ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain mnsm.us.com.

Database Entry


IOC ID:1776773
IOC: mnsm.us.com
IOC Type :domain
Threat Type :payload_delivery
Malware: NodeRAT
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS215439 PLAY2GO-NET
Country:- RU
First seen:2026-03-26 14:58:59 UTC
Last seen:never
UUID:ee643d44-2920-11f1-9af6-42010aa4000a
Reporter Lenny_3BO
Reward 5 credits from ThreatFox
Reference: https://www.virustotal.com/gui/file/84802194859b530dcb8e374b7970912f6a27ff5e97f2bec509e59b2dffcc6146

Avatar
Lenny_3BO
MSI delivery via msiexec path traversal. WiX MSI drops batch loader + AES-256-CBC encrypted Node.js polling implant. Build 0422d2e2. Downloads Node.js v18.17.0 as LOLBin.