TF-1932680
high
📛 Threat Title
IClickFix: Domain name that delivers a malware payload cup.blinqueofficial.com
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: IClickFix. Confidence: 100. First seen: 2026-09-25 05:14:10 UTC. Reporter: threatcat_ch. Tags: ClickFix.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
cup.blinqueofficial.com
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
cup.blinqueofficial.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Domain that is used for botnet Command&control (C&C) attributed to ClearFake
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: IClickFix. Confidence: 100. First seen: 2026-09-25 05:14:10 UTC. Reporter: threatcat_ch. Tags: ClickFix.
Remediations (10)
-
web:blog.sicuranext.com
EtherHiding: blockchain-based payload delivery Two seconds after the page loaded, the injected JavaScript initiated outbound queries to the BNB Smart Chain (BSC) Testnet. The BSC Testnet (Chain ID 97) is a free-to-use Ethereum Virtual Machine-compatible blockchain.
-
web:ismalicious.com
7,609 indicators of compromise attributed to the IClickFix malware family — domains , IPs, URLs and file hashes, from abuse.ch feeds.
-
web:thehackernews.com
Microsoft details a new ClickFix variant abusing DNS nslookup commands to stage malware , enabling stealthy payload delivery and RAT deployment.
-
web:thehackernews.com
ClickFix accounted for 47% of Microsoft Defender Experts initial-access cases in 2025, while a Polygon contract rotated lure hosts.
-
web:www.doppel.com
ClickFix scams turn fake CAPTCHAs and browser errors into malware delivery. Learn how the attack works, what to watch for, and how to respond.
-
web:www.group-ib.com
Learn how the ClickFix attack works, how ClickFix malware spreads through social engineering, common scam techniques, and how to protect your organization.
-
web:www.malwarebytes.com
At the time of writing the domain hosting the script is not resolving. ClickFix is a social-engineering technique that turns the victim into the malware installer.
-
web:www.microsoft.com
The ClickFix social engineering technique has been growing in popularity, with campaigns targeting thousands of enterprise and end-user devices daily. This technique exploits users' tendency to resolve technical issues by tricking them into running malicious commands. These commands, in turn, deliver payloads that ultimately lead to information theft and exfiltration.
-
web:www.proofpoint.com
Learn how the threat of ClickFix malware is spreading through social engineering. Find out how to protect yourself from these attacks with Proofpoint.
-
web:www.seqrite.com
Introduction With the evolution of cyber threats, the final execution of a malicious payload is no longer the sole focus of the cybersecurity industry. Attack loaders have emerged as a critical element of modern attacks, serving as a primary vector for initial access and enabling the covert delivery of sophisticated malware within an organization.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.