s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1933831 high

📛 Threat Title

Unknown Loader: Domain name that delivers a malware payload tkevi.edu.ng

Category: Unknown Loader Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:30 UTC. Reporter: varysz. Tags: etherhiding, victim.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain tkevi.edu.ng VT 3 / 91 UrlVoid 3 / 36

IOC database

Type
domain
Value
tkevi.edu.ng
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 3 of 91 VirusTotal vendors

VendorVerdictDetection
CRDF malicious malicious
Gridinsoft suspicious suspicious
SOCRadar suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarRegisteram.com Limited
TLDedu.ng
History
Creation date2017-03-20 11:00 UTC
Last analysis2026-09-25 17:17 UTC
Last modified on VirusTotal2026-09-26 00:26 UTC
Last WHOIS update2026-03-17 14:05 UTC
WHOIS record date2026-07-10 12:21 UTC

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:30 UTC. Reporter: varysz. Tags: etherhiding, victim.

Remediations (10)

  • web:darkwebinformer.com

    A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.

  • web:precisionsec.com

    Recent Malware Domain List indicators Live domain indicators, including phishing lures, C2 and payload -hosting infrastructure, pulled straight from our threat feed and refreshed hourly. For full coverage and API delivery, start a free trial. A sample from our threat feed.

  • web:reliaquest.com

    Learn about the role of malware loaders in cybercriminal campaigns, their distribution methods, and strategies for detection and mitigation .

  • web:research.checkpoint.com

    Among the payloads distributed through this TDS infrastructure, we identified several malware families: SessionGate — A previously unknown multi-stage loader with heavy obfuscation and extensive anti-analysis mechanisms, which makes obtaining the final payload extremely difficult.

  • web:thehackernews.com

    ClickFix attacks are delivering BabaDeda, Lorem Ipsum, and Potemkin loaders to deploy stealers, RATs, and ransomware-linked tooling.

  • web:undercodetesting.com

    Introduction: Cybercriminals are increasingly abusing DNS TXT records to deliver malware and command-and-control (C2) payloads covertly. A recent investigation by DomainTools revealed how attackers fragment, hex-encode, and distribute malicious code across multiple DNS queries, evading traditional security measures. This article explores detection techniques, mitigation strategies, and hands ...

  • web:www.endorlabs.com

    NPM malware is spreading through some of the registry's most-downloaded packages. On August 4, 2026, malicious versions of keyv, flat-cache, and file-entry-cache, which together exceed 500 million weekly downloads, began running an install-time credential stealer. The same payload has since been republished across hundreds of other packages under multiple maintainer accounts. Endor Labs is ...

  • web:www.kodemsecurity.com

    The keyv supply chain attack poisoned 11 npm seed packages and spread a Shai-Hulud worm to 400+ more. Get affected versions, IOCs, and the first-hour runbook.

  • web:www.malwarebytes.com

    We uncovered ClickFix attacks using fake Google and Cloudflare pages to deliver everything from infostealers to a newly discovered malware loader .

  • web:www.wiz.io

    Wiz Research is actively investigating an ongoing software supply chain attack affecting multiple keyv/cacheable npm packages.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.