IOC Radar
TLP:WHITE15 IOCs

Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years

SE
Securelist
Published May 28, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREqdmagva5.spaceurush1bar4.online107.172.212.235CAPABILITYXMRigVICTIMunknown
Adversary
Infrastructure(6)
Capability(1)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise15

TypeIndicatorConfidenceScoreFirst Seen
Domainqdmagva5.space
c2intel-blogmalware
High
58
Jun 2, 26
Domainurush1bar4.online
intel-blogmalwarenetwork
High
58
Jun 2, 26
IP107.172.212.235
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domainzgj1tam9.space
c2intel-blogmalware
High
58
Jun 2, 26
MD502a43b3423367b9dddc24cc7dfc070df
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainjeaw520i.space
c2intel-blogmalware
High
58
Jun 2, 26
Domainkristina.quest
exploitintel-blogmalware
High
58
Jun 2, 26
MD50123456789abcdef0123456789abcdef
file-hashintel-blogmalware
Medium
53
Jun 2, 26
MD56a0fe6065d76715feebc1526d456db73
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainr7mvjl67.space
c2intel-blogmalware
High
58
Jun 2, 26
MD5000102030405060708090a0b0c0d0e0f
file-hashintel-blogmalware
Medium
53
Jun 2, 26
MD57f624407ae489324e96a708a09c17e6f
exploitfile-hashintel-blog
Medium
53
Jun 2, 26
Domainm4yuri.online
exploitintel-blogmalware
High
58
Jun 2, 26
Domain5d14vnfb.space
intel-blogmalwarenetwork
High
58
Jun 2, 26
Domainfile.ipfs.us.69.mu
intel-blogmalwarenetwork
High
58
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph15 total IOCs
DomainIPMD5
Domain9MD55IP1Malware1REPORTPirates in the crosshairs:XMRig
scroll to zoom · drag to pan · click IOC to open