IOC Radar
TLP:WHITE249 IOCs

Maltrail IOC for 2026-06-09

CO
CIRCL OSINT Feed
Published June 9, 2026Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYLockBitPlayINFRASTRUCTUREfees-pumps.funrecruitptogether.xyznlf.ssffaa19.xyzCAPABILITYLockBitLummaMetasploitVICTIMunknown
Adversary(2)
Infrastructure(6)
Capability(5)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise249

TypeIndicatorConfidenceScoreFirst Seen
SHA19f8ac6a630f1128e1eca0ccc63bf54312af40bcc
aptespionagefile-hash
High
68
Jun 9, 26
Domainfees-pumps.fun
malwarenetwork
High
68
Jun 9, 26
Domainrecruitptogether.xyz
aptespionagemalware
High
68
Jun 9, 26
Domainnlf.ssffaa19.xyz
malwarenetworkstealer
High
68
Jun 9, 26
SHA13f301fd3a1bc5226548e50f92488d662f61429ff
file-hashmalware
High
68
Jun 9, 26
Domaindeep-seek.ai
malwarenetwork
High
68
Jun 9, 26
Domaintrixauvexnet.ink
aptespionagemalware
High
68
Jun 9, 26
Domainfilecrystalhaven.com
malwarenetwork
High
68
Jun 9, 26
Domaintoknportl.site
malwarenetwork
High
68
Jun 9, 26
Domaincontactpulsynk.ink
aptespionagemalware
High
68
Jun 9, 26
Domainfax-cover.com
aptespionagemalware
High
68
Jun 9, 26
Domaintubeuyd.com
aptespionagemalware
High
68
Jun 9, 26
SHA190bc2c371f59691a7753d35c2067701b73493ffa
file-hashmalware
High
68
Jun 9, 26
Domaindeepseek-go.com
malwarenetwork
High
68
Jun 9, 26
Domainveadvhb.com
aptespionagemalware
High
68
Jun 9, 26
Domainhk-deepseek.com
malwarenetwork
High
68
Jun 9, 26
Domainbill-boss-mac.github.io
aptespionagemalware
High
68
Jun 9, 26
Domainhowartin.top
malwarenetworkstealer
High
68
Jun 9, 26
Domaindeepseekapp.com.cn
malwarenetwork
High
68
Jun 9, 26
IP136.0.141.112
malwarenetwork
High
68
Jun 9, 26
Domainapp-deepseekcn.com.cn
malwarenetwork
High
68
Jun 9, 26
Domainvymgwac.com
aptespionagemalware
High
68
Jun 9, 26
SHA2569d7576046152695728ead43e9752a105ef2641ef6317ff8d47094b8f541835b2
aptespionagefile-hash
High
68
Jun 9, 26
Domainbgpuome.com
aptespionagemalware
High
68
Jun 9, 26
Domainrmkncoo.com
aptespionagemalware
High
68
Jun 9, 26
Domainempowerpharmacy.space
aptespionagemalware
High
68
Jun 9, 26
Domaindeepseek.ai
malwarenetwork
High
68
Jun 9, 26
SHA1071914e5663924c2f857c1e7d1ebcda7ba51d741
aptespionagefile-hash
High
68
Jun 9, 26
Domaintrs668.cc
aptespionagemalware
High
68
Jun 9, 26
Domaintogetherhire.fun
aptespionagemalware
High
68
Jun 9, 26
Domainpan.rongtv.xyz
intel-blogloadermalware
High
64
Jun 8, 26
IP216.126.225.67
aptespionagemalware
High
68
Jun 9, 26
Domainhahaios.com
aptbotnetespionage
High
86
Jun 9, 26
IP209.182.224.49
aptespionagemalware
High
68
Jun 9, 26
Domaincoinbase-backup.com
aptespionagemalware
High
68
Jun 9, 26
Domainpulsynk.org
aptespionagemalware
High
68
Jun 9, 26
Domainaideepseek.cc
malwarenetwork
High
68
Jun 9, 26
Domainbrokeapt.com
aptc2espionage
High
64
Jun 8, 26
Domaintalentnexhr.ink
aptespionagemalware
High
68
Jun 9, 26
Domainnsicksf.com
aptespionagemalware
High
68
Jun 9, 26
Domaindeepseek404.com
malwarenetwork
High
68
Jun 9, 26
Domainai-deepseek.com.cn
malwarenetwork
High
68
Jun 9, 26
Domainfdutcor.com
aptespionagemalware
High
68
Jun 9, 26
Domaindygutvb.com
aptespionagemalware
High
68
Jun 9, 26
SHA148e9d4f27f51d6dffacb7ab362f8a895d0901c9e
aptespionagefile-hash
High
68
Jun 9, 26
IP80.78.24.169
malwarenetworkstealer
High
68
Jun 9, 26
Domain3la6ol.net
aptespionagemalware
High
68
Jun 9, 26
IP144.172.89.183
aptespionagemalware
High
68
Jun 9, 26
SHA1a6c906e7b7c5d591d68a041c0e676f53cb989126
aptc2espionage
High
68
Jun 9, 26
Domaindeepseek-plus.github.io
malwarenetwork
High
68
Jun 9, 26
Domainbackup.coinbase-backup.com
aptespionagemalware
High
68
Jun 9, 26
Domaincardlumeonline.com
malwarenetwork
High
68
Jun 9, 26
Domainocalatreeservices.com
aptespionagemalware
High
68
Jun 9, 26
Domainlab99.sbs
aptespionagemalware
High
68
Jun 9, 26
Domainsigner.dns.army
aptespionagemalware
High
68
Jun 9, 26
Domainftemu.com
malwarenetwork
High
68
Jun 9, 26
Domainonoplanoai.ink
aptespionagemalware
High
68
Jun 9, 26
Domaincc.attachfile.verymad.net
aptespionagemalware
High
68
Jun 9, 26
SHA25691ed53ad7977c0fa482c5a58c0590512a621852fd5bc4303e5bf209a1117b30d
botnetfile-hashmalware
High
86
Jun 9, 26
Domainmailtrixauvex.ink
aptespionagemalware
High
68
Jun 9, 26
SHA1b709819b72b9c1b5d318ff02e0305ad0bfcbb024
aptespionagefile-hash
High
68
Jun 9, 26
Domainplay-best-games.online
aptespionagemalware
High
68
Jun 9, 26
IP136.0.141.41
malwarenetwork
High
68
Jun 9, 26
SHA256068505fab1dc1b784ddc845c9eeeba8e04da512383ecd55a7a3d076879656393
aptbotnetespionage
High
86
Jun 9, 26
Domaindomatisc.ink
aptespionagemalware
High
68
Jun 9, 26
IP166.0.132.237
malwarenetworkproxy
High
68
Jun 9, 26
Domainfruitbeginner.space
aptespionageloader
High
68
Jun 9, 26
Domainaz2030port.duckdns.org
aptbotnetespionage
High
86
Jun 9, 26
Domaindeepseek.ai-kit.cn
malwarenetwork
High
68
Jun 9, 26
SHA184f0eefcb198ff0f3a6ce15146abb043f6e01e5e
file-hashmalware
High
68
Jun 9, 26
Domainggl.ssffaa19.xyz
malwarenetworkstealer
High
68
Jun 9, 26
Domaintolerancemodernincruiter.com
aptespionagemalware
High
68
Jun 9, 26
SHA1ebdd67baab06940871ce3c32cc7950764f0d3217
aptespionagefile-hash
High
68
Jun 9, 26
Domainpan.ssffaa19.xyz
aptespionageintel-blog
High
64
Jun 8, 26
Domainasteara.org
aptespionagemalware
High
68
Jun 9, 26
SHA2567127cb878cab370d24ef87cf0145c2e4af63bd021f67b58d08ed30f87b78afa1
botnetfile-hashmalware
High
82
Jun 8, 26
Domainorangefilehub.com
malwarenetwork
High
68
Jun 9, 26
IP23.137.105.75
aptespionagemalware
High
68
Jun 9, 26
Domainpipeplane.cfd
malwarenetwork
High
68
Jun 9, 26
Domainnowurisch.fit
