IOC Radar
TLP:WHITE137 IOCs

The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign

SE
Securelist
Published July 1, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREarma-reforger.comdefendercontrol.downl…defendercontrol.appCAPABILITYAsyncRATVICTIMunknown
Adversary
Infrastructure(6)
Capability(1)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise137

TypeIndicatorConfidenceScoreFirst Seen
Domainarma-reforger.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domaindefendercontrol.download
exploitintel-blogloader
High
58
Jul 1, 26
MD554025ce2a9405039899fe99a1d77e0bb
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domaindefendercontrol.app
exploitintel-blogmalware
High
58
Jul 1, 26
Domaincloudsynn.com
exploitintel-blogmalware
High
58
Jul 1, 26
MD5a85a5bfdcb7c65ab93043b8cf9e20065
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainapexlegends.org
exploitintel-blogmalware
High
58
Jul 1, 26
URLhttps://fileget.loseyourip.com/obs-studio-windows-full/gVOMs5VZ9BtlcaM
aptespionageintel-blog
High
58
Jul 1, 26
Domaincpuz.app
exploitintel-blogmalware
High
58
Jul 1, 26
Domainlossless-scaling.download
exploitintel-blogmalware
High
58
Jul 1, 26
MD501325880efffec546f59490089a3b415
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
MD5776dfd3df9c04bb9fcdd6c1880c3761a
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainkm-player.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domainwinservec.net
exploitintel-blogmalware
High
58
Jul 1, 26
Domainkms-tools.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domaintmodloader.pro
exploitintel-blogloader
High
58
Jul 1, 26
Domainvlc-player.net
exploitintel-blogmalware
High
58
Jul 1, 26
Domainantimicrox.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domainprocesshacker.app
exploitintel-blogmalware
High
58
Jul 1, 26
Domaindownload-full-version.ooguy.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainlossless-scaling.online
exploitintel-blogmalware
High
58
Jul 1, 26
Domainfile-download-crosshairx.giize.com
exploitintel-blogmalware
High
58
Jul 1, 26
MD5bd05fcf80e493cf9aa71ec510319469d
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainr.manage-server.xyz
exploitintel-blogmalware
High
58
Jul 1, 26
Domaintmodloader.download
exploitintel-blogloader
High
58
Jul 1, 26
Domainready-ornot.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainvlc-media.net
exploitintel-blogmalware
High
58
Jul 1, 26
MD5edff4f58722c93d7c09ed71899416396
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainferdium.app
exploitintel-blogmalware
High
58
Jul 1, 26
MD55b7e1fe55bd7b5ea54bd4ed1677e5a26
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainglary-utilities.com
exploitintel-blogmalware
High
58
Jul 1, 26
MD59a9ccd8b0e5d05f4ee77667b024844db
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainbandicam.io
exploitintel-blogmalware
High
58
Jul 1, 26
Domainkm-player.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainmgba.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domainbandizip.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domaindeadreset.com
exploitintel-blogmalware
High
58
Jul 1, 26
MD55f96c04e3afae97017b201be112284d2
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domaincrystaldiskmark.dev
exploitintel-blogmalware
High
58
Jul 1, 26
Domainmgba.app
exploitintel-blogmalware
High
58
Jul 1, 26
Domaintmodloader.app
exploitintel-blogloader
High
58
Jul 1, 26
Domaincrystaldiskmark.app
exploitintel-blogmalware
High
58
Jul 1, 26
MD573bead922109a61e5f9f85771a7812c5
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainstudio-obs.net
exploitintel-blogmalware
High
58
Jul 1, 26
Domainsteamtools.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domaincrusader-kings.church
exploitintel-blogmalware
High
58
Jul 1, 26
Domaincrystaldiskmark.cc
exploitintel-blogmalware
High
58
Jul 1, 26
Domaincrosshairx.site
exploitintel-blogmalware
High
58
Jul 1, 26
Domainmediaplayerclassic.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domaincrosshair-x.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainlibreoffice.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domaingom-player.net
exploitintel-blogmalware
High
58
Jul 1, 26
Domainbandicam.cc
exploitintel-blogmalware
High
58
Jul 1, 26
Domainferdium.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domainds4windows.io
exploitintel-blogmalware
High
58
Jul 1, 26
Domainlossless-scaling.app
exploitintel-blogmalware
High
58
Jul 1, 26
Domainmgba.dev
exploitintel-blogmalware
High
58
Jul 1, 26
Domainds4windows.net
exploitintel-blogloader
High
58
Jul 1, 26
Domainr.servermanagemen.xyz
aptespionageintel-blog
High
58
Jul 1, 26
Domainwallpaper-engine.app
exploitintel-blogmalware
High
58
Jul 1, 26
Domainmonster-hunterwilds.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainlosslessscaling.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domainstudioobs.com
exploitintel-blogmalware
High
58
Jul 1, 26
MD5999a63730c9634481d1d76955a2e76a8
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainvlc-media.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainclair-obscur-33.town
exploitintel-blogmalware
High
58
Jul 1, 26
Domainfernbus-simulator.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainovr-toolkit.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainarksurvival-ascended.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainall-toll-free.publicvm.com
exploitintel-blogmalware
High
58
Jul 1, 26
IP2.59.134.97
aptespionageintel-blog
High
58
Jul 1, 26
Domainmanagedevice.xyz
exploitintel-blogmalware
High
58
Jul 1, 26
Domainmanageserver.xyz
exploitintel-blogmalware
High
58
Jul 1, 26
MD58f4e8b680d3e8d3f5ac39bd72882f713
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainbandicam.app
exploitintel-blogmalware
High
58
Jul 1, 26
Domainprocesshacker.org
exploitintel-blogmalware
High
58
Jul 1, 26
Domainstudioobs.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domainds4windows.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domaindefendercontrol.pro
exploitintel-blogmalware
High
58
Jul 1, 26
IP162.216.241.242
intel-blogmalwarenetwork
High
58
Jul 1, 26
Domaindns-jumper.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domaincrystaldiskmark.io
exploitintel-blogmalware
High
58
Jul 1, 26
Domainservermanagemen.xyz
aptespionageintel-blog
High
58
Jul 1, 26
Domaincpuz.pro
exploitintel-blogmalware
High
58
Jul 1, 26
MD51e6a5c7b620d487d0cfc6874c3b77c90
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainantimicrox.net
exploitintel-blogmalware
High
58
Jul 1, 26
Domaintmodloader.org
exploitintel-blogloader
High
58
Jul 1, 26
Domaindefendercontrol.org
exploitintel-blogmalware
High
58
Jul 1, 26
Domaincorel-draw.net
exploitintel-blogmalware
High
58
Jul 1, 26
Domaingom-player.app
exploitintel-blogmalware
High
58
Jul 1, 26
Domaincrosshairx2.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainpingserv.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domainbandizip.net
exploitintel-blogmalware
High
58
Jul 1, 26
Domaintmod-loader.com
exploitintel-blogloader
High
58
Jul 1, 26
Domainprocesshacker.dev
exploitintel-blogmalware
High
58
Jul 1, 26
Domainehostservers.xyz
exploitintel-blogmalware
High
58
Jul 1, 26
Domainovr-advanced-settings.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainclair-obscur-33.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domaindnsjumper.app
exploitintel-blogmalware
High
58
Jul 1, 26
MD58e4c57358a66eb14d31abb614ddc68de
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainstudio-obs.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domainobs-studio.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domaincrystaldiskmark.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domaindefender-control.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainkms-tools.net
exploitintel-blogmalware
High
58
Jul 1, 26
URLhttps://direct-download.giize.com/dns-jumper/iopbsr4hymbo7nfa1q7j
exploitintel-blogmalware
High
58
Jul 1, 26
Domainelden-ringnightreign.com
exploitintel-blogmalware
High
58
Jul 1, 26
MD583601c3d4ed28e8d2be1b99beb8ec18c
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainmpc-update.giize.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainmediaplayerclassic.net
exploitintel-blogmalware
High
58
Jul 1, 26
Domainall-toll-free.loseyourip.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domaincrusader-kings.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainprocesshacker.net
exploitintel-blogmalware
High
58
Jul 1, 26
URLhttps://www.studioobs.com/
exploitintel-blogmalware
High
58
Jul 1, 26
Domainsteamtools.cc
exploitintel-blogmalware
High
58
Jul 1, 26
Domainobs-studio.site
exploitintel-blogmalware
High
58
Jul 1, 26
Domaincrosshairxv2.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domainedgeserv.ru
intel-blogmalwarenetwork
High
58
Jul 1, 26
IP45.145.41.205
exploitintel-blogmalware
High
58
Jul 1, 26
MD587603ea025623b19954e460add532048
aptespionagefile-hash
Medium
53
Jul 1, 26
Domainlosslessscaling.app
exploitintel-blogmalware
High
58
Jul 1, 26
Domaindnsjumper.io
exploitintel-blogloader
High
58
Jul 1, 26
MD5a40d3aeb0dae5b00bdb3a517f3135bbb
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
MD5479bd3bb617b39cd4a46d0768a2592d4
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainpingpanl.pro
exploitintel-blogmalware
High
58
Jul 1, 26
Domainserverdnsplan.net
exploitintel-blogmalware
High
58
Jul 1, 26
Domainfree-download.camdvr.org
exploitintel-blogmalware
High
58
Jul 1, 26
Domaindnsjumper.pro
exploitintel-blogmalware
High
58
Jul 1, 26
MD50eee9bad07e22415439e854657fa1366
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainmora1987.work.gd
aptc2espionage
High
64
Jul 1, 26
MD5b32810973132d11afd61ccee222bbb79
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
Domainstudio-obs.com
exploitintel-blogmalware
High
58
Jul 1, 26
Domaincrosshairx.pro
exploitintel-blogmalware
High
58
Jul 1, 26
MD5695e794631ef130583368770e7b81e98
exploitfile-hashintel-blog
Medium
53
Jul 1, 26
IP198.23.185.81
intel-blogmalwarenetwork
High
58
Jul 1, 26
Domaincrosshairx.net
exploitintel-blogmalware
High
58
Jul 1, 26
IP185.254.97.249
exploitintel-blogmalware
High
58
Jul 1, 26

IOC Relationship Graph

IOC Relationship Graph137 total IOCs
DomainMD5URLIP
Domain108MD521IP5URL3Malware1REPORTThe SOC Files: ScreenConneAsyncRAT
scroll to zoom · drag to pan · click IOC to open