Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-06-03

0
Medium
Published: Tue Jun 02 2026 (06/02/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed

Description

Maltrail IOC for 2026-06-03

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/03/2026, 13:18:25 UTC

Technical Analysis

The report details a malware-related IOC identified by Maltrail on 2026-06-03, sourced from CIRCL OSINT. It is categorized under OSINT and network activity but lacks specific technical indicators or affected software versions. No exploits or patches are associated with this IOC. The data serves as an external analysis observation to support threat intelligence efforts.

Potential Impact

The impact is currently limited to awareness of potential malware-related network activity. There are no known exploits in the wild and no affected software versions identified, indicating no direct vulnerability or exploit to remediate at this time.

Mitigation Recommendations

No patch or official remediation is available or required. Security teams should incorporate this IOC into their detection and monitoring tools as appropriate. Since this is an observational IOC without actionable exploit details, no urgent remediation actions are necessary.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
f828f058-5a81-4142-a0b3-b47e28c71e2a
Original Timestamp
1780488010

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/53007f48e07f7e1b5cf2aaf0d70e36985c548316
android_fvncbot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c5ae4119bcfe6df53417d2fc5b6b8b9a34fc7140
offloader
urlhttps://api.github.com/repos/stamparm/maltrail/commits/39d6973f904df841a91e55ce8c2154654b12b6a8
osx_nova
urlhttps://api.github.com/repos/stamparm/maltrail/commits/6899ef534ad323f43dc030e93be8221cd633c7dc
osx_atomic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/087ea6483d9ed8dc2f6e9d48c73775c8d06485a7
dynamic_domain
urlhttps://urlscan.io/result/019e8c72-eaae-771d-88eb-df58d0ab6221
dynamic_domain
urlhttps://api.github.com/repos/stamparm/maltrail/commits/8e2690769b86df153cc6be4b4d09dd9e4be38f52
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c8e73242425968a41c4346f6de1e4391017e6f64
lummac2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/242ead648a89ceffbf7933c088a47a5fcf25f4f2
ek_landupdate808
urlhttps://api.github.com/repos/stamparm/maltrail/commits/9ee0dd682671643f5ae4831a0f46ee9627b8f435
free_web_hosting
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4d5e1bf8e162b900b8ba362ab8293aec48de8b6e
hak5cloud_c2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/23232e97ede9dae4db4fcfe065f4795d7b16ec61
supershell_c2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/13fba8ff0f5dc6f9a01d3497de575413da031d1a
c2_panel
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4ac05e5847988676bfad562d6c0d49ff626e4334
peaklight
urlhttps://api.github.com/repos/stamparm/maltrail/commits/395f67e5765af4a98021f7f74c8c6ff50fb72c8e
adaptix_c2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/58e50c48a260fd0647a52de21e478cae66ceedda
netsupport
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4aacd763401a47494bcdf0c5619606924f138656
apt_unc2465
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c115125457d9fceefcae9111acb7f7a292e32ac6
1312
urlhttps://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-as-a-service-campaign-research
1312
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4d526f11dd41cc39d349c00bcc4361953bce41b3
apt_lazarus
urlhttps://mp.weixin.qq.com/s/3kwDMAXviaE1TUDnkYlqrg
apt_lazarus
urlhttps://www.virustotal.com/gui/file/09cc7c879b7facbda5349a8d273f8fac6b9be8c3f9927820bcd04583114564eb/detection
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ff4d44454c4630d058e7e1666343525880980901
plugx
urlhttps://x.com/malwrhunterteam/status/2062110058343698897
plugx
urlhttps://www.virustotal.com/gui/file/b4f02aaa43b86d151c11a945d01e9b60eb37227e2a552cc67ecdcb475e21eb67/detection
plugx

