s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1903643 high

📛 Threat Title

Unknown Stealer: URL that delivers a malware payload https://haziranaltyapi.com/welcome/

Category: Unknown Stealer Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Unknown Stealer. Confidence: 90. First seen: 2026-09-07 11:54:11 UTC. Reporter: Sir_XX. Tags: credit-card, phishing, planzer, switzerland.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

url https://haziranaltyapi.com/welcome/ VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly9oYXppcmFuYWx0eWFwaS5jb20vd2VsY29tZS8
UrlVoid 3 / 36

IOC database

Type
url
Value
https://haziranaltyapi.com/welcome/
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that delivers a malware payload attributed to Unknown Stealer

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly9oYXppcmFuYWx0eWFwaS5jb20vd2VsY29tZS8

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: URL that delivers a malware payload. Attributed malware: Unknown Stealer. Confidence: 90. First seen: 2026-09-07 11:54:11 UTC. Reporter: Sir_XX. Tags: credit-card, phishing, planzer, switzerland.

Remediations (10)

  • web:blog.virustotal.com

    Within the Payload Filessection, additional payloads are visible. These represent secondary stages dropped during the initial DLL execution, which act as the final malware samples. These final payloads are primarily identified as infostealers, designed to exfiltrate sensitive data.

  • web:cybersecuritynews.com

    ‼️ A threat actor is advertising a "ClickFix" payload delivery method that allegedly stores malware within browser cache to evade detection and bypass EDR, claiming it avoids suspicious web requests and executes via disguised commands in File Explorer.

  • web:gbhackers.com

    Payload delivery is highly modular, distributing malware via MSI installers, ZIP archives, and executable loaders. Observed payload mappings include libEGL.zip, which delivers a trojanized Electron-based Franz application with ResiLoader and StealC, Test.msiwhich deploys a Deno loader along with a PowerShell stealer , arworks.zipdelivering Amatera Stealer , water-night.zipdeploying Remus, and ...

  • web:radar.cloudflare.com

    Understand the security, performance, technology, and network details of a URL with a publicly shareable report.

  • web:thehackernews.com

    Researcher analyzed 3,000 ClickFix payloads and found rotating wrappers plus a Downloads-folder method built to bypass AMSI.

  • web:urlhaus.abuse.ch

    URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries.

  • web:www.eset.com

    Is this link really safe? Instantly check any URL for malware , phishing, fraud, or scams. Protect yourself from malicious websites with ESET's free, easy-to-use link checker tool.

  • web:www.malwarebytes.com

    We uncovered ClickFix attacks using fake Google and Cloudflare pages to deliver everything from infostealers to a newly discovered malware loader.

  • web:www.microsoft.com

    In the cybercriminal ecosystem, infostealer families like StealC and malware delivery services like Amadey are sold and rented as commodities. Stolen data flows through an underground economy of access brokers that feeds ransomware and other operations.

  • web:www.microsoft.com

    ACR Stealer is an information-stealing malware family reportedly offered through a malware - as -a-service (MaaS) model and associated with the rebranding of Amatera Stealer . During this period, two campaigns stand out, together appearing frequently in reviewed recent intrusions. Both begin the same way, with a ClickFix social engineering technique that tricks targets into running the threat ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.