ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain jsonapi.biz.

Database Entry


IOC ID:1797077
IOC: jsonapi.biz
IOC Type :domain
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is moderate (49%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-04-24 08:50:31 UTC
Last seen:never
UUID:0ed75c45-3fb9-11f1-8759-42010aa4000a
Reporter johannes
Reward 5 credits from ThreatFox
Tags:KYCShadow
Reference: https://www.cyfirma.com/research/kycshadow-an-android-banking-malware-exploiting-fake-kyc-workflows-for-credential-and-otp-theft/

Avatar
johannes
From the CYFIRMA report "KYCShadow: An Android Banking Malware Exploiting Fake KYC Workflows for Credential and OTP Theft". See all IOC from that report at https://rosti.dev/reports/f5sUeLBX