TF-1933818
high
📛 Threat Title
Unknown Loader: Domain name that delivers a malware payload themoon24.net
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:29 UTC. Last seen: 2026-09-25 16:28:19 UTC. Reporter: varysz. Tags: etherhiding, victim.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
themoon24.net
VT 1 / 91
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
themoon24.net- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | GoDaddy.com, LLC |
| TLD | net |
History
| Creation date | 2024-06-18 12:13 UTC |
| Last analysis | 2026-09-25 17:16 UTC |
| Last modified on VirusTotal | 2026-09-26 00:08 UTC |
| Last WHOIS update | 2026-06-25 11:13 UTC |
| WHOIS record date | 2026-09-15 00:15 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:29 UTC. Last seen: 2026-09-25 16:28:19 UTC. Reporter: varysz. Tags: etherhiding, victim.
Remediations (10)
-
web:cyberpress.org
Attackers changed lure domains , payload sources and command-and-control methods across four malware chains observed over five months.
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with ** payload delivery** activity tied to the malware ** unknown\_loader **. This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations. ---
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.
-
web:femtosec.io
Analysis of the ClickFix loader emerging on underground forums. Learn how this malware deployment tool impacts enterprise security and how to mitigate the risk.
-
web:radar.cloudflare.com
Understand the security, performance, technology, and network details of a URL with a publicly shareable report.
-
web:thehackernews.com
ClickFix accounted for 47% of Microsoft Defender Experts initial-access cases in 2025, while a Polygon contract rotated lure hosts.
-
web:threatfox.abuse.ch
A malware sample can be associated with only one malware family. The page below gives you an overview on indicators of compromise associated with unknown_loader .
-
web:www.hhs.gov
Overview of ClickFix Attacks Threat actors initiate these campaigns by logging into websites with stolen credentials and installing fake plugins in compromised environments. Once installed, the plugins inject malicious JavaScript containing a known variation of fake browser update malware that uses blockchain and smart contracts to obtain malicious payloads ( a practice known as EtherHiding ...
-
web:www.malwarebytes.com
A domain used in software examples—third-party[.]com—now serves up a fake verification page that tells Windows users to run a PowerShell command.
-
web:www.malwarebytes.com
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.