IOC Radar
TLP:WHITE124 IOCs

Maltrail IOC for 2026-06-04

CO
CIRCL OSINT Feed
Published June 4, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREfileonyxcanvas.online89.47.51.187150.241.81.0CAPABILITYLummaVICTIMunknown
Adversary
Infrastructure(6)
Capability(1)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise124

TypeIndicatorConfidenceScoreFirst Seen
Domainfileonyxcanvas.online
malwarenetwork
High
72
Jun 4, 26
IP89.47.51.187
malwarenetwork
High
72
Jun 4, 26
IP150.241.81.0
malwarenetwork
High
72
Jun 4, 26
SHA1f593cb248eb194d85cafaa4fcb782885005ba6cc
aptespionagefile-hash
High
72
Jun 4, 26
Domainedoc-mane.dns.navy
aptespionagemalware
High
72
Jun 4, 26
IP2.26.74.0
malwarenetwork
High
72
Jun 4, 26
IP149.50.98.36
malwarenetworkrat
High
72
Jun 4, 26
Domainsolutionlogz.info
aptespionageexploit
High
72
Jun 4, 26
Domainpumps-streams.fun
malwarenetwork
High
72
Jun 4, 26
Domainconnect-socket.com
malwarenetwork
High
72
Jun 4, 26
Domainpitchgb.cyou
aptespionageloader
High
72
Jun 4, 26
Domainlumanotch.com
exploitmalwarenetwork
High
72
Jun 4, 26
Domainwsrequest.net
malwarenetwork
High
72
Jun 4, 26
IP149.50.98.31
malwarenetworkrat
High
72
Jun 4, 26
Domainnid.naver.subsoniclabs.com
aptespionagemalware
High
72
Jun 4, 26
Domainpanel-fsc.online
malwarenetwork
High
72
Jun 4, 26
Domainhot-mango.com
malwarenetwork
High
72
Jun 4, 26
Domaintruesignal77.com
malwarenetwork
High
72
Jun 4, 26
Domaingooglechtome.com
malwarenetwork
High
72
Jun 4, 26
Domainorlandoweddingfilms.com
aptespionagemalware
High
72
Jun 4, 26
SHA13feebe5c6cd17f3ee1d14c580677c7777aa4e90f
file-hashloadermalware
High
72
Jun 4, 26
Domainbridgetontowing.com
aptespionagemalware
High
72
Jun 4, 26
Domainr734yn7cnm7h7xmxuhjfshesiuaow21.dad
malwarenetwork
High
72
Jun 4, 26
Domainnaver.subsoniclabs.com
aptespionagemalware
High
72
Jun 4, 26
SHA177e68d0d428d6e59a3aa3db34d31315e0d128ea6
aptespionagefile-hash
High
72
Jun 4, 26
IP193.202.84.0
malwarenetwork
High
72
Jun 4, 26
SHA14bfd2a5f1adcf89625cf32cefb75eb53a46ce8fd
file-hashmalware
High
72
Jun 4, 26
SHA119ef9004df3290308e1f11ef5903250274770207
file-hashmalware
High
72
Jun 4, 26
IP31.76.118.0
malwarenetwork
High
72
Jun 4, 26
Domaincheckout.googlechtome.com
malwarenetwork
High
72
Jun 4, 26
IP2.27.5.0
malwarenetwork
High
72
Jun 4, 26
Domainhometa16x.dns.army
aptespionagemalware
High
72
Jun 4, 26
Domainfileembercloud.online
malwarenetwork
High
72
Jun 4, 26
IP31.76.93.0
malwarenetwork
High
72
Jun 4, 26
Domainfiletopazisland.online
malwarenetwork
High
72
Jun 4, 26
Domainrelay.mtrdrgzcid.com
malwarenetwork
High
72
Jun 4, 26
Domainshoepay.io
aptespionagemalware
High
72
Jun 4, 26
Domainws-socket.net
malwarenetwork
High
72
Jun 4, 26
Domainnidservers.tpox17er.dns.army
aptespionagemalware
High
72
Jun 4, 26
IP149.50.98.34
malwarenetworkrat
High
72
Jun 4, 26
Domainmsticker.club
aptespionagemalware
High
72
Jun 4, 26
Domainedoc-mew.dynv6.net
aptespionagemalware
High
72
Jun 4, 26
IP149.50.98.26
malwarenetworkrat
High
72
Jun 4, 26
IP149.50.98.27
malwarenetworkrat
High
72
Jun 4, 26
SHA1cca5e11ac679a08cf364ba8431877b9fb5f0241f
aptespionagefile-hash
High
72
Jun 4, 26
IP45.8.150.50
malwarenetwork
High
72
Jun 4, 26
Domainapi.fildeler.dk
malwarenetworkrat
High
72
Jun 4, 26
IP149.50.98.33
malwarenetworkrat
High
72
Jun 4, 26
Domainerpri.help
malwarenetworkrat
High
72
Jun 4, 26
Domainfilecopperforest.online
malwarenetwork
High
72
Jun 4, 26
Domainapigodaddy.net
malwarenetwork
High
72
Jun 4, 26
Domaincdn.ibanqq.icu
loadermalwarenetwork
High
72
Jun 4, 26
Domainlinkidjan.com
malwarenetwork
High
72
Jun 4, 26
Domainfilemoonlitengine.online
malwarenetwork
High
72
Jun 4, 26
Domainn-cloud.ntr26edc.dynv6.net
aptespionagemalware
High
72
Jun 4, 26
IP149.50.98.25
malwarenetworkrat
High
72
Jun 4, 26
SHA18859738f2c781a61f94a99d2441d339af57705a7
file-hashmalware
High
72
Jun 4, 26
Domainncodbyverify.dynv6.net
aptespionagemalware
High
72
Jun 4, 26
SHA168bd06f18e332bcc2cdb1b438da014b17b835bea
file-hashmalware
High
72
Jun 4, 26
Domainrequest-ws.com
malwarenetwork
High
72
Jun 4, 26
Domaintpox17er.dns.army
aptespionagemalware
High
72
Jun 4, 26
Domainnid-naversis.servepics.com
aptespionagemalware
High
72
Jun 4, 26
SHA187775b95e07eb9fd48fc724b5322310eb67cd13f
file-hashmalwarerat
High
72
Jun 4, 26
SHA172995a0da7899b024931521d973bbb67d4b45d72
file-hashloadermalware
High
72
Jun 4, 26
Domainfileaquamarinebridge.online
malwarenetwork
High
72
Jun 4, 26
SHA1348820bd7574bf2ce2f2bc617d9389c2d3c5976e
file-hashmalware
High
72
Jun 4, 26
IP2.26.75.0
malwarenetwork
High
72
Jun 4, 26
Domainbatcemetery.space
loadermalwarenetwork
High
72
Jun 4, 26
Domainfilecrystalwave.com
malwarenetwork
High
72
Jun 4, 26
Domainst.cc.forensic.cafe
malwarenetwork
High
72
Jun 4, 26
Domainkehypu.club
malwarenetwork
High
72
Jun 4, 26
SHA1a6c434c7a3e53902f5162306774246f0d758a59d
file-hashmalware
High
72
Jun 4, 26
Domainnids.ndocbqcheck.dynv6.net
aptespionagemalware
High
72
Jun 4, 26
IP149.50.98.32
malwarenetworkrat
High
72
Jun 4, 26
Domainrespectmountain.xyz
loadermalwarenetwork
High
72
Jun 4, 26
Domainncodcgpass.dynv6.net
aptespionagemalware
High
72
Jun 4, 26
IP149.50.98.23
aptespionagemalware
High
72
Jun 4, 26
Domainwallspace4k.net
malwarenetwork
High
72
Jun 4, 26
SHA1ec340c41eb192c70da0068222153ab6b3db672d8
aptespionagefile-hash
High
72
Jun 4, 26
IP149.50.98.35
malwarenetworkrat
High
72
Jun 4, 26
SHA11e641425a0c3c7f5a0665c6cf222a51ad7082cd3
file-hashmalwarerat
High
72
Jun 4, 26
Domainreader-doc.digital
aptespionagemalware
High
72
Jun 4, 26
IP149.50.98.28
malwarenetworkrat
High
72
Jun 4, 26
Domainbreonros.it.com
aptespionagemalware
High
72
Jun 4, 26
Domaininfo.edoc-mew.dynv6.net
aptespionagemalware
High
72
Jun 4, 26
Domainpumpstreaminghub.fun
malwarenetwork
High
72
Jun 4, 26
Domainsign-mess.digital
aptespionagemalware
High
72
Jun 4, 26
IP209.99.186.176
malwarenetwork
High
72
Jun 4, 26
Domaindollscough.cfd
malwarenetwork
High
72
Jun 4, 26
Domainfilecoralbridge.cyou
malwarenetwork
High
72
Jun 4, 26
Domaininfo.edoc-mane.dns.navy
aptespionagemalware
High
72
Jun 4, 26
Domainndocbqcheck.dynv6.net
aptespionagemalware
High
72
Jun 4, 26
IP149.50.98.30
malwarenetworkrat
High
72
Jun 4, 26
Domainlinkedrink.click
malwarenetwork
High
72
Jun 4, 26
SHA1660ba6d9bb811ee5b00454b8a8000105fe6e61b1
file-hashmalware
High
72
Jun 4, 26
IP144.31.236.0
malwarenetwork
High
72
Jun 4, 26
Domainfiscatium.info
malwarenetwork
High
72
Jun 4, 26
Domainnid-naverewj.serveftp.com
aptespionagemalware
High
72
Jun 4, 26
Domainljinkidin.com
malwarenetwork
High
72
Jun 4, 26
Domaintradeback-pumps.fun
malwarenetwork
High
72
Jun 4, 26
IP149.50.98.29
malwarenetworkrat
High
72
Jun 4, 26
IP192.151.146.82
malwarenetwork
High
72
Jun 4, 26
Domainfilebirchorbit.online
malwarenetwork
High
72
Jun 4, 26
SHA1f4eaaf3ea846f4ddc862fe5ad71016caeb1742cc
file-hashmalwarerat
High
72
Jun 4, 26
Domainnid-naverkuf.servehalflife.com
aptespionagemalware
High
72
Jun 4, 26
SHA1c00bb6aa9259d5e0a7e659640640780d83beb5a0
file-hashmalware
High
72
Jun 4, 26
Domaincdn-request.com
malwarenetwork
High
72
Jun 4, 26
Domainfileprairiestudio.online
malwarenetwork
High
72
Jun 4, 26
IP109.238.92.154
malwarenetwork
High
72
Jun 4, 26
IP194.9.6.97
malwarenetworkrat
High
72
Jun 4, 26
Domaincc.forensic.cafe
malwarenetwork
High
72
Jun 4, 26
IP31.76.87.0
malwarenetwork
High
72
Jun 4, 26
SHA1251c5a6e4ec65dc07ae88e4d3b9225742d93a28d
file-hashmalware
High
72
Jun 4, 26
Domainntr26edc.dynv6.net
aptespionagemalware
High
72
Jun 4, 26
SHA15bc08a500059cde822792f8c0b0e347abfcf7ebe
aptespionageexploit
High
72
Jun 4, 26
Domainspace.lumanotch.com
exploitmalwarenetwork
High
72
Jun 4, 26
Domainns6docs.dynv6.net
aptespionagemalware
High
72
Jun 4, 26
Domainkickbyt.com
malwarenetwork
High
72
Jun 4, 26
Domainpunps.fun
malwarenetwork
High
72
Jun 4, 26
Domainnid-naverdvl.servequake.com
aptespionagemalware
High
72
Jun 4, 26
Domainlairatech.it.com
aptespionagemalware
High
72
Jun 4, 26
IP149.50.98.24
malwarenetworkrat
High
72
Jun 4, 26
Domainfilesilentfalcon.com
malwarenetwork
High
72
Jun 4, 26
Domaincold-apple.com
malwarenetwork
High
72
Jun 4, 26

IOC Relationship Graph

IOC Relationship Graph124 total IOCs
DomainIPSHA1
Domain76IP29SHA119Malware1REPORTMaltrail IOC for 2026-06-0Lumma
scroll to zoom · drag to pan · click IOC to open