ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://truecorehub.top/handler/realm-component.js.

Database Entry


IOC ID:1801558
IOC: https://truecorehub.top/handler/realm-component.js
IOC Type :url
Threat Type :payload_delivery
Malware: SmartApeSG
Malware alias:HANEYMANEY, ZPHP
Confidence Level : Confidence level is high (100%)
Is compromised? : True
ASN:AS395092 SHOCK-1
Country:- US
First seen:2026-04-28 16:42:47 UTC
Last seen:never
UUID:13a7b453-42fb-11f1-8759-42010aa4000a
Reporter monitorsg
Reward 5 credits from ThreatFox
Tags:SmartApeSG
Reference: https://infosec.exchange/@monitorsg/116482253949864997

Avatar
monitorsg
hXXps://mezcalpro[.]com/scq (injected) --> hXXps://truecorehub[.]top/handler/status-partial.js --> hXXps://truecorehub[.]top/handler/redirect-server.php --> hXXps://truecorehub[.]top/handler/realm-component.js (clickfix) --> hXXp://185[.]93.221.129 (Powershell) --> hXXp://103[.]20.235.207 (Powershell) --> hXXps://solidnexio[.]com/software/python (ZIP)