ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://wexlunto.top/session/realm-response.php.

Database Entry


IOC ID:1780076
IOC: https://wexlunto.top/session/realm-response.php
IOC Type :url
Threat Type :payload_delivery
Malware: SmartApeSG
Malware alias:HANEYMANEY, ZPHP
Confidence Level : Confidence level is high (100%)
Is compromised? : True
ASN:AS395092 SHOCK-1
Country:- US
First seen:2026-04-01 12:18:30 UTC
Last seen:never
UUID:2c7b86d8-2dbb-11f1-9af6-42010aa4000a
Reporter monitorsg
Reward 5 credits from ThreatFox
Tags:SmartApeSG
Reference: https://infosec.exchange/@monitorsg/116329134250426228

Avatar
monitorsg
hXXps://cpajoliette[.]com/meta.google.com (injected) --> hXXps://wexlunto[.]top/session/version-header.js --> hXXps://wexlunto[.]top/session/realm-response.php --> hXXps://wexlunto[.]top/session/login-stylesheet.js (clickfix) --> hXXps://pelgiron[.]com/v1/user/py (HTA)