TF-1931098
high
📛 Threat Title
Unknown Stealer: Domain name that delivers a malware payload chilloutvrmodded.net
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Stealer. Confidence: 100. First seen: 2026-09-23 22:51:03 UTC. Reporter: NekoPunchii. Tags: BTWStealer, spyware, stealer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
chilloutvrmodded.net
UrlVoid 0 / 36
IOC database
- Type
- domain
- Value
chilloutvrmodded.net- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain name that delivers a malware payload attributed to Unknown Stealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Stealer. Confidence: 100. First seen: 2026-09-23 22:51:03 UTC. Reporter: NekoPunchii. Tags: BTWStealer, spyware, stealer.
- External reference ThreatFox IOCs
Remediations (10)
-
web:blog.talosintelligence.com
The payload is a cryptocurrency stealer written in Zig language — ZigCryptoStealer. It polls the clipboard, recognizes several cryptocurrency address formats and can replace matching values with addresses embedded in the payload .
-
web:ismalicious.com
Check IPs, domains , URLs, emails, phones and crypto wallets against indexed threat indicators. Streaming reports, blocklist API, free API key.
-
web:radar.cloudflare.com
Understand the security, performance, technology, and network details of a URL with a publicly shareable report.
-
web:threatfox.abuse.ch
Browse indicators of compromise (IOCs) on ThreatFox ThreatFox IOC Database You are browsing the Indicator Of Compromise (IOC) database of ThreatFox. If you would like to contribute IOCs to the corpuse, you can do so through either the web form or the API.
-
web:urlhaus.abuse.ch
Here you can propose new malware urls or just browse the URLhaus database. If you are looking for a parsable list of the dataset, you might want to check out the URLhaus API.
-
web:www.csoonline.com
The WordPress ClickFix campaign delivers three separate infostealer payloads — two of them previously unknown — and uses domain infrastructure that appears to have been set up since July 2025.
-
web:www.malwarebytes.com
We uncovered ClickFix attacks using fake Google and Cloudflare pages to deliver everything from infostealers to a newly discovered malware loader.
-
web:www.microsoft.com
Amadey: Malware - as -a-service for delivery of infostealers Active since at least 2018, Amadey operates as a malware - as -a-service (MaaS) that has been used as a delivery mechanism for downstream malware such as StealC, Lumma Stealer , remote access trojans (RATs), crypto miners, and, in some cases, ransomware. Figure 4.
-
web:www.microsoft.com
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments.
-
web:www.splunk.com
STRT observed that Phantom Stealer leverages multiple loader variants to deliver its payload . One notable variant is a .NET-based loader that conceals the actual malware payload within .NET resource manifest metadata, a technique that abuses the way .NET assemblies store embedded resources to hide malicious content from casual inspection.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.