TF-1933831
high
📛 Threat Title
Unknown Loader: Domain name that delivers a malware payload tkevi.edu.ng
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:30 UTC. Reporter: varysz. Tags: etherhiding, victim.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
tkevi.edu.ng
VT 3 / 91
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
tkevi.edu.ng- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 3 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| CRDF | malicious | malicious |
| Gridinsoft | suspicious | suspicious |
| SOCRadar | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | Registeram.com Limited |
| TLD | edu.ng |
History
| Creation date | 2017-03-20 11:00 UTC |
| Last analysis | 2026-09-25 17:17 UTC |
| Last modified on VirusTotal | 2026-09-26 00:26 UTC |
| Last WHOIS update | 2026-03-17 14:05 UTC |
| WHOIS record date | 2026-07-10 12:21 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:30 UTC. Reporter: varysz. Tags: etherhiding, victim.
Remediations (10)
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.
-
web:precisionsec.com
Recent Malware Domain List indicators Live domain indicators, including phishing lures, C2 and payload -hosting infrastructure, pulled straight from our threat feed and refreshed hourly. For full coverage and API delivery, start a free trial. A sample from our threat feed.
-
web:reliaquest.com
Learn about the role of malware loaders in cybercriminal campaigns, their distribution methods, and strategies for detection and mitigation .
-
web:research.checkpoint.com
Among the payloads distributed through this TDS infrastructure, we identified several malware families: SessionGate — A previously unknown multi-stage loader with heavy obfuscation and extensive anti-analysis mechanisms, which makes obtaining the final payload extremely difficult.
-
web:thehackernews.com
ClickFix attacks are delivering BabaDeda, Lorem Ipsum, and Potemkin loaders to deploy stealers, RATs, and ransomware-linked tooling.
-
web:undercodetesting.com
Introduction: Cybercriminals are increasingly abusing DNS TXT records to deliver malware and command-and-control (C2) payloads covertly. A recent investigation by DomainTools revealed how attackers fragment, hex-encode, and distribute malicious code across multiple DNS queries, evading traditional security measures. This article explores detection techniques, mitigation strategies, and hands ...
-
web:www.endorlabs.com
NPM malware is spreading through some of the registry's most-downloaded packages. On August 4, 2026, malicious versions of keyv, flat-cache, and file-entry-cache, which together exceed 500 million weekly downloads, began running an install-time credential stealer. The same payload has since been republished across hundreds of other packages under multiple maintainer accounts. Endor Labs is ...
-
web:www.kodemsecurity.com
The keyv supply chain attack poisoned 11 npm seed packages and spread a Shai-Hulud worm to 400+ more. Get affected versions, IOCs, and the first-hour runbook.
-
web:www.malwarebytes.com
We uncovered ClickFix attacks using fake Google and Cloudflare pages to deliver everything from infostealers to a newly discovered malware loader .
-
web:www.wiz.io
Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.