ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain mohadm.sw.so.

Database Entry


IOC ID:1778771
IOC: mohadm.sw.so
IOC Type :domain
Threat Type :botnet_cc
Malware: Evilginx
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS55293 A2HOSTING
Country:- US
First seen:2026-03-30 06:21:11 UTC
Last seen:never
UUID:b3657d84-2bbc-11f1-9af6-42010aa4000a
Reporter Lenny_3BO
Reward 5 credits from ThreatFox

Avatar
Lenny_3BO
Evilginx AiTM phishing domains targeting Okta SSO. Found on AS210558 (1337 Services / rdp.sh). Subdomains include okta.*, sso.*, account.*, login.* patterns.