TF-1933788
high
📛 Threat Title
Unknown Loader: Domain name that delivers a malware payload sulsonintl.com
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:25 UTC. Reporter: varysz. Tags: etherhiding, victim.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
sulsonintl.com
VT 4 / 91
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
sulsonintl.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| CRDF | malicious | malicious |
| Kaspersky | malicious | phishing |
| Gridinsoft | suspicious | suspicious |
| SOCRadar | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | Hosting Concepts B.V. d/b/a Registrar.eu |
| TLD | com |
History
| Creation date | 2009-04-14 10:55 UTC |
| Last analysis | 2026-09-18 18:05 UTC |
| Last modified on VirusTotal | 2026-09-25 23:59 UTC |
| Last WHOIS update | 2026-04-30 15:30 UTC |
| WHOIS record date | 2026-09-18 18:39 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:25 UTC. Reporter: varysz. Tags: etherhiding, victim.
Remediations (10)
-
web:blog.sicuranext.com
EtherHiding: blockchain-based payload delivery Two seconds after the page loaded, the injected JavaScript initiated outbound queries to the BNB Smart Chain (BSC) Testnet. The BSC Testnet (Chain ID 97) is a free-to-use Ethereum Virtual Machine-compatible blockchain.
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.
-
web:reliaquest.com
"DeepLoad" malware has arrived in enterprise environments via "ClickFix" delivery, turning one user action into rapid, fileless compromise. It likely uses AI-assisted obfuscation and process injection to evade static scanning, while credential theft starts immediately and captures passwords and sessions even if the primary loader is ...
-
web:thehackernews.com
Microsoft details a new ClickFix variant abusing DNS nslookup commands to stage malware , enabling stealthy payload delivery and RAT deployment.
-
web:thehackernews.com
ClickFix attacks are delivering BabaDeda, Lorem Ipsum, and Potemkin loaders to deploy stealers, RATs, and ransomware-linked tooling.
-
web:www.csoonline.com
The WordPress ClickFix campaign delivers three separate infostealer payloads — two of them previously unknown — and uses domain infrastructure that appears to have been set up since July 2025.
-
web:www.malwarebytes.com
We uncovered ClickFix attacks using fake Google and Cloudflare pages to deliver everything from infostealers to a newly discovered malware loader .
-
web:www.microsoft.com
Threat actors are targeting macOS users with fake utility fixes that trick them into running malicious Terminal commands. This campaign evades traditional defenses by stealing credentials, wallets, and sensitive data.
-
web:www.microsoft.com
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat.
-
web:www.rapid7.com
Rapid7 Labs has identified an ongoing, widespread compromise of legitimate WordPress websites, misused by an unidentified threat actor to inject a ClickFix implant (impersonating a Cloudflare human verification challenge [CAPTCHA]). The lure can be used for financial theft or to conduct further, more targeted attacks against organizations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.