s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-6a722dd4a132dc9e71bc11b2 high

📛 Threat Title

Infrastructure of Interest: High Confidence C2 - 2026-08

Category: ioi Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

IoI High Confidence C2 domains detected during 2026-08. Pulse contains 27 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (27)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain trainslive.uk VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/trainslive.uk
UrlVoid 2 / 35 1 feed

IOC database

Type
domain
Value
trainslive.uk
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/trainslive.uk

domain clovergroup.click VT 3 / 91 UrlVoid 2 / 35 1 feed

IOC database

Type
domain
Value
clovergroup.click
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Imported from threat-intel feed: threatview.io

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Flagged by 3 of 91 VirusTotal vendors

VendorVerdictDetection
CRDF malicious malicious
alphaMountain.ai suspicious suspicious
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarNameSilo, LLC
TLDclick
History
Creation date2024-11-05 14:43 UTC
Last analysis2026-07-31 09:24 UTC
Last modified on VirusTotal2026-07-31 09:35 UTC
Last WHOIS update2026-06-08 21:43 UTC
WHOIS record date2026-07-31 09:30 UTC
domain okdelike.click VT 1 / 91 UrlVoid 0 / 35

IOC database

Type
domain
Value
okdelike.click
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 1 of 91 VirusTotal vendors

VendorVerdictDetection
alphaMountain.ai suspicious suspicious

Details From VirusTotal

Basic Properties
TLDclick
History
Creation date2025-10-11 00:00 UTC
Last analysis2026-07-27 06:00 UTC
Last modified on VirusTotal2026-08-03 16:01 UTC
Last WHOIS update2026-01-05 00:00 UTC
WHOIS record date2026-10-11 00:00 UTC
domain topazharbor.top VT 18 / 91 UrlVoid 3 / 35

IOC database

Type
domain
Value
topazharbor.top
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
Domain name that delivers a malware payload attributed to SmartApeSG

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 18 of 91 VirusTotal vendors

VendorVerdictDetection
AlphaSOC malicious malware
BitDefender malicious phishing
CRDF malicious malicious
Forcepoint ThreatSeeker malicious malicious
Fortinet malicious malware
G-Data malicious phishing
LevelBlue malicious phishing
Lionic malicious malicious
Lumu malicious malware
MalwareURL malicious malware
Seclookup malicious malicious
SOCRadar malicious malicious
Sophos malicious phishing
Sucuri SiteCheck malicious malicious
VIPRE malicious malware
alphaMountain.ai suspicious suspicious
Certego suspicious suspicious
ESET suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarPDR Ltd
TLDtop
History
Creation date2026-07-09 08:30 UTC
Last analysis2026-07-31 11:33 UTC
Last modified on VirusTotal2026-07-31 11:43 UTC
Last WHOIS update2026-07-11 10:01 UTC
WHOIS record date2026-07-17 03:31 UTC
domain sbird.xyz VT 1 / 91 UrlVoid 0 / 35

IOC database

Type
domain
Value
sbird.xyz
First seen
Last seen
Attached to this threat
Appears in
2 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 1 of 91 VirusTotal vendors

VendorVerdictDetection
Forcepoint ThreatSeeker suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarAlibaba Cloud Computing Ltd. d/b/a HiChina (www.net.cn)
TLDxyz
History
Creation date2015-12-18 07:00 UTC
Last analysis2026-06-29 15:39 UTC
Last modified on VirusTotal2026-08-04 18:27 UTC
Last WHOIS update2025-12-01 14:36 UTC
WHOIS record date2026-06-29 15:44 UTC
domain builderio.xyz VT 2 / 91

IOC database

Type
domain
Value
builderio.xyz
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 2 of 91 VirusTotal vendors

VendorVerdictDetection
Forcepoint ThreatSeeker suspicious suspicious
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
TLDxyz
History
Creation date2025-10-06 00:00 UTC
Last analysis2026-07-24 01:28 UTC
Last modified on VirusTotal2026-08-04 07:32 UTC
Last WHOIS update2025-10-06 00:00 UTC
WHOIS record date2026-10-06 00:00 UTC
domain kidfun.xyz VT 16 / 91 UrlVoid 3 / 35

IOC database

Type
domain
Value
kidfun.xyz
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 16 of 91 VirusTotal vendors

