TF-1821476
high
📛 Threat Title
Unknown Stealer: Domain name that delivers a malware payload safepals.gr.com
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Stealer. Confidence: 100. First seen: 2026-06-02 19:41:13 UTC. Reporter: ninjacatcher. Tags: infostealer, stealer.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
185.53.179.136
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/185.53.179.136
IOC database
- Type
- ipv4
- Value
185.53.179.136- First seen
- Last seen
- Attached to this threat
- Appears in
- 17 threats
- Description
- Resolved from domain xkobeimparatu.net
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/185.53.179.136
ipv4
94.183.187.207
IOC database
- Type
- ipv4
- Value
94.183.187.207- First seen
- Last seen
- Attached to this threat
- Appears in
- 10 threats
- Description
- Resolved from domain safepal-app.co.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
safepals.gr.com
UrlVoid 4 / 36
IOC database
- Type
- domain
- Value
safepals.gr.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Stealer. Confidence: 100. First seen: 2026-06-02 19:41:13 UTC. Reporter: ninjacatcher. Tags: infostealer, stealer.
Remediations (10)
-
web:cybersecuritynews.com
A sophisticated DNS-based malware campaign has emerged, utilizing thousands of compromised websites worldwide to deliver the Strela Stealer information-stealing malware through an unprecedented technique involving DNS TXT records. The threat, tracked as Detour Dog by security researchers, represents a significant evolution in malware distribution methods that leverages the Domain Name System ...
-
web:gbhackers.com
Detour Dog, a stealthy website malware campaign tracked since August 2023, has evolved from redirecting victims to tech-support scams into a sophisticated DNS-based command-and-control (C2) distribution system that delivers the Strela Stealer information stealer via DNS TXT records.
-
web:help.upguard.com
The Infostealer Malware Detected risk identifies when UpGuard has observed one or more email addresses to a monitored primary domain in known infostealer malware data leaks. Infostealer malware is malicious software installed on a computer - often through phishing, malicious downloads, or fake software updates - that steals data and credentials stored on the machine. This can include saved ...
-
web:malwarediscoverer.com
Discover domain abuse before they impact real users Malicious URL redirection leads to malware , phishing and scam. Waiting for real users to report domain abuse is slow. Our proactive system discovers URL redirections without human interference.
-
web:unit42.paloaltonetworks.com
PhantomVAI is a new loader used to deploy multiple infostealers. We discuss its overall evolution and use of steganography and obfuscated scripts.
-
web:urlhaus.abuse.ch
URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...
-
web:www.defenddomain.com
Ransomware costs organisations $4.54 million per incident on average — and 71% of malware distribution campaigns use lookalike domains to deliver their payloads . We detect the fake download infrastructure before it delivers a single payload . DefendDomain monitors for lookalike domains hosting malicious files, fake software update pages, and SSL certificates that make dangerous downloads look ...
-
web:www.filescan.io
Submit malware for analysis on this next-gen malware assessment platform. Filescan GmbH develops and licenses technology to fight malware with a focus on Indicator-of-Compromise (IOC) extraction at scale.
-
web:www.ipqualityscore.com
Scan URLs for malware and phishing with our free malicious URL scanner. Check links in real-time to detect suspicious domains and prevent cyber threats.
-
web:www.virustotal.com
VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.