s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-65b2ce156fed993ea0af32b3 high

📛 Threat Title

DarkGate - C2 IP/Domain Tracker

Category: threat-intel Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

This pulse contains IOCs related to DarkGate Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 92 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (116)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 34.41.139.193 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/34.41.139.193

IOC database

Type
ipv4
Value
34.41.139.193
First seen
Last seen
Attached to this threat
Appears in
21 threats
Description
Resolved from domain xjp.cyberspeed.baby

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/34.41.139.193

ipv4 43.247.166.196 VT 1 / 91

IOC database

Type
ipv4
Value
43.247.166.196
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain zochao.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 1 of 91 VirusTotal vendors

VendorVerdictDetection
alphaMountain.ai malicious malicious

Details From VirusTotal

Basic Properties
Network43.247.164.0/22
CountryHK
AS ownerForewin Telecom Group Limited, ISP at HK
ASN38186
Regional registryAPNIC
History
Last analysis2026-08-02 11:18 UTC
Last modified on VirusTotal2026-08-02 11:27 UTC
WHOIS record date2026-08-02 11:22 UTC

ipv4 94.103.2.203

IOC database

Type
ipv4
Value
94.103.2.203
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain lili19mainmasters.com UrlVoid 5 / 35 1 feed

IOC database

Type
domain
Value
lili19mainmasters.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Imported from threat-intel feed: threatview.io

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain newdomainfortesteenestle.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
newdomainfortesteenestle.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Imported from threat-intel feed: threatview.io

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain strongdomainsercgerhhost.com UrlVoid 5 / 35 1 feed

IOC database

Type
domain
Value
strongdomainsercgerhhost.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Imported from threat-intel feed: threatview.io

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain prestige-castom.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
prestige-castom.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Imported from threat-intel feed: threatview.io

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 62.233.57.80 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/62.233.57.80

IOC database

Type
ipv4
Value
62.233.57.80
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain 44-35-63-31.internalsakamai.net

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/62.233.57.80

ipv4 179.60.149.194 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/179.60.149.194

IOC database

Type
ipv4
Value
179.60.149.194
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url http://179.60.149.194:8080/vxhxrqnb

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/179.60.149.194

ipv4 91.243.50.68 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/91.243.50.68

IOC database

Type
ipv4
Value
91.243.50.68
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url http://91.243.50.68:8080/eqvukhda

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/91.243.50.68

ipv4 154.214.85.53 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/154.214.85.53

IOC database

Type
ipv4
Value
154.214.85.53
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain languangjob.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/154.214.85.53

ipv4 104.152.168.10 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.152.168.10

IOC database

Type
ipv4
Value
104.152.168.10
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url http://savoystocks.com/yrorantd

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.152.168.10

ipv4 172.67.164.57 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.164.57

IOC database

Type
ipv4
Value
172.67.164.57
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain flexiblemaria.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.164.57

ipv4 104.21.15.206 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.15.206

IOC database

Type
ipv4
Value
104.21.15.206
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain flexiblemaria.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.15.206

ipv4 209.204.175.65 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/209.204.175.65

IOC database

Type
ipv4
Value
209.204.175.65
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url http://smbeckwithlaw.com/1.zip

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/209.204.175.65

ipv4 45.154.98.21 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/45.154.98.21

IOC database

Type
ipv4
Value
45.154.98.21
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url http://45.154.98.21/iopsmxt.a3x

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/45.154.98.21

ipv4 194.26.192.57 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/194.26.192.57

IOC database

Type
ipv4
Value
194.26.192.57
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url http://194.26.192.57/r-ops/test.txt

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/194.26.192.57

ipv4 104.201.29.84 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.201.29.84

IOC database

Type
ipv4
Value
104.201.29.84
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain 31yc.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.201.29.84

ipv4 45.89.53.187 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/45.89.53.187

IOC database

Type
ipv4
Value
45.89.53.187
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url http://45.89.53.187/s/ms_excel_azure_cloud_open_document.vbs

