OTX-65b2ce156fed993ea0af32b3
high
📛 Threat Title
DarkGate - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to DarkGate Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 92 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (116)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
34.41.139.193
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/34.41.139.193
IOC database
- Type
- ipv4
- Value
34.41.139.193- First seen
- Last seen
- Attached to this threat
- Appears in
- 21 threats
- Description
- Resolved from domain xjp.cyberspeed.baby
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/34.41.139.193
ipv4
43.247.166.196
VT 1 / 91
IOC database
- Type
- ipv4
- Value
43.247.166.196- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain zochao.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 1 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| alphaMountain.ai | malicious | malicious |
Details From VirusTotal
Basic Properties
| Network | 43.247.164.0/22 |
| Country | HK |
| AS owner | Forewin Telecom Group Limited, ISP at HK |
| ASN | 38186 |
| Regional registry | APNIC |
History
| Last analysis | 2026-08-02 11:18 UTC |
| Last modified on VirusTotal | 2026-08-02 11:27 UTC |
| WHOIS record date | 2026-08-02 11:22 UTC |
ipv4
94.103.2.203
IOC database
- Type
- ipv4
- Value
94.103.2.203- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
lili19mainmasters.com
UrlVoid 5 / 35
1 feed
IOC database
- Type
- domain
- Value
lili19mainmasters.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Imported from threat-intel feed: threatview.io
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
newdomainfortesteenestle.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
newdomainfortesteenestle.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Imported from threat-intel feed: threatview.io
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
strongdomainsercgerhhost.com
UrlVoid 5 / 35
1 feed
IOC database
- Type
- domain
- Value
strongdomainsercgerhhost.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Imported from threat-intel feed: threatview.io
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
prestige-castom.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
prestige-castom.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Imported from threat-intel feed: threatview.io
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
62.233.57.80
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/62.233.57.80
IOC database
- Type
- ipv4
- Value
62.233.57.80- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain 44-35-63-31.internalsakamai.net
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/62.233.57.80
ipv4
179.60.149.194
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/179.60.149.194
IOC database
- Type
- ipv4
- Value
179.60.149.194- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url http://179.60.149.194:8080/vxhxrqnb
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/179.60.149.194
ipv4
91.243.50.68
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/91.243.50.68
IOC database
- Type
- ipv4
- Value
91.243.50.68- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url http://91.243.50.68:8080/eqvukhda
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/91.243.50.68
ipv4
154.214.85.53
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/154.214.85.53
IOC database
- Type
- ipv4
- Value
154.214.85.53- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain languangjob.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/154.214.85.53
ipv4
104.152.168.10
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.152.168.10
IOC database
- Type
- ipv4
- Value
104.152.168.10- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url http://savoystocks.com/yrorantd
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.152.168.10
ipv4
172.67.164.57
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.164.57
IOC database
- Type
- ipv4
- Value
172.67.164.57- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain flexiblemaria.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.164.57
ipv4
104.21.15.206
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.15.206
IOC database
- Type
- ipv4
- Value
104.21.15.206- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain flexiblemaria.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.15.206
ipv4
209.204.175.65
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/209.204.175.65
IOC database
- Type
- ipv4
- Value
209.204.175.65- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url http://smbeckwithlaw.com/1.zip
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/209.204.175.65
ipv4
45.154.98.21
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/45.154.98.21
IOC database
- Type
- ipv4
- Value
45.154.98.21- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url http://45.154.98.21/iopsmxt.a3x
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/45.154.98.21
ipv4
194.26.192.57
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/194.26.192.57
IOC database
- Type
- ipv4
- Value
194.26.192.57- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url http://194.26.192.57/r-ops/test.txt
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/194.26.192.57
ipv4
104.201.29.84
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.201.29.84
IOC database
- Type
- ipv4
- Value
104.201.29.84- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain 31yc.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.201.29.84
ipv4
45.89.53.187
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/45.89.53.187
IOC database
- Type
- ipv4
- Value
45.89.53.187- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url http://45.89.53.187/s/ms_excel_azure_cloud_open_document.vbs
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/45.89.53.187
ipv4
206.188.196.222
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/206.188.196.222
IOC database
- Type
- ipv4
- Value
206.188.196.222- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url http://206.188.196.222/ex.zip
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/206.188.196.222
ipv4
145.239.202.110
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/145.239.202.110
IOC database
- Type
- ipv4
- Value
145.239.202.110- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url http://145.239.202.110:81/dark.vbs
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/145.239.202.110
