Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-06-29

0
Medium
Published: 06/28/2026 (06/28/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed

Description

Maltrail IOC for 2026-06-29

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/29/2026, 12:06:18 UTC

Technical Analysis

The report details a Maltrail IOC for the date 2026-06-29, indicating observed malware-related network activity collected via open-source intelligence. The information is an observation without detailed technical indicators or affected software versions. No patches or fixes are applicable as this is an IOC rather than a vulnerability in software. The threat is assessed as medium severity based on the source classification.

Potential Impact

The impact is limited to the detection of malware-related network activity indicators. There is no evidence of active exploitation or direct software vulnerabilities. The medium severity suggests a moderate risk of malicious network behavior but no confirmed widespread compromise or critical impact.

Mitigation Recommendations

No patch or remediation is available or applicable for this IOC. Security teams should incorporate the IOC into their detection and monitoring tools to identify potential malicious activity. No urgent remediation actions are indicated by the source.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
823a8f32-6afa-443a-9413-1e9fc114c8cc
Original Timestamp
1782730810

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/596e8a9e1b3c0d313ff9e2bb387d31752558621e
purelogs
urlhttps://x.com/smica83/status/2071494475633820017
purelogs
urlhttps://www.virustotal.com/gui/file/e18f7f0fd6ca2a9be32682c74586e753e91732557268d1fb31df45cf26cd1e3d/detection
purelogs
urlhttps://api.github.com/repos/stamparm/maltrail/commits/41d10b4c51a8af2e0f30255934f91372126487c9
farfli
urlhttps://x.com/smica83/status/2071501384063582277
farfli
urlhttps://www.virustotal.com/gui/file/7367ea4cb0851baf6e17d42347060d4c60fd40d18d3faa7af146992cdead2999/detection
farfli
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c3cabb6f7ef7a385a498bdaa2c475c53d4d22503
android_fvncbot
urlhttps://api.github.com/repos/stamparm/maltrail/commits/0dfe6d1736cd08b9485102f0d7883655a7663668
c2_panel
urlhttps://api.github.com/repos/stamparm/maltrail/commits/bddb84771635350990625d79fcd1022ca059cad2
peaklight
urlhttps://api.github.com/repos/stamparm/maltrail/commits/aafaab50e053e7f95c9a7e253843cbca27599c2c
vidar
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4154e031b8e6cd1cf7e8453555fa6c22c9735e10
apt_lazarus
urlhttps://api.github.com/repos/stamparm/maltrail/commits/81c048cdcd70767b01096e5fa4b574bcdb21b61f
cyberstrikeai
urlhttps://api.github.com/repos/stamparm/maltrail/commits/f014ff8b2b465c93e5d4e4398c0631a2d53d44c2
c2_panel
urlhttps://x.com/Fact_Finder03/status/2071547793626587476
c2_panel
urlhttps://api.github.com/repos/stamparm/maltrail/commits/e6035e1a33829834bdafcedbb776610a200b25f3
supershell_c2
urlhttps://api.github.com/repos/stamparm/maltrail/commits/c4003dc31c7dbf4c91b33125e8b66f02ae1cda19
offloader
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4f61c90e9a9ac68f2733003f1a99401b0df8e3e1
sectoprat
urlhttps://api.github.com/repos/stamparm/maltrail/commits/789baed7785f3bde1b55ba16bd231666c7e968d9
farfli
urlhttps://x.com/smica83/status/2071498469567496448
farfli
urlhttps://www.virustotal.com/gui/file/a322645437729eb669b59486b077ac29aa949f4bc97f20651bf3d0f75dd7a507/detection
farfli
urlhttps://api.github.com/repos/stamparm/maltrail/commits/140e9816344e51e702b6e1a7db7ca21712bb3afd
apt_kimsuky

Ip

ValueDescriptionCopy
ip193.26.115.168
purelogs
ip112.121.177.250
farfli
ip102.220.160.40
c2_panel
ip91.92.34.103
vidar
ip198.135.49.65
apt_lazarus
ip216.250.252.245
apt_lazarus
ip101.43.76.160
cyberstrikeai
ip172.67.129.36
cyberstrikeai
ip38.76.188.246
cyberstrikeai
ip8.137.170.3
cyberstrikeai
ip89.125.146.28
c2_panel
ip8.218.242.120
supershell_c2
ip193.233.126.38
sectoprat
ip175.27.132.207
farfli

Domain

ValueDescriptionCopy
domaingogousdtdiaoyu.org
farfli
domainbentool.space
android_fvncbot
domainolx.bentool.space
android_fvncbot
domainbitarasaa.top
vidar
domainterracello.icu
vidar
domainloongkong.app
cyberstrikeai
domainloongkong.xyz
cyberstrikeai
domainbrakepail.space
offloader
domainerrornote.info
offloader
domaineyemove.space
offloader
domainstarquarter.space
offloader
domainansidnmt.dynu.org
apt_kimsuky
domainedcmoies.dynuddns.net
apt_kimsuky
domaininlinepoldep.dynu.net
apt_kimsuky
domaininlinepoldeps.dynu.net
apt_kimsuky
domainmemnhis.dynu.org
apt_kimsuky
domainmsinidnc.dynu.org
apt_kimsuky
domainnblogapps.dynu.net
apt_kimsuky
domainncodgacheck.dynu.org
apt_kimsuky
domainncodgapass.dynu.org
apt_kimsuky
domainncodgaverify.dynu.org
apt_kimsuky
domainnmsinls.dynu.org
apt_kimsuky
domainsnidnmls.dynu.org
apt_kimsuky
domaintaxdepright.dynu.net
apt_kimsuky
domaintaxdeprights.dynu.net
apt_kimsuky
domainublogapps.dynu.net
apt_kimsuky
domainuitxlog.dynu.net
apt_kimsuky
domainuitxlog.dynuddns.net
apt_kimsuky

Threat ID: 6a425fb327e9c79719cfc03b

Added to database: 06/29/2026, 12:06:11 UTC

Last enriched: 06/29/2026, 12:06:18 UTC

Last updated: 06/29/2026, 14:21:11 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses