TF-1931921
high
📛 Threat Title
Unknown Loader: Domain name that delivers a malware payload ravikakkepadavucharitytrust.org
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-24 07:37:17 UTC. Last seen: 2026-09-24 07:47:44 UTC. Reporter: varysz. Tags: etherhiding, victim.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
ravikakkepadavucharitytrust.org
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
ravikakkepadavucharitytrust.org- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain name that delivers a malware payload attributed to Unknown Loader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-24 07:37:17 UTC. Last seen: 2026-09-24 07:47:44 UTC. Reporter: varysz. Tags: etherhiding, victim.
Remediations (10)
-
web:any.run
A loader is malicious software that infiltrates devices to deliver malicious payloads . This malware is capable of infecting victims' computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running ...
-
web:cybersecuritynews.com
An unrecorded .NET Loader was identified during routine threat hunting that downloads, decrypts, and executes a wide range of malicious payloads . Multiple threat actors extensively distributed this new loader in early June 2023 through the following mediums:- Security analysts appointed this name ...
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.
-
web:radar.cloudflare.com
Understand the security, performance, technology, and network details of a URL with a publicly shareable report.
-
web:research.checkpoint.com
Among the payloads distributed through this TDS infrastructure, we identified several malware families: SessionGate — A previously unknown multi-stage loader with heavy obfuscation and extensive anti-analysis mechanisms, which makes obtaining the final payload extremely difficult.
-
web:socradar.io
Multiple independent ClickFix social engineering campaigns observed between April and June 2026 are delivering three distinct malware loaders BabaDeda Loader , Lorem Ipsum Loader , and Potemkin that fetch information stealers, remote access trojans, and ransomware-linked tooling onto Windows hosts. Victims are lured into pasting attacker supplied commands into the Run dialog or terminal, after ...
-
web:socradar.io
What Is a Malware Loader ? A malware loader is code whose primary purpose is to retrieve, unpack, inject, or execute another malicious payload . Loaders give operators a small initial foothold that can be updated with an infostealer, ransomware, remote access Trojan, or campaign-specific module after the victim is assessed. A loader is defined by its role in the infection chain, not by one file ...
-
web:threatfox.abuse.ch
A malware sample can be associated with only one malware family. The page below gives you an overview on indicators of compromise associated with unknown_loader .
-
web:www.malwarebytes.com
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware .
-
web:www.microsoft.com
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.