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/45.89.53.187

ipv4 206.188.196.222 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/206.188.196.222

IOC database

Type
ipv4
Value
206.188.196.222
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url http://206.188.196.222/ex.zip

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/206.188.196.222

ipv4 145.239.202.110 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/145.239.202.110

IOC database

Type
ipv4
Value
145.239.202.110
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url http://145.239.202.110:81/dark.vbs

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/145.239.202.110

ipv4 149.56.252.31 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/149.56.252.31

IOC database

Type
ipv4
Value
149.56.252.31
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url http://149.56.252.31:8094/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/149.56.252.31

ipv4 192.254.228.189 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/192.254.228.189

IOC database

Type
ipv4
Value
192.254.228.189
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url https://grpt.ca/js/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/192.254.228.189

ipv4 95.164.63.54 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/95.164.63.54

IOC database

Type
ipv4
Value
95.164.63.54
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from url http://95.164.63.54/documents/build-x64.zip

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/95.164.63.54

ipv4 147.135.84.14 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/147.135.84.14

IOC database

Type
ipv4
Value
147.135.84.14
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
Resolved from domain zephalon.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/147.135.84.14

ipv4 8.218.118.157 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/8.218.118.157

IOC database

Type
ipv4
Value
8.218.118.157
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain zochao.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/8.218.118.157

ipv4 76.223.54.146 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/76.223.54.146

IOC database

Type
ipv4
Value
76.223.54.146
First seen
Last seen
Attached to this threat
Appears in
27 threats
Description
Resolved from domain xinglou001.xyz

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/76.223.54.146

ipv4 13.248.169.48 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/13.248.169.48

IOC database

Type
ipv4
Value
13.248.169.48
First seen
Last seen
Attached to this threat
Appears in
27 threats
Description
Resolved from domain xinglou001.xyz

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/13.248.169.48

url http://remasterprodelherskjs.com:80 UrlVoid 4 / 35

IOC database

Type
url
Value
http://remasterprodelherskjs.com:80
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://cayennesxque.boo:80 UrlVoid 3 / 35

IOC database

Type
url
Value
http://cayennesxque.boo:80
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://porsherses.com:80 UrlVoid 4 / 35

IOC database

Type
url
Value
http://porsherses.com:80
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://149.56.252.31:8094/

IOC database

Type
url
Value
http://149.56.252.31:8094/
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://149.56.252.31/dark.vbs

IOC database

Type
url
Value
http://149.56.252.31/dark.vbs
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://145.239.202.110:81/dark.vbs

IOC database

Type
url
Value
http://145.239.202.110:81/dark.vbs
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://206.188.196.222/ex.zip

IOC database

Type
url
Value
http://206.188.196.222/ex.zip
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain nextroundst.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
nextroundst.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain diveupdown.com UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
diveupdown.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain buassinnndm.net UrlVoid 4 / 35

IOC database

Type
domain
Value
buassinnndm.net
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain badbutperfect.com UrlVoid 4 / 35

IOC database

Type
domain
Value
badbutperfect.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain goingupdate.com UrlVoid 2 / 35 1 feed

IOC database

Type
domain
Value
goingupdate.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://backupitfirst.com/wgfqneerod UrlVoid 4 / 35

IOC database

Type
url
Value
http://backupitfirst.com/wgfqneerod
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://withupdate.com/oudowibspr UrlVoid 5 / 35

IOC database

Type
url
Value
http://withupdate.com/oudowibspr
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain backupitfirst.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
backupitfirst.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain withupdate.com UrlVoid 5 / 35 1 feed

IOC database

Type
domain
Value
withupdate.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain madeyourbackup.com UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
madeyourbackup.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain 31yc.com UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
31yc.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain irreceiver.com UrlVoid 3 / 35

IOC database

Type
domain
Value
irreceiver.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://45.89.53.187/s/ms_excel_azure_cloud_open_document.vbs