ipv4
149.56.252.31
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/149.56.252.31
IOC database
- Type
- ipv4
- Value
149.56.252.31- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url http://149.56.252.31:8094/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/149.56.252.31
ipv4
192.254.228.189
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/192.254.228.189
IOC database
- Type
- ipv4
- Value
192.254.228.189- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url https://grpt.ca/js/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/192.254.228.189
ipv4
95.164.63.54
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/95.164.63.54
IOC database
- Type
- ipv4
- Value
95.164.63.54- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url http://95.164.63.54/documents/build-x64.zip
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/95.164.63.54
ipv4
147.135.84.14
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/147.135.84.14
IOC database
- Type
- ipv4
- Value
147.135.84.14- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- Resolved from domain zephalon.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/147.135.84.14
ipv4
8.218.118.157
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/8.218.118.157
IOC database
- Type
- ipv4
- Value
8.218.118.157- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain zochao.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/8.218.118.157
ipv4
76.223.54.146
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/76.223.54.146
IOC database
- Type
- ipv4
- Value
76.223.54.146- First seen
- Last seen
- Attached to this threat
- Appears in
- 27 threats
- Description
- Resolved from domain xinglou001.xyz
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/76.223.54.146
ipv4
13.248.169.48
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/13.248.169.48
IOC database
- Type
- ipv4
- Value
13.248.169.48- First seen
- Last seen
- Attached to this threat
- Appears in
- 27 threats
- Description
- Resolved from domain xinglou001.xyz
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/13.248.169.48
url
http://remasterprodelherskjs.com:80
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://remasterprodelherskjs.com:80- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://cayennesxque.boo:80
UrlVoid 3 / 35
IOC database
- Type
- url
- Value
http://cayennesxque.boo:80- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://porsherses.com:80
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://porsherses.com:80- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://149.56.252.31:8094/
IOC database
- Type
- url
- Value
http://149.56.252.31:8094/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://149.56.252.31/dark.vbs
IOC database
- Type
- url
- Value
http://149.56.252.31/dark.vbs- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://145.239.202.110:81/dark.vbs
IOC database
- Type
- url
- Value
http://145.239.202.110:81/dark.vbs- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://206.188.196.222/ex.zip
IOC database
- Type
- url
- Value
http://206.188.196.222/ex.zip- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
nextroundst.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
nextroundst.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
diveupdown.com
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
diveupdown.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
buassinnndm.net
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
buassinnndm.net- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
badbutperfect.com
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
badbutperfect.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
goingupdate.com
UrlVoid 2 / 35
1 feed
IOC database
- Type
- domain
- Value
goingupdate.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://backupitfirst.com/wgfqneerod
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://backupitfirst.com/wgfqneerod- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://withupdate.com/oudowibspr
UrlVoid 5 / 35
IOC database
- Type
- url
- Value
http://withupdate.com/oudowibspr- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
backupitfirst.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
backupitfirst.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
withupdate.com
UrlVoid 5 / 35
1 feed
IOC database
- Type
- domain
- Value
withupdate.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
madeyourbackup.com
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
madeyourbackup.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
31yc.com
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
31yc.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
irreceiver.com
UrlVoid 3 / 35
IOC database
- Type
- domain
- Value
irreceiver.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://45.89.53.187/s/ms_excel_azure_cloud_open_document.vbs
IOC database
- Type
- url
- Value
http://45.89.53.187/s/ms_excel_azure_cloud_open_document.vbs- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
wassonite.com
UrlVoid 5 / 35
1 feed
IOC database
- Type
- domain
- Value
wassonite.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
https://linktoxic34.com/wp-content/themes/twentytwentytwo/dark.hta
UrlVoid 5 / 35
IOC database
- Type
- url
- Value
https://linktoxic34.com/wp-content/themes/twentytwentytwo/dark.hta- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
dogmupdate.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
dogmupdate.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://194.26.192.57/r-ops/test.txt
IOC database
- Type
- url
- Value
http://194.26.192.57/r-ops/test.txt- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://45.154.98.21/iopsmxt.a3x
IOC database
- Type
- url
- Value
http://45.154.98.21/iopsmxt.a3x- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://194.26.192.57/r-ops/ncvui.exe
IOC database
- Type
- url
- Value
http://194.26.192.57/r-ops/ncvui.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://45.154.98.21/pqkizk.exe
IOC database
- Type
- url
- Value
http://45.154.98.21/pqkizk.exe- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://194.26.192.57/r-ops/yreuit.a3x
IOC database
- Type
- url
- Value
http://194.26.192.57/r-ops/yreuit.a3x- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://45.154.98.21/test.txt
IOC database
- Type
- url
- Value
http://45.154.98.21/test.txt- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
