Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-06-16

0
Medium
Published: Mon Jun 15 2026 (06/15/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed

Description

Maltrail IOC for 2026-06-16

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/16/2026, 17:00:16 UTC

Technical Analysis

The report details a Maltrail IOC for June 16, 2026, indicating detection of suspicious or malicious network activity associated with malware. The information is derived from open-source intelligence (OSINT) and represents an observation rather than a vulnerability or exploit. There are no technical indicators or affected software versions specified, and no patches or fixes are applicable.

Potential Impact

The impact is limited to the detection of potential malware-related network activity. Since no specific vulnerabilities or exploits are identified, the direct impact on systems or software cannot be assessed from the provided data.

Mitigation Recommendations

No patches or official remediation are available or applicable. Security teams should incorporate this IOC into their detection and monitoring tools as appropriate. No urgent action is mandated by the vendor or source.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
869bde21-bfc1-48fa-a7ff-0fd0bef879f5
Original Timestamp
1781625606

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a949a99d7414a9cbf7de6ec0203d0f30014b34cf
warbyrat
urlhttps://x.com/Fact_Finder03/status/2066779322959196592
warbyrat
urlhttps://api.github.com/repos/stamparm/maltrail/commits/0612d96c2b0c1f9aeaf8389a98a17180996a4f15
android_bankbot
urlhttps://x.com/Fact_Finder03/status/2066770247907152329
android_bankbot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/155d2bf40e802b1a082add7dc41db6a3d072176a
urlhttps://api.github.com/repos/stamparm/maltrail/commits/de054c196c948951a2299d6f390247a3702d3a49
generic_stealer
urlhttps://www.virustotal.com/gui/ip-address/104.21.2.27/relations
generic_stealer
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d68575a40314bf9b87ff78de798c23ea25f05df1
c2_panel
urlhttps://x.com/Fact_Finder03/status/2066761141737697504
c2_panel
urlhttps://api.github.com/repos/stamparm/maltrail/commits/9b76d93ff6fc74d2ef6123773c2fc54d2962afdd
osx_nova
urlhttps://api.github.com/repos/stamparm/maltrail/commits/311b96475c4fc7c2756c055561cf8dd040f1a5ab
apt_muddywater
urlhttps://api.github.com/repos/stamparm/maltrail/commits/ebbff60f7d137914535d5bf9456a6a3e58aa3987
c2_panel
urlhttps://urlscan.io/result/019ecfd3-f947-75bd-b0e4-6589084f9476
c2_panel
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5657c7f0b5e32536a93c6c7a9da040c1403941d5
c2_panel
urlhttps://urlscan.io/result/019ecfd2-8d44-717b-ba68-7443d52b3565
c2_panel
urlhttps://api.github.com/repos/stamparm/maltrail/commits/46e9450b04938db6fdcf6cf7bd5ce7f6d011ae08
santa
urlhttps://api.github.com/repos/stamparm/maltrail/commits/6681009f6adc22adea785379b3365ea851cecd51
apt_unclassified
urlhttps://x.com/ElementalX2/status/2066778907521724688
apt_unclassified
urlhttps://www.virustotal.com/gui/file/cc27de5f39ce95714f6252947dbde8333ad73d0102875814c11d03e943ca3fe1/detection
apt_unclassified
urlhttps://api.github.com/repos/stamparm/maltrail/commits/67d48b5cdeca0f08bbdbbe1e69d8e4875dc70d07
fakeapp
urlhttps://x.com/Malwarehunterr/status/2066829136090526017
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/a1ba1d7228a8045ae879f30ed09a215291656bb3
android_bankbot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/e52b14b37c68162d377904761c68f6e3149d0914
elf_mirai
urlhttps://www.virustotal.com/gui/file/0ac192ca5acff05d0c4781884cb37a7e75010e2843112673c072446a14b1c6b1/detection
elf_mirai
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5fbd866aa052618799db0dda9c1075a4519b254b
apt_unclassified
urlhttps://hunt.io/blog/ababil-of-minab-iranian-hackers-exposed-la-metro-breach-open-directory
apt_unclassified
urlhttps://api.github.com/repos/stamparm/maltrail/commits/fae3bfc187b5cad56c8fd1bfa8c98dda03dfe35f
fakeapp
urlhttps://x.com/Malwarehunterr/status/2066862838275301537
fakeapp
urlhttps://www.virustotal.com/gui/file/5172c183e2a809439aeea23980e8168dbff4c23fd603d7e217821413a6da81e8/detection
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7de557ed8d582d70f18fba65f4daaebf96aff5d5
connectwise
urlhttps://api.github.com/repos/stamparm/maltrail/commits/beaa05bd86a0a779e3f204910e7241ea5b738b7e
sosihvncrat
urlhttps://x.com/malwrhunterteam/status/2066820173646995906
sosihvncrat
urlhttps://api.github.com/repos/stamparm/maltrail/commits/2ec181d18a80397a24f7460dc183537c067d2e87
powershell_injector
urlhttps://x.com/malwrhunterteam/status/2066810677654700428
powershell_injector
urlhttps://www.virustotal.com/gui/file/91f0397ad227ed9a9d687937aebf55291dd3f03dd2ae1bd2e2eb72d8296683dc/detection
powershell_injector
urlhttps://api.github.com/repos/stamparm/maltrail/commits/e0dc808dec766b5e5ebf5ea7c14d538db6fbe22e
apt_unc2465
urlhttps://api.github.com/repos/stamparm/maltrail/commits/274e1062b8d946a71157bc655a14f8f8340a4ae4
osx_nova
urlhttps://api.github.com/repos/stamparm/maltrail/commits/17dd766e5326d7916278d3fa336ff27e6aaff115
apt_unc6691
urlhttps://api.github.com/repos/stamparm/maltrail/commits/0ec70e0d0343694b49197d29059efb69ffdc45a8
osx_atomic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d5f359b57aea84d151750fe523654cef71b8fb67
osx_atomic
urlhttps://x.com/stop_spammerz/status/2066868071524921443
osx_atomic
urlhttps://api.github.com/repos/stamparm/maltrail/commits/2190cde0fae32015a767b23562df5595a9b40d61
apt_unc6691
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4435c28bcef1844794ec8b8b94cc2f42a9341e40
banload
urlhttps://api.github.com/repos/stamparm/maltrail/commits/cb00bb0cb043103313575133b86ede480e39d6d3
apt_cloudatlas
urlhttps://api.github.com/repos/stamparm/maltrail/commits/98f8f47ab86bc8785a1014ec52f706aa2a1db057
apt_cloudatlas
urlhttps://x.com/askardyuss/status/2066210696929452163
apt_cloudatlas
urlhttps://www.virustotal.com/gui/file/1402053d6edb096b59b8df3b81d56d5a30e6577f9022ef9b5dae910f328d0401/detection
apt_cloudatlas
urlhttps://www.virustotal.com/gui/file/4661735db0f33dd567d29b2a056a967bb3762f831eb3678b27c4ffb06dbb8ec1/detection
apt_cloudatlas
urlhttps://api.github.com/repos/stamparm/maltrail/commits/9dd178d528b156c0877eaf02c12bb376a7837801
apt_lazarus
urlhttps://x.com/blackorbird/status/2066892874839687418
apt_lazarus
urlhttps://roman.pt/posts/linkedin-backdoor
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/9d817d5404cf38d41d137c20f9ac68a43eadfd8c
apt_q27
urlhttps://x.com/askardyuss/status/2066859258130665974
apt_q27
urlhttps://www.virustotal.com/gui/file/0010762b4b1361aa9bc66892021869ff8cfa6ff51c660021843b5ad2b2799a8a/detection
apt_q27

Domain

ValueDescriptionCopy
domainqualquernomepow.online
warbyrat
domainexchange24app.cfd
android_bankbot
domainechelon36solutions.click
domainmeridian21resources.click
domainsentra2026management.click
domainkeylogger-c2-panel.pages.dev
generic_stealer
domainsteampowered.cc.cd
generic_stealer
domainapartfocus.info
osx_nova
domainchronoconcake.shop
osx_nova
domainmarketcap-community.site
osx_nova
domainmarketcap-community.space
osx_nova
domainmarketcap-community.top
osx_nova
domainmoonlisting.shop
osx_nova
domainmoonshoot-vote.help
osx_nova
domainmoonshoot-vote.life
osx_nova
domainmoonshootvote.online
osx_nova
domainmoonshootvote.site
osx_nova
domainmoonshootvote.space
osx_nova
domainmoonvote.club
osx_nova
domainmoonvote.help
osx_nova
domainmoonvote.space
osx_nova
domainpumpx.live
osx_nova
domainmeet-837878474985876594.safelinks-microsoftonline.com
apt_muddywater
domainlive.meet-837878474985876594.safelinks-microsoftonline.com
apt_muddywater
domainteams.live.meet-837878474985876594.safelinks-microsoftonline.com
apt_muddywater
domainftoaxz.easypanel.host
c2_panel
domaingreenhouseclub.org
c2_panel
domaingearea-fadimi.com
santa
domainbigslotjp.top
apt_unclassified
domainfuturead.site
apt_unclassified
domainlucky86-game-cloud.top
apt_unclassified
domainpipelinebuilder.top
apt_unclassified
domaint3ch.tech
apt_unclassified
domainupdatetxmc.top
apt_unclassified
domainmorg-234.com
fakeapp
domainpub-53cea2db57dc4d53a276334acb98f5c0.r2.dev
fakeapp
domainnefeshhope.com
apt_unclassified
domainbrcee.com
fakeapp
domainsynergyconsulting.com.br
fakeapp
domainmintu.filcb.com
connectwise
domainhawkteam.ru
sosihvncrat
domainvpn.hawkteam.ru
sosihvncrat
domaines-com-556444.quest
sosihvncrat
domainairbnb.es-com-556444.quest
sosihvncrat
domaincsic-gob-es.netlify.app
powershell_injector
domaincipheriumlabs.com
apt_unc2465
domaincorden.it.com
apt_unc2465
domaincorevoryx.com
apt_unc2465
domainnodequantixlab.com
apt_unc2465
domainorangecountywaterheater.com
apt_unc2465
domainpnohub.top
apt_unc2465
domainunbiaseddaily.com
apt_unc2465
domainverteglo.it.com
apt_unc2465
domainwillcountycriminaldefense.com
apt_unc2465
domainpumpbase.lol
osx_nova
domain141.st
apt_unc6691
domain63def09oaj.click
apt_unc6691
domainagixzze.com
apt_unc6691
domainavctatc.com
apt_unc6691
domainbhycigc.com
apt_unc6691
domainbipfpwv.com
apt_unc6691
domaincoyuccu.com
apt_unc6691
domaincpmlipd.com
apt_unc6691
domaincyixmqr.com
apt_unc6691
domaindrojcuk.com
apt_unc6691
domaindxberby.com
apt_unc6691
domainfbdebll.com
apt_unc6691
domainfbymhdh.com
apt_unc6691
domainfyylpzh.com
apt_unc6691
domaingcymsjv.com
apt_unc6691
domaingdiqaun.com
apt_unc6691
domainhbkltpp.com
apt_unc6691
domainhdnyjaw.com
apt_unc6691
domainhnlfacz.com
apt_unc6691
domainhssfvhf.com
apt_unc6691
domainhyfmlac.com
apt_unc6691
domainhyyclxa.com
apt_unc6691
domainifzixau.com
apt_unc6691
domainijsdtso.com
apt_unc6691
domainjixzjrh.com
apt_unc6691
domainjmxvfga.com
apt_unc6691
domainjxjrsoo.com
apt_unc6691
domainkmbuirx.com
apt_unc6691
domainlntzruf.com
apt_unc6691
domainlrfatds.com
apt_unc6691
domainmcctfen.com
apt_unc6691
domainnosyrkh.com
apt_unc6691
domainoawxyzp.com
apt_unc6691
domainoylufdy.com
apt_unc6691
domainpekceyu.com
apt_unc6691
domainpfhpwvf.com
apt_unc6691
domainqsskhoo.com
apt_unc6691
domainqyehlxl.com
apt_unc6691
domainrwjftqk.com
apt_unc6691
domainrwsbqwy.com
apt_unc6691
domainservpzb.com
apt_unc6691
domainsmxabss.com
apt_unc6691
domaintsgauhq.com
apt_unc6691
domainucoemah.com
apt_unc6691
domainunassib.com
apt_unc6691
domainuuutalk.me
apt_unc6691
domainvrcqjup.com
apt_unc6691
domainvxczjik.com
apt_unc6691
domainvypjmfk.com
apt_unc6691
domainwbmdhzw.com
apt_unc6691
domainwwbifed.com
apt_unc6691
domainxdasvpn.com
apt_unc6691
domainxuexqfw.com
apt_unc6691
domainypnjhab.com
apt_unc6691
domainysbllry.com
apt_unc6691
domainzwugzhm.com
apt_unc6691
domainabloubilis.com
osx_atomic
domainagagagagagag.abloubilis.com
osx_atomic
domainangiowaiwa.media
osx_atomic
domainantiqcrypt.media
osx_atomic
domainaqua-ventures.world
osx_atomic
domainautodiscover.geelongwebhosting.com.au
osx_atomic
domainbacbcack.exchange
osx_atomic
domainbasetax.live
osx_atomic
domaincorvantarls.pro
osx_atomic
domaincpcontacts.geelongwebhosting.com.au
osx_atomic
domaindomain-one.site
osx_atomic
domaindrenoxabit.com
osx_atomic
domainelitevpn.space
osx_atomic
domainfigfilearchive.com
osx_atomic
domainfondaunfor.media
osx_atomic
domainftp.geelongwebhosting.com.au
osx_atomic
domainkredovianfx.com
osx_atomic
domainkristalnevsehir.com
osx_atomic
domainmy.domain-one.site
osx_atomic
domainns7.geelongwebhosting.com.au
osx_atomic
domainns8.geelongwebhosting.com.au
osx_atomic
domainofni.ae-topupnow.info
osx_atomic
domainphersonetwork.com
osx_atomic
domainpineapplefileworks.com
osx_atomic
domainplumfilenetwork.com
osx_atomic
domainsporkdex.com
osx_atomic
domainsso.blissgleam.lk
osx_atomic
domaintest.uae-electricity-portal.cfd
osx_atomic
domaintrade-paperdex.app
osx_atomic
domaintv-activateterminal.com
osx_atomic
domainuae-electricity-portal.cfd
osx_atomic
domainwebmail.geelongwebhosting.com.au
osx_atomic
domainzolotoy-vek.com
osx_atomic
domaintide-39.com
osx_atomic
domain4131.tw
apt_unc6691
domainedkyznr.com
apt_unc6691
domainqeghfhe.com
apt_unc6691
domainrrcctxh.com
apt_unc6691
domainultjrwm.com
apt_unc6691
domainxwlrayo.com
apt_unc6691
domainmhtecnica.com
banload
domaintsadesertracing.com
banload
domainaitoall.ru
apt_cloudatlas
domainarendelle.ru
apt_cloudatlas
domainbryksina.ru
apt_cloudatlas
domainelycleu.click
apt_cloudatlas
domainfcauditsp.ru
apt_cloudatlas
domainfortune-wheel.ru
apt_cloudatlas
domainhilsabecks.net
apt_cloudatlas
domainkjzxpe.ru
apt_cloudatlas
domainmsgntfsys.link
apt_cloudatlas
domainmvecak.ru
apt_cloudatlas
domainrefunmvd.sa.com
apt_cloudatlas
domainwolrpg.ru
apt_cloudatlas
domainyarcoff.ru
apt_cloudatlas
domainzhk-ambassador.ru
apt_cloudatlas
domain3i.hilsabecks.net
apt_cloudatlas
domain56.msgntfsys.link
apt_cloudatlas
domain7h.ahmetgurses.net
apt_cloudatlas
domainbot.fortune-wheel.ru
apt_cloudatlas
domainftp.arendelle.ru
apt_cloudatlas
domainftp.bryksina.ru
apt_cloudatlas
domainftp.dezinsekciya-top.ru
apt_cloudatlas
domainftp.wolrpg.ru
apt_cloudatlas
domainftp.zhk-ambassador.ru
apt_cloudatlas
domainmail.aitoall.ru
apt_cloudatlas
domainmail.arendelle.ru
apt_cloudatlas
domainmail.bryksina.ru
apt_cloudatlas
domainmail.dezinsekciya-top.ru
apt_cloudatlas
domainmail.msgntfsys.link
apt_cloudatlas
domainmail.wolrpg.ru
apt_cloudatlas
domainmail.zhk-ambassador.ru
apt_cloudatlas
domainahmetgurses.net
apt_cloudatlas
domaindezinsekciya-top.ru
apt_cloudatlas
domainrest-icon-handler.store
apt_lazarus
domainapi.keensie.com
apt_q27

Ip

ValueDescriptionCopy
ip107.189.20.42
android_bankbot
ip157.173.203.13
c2_panel
ip185.130.45.201
c2_panel
ip45.77.242.76
apt_unclassified
ip209.14.84.37
elf_mirai
ip146.70.233.83
apt_unclassified
ip31.172.87.20
apt_unclassified
ip5.255.127.55
apt_unclassified
ip91.219.239.197
connectwise
ip93.190.247.238
sosihvncrat
ip194.190.153.182
apt_cloudatlas
ip94.232.248.34
apt_cloudatlas
ip35.78.126.246
apt_q27

Threat ID: 6a317d8e0b89be6888dfe3b9

Added to database: 6/16/2026, 4:45:02 PM

Last enriched: 6/16/2026, 5:00:16 PM

Last updated: 6/17/2026, 4:53:06 AM

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses