TF-1933828
high
📛 Threat Title
Unknown Loader: Domain name that delivers a malware payload timejas.lt
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:30 UTC. Last seen: 2026-09-25 16:28:19 UTC. Reporter: varysz. Tags: etherhiding, victim.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
timejas.lt
VT 2 / 91
UrlVoid 2 / 36
IOC database
- Type
- domain
- Value
timejas.lt- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 2 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| CRDF | malicious | malicious |
| Gridinsoft | malicious | phishing |
Details From VirusTotal
Basic Properties
| Registrar | UAB "Interneto vizija" |
| TLD | lt |
History
| Last analysis | 2026-09-24 21:27 UTC |
| Last modified on VirusTotal | 2026-09-25 20:35 UTC |
| WHOIS record date | 2026-09-21 11:45 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:30 UTC. Last seen: 2026-09-25 16:28:19 UTC. Reporter: varysz. Tags: etherhiding, victim.
Remediations (10)
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.
-
web:github.com
This repository documents a malware investigation of an unknown Windows executable named Unknown .exe. The sample was handled inside an isolated lab, first through static analysis and then through controlled dynamic analysis to understand its file structure, indicators, network behavior, file activity, registry activity, and likely purpose.
-
web:ismalicious.com
4,553 indicators of compromise attributed to the Unknown Loader malware family — domains , IPs, URLs and file hashes, from abuse.ch feeds.
-
web:socprime.com
The malware relies on strong obfuscation, a domain -generation algorithm, and a Beacon Object File (BOF) loader to expand its capabilities after execution. Its network communications are encrypted over TLS and are designed to resemble legitimate Microsoft Delivery Optimization traffic, helping the activity blend into normal network behavior.
-
web:socradar.io
What Is a Malware Loader ? A malware loader is code whose primary purpose is to retrieve, unpack, inject, or execute another malicious payload . Loaders give operators a small initial foothold that can be updated with an infostealer, ransomware, remote access Trojan, or campaign-specific module after the victim is assessed. A loader is defined by its role in the infection chain, not by one file ...
-
web:thehackernews.com
Microsoft details a new ClickFix variant abusing DNS nslookup commands to stage malware , enabling stealthy payload delivery and RAT deployment.
-
web:thehackernews.com
ClickFix attacks are delivering BabaDeda, Lorem Ipsum, and Potemkin loaders to deploy stealers, RATs, and ransomware-linked tooling.
-
web:threatlabsnews.xcitium.com
Discover how the new ClickFix attack abuses DNS queries and nslookup to deliver the ModeloRAT malware . Learn how to protect your network from this evolving social engineering threat.
-
web:www.intertecsystems.com
Modern malware loaders deliver multi- payload attacks like adware and RATs. Learn techniques, risks, and detection strategies.
-
web:www.malwarebytes.com
A domain used in software examples—third-party[.]com—now serves up a fake verification page that tells Windows users to run a PowerShell command.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.