Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-06-21

0
Medium
Published: 06/20/2026 (06/20/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed

Description

Maltrail IOC for 2026-06-21

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/21/2026, 09:26:22 UTC

Technical Analysis

The report details a Maltrail IOC for June 21, 2026, sourced from the CIRCL OSINT feed. It is classified as malware-related network activity with medium risk. The data lacks specific technical indicators or affected software versions. No patches or remediation measures are indicated, and no active exploitation has been confirmed.

Potential Impact

The impact is currently assessed as medium risk based on the source classification. Without detailed indicators or affected versions, the precise operational impact or exploitation potential cannot be determined. No known active exploitation has been reported.

Mitigation Recommendations

No patch or remediation is available for this IOC. Organizations should monitor for relevant network activity using Maltrail or similar detection tools. Follow standard incident response procedures if indicators matching this IOC are observed. Since no vendor advisory or fix exists, rely on detection and containment strategies.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
52f2c65f-9b18-48d0-b314-389497c784a6
Original Timestamp
1782000023

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/38dde887a57a429a193affc9349e07a0655254f7
generic_fortibleed
urlhttps://x.com/MonThreat/status/2068391787366957546
generic_fortibleed
urlhttps://api.github.com/repos/stamparm/maltrail/commits/cc71bb10b1b33d0310b36e20935103ec7d024e22
fakeapp
urlhttps://x.com/v0lundr_/status/2064374733550817617
fakeapp
urlhttps://api.github.com/repos/stamparm/maltrail/commits/3ac7857492d7aaee64e0622845d5d2865cd21b50
powershell_injector
urlhttps://x.com/_IMalihi_/status/2064747807320252780
powershell_injector
urlhttps://api.github.com/repos/stamparm/maltrail/commits/83acedc23ca7d5d560da36afe1b55a0effef5ade
apt_lazarus
urlhttps://x.com/v0lundr_/status/2065375317682696560
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/7046159134371d026ad55d88a063f5845e7d9dc5
apt_unc6353
urlhttps://x.com/_IMalihi_/status/2067948568401395880
apt_unc6353
urlhttps://api.github.com/repos/stamparm/maltrail/commits/00ba38136aa20c0b630b46e1735468927331d15c
apt_turla
urlhttps://api.github.com/repos/stamparm/maltrail/commits/63c85ccb9ba40c451032bbf660cea52b7f3199ac
apt_turla
urlhttps://api.github.com/repos/stamparm/maltrail/commits/8813480dc1772d5bccc09470b8e70cb5252bb6f2
apt_turla
urlhttps://x.com/_IMalihi_/status/2068422081855836300
apt_turla
urlhttps://api.github.com/repos/stamparm/maltrail/commits/26eb38bd534ed83fe70bb47065987b0688080a97
powershell_injector

Ip

ValueDescriptionCopy
ip211.72.37.226
generic_fortibleed
ip38.55.151.63
fakeapp
ip161.248.87.10
powershell_injector
ip103.136.43.65
apt_turla
ip103.143.40.60
apt_turla
ip103.143.40.91
apt_turla
ip104.167.16.42
apt_turla
ip185.253.116.122
apt_turla
ip38.180.173.194
apt_turla
ip45.89.107.77
apt_turla
ip103.30.76.194
apt_turla
ip194.36.190.17
apt_turla
ip205.186.64.197
apt_turla
ip46.17.45.93
apt_turla
ip5.252.176.22
apt_turla

Domain

ValueDescriptionCopy
domainbaskwms.top
fakeapp
domainaigtech.dev
apt_lazarus
domaincartned.sheexcell.ink
apt_unc6353
domainduflaro.com
apt_unc6353
domaininventorepkrje.sheexcell.ink
apt_unc6353
domainiokert.com
apt_unc6353
domainlifechangerai.site
apt_unc6353
domainlink.sheexcell.ink
apt_unc6353
domainmxloft.sheexcell.ink
apt_unc6353
domainsheexcell.ink
apt_unc6353
domaint.sheexcell.ink
apt_unc6353
domainwwteam.space
apt_unc6353
domainsoftwareupdatenews.com
apt_turla
domaindatacenterate.com
apt_turla
domaindzerl.com
apt_turla
domainfootballcharge.us
apt_turla
domainnewscloud.mn
apt_turla
domainoftwareupdatenews.com
apt_turla
domainonekey-host.com
apt_turla
domainwaterwinterend.com
apt_turla
domainwebfurina.com
apt_turla
domainapi.softwareupdatenews.com
apt_turla
domaincdn.datacenterate.com
apt_turla
domainen.footballcharge.us
apt_turla
domainminkstore.vip
apt_turla
domainstudiokaspersky.com
apt_turla
domainns.minkstore.vip
apt_turla
domainupdate.studiokaspersky.com
apt_turla
domaintpa6ipinfabdsbimjra4l-h.top
powershell_injector
domainusenetmodels.vip
powershell_injector

Threat ID: 6a37ae3ac92c87df5d9630d0

Added to database: 06/21/2026, 09:26:18 UTC

Last enriched: 06/21/2026, 09:26:22 UTC

Last updated: 06/21/2026, 11:31:27 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses