ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://unifiedmotionworks.com/paul.

Database Entry


IOC ID:1808848
IOC: https://unifiedmotionworks.com/paul
IOC Type :url
Threat Type :payload_delivery
Malware: SmartApeSG
Malware alias:HANEYMANEY, ZPHP
Confidence Level : Confidence level is high (100%)
Is compromised? : True
ASN:AS395092 SHOCK-1
Country:- US
First seen:2026-05-08 14:14:22 UTC
Last seen:never
UUID:d3a94afe-4ae7-11f1-8759-42010aa4000a
Reporter monitorsg
Reward 5 credits from ThreatFox
Tags:SmartApeSG
Reference: https://infosec.exchange/@monitorsg/116539357902512792

Avatar
monitorsg
hXXps://mezcalpro[.]com/scq (injected) --> hXXps://primegridhub[.]top/refresh/redirect-hook.js --> hXXps://primegridhub[.]top/refresh/verify-parser.php --> hXXps://primegridhub[.]top/refresh/dashboard-bundle.js (clickfix) --> hXXp://178[.]156.241.213 (Powershell) --> hXXp://5[.]78.87.19 (Powershell) --> hXXps://unifiedmotionworks[.]com/paul (ZIP)