Maltrail IOC for 2026-08-01
Maltrail IOC for 2026-08-01
AI Analysis
Technical Summary
The CIRCL OSINT Feed published a set of IOCs on 2026-08-01 linked to the APT group known as 'APT Duke'. These IOCs include a collection of IP addresses and domains used in malware delivery and credential theft campaigns targeting travelers worldwide, as referenced by a Microsoft security blog. There is no associated CVE or software vulnerability; rather, this is an intelligence report on malicious infrastructure and activity patterns. No exploits in the wild or patches are applicable.
Potential Impact
The impact involves potential malware infections and credential theft facilitated by infrastructure linked to APT Duke. There is no direct software vulnerability or exploit described, so the impact is limited to detection and blocking of malicious network activity and domains to prevent compromise.
Mitigation Recommendations
No patch or official remediation is available or applicable since this is an IOC report rather than a software vulnerability. Defenders should use the provided IP addresses and domains to update detection and blocking rules in network security devices and endpoint protection systems. Monitoring for related activity and applying threat intelligence feeds is recommended.
Indicators of Compromise
- url: https://api.github.com/repos/stamparm/maltrail/commits/5d968a2223113177bdda4ec168dfd31f0f4f91f9
- url: https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft
- ip: 104.194.159.150
- ip: 107.189.26.194
- ip: 138.197.202.81
- ip: 138.68.160.124
- ip: 165.22.146.161
- ip: 213.145.86.112
- ip: 216.126.224.95
- ip: 31.172.83.142
- ip: 31.57.243.154
- ip: 38.146.28.132
- ip: 38.146.28.75
- ip: 84.200.154.162
- domain: m365-owa.com
- domain: ms365-device.com
- domain: ms365-live.com
- domain: my-invite.org
- domain: owa-ms365.com
Maltrail IOC for 2026-08-01
Description
Maltrail IOC for 2026-08-01
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The CIRCL OSINT Feed published a set of IOCs on 2026-08-01 linked to the APT group known as 'APT Duke'. These IOCs include a collection of IP addresses and domains used in malware delivery and credential theft campaigns targeting travelers worldwide, as referenced by a Microsoft security blog. There is no associated CVE or software vulnerability; rather, this is an intelligence report on malicious infrastructure and activity patterns. No exploits in the wild or patches are applicable.
Potential Impact
The impact involves potential malware infections and credential theft facilitated by infrastructure linked to APT Duke. There is no direct software vulnerability or exploit described, so the impact is limited to detection and blocking of malicious network activity and domains to prevent compromise.
Mitigation Recommendations
No patch or official remediation is available or applicable since this is an IOC report rather than a software vulnerability. Defenders should use the provided IP addresses and domains to update detection and blocking rules in network security devices and endpoint protection systems. Monitoring for related activity and applying threat intelligence feeds is recommended.
Technical Details
- Uuid
- 183b6a5f-ebc1-4575-ac91-87e2e13c3731
- Original Timestamp
- 1785589207
Indicators of Compromise
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://api.github.com/repos/stamparm/maltrail/commits/5d968a2223113177bdda4ec168dfd31f0f4f91f9 | apt_duke | |
urlhttps://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft | apt_duke |
Ip
| Value | Description | Copy |
|---|---|---|
ip104.194.159.150 | apt_duke | |
ip107.189.26.194 | apt_duke | |
ip138.197.202.81 | apt_duke | |
ip138.68.160.124 | apt_duke | |
ip165.22.146.161 | apt_duke | |
ip213.145.86.112 | apt_duke | |
ip216.126.224.95 | apt_duke | |
ip31.172.83.142 | apt_duke | |
ip31.57.243.154 | apt_duke | |
ip38.146.28.132 | apt_duke | |
ip38.146.28.75 | apt_duke | |
ip84.200.154.162 | apt_duke |
Domain
| Value | Description | Copy |
|---|---|---|
domainm365-owa.com | apt_duke | |
domainms365-device.com | apt_duke | |
domainms365-live.com | apt_duke | |
domainmy-invite.org | apt_duke | |
domainowa-ms365.com | apt_duke |
Threat ID: 6a6e3f52bf32cb7a34224965
Added to database: 08/01/2026, 18:47:46 UTC
Last enriched: 08/01/2026, 19:09:12 UTC
Last updated: 08/01/2026, 20:02:47 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.