TF-1812254
high
📛 Threat Title
Unknown malware: Domain name that delivers a malware payload vanta.st
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-05-14 18:08:36 UTC. Reporter: burger.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
172.66.44.138
IOC database
- Type
- ipv4
- Value
172.66.44.138- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url https://vanta.st/file123
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
172.66.47.118
IOC database
- Type
- ipv4
- Value
172.66.47.118- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url https://vanta.st/file123
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
64.89.161.63
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/64.89.161.63
1 feed
IOC database
- Type
- ipv4
- Value
64.89.161.63- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Imported from threat-intel feed: Ipsum
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Ipsum. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/64.89.161.63
domain
vanta.st
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
vanta.st- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain name that delivers a malware payload attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference Threatfox IOCs/Threats
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-05-14 18:08:36 UTC. Reporter: burger.
Remediations (10)
-
web:app.any.run
Join ANY.RUN and check malware for free. With our online malware analysis tools you can research malicious files and URLs and get result with incredible speed
-
web:efficientip.com
A previously unknown malware campaign was uncovered through EfficientIP's real-time DNS Threat Intelligence. By exploiting DNS TXT records for stealthy command-and-control and data exfiltration, it bypassed traditional defenses—until DNS Security stopped it.
-
web:learn.microsoft.com
When you look up this malware name in the Microsoft Defender Security Intelligence website, you find information specific to that malware , including technical details and mitigation steps.
-
web:precisionsec.com
PrecisionSec's Malware Domain List is a high fidelity feed of domains actively being used by malware . Our feed is used by experts globally to identify and block malicious domains known to be associated with malware . Whether you are a data reseller, MSSP, or Security Manager, having an accurate and up-to-date list of active malware domains is essential to protecting your internal assets and ...
-
web:threatfox.abuse.ch
Database Entry Actions Add tag Delete this IOC Report False Positive Export IOC (JSON) Export IOC (CSV)
-
web:urlhaus.abuse.ch
URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...
-
web:www.ipqualityscore.com
Scan URLs for malware and phishing with our free malicious URL scanner. Check links in real-time to detect suspicious domains and prevent cyber threats.
-
web:www.ncsc.gov.ie
CSIRT-IE monitors the URLhaus dataset for reports of sites, within its jurisdiction, that are reported to be actively distributing malware . Active Malware Distribution Sites The URLhaus platform only report sites (URLs) that are directly being used to distribute malware .
-
web:www.virustotal.com
VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.
-
web:www.virustotal.com
VirusTotal is a free online tool that analyzes files and URLs for viruses, worms, trojans, and other kinds of malicious content.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.