s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1933754 high

📛 Threat Title

Unknown Loader: Domain name that delivers a malware payload shrikrishnasaiclinic.com

Category: Unknown Loader Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:21 UTC. Reporter: varysz. Tags: etherhiding, victim.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain shrikrishnasaiclinic.com VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/shrikrishnasaiclinic.com
UrlVoid 3 / 36

IOC database

Type
domain
Value
shrikrishnasaiclinic.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/shrikrishnasaiclinic.com

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:21 UTC. Reporter: varysz. Tags: etherhiding, victim.

Remediations (10)

  • web:darkwebinformer.com

    A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.

  • web:femtosec.io

    Analysis of the ClickFix loader emerging on underground forums. Learn how this malware deployment tool impacts enterprise security and how to mitigate the risk.

  • web:ismalicious.com

    4,553 indicators of compromise attributed to the Unknown Loader malware family — domains , IPs, URLs and file hashes, from abuse.ch feeds.

  • web:radar.cloudflare.com

    Understand the security, performance, technology, and network details of a URL with a publicly shareable report.

  • web:reliaquest.com

    "DeepLoad" malware has arrived in enterprise environments via "ClickFix" delivery, turning one user action into rapid, fileless compromise. It likely uses AI-assisted obfuscation and process injection to evade static scanning, while credential theft starts immediately and captures passwords and sessions even if the primary loader is ...

  • web:rhisac.org

    The malware provides operators with persistence, system reconnaissance, command execution, payload delivery, and resilient command and control capabilities. Key Takeaways DOUBLECUP is a Russian Loader - as -a-Service developed for ClickFix campaigns and has operated since early June 2026.

  • web:socprime.com

    The initial malware communicated with a command-and-control server at 89.110.110.119 over TCP port 443 using encoded traffic. The campaign, tracked as SmartApeSG ClickFix, relied on malicious scripts and a CAB archive to install the NetSupport RAT on victim systems.

  • web:urlhaus.abuse.ch

    URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...

  • web:www.picussecurity.com

    DeepLoad is a fileless loader observed in enterprise compromises. It is delivered through ClickFix, a social engineering technique where users are tricked into pasting an attacker-supplied command into Windows Run or a terminal. The command is disguised as a fix for a fake browser error, but it fetches and executes a remote payload directly in memory.

  • web:www.picussecurity.com

    Key Takeaways ModeloRAT is a Python-based Windows Remote Access Trojan first observed in January 2026 targeting domain -joined hosts. The CrashFix campaign delivers it through a fake NexShield Chrome extension that crashes the browser, then shows a repair prompt.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.