ThreatFox IOC Database
You are viewing the ThreatFox database entry for url https://api.jsonsilo.com/public/0d332804-985c-4fc9-bcb4-d6089c3eace3.
Database Entry
| IOC ID: | 1956264 |
|---|---|
| IOC: | https://api.jsonsilo.com/public/0d332804-985c-4fc9-bcb4-d6089c3eace3 |
| IOC Type : | url |
| Threat Type : | payload_delivery |
| Malware: | ContagiousDrop |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS13335 CLOUDFLARENET |
| Country: | US |
| First seen: | 2026-10-07 10:38:15 UTC |
| Last seen: | never |
| UUID: | cf111354-c238-11f1-bd13-42010aa4000a |
| Reporter | |
| Reward | 5 credits from ThreatFox |
| Tags: | ContagiousInterview vscode vscode-tasks-folderOpen |
| Reference: | https://www.microsoft.com/en-us/security/blog/2026/03/11/contagious-interview-malware-delivered-through-fake-developer-job-interviews/ |
Dethanc
Second-stage domains for Contagious Interview attack - interviewee is asked to clone repo that contains tasks.json, which auto-runs code in VSCode. This code harvests local credentials and sends them to malicious domains, which then respond with additional code to be executed on the compromised machine.A second payload in these repos triggers when the application is started, at which point these URLs are called to carry out a similar procedure.
US