TF-1932065
high
📛 Threat Title
Unknown Loader: Domain name that delivers a malware payload techscription.us
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-24 07:38:08 UTC. Last seen: 2026-09-24 07:48:27 UTC. Reporter: varysz. Tags: etherhiding, victim.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
techscription.us
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
techscription.us- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain name that delivers a malware payload attributed to Unknown Loader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-24 07:38:08 UTC. Last seen: 2026-09-24 07:48:27 UTC. Reporter: varysz. Tags: etherhiding, victim.
Remediations (10)
-
web:blog.sicuranext.com
The C2 domain autum-path [.]vo8xalon [.]in [.]net is attributed to GULoader based on Cluster25 reporting on VirustTotal. GULoader is a shellcode-based downloader that operates in memory with anti-VM, anti-debug, and anti-sandbox capabilities.
-
web:reliaquest.com
"DeepLoad" malware has arrived in enterprise environments via "ClickFix" delivery, turning one user action into rapid, fileless compromise. It likely uses AI-assisted obfuscation and process injection to evade static scanning, while credential theft starts immediately and captures passwords and sessions even if the primary loader is ...
-
web:socprime.com
DeepLoad is a fileless malware family distributed through ClickFix social engineering. It relies on an obfuscated PowerShell loader , in-memory shellcode injection into trusted Windows processes, and AI-generated "noise" to reduce static-detection fidelity.
-
web:thehackernews.com
Microsoft details a new ClickFix variant abusing DNS nslookup commands to stage malware , enabling stealthy payload delivery and RAT deployment.
-
web:thehackernews.com
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login credentials.
-
web:www.csoonline.com
The WordPress ClickFix campaign delivers three separate infostealer payloads — two of them previously unknown — and uses domain infrastructure that appears to have been set up since July 2025.
-
web:www.ctm360.com
ClickFix is a rapidly evolving social engineering technique that tricks users into executing malicious commands through fake CAPTCHA checks, browser errors, verification prompts, and other seemingly legitimate instructions. Unlike traditional malware delivery, ClickFix often requires no software exploit—the user is manipulated into initiating the attack themselves. In ClickFix & Beyond ...
-
web:www.malwarebytes.com
We uncovered ClickFix attacks using fake Google and Cloudflare pages to deliver everything from infostealers to a newly discovered malware loader .
-
web:www.microsoft.com
Threat actors are targeting macOS users with fake utility fixes that trick them into running malicious Terminal commands. This campaign evades traditional defenses by stealing credentials, wallets, and sensitive data.
-
web:www.microsoft.com
The retrieved content is executed directly in memory. Steganography-based payload delivery A notable technique in this campaign is the use of steganography to conceal malicious content inside a publicly hosted image. Instead of downloading a secondary script ( as in Campaign 1), the malware retrieves a JPEG image from an image-hosting service.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.