VendorVerdictDetection
ADMINUSLabs malicious malicious
alphaMountain.ai malicious phishing
BitDefender malicious phishing
Chong Lua Dao malicious malicious
CyRadar malicious phishing
Fortinet malicious phishing
G-Data malicious phishing
Gridinsoft malicious phishing
Kaspersky malicious phishing
Lionic malicious malicious
SafeToOpen malicious phishing
Sophos malicious phishing
VIPRE malicious phishing
Webroot malicious malicious
ESET suspicious suspicious
Forcepoint ThreatSeeker suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarNAMECHEAP INC
TLDxyz
History
Creation date2024-08-31 16:47 UTC
Last analysis2026-08-03 10:33 UTC
Last modified on VirusTotal2026-08-04 21:53 UTC
Last WHOIS update2025-11-01 14:04 UTC
WHOIS record date2026-07-13 10:11 UTC
domain atukhyistak.xyz VT 2 / 91 UrlVoid 0 / 35

IOC database

Type
domain
Value
atukhyistak.xyz
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 2 of 91 VirusTotal vendors

VendorVerdictDetection
alphaMountain.ai suspicious suspicious
Forcepoint ThreatSeeker suspicious suspicious

Details From VirusTotal

Basic Properties
TLDxyz
History
Creation date2025-08-26 00:00 UTC
Last analysis2026-08-01 00:01 UTC
Last modified on VirusTotal2026-08-02 00:04 UTC
Last WHOIS update2025-08-26 00:00 UTC
WHOIS record date2026-08-26 00:00 UTC
domain thedailypost.xyz VT 0 / 91

IOC database

Type
domain
Value
thedailypost.xyz
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
RegistrarNAMECHEAP INC
TLDxyz
History
Creation date2026-05-31 12:21 UTC
Last analysis2026-07-30 01:48 UTC
Last modified on VirusTotal2026-07-30 02:00 UTC
Last WHOIS update2026-07-01 08:12 UTC
WHOIS record date2026-07-29 20:56 UTC
domain streampsh.top VT 6 / 91 UrlVoid 2 / 35

IOC database

Type
domain
Value
streampsh.top
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 6 of 91 VirusTotal vendors

VendorVerdictDetection
alphaMountain.ai malicious malicious
Chong Lua Dao malicious malicious
CRDF malicious malicious
CyRadar malicious malicious
Webroot malicious malicious
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarNAMECHEAP INC
TLDtop
History
Creation date2022-11-18 10:26 UTC
Last analysis2026-08-02 14:01 UTC
Last modified on VirusTotal2026-08-04 17:53 UTC
Last WHOIS update2025-10-23 11:32 UTC
WHOIS record date2026-07-24 17:26 UTC
domain aftrk.click VT 0 / 91 UrlVoid 0 / 35

IOC database

Type
domain
Value
aftrk.click
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
RegistrarNAMECHEAP
TLDclick
History
Creation date2022-08-26 08:31 UTC
Last analysis2026-07-20 09:09 UTC
Last modified on VirusTotal2026-07-21 02:00 UTC
Last WHOIS update2025-08-01 05:45 UTC
WHOIS record date2026-07-20 09:13 UTC
domain 32891098.xyz VT 0 / 91 UrlVoid 0 / 35

IOC database

Type
domain
Value
32891098.xyz
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
TLDxyz
History
Creation date2025-09-04 00:00 UTC
Last analysis2026-07-27 03:22 UTC
Last modified on VirusTotal2026-07-27 03:34 UTC
WHOIS record date2026-09-04 00:00 UTC
domain 927ti.top VT 2 / 91

IOC database

Type
domain
Value
927ti.top
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 2 of 91 VirusTotal vendors

VendorVerdictDetection
alphaMountain.ai suspicious spam
Fortinet suspicious spam

Details From VirusTotal

Basic Properties
RegistrarNameSilo,LLC
TLDtop
History
Creation date2026-03-23 13:21 UTC
Last analysis2026-06-21 08:59 UTC
Last modified on VirusTotal2026-07-19 09:02 UTC
Last WHOIS update2026-03-23 15:30 UTC
WHOIS record date2026-05-22 22:04 UTC
domain aquaaqua.top VT 0 / 91

IOC database

Type
domain
Value
aquaaqua.top
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
TLDtop
History
Creation date2024-10-21 00:00 UTC
Last analysis2026-08-04 16:18 UTC
Last modified on VirusTotal2026-08-04 16:29 UTC
Last WHOIS update2026-02-02 00:00 UTC
WHOIS record date2026-10-21 00:00 UTC
domain cdn-stream.top VT 0 / 91 UrlVoid 0 / 35

IOC database

Type
domain
Value
cdn-stream.top
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
TLDtop
History
Creation date2026-07-12 00:00 UTC
Last analysis2026-07-14 16:27 UTC
Last modified on VirusTotal2026-07-26 16:54 UTC
Last WHOIS update2026-07-12 00:00 UTC
WHOIS record date2027-07-12 00:00 UTC
domain dareplus.eu VT 0 / 91 UrlVoid 0 / 35

