TF-1812131
high
📛 Threat Title
FAKEUPDATES: Domain name that delivers a malware payload editions.seattlemysterylovers.com
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: FAKEUPDATES (aliases: FakeUpdate,GhoLoader,SocGholish). Confidence: 75. First seen: 2026-05-14 10:23:31 UTC. Reporter: varysz. Tags: SocGholish.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
190.211.254.31
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/190.211.254.31
IOC database
- Type
- ipv4
- Value
190.211.254.31- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain editions.seattlemysterylovers.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/190.211.254.31
domain
editions.seattlemysterylovers.com
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
editions.seattlemysterylovers.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain name that delivers a malware payload attributed to FAKEUPDATES
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: FAKEUPDATES (aliases: FakeUpdate,GhoLoader,SocGholish). Confidence: 75. First seen: 2026-05-14 10:23:31 UTC. Reporter: varysz. Tags: SocGholish.
Remediations (10)
-
web:blog.checkpoint.com
April 2025 saw a sharp rise in stealthy, multi-stage attacks leveraging commodity malware like AgentTesla and Remcos within advanced delivery chains. FakeUpdates led global infections, while mobile Trojans such as Anubis and AhMyth expanded their capabilities.
-
web:blog.sucuri.net
Learn about SocGholish malware - AKA Fake Updates. We examine domain shadowing techniques, injections, domains and IPs used in SocGholish infections.
-
web:cyberflorida.org
SocGholish, also known as " FakeUpdates ," has emerged as the leading malware in Q3 2024. This malware has been active since 2018 and operates as a JavaScript-based downloader that exploits drive-by-download techniques to gain initial access.
-
web:cybersecsentinel.com
The SocGholish, or " FakeUpdate ," malware is a sophisticated and pervasive threat designed to infiltrate systems through seemingly legitimate update alerts. Delivered via compromised websites, this malware lures users into downloading malicious files disguised as updates for web browsers like Chrome and Firefox.
-
web:malpedia.caad.fkie.fraunhofer.de
FAKEUPDATES is a downloader written in JavaScript that communicates via HTTP. Supported payload types include executables and JavaScript. It writes the payloads to disk prior to launching them. FAKEUPDATES has led to further compromise via additional malware families that include CHTHONIC, DRIDEX, EMPIRE, KOADIC, DOPPELPAYMER, and AZORULT.
-
web:security.googlecloudcommunity.com
About the Finding Malware Series The "Finding Malware " blog series from Managed Defense is designed to empower the Google Security Operations (SecOps) community to detect emerging and persistent malware threats. This post dive into Fake Browser Update Attacks, the payloads they deliver , and detectio...
-
web:threatfox.abuse.ch
FAKEUPDATES IOC: editions.seattlemysterylovers.com ( domain ) You are viewing the ThreatFox database entry for domain editions.seattlemysterylovers.com .
-
web:threats.wiz.io
FAKEUPDATES , also known as SocGholish, is a JavaScript-based downloader malware that masquerades as legitimate software updates. It employs social engineering tactics, presenting users with fake browser or software update prompts on compromised websites. When users download and execute the purported update, the malware establishes a connection to its command-and-control server, facilitating ...
-
web:www.levelblue.com
This blog is the latest in a series that delves into the deep research conducted daily by the Trustwave SpiderLabs Threat Operations team on major threat actor groups and malware currently operating globally. Operating as a Malware - as -a-Service (MaaS) SocGholish, also known as FakeUpdates , has been in service since 2017.
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.