ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://meetme.norvina.cfd/Goo/Meet/Windows/download.php.

Database Entry


IOC ID:1806056
IOC: https://meetme.norvina.cfd/Goo/Meet/Windows/download.php
IOC Type :url
Threat Type :payload_delivery
Malware: RemoteAdmin
Confidence Level : Confidence level is high (90%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-05-04 17:28:46 UTC
Last seen:never
UUID:8e0a6d26-47d5-11f1-8759-42010aa4000a
Reporter Lenny_3BO
Reward 5 credits from ThreatFox
Tags:clickfix-precursor Cloudflare googlemeet-spoof NICENIC RMM-abuse tiflux

Avatar
Lenny_3BO
Cloudflare-fronted Google Meet brand-spoof URL serving validly-signed TiFlux RMM agent (v2.0.0.82). Operator tenant: org_id=21258, client_id=2251204, token=16d17716-ad7c-4c66-9ac5-6497b3ca5641, C2 agent.tiflux[.]com:443. Bundles UltraVNC MSRC4 mirror driver. Uninstall scrubs RustDesk/Splashtop/TiPeerToPeer.