IOC Radar
TLP:WHITE54 IOCs

Maltrail IOC for 2026-06-11

CO
CIRCL OSINT Feed
Published June 11, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTURE65.21.96.129wwxik2s.topjiugui22.comCAPABILITYLummaVidarVICTIMunknown
Adversary
Infrastructure(6)
Capability(2)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise54

TypeIndicatorConfidenceScoreFirst Seen
SHA2567b03fb383a5ce784a3cb9b0f8a76a84e984d14e553de5d98faff3d07d9793085
file-hashmalwarestealer
High
68
Jun 11, 26
SHA13c2f5bddea4103e962b36726f2834cc8c64f1ba0
aptespionageexploit
High
68
Jun 11, 26
SHA1ecf3a4dc48d24114e106ecf6de6e0f12e89a97e1
aptespionageexploit
High
68
Jun 11, 26
IP65.21.96.129
malwarenetworkstealer
High
68
Jun 11, 26
Domainwwxik2s.top
malwarenetwork
High
68
Jun 11, 26
Domainjiugui22.com
malwarenetworkrat
High
68
Jun 11, 26
SHA1f7c0ad302c64ba5a204772f825c6402b7b9fdb3c
file-hashmalwarestealer
High
68
Jun 11, 26
SHA1edd9ef8608bebc5c8948ff07100f6ef46fa09190
file-hashmalwarestealer
High
68
Jun 11, 26
Domainoxdo.xyz
aptespionagemalware
High
68
Jun 11, 26
SHA1e6dcdd819144f27dd90f986ba9d07b4db4a58a02
aptespionagefile-hash
High
68
Jun 11, 26
Domainimbyter.com
malwarenetwork
High
68
Jun 11, 26
Domaindatasecure-service.vercel.app
aptespionageexploit
High
68
Jun 11, 26
IP163.245.220.108
aptespionagemalware
High
68
Jun 11, 26
Domaincdn.ytrtyab.icu
malwarenetwork
High
68
Jun 11, 26
IP204.10.194.239
malwarenetwork
High
68
Jun 11, 26
SHA15a14d790a9ba314b5ece2111b40eb8d106fb7389
file-hashmalware
High
68
Jun 11, 26
Domainak.wwxik2s.top
malwarenetwork
High
68
Jun 11, 26
URLhttps://mp.weixin.qq.com/s/jH60_sYtZjJZWtVc5d277g
aptespionagemalware
High
68
Jun 11, 26
SHA1bd2a70c2c18803ba4d3c43c4212fe86853d6e3d4
file-hashmalwarestealer
High
68
Jun 11, 26
SHA11899bf672dcbfbd75cfd1d436db5eead7a3fffa1
aptespionagefile-hash
High
68
Jun 11, 26
SHA1859051f9a5b0fbc8ec8473a84fd53b04bb3004b1
file-hashmalware
High
68
Jun 11, 26
Domainvscode-ip-address-checking.vercel.app
aptespionageexploit
High
68
Jun 11, 26
Domainmicronsoftwares.com
malwarenetworkstealer
High
68
Jun 11, 26
SHA186d74a40f342cf9d04b00df2b1a4319cd6f939da
file-hashmalware
High
68
Jun 11, 26
SHA1959f5ed026a208d895d3e95589cfa63b75e56be1
aptespionageexploit
High
68
Jun 11, 26
Domaincloudflare1.vercel.app
aptespionageexploit
High
68
Jun 11, 26
Domaincdn.zeqfge.icu
malwarenetworkstealer
High
68
Jun 11, 26
SHA1cac5c21b0c2630cec988ce50dee69466ccc5e24c
file-hashmalware
High
68
Jun 11, 26
Domaincolesms.top
malwarenetwork
High
68
Jun 11, 26
SHA1c1138ed0d2bb5745191ebacaf3710c03a7ae5418
aptespionagefile-hash
High
68
Jun 11, 26
Domaindownloadclouddata.com
aptespionagemalware
High
68
Jun 11, 26
Domainvscode-ip-checking-nine.vercel.app
aptespionageexploit
High
68
Jun 11, 26
SHA19a51200f3b90c7af54c220f2526db6f36d63294d
aptespionageexploit
High
68
Jun 11, 26
IP8.218.196.168
malwarenetworkrat
High
68
Jun 11, 26
Domaincostumes-met-zum-refinance.trycloudflare.com
aptespionagemalware
High
68
Jun 11, 26
IP38.60.224.210
malwarenetwork
High
68
Jun 11, 26
Domainpublic.mexc.co.com
malwarenetworkstealer
High
68
Jun 11, 26
SHA1c5a822cd8783de9363ff8e504528da5a08f515ca
file-hashmalwarerat
High
68
Jun 11, 26
SHA256adff46b9cdccb4c75b3b8a236b3c799e4d6184a3d8ada97bf7f076db20102165
file-hashmalwarestealer
High
68
Jun 11, 26
IP149.104.87.94
malwarenetwork
High
68
Jun 11, 26
Domainblog.imbyter.com
malwarenetwork
High
68
Jun 11, 26
Domaincolor.imbyter.com
malwarenetwork
High
68
Jun 11, 26
SHA121269b305abd633d1278097eace5015dec234fda
file-hashmalwarerat
High
68
Jun 11, 26
SHA1e89fc8cacba42f5b8d037a10946cbe76e4bf44ed
file-hashmalware
High
68
Jun 11, 26
SHA13a666616b48662049435aa6a4e3c5eda123b9cf7
file-hashmalware
High
68
Jun 11, 26
Domaingomezdown.cc
malwarenetwork
High
68
Jun 11, 26
Domainproemre.space
aptespionageexploit
High
68
Jun 11, 26
SHA14bdf5fc99069086b6b93c180d1d63707fa2841e4
file-hashmalwarestealer
High
68
Jun 11, 26
SHA256446aad1d86aaf82a32f7e63bd0dd34cb2ac85ca2a412b9bea2122fb5506ddac1
file-hashmalwarerat
High
86
Jun 11, 26
SHA2568f7cbdf63a7d08ffc2035a80886081798ce77b519b514eea574781bb54120125
botnetfile-hashmalware
High
86
Jun 11, 26
Domainhelloworld-sub.pages.dev
aptespionagemalware
High
68
Jun 11, 26
IP192.3.16.34
malwarenetworkstealer
High
68
Jun 11, 26
IP104.234.18.91
botnetmalwarenetwork
High
76
Jun 11, 26
IP64.89.162.159
malwarenetworkrat
High
68
Jun 11, 26

IOC Relationship Graph

IOC Relationship Graph54 total IOCs
SHA256SHA1IPDomainURL
Domain21SHA119IP9SHA2564URL1Malware2REPORTMaltrail IOC for 2026-06-1LummaVidar
scroll to zoom · drag to pan · click IOC to open