TF-1933837
high
📛 Threat Title
Unknown Loader: Domain name that delivers a malware payload transferslovenia.com
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:31 UTC. Reporter: varysz. Tags: etherhiding, victim.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
transferslovenia.com
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/transferslovenia.com
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
transferslovenia.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/transferslovenia.com
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:31 UTC. Reporter: varysz. Tags: etherhiding, victim.
Remediations (10)
-
web:blog.sicuranext.com
EtherHiding: blockchain-based payload delivery Two seconds after the page loaded, the injected JavaScript initiated outbound queries to the BNB Smart Chain (BSC) Testnet. The BSC Testnet (Chain ID 97) is a free-to-use Ethereum Virtual Machine-compatible blockchain.
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.
-
web:reliaquest.com
"DeepLoad" malware has arrived in enterprise environments via "ClickFix" delivery, turning one user action into rapid, fileless compromise. It likely uses AI-assisted obfuscation and process injection to evade static scanning, while credential theft starts immediately and captures passwords and sessions even if the primary loader is ...
-
web:socradar.io
Multiple independent ClickFix social engineering campaigns observed between April and June 2026 are delivering three distinct malware loaders BabaDeda Loader , Lorem Ipsum Loader , and Potemkin that fetch information stealers, remote access trojans, and ransomware-linked tooling onto Windows hosts. Victims are lured into pasting attacker supplied commands into the Run dialog or terminal, after ...
-
web:thehackernews.com
ClickFix attacks are delivering BabaDeda, Lorem Ipsum, and Potemkin loaders to deploy stealers, RATs, and ransomware-linked tooling.
-
web:thehackernews.com
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login credentials.
-
web:undercodetesting.com
Introduction: Cybercriminals are increasingly abusing DNS TXT records to deliver malware and command-and-control (C2) payloads covertly. A recent investigation by DomainTools revealed how attackers fragment, hex-encode, and distribute malicious code across multiple DNS queries, evading traditional security measures.
-
web:urlhaus.abuse.ch
URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...
-
web:www.malwarebytes.com
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware .
-
web:www.rapid7.com
Rapid7 Labs has identified an ongoing, widespread compromise of legitimate WordPress websites, misused by an unidentified threat actor to inject a ClickFix implant (impersonating a Cloudflare human verification challenge [CAPTCHA]). The lure can be used for financial theft or to conduct further, more targeted attacks against organizations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.