TF-1903643
high
📛 Threat Title
Unknown Stealer: URL that delivers a malware payload https://haziranaltyapi.com/welcome/
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Unknown Stealer. Confidence: 90. First seen: 2026-09-07 11:54:11 UTC. Reporter: Sir_XX. Tags: credit-card, phishing, planzer, switzerland.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
https://haziranaltyapi.com/welcome/
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly9oYXppcmFuYWx0eWFwaS5jb20vd2VsY29tZS8
UrlVoid 3 / 36
IOC database
- Type
- url
- Value
https://haziranaltyapi.com/welcome/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that delivers a malware payload attributed to Unknown Stealer
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly9oYXppcmFuYWx0eWFwaS5jb20vd2VsY29tZS8
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Unknown Stealer. Confidence: 90. First seen: 2026-09-07 11:54:11 UTC. Reporter: Sir_XX. Tags: credit-card, phishing, planzer, switzerland.
Remediations (10)
-
web:blog.virustotal.com
Within the Payload Filessection, additional payloads are visible. These represent secondary stages dropped during the initial DLL execution, which act as the final malware samples. These final payloads are primarily identified as infostealers, designed to exfiltrate sensitive data.
-
web:cybersecuritynews.com
‼️ A threat actor is advertising a "ClickFix" payload delivery method that allegedly stores malware within browser cache to evade detection and bypass EDR, claiming it avoids suspicious web requests and executes via disguised commands in File Explorer.
-
web:gbhackers.com
Payload delivery is highly modular, distributing malware via MSI installers, ZIP archives, and executable loaders. Observed payload mappings include libEGL.zip, which delivers a trojanized Electron-based Franz application with ResiLoader and StealC, Test.msiwhich deploys a Deno loader along with a PowerShell stealer , arworks.zipdelivering Amatera Stealer , water-night.zipdeploying Remus, and ...
-
web:radar.cloudflare.com
Understand the security, performance, technology, and network details of a URL with a publicly shareable report.
-
web:thehackernews.com
Researcher analyzed 3,000 ClickFix payloads and found rotating wrappers plus a Downloads-folder method built to bypass AMSI.
-
web:urlhaus.abuse.ch
URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries.
-
web:www.eset.com
Is this link really safe? Instantly check any URL for malware , phishing, fraud, or scams. Protect yourself from malicious websites with ESET's free, easy-to-use link checker tool.
-
web:www.malwarebytes.com
We uncovered ClickFix attacks using fake Google and Cloudflare pages to deliver everything from infostealers to a newly discovered malware loader.
-
web:www.microsoft.com
In the cybercriminal ecosystem, infostealer families like StealC and malware delivery services like Amadey are sold and rented as commodities. Stolen data flows through an underground economy of access brokers that feeds ransomware and other operations.
-
web:www.microsoft.com
ACR Stealer is an information-stealing malware family reportedly offered through a malware - as -a-service (MaaS) model and associated with the rebranding of Amatera Stealer . During this period, two campaigns stand out, together appearing frequently in reviewed recent intrusions. Both begin the same way, with a ClickFix social engineering technique that tricks targets into running the threat ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.