Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-06-09

0
Medium
Published: Mon Jun 08 2026 (06/08/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed

Description

Maltrail IOC for 2026-06-09

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/09/2026, 21:42:42 UTC

Technical Analysis

The report details a Maltrail IOC identified on 2026-06-09, indicating detection of suspicious or malicious network activity. The information is derived from open-source intelligence and represents an observation rather than a confirmed active threat or vulnerability. No affected software versions or specific malware signatures are included, limiting the technical detail available.

Potential Impact

The impact is assessed as medium risk based on the source classification. However, without specific indicators or exploitation details, the direct impact on systems cannot be precisely determined. There are no known exploits in the wild associated with this IOC at this time.

Mitigation Recommendations

No patch or official remediation is available for this IOC. Security teams should incorporate the IOC into their detection and monitoring tools as appropriate. Since this is an OSINT observation, no immediate action is mandated beyond standard network monitoring and threat intelligence integration.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
70a24add-ca6c-48d7-8196-280b648237fd
Original Timestamp
1781035210

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a03c616c0a82c03077488b17bc965421f66a986f
fakeapp
urlhttps://github.com/hagezi/dns-blocklists/issues/10457
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/3f301fd3a1bc5226548e50f92488d662f61429ff
op512
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1aa3abf13065cebf809a296d8bb05e621f30b75b
vidar
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d2e0c229cca80850419a9bdf76fc3e5d91e1f3dc
fakeapp
urlhttps://www.virustotal.com/gui/ip-address/80.78.24.169/relations
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5f7f7941277efd085a67f6eefa9a260684b3b229
fakeapp
urlhttps://www.microsoft.com/en-us/security/blog/2026/06/08/ai-brands-as-bait-how-threat-actors-are-using-the-ai-hype-in-social-engineering
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5cf1b3a83f7d3eb43168c7bb6ded1d9d4b30e000
vidar
urlhttps://api.github.com/repos/stamparm/maltrail/commits/9f8ac6a630f1128e1eca0ccc63bf54312af40bcc
apt_unc6691
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7668808b0a6030c0e269827ad05e21bca7b57c87
apt_unc6691
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ebdd67baab06940871ce3c32cc7950764f0d3217
offloader
urlhttps://api.github.com/repos/stamparm/maltrail/commits/8411cad93376bdb02f98da035700c235f620d1de
osx_atomic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/90bc2c371f59691a7753d35c2067701b73493ffa
osx_nova
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d9f3a50786280e277cba76ec85dc3dc3bc77f955
apt_unc2465
urlhttps://api.github.com/repos/stamparm/maltrail/commits/8f50c51c370facefc76c84cf0d8c31198b7a9fff
