TF-1933873
high
📛 Threat Title
Unknown Loader: Domain name that delivers a malware payload vantilenj.com
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:34 UTC. Reporter: varysz. Tags: etherhiding, victim.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
vantilenj.com
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/vantilenj.com
IOC database
- Type
- domain
- Value
vantilenj.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/vantilenj.com
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:34 UTC. Reporter: varysz. Tags: etherhiding, victim.
Remediations (10)
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with ** payload delivery** activity tied to the malware ** unknown\_loader **. This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations. ---
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.
-
web:davidgodwinpratt.com
The deployment process involves the ccmsetup.exe or msiexec.exe spawning a temporary loader process that downloads and executes an unsigned or newly signed payload , matching the " Unknown Loader " signature before the certificate is fully recognized by ThreatFox.
-
web:femtosec.io
Analysis of the ClickFix loader emerging on underground forums. Learn how this malware deployment tool impacts enterprise security and how to mitigate the risk.
-
web:ismalicious.com
4,553 indicators of compromise attributed to the Unknown Loader malware family — domains , IPs, URLs and file hashes, from abuse.ch feeds.
-
web:precisionsec.com
Recent Malware Domain List indicators Live domain indicators, including phishing lures, C2 and payload -hosting infrastructure, pulled straight from our threat feed and refreshed hourly. For full coverage and API delivery, start a free trial. A sample from our threat feed.
-
web:socprime.com
The initial malware communicated with a command-and-control server at 89.110.110.119 over TCP port 443 using encoded traffic. The campaign, tracked as SmartApeSG ClickFix, relied on malicious scripts and a CAB archive to install the NetSupport RAT on victim systems.
-
web:thehackernews.com
ClickFix attacks are delivering BabaDeda, Lorem Ipsum, and Potemkin loaders to deploy stealers, RATs, and ransomware-linked tooling.
-
web:thehackernews.com
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login credentials.
-
web:www.malwarebytes.com
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.