ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://beroniw.com/hwkOP5.

Database Entry


IOC ID:1834080
IOC: https://beroniw.com/hwkOP5
IOC Type :url
Threat Type :payload_delivery
Malware: NetSupportManager RAT
Malware alias:NetSupport
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-06-19 11:36:35 UTC
Last seen:2026-06-19 11:13:41 UTC
UUID:971b5d9b-6bca-11f1-9258-42010aa4000a
Reporter alpaco
Reward 5 credits from ThreatFox
Tags:ClickFix FakeCaptcha NetSupport powershell

Avatar
alpaco
ClickFix → NetSupport RAT chain. beroniw.com/hwkOP5 = fake CAPTCHA + clipboard hijack (navigator.clipboard.writeText). 91.92.34.228/test22.txt = fileless NetSupport dropper (stage 3). Reached via injected data: URI loader on a compromised WordPress site.