vidar
urlhttps://api.github.com/repos/stamparm/maltrail/commits/fb45a2b4ebaee87f1e53bc58ac3afabb63da9070
android_joker
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7e78a49979639dfe77b5d5a8b3f4d01a78f1c307
lummac2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/48e9d4f27f51d6dffacb7ab362f8a895d0901c9e
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/97a5cc65f45a225c417bd547bf88bdac19d65021
cyberstrikeai
urlhttps://api.github.com/repos/stamparm/maltrail/commits/dad9feabf41f81652786d3d20c55ae165757624b
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/b709819b72b9c1b5d318ff02e0305ad0bfcbb024
giftedcrook
urlhttps://www.trendmicro.com/en_us/research/26/f/old-winrar-flaw-fuels-attacks-on-ukraine.html
giftedcrook
urlhttps://api.github.com/repos/stamparm/maltrail/commits/051c16b32a64ccc3ed51f96722cdd9f925952717
metasploit
urlhttps://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware
metasploit
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a6c906e7b7c5d591d68a041c0e676f53cb989126
apt_lazarus
urlhttps://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/071914e5663924c2f857c1e7d1ebcda7ba51d741
powershell_injector
urlhttps://www.virustotal.com/gui/file/7127cb878cab370d24ef87cf0145c2e4af63bd021f67b58d08ed30f87b78afa1/detection
powershell_injector
urlhttps://api.github.com/repos/stamparm/maltrail/commits/84f0eefcb198ff0f3a6ce15146abb043f6e01e5e
osx_nova
urlhttps://x.com/malwrhunterteam/status/2064285953351389281
osx_nova
urlhttps://api.github.com/repos/stamparm/maltrail/commits/aac6cf88b33384f08669c3b7648da539b201957b
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/55f15cd23b3ddf60a6fa220a3778589742754d90
fakeapp
urlhttps://x.com/abuse_ch/status/2064421055515570412
fakeapp
urlhttps://www.virustotal.com/gui/file/91ed53ad7977c0fa482c5a58c0590512a621852fd5bc4303e5bf209a1117b30d/detection
fakeapp
urlhttps://www.virustotal.com/gui/file/b1aa30190c7000337b4e3466db07dad3cff5d2b61ebeeecf1bda85fb27677e68/detection
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/b5307ec889aa246a417a216e74c1ded2dc73a90b
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/bcdf9e4c6b0871c3e4136fe9ca76772139ba176d
apt_lazarus
urlhttps://x.com/malwrhunterteam/status/2064325045938274373
apt_lazarus
urlhttps://www.virustotal.com/gui/file/c7a24e1fc68b7233e1c93c02409e9429a1ea5cf0662eb4cd03364373df7d7044/detection
apt_lazarus
urlhttps://www.virustotal.com/gui/file/9d7576046152695728ead43e9752a105ef2641ef6317ff8d47094b8f541835b2/detection
apt_lazarus
urlhttps://www.virustotal.com/gui/file/70f732e98634c3f887d84ba8acb1ee7b62e4f865ea4cb1be1edf32c40c27ae51/detection
apt_lazarus
urlhttps://www.virustotal.com/gui/file/51e1f3a97629e8db50ca1f9a0b68c019e74c07ce5209d5eefd4a2e3f4fe62869/detection
apt_lazarus
urlhttps://www.virustotal.com/gui/file/322b2eb4e4d61ec6a746e3da421e8fd9c62ce4f919f03aed373f663de539b2ba/detection
apt_lazarus
urlhttps://www.virustotal.com/gui/file/068505fab1dc1b784ddc845c9eeeba8e04da512383ecd55a7a3d076879656393/detection
apt_lazarus

Domain

ValueDescriptionCopy
domain51mitu.com
fakeapp
domainai-kit.cn
fakeapp
domainai.deepseekem.com
fakeapp
domainaideepseek.cc
fakeapp
domainchat-deep.ai
fakeapp
domainchat.51mitu.com
fakeapp
domainchat.mixinnet.cn
fakeapp
domainchats.mixinnet.cn
fakeapp
domaindeeeseek.com
fakeapp
domaindeep-seek.ai
fakeapp
domaindeep-seek.com
fakeapp
domaindeepseek-free-r1.github.io
fakeapp
domaindeepseek-go.com
fakeapp
domaindeepseek-plus.github.io
fakeapp
domaindeepseek-v4.io
fakeapp
domaindeepseek.ai-kit.cn
fakeapp
domaindeepseek.chat
fakeapp
domaindeepseek.net
fakeapp
domaindeepseek404.com
fakeapp
domaindeepseekaigo.cyou
fakeapp
domaindeepseekapi.cc
fakeapp
domaindeepseekapp.cc
fakeapp
domaindeepseekcn.cyou
fakeapp
domaindeepseekcoder.github.io
fakeapp
domaindeepseekem.com
fakeapp
domaindeepseekplus.cc
fakeapp
domaindeepseeksai.com
fakeapp
domaindeepseeksr1.com
fakeapp
domaindeepseekss.com
fakeapp
domaindeepseekweb.cc
fakeapp
domaindsai.cc
fakeapp
domainhk-deepseek.com
fakeapp
domainmixinnet.cn
fakeapp
domainweb.deepseekaigo.cyou
fakeapp
domainai-deepseek.com.cn
op512
domainai-deepseel.com.cn
op512
domainapp-deepseek.com.cn
op512
domainapp-deepseekcn.com.cn
op512
domainch-deepseek.com.cn
op512
domaincn-deepseek.com.cn
op512
domaindeepaesk.com.cn
op512
domaindeepseek.ai
op512
domaindeepseekapp.com.cn
op512
domaindeepseekl.com.cn
op512
domaindeepseik.com.cn
op512
domaindeepsesk.com.cn
op512
domaindeepsiek.com.cn
op512
domaindeepssek.com.cn
op512
domaincha.rongtv.xyz
vidar
domaincha.ssffaa19.xyz
vidar
domainggl.rongtv.xyz
vidar
domainggl.ssffaa19.xyz
vidar
domainnlf.rongtv.xyz
vidar
domainnlf.ssffaa19.xyz
vidar
domainsndvol32.com
fakeapp
domainbrokeapt.com
fakeapp
domainrongtv.xyz
vidar
domainssffaa19.xyz
vidar
domainpan.rongtv.xyz
vidar
domainpan.ssffaa19.xyz
vidar
domain985.ad
apt_unc6691
domainayxfaga.com
apt_unc6691
domainbgpuome.com
apt_unc6691
domaindgxcybe.com
apt_unc6691
domaindmjhaha.com
apt_unc6691
domaindpzhhdj.com
apt_unc6691
domaindygutvb.com
apt_unc6691
domaineskezgn.com
apt_unc6691
domainfdutcor.com
apt_unc6691
domainjuxihawqvgc89.click
apt_unc6691
domainloydfst.com
apt_unc6691
domainlyfmaex.com
apt_unc6691
domainmgmy.my
apt_unc6691
domainmkhygqxasfc.click
apt_unc6691
domainmtdxmgl.com
apt_unc6691
domainnjixzni.com
apt_unc6691
domainnsicksf.com
apt_unc6691
domainogbxtmj.com
apt_unc6691
domainpmrejwb.com
apt_unc6691
domainqanhtrx.com
apt_unc6691
domainrmkncoo.com
apt_unc6691
domaintrs668.cc
apt_unc6691
domaintubeuyd.com
apt_unc6691
domainveadvhb.com
apt_unc6691
domainvymgwac.com
apt_unc6691
domainwuxi.trs668.cc
apt_unc6691
domainxdgxuln.com
apt_unc6691
domainxjiyuerbfa48y.xyz
apt_unc6691
domainxjtqqai.com
apt_unc6691
domainzuyuhtv.com
apt_unc6691
domainfruitbeginner.space
offloader
domainapricotfilepoint.com
osx_atomic
domaincardlumeonline.com
osx_atomic
domainfilecrystalhaven.com
osx_atomic
domainfileprairiestudio.com
osx_atomic
domainfilerubycompass.com
osx_atomic
domainfilesilverharbor.com
osx_atomic
domainftemu.com
osx_atomic
domaingrapefruitfilezone.com
osx_atomic
domainhorizonfilevalley.com
osx_atomic
domainkiwifilecenter.com
osx_atomic
domainorangefilehub.com
osx_atomic
domainpearfiledepot.com
osx_atomic
domainpipeplane.cfd
osx_atomic
domainrainfont.com
osx_atomic
domaintorcyber.com
osx_atomic
domainfees-pumps.fun
osx_nova
domainscanwallet-pump.fun
osx_nova
domaintoknportl.pro
osx_nova
domaintoknportl.site
osx_nova
domaintoknportl.space
osx_nova
domainbestgames-play.com
apt_unc2465
domaincreditanova.com
apt_unc2465
domaincrestpoints.it.com
apt_unc2465
domainlorettostorage.com
apt_unc2465
domainocalatreeservices.com
apt_unc2465
