TF-1931969
high
📛 Threat Title
Unknown Loader: Domain name that delivers a malware payload schupp-kfz.de
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-24 07:37:20 UTC. Reporter: varysz. Tags: etherhiding, victim.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
schupp-kfz.de
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
schupp-kfz.de- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain name that delivers a malware payload attributed to Unknown Loader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-24 07:37:20 UTC. Reporter: varysz. Tags: etherhiding, victim.
Remediations (10)
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.
-
web:thehackernews.com
Microsoft details a new ClickFix variant abusing DNS nslookup commands to stage malware , enabling stealthy payload delivery and RAT deployment.
-
web:threatfox.abuse.ch
A malware sample can be associated with only one malware family. The page below gives you an overview on indicators of compromise associated with unknown_loader .
-
web:threatlabsnews.xcitium.com
Discover how the new ClickFix attack abuses DNS queries and nslookup to deliver the ModeloRAT malware . Learn how to protect your network from this evolving social engineering threat.
-
web:urlhaus.abuse.ch
URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...
-
web:www.bleepingcomputer.com
Threat actors are now abusing DNS queries as part of ClickFix social engineering attacks to deliver malware , making this the first known use of DNS as a channel in these campaigns.
-
web:www.malwarebytes.com
We found PavinLoader being used across ClickFix, fake software, and RenPy campaigns to deliver Amatera Stealer and other malware .
-
web:www.opswat.com
ClickFix bypasses EDR by making the user the execution layer. Learn how it works and how MetaDefender Aether detects ClickFix payloads pre-execution.
-
web:www.seqrite.com
Table of Contents Introduction The Evolving Threat of Attack Loaders Objective of This Blog Technical Methodology and Analysis Initial Access and Social Engineering Multi-Stage Obfuscation and De-obfuscation Anti-Analysis Techniques The Final Payload Conclusion IOCs Quick Heal \ Seqrite Protection MITRE ATT&CK Mapping Introduction With the evolution of cyber threats, the final execution of a ...
-
web:www.threatlog.com
ThreatLog tracks 380,000+ malicious domains linked to malware , phishing, scams and fraud. A continuously growing database of malicious domains .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.