s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1812131 high

📛 Threat Title

FAKEUPDATES: Domain name that delivers a malware payload editions.seattlemysterylovers.com

Category: FAKEUPDATES Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: FAKEUPDATES (aliases: FakeUpdate,GhoLoader,SocGholish). Confidence: 75. First seen: 2026-05-14 10:23:31 UTC. Reporter: varysz. Tags: SocGholish.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 190.211.254.31 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/190.211.254.31

IOC database

Type
ipv4
Value
190.211.254.31
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain editions.seattlemysterylovers.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/190.211.254.31

domain editions.seattlemysterylovers.com UrlVoid 4 / 35

IOC database

Type
domain
Value
editions.seattlemysterylovers.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain name that delivers a malware payload attributed to FAKEUPDATES

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: FAKEUPDATES (aliases: FakeUpdate,GhoLoader,SocGholish). Confidence: 75. First seen: 2026-05-14 10:23:31 UTC. Reporter: varysz. Tags: SocGholish.

Remediations (10)

  • web:blog.checkpoint.com

    April 2025 saw a sharp rise in stealthy, multi-stage attacks leveraging commodity malware like AgentTesla and Remcos within advanced delivery chains. FakeUpdates led global infections, while mobile Trojans such as Anubis and AhMyth expanded their capabilities.

  • web:blog.sucuri.net

    Learn about SocGholish malware - AKA Fake Updates. We examine domain shadowing techniques, injections, domains and IPs used in SocGholish infections.

  • web:cyberflorida.org

    SocGholish, also known as " FakeUpdates ," has emerged as the leading malware in Q3 2024. This malware has been active since 2018 and operates as a JavaScript-based downloader that exploits drive-by-download techniques to gain initial access.

  • web:cybersecsentinel.com

    The SocGholish, or " FakeUpdate ," malware is a sophisticated and pervasive threat designed to infiltrate systems through seemingly legitimate update alerts. Delivered via compromised websites, this malware lures users into downloading malicious files disguised as updates for web browsers like Chrome and Firefox.

  • web:malpedia.caad.fkie.fraunhofer.de

    FAKEUPDATES is a downloader written in JavaScript that communicates via HTTP. Supported payload types include executables and JavaScript. It writes the payloads to disk prior to launching them. FAKEUPDATES has led to further compromise via additional malware families that include CHTHONIC, DRIDEX, EMPIRE, KOADIC, DOPPELPAYMER, and AZORULT.

  • web:security.googlecloudcommunity.com

    About the Finding Malware Series The "Finding Malware " blog series from Managed Defense is designed to empower the Google Security Operations (SecOps) community to detect emerging and persistent malware threats. This post dive into Fake Browser Update Attacks, the payloads they deliver , and detectio...

  • web:threatfox.abuse.ch

    FAKEUPDATES IOC: editions.seattlemysterylovers.com ( domain ) You are viewing the ThreatFox database entry for domain editions.seattlemysterylovers.com .

  • web:threats.wiz.io

    FAKEUPDATES , also known as SocGholish, is a JavaScript-based downloader malware that masquerades as legitimate software updates. It employs social engineering tactics, presenting users with fake browser or software update prompts on compromised websites. When users download and execute the purported update, the malware establishes a connection to its command-and-control server, facilitating ...

  • web:www.levelblue.com

    This blog is the latest in a series that delves into the deep research conducted daily by the Trustwave SpiderLabs Threat Operations team on major threat actor groups and malware currently operating globally. Operating as a Malware - as -a-Service (MaaS) SocGholish, also known as FakeUpdates , has been in service since 2017.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…