TF-1933841
high
📛 Threat Title
Unknown Loader: Domain name that delivers a malware payload trebadaznas.com
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:31 UTC. Reporter: varysz. Tags: etherhiding, victim.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
trebadaznas.com
VT 4 / 91
UrlVoid 0 / 36
IOC database
- Type
- domain
- Value
trebadaznas.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| CRDF | malicious | malicious |
| Fortinet | malicious | malware |
| alphaMountain.ai | suspicious | suspicious |
| SOCRadar | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | Cloudflare, Inc. |
| TLD | com |
History
| Creation date | 2020-03-26 13:36 UTC |
| Last analysis | 2026-09-25 21:51 UTC |
| Last modified on VirusTotal | 2026-09-25 22:39 UTC |
| Last WHOIS update | 2026-05-16 17:32 UTC |
| WHOIS record date | 2026-09-12 03:53 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:31 UTC. Reporter: varysz. Tags: etherhiding, victim.
Remediations (10)
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.
-
web:davidgodwinpratt.com
Hunt Hypothesis This detection identifies adversary activity involving the execution of Unknown Loader components, which often serve as initial footholds for lateral movement and payload delivery within Azure environments. Proactive hunting is critical to uncover early-stage compromises that may evade standard signature-based defenses by correlating these specific IOCs with anomalous process ...
-
web:davidgodwinpratt.com
Hunt Hypothesis This hypothesis posits that adversaries are leveraging the Unknown Loader campaign to establish persistence by executing malicious payloads identified through seven specific Indicators of Compromise (IOCs). Proactive hunting for these IOCs in Azure Sentinel is critical because early detection of this loader's activity can prevent lateral movement and data exfiltration before ...
-
web:ismalicious.com
4,553 indicators of compromise attributed to the Unknown Loader malware family — domains , IPs, URLs and file hashes, from abuse.ch feeds.
-
web:rhisac.org
The malware provides operators with persistence, system reconnaissance, command execution, payload delivery, and resilient command and control capabilities. Key Takeaways DOUBLECUP is a Russian Loader - as -a-Service developed for ClickFix campaigns and has operated since early June 2026.
-
web:socprime.com
The initial malware communicated with a command-and-control server at 89.110.110.119 over TCP port 443 using encoded traffic. The campaign, tracked as SmartApeSG ClickFix, relied on malicious scripts and a CAB archive to install the NetSupport RAT on victim systems.
-
web:thehackernews.com
The payload is gated on machine identity The third finding is the one that should change how teams interpret their tooling. In the dropper recovered from the live host, a hardware and account fingerprint machine GUID, volume serial, computer name , BIOS manufacturer, system model, GPU and username is base64-encoded directly into the download path.
-
web:threatfox.abuse.ch
A malware sample can be associated with only one malware family. The page below gives you an overview on indicators of compromise associated with unknown_loader .
-
web:www.bleepingcomputer.com
The "third-party.com" domain , commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into ...
-
web:www.malwarebytes.com
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.