TF-1931110
high
📛 Threat Title
ClearFake: ip:port combination that delivery a malware payload 91.92.33.76:80
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: ip:port combination that delivery a malware payload. Attributed malware: ClearFake. Confidence: 100. Observed port: 80. First seen: 2026-09-23 23:42:50 UTC. Reporter: anonymous.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
91.92.33.76
IOC database
- Type
- ipv4
- Value
91.92.33.76- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- ip:port combination that delivery a malware payload attributed to ClearFake
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: ip:port combination that delivery a malware payload. Attributed malware: ClearFake. Confidence: 100. Observed port: 80. First seen: 2026-09-23 23:42:50 UTC. Reporter: anonymous.
Remediations (10)
-
web:ieeexplore.ieee.org
Security breaches due to attacks by malicious software ( malware ) continue to escalate posing a major security concern in this digital age. With many computer users, corporations, and governments affected due to an exponential growth in malware attacks, malware detection continues to be a hot research topic. Current malware detection solutions that adopt the static and dynamic analysis of ...
-
web:owasp.org
Summary The scope of this test is to verify if it is possible to collect a set of valid usernames by interacting with the authentication mechanism of the application. This test will be useful for brute force testing, in which the tester verifies if, given a valid username, it is possible to find the corresponding password. Often, web applications reveal when a username exists on system, either ...
-
web:owasp.org
Summary Cross Origin Resource Sharing (CORS) is a mechanism that enables a web browser to perform cross-domain requests using the XMLHttpRequest (XHR) Level 2 (L2) API in a controlled manner. In the past, the XHR L1 API only allowed requests to be sent within the same origin as it was restricted by the Same Origin Policy (SOP). Cross-origin requests have an Origin header that identifies the ...
-
web:pmc.ncbi.nlm.nih.gov
We would like to show you a description here but the site won't allow us.
-
web:windowsforum.com
windowsforum.com
-
web:windowsforum.com
windowsforum.com
-
web:windowsforum.com
Retaining meaningful warnings about malware , account access, subscription status, and protection failures. Avoiding links, numbers, and payment forms inside unsolicited antivirus warnings. Keeping Windows, browsers, and security software updated. Fake McAfee pop-ups succeed because they exploit urgency.
-
web:www.cisa.gov
Home Page | CISA
-
web:www.executivebiz.com
ExecutiveBiz
-
web:www.reddit.com
We would like to show you a description here but the site won't allow us.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.