🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://idealvgtrens.com/cloud/x/6157/.

Database Entry


IOC ID:1888215
IOC: https://idealvgtrens.com/cloud/x/6157/
IOC Type :url
Threat Type :payload_delivery
Malware: Lumma Stealer
Malware alias:LummaC2 Stealer
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS33837 PRQ-AS
Country:- SE
First seen:2026-08-26 12:52:10 UTC
Last seen:never
UUID:a820a023-a14c-11f1-9e13-42010aa4000a
Reporter Sir_XX
Reward 5 credits from ThreatFox
Tags:credential-phishing Fake-Captcha google-sites-lure m365

Avatar
Sir_XX
M365 credential phishing kit (not Lumma - no matching family in ThreatFox for phishing kits). Lure via Google Sites impersonating CMA CNC-Mechanik AG. Fake Cloudflare CAPTCHA gate, obfuscated M365 login clone, creds POSTed to server.php. Infra: 88.80.17.227 PRQ/AS33837.