TLP:WHITE5 IOCs
Malspam Campaign Uses DoubleClick Redirects to Deliver .NET Loader
Malware Families
Diamond Model
Adversary
Infrastructure(5)
Capability(2)
Victim
Attack Flow10 steps · MITRE ATT&CK mapped
5W+H Threat Analysis
Analysis unavailable
Indicators of Compromise
Indicators of Compromise5
| Type | Indicator | Confidence | Score | First Seen |
|---|---|---|---|---|
| Domain | xtadts.ddns.net c2intel-blogloader | High | 58 | Jun 7, 26 |
| Domain | catalogo.castrouria.com intel-blogloadermalware | High | 72 | Jun 5, 26 |
| Domain | afxwd.ddns.net c2intel-blogloader | High | 58 | Jun 7, 26 |
| Domain | ipapi.co aptespionageexploit | High | 55 | Jun 7, 26 |
| Domain | ad.doubleclick.net intel-blogmalwarenetwork | High | 55 | Jun 7, 26 |
IOC Relationship Graph
IOC Relationship Graph5 total IOCs
Domain