updateleft.com
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
updateleft.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
findyourbackups.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
findyourbackups.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
https://smbeckwithlaw.com/1.zip
UrlVoid 2 / 35
IOC database
- Type
- url
- Value
https://smbeckwithlaw.com/1.zip- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
kindupdates.com
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
kindupdates.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://smbeckwithlaw.com/1.zip
UrlVoid 2 / 35
IOC database
- Type
- url
- Value
http://smbeckwithlaw.com/1.zip- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
flexiblemaria.com
UrlVoid 5 / 35
IOC database
- Type
- domain
- Value
flexiblemaria.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://savoystocks.com/yrorantd
UrlVoid 3 / 35
IOC database
- Type
- url
- Value
http://savoystocks.com/yrorantd- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://savoystocks.com/awybcwjc
UrlVoid 3 / 35
IOC database
- Type
- url
- Value
http://savoystocks.com/awybcwjc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
savoystocks.com
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
savoystocks.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
voip.analytics-edges.com
VT 14 / 91
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
voip.analytics-edges.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Flagged by 14 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| BitDefender | malicious | phishing |
| Chong Lua Dao | malicious | malicious |
| CRDF | malicious | malicious |
| CyRadar | malicious | malicious |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | phishing |
| Gridinsoft | malicious | malicious |
| Kaspersky | malicious | malware |
| Lionic | malicious | phishing |
| Sophos | malicious | malicious |
| VIPRE | malicious | malware |
| Webroot | malicious | malicious |
Details From VirusTotal
Basic Properties
| TLD | com |
History
| Creation date | 2024-04-15 00:00 UTC |
| Last analysis | 2026-07-25 11:49 UTC |
| Last modified on VirusTotal | 2026-07-30 13:05 UTC |
| Last WHOIS update | 2024-04-15 00:00 UTC |
domain
mylittlecabbage.net
UrlVoid 6 / 35
1 feed
IOC database
- Type
- domain
- Value
mylittlecabbage.net- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
https://kostumn1.ilabserver.com/1.zip
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
https://kostumn1.ilabserver.com/1.zip- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
languangjob.com
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
languangjob.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
dr-networks.com
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
dr-networks.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
gratisbonuses.com
UrlVoid 3 / 35
IOC database
- Type
- domain
- Value
gratisbonuses.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
hostingrapid.com
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
hostingrapid.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
https://applylawofattraction.com:80
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
https://applylawofattraction.com:80- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
australiaivf.com
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
australiaivf.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
eventgrids.online
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
eventgrids.online- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
othergate.site
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
othergate.site- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
filetmoon.site
UrlVoid 5 / 35
IOC database
- Type
- domain
- Value
filetmoon.site- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
wuauserv.site
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
wuauserv.site- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
webkruzjevo.site
UrlVoid 3 / 35
IOC database
- Type
- domain
- Value
webkruzjevo.site- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
44-35-63-31.internalsakamai.net
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
44-35-63-31.internalsakamai.net- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://91.243.50.68:8080/eqvukhda
IOC database
- Type
- url
- Value
http://91.243.50.68:8080/eqvukhda- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://179.60.149.194:8080/vxhxrqnb
IOC database
- Type
- url
- Value
http://179.60.149.194:8080/vxhxrqnb- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://91.243.50.68:8080/rdullfph
IOC database
- Type
- url
- Value
http://91.243.50.68:8080/rdullfph- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
todayput.shop
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
todayput.shop- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
harlemsupport.com
UrlVoid 5 / 35
1 feed
IOC database
- Type
- domain
- Value
harlemsupport.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://oneinvestmentstudio.top
UrlVoid 3 / 35
IOC database
- Type
- url
- Value
http://oneinvestmentstudio.top- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://investmentsystems.top
UrlVoid 3 / 35
IOC database
- Type
- url
- Value
http://investmentsystems.top- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
applylawofattraction.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
applylawofattraction.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
aspava-yachting.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
aspava-yachting.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
clickminded.agency
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
clickminded.agency- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
80.66.88.145
IOC database
- Type
- ipv4
- Value
80.66.88.145- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
149.248.0.82
IOC database
- Type
- ipv4
- Value
149.248.0.82- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
zochao.com
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
zochao.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
katiklan.tech
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
katiklan.tech- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
wear626.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
wear626.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