Domain

ValueDescriptionCopy
domaincdn.eddvbaz.icu
android_fvncbot
domainduhjett.icu
android_fvncbot
domaineddvbaz.icu
android_fvncbot
domainoonaent.icu
android_fvncbot
domainoopple.icu
android_fvncbot
domaintyhbnee.icu
android_fvncbot
domainuunatt.icu
android_fvncbot
domainytrtyab.icu
android_fvncbot
domainfuelleg.info
offloader
domainvolcanomountain.xyz
offloader
domainleinkideen.com
osx_nova
domainljnkideen.com
osx_nova
domainfilecedarwallet.online
osx_atomic
domainfilecrimsonsignal.online
osx_atomic
domainfilegoldenengine.online
osx_atomic
domainfilegranitecamera.online
osx_atomic
domainfilehiddenvalley.com
osx_atomic
domainfilehorizoncastle.online
osx_atomic
domainfilejadewallet.online
osx_atomic
domainfilepineplanet.online
osx_atomic
domainfilestormcoffee.online
osx_atomic
domaindynu.org
dynamic_domain
domainhets22ex.dns.army
apt_kimsuky
domainn-cloud.nndvdoc.dynv6.net
apt_kimsuky
domainnaver.craftleds.com
apt_kimsuky
domainnblog4krs.dynu.org
apt_kimsuky
domainncodbzcheck.dynv6.net
apt_kimsuky
domainncodckpass.dns.navy
apt_kimsuky
domainnid-user.hets22ex.dns.army
apt_kimsuky
domainnid.naver.craftleds.com
apt_kimsuky
domainnid.ncodckpass.dns.navy
apt_kimsuky
domainnids.nblog4krs.dynu.org
apt_kimsuky
domainnndvdoc.dynv6.net
apt_kimsuky
domainnskrm.dynv6.net
apt_kimsuky
domainntaxe9otp.dynv6.net
apt_kimsuky
domainntpx5ee.dns.army
apt_kimsuky
domainntxr12os.dns.army
apt_kimsuky
domainnuser-login.nskrm.dynv6.net
apt_kimsuky
domaintals1ex.dynv6.net
apt_kimsuky
domainfeathqz.cyou
lummac2
domainblbnchard.lol
ek_landupdate808
domainmarqueq.lol
ek_landupdate808
domainwixstudio.com
free_web_hosting
domainc2.olivermeowface.com
hak5cloud_c2
domainns1.astahin.com
adaptix_c2
domainns2.astahin.com
adaptix_c2
domainsso.global-muangthai.com
adaptix_c2
domainxldr004.online
adaptix_c2
domainalterasgroup.it.com
apt_unc2465
domainbuyitallnow.com
apt_unc2465
domaingaragedoorscentralflorida.com
apt_unc2465
domainthenarcjournal.com
apt_unc2465
domaindonutdupe.xyz
1312
domainfriendlydomain.ru
1312
domainkryptonclient.gg
1312
domainnova-client.com
1312
domainodinclient.com
1312
domainsimplevoicechatmod.co
1312
domainskyhanni.net
1312
domainskytils.net
1312
domainweedhack.to
1312
domainweedhack.xyz
1312
domainwhack.cy
1312
domainwhnewreceive.ru
1312
domainwhpayment.ru
1312
domainwhrc.ru
1312
domainwhreceiverrrrrrrrr.ru
1312
domainwhtempdomain.com
1312
domainxenonclient.com
1312
domainmagazineschool.co.kr
apt_lazarus

Ip

ValueDescriptionCopy
ip1.117.77.166
supershell_c2
ip101.42.104.134
supershell_c2
ip115.159.72.181
supershell_c2
ip195.177.94.62
c2_panel
ip45.13.212.253
netsupport
ip45.182.189.98
netsupport
ip43.142.9.118
plugx

Threat ID: 6a202619e29bf47b50b6a865

Added to database: 6/3/2026, 1:03:21 PM

Last enriched: 6/3/2026, 1:18:25 PM

Last updated: 6/3/2026, 4:27:20 PM

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses