
domainview-chats.com | fakeapp | |
domainview-lives.com | fakeapp | |
domaincfww.shop | apt_unc6691 | |
domainutaq.cfww.shop | apt_unc6691 | |
domain0fx7qmdggegytul.xyz | apt_unc6691 | |
domain1an94xtp37j04rh.xyz | apt_unc6691 | |
domain23hs16uua03wc37.xyz | apt_unc6691 | |
domain2n8psx9r4rbu4ym.xyz | apt_unc6691 | |
domain4laqouz21lrm4qa.xyz | apt_unc6691 | |
domain4z1jn2d6f95ab6o.xyz | apt_unc6691 | |
domain5hz5vevyy0sccxx.xyz | apt_unc6691 | |
domain6y3r7895ec4ucxd.xyz | apt_unc6691 | |
domain7kvgccspqu66khd.xyz | apt_unc6691 | |
domain82lqwfoid9uh03u.xyz | apt_unc6691 | |
domain8d3x413aph9yel4.xyz | apt_unc6691 | |
domain93ulni68qu7fkqt.xyz | apt_unc6691 | |
domain9pzx64gxoro0o8t.xyz | apt_unc6691 | |
domaina1t5ps59bvg58nl.xyz | apt_unc6691 | |
domainaygd82dymm4kpw4.xyz | apt_unc6691 | |
domainc3atzhavt9t3drw.xyz | apt_unc6691 | |
domaincb6b06ev3e789cy.xyz | apt_unc6691 | |
domainct1boy78fhhbi7b.xyz | apt_unc6691 | |
domaind1q2kfw4wj6a1p0.xyz | apt_unc6691 | |
domaind95l3efcegbrma2.xyz | apt_unc6691 | |
domaing3knq19zsveuvux.xyz | apt_unc6691 | |
domaingkxtguomb5mrs16.xyz | apt_unc6691 | |
domainhivkaimrsrbnuek.xyz | apt_unc6691 | |
domainisllczzovdlvg5s.xyz | apt_unc6691 | |
domainj7bvmd04ttsyua6.xyz | apt_unc6691 | |
domainje43wrtxf8j27rm.xyz | apt_unc6691 | |
domainkm974980kv49sf2.xyz | apt_unc6691 | |
domainl1ewsu3yjkqeroy.xyz | apt_unc6691 | |
domainmxjht88dwegvaku.xyz | apt_unc6691 | |
domainned0e3bwqooh4kz.xyz | apt_unc6691 | |
domainnpihetcniyq5ymb.xyz | apt_unc6691 | |
domainodntitrx9mulxf0.xyz | apt_unc6691 | |
domainog2yyl3vgizq6rx.xyz | apt_unc6691 | |
domainq6762dzwtgypc80.xyz | apt_unc6691 | |
domainq6ouy6sewocm3sy.xyz | apt_unc6691 | |
domainqcpujc0ep5ujntz.xyz | apt_unc6691 | |
domaint6ptmj5tay5s5p8.xyz | apt_unc6691 | |
domaintpl09o77v75fygn.xyz | apt_unc6691 | |
domainukgwi7hotwlzpnp.xyz | apt_unc6691 | |
domainwvd1u78mc4tvk1l.xyz | apt_unc6691 | |
domainx2wy5e652cjcmvl.xyz | apt_unc6691 | |
domainx8fdyv0vp4txtfi.xyz | apt_unc6691 | |
domainxjclgn6ospcjvci.xyz | apt_unc6691 | |
domainxy7bhvf7s4fiz42.xyz | apt_unc6691 | |
domainyagy548ag5zlsrf.xyz | apt_unc6691 | |
domainyauo3bdp0fqu9hb.xyz | apt_unc6691 | |
domainyw5jbbhgzqe3gnq.xyz | apt_unc6691 | |
domainzu44xabg5ak3pxt.xyz | apt_unc6691 | |
domaindrivinguber.com | osx_atomic | |
domainyouzzjizz.com | hacked_npmrepos | |
domaingit.youzzjizz.com | hacked_npmrepos | |
domainv3.jiathis.com | hacked_npmrepos | |
domainkarasb.com | hacked_npmrepos | |
domainapp-wendinggo.com | fakeapp | |
domainearthstring.space | offloader | |
domainselectionaftermath.xyz | offloader | |
domaink1be.yu95pzwvz84.dns.navy | apt_kimsuky | |
