TF-1811927
high
📛 Threat Title
IClickFix: Domain name that delivers a malware payload 2026123.xyz
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: IClickFix. Confidence: 75. First seen: 2026-05-13 18:54:35 UTC. Reporter: varysz. Tags: ClickFix, Vidar.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
188.114.96.3
VT 0 / 92
IOC database
- Type
- ipv4
- Value
188.114.96.3- First seen
- Last seen
- Attached to this threat
- Appears in
- 105 threats
- Description
- Resolved from domain xingshang734.xyz
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Network | 188.114.96.0/22 |
| AS owner | Cloudflare, Inc. |
| ASN | 13335 |
History
| Last analysis | 2026-05-16 04:56 UTC |
| Last modified on VirusTotal | 2026-05-16 04:57 UTC |
| WHOIS record date | 2026-05-07 15:07 UTC |
ipv4
188.114.97.3
VT 8 / 92
IOC database
- Type
- ipv4
- Value
188.114.97.3- First seen
- Last seen
- Attached to this threat
- Appears in
- 105 threats
- Description
- Resolved from domain xingshang734.xyz
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 8 of 92 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| Chong Lua Dao | malicious | malicious |
| CyRadar | malicious | malicious |
| Lionic | malicious | malicious |
| Viettel Threat Intelligence | malicious | malicious |
| VIPRE | malicious | malware |
| Webroot | malicious | malicious |
| alphaMountain.ai | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 188.114.96.0/22 |
| AS owner | Cloudflare, Inc. |
| ASN | 13335 |
History
| Last analysis | 2026-05-16 04:44 UTC |
| Last modified on VirusTotal | 2026-05-16 04:46 UTC |
| WHOIS record date | 2026-05-07 01:55 UTC |
domain
2026123.xyz
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/2026123.xyz
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
2026123.xyz- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain name that delivers a malware payload attributed to IClickFix
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/2026123.xyz
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: IClickFix. Confidence: 75. First seen: 2026-05-13 18:54:35 UTC. Reporter: varysz. Tags: ClickFix, Vidar.
Remediations (10)
-
web:blog.sekoia.io
Uncover IClickFix : a malicious framework exploiting the ClickFix tactic in widespread malware campaigns to deliver NetSupport RAT.
-
web:cybersecuritynews.com
A threat actor is advertising a "ClickFix" payload delivery method that allegedly stores malware within browser cache to evade detection and bypass EDR, claiming it avoids suspicious web requests and executes via disguised commands in File Explorer.
-
web:threatfox.abuse.ch
IClickFix IOC: 2026123.xyz ( domain ) You are viewing the ThreatFox database entry for domain 2026123.xyz .
-
web:www.bleepingcomputer.com
Threat actors are now abusing DNS queries as part of ClickFix social engineering attacks to deliver malware , making this the first known use of DNS as a channel in these campaigns.
-
web:www.malwarebytes.com
ClickFix just got more convincing, hiding malware in PNG images and faking Windows updates to make users run dangerous commands.
-
web:www.microsoft.com
The ClickFix social engineering technique has been growing in popularity, with campaigns targeting thousands of enterprise and end-user devices daily. This technique exploits users' tendency to resolve technical issues by tricking them into running malicious commands. These commands, in turn, deliver payloads that ultimately lead to information theft and exfiltration.
-
web:www.securityweek.com
Microsoft has warned users that threat actors are leveraging a new variant of the ClickFix technique to deliver malware .
-
web:www.sentinelone.com
Learn about the latest ClickFix tactics compromising websites and embedding fraudulent CAPTCHA images to deliver malware and malicious code.
-
web:www.seraphsecure.com
As if that isn't already bad enough, sometimes it comes bundled with additional malware , things we promise you don't want on your device. After the malicious command is run, infostealer malware downloads and installs silently and begins collecting passwords, session cookies, and other sensitive data.
-
web:zerodai.com
Microsoft warns of a new ClickFix attack using nslookup for DNS-based malware delivery. Learn how to detect and mitigate this stealthy threat.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.