ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain u888az.dev.

Database Entry


IOC ID:1815557
IOC: u888az.dev
IOC Type :domain
Threat Type :payload_delivery
Malware: ClearFake
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-05-17 15:52:59 UTC
Last seen:never
UUID:5b770ea6-51c6-11f1-b930-42010aa4000a
Reporter Anonymous
Reward 10 credits from anonymous
Tags:ClearFake Windows

Avatar
Anonymous
Domain identified as a suspected malware payload delivery infrastructure associated with ClearFake-style malware distribution activity.

IOC: u888az.dev

Evidence indicates the domain has been linked to malicious payload delivery and malware-related infrastructure observed in public threat intelligence sources, including VirusTotal relations and malware distribution telemetry.

Observed malware family:
- Trojan.MSIL/NanoCore
- Fake update / ClearFake-style delivery behavior

Additional context:
- The domain has been reported and flagged by multiple security vendors.
- Associated samples show command-and-control and payload delivery characteristics.
- Infrastructure appears intended for malicious distribution rather than legitimate services.

Public references:
https://www.virustotal.com/gui/domain/u888az.dev
https://www.virustotal.com/gui/file/7040c257931841f708e69e647106ac8b727c1f04d5542a55d2eeee5aa190be19/relations

SHA1:
8337d754d3cc60cd9aba164f77084931ffb505a1

MD5:
17cd2f1f43986a3f3851dfeed2343b7e