ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://chinasite.com.br/MSI_180922.png.

Database Entry


IOC ID:1776542
IOC: https://chinasite.com.br/MSI_180922.png
IOC Type :url
Threat Type :payload_delivery
Malware: XpertRAT
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS47583 AS-HOSTINGER
Country:- LT
First seen:2026-03-26 06:49:39 UTC
Last seen:never
UUID:76e9afd3-28c0-11f1-9af6-42010aa4000a
Reporter Lenny_3BO
Reward 5 credits from ThreatFox
Tags:emoji-obfuscation vbs XpertRAT
Reference: https://www.virustotal.com/gui/file/62ca5642b20c9155e148a3a8535f69efc139fe78cd5d48a070a58c908d077618

Avatar
Lenny_3BO
Stage 1 .NET loader disguised as PNG. Downloaded by VBS dropper (62ca5642) via PowerShell. Hosted on compromised Brazilian website (Hostinger).