ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain support-onion.club.

Database Entry


IOC ID:1807817
IOC: support-onion.club
IOC Type :domain
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is moderate (49%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-05-06 20:53:15 UTC
Last seen:never
UUID:7b11d249-4973-11f1-8759-42010aa4000a
Reporter johannes
Reward 5 credits from ThreatFox
Tags:NWHStealer
Reference: https://www.malwarebytes.com/blog/threat-intel/2026/05/attackers-adopt-javascript-runtime-bun-to-spread-nwhstealer

Avatar
johannes
Bun Loader server, from the Malwarebytes report "Attackers adopt JavaScript runtime Bun to spread NWHStealer". See all IOC from that report at https://rosti.dev/reports/AfhkGZ5q