TF-1933914
high
📛 Threat Title
Unknown Loader: Domain name that delivers a malware payload wiltshire.energy
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:38 UTC. Reporter: varysz. Tags: etherhiding, victim.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
wiltshire.energy
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/wiltshire.energy
UrlVoid 0 / 36
IOC database
- Type
- domain
- Value
wiltshire.energy- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/wiltshire.energy
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:38 UTC. Reporter: varysz. Tags: etherhiding, victim.
Remediations (10)
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.
-
web:femtosec.io
Analysis of the ClickFix loader emerging on underground forums. Learn how this malware deployment tool impacts enterprise security and how to mitigate the risk.
-
web:ismalicious.com
4,553 indicators of compromise attributed to the Unknown Loader malware family — domains , IPs, URLs and file hashes, from abuse.ch feeds.
-
web:rhisac.org
The malware provides operators with persistence, system reconnaissance, command execution, payload delivery, and resilient command and control capabilities. Key Takeaways DOUBLECUP is a Russian Loader - as -a-Service developed for ClickFix campaigns and has operated since early June 2026.
-
web:thehackernews.com
The payload is gated on machine identity The third finding is the one that should change how teams interpret their tooling. In the dropper recovered from the live host, a hardware and account fingerprint machine GUID, volume serial, computer name , BIOS manufacturer, system model, GPU and username is base64-encoded directly into the download path.
-
web:urlhaus.abuse.ch
URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...
-
web:www.hhs.gov
Overview of ClickFix Attacks Threat actors initiate these campaigns by logging into websites with stolen credentials and installing fake plugins in compromised environments. Once installed, the plugins inject malicious JavaScript containing a known variation of fake browser update malware that uses blockchain and smart contracts to obtain malicious payloads ( a practice known as EtherHiding ...
-
web:www.malwarebytes.com
A domain used in software examples—third-party[.]com—now serves up a fake verification page that tells Windows users to run a PowerShell command.
-
web:www.microsoft.com
The ClickFix social engineering technique has been growing in popularity, with campaigns targeting thousands of enterprise and end-user devices daily. This technique exploits users' tendency to resolve technical issues by tricking them into running malicious commands. These commands, in turn, deliver payloads that ultimately lead to information theft and exfiltration.
-
web:www.picussecurity.com
DeepLoad is a fileless loader observed in enterprise compromises. It is delivered through ClickFix, a social engineering technique where users are tricked into pasting an attacker-supplied command into Windows Run or a terminal. The command is disguised as a fix for a fake browser error, but it fetches and executes a remote payload directly in memory.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.