🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain ifuqpatr.com.

Database Entry


IOC ID:1892305
IOC: ifuqpatr.com
IOC Type :domain
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS135097 MYCLOUD-AS-AP
Country:- HK
First seen:2026-09-01 06:10:31 UTC
Last seen:never
UUID:e369883b-a5c6-11f1-9e13-42010aa4000a
Reporter 3lias
Reward 5 credits from ThreatFox
Tags:webshell webshell credential-exfiltration WordPress
Reference: https://www.virustotal.com/gui/file/E3DA2973957017A72403531D5475BD95189DFF1C70B23E4657D0D5F23955575E

Avatar
3lias
Domain hardcoded as credential-exfiltration rendezvous in a WordPress admin-creation dropper captured during an in-the-wild 0-day campaign (2026-08-26). The malware creates a covert administrator account and exfiltrates the generated credentials to shop@toph72psed.v2fqr6qyi0.ifuqpatr.com (random-label subdomains, DGA-style mail setup). Sample SHA256: E3DA2973957017A72403531D5475BD95189DFF1C70B23E4657D0D5F23955575E. Delivery vector: unauthenticated arbitrary file upload in WPLP Cookie Consent plugin (patched in 4.4.2). PHP dropper - not sandbox-executable, hence no behavioral contacted-domains data on VT.