s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1821476 high

📛 Threat Title

Unknown Stealer: Domain name that delivers a malware payload safepals.gr.com

Category: Unknown Stealer Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Stealer. Confidence: 100. First seen: 2026-06-02 19:41:13 UTC. Reporter: ninjacatcher. Tags: infostealer, stealer.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 185.53.179.136 VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/185.53.179.136

IOC database

Type
ipv4
Value
185.53.179.136
First seen
Last seen
Attached to this threat
Appears in
17 threats
Description
Resolved from domain xkobeimparatu.net

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/ip_addresses/185.53.179.136

ipv4 94.183.187.207

IOC database

Type
ipv4
Value
94.183.187.207
First seen
Last seen
Attached to this threat
Appears in
10 threats
Description
Resolved from domain safepal-app.co.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain safepals.gr.com UrlVoid 4 / 36

IOC database

Type
domain
Value
safepals.gr.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Stealer. Confidence: 100. First seen: 2026-06-02 19:41:13 UTC. Reporter: ninjacatcher. Tags: infostealer, stealer.

Remediations (10)

  • web:cybersecuritynews.com

    A sophisticated DNS-based malware campaign has emerged, utilizing thousands of compromised websites worldwide to deliver the Strela Stealer information-stealing malware through an unprecedented technique involving DNS TXT records. The threat, tracked as Detour Dog by security researchers, represents a significant evolution in malware distribution methods that leverages the Domain Name System ...

  • web:gbhackers.com

    Detour Dog, a stealthy website malware campaign tracked since August 2023, has evolved from redirecting victims to tech-support scams into a sophisticated DNS-based command-and-control (C2) distribution system that delivers the Strela Stealer information stealer via DNS TXT records.

  • web:help.upguard.com

    The Infostealer Malware Detected risk identifies when UpGuard has observed one or more email addresses to a monitored primary domain in known infostealer malware data leaks. Infostealer malware is malicious software installed on a computer - often through phishing, malicious downloads, or fake software updates - that steals data and credentials stored on the machine. This can include saved ...

  • web:malwarediscoverer.com

    Discover domain abuse before they impact real users Malicious URL redirection leads to malware , phishing and scam. Waiting for real users to report domain abuse is slow. Our proactive system discovers URL redirections without human interference.

  • web:unit42.paloaltonetworks.com

    PhantomVAI is a new loader used to deploy multiple infostealers. We discuss its overall evolution and use of steganography and obfuscated scripts.

  • web:urlhaus.abuse.ch

    URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...

  • web:www.defenddomain.com

    Ransomware costs organisations $4.54 million per incident on average — and 71% of malware distribution campaigns use lookalike domains to deliver their payloads . We detect the fake download infrastructure before it delivers a single payload . DefendDomain monitors for lookalike domains hosting malicious files, fake software update pages, and SSL certificates that make dangerous downloads look ...

  • web:www.filescan.io

    Submit malware for analysis on this next-gen malware assessment platform. Filescan GmbH develops and licenses technology to fight malware with a focus on Indicator-of-Compromise (IOC) extraction at scale.

  • web:www.ipqualityscore.com

    Scan URLs for malware and phishing with our free malicious URL scanner. Check links in real-time to detect suspicious domains and prevent cyber threats.

  • web:www.virustotal.com

    VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…