TF-1933810
high
📛 Threat Title
Unknown Loader: Domain name that delivers a malware payload theatrum-mundi.org
Description
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:28 UTC. Reporter: varysz. Tags: etherhiding, victim.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
theatrum-mundi.org
VT 3 / 91
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
theatrum-mundi.org- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 3 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| CRDF | malicious | malicious |
| Gridinsoft | suspicious | suspicious |
| SOCRadar | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | Bluehost Inc. |
| TLD | org |
History
| Creation date | 2012-06-18 17:04 UTC |
| Last analysis | 2026-09-21 23:18 UTC |
| Last modified on VirusTotal | 2026-09-26 00:27 UTC |
| Last WHOIS update | 2026-08-12 07:18 UTC |
| WHOIS record date | 2026-08-23 00:15 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a malware distribution server (payload delivery). IOC type: Domain name that delivers a malware payload. Attributed malware: Unknown Loader. Confidence: 75. First seen: 2026-09-25 16:07:28 UTC. Reporter: varysz. Tags: etherhiding, victim.
Remediations (10)
-
web:blog.sicuranext.com
A real-world ClickFix intrusion observed from both sandbox and endpoint telemetry, revealing the complete attack path from a compromised WordPress site to a blocked GULoader execution, including a full process creation call stack from the Windows Run dialog to the kernel.
-
web:darkwebinformer.com
A new domain -based indicator has been identified associated with payload delivery activity tied to the malware unknown_loader . This domain , advertised under the guise of a mobile advertising and monetization platform, poses a high-confidence threat to users and organizations.
-
web:gbhackers.com
Threat actors on underground forums are now promoting a new "ClickFix" payload -delivery technique that hides malware in the browser cache to evade endpoint detection and response.
-
web:reliaquest.com
"DeepLoad" malware has arrived in enterprise environments via "ClickFix" delivery, turning one user action into rapid, fileless compromise. It likely uses AI-assisted obfuscation and process injection to evade static scanning, while credential theft starts immediately and captures passwords and sessions even if the primary loader is ...
-
web:thehackernews.com
WordlistLoader delivers Amatera via ClearFake ClickFix attacks, while SynkLoader uses Teams phishing to steal Windows login credentials.
-
web:www.csa.gov.sg
There have been reports of threat actors using a social engineering technique known as ClickFix to trick potential victims into executing malicious commands.
-
web:www.malwarebytes.com
We uncovered ClickFix attacks using fake Google and Cloudflare pages to deliver everything from infostealers to a newly discovered malware loader .
-
web:www.microsoft.com
Threat actors are targeting macOS users with fake utility fixes that trick them into running malicious Terminal commands. This campaign evades traditional defenses by stealing credentials, wallets, and sensitive data.
-
web:www.microsoft.com
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments.
-
web:www.rapid7.com
Rapid7 Labs has identified an ongoing, widespread compromise of legitimate WordPress websites, misused by an unidentified threat actor to inject a ClickFix implant (impersonating a Cloudflare human verification challenge [CAPTCHA]). The lure can be used for financial theft or to conduct further, more targeted attacks against organizations.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.