getldrrgoodgame.com
UrlVoid 5 / 35
1 feed
IOC database
- Type
- domain
- Value
getldrrgoodgame.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
prestigiousdentistry.com
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
prestigiousdentistry.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
eugelens.com
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
eugelens.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
185.130.227.202
IOC database
- Type
- ipv4
- Value
185.130.227.202- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
prodomainnameeforappru.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
prodomainnameeforappru.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://prodomainnameeforappru.com:443
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://prodomainnameeforappru.com:443- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://95.164.63.54/documents/build-x64.zip
IOC database
- Type
- url
- Value
http://95.164.63.54/documents/build-x64.zip- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
https://grpt.ca/js/
UrlVoid 5 / 35
IOC database
- Type
- url
- Value
https://grpt.ca/js/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://95.164.63.54/documents/build-x64.zip/build-x64.msi
VT 12 / 98
IOC database
- Type
- url
- Value
http://95.164.63.54/documents/build-x64.zip/build-x64.msi- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 12 of 98 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| BitDefender | malicious | malware |
| CRDF | malicious | malicious |
| CyRadar | malicious | malicious |
| Dr.Web | malicious | malicious |
| Emsisoft | malicious | malware |
| ESET | malicious | malware |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | malware |
| Lionic | malicious | malicious |
| Sophos | malicious | malware |
| Webroot | malicious | malicious |
Details From VirusTotal
Basic Properties
| Final URL | http://95.164.63.54/documents/build-x64.zip/build-x64.msi |
History
| First seen on VirusTotal | 2024-02-14 07:40 UTC |
| Last submission | 2025-12-04 18:05 UTC |
| Last analysis | 2025-12-04 18:05 UTC |
| Last modified on VirusTotal | 2025-12-04 21:56 UTC |
url
https://grpt.ca/js/index.php
UrlVoid 5 / 35
IOC database
- Type
- url
- Value
https://grpt.ca/js/index.php- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
rourtmanjsdadhfakja.com
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
rourtmanjsdadhfakja.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
remasterprodelherskjs.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
remasterprodelherskjs.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
porsherses.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
porsherses.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
persikmonkiey7drone.com
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
persikmonkiey7drone.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
cayennesxque.boo
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
cayennesxque.boo- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://persikmonkiey7drone.com:80
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://persikmonkiey7drone.com:80- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://cdn-uk.widgetsfordeploy.com
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://cdn-uk.widgetsfordeploy.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
jenb128hiuedfhajduihfa.com
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
jenb128hiuedfhajduihfa.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
adfhjadfbjadbfjkhad44jka.com
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
adfhjadfbjadbfjkhad44jka.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
afdhf198jfadafdkfad.com
UrlVoid 5 / 35
1 feed
IOC database
- Type
- domain
- Value
afdhf198jfadafdkfad.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to DarkGate Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:attack.mitre.org
DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named " DarkGate " by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions. [1] DarkGate use increased significantly starting in 2022 and is under active development by its ...
-
web:medium.com
Detailed Analysis of DarkGate ; Investigating new top-trend backdoor malware Author: Minyeop Choi | BLKSMTH Last Modified : Jan 16, 2024 Executive Summary DarkGate is a malware that has been ...
-
web:unit42.paloaltonetworks.com
We perform an in-depth study of a DarkGate malware campaign exploiting Excel files from early this year, assessing its functionality and its C2 traffic.
-
web:www.mcafee.com
McAfee Labs has recently uncovered a novel infection chain associated with DarkGate malware. This chain commences with an HTML-based entry point and progresses to exploit the AutoHotkey utility in its subsequent stages. DarkGate , a Remote Access Trojan (RAT) developed using Borland Delphi, has been marketed as a Malware-as-a-Service (MaaS) offering on a Russian-language cybercrime forum since ...
-
web:www.proofpoint.com
Remediation : What are the lessons learned? To help safeguard against DarkGate phishing and malware attacks, we recommend that businesses take the following actions. Implement pre-delivery threat protection. Our research shows that 1 in 7 users will click on an email within one minute.
-
web:www.sonicwall.com
The SonicWall RTDMI ™ engine has recently protected users against the distribution of the "6.6" variant of DarkGate malware by a phishing email campaign containing PDF files as an attachment. DarkGate is an advanced Remote Access Trojan that has been widely active since 2018. The RAT has been marketed as Malware-as-a-Service in underground forums, and threat actors are actively updating ...
-
web:www.startupdefense.io
How can organizations detect DarkGate's use of legitimate DNS services for C2 ? DarkGate cloaks C2 traffic in DNS records from legitimate services, making reputation-based blocking ineffective. Detection requires analyzing the content of DNS queries rather than just the destination domain.
-
web:www.trellix.com
Figure 18: Encrypted DarkGate payload downloaded by the loader, in which the first 8 bytes are the XOR key used to decrypt the rest of the file. DarkGate malware payload The DarkGate payload is a modular sample that contains many functionalities to fully control a remote system.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.