s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1812254 high

📛 Threat Title

Unknown malware: Domain name that delivers a malware payload vanta.st

Category: Unknown malware Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-05-14 18:08:36 UTC. Reporter: burger.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 172.66.44.138

IOC database

Type
ipv4
Value
172.66.44.138
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url https://vanta.st/file123

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 172.66.47.118

IOC database

Type
ipv4
Value
172.66.47.118
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url https://vanta.st/file123

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 64.89.161.63 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/64.89.161.63
1 feed

IOC database

Type
ipv4
Value
64.89.161.63
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Imported from threat-intel feed: Ipsum

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Ipsum. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/64.89.161.63

domain vanta.st UrlVoid 4 / 35

IOC database

Type
domain
Value
vanta.st
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain name that delivers a malware payload attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference Threatfox IOCs/Threats
  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-05-14 18:08:36 UTC. Reporter: burger.

Remediations (10)

  • web:app.any.run

    Join ANY.RUN and check malware for free. With our online malware analysis tools you can research malicious files and URLs and get result with incredible speed

  • web:efficientip.com

    A previously unknown malware campaign was uncovered through EfficientIP's real-time DNS Threat Intelligence. By exploiting DNS TXT records for stealthy command-and-control and data exfiltration, it bypassed traditional defenses—until DNS Security stopped it.

  • web:learn.microsoft.com

    When you look up this malware name in the Microsoft Defender Security Intelligence website, you find information specific to that malware , including technical details and mitigation steps.

  • web:precisionsec.com

    PrecisionSec's Malware Domain List is a high fidelity feed of domains actively being used by malware . Our feed is used by experts globally to identify and block malicious domains known to be associated with malware . Whether you are a data reseller, MSSP, or Security Manager, having an accurate and up-to-date list of active malware domains is essential to protecting your internal assets and ...

  • web:threatfox.abuse.ch

    Database Entry Actions Add tag Delete this IOC Report False Positive Export IOC (JSON) Export IOC (CSV)

  • web:urlhaus.abuse.ch

    URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...

  • web:www.ipqualityscore.com

    Scan URLs for malware and phishing with our free malicious URL scanner. Check links in real-time to detect suspicious domains and prevent cyber threats.

  • web:www.ncsc.gov.ie

    CSIRT-IE monitors the URLhaus dataset for reports of sites, within its jurisdiction, that are reported to be actively distributing malware . Active Malware Distribution Sites The URLhaus platform only report sites (URLs) that are directly being used to distribute malware .

  • web:www.virustotal.com

    VirusTotal Assistant Bot offers a platform for users to interact with VirusTotal's threat intelligence suite and explore artifact-related information effectively.

  • web:www.virustotal.com

    VirusTotal is a free online tool that analyzes files and URLs for viruses, worms, trojans, and other kinds of malicious content.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…