🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://raw.githubusercontent.com/vangguardadomorrisseyney32/dust-0001/main/d.txt.

Database Entry


IOC ID:1153439
IOC: https://raw.githubusercontent.com/vangguardadomorrisseyney32/dust-0001/main/d.txt
IOC Type :url
Threat Type :payload_delivery
Malware: FAKEUPDATES
Malware alias:FakeUpdate, GhoLoader, SocGholish
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS54113 FASTLY
Country:- DE
First seen:2023-09-04 05:20:53 UTC
Last seen:never
UUID:31e02de4-49e0-11ee-9416-42010aa4000a
Reporter monitorsg
Reward 5 credits from ThreatFox
Tags:ClearFake

Avatar
monitorsg
hXXps://raw.githubusercontent[.]com/vangguardadomorrisseyney32/dust-0001/main/d.txt (Injected) --> hXXps://owkdzodqzodqjefjnnejenefe[.]site/vvmd54/ --> hXXps://ewkekezmwzfevwvwvvmmmmmmwfwf[.]site/ZgbN19Mx (Keitaro) --> hXXps://ewkekezmwzfevwvwvvmmmmmmwfwf[.]site/lander/chrome/_index.php (landing) --> hXXps://stats-best[.]site/fp.php (fingerprint) --> hXXps://ydlo9a.dm.files.1drv[.]com (download)