domainndocsuppport.dns.army | apt_kimsuky | |
domainnid-naverdlc.servequake.com | apt_kimsuky | |
domainnid.ndocsuppport.dns.army | apt_kimsuky | |
domainnidsec.dns.army | apt_kimsuky | |
domainnidsign.k1be.yu95pzwvz84.dns.navy | apt_kimsuky | |
domainnopts.xubi.org | apt_kimsuky | |
domainopenuasermdoc19s.dns.army | apt_kimsuky | |
domainopenuasermdoc21s.dns.army | apt_kimsuky | |
domainopenuasermdoc34s.dns.army | apt_kimsuky | |
domainyu95pzwvz84.dns.navy | apt_kimsuky | |
domainslsa-framework.github.io | hacked_npmrepos | |
domain9i.campdevanolg.lol | magentocore | |
domainsocket-analytics.org | magentocore | |
domainyo.exiverse.lol | magentocore | |
domaineefage.icu | android_fvncbot | |
domainiimna.icu | android_fvncbot | |
domainionnemt.icu | android_fvncbot | |
domainoirnme.icu | android_fvncbot | |
domain40.workbencse.com | apt_unc2465 | |
domain4l.rvtoolslab.com | apt_unc2465 | |
domainfluxelyx.com | apt_unc2465 | |
domainorlandoapt.com | apt_unc2465 | |
domainrychlereseni.com | apt_unc2465 | |
domainsubito-fatto.com | apt_unc2465 | |
domainvert-feu.com | apt_unc2465 | |
domainworkbencse.com | apt_unc2465 | |
domainyx.rvtooli.info | apt_unc2465 | |
domainteenvogue.icu | mythic | |
domain11.fastcdnjs.net | magentocore | |
domainjartrack.com | magentocore | |
domainxr.jartrack.com | magentocore | |
domainb2banalytics.org | magentocore | |
domaincertanalytics.com | magentocore | |
domaincommerce-flow.net | magentocore | |
domaincrmflow24.com | magentocore | |
domaincrmflow365.com | magentocore | |
domainecomm365.net | magentocore | |
domainfastcdnjs.net | magentocore | |
domainarendje.jsdelive.com | magentocore | |
domainshop.jsdelive.com | magentocore | |
domaincloudevos.xyz | powershell_injector | |
domaintrustnewusacool.xyz | powershell_injector | |
domainconnectnowlives.vercel.app | fakeapp | |
domainliveconnetionow.vercel.app | fakeapp | |
domainlivlocationow.netlify.app | fakeapp | |
domainmyliveloationnow.vercel.app | fakeapp | |
domainteal-chimera-f00ab1.netlify.app | fakeapp | |
domainview-location-for-us.link | fakeapp |
Ip
| Value | Description | Copy |
|---|---|---|
ip195.201.194.107 | apt_lazarus | |
ip23.254.203.244 | hacked_npmrepos | |
ip23.254.164.61 | hacked_npmrepos | |
ip23.254.164.92 | hacked_npmrepos | |
ip151.243.109.130 | powershell_injector | |
ip38.47.227.212 | fakeapp | |
ip43.165.179.173 | fakeapp | |
ip157.173.113.151 | vacbot | |
ip103.45.66.52 | quasarrat |
Threat ID: 6a0e332fba1db47362b04512
Added to database: 5/20/2026, 10:18:23 PM
Last enriched: 5/20/2026, 10:33:43 PM
Last updated: 5/21/2026, 4:26:07 AM
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.