🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain gd.tracelic.com.

Database Entry


IOC ID:1956255
IOC: gd.tracelic.com
IOC Type :domain
Threat Type :payload_delivery
Malware: ContagiousDrop
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-10-07 10:38:25 UTC
Last seen:never
UUID:8a244914-c238-11f1-bd13-42010aa4000a
Reporter Dethanc
Reward 5 credits from ThreatFox
Reference: https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/

Avatar
Dethanc
Second-stage domains for Contagious Interview attack - interviewee is asked to clone repo that contains tasks.json, which auto-runs code in VSCode. This code harvests local credentials and sends them to malicious domains, which then respond with additional code to be executed on the compromised machine.

A second payload in these repos triggers when the application is started, at which point these domains are called to carry out a similar procedure.