s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1931110 high

📛 Threat Title

ClearFake: ip:port combination that delivery a malware payload 91.92.33.76:80

Category: ClearFake Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: ip:port combination that delivery a malware payload. Attributed malware: ClearFake. Confidence: 100. Observed port: 80. First seen: 2026-09-23 23:42:50 UTC. Reporter: anonymous.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 91.92.33.76

IOC database

Type
ipv4
Value
91.92.33.76
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
ip:port combination that delivery a malware payload attributed to ClearFake

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: ip:port combination that delivery a malware payload. Attributed malware: ClearFake. Confidence: 100. Observed port: 80. First seen: 2026-09-23 23:42:50 UTC. Reporter: anonymous.

Remediations (10)

  • web:ieeexplore.ieee.org

    Security breaches due to attacks by malicious software ( malware ) continue to escalate posing a major security concern in this digital age. With many computer users, corporations, and governments affected due to an exponential growth in malware attacks, malware detection continues to be a hot research topic. Current malware detection solutions that adopt the static and dynamic analysis of ...

  • web:owasp.org

    Summary The scope of this test is to verify if it is possible to collect a set of valid usernames by interacting with the authentication mechanism of the application. This test will be useful for brute force testing, in which the tester verifies if, given a valid username, it is possible to find the corresponding password. Often, web applications reveal when a username exists on system, either ...

  • web:owasp.org

    Summary Cross Origin Resource Sharing (CORS) is a mechanism that enables a web browser to perform cross-domain requests using the XMLHttpRequest (XHR) Level 2 (L2) API in a controlled manner. In the past, the XHR L1 API only allowed requests to be sent within the same origin as it was restricted by the Same Origin Policy (SOP). Cross-origin requests have an Origin header that identifies the ...

  • web:pmc.ncbi.nlm.nih.gov

    We would like to show you a description here but the site won't allow us.

  • web:windowsforum.com

    windowsforum.com

  • web:windowsforum.com

    windowsforum.com

  • web:windowsforum.com

    Retaining meaningful warnings about malware , account access, subscription status, and protection failures. Avoiding links, numbers, and payment forms inside unsolicited antivirus warnings. Keeping Windows, browsers, and security software updated. Fake McAfee pop-ups succeed because they exploit urgency.

  • web:www.cisa.gov

    Home Page | CISA

  • web:www.executivebiz.com

    ExecutiveBiz

  • web:www.reddit.com

    We would like to show you a description here but the site won't allow us.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…