IOC database

Type
url
Value
http://45.89.53.187/s/ms_excel_azure_cloud_open_document.vbs
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain wassonite.com UrlVoid 5 / 35 1 feed

IOC database

Type
domain
Value
wassonite.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url https://linktoxic34.com/wp-content/themes/twentytwentytwo/dark.hta UrlVoid 5 / 35

IOC database

Type
url
Value
https://linktoxic34.com/wp-content/themes/twentytwentytwo/dark.hta
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain dogmupdate.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
dogmupdate.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://194.26.192.57/r-ops/test.txt

IOC database

Type
url
Value
http://194.26.192.57/r-ops/test.txt
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://45.154.98.21/iopsmxt.a3x

IOC database

Type
url
Value
http://45.154.98.21/iopsmxt.a3x
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://194.26.192.57/r-ops/ncvui.exe

IOC database

Type
url
Value
http://194.26.192.57/r-ops/ncvui.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://45.154.98.21/pqkizk.exe

IOC database

Type
url
Value
http://45.154.98.21/pqkizk.exe
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://194.26.192.57/r-ops/yreuit.a3x

IOC database

Type
url
Value
http://194.26.192.57/r-ops/yreuit.a3x
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://45.154.98.21/test.txt

IOC database

Type
url
Value
http://45.154.98.21/test.txt
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain updateleft.com UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
updateleft.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain findyourbackups.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
findyourbackups.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url https://smbeckwithlaw.com/1.zip UrlVoid 2 / 35

IOC database

Type
url
Value
https://smbeckwithlaw.com/1.zip
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain kindupdates.com UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
kindupdates.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://smbeckwithlaw.com/1.zip UrlVoid 2 / 35

IOC database

Type
url
Value
http://smbeckwithlaw.com/1.zip
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain flexiblemaria.com UrlVoid 5 / 35

IOC database

Type
domain
Value
flexiblemaria.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://savoystocks.com/yrorantd UrlVoid 3 / 35

IOC database

Type
url
Value
http://savoystocks.com/yrorantd
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://savoystocks.com/awybcwjc UrlVoid 3 / 35

IOC database

Type
url
Value
http://savoystocks.com/awybcwjc
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain savoystocks.com UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
savoystocks.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain voip.analytics-edges.com VT 14 / 91 UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
voip.analytics-edges.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Flagged by 14 of 91 VirusTotal vendors

VendorVerdictDetection
ADMINUSLabs malicious malicious
BitDefender malicious phishing
Chong Lua Dao malicious malicious
CRDF malicious malicious
CyRadar malicious malicious
Forcepoint ThreatSeeker malicious malicious
Fortinet malicious malware
G-Data malicious phishing
Gridinsoft malicious malicious
Kaspersky malicious malware
Lionic malicious phishing
Sophos malicious malicious
VIPRE malicious malware
Webroot malicious malicious

Details From VirusTotal

Basic Properties
TLDcom
History
Creation date2024-04-15 00:00 UTC
Last analysis2026-07-25 11:49 UTC
Last modified on VirusTotal2026-07-30 13:05 UTC
Last WHOIS update2024-04-15 00:00 UTC
domain mylittlecabbage.net UrlVoid 6 / 35 1 feed

IOC database

Type
domain
Value
mylittlecabbage.net
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url https://kostumn1.ilabserver.com/1.zip UrlVoid 4 / 35

IOC database

Type
url
Value
https://kostumn1.ilabserver.com/1.zip
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain languangjob.com UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
languangjob.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain dr-networks.com UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
dr-networks.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain gratisbonuses.com UrlVoid 3 / 35

IOC database

Type
domain
Value
gratisbonuses.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain hostingrapid.com UrlVoid 4 / 35

IOC database

Type
domain
Value
hostingrapid.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url https://applylawofattraction.com:80 UrlVoid 4 / 35

