Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-05-23

0
Medium
Published: Fri May 22 2026 (05/22/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed
Vendor/Project: tlp
Product: clear

Description

Maltrail IOC for 2026-05-23

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/23/2026, 12:01:32 UTC

Technical Analysis

The report details a malware-related IOC detected by Maltrail on 2026-05-23, sourced from CIRCL OSINT Feed. It is categorized under network activity and external analysis but lacks specific technical indicators or affected software versions. No exploits are currently known, and no patch or fix exists. The threat is assessed at medium severity based on the source classification.

Potential Impact

The impact is currently limited to the detection of suspicious network activity associated with malware. There are no known exploits in the wild and no direct evidence of compromise or vulnerability exploitation. The medium severity rating suggests a moderate risk based on observed activity rather than confirmed attacks or breaches.

Mitigation Recommendations

No patch or official remediation is available for this IOC. Since this is an intelligence observation without specific actionable indicators, no direct mitigation steps are provided. Security teams should incorporate this IOC into their monitoring and detection systems as appropriate but no urgent action is mandated by the vendor or source.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
c124c2a5-e3d7-4edf-bb8f-3de9bc35834a
Original Timestamp
1779534016

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5caaf15897ad961e837f571242b5481c6984b779
offloader
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a0d24c5450db0409cbb6c8818eb3656f37456a61
tsundere
urlhttps://api.github.com/repos/stamparm/maltrail/commits/e30b651fc7513f8af22dbba5fbb716ea99736de3
c2_panel
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1c3d97e9fcbe5dfd0673cfb46778dff9965906b2
peaklight
urlhttps://api.github.com/repos/stamparm/maltrail/commits/512a4cc90b07d2b35735c6511bb3f2331553f2ad
urlhttps://api.github.com/repos/stamparm/maltrail/commits/2fc04733ab5a4799c29a7efbaddbfdf9e90656ca
apt_unc2465
urlhttps://api.github.com/repos/stamparm/maltrail/commits/0c5b50995aeed95cd9888dadf4e314f613bbf816
android_fvncbot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/3ee6f511b6cbcb68b13bd408179b21abbd8cac37
magentocore
urlhttps://api.github.com/repos/stamparm/maltrail/commits/37444af6a1e86eae83b86b89d48f456434771faf
android_joker
urlhttps://api.github.com/repos/stamparm/maltrail/commits/922771885db706042e4409c4fc6e838cd4ae2439
android_roamingmantis
urlhttps://x.com/masaomi346/status/2057695716097843508
android_roamingmantis
urlhttps://www.virustotal.com/gui/file/99f972412c0689d0f78c3e3bbe5294512a3a86ac18e25ddc8904a09c5ad2f234/detection
android_roamingmantis
urlhttps://www.virustotal.com/gui/file/6b61a139e764cbdaa53a5b7f43435983f73ed9a5e457bddc2b4c2115869c92fc/detection
android_roamingmantis
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5fb2c58b5da843e22277fc1976622f086a0c8f90
osx_atomic
urlhttps://x.com/masaomi346/status/2058057289173750075
osx_atomic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5ec612a5156010c3ab30d004e2b3f87a38b0e842
hacked_npmrepos
urlhttps://socket.dev/blog/laravel-lang-compromise
hacked_npmrepos
urlhttps://api.github.com/repos/stamparm/maltrail/commits/462fd9969366abbca24358c1c8a0f6694ccc6de9
cyberstrikeai
urlhttps://api.github.com/repos/stamparm/maltrail/commits/99932955a97b102fe52ef56fae604185ac18dc34
hak5cloud_c2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d7f60d2e050d1b0a2900b8d396f8671dfbabcb53
adaptix_c2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d8d4d98fb8e192f5850fe62ef439ff39f493ad64
apt_kimsuky