IOC database

Type
domain
Value
dareplus.eu
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
TLDeu
History
Last analysis2025-09-18 21:35 UTC
Last modified on VirusTotal2025-10-16 21:40 UTC
WHOIS record date2025-08-13 21:03 UTC
domain dihimystore.top VT 1 / 91 UrlVoid 1 / 35

IOC database

Type
domain
Value
dihimystore.top
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 1 of 91 VirusTotal vendors

VendorVerdictDetection
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarNameSilo,LLC
TLDtop
History
Creation date2026-07-25 19:00 UTC
Last analysis2026-08-04 21:48 UTC
Last modified on VirusTotal2026-08-04 22:01 UTC
Last WHOIS update2026-07-25 19:00 UTC
WHOIS record date2026-07-25 20:31 UTC
domain fdskjfcmcc.xyz VT 12 / 91

IOC database

Type
domain
Value
fdskjfcmcc.xyz
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 12 of 91 VirusTotal vendors

VendorVerdictDetection
BitDefender malicious phishing
CRDF malicious malicious
Fortinet malicious phishing
G-Data malicious phishing
Kaspersky malicious phishing
Lionic malicious phishing
SafeToOpen malicious phishing
Sophos malicious phishing
VIPRE malicious phishing
Webroot malicious malicious
alphaMountain.ai suspicious suspicious
ESET suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarNameCheap, Inc.
TLDxyz
History
Creation date2026-07-22 08:28 UTC
Last analysis2026-08-04 15:40 UTC
Last modified on VirusTotal2026-08-04 15:46 UTC
Last WHOIS update2026-07-22 08:28 UTC
WHOIS record date2026-07-22 10:33 UTC
domain genuggut.buzz VT 0 / 91

IOC database

Type
domain
Value
genuggut.buzz
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
RegistrarSpaceship, Inc.
TLDbuzz
History
Creation date2026-07-27 12:10 UTC
Last analysis2026-08-04 22:42 UTC
Last modified on VirusTotal2026-08-04 22:58 UTC
Last WHOIS update2026-07-27 12:11 UTC
WHOIS record date2026-07-27 13:29 UTC
domain hotwheelsasdas.xyz VT 10 / 91 UrlVoid 4 / 35

IOC database

Type
domain
Value
hotwheelsasdas.xyz
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 10 of 91 VirusTotal vendors

VendorVerdictDetection
BitDefender malicious phishing
CRDF malicious malicious
CyRadar malicious phishing
Fortinet malicious phishing
G-Data malicious phishing
Kaspersky malicious phishing
SafeToOpen malicious phishing
Sophos malicious phishing
alphaMountain.ai suspicious suspicious
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarNAMECHEAP INC
TLDxyz
History
Creation date2026-07-27 14:41 UTC
Last analysis2026-08-04 16:32 UTC
Last modified on VirusTotal2026-08-04 21:40 UTC
Last WHOIS update2026-07-27 14:41 UTC
WHOIS record date2026-07-27 16:29 UTC
domain j2m20.xyz VT 1 / 91 UrlVoid 1 / 35

IOC database

Type
domain
Value
j2m20.xyz
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 1 of 91 VirusTotal vendors

VendorVerdictDetection
Forcepoint ThreatSeeker suspicious suspicious

Details From VirusTotal

Basic Properties
TLDxyz
History
Creation date2025-01-24 00:00 UTC
Last analysis2026-06-20 20:58 UTC
Last modified on VirusTotal2026-06-24 20:27 UTC
Last WHOIS update2026-01-25 00:00 UTC
WHOIS record date2027-01-24 00:00 UTC
domain quickvaultflow.click VT 2 / 91

IOC database

Type
domain
Value
quickvaultflow.click
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 2 of 91 VirusTotal vendors

VendorVerdictDetection
CRDF malicious malicious
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarSpaceship, Inc.
TLDclick
History
Creation date2026-07-23 06:04 UTC
Last analysis2026-07-29 13:47 UTC
Last modified on VirusTotal2026-08-04 11:58 UTC
Last WHOIS update2026-07-23 06:07 UTC
WHOIS record date2026-07-23 07:08 UTC
domain swiftfilebridge.click VT 0 / 91 UrlVoid 0 / 35

IOC database

Type
domain
Value
swiftfilebridge.click
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
RegistrarSpaceship, Inc.
TLDclick
History
Creation date2026-07-23 06:04 UTC
Last analysis2026-07-23 08:03 UTC
Last modified on VirusTotal2026-08-04 18:34 UTC
Last WHOIS update2026-07-23 06:07 UTC
WHOIS record date2026-07-23 07:08 UTC
domain x5ly4jmy.xyz VT 2 / 91 UrlVoid 0 / 35

