s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1811926 high

📛 Threat Title

Unknown Webinject: Domain name that delivers a malware payload babybon.cfd

Category: Unknown Webinject Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Webinject. Confidence: 100. First seen: 2026-05-13 18:45:33 UTC. Reporter: Gi7w0rm. Tags: ErrTraffic.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 104.21.91.60 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.91.60

IOC database

Type
ipv4
Value
104.21.91.60
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain babybon.cfd

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.91.60

ipv4 172.67.167.123 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.167.123

IOC database

Type
ipv4
Value
172.67.167.123
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain babybon.cfd

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.167.123

domain babybon.cfd UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
babybon.cfd
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
Domain name that delivers a malware payload attributed to Unknown Webinject

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Webinject. Confidence: 100. First seen: 2026-05-13 18:45:33 UTC. Reporter: Gi7w0rm. Tags: ErrTraffic.

Remediations (10)

  • web:cyberpedia.reasonlabs.com

    It could prevent the initial download and installation of the malicious payload responsible for such incursions. regular updates to the antivirus signatures can effectively counter new variants of the malware that continue to emerge regularly. Another effective means is proper employee education and routine software updates.

  • web:malwarediscoverer.com

    High-quality, real-time URL redirection threat intelligence Our technology continuously discovers malicious redirection campaigns. Whether you are a security company, domain name registrar, or advertising platform, our intelligence will enhance your product.

  • web:precisionsec.com

    PrecisionSec's Malware Domain List is a high fidelity feed of domains actively being used by malware . Our feed is used by experts globally to identify and block malicious domains known to be associated with malware . Whether you are a data reseller, MSSP, or Security Manager, having an accurate and up-to-date list of active malware domains is essential to protecting your internal assets and ...

  • web:sitecheck.sucuri.net

    Free website malware and security checker Enter a URL like example.com and the Sucuri SiteCheck scanner will check the website for known malware , viruses, blacklisting status, website errors, out-of-date software, and malicious code.

  • web:threatfox.abuse.ch

    A malware sample can be associated with only one malware family. The page below gives you an overview on indicators of compromise associated with unknown_webinject .

  • web:www.cyberly.org

    While the term " malware " refers to any software designed to perform malicious activities, a malware payload is the component that actually executes the attack or damage. Understanding what a malware payload is and how it works is crucial for recognising, preventing, and mitigating the effects of malware attacks.

  • web:www.fortra.com

    The delivery stage is the third phase of the cyber kill chain, whereby attackers transmit the weaponized payload to the target environment. It marks the transition from preparation to active engagement with the target.

  • web:www.illumio.com

    Understanding malware beacons and knowing how to block them can help keep your organization safer. A beacon, also known as a payload , is an executable or program that communicates back to a cyberattacker via some communication channel. From the threat actor's point of view, beacon management is the foundation for their malicious campaign.

  • web:www.ipqualityscore.com

    Scan URLs for malware and phishing with our free malicious URL scanner. Check links in real-time to detect suspicious domains and prevent cyber threats.

  • web:www.malwarebytes.com

    Malwarebytes uses the detection name "Exploit" for a category of malware that uses known exploits to deliver their payloads .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…