Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-05-29

0
Medium
Published: Thu May 28 2026 (05/28/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed

Description

Maltrail IOC for 2026-05-29

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/29/2026, 11:33:25 UTC

Technical Analysis

The report details a malware-related IOC identified on 2026-05-29 by the CIRCL OSINT Feed. It is classified as a medium-risk observation of network activity linked to malware but lacks detailed technical indicators, affected software versions, or exploit information. No patch or remediation is applicable as this is an intelligence observation rather than a vulnerability or active exploit. The IOC serves as a threat intelligence data point for monitoring and detection purposes.

Potential Impact

There is no direct impact described beyond the presence of a malware-related IOC. No known active exploitation or vulnerabilities are reported. This information supports detection and situational awareness but does not indicate an immediate threat requiring patching or urgent mitigation.

Mitigation Recommendations

No patch or direct remediation is available or required for this IOC. Security teams should incorporate this intelligence into their detection and monitoring systems as appropriate. No urgent action is mandated based on the provided data.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
a03acbf1-881f-4cb3-884b-360fa93e141e
Original Timestamp
1780041610

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/fc6806078742d6b94361a6ba095401bd30ea02ab
hacked_pypirepos
urlhttps://x.com/TekDefense/status/2060075053769720156
hacked_pypirepos
urlhttps://sandyclaw.permiso.io/shared/dcpgKUGkdIoQB6ofXHOWNsoe51Koohh0GDXkU0xD9Dg#network-activity
hacked_pypirepos
urlhttps://api.github.com/repos/stamparm/maltrail/commits/29f7f352025526cc1b3f4c7cca002ef599ff7f52
apt_kimsuky
urlhttps://x.com/skocherhan/status/2060069310840844770
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/cb8e25da30ac6b2d394e9cf53c79b54e957c91c6
fakeapp
urlhttps://x.com/patialavii/status/2060198653751640208
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/88d3624a770f67f54723cc718b3f680be419b056
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5f2e973d2690b652afc9bdb96c09a5f03357e5fb
osx_atomic
urlhttps://x.com/masaomi346/status/2060149098226057266
osx_atomic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/3ba6014651c2be06ef56a0c0e87b5df11627ad20
apt_kimsuky
urlhttps://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant
apt_kimsuky

Domain

ValueDescriptionCopy
domainaab.sportsontheweb.net
hacked_pypirepos
domain0t3ofn4r21.dns.navy
apt_kimsuky
domain41mhzh442tc.dns.navy
apt_kimsuky
domain46fy9m5lc2.dns.navy
apt_kimsuky
domain4x97qnzirrl.dns.navy
apt_kimsuky
domain52f6qb4jai.dns.navy
apt_kimsuky
domainc4f0rhn5qdp.dns.navy
apt_kimsuky
domaindns.reward.freeddns.org
apt_kimsuky
domainnusetx.dns.army
apt_kimsuky
domainooolde0khlq.dns.navy
apt_kimsuky
domainreward.freeddns.org
apt_kimsuky
domainrffiuystub.dns.navy
apt_kimsuky
domainzalcjrft0zv.dns.navy
apt_kimsuky
domainzom-6ep.pages.dev
fakeapp
domain31q1gqglqrqi5blzyi269rf0d02ex0.live
fakeapp
domain747aqkwvpmipxaag7fwsilshk9y6ch.live
fakeapp
domainlejqhwd0odw1kig0t8k7cg87yfy4f9.live
fakeapp
domainblueprintmesh.com
osx_atomic
domainbigfile.crabdance.com
apt_kimsuky
domainconference.birdriver.org
apt_kimsuky
domainhdrgdrfes.chickenkiller.com
apt_kimsuky

Threat ID: 6a1975fce29bf47b50dd2a2d

Added to database: 5/29/2026, 11:18:20 AM

Last enriched: 5/29/2026, 11:33:25 AM

Last updated: 5/29/2026, 6:19:49 PM

Views: 9

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses