Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Maltrail IOC for 2026-08-01

0
Medium
Published: 07/31/2026 (07/31/2026, 00:00:00 UTC)
Source: CIRCL OSINT Feed

Description

Maltrail IOC for 2026-08-01

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/01/2026, 19:09:12 UTC

Technical Analysis

The CIRCL OSINT Feed published a set of IOCs on 2026-08-01 linked to the APT group known as 'APT Duke'. These IOCs include a collection of IP addresses and domains used in malware delivery and credential theft campaigns targeting travelers worldwide, as referenced by a Microsoft security blog. There is no associated CVE or software vulnerability; rather, this is an intelligence report on malicious infrastructure and activity patterns. No exploits in the wild or patches are applicable.

Potential Impact

The impact involves potential malware infections and credential theft facilitated by infrastructure linked to APT Duke. There is no direct software vulnerability or exploit described, so the impact is limited to detection and blocking of malicious network activity and domains to prevent compromise.

Mitigation Recommendations

No patch or official remediation is available or applicable since this is an IOC report rather than a software vulnerability. Defenders should use the provided IP addresses and domains to update detection and blocking rules in network security devices and endpoint protection systems. Monitoring for related activity and applying threat intelligence feeds is recommended.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Uuid
183b6a5f-ebc1-4575-ac91-87e2e13c3731
Original Timestamp
1785589207

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5d968a2223113177bdda4ec168dfd31f0f4f91f9
apt_duke
urlhttps://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft
apt_duke

Ip

ValueDescriptionCopy
ip104.194.159.150
apt_duke
ip107.189.26.194
apt_duke
ip138.197.202.81
apt_duke
ip138.68.160.124
apt_duke
ip165.22.146.161
apt_duke
ip213.145.86.112
apt_duke
ip216.126.224.95
apt_duke
ip31.172.83.142
apt_duke
ip31.57.243.154
apt_duke
ip38.146.28.132
apt_duke
ip38.146.28.75
apt_duke
ip84.200.154.162
apt_duke

Domain

ValueDescriptionCopy
domainm365-owa.com
apt_duke
domainms365-device.com
apt_duke
domainms365-live.com
apt_duke
domainmy-invite.org
apt_duke
domainowa-ms365.com
apt_duke

Threat ID: 6a6e3f52bf32cb7a34224965

Added to database: 08/01/2026, 18:47:46 UTC

Last enriched: 08/01/2026, 19:09:12 UTC

Last updated: 08/01/2026, 20:02:47 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses