Maltrail IOC for 2026-07-25
Maltrail IOC for 2026-07-25
AI Analysis
Technical Summary
This threat intelligence report from the CIRCL OSINT Feed provides a collection of IOCs related to multiple malware families, including phorpiex, littlerat, and adaptix_c2. The indicators comprise URLs, IP addresses, and domains linked to these malware campaigns. The report does not describe any software vulnerabilities or exploits but focuses on network activity associated with malware infections. No active exploitation or ransomware campaigns are reported. The information is intended to support detection and blocking efforts in security monitoring tools.
Potential Impact
The impact is limited to the potential detection and blocking of network traffic related to known malware campaigns. There is no direct vulnerability or software flaw described, so no direct system compromise or exploitation is indicated. The presence of these IOCs in network traffic may indicate infection or malicious communication attempts by the referenced malware families.
Mitigation Recommendations
No patch or official remediation is available or applicable since this is threat intelligence data rather than a vulnerability. Security teams should incorporate the provided IOCs into intrusion detection/prevention systems, firewalls, and endpoint protection solutions to detect and block related malicious activity. No urgent action is mandated beyond updating detection rules and monitoring for these indicators.
Indicators of Compromise
- url: https://api.github.com/repos/stamparm/maltrail/commits/15012c9a3de59634ce4a7ec3e6b85c7eba5db5af
- url: https://www.virustotal.com/gui/file/0a46a6c837d5db4ec12a1d067f9a087abddd23e5c180c2a239eac76fbbc300ce/detection
- ip: 46.165.244.150
- url: https://api.github.com/repos/stamparm/maltrail/commits/4d307b14b467b39e215636c4e2bfed544ee80b8b
- url: https://www.virustotal.com/gui/file/0188a723f26174fb0a9266704410578a1f095834fb16e6c412837b56c1436a56/detection
- domain: nukebooter.no-ip.info
- url: https://api.github.com/repos/stamparm/maltrail/commits/d27a24e72cbb4103048aa78c29fce81acf8ed6c2
- url: https://x.com/malwrhunterteam/status/2080626563977011542
- url: https://www.virustotal.com/gui/file/3a5dc19f8c518a46f92d6d475e96c87fb1130352eae36530e0e721515deb7ba6/detection
- url: https://www.virustotal.com/gui/file/73df809d1e115d580f56a7b788f9edc528c031c4ccb2e276fead8051d09ec8d8/detection
- domain: vapeauroz.com
- domain: mail.vapeauroz.com
Maltrail IOC for 2026-07-25
Description
Maltrail IOC for 2026-07-25
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat intelligence report from the CIRCL OSINT Feed provides a collection of IOCs related to multiple malware families, including phorpiex, littlerat, and adaptix_c2. The indicators comprise URLs, IP addresses, and domains linked to these malware campaigns. The report does not describe any software vulnerabilities or exploits but focuses on network activity associated with malware infections. No active exploitation or ransomware campaigns are reported. The information is intended to support detection and blocking efforts in security monitoring tools.
Potential Impact
The impact is limited to the potential detection and blocking of network traffic related to known malware campaigns. There is no direct vulnerability or software flaw described, so no direct system compromise or exploitation is indicated. The presence of these IOCs in network traffic may indicate infection or malicious communication attempts by the referenced malware families.
Defensive Guidance
No patch or official remediation is available or applicable since this is threat intelligence data rather than a vulnerability. Security teams should incorporate the provided IOCs into intrusion detection/prevention systems, firewalls, and endpoint protection solutions to detect and block related malicious activity. No urgent action is mandated beyond updating detection rules and monitoring for these indicators.
Technical Details
- Uuid
- fde8c224-d432-4ef4-bd2a-e6a7cbce079d
- Original Timestamp
- 1784934006
Indicators of Compromise
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://api.github.com/repos/stamparm/maltrail/commits/15012c9a3de59634ce4a7ec3e6b85c7eba5db5af | phorpiex | |
urlhttps://www.virustotal.com/gui/file/0a46a6c837d5db4ec12a1d067f9a087abddd23e5c180c2a239eac76fbbc300ce/detection | phorpiex | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/4d307b14b467b39e215636c4e2bfed544ee80b8b | littlerat | |
urlhttps://www.virustotal.com/gui/file/0188a723f26174fb0a9266704410578a1f095834fb16e6c412837b56c1436a56/detection | littlerat | |
urlhttps://api.github.com/repos/stamparm/maltrail/commits/d27a24e72cbb4103048aa78c29fce81acf8ed6c2 | adaptix_c2 | |
urlhttps://x.com/malwrhunterteam/status/2080626563977011542 | adaptix_c2 | |
urlhttps://www.virustotal.com/gui/file/3a5dc19f8c518a46f92d6d475e96c87fb1130352eae36530e0e721515deb7ba6/detection | adaptix_c2 | |
urlhttps://www.virustotal.com/gui/file/73df809d1e115d580f56a7b788f9edc528c031c4ccb2e276fead8051d09ec8d8/detection | adaptix_c2 |
Ip
| Value | Description | Copy |
|---|---|---|
ip46.165.244.150 | phorpiex |
Domain
| Value | Description | Copy |
|---|---|---|
domainnukebooter.no-ip.info | littlerat | |
domainvapeauroz.com | adaptix_c2 | |
domainmail.vapeauroz.com | adaptix_c2 |
Threat ID: 6a6452d79c2644c7f8c8f88d
Added to database: 07/25/2026, 06:08:23 UTC
Last enriched: 08/01/2026, 07:54:24 UTC
Last updated: 09/07/2026, 20:21:39 UTC
Views: 98
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.