Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-06-10

0
Medium
Published: Tue Jun 09 2026 (06/09/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed

Description

Maltrail IOC for 2026-06-10

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/10/2026, 17:39:47 UTC

Technical Analysis

The report details a Maltrail IOC dated 2026-06-10, indicating detection of suspicious or malicious network activity associated with malware. It is sourced from the CIRCL OSINT Feed and classified as an external OSINT observation with medium threat level. No technical exploit details, affected software versions, or known active exploits are documented. This is an intelligence observation rather than a software vulnerability or exploit requiring patching.

Potential Impact

The impact is limited to the detection of malware-related network activity as indicated by the IOC. There is no direct information about exploitation, affected software, or systems. The medium severity suggests a moderate risk level for network security monitoring and incident response.

Mitigation Recommendations

No patch or official remediation is applicable for this IOC. Security teams should incorporate this IOC into their detection and monitoring systems to identify potential malicious activity. Follow standard incident response procedures if the IOC is observed in network traffic.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
a569ecc1-9e0d-413a-bb85-50ada5e643c2
Original Timestamp
1781110804

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c334ebfee9db15fa23ad5a8e4a264655f673c927
urlhttps://www.virustotal.com/gui/ip-address/184.174.96.105/relations
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a1bd6a53be5f7b86e593d28da76fccd697d926f8
magentocore
urlhttps://api.github.com/repos/stamparm/maltrail/commits/b00b6c20b3791d9267cc00599681a28ea069c9ad
cyberstrikeai
urlhttps://api.github.com/repos/stamparm/maltrail/commits/fe0de778506d54e2761521984004cbb5d0e65bee
apt_sidewinder
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a40910f3fcfdac1de74d7d780df4b6e8d8daa45e
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/3f3491e7ffedf5457d3769b5523391e5ec9463e8
powershell_injector
urlhttps://api.github.com/repos/stamparm/maltrail/commits/0b82355fab77526642e23235ea79b9b2fdf71a9c
powershell_injector
urlhttps://www.virustotal.com/gui/file/1ca86dcafd0b6d208c072760919b38b830ca907f8cc3c77401275731d422ce63/detection
powershell_injector
urlhttps://api.github.com/repos/stamparm/maltrail/commits/22bfbd5189d9486a999bdba54c6e3fbcd54ab276
adaptix_c2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5216110cf368cdfe9faf110acf6b13e19e7335a7
netsupport
urlhttps://api.github.com/repos/stamparm/maltrail/commits/01296598344a41f458600afd37ade45ad5c73ce3
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/779d7edce8769287577c8e7a398fcfe6945c4c11
lummac2
urlhttps://www.virustotal.com/gui/ip-address/2.27.5.124/relations
lummac2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/849709ee1c7c0a091f94341f876fb2e58554ad23
osx_nova
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4c3e233cce3ba15112f6bc2debaf15b469fc0f7b
android_fvncbot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/69096bd069bfe484dbf018c2538173aec73d8456
osx_atomic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1073cb4d0bcff5dc4c07719b67c2c5cfa4f8ac92
lummac2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/be4f831a22b5689c92f48246b2e8eb2899ef6e3d
android_joker
urlhttps://api.github.com/repos/stamparm/maltrail/commits/e712b9e88a9acbfa7fd71627c6fff4f9e7169f95
lkmc2
urlhttps://x.com/solostalking/status/2063834202454598012
lkmc2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/99a7eec5efab4a7a405a51624b59ebb508f17579
ek_landupdate808
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1715b7f4a7f6cddd342588b7ad2f7617a13c20cd
mlt
urlhttps://api.github.com/repos/stamparm/maltrail/commits/8094df8739c46a40080b399e751c15ff328fc028
mlt
urlhttps://www.zscaler.com/blogs/security-research/technical-analysis-mltbackdoor
mlt
urlhttps://api.github.com/repos/stamparm/maltrail/commits/33c837024539b66e00c96792ef4417c66587cd13
agenttesla
urlhttps://x.com/tdatwja/status/2064539059540959522
agenttesla
urlhttps://www.virustotal.com/gui/file/bb52887a2013478c31dd9b9e8272e4702212b1163877bea8602eb6eb761067a9/detection
agenttesla
urlhttps://api.github.com/repos/stamparm/maltrail/commits/736fc30b3cc8f58c35858687aa6c40c4f307f7db
c2_panel
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4b0d4ed5c2f971ef107c2b7aac55c41ce8a5e69c
peaklight
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f3ebc84e87252fed641cc914c238937935dd2493
tsundere
urlhttps://www.virustotal.com/gui/file/56058b92ce87a8e6a46b1b9a71e2cd0b32325e6a54e26d6e500f3b0b0f05cc0b/detection
tsundere
urlhttps://api.github.com/repos/stamparm/maltrail/commits/dffbde9662b08a06fdeafe31c5d259826766352d
nightshadec2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/76c572a2726319868e1e8b142934a75be4c2e6f0
offloader
urlhttps://api.github.com/repos/stamparm/maltrail/commits/14671b974e9ccb8802f0d2b983de9a4cc00ba79e
discordgrabber
urlhttps://www.virustotal.com/gui/file/45171981ac23dcb7e90dd9a3ce07415720be92815bcd2ccfe51e716d736eab3e/detection
discordgrabber
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d93f5f988f2c6972c46f30c7fc61809e8dd06f8a
python_injector
urlhttps://www.virustotal.com/gui/file/29aa6c06316bde50348ae1483ef746d1413ca8c02230692ac697c84b7863f30c/detection
python_injector
urlhttps://api.github.com/repos/stamparm/maltrail/commits/1bf8d6af97f185639fd850b2d6d791a4157c71bd
apt_kimsuky
urlhttps://x.com/skocherhan/status/2064423269063704732
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/6cc04f186be1942e5c9bcba8804ced88c0588061
connectwise
urlhttps://x.com/smica83/status/2064668946775650676
connectwise
urlhttps://tria.ge/260610-nx8cgsa14r/behavioral1
connectwise
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f67175a29e7e6832eef3ec3516cda3b0adf20594
apt_kimsuky
urlhttps://x.com/skocherhan/status/2064418614216622388
apt_kimsuky
urlhttps://api.github.com/repos/stamparm/maltrail/commits/89f595d525ac0154454333465ae24bf1947c7453
apt_transparenttribe
urlhttps://x.com/goldenjackel12/status/2064679226838806667
apt_transparenttribe
urlhttps://www.virustotal.com/gui/file/abfac8026d1974220871568caf9344cbffed19a184ff098c0912ffbb4f1e42d5/detection
apt_transparenttribe
urlhttps://api.github.com/repos/stamparm/maltrail/commits/59d8dcee3de05fdeb1acc3a9ed588a7dcd952645
fakeapp
urlhttps://x.com/smica83/status/2064644653031235914
fakeapp
urlhttps://www.virustotal.com/gui/file/dec8dc49fc34fe5898e452a1dd98b98d6a8704d55458982b3b7af05bf52016ca/detection
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/dba1aa295370c57add32458ada24eaade3fb959e
osx_atomic
urlhttps://www.malware-traffic-analysis.net/2026/06/09/index.html
osx_atomic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c8263ba7e66ca9f9606e7828449e3eda6c922f4a
supershell_c2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/de6bc9ce160f0db498aae50e46d8ee91a4a4dfc4
medusa_c2
urlhttps://www.virustotal.com/gui/ip-address/41.216.188.11/relations
medusa_c2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/cbf454b8189b95afe81b7f0ea9aaee8be464a52d
apt_sidewinder
urlhttps://x.com/volrant136/status/2064713040029991309
apt_sidewinder
urlhttps://api.github.com/repos/stamparm/maltrail/commits/daf41ccbffe96eeb4184dbc6d625381a3abcffac
apt_sidewinder

Domain

ValueDescriptionCopy
domainbswinpay.com
domaingoogle-analysis.net
magentocore
domaincyber.zeroa.dev
cyberstrikeai
domainpk-cc.com
apt_sidewinder
domainpk-qrs.online
apt_sidewinder
domainvisa.nadra.gov.pk-cc.com
apt_sidewinder
domainalqaflah.com
apt_lazarus
domainadmin.rohapowers.com
apt_lazarus
domainfriendly-trifle-f3e6f0.netlify.app
powershell_injector
domaint-internal.sk
adaptix_c2
domainweb.wpscdm.top
adaptix_c2
domainhets12ex.dns.army
apt_kimsuky
domainncodcmcheck.dns.navy
apt_kimsuky
domainpoldoc3osp.dns.army
apt_kimsuky
domaincohesrc.cyou
lummac2
domainlossesbacks-pump.fun
osx_nova
domainrugsback-pumps.fun
osx_nova
domaincdn.uijaeea.icu
android_fvncbot
domaincoconutfilebase.com
osx_atomic
domainnewclaybvas.com
osx_atomic
domainclaimsj.cyou
lummac2
domainauedit.pw
android_joker
domainfrancoife.lol
ek_landupdate808
domainglegchner.com
mlt
domaintillmat.com
mlt
domaincarrolc.com
mlt
domainhrs2y15sungu.com
mlt
domainpowwowski.com
mlt
domainenogcaen-br.com
agenttesla
domainftp.enogcaen-br.com
agenttesla
domainaravisblog.com
tsundere
domain25hill.com
nightshadec2
domainaltwebsitesgroup.com
nightshadec2
domainbauama.com
nightshadec2
domainbelderbossolicitors.com
nightshadec2
domainblessedhomehealthcare.com
nightshadec2
domaincreekstonedental.com
nightshadec2
domaineconestexperts.com
nightshadec2
domainflastergroup.com
nightshadec2
domainperivolaslifestylehotel.com
nightshadec2
domainsicapotec.com
nightshadec2
domainsurfingticket.com
nightshadec2
domainthe-stonefamily.com
nightshadec2
domainboatdesk.xyz
offloader
domainrailcountry.xyz
offloader
domainastrovaultnet.site
apt_kimsuky
domaincryptonexium.store
apt_kimsuky
domaindynavoltmedia.site
apt_kimsuky
domaineagleapple.sbs
apt_kimsuky
domainechoanswer.website
apt_kimsuky
domainedgeanimal.cyou
apt_kimsuky
domaineffectangry.cfd
apt_kimsuky
domainelectricapril.space
apt_kimsuky
domainemotionarea.homes
apt_kimsuky
domainenergyagree.store
apt_kimsuky
domainescapeafraid.site
apt_kimsuky
domainfailuremiss.site
apt_kimsuky
domainfangtongen.homes
apt_kimsuky
domainfatherbismake.sbs
apt_kimsuky
domainfusionmatrixx.cfd
apt_kimsuky
domaingamesticky.homes
apt_kimsuky
domaingerogemelt.sbs
apt_kimsuky
domainghanacity.cyou
apt_kimsuky
domaingoalkeeperwrok.store
apt_kimsuky
domainhappycamera.sbs
apt_kimsuky
domainhealthcookie.store
apt_kimsuky
domainhistorycredit.homes
apt_kimsuky
domainhopecotton.cyou
apt_kimsuky
domainhorsecircle.site
apt_kimsuky
domainhousecandle.cfd
apt_kimsuky
domainhypernexlogic.sbs
apt_kimsuky
domaininfinitexlabs.cyou
apt_kimsuky
domainlunargridnet.space
apt_kimsuky
domainmountainspeedon.org
apt_kimsuky
domainnexorafusion.space
apt_kimsuky
domainngtoscieuebxsdt.xn
apt_kimsuky
domainnkvcyephcwxsosun.n-e.kr
apt_kimsuky
domainnoovpnqcompsi.p-e.kr
apt_kimsuky
domainodawruxpawp.p-e.kr
apt_kimsuky
domainolqptwmezvwkg.n-e.kr
apt_kimsuky
domainomnicorelabs.shop
apt_kimsuky
domainopkffbeqgsfg.xn
apt_kimsuky
domainorbitalsphere.cyou
apt_kimsuky
domainoufhwfumzgu.xn
apt_kimsuky
domainpckeafrycrzhfk.xn
apt_kimsuky
domainpifibkwurbvnt.p-e.kr
apt_kimsuky
domainpijrhhdfjvvywzgs.xn
apt_kimsuky
domainpixelstormhub.online
apt_kimsuky
domainpnciwegahznhkccn.o-r.kr
apt_kimsuky
domainpnivrdywbhd.xn
apt_kimsuky
domainpotgdxontxnx.p-e.kr
apt_kimsuky
domainppsfzamdsndrac.n-e.kr
apt_kimsuky
domainptombmttnprrvo.n-e.kr
apt_kimsuky
domainqsplzhqgvvtjfu.n-e.kr
apt_kimsuky
domainquantivexhub.shop
apt_kimsuky
domainqvitzgacvng.r-e.kr
apt_kimsuky
domainrltkbqbyftuchkkg.xn
apt_kimsuky
domainrmrhpktxugxggmso.o-r.kr
apt_kimsuky
domainrqudcadaburuxbb.xn
apt_kimsuky
domainrsmvoomcxhsp.xn
apt_kimsuky
domainsbfdaxewcrusybq.n-e.kr
apt_kimsuky
domainsiwqajimxmhj.o-r.kr
apt_kimsuky
domainsnrhbyerfgfashr.kro.kr
apt_kimsuky
domainsolarisfusion.cfd
apt_kimsuky
domaintauvzgtnkvzyaxn.p-e.kr
apt_kimsuky
domaintjatcyabvqv.xn
apt_kimsuky
domaintouxaxhrpuut.n-e.kr
apt_kimsuky
domaintrionexglobal.store
apt_kimsuky
domaintykqgpsmqaoh.o-r.kr
apt_kimsuky
domainveltronicbase.website
apt_kimsuky
domainvertexialink.website
apt_kimsuky
domainvortexchainx.sbs
apt_kimsuky
domainzenithcorelab.online
apt_kimsuky
domaingreentotalsecurity.com
connectwise
domainpal0osp.dns.army
apt_kimsuky
domainpal14osp.dns.army
apt_kimsuky
domainpal22osp.dns.army
apt_kimsuky
domainpal35osp.dns.army
apt_kimsuky
domainpal7osp.dns.army
apt_kimsuky
domainpass25op.dns.army
apt_kimsuky
domainpass2op.dns.army
apt_kimsuky
domainpass5op.dns.army
apt_kimsuky
domainpass6op.dns.army
apt_kimsuky
domainpeld12or.dynv6.net
apt_kimsuky
domainpeld2or.dynv6.net
apt_kimsuky
domainpeld7or.dynv6.net
apt_kimsuky
domainpld1ker.dynv6.net
apt_kimsuky
domainplice22osp.dns.army
apt_kimsuky
domainplice32osp.dns.army
apt_kimsuky
domainplice35osp.dns.army
apt_kimsuky
domainplice8osp.dns.army
apt_kimsuky
domainplod5kor.dynv6.net
apt_kimsuky
domainpnx4ods.dynv6.net
apt_kimsuky
domainpol15sx.dynv6.net
apt_kimsuky
domainpol35odr.dynv6.net
apt_kimsuky
domainpold9kr.dynv6.net
apt_kimsuky
domainpoldoc10osp.dns.army
apt_kimsuky
domainpoldoc12osp.dns.army
apt_kimsuky
domainpoldoc13osp.dns.army
apt_kimsuky
domainpoldoc1osp.dns.army
apt_kimsuky
domainpoldoc23osp.dns.army
apt_kimsuky
domainpoldoc34osp.dns.army
apt_kimsuky
domainpoldoc35osp.dns.army
apt_kimsuky
domainpoldoc36osp.dns.army
apt_kimsuky
domainpoldoc4osp.dns.army
apt_kimsuky
domainpolr10es.dynv6.net
apt_kimsuky
domainpolr35es.dynv6.net
apt_kimsuky
domainpolr6es.dynv6.net
apt_kimsuky
domainpolr7es.dynv6.net
apt_kimsuky
domainpols11kc.dynv6.net
apt_kimsuky
domainpols32kc.dynv6.net
apt_kimsuky
domainpot10sx.dynv6.net
apt_kimsuky
domainpot16ice.dns.army
apt_kimsuky
domainpot18ice.dns.army
apt_kimsuky
domainpot28sx.dynv6.net
apt_kimsuky
domainpot32sx.dynv6.net
apt_kimsuky
domainpot39sx.dynv6.net
apt_kimsuky
domainpxl34op.dns.army
apt_kimsuky
domainn-cloud.pass5op.dns.army
apt_kimsuky
domainn-cloud.peld7or.dynv6.net
apt_kimsuky
domainn-corp.pal22osp.dns.army
apt_kimsuky
domainn-corp.plod5kor.dynv6.net
apt_kimsuky
domainn-corp.pold9kr.dynv6.net
apt_kimsuky
domainn-corp.polr10es.dynv6.net
apt_kimsuky
domainn-corp.polr35es.dynv6.net
apt_kimsuky
domainn-store.plice32osp.dns.army
apt_kimsuky
domainn-store.pol35odr.dynv6.net
apt_kimsuky
domainn-store.polr7es.dynv6.net
apt_kimsuky
domainn-store.pot28sx.dynv6.net
apt_kimsuky
domainnid-user.pnx4ods.dynv6.net
apt_kimsuky
domainnuser-login.pol15sx.dynv6.net
apt_kimsuky
domainnuser-login.poldoc34osp.dns.army
apt_kimsuky
domainpineappleviewer.info
fakeapp
domainfaq.pineappleviewer.info
fakeapp
domainballad-20.com
osx_atomic
domainchiselvibe.com
osx_atomic
domainlyricopal1.com
osx_atomic
domainsdgf9af72f31706769d32bf1ff66cdec1d1gkj5jg95jg5k0hkg95kg0tk.pages.dev
apt_sidewinder
domain2672ewr5403894534fgdgfd5907e44fdfgdfg67088gdfgfd90e2cbd8b6.pages.dev
apt_sidewinder
domain9af72fg4jg75hg8jg9dfghhfgdh5666k41706769d32bf1f766cdec1d1.pages.dev
apt_sidewinder
domain9af72fg4jg75hg8jg9dfghhfgdh5666k41706769d32bf1f766cdec1d11.pages.dev
apt_sidewinder
domaindnsvay8faydj3f79dje9djr02j101c4atg3c3acdd2a06ca2fb183cf995.pages.dev
apt_sidewinder
domainmail-defence-lk-webmail-imp-view-php-actiob-ri5it-kgfi5kg9.pages.dev
apt_sidewinder
domainmail-navy-lk-4326er48fdu49fgu49fgj549fj349fdj3490fdjk390df.pages.dev
apt_sidewinder
domainsdf-sdgyhsdfg-sdfglksdjh-sdglkjsdglhks-gsdflsdfhhsdfgjklls.pages.dev
apt_sidewinder
domainsdfsdf-tfghfghf546rty6ytuuyjgutyjghj-rtfytr54fghf-fghfg-fg.pages.dev
apt_sidewinder

Ip

ValueDescriptionCopy
ip38.76.169.176
cyberstrikeai
ip46.101.23.113
cyberstrikeai
ip95.85.229.133
powershell_injector
ip45.13.212.231
netsupport
ip103.214.174.248
lkmc2
ip108.61.193.37
lkmc2
ip45.91.81.112
lkmc2
ip45.91.81.190
lkmc2
ip151.247.210.135
c2_panel
ip31.76.16.211
tsundere
ip40.127.11.3
tsundere
ip41.216.188.11
discordgrabber
ip173.249.202.61
connectwise
ip155.117.45.44
apt_transparenttribe
ip156.238.235.199
supershell_c2
ip86.54.42.212
medusa_c2

Threat ID: 6a29a15f22bf768b3a6d83ec

Added to database: 6/10/2026, 5:39:43 PM

Last enriched: 6/10/2026, 5:39:47 PM

Last updated: 6/10/2026, 6:20:02 PM

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses