🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain nrfusleio.cloud.

Database Entry


IOC ID:1561400
IOC: nrfusleio.cloud
IOC Type :domain
Threat Type :payload_delivery
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2025-07-27 21:35:45 UTC
Last seen:2025-09-09 11:18:16 UTC
UUID:a7307eab-6b31-11f0-851c-42010aa4000a
Reporter HuntYethHounds
Reward 5 credits from ThreatFox

Avatar
HuntYethHounds
Currently directs victims to Lumma Stealer payloads hosted on mega.nz

hxxps[:]//mega[.]nz/file/C9BUGJwA#8SWriF4NeO50eZsya-dQRiRnhib8TpKXzKIkNKFDu9o
hxxps[://]mega[.]nz/file/0BQDESIB#Y6Lyx5KSf5TxAUtQoYylhV1pMtTSyTGCF6OoOf--dcY
hxxps[://]mega[.]nz/file/TgplHK6L#JgqApJA7wqHoT5hh_dowH17FlPtAJTWf6GPg1yv18N4
hxxps[://]mega[.]nz/file/JYwhgCBa#edpWh0AIhT0SBnrUOmMuCvW1SeSkl7FJF2diXaR_h0o