ThreatFox IOC Database
You are viewing the ThreatFox database entry for domain yrvbhsjni.cloud.
Database Entry
This IOC expired
This IOC is an old IOC and hence has expired on 2026-09-13 01:15:01 UTC. We therefore refrain from exporting it into our datasets. As a result, this database entry is purely informational and has no impact.
| IOC ID: | 1561469 |
|---|---|
| IOC: | yrvbhsjni.cloud |
| IOC Type : | domain |
| Threat Type : | payload_delivery |
| Malware: | Unknown malware |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS13335 CLOUDFLARENET |
| Country: | US |
| First seen: | 2025-07-27 21:35:46 UTC |
| Last seen: | 2025-09-09 11:18:18 UTC |
| UUID: | a8272035-6b31-11f0-851c-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
HuntYethHounds
Currently directs victims to Lumma Stealer payloads hosted on mega.nzhxxps[:]//mega[.]nz/file/C9BUGJwA#8SWriF4NeO50eZsya-dQRiRnhib8TpKXzKIkNKFDu9o
hxxps[://]mega[.]nz/file/0BQDESIB#Y6Lyx5KSf5TxAUtQoYylhV1pMtTSyTGCF6OoOf--dcY
hxxps[://]mega[.]nz/file/TgplHK6L#JgqApJA7wqHoT5hh_dowH17FlPtAJTWf6GPg1yv18N4
hxxps[://]mega[.]nz/file/JYwhgCBa#edpWh0AIhT0SBnrUOmMuCvW1SeSkl7FJF2diXaR_h0o
US