IOC database

Type
url
Value
https://applylawofattraction.com:80
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain australiaivf.com UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
australiaivf.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain eventgrids.online UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
eventgrids.online
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain othergate.site UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
othergate.site
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain filetmoon.site UrlVoid 5 / 35

IOC database

Type
domain
Value
filetmoon.site
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain wuauserv.site UrlVoid 4 / 35

IOC database

Type
domain
Value
wuauserv.site
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain webkruzjevo.site UrlVoid 3 / 35

IOC database

Type
domain
Value
webkruzjevo.site
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain 44-35-63-31.internalsakamai.net UrlVoid 4 / 35

IOC database

Type
domain
Value
44-35-63-31.internalsakamai.net
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://91.243.50.68:8080/eqvukhda

IOC database

Type
url
Value
http://91.243.50.68:8080/eqvukhda
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://179.60.149.194:8080/vxhxrqnb

IOC database

Type
url
Value
http://179.60.149.194:8080/vxhxrqnb
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://91.243.50.68:8080/rdullfph

IOC database

Type
url
Value
http://91.243.50.68:8080/rdullfph
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain todayput.shop UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
todayput.shop
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain harlemsupport.com UrlVoid 5 / 35 1 feed

IOC database

Type
domain
Value
harlemsupport.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://oneinvestmentstudio.top UrlVoid 3 / 35

IOC database

Type
url
Value
http://oneinvestmentstudio.top
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://investmentsystems.top UrlVoid 3 / 35

IOC database

Type
url
Value
http://investmentsystems.top
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain applylawofattraction.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
applylawofattraction.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain aspava-yachting.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
aspava-yachting.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain clickminded.agency UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
clickminded.agency
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 80.66.88.145

IOC database

Type
ipv4
Value
80.66.88.145
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 149.248.0.82

IOC database

Type
ipv4
Value
149.248.0.82
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain zochao.com UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
zochao.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain katiklan.tech UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
katiklan.tech
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain wear626.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
wear626.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain getldrrgoodgame.com UrlVoid 5 / 35 1 feed

IOC database

Type
domain
Value
getldrrgoodgame.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain prestigiousdentistry.com UrlVoid 4 / 35

IOC database

Type
domain
Value
prestigiousdentistry.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain eugelens.com UrlVoid 4 / 35

IOC database

Type
domain
Value
eugelens.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 185.130.227.202

IOC database

Type
ipv4
Value
185.130.227.202
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain prodomainnameeforappru.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
prodomainnameeforappru.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://prodomainnameeforappru.com:443 UrlVoid 4 / 35

IOC database

Type
url
Value
http://prodomainnameeforappru.com:443
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://95.164.63.54/documents/build-x64.zip

IOC database

Type
url
Value
http://95.164.63.54/documents/build-x64.zip
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url https://grpt.ca/js/ UrlVoid 5 / 35

IOC database

Type
url
Value
https://grpt.ca/js/
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://95.164.63.54/documents/build-x64.zip/build-x64.msi VT 12 / 98

IOC database

Type
url
Value
http://95.164.63.54/documents/build-x64.zip/build-x64.msi
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 12 of 98 VirusTotal vendors

VendorVerdictDetection
BitDefender malicious malware
CRDF malicious malicious
CyRadar malicious malicious
Dr.Web malicious malicious
Emsisoft malicious malware
ESET malicious malware
Forcepoint ThreatSeeker malicious malicious
Fortinet malicious malware
G-Data malicious malware
Lionic malicious malicious
Sophos malicious malware
Webroot malicious malicious

Details From VirusTotal

Basic Properties
Final URLhttp://95.164.63.54/documents/build-x64.zip/build-x64.msi
History
First seen on VirusTotal2024-02-14 07:40 UTC
Last submission2025-12-04 18:05 UTC
Last analysis2025-12-04 18:05 UTC
Last modified on VirusTotal2025-12-04 21:56 UTC
url https://grpt.ca/js/index.php UrlVoid 5 / 35

IOC database

Type
url
Value
https://grpt.ca/js/index.php
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain rourtmanjsdadhfakja.com UrlVoid 4 / 35

IOC database

Type
domain
Value
rourtmanjsdadhfakja.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain remasterprodelherskjs.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
remasterprodelherskjs.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain porsherses.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
porsherses.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain persikmonkiey7drone.com UrlVoid 4 / 35 1 feed

IOC database

Type
domain
Value
persikmonkiey7drone.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain cayennesxque.boo UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
cayennesxque.boo
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://persikmonkiey7drone.com:80 UrlVoid 4 / 35

IOC database

Type
url
Value
http://persikmonkiey7drone.com:80
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://cdn-uk.widgetsfordeploy.com UrlVoid 4 / 35

IOC database

Type
url
Value
http://cdn-uk.widgetsfordeploy.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain jenb128hiuedfhajduihfa.com UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
jenb128hiuedfhajduihfa.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain adfhjadfbjadbfjkhad44jka.com UrlVoid 3 / 35 1 feed

IOC database

Type
domain
Value
adfhjadfbjadbfjkhad44jka.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain afdhf198jfadafdkfad.com UrlVoid 5 / 35 1 feed

IOC database

Type
domain
Value
afdhf198jfadafdkfad.com
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • OTX pulse AlienVaulkt OTX

    This pulse contains IOCs related to DarkGate Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Remediations (8)

  • web:attack.mitre.org

    DarkGate first emerged in 2018 and has evolved into an initial access and data gathering tool associated with various criminal cyber operations. Written in Delphi and named " DarkGate " by its author, DarkGate is associated with credential theft, cryptomining, cryptotheft, and pre-ransomware actions. [1] DarkGate use increased significantly starting in 2022 and is under active development by its ...

  • web:medium.com

    Detailed Analysis of DarkGate ; Investigating new top-trend backdoor malware Author: Minyeop Choi | BLKSMTH Last Modified : Jan 16, 2024 Executive Summary DarkGate is a malware that has been ...

  • web:unit42.paloaltonetworks.com

    We perform an in-depth study of a DarkGate malware campaign exploiting Excel files from early this year, assessing its functionality and its C2 traffic.

  • web:www.mcafee.com

    McAfee Labs has recently uncovered a novel infection chain associated with DarkGate malware. This chain commences with an HTML-based entry point and progresses to exploit the AutoHotkey utility in its subsequent stages. DarkGate , a Remote Access Trojan (RAT) developed using Borland Delphi, has been marketed as a Malware-as-a-Service (MaaS) offering on a Russian-language cybercrime forum since ...

  • web:www.proofpoint.com

    Remediation : What are the lessons learned? To help safeguard against DarkGate phishing and malware attacks, we recommend that businesses take the following actions. Implement pre-delivery threat protection. Our research shows that 1 in 7 users will click on an email within one minute.

  • web:www.sonicwall.com

    The SonicWall RTDMI ™ engine has recently protected users against the distribution of the "6.6" variant of DarkGate malware by a phishing email campaign containing PDF files as an attachment. DarkGate is an advanced Remote Access Trojan that has been widely active since 2018. The RAT has been marketed as Malware-as-a-Service in underground forums, and threat actors are actively updating ...

  • web:www.startupdefense.io

    How can organizations detect DarkGate's use of legitimate DNS services for C2 ? DarkGate cloaks C2 traffic in DNS records from legitimate services, making reputation-based blocking ineffective. Detection requires analyzing the content of DNS queries rather than just the destination domain.

  • web:www.trellix.com

    Figure 18: Encrypted DarkGate payload downloaded by the loader, in which the first 8 bytes are the XOR key used to decrypt the rest of the file. DarkGate malware payload The DarkGate payload is a modular sample that contains many functionalities to fully control a remote system.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…