Domain

ValueDescriptionCopy
domainsaltminister.xyz
offloader
domaintubidycep.com
tsundere
domainbootstrup-framework-js.beer
domainnshostvps.beer
domainacfcjsbi.gift-lattice.christmas
domainacxmquqg.winter-pulse.christmas
domainauhlsdki.frost-engine.christmas
domainbadxqjge.gift-lattice.christmas
domainbetnoise-unionour.cyou
domainbrhwmjkk.frost-engine.christmas
domaincomputationalgrid.com
domaincontainer-beacon.buzz
domaindataproxy-hub.christmas
domaindebugshy-fansync.cyou
domainelf-infrastructure.christmas
domaineuftrhnx.computationalgrid.com
domainflopstin-gymcargo.cyou
domainfrost-engine.christmas
domainftjilgqw.winter-pulse.christmas
domaingift-lattice.christmas
domainholiday-matrix.christmas
domainhoycbijv.holiday-matrix.christmas
domainhypervisor-resource-node.christmas
domainhzlqlpfw.frost-engine.christmas
domainihtfqktk.holiday-matrix.christmas
domainilhvyrij.ipv4has-lampnew.cyou
domainintelsky-acttext-broker.christmas
domainipv4has-lampnew.cyou
domainkernel-routing-node.christmas
domainlogic-compass.buzz
domainlzascdxk.xenomorphhiveintel.christmas
domainmckglhnz.holiday-matrix.christmas
domainmfbrkbuv.betnoise-unionour.cyou
domainmfwhezll.gift-lattice.christmas
domainmkszunli.flopstin-gymcargo.cyou
domainmokmgdal.gift-lattice.christmas
domainmstdvyct.gift-lattice.christmas
domainmvltyody.frost-engine.christmas
domainpacket-relay.christmas
domainpaqcfwvt.winter-pulse.christmas
domainproofsrefluxankle.com
domainpvnhnpre.computationalgrid.com
domainqmxvwfew.winter-pulse.christmas
domainsmartworkflowmanagement.study
domainsnow-harbor.christmas
domainsopranos-familytree.christmas
domainsystemanalyticspro.study
domainthdnyyif.winter-pulse.christmas
domainukkqtbst.snow-harbor.christmas
domainwinter-pulse.christmas
domainxenomorphhiveintel.christmas
domainxiidysrc.xenomorphhiveintel.christmas
domainxusyyrhk.gift-lattice.christmas
domainymeivxaj.holiday-matrix.christmas
domainynkcoqkg.snow-harbor.christmas
domainpanelcaptchaview.com
domainpanelviewcaptcha.com
domainpropertypanelmessages.com
domainamberwisp.com
domainantaires.one
domainantivirus-2026.com
domainapplytermsonline.xyz
domainbinancekundensupport.com
domainc3ilent-02d-gu0vc0cu.help
domaincompletsou.com
domaindefinsokem.com
domainfintinhappmin.com
domainfreedommobile-billingaccount.com
domaing0giie.cc
domainmitsui-documents.com
domainmyaustraliaonline-services.sbs
domainnabconnectlivehelpportal.com
domainovareild.com
domainportalbzst.com
domainredirectthislinkdirect.com
domainsecure-insurance2.com
domainsecurelogin-freedommobiie.com
domainsecurewingsauth.com
domainsmsmeblue.xyz
domainsolidfoundationq.com
domainsupport-lf.com
domainsupport-nabliveportal.com
domaintriustt.com
domainuser-insurance-policy.com
domainvesstcast.com
domainwolfxotdemo.com
domain20.rvtoolsme.com
apt_unc2465
domain24.rvtoolsgo.com
apt_unc2465
domain5n.rvtoolsrun.com
apt_unc2465
domainbrandhighland.com
apt_unc2465
domainfaithful-sigh.com
apt_unc2465
domainkalosrobotics.com
apt_unc2465
domainkokoro-travel.org
apt_unc2465
domainmeshquantumlab.com
apt_unc2465
domainparsemesh.com
apt_unc2465
domainsquaredinc.com
apt_unc2465
domaintxartificialturf.com
apt_unc2465
domainyv.rvtoolas.com
apt_unc2465
domainzs.s3bravser.com
apt_unc2465
domainjukkegd.icu
android_fvncbot
domainonmege.icu
android_fvncbot
domainottihna.icu
android_fvncbot
domainttehhag.icu
android_fvncbot
domainttgehae.icu
android_fvncbot
domainuijaeea.icu
android_fvncbot
domaincsgou.vip
magentocore
domaindevadmin.csgou.vip
magentocore
domainandy-527.com
android_joker
domainshpwm.xyz
android_roamingmantis
domainsscgw.xyz
android_roamingmantis
domainssotp.xyz
android_roamingmantis
domaindsrgt.shpwm.xyz
android_roamingmantis
domainfdsrygh.sscgw.xyz
android_roamingmantis
domaingfdrthu.ssotp.xyz
android_roamingmantis
domainqo.sscgw.xyz
android_roamingmantis
domainqw.shpwm.xyz
android_roamingmantis
domainbyrnewealthmanagement.com
osx_atomic
domainflipboxstudio.info
hacked_npmrepos
domainc2.cuteops.fr
hak5cloud_c2
domainc2.gr3ybox.com
hak5cloud_c2
domainc2.xcontent.red
hak5cloud_c2
domainftp.cuteops.fr
hak5cloud_c2
domainpihole.cuteops.fr
hak5cloud_c2
domainsarudy.ovh
hak5cloud_c2
domainbestatto.ru
adaptix_c2
domainblatatto.ru
adaptix_c2
domaincomplty.fit
adaptix_c2
domainf1ashupdate.online
adaptix_c2
domainhk.32069.com
adaptix_c2
domainkrypton.taileb042a.ts.net
adaptix_c2
domainmatatto.ru
adaptix_c2
domainmxcloud.cloud
adaptix_c2
domainpankebab.com
adaptix_c2
domaintattoblack.ru
adaptix_c2
domaintattoma.ru
adaptix_c2
domaintattomos.ru
adaptix_c2
domaintattop.ru
adaptix_c2
domaintattosic.ru
adaptix_c2
domaintattova.ru
adaptix_c2
domaintattozona.ru
adaptix_c2
domainupdate.f1ashupdate.online
adaptix_c2
domainupdateflash-client.xyz
adaptix_c2
domainvpn734653413.softether.net
adaptix_c2
domainvpn880365101.softether.net
adaptix_c2
domain1exi8anhok2.dns.navy
apt_kimsuky
domain3t1tjp49cf7.dns.navy
apt_kimsuky
domainhello.mwuglp.1exi8anhok2.dns.navy
apt_kimsuky
domainmwuglp.1exi8anhok2.dns.navy
apt_kimsuky
domainntc13xt.dns.navy
apt_kimsuky
domainntc6xt.dns.navy
apt_kimsuky
domainpor4dwim0u.v6.army
apt_kimsuky

Ip

ValueDescriptionCopy
ip158.94.210.164
c2_panel
ip79.137.206.163
c2_panel
ip198.144.149.133
android_roamingmantis
ip107.173.13.251
cyberstrikeai

Threat ID: 6a11939309f6977edbfa1695

Added to database: 5/23/2026, 11:46:27 AM

Last enriched: 5/23/2026, 12:01:32 PM

Last updated: 5/23/2026, 7:56:21 PM

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses