ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain port-air.nikolaiit.work.

Database Entry


IOC ID:1803909
IOC: port-air.nikolaiit.work
IOC Type :domain
Threat Type :payload_delivery
Malware: ClearFake
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-05-02 05:24:58 UTC
Last seen:2026-05-01 19:11:13 UTC
UUID:8225ebbd-4591-11f1-8759-42010aa4000a
Reporter Gi7w0rm
Reward 10 credits from anonymous
Tags:1May2026 ClearFake Commandline Windows