IOC database

Type
domain
Value
x5ly4jmy.xyz
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 2 of 91 VirusTotal vendors

VendorVerdictDetection
alphaMountain.ai suspicious suspicious
Forcepoint ThreatSeeker suspicious suspicious

Details From VirusTotal

Basic Properties
TLDxyz
History
Creation date2025-08-21 00:00 UTC
Last analysis2026-07-18 09:58 UTC
Last modified on VirusTotal2026-08-04 16:59 UTC
Last WHOIS update2025-08-21 00:00 UTC
WHOIS record date2026-08-21 00:00 UTC
domain xw20z.top VT 0 / 91 UrlVoid 0 / 35

IOC database

Type
domain
Value
xw20z.top
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
TLDtop
History
Creation date2025-10-13 00:00 UTC
Last analysis2026-07-31 17:37 UTC
Last modified on VirusTotal2026-07-31 17:45 UTC
Last WHOIS update2025-10-13 00:00 UTC
WHOIS record date2026-10-13 00:00 UTC
domain yifacai.top VT 4 / 91

IOC database

Type
domain
Value
yifacai.top
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 4 of 91 VirusTotal vendors

VendorVerdictDetection
CRDF malicious malicious
ESET malicious malware
Fortinet malicious malware
alphaMountain.ai suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarNameSilo, LLC
TLDtop
History
Creation date2026-07-01 04:02 UTC
Last analysis2026-07-25 14:04 UTC
Last modified on VirusTotal2026-07-25 15:53 UTC
Last WHOIS update2026-07-01 07:00 UTC
WHOIS record date2026-07-01 15:35 UTC
domain zznq.buzz VT 0 / 91 UrlVoid 1 / 35

IOC database

Type
domain
Value
zznq.buzz
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

Basic Properties
TLDbuzz
History
Creation date2022-03-29 00:00 UTC
Last analysis2026-07-29 01:51 UTC
Last modified on VirusTotal2026-07-29 02:10 UTC
Last WHOIS update2026-03-26 00:00 UTC
WHOIS record date2027-03-29 00:00 UTC

References (1)

  • OTX pulse AlienVaulkt OTX

    IoI High Confidence C2 domains detected during 2026-08.

Remediations (9)

  • web:about.att.com

    Communications Cybersecurity Information Sharing and Analysis Center, known as C2 ISAC, is dedicated to strengthening cybersecurity across the communications sector.

  • web:acsmi.org

    Critical infrastructure cybersecurity report with 2026 -2027 threat assessment, OT risks, ransomware exposure, and defense priorities.

  • web:blog.netmanageit.com

    The IOCs included in this pulse are associated with command and control ( C2 ) infrastructure , facilitating malware communication, data exfiltration, and persistent threat actor operations. Use this data to enhance detection rules, block malicious infrastructure , or correlate with existing incident investigations. OPENCTI LABELS :

  • web:blog.netmanageit.com

    These indicators of compromise (IOCs) were identified through LevelBlue Labs' proprietary collection and threat hunting processes, leveraging AI-driven heuristics to detect anomalous patterns, behavioral analysis of malicious activity, and cross-referenced intelligence from endpoint telemetry and external sources. Use this data to enhance detection rules, block malicious infrastructure , or ...

  • web:informatix.systems

    Discover how CTI monitors command and control servers using IOCs, AI detection, and threat intel frameworks. Learn advanced techniques for 2026 enterprise security from Informatix.Systems experts.

  • web:informatix.systems

    Discover expert techniques for tracking malware infrastructure using Cyber Threat Intelligence (CTI). Learn OSINT methods, C2 detection, tools, and enterprise strategies to hunt malicious networks in 2026 .

  • web:www.microsoft.com

    On March 31, 2026 , the popular HTTP client Axios experienced a supply chain attack, causing two newly published npm packages for version updates to download from command and control ( C2 ) that Microsoft Threat Intelligence has attributed to the North Korean state actor Sapphire Sleet. Although the malicious versions are no longer available for download, since Axios is one of the most widely ...

  • web:www.securitricks.com

    These indicators of compromise (IOCs) were identified through LevelBlue Labs' proprietary collection and threat hunting processes, leveraging AI-driven heuristics to detect anomalous patterns, behavioral analysis of malicious activity, and cross-referenced intelligence from endpoint telemetry and external sources. The IOCs included in this pulse are associated with infostealer malware ...

  • web:www.vulncheck.com

    Command and control ( C2 or C&C) infrastructure is the technical foundation of these attacks. By understanding what C2 is and how C2 -based attacks work, security teams can improve their effectiveness and reduce an attack's impact.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.