aptespionagemalware
High
68
Jun 9, 26
SHA197a5cc65f45a225c417bd547bf88bdac19d65021
aptespionagefile-hash
High
68
Jun 9, 26
Domainprism-tech.cfd
malwarenetwork
High
68
Jun 9, 26
Domaindeepsesk.com.cn
malwarenetwork
High
68
Jun 9, 26
Domainconnectptogether.ink
aptespionagemalware
High
68
Jun 9, 26
IP178.16.55.28
botnetmalwarenetwork
High
86
Jun 9, 26
Domaindeepseekaigo.cyou
malwarenetwork
High
68
Jun 9, 26
IP38.225.209.229
c2malwarenetwork
High
68
Jun 9, 26
Domainweb.deepseekaigo.cyou
malwarenetwork
High
68
Jun 9, 26
Domaincreditanova.com
aptespionagemalware
High
68
Jun 9, 26
Domainrongtv.xyz
malwarenetworkstealer
High
68
Jun 9, 26
Domaindeepseeksai.com
malwarenetwork
High
68
Jun 9, 26
Domaineskezgn.com
aptespionagemalware
High
68
Jun 9, 26
Domaindeepseek.chat
malwarenetwork
High
68
Jun 9, 26
URLhttps://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware
c2exploitmalware
High
68
Jun 9, 26
Domainpredictcareertogether.space
aptespionagemalware
High
68
Jun 9, 26
Domainchat.mixinnet.cn
malwarenetwork
High
68
Jun 9, 26
Domaingrapefruitfilezone.com
malwarenetwork
High
68
Jun 9, 26
Domainpredicttogerecruit.store
aptespionagemalware
High
68
Jun 9, 26
Domainkiwifilecenter.com
malwarenetwork
High
68
Jun 9, 26
Domainhvdaconversions.com
aptespionagemalware
High
68
Jun 9, 26
IP91.92.43.71
aptespionagemalware
High
68
Jun 9, 26
Domaincha.rongtv.xyz
malwarenetworkstealer
High
68
Jun 9, 26
Domainnotifypulsynk.ink
aptespionagemalware
High
68
Jun 9, 26
Domainzuyuhtv.com
aptespionageloader
High
68
Jun 9, 26
Domainlog.signer.dns.army
aptespionagemalware
High
68
Jun 9, 26
Domainxjiyuerbfa48y.xyz
aptespionagemalware
High
68
Jun 9, 26
Domain985.ad
aptespionagemalware
High
68
Jun 9, 26
Domaindeepseik.com.cn
malwarenetwork
High
68
Jun 9, 26
Domainpredicttocareer.space
aptespionagemalware
High
68
Jun 9, 26
Domainchats.mixinnet.cn
malwarenetwork
High
68
Jun 9, 26
Domaincha.ssffaa19.xyz
malwarenetworkstealer
High
68
Jun 9, 26
Domaindeepseek.net
malwarenetwork
High
68
Jun 9, 26
SHA17668808b0a6030c0e269827ad05e21bca7b57c87
aptespionagefile-hash
High
68
Jun 9, 26
Domainapp-deepseek.com.cn
malwarenetwork
High
68
Jun 9, 26
Domaincoslyintra.online
aptespionagemalware
High
68
Jun 9, 26
Domain51mitu.com
malwarenetwork
High
68
Jun 9, 26
SHA1051c16b32a64ccc3ed51f96722cdd9f925952717
c2exploitfile-hash
High
68
Jun 9, 26
Domainbestgames-play.com
aptespionagemalware
High
68
Jun 9, 26
Domainfileprairiestudio.com
malwarenetwork
High
68
Jun 9, 26
Domaintrixauvex.org
aptespionagemalware
High
68
Jun 9, 26
Domaintorcyber.com
malwarenetwork
High
68
Jun 9, 26
SHA18f50c51c370facefc76c84cf0d8c31198b7a9fff
aptespionagefile-hash
High
68
Jun 9, 26
Domainb.howartin.top
malwarenetworkstealer
High
68
Jun 9, 26
Domaindeepseekss.com
malwarenetwork
High
68
Jun 9, 26
Domainpearfiledepot.com
malwarenetwork
High
68
Jun 9, 26
Domaindeep-seek.com
malwarenetwork
High
68
Jun 9, 26
Domainceronet.work
aptespionagemalware
High
68
Jun 9, 26
Domainxdgxuln.com
aptespionagemalware
High
68
Jun 9, 26
SHA256b1aa30190c7000337b4e3466db07dad3cff5d2b61ebeeecf1bda85fb27677e68
file-hashmalwarerat
High
86
Jun 9, 26
Domaindeepseekapi.cc
malwarenetwork
High
68
Jun 9, 26
Domainmixinnet.cn
malwarenetwork
High
68
Jun 9, 26
Domainchat-deep.ai
malwarenetwork
High
68
Jun 9, 26
Domaincareerpulsynk.xyz
aptespionagemalware
High
68
Jun 9, 26
SHA155f15cd23b3ddf60a6fa220a3778589742754d90
aptespionagefile-hash
High
68
Jun 9, 26
Domaindeepsiek.com.cn
malwarenetwork
High
68
Jun 9, 26
IP23.26.237.80
malwarenetwork
High
68
Jun 9, 26
Domaineager-shockley.144-172-108-248.plesk.page
aptespionagemalware
High
68
Jun 9, 26
SHA1aac6cf88b33384f08669c3b7648da539b201957b
aptespionagefile-hash
High
68
Jun 9, 26
Domainteampulsynk.team
aptespionagemalware
High
68
Jun 9, 26
Domaincn-deepseek.com.cn
malwarenetwork
High
68
Jun 9, 26
Domainpassedt.cyou
aptespionagemalware
High
68
Jun 9, 26
Domainxjtqqai.com
aptespionagemalware
High
68
Jun 9, 26
IP144.172.112.213
aptespionagemalware
High
68
Jun 9, 26
Domaindeepseek-free-r1.github.io
malwarenetwork
High
68
Jun 9, 26
Domainmailpulsynk.xyz
aptespionagemalware
High
68
Jun 9, 26
Domaindeepssek.com.cn
malwarenetworkstealer
High
68
Jun 9, 26
Domainpredicttogether.ink
aptespionagemalware
High
68
Jun 9, 26
Domaindeepaesk.com.cn
malwarenetwork
High
68
Jun 9, 26
Domainmgmy.my
aptespionagemalware
High
68
Jun 9, 26
Domaindoxxela.ink
aptespionagemalware
High
68
Jun 9, 26
Domaindmjhaha.com
aptespionagemalware
High
68
Jun 9, 26
Domaincotrixauvex.ink
aptespionagemalware
High
68
Jun 9, 26
Domainrainfont.com
malwarenetwork
High
68
Jun 9, 26
Domainonoplainai.ink
aptespionagemalware
High
68
Jun 9, 26
Domainfilesilverharbor.com
malwarenetwork
High
68
Jun 9, 26
SHA1dad9feabf41f81652786d3d20c55ae165757624b
aptespionagefile-hash
High
68
Jun 9, 26
Domainraxvatange.ink
aptespionagemalware
High
68
Jun 9, 26
SHA1a03c616c0a82c03077488b17bc965421f66a986f
file-hashmalware
High
68
Jun 9, 26
SHA1bcdf9e4c6b0871c3e4136fe9ca76772139ba176d
aptespionagefile-hash
High
68
Jun 9, 26
Domaindeeeseek.com
malwarenetwork
High
68
Jun 9, 26
Domainmtdxmgl.com
aptespionagemalware
High
68
Jun 9, 26
Domaintrailerflorida.com
aptespionagemalware
High
68
Jun 9, 26
SHA11aa3abf13065cebf809a296d8bb05e621f30b75b
file-hashmalwarestealer
High
68
Jun 9, 26
Domaindeep-ai-guard.store
aptespionagemalware
High
68
Jun 9, 26
IP166.62.100.52
aptc2espionage
High
68
Jun 9, 26
Domainjuxihawqvgc89.click
aptespionagemalware
High
68
Jun 9, 26
Domainmonade.online
aptespionagemalware
High
68
Jun 9, 26
IP166.62.100.62
c2exploitmalware
High
68
Jun 9, 26
SHA256c7a24e1fc68b7233e1c93c02409e9429a1ea5cf0662eb4cd03364373df7d7044
aptespionagefile-hash
High
86
Jun 9, 26
Domaindeepseek-v4.io
malwarenetwork
High
68
Jun 9, 26
SHA1b5307ec889aa246a417a216e74c1ded2dc73a90b
aptespionagefile-hash
High
68
Jun 9, 26
IP38.225.209.122
malwarenetworkproxy
High
68
Jun 9, 26
SHA25670f732e98634c3f887d84ba8acb1ee7b62e4f865ea4cb1be1edf32c40c27ae51
aptespionagefile-hash
High
68
Jun 9, 26
Domainnjixzni.com
aptespionagemalware
High
68
Jun 9, 26
Domainai-deepseel.com.cn
malwarenetwork
High
68
Jun 9, 26
Domaincontactpredicttogether.ink
aptespionagemalware
High
68
Jun 9, 26
Domaindeepseekcoder.github.io
malwarenetwork
High
68
Jun 9, 26
Domainmailpredicttogether.ink
aptespionagemalware
High
68
Jun 9, 26
Domaindeepseekl.com.cn
malwarenetwork
High
68
Jun 9, 26
Domainloydfst.com
aptespionagemalware
High
68
Jun 9, 26
Domainid37093.com
aptespionagemalware
High
68
Jun 9, 26
IP144.172.115.177
aptespionagemalware
High
68
Jun 9, 26
Domainlorettostorage.com
aptespionagemalware
High
68
Jun 9, 26
Domainggl.rongtv.xyz
malwarenetworkstealer
High
68
Jun 9, 26
Domainayxfaga.com
aptespionagemalware
High
68
Jun 9, 26
Domaincsai.hkinfosecurity.com
aptespionagemalware
High
68
Jun 9, 26
Domainondofinance.tech
aptespionagemalware
High
68
Jun 9, 26
Domaindeepseeksr1.com
malwarenetwork
High
68
Jun 9, 26
Domaintoknportl.pro
malwarenetwork
High
68
Jun 9, 26
Domainvalorecuiting.online
aptespionagemalware
High
68
Jun 9, 26
Domainapricotfilepoint.com
loadermalwarenetwork
High
68
Jun 9, 26
Domainsndvol32.com
malwarenetwork
High
68
Jun 9, 26
Domainnxlog.tech
aptespionagemalware
High
68
Jun 9, 26
Domainogbxtmj.com
aptespionagemalware
High
68
Jun 9, 26
Domainculyrax.us
aptespionagemalware
High
68
Jun 9, 26
IP144.172.108.248
aptespionagemalware
High
68
Jun 9, 26
SHA25651e1f3a97629e8db50ca1f9a0b68c019e74c07ce5209d5eefd4a2e3f4fe62869
aptespionagefile-hash
High
86
Jun 9, 26
Domainnlf.rongtv.xyz
malwarenetworkstealer
High
68
Jun 9, 26
Domaincareerpredictto.space
aptespionagemalware
High
68
Jun 9, 26
Domainfilerubycompass.com
malwarenetwork
High
68
Jun 9, 26
Domainmkhygqxasfc.click
aptespionagemalware
High
68
Jun 9, 26
Domainrecruiterlogon.company
aptespionagemalware
High
68
Jun 9, 26
SHA18411cad93376bdb02f98da035700c235f620d1de
file-hashloadermalware
High
68
Jun 9, 26
Domainbugnol.com
aptespionagemalware
High
68
Jun 9, 26
Domainhorizonfilevalley.com
malwarenetwork
High
68
Jun 9, 26
Domainalphanonega.org
aptespionagemalware
High
68
Jun 9, 26
IP216.126.237.200
aptespionagemalware
High
68
Jun 9, 26
Domainhyperdevpipline.org
aptespionagemalware
High
68
Jun 9, 26
SHA1d2e0c229cca80850419a9bdf76fc3e5d91e1f3dc
file-hashmalwarestealer
High
68
Jun 9, 26
Domainmail.reuniao21.admescolassistema.com
aptespionagemalware
High
68
Jun 9, 26
Domainchat.51mitu.com
malwarenetwork
High
68
Jun 9, 26
SHA17e78a49979639dfe77b5d5a8b3f4d01a78f1c307
file-hashmalwarestealer
High
68
Jun 9, 26
Domainpmrejwb.com
aptespionagemalware
High
68
Jun 9, 26
SHA15f7f7941277efd085a67f6eefa9a260684b3b229
file-hashmalware
High
68
Jun 9, 26
Domaindgxcybe.com
aptespionagemalware
High
68
Jun 9, 26
Domainmigadyn.info
aptespionagemalware
High
68
Jun 9, 26
Domaincontacttrixauvex.ink
aptespionagemalware
High
68
Jun 9, 26
Domaindeepseekcn.cyou
malwarenetwork
High
68
Jun 9, 26
Domainoptixauvex.us
aptespionagemalware
High
68
Jun 9, 26
Domainwuxi.trs668.cc
aptespionagemalware
High
68
Jun 9, 26
SHA256322b2eb4e4d61ec6a746e3da421e8fd9c62ce4f919f03aed373f663de539b2ba
aptespionagefile-hash
High
68
Jun 9, 26
Domaindpzhhdj.com
aptespionagemalware
High
68
Jun 9, 26
IP144.172.108.225
aptespionagemalware
High
68
Jun 9, 26
SHA15cf1b3a83f7d3eb43168c7bb6ded1d9d4b30e000
aptespionagefile-hash
High
68
Jun 9, 26
Domaindeepseekplus.cc
malwarenetwork
High
68
Jun 9, 26
Domaindeepseekem.com
malwarenetwork
High
68
Jun 9, 26
SHA1d9f3a50786280e277cba76ec85dc3dc3bc77f955
aptespionagefile-hash
High
68
Jun 9, 26
Domainscanwallet-pump.fun
malwarenetwork
High
68
Jun 9, 26
Domaintoknportl.space
aptespionagemalware
High
68
Jun 9, 26
Domainssffaa19.xyz
malwarenetworkstealer
High
68
Jun 9, 26
Domainai-kit.cn
malwarenetwork
High
68
Jun 9, 26
Domainch-deepseek.com.cn
malwarenetwork
High
68
Jun 9, 26
Domainpredicttogetherrecruit.store
aptespionagemalware
High
68
Jun 9, 26
Domaindeepseekapp.cc
malwarenetwork
High
68
Jun 9, 26
Domainceronetwork.org
aptespionagemalware
High
68
Jun 9, 26
Domaincrestpoints.it.com
aptespionagemalware
High
68
Jun 9, 26
Domainpinnacle-labs.lat
malwarenetwork
High
68
Jun 9, 26
Domainnemesistrade.work
aptespionagemalware
High
68
Jun 9, 26
Domainrecruitvex.us
aptespionagemalware
High
68
Jun 9, 26
Domaincareertrixauvex.ink
aptespionagemalware
High
68
Jun 9, 26
Domaindsai.cc
malwarenetwork
High
68
Jun 9, 26
Domainelsavora.us
aptespionagemalware
High
68
Jun 9, 26
Domainai.deepseekem.com
malwarenetwork
High
68
Jun 9, 26
IP216.126.225.243
aptbotnetespionage
High
86
Jun 9, 26
Domainattachfile.verymad.net
aptespionagemalware
High
68
Jun 9, 26
Domaindezertir.com
aptespionagemalware
High
68
Jun 9, 26
Domainsofort-gelds.com
aptespionagemalware
High
68
Jun 9, 26
Domaindeepseekweb.cc
malwarenetwork
High
68
Jun 9, 26
SHA1fb45a2b4ebaee87f1e53bc58ac3afabb63da9070
file-hashmalwarestealer
High
68
Jun 9, 26

IOC Relationship Graph

IOC Relationship Graph249 total IOCs
SHA1DomainIPSHA256URL
Domain191SHA127IP21SHA2569URL1Actors2Malware5REPORTMaltrail IOC for 2026-06-0LockBitPlayLockBitLummaMetasploitPlayVidar
scroll to zoom · drag to pan · click IOC to open