TF-1811926
high
📛 Threat Title
Unknown Webinject: Domain name that delivers a malware payload babybon.cfd
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Webinject. Confidence: 100. First seen: 2026-05-13 18:45:33 UTC. Reporter: Gi7w0rm. Tags: ErrTraffic.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
104.21.91.60
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.91.60
IOC database
- Type
- ipv4
- Value
104.21.91.60- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain babybon.cfd
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.91.60
ipv4
172.67.167.123
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.167.123
IOC database
- Type
- ipv4
- Value
172.67.167.123- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain babybon.cfd
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.167.123
domain
babybon.cfd
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
babybon.cfd- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- Domain name that delivers a malware payload attributed to Unknown Webinject
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Webinject. Confidence: 100. First seen: 2026-05-13 18:45:33 UTC. Reporter: Gi7w0rm. Tags: ErrTraffic.
Remediations (10)
-
web:cyberpedia.reasonlabs.com
It could prevent the initial download and installation of the malicious payload responsible for such incursions. regular updates to the antivirus signatures can effectively counter new variants of the malware that continue to emerge regularly. Another effective means is proper employee education and routine software updates.
-
web:malwarediscoverer.com
High-quality, real-time URL redirection threat intelligence Our technology continuously discovers malicious redirection campaigns. Whether you are a security company, domain name registrar, or advertising platform, our intelligence will enhance your product.
-
web:precisionsec.com
PrecisionSec's Malware Domain List is a high fidelity feed of domains actively being used by malware . Our feed is used by experts globally to identify and block malicious domains known to be associated with malware . Whether you are a data reseller, MSSP, or Security Manager, having an accurate and up-to-date list of active malware domains is essential to protecting your internal assets and ...
-
web:sitecheck.sucuri.net
Free website malware and security checker Enter a URL like example.com and the Sucuri SiteCheck scanner will check the website for known malware , viruses, blacklisting status, website errors, out-of-date software, and malicious code.
-
web:threatfox.abuse.ch
A malware sample can be associated with only one malware family. The page below gives you an overview on indicators of compromise associated with unknown_webinject .
-
web:www.cyberly.org
While the term " malware " refers to any software designed to perform malicious activities, a malware payload is the component that actually executes the attack or damage. Understanding what a malware payload is and how it works is crucial for recognising, preventing, and mitigating the effects of malware attacks.
-
web:www.fortra.com
The delivery stage is the third phase of the cyber kill chain, whereby attackers transmit the weaponized payload to the target environment. It marks the transition from preparation to active engagement with the target.
-
web:www.illumio.com
Understanding malware beacons and knowing how to block them can help keep your organization safer. A beacon, also known as a payload , is an executable or program that communicates back to a cyberattacker via some communication channel. From the threat actor's point of view, beacon management is the foundation for their malicious campaign.
-
web:www.ipqualityscore.com
Scan URLs for malware and phishing with our free malicious URL scanner. Check links in real-time to detect suspicious domains and prevent cyber threats.
-
web:www.malwarebytes.com
Malwarebytes uses the detection name "Exploit" for a category of malware that uses known exploits to deliver their payloads .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.