domainplay-best-games.online
apt_unc2465
domainsofort-gelds.com
apt_unc2465
domaintrailerflorida.com
apt_unc2465
domainb.howartin.top
android_joker
domainhowartin.top
android_joker
domainpassedt.cyou
lummac2
domainattachfile.verymad.net
apt_kimsuky
domaincc.attachfile.verymad.net
apt_kimsuky
domainlog.signer.dns.army
apt_kimsuky
domainsigner.dns.army
apt_kimsuky
domaincsai.hkinfosecurity.com
cyberstrikeai
domaintolerancemodernincruiter.com
apt_lazarus
domainalphanonega.org
apt_lazarus
domainasteara.org
apt_lazarus
domaincareerpredictto.space
apt_lazarus
domaincareerpulsynk.xyz
apt_lazarus
domaincareertrixauvex.ink
apt_lazarus
domainceronet.work
apt_lazarus
domainceronetwork.org
apt_lazarus
domainconnectptogether.ink
apt_lazarus
domaincontactpredicttogether.ink
apt_lazarus
domaincontactpulsynk.ink
apt_lazarus
domaincontacttrixauvex.ink
apt_lazarus
domaincoslyintra.online
apt_lazarus
domaincotrixauvex.ink
apt_lazarus
domainculyrax.us
apt_lazarus
domaindeep-ai-guard.store
apt_lazarus
domaindomatisc.ink
apt_lazarus
domaindoxxela.ink
apt_lazarus
domainelsavora.us
apt_lazarus
domainempowerpharmacy.space
apt_lazarus
domainhyperdevpipline.org
apt_lazarus
domainmailpredicttogether.ink
apt_lazarus
domainmailpulsynk.xyz
apt_lazarus
domainpinnacle-labs.lat
powershell_injector
domainprism-tech.cfd
powershell_injector
domainbill-boss-mac.github.io
osx_nova
domainmailtrixauvex.ink
apt_lazarus
domainmigadyn.info
apt_lazarus
domainnemesistrade.work
apt_lazarus
domainnotifypulsynk.ink
apt_lazarus
domainnowurisch.fit
apt_lazarus
domainnxlog.tech
apt_lazarus
domainondofinance.tech
apt_lazarus
domainonoplainai.ink
apt_lazarus
domainonoplanoai.ink
apt_lazarus
domainoptixauvex.us
apt_lazarus
domainpredictcareertogether.space
apt_lazarus
domainpredicttocareer.space
apt_lazarus
domainpredicttogerecruit.store
apt_lazarus
domainpredicttogether.ink
apt_lazarus
domainpredicttogetherrecruit.store
apt_lazarus
domainpulsynk.org
apt_lazarus
domainraxvatange.ink
apt_lazarus
domainrecruitptogether.xyz
apt_lazarus
domainrecruitvex.us
apt_lazarus
domaintalentnexhr.ink
apt_lazarus
domainteampulsynk.team
apt_lazarus
domaintogetherhire.fun
apt_lazarus
domaintrixauvex.org
apt_lazarus
domaintrixauvexnet.ink
apt_lazarus
domainvalorecuiting.online
apt_lazarus
domain3la6ol.net
apt_lazarus
domainbackup.coinbase-backup.com
apt_lazarus
domainbugnol.com
apt_lazarus
domaincoinbase-backup.com
apt_lazarus
domaindezertir.com
apt_lazarus
domaineager-shockley.144-172-108-248.plesk.page
apt_lazarus
domainfax-cover.com
apt_lazarus
domainhahaios.com
apt_lazarus
domainhvdaconversions.com
apt_lazarus
domainid37093.com
apt_lazarus
domainmail.reuniao21.admescolassistema.com
apt_lazarus
domainmonade.online
apt_lazarus
domainrecruiterlogon.company
apt_lazarus
domainaz2030port.duckdns.org
fakeapp
domainlab99.sbs
apt_lazarus

Ip

ValueDescriptionCopy
ip91.92.43.71
vidar
ip136.0.141.112
giftedcrook
ip136.0.141.41
giftedcrook
ip166.0.132.237
giftedcrook
ip23.26.237.80
giftedcrook
ip38.225.209.122
giftedcrook
ip38.225.209.229
giftedcrook
ip166.62.100.62
metasploit
ip166.62.100.52
metasploit
ip23.137.105.75
apt_lazarus
ip144.172.108.225
apt_lazarus
ip144.172.108.248
apt_lazarus
ip144.172.112.213
apt_lazarus
ip144.172.115.177
apt_lazarus
ip144.172.89.183
apt_lazarus
ip209.182.224.49
apt_lazarus
ip216.126.225.67
apt_lazarus
ip216.126.237.200
apt_lazarus
ip178.16.55.28
fakeapp
ip216.126.225.243
apt_lazarus

Threat ID: 6a2884cb8dd33fbd85814801

Added to database: 6/9/2026, 9:25:31 PM

Last enriched: 6/9/2026, 9:42:42 PM

Last updated: 6/9/2026, 10:35:00 PM

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses