ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain campanha1-api.ef971a42.workers.dev.

Database Entry


IOC ID:1807819
IOC: campanha1-api.ef971a42.workers.dev
IOC Type :domain
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is moderate (49%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-05-06 20:53:16 UTC
Last seen:never
UUID:83316768-4973-11f1-8759-42010aa4000a
Reporter johannes
Reward 5 credits from ThreatFox
Tags:TCLBANKER
Reference: https://www.elastic.co/security-labs/tclbanker-brazilian-banking-trojan

Avatar
johannes
domain-name TCLBanker, from the Elasticsearch report "TCLBANKER: Brazilian Banking Trojan Spreading via WhatsApp and Outlook". See all IOC from that report at https://rosti.dev/reports/VWNtaMVI