Maltrail IOC List Analysis - June 1, 2026
This brief analyzes a Maltrail IOC list from June 1, 2026, identifying domains and IP addresses associated with various malware and threat actors, including android_fvncbot, lummac2, magentocore, sectoprat, apt_lazarus, offloader, android_joker, cyberstrikeai, and nightshadec2, potentially used for command and control, malware distribution, or phishing campaigns.
This brief examines a set of indicators of compromise (IOCs) published by CIRCL-MISP in their Maltrail feed on June 1, 2026. The IOCs consist of domains and IP addresses identified as potentially malicious. These indicators are associated with various malware families and threat actors, including android_fvncbot, lummac2, magentocore, sectoprat, apt_lazarus, offloader, android_joker, cyberstrikeai, and nightshadec2. While the specific campaigns or malware variants employing these indicators are not detailed, the broad association with known threat actors and malware families suggests potential command and control (C2) infrastructure, malware distribution networks, or phishing campaign infrastructure. Defenders should proactively monitor for these indicators in network traffic and DNS logs to identify potential compromise.
Attack Chain
Given the nature of the IOCs, the following attack chain is inferred:
- Initial Access: The attacker may gain initial access through various methods, such as phishing emails, drive-by downloads, or exploiting vulnerabilities in public-facing applications.
- Malware Delivery: Upon successful initial access, the attacker deploys malware onto the compromised system. This malware may be delivered directly or through a multi-stage process using droppers or loaders.
- Command and Control (C2) Communication: The malware establishes communication with a C2 server, often using the domains listed in the IOCs. This communication allows the attacker to remotely control the compromised system.
- Persistence: The attacker establishes persistence on the compromised system to maintain access even after reboots or system updates.
- Lateral Movement: The attacker attempts to move laterally within the network, compromising additional systems and escalating privileges.
- Data Exfiltration: The attacker identifies and exfiltrates sensitive data from the compromised network to a remote server controlled by the attacker.
- Final Objective: Depending on the attacker’s motives, the final objective may include data theft, financial gain (e.g., ransomware), espionage, or disruption of services.
- Infrastructure Hardening: The attacker may use infrastructure such as the domains and IPs to facilitate ongoing attacks and evade detection.
Impact
The successful deployment of malware and establishment of C2 communication can lead to significant damage. This can include data breaches, financial losses, reputational damage, and disruption of critical services. The variety of threat actors and malware families associated with these IOCs suggests a broad range of potential impacts, from targeted attacks by APT groups like Lazarus to widespread malware infections.
Recommendation
- Monitor network traffic and DNS queries for connections to the domains listed in the IOC table to identify potential C2 communication or malware activity.
- Block the IP addresses listed in the IOC table at the firewall to prevent communication with known malicious hosts.
- Deploy the Sigma rule “Detect Outbound Connection to Maltrail IOC” to identify potential C2 communication based on connections to the identified domains and IPs.
- Investigate any systems communicating with the identified IOCs to determine the extent of the compromise and take appropriate remediation steps.
- Implement robust endpoint detection and response (EDR) solutions to detect and prevent malware infections.
Detection coverage 2
Detect Outbound Connection to Maltrail IOC - Domain
mediumDetects outbound network connections to domains identified in the Maltrail IOC list.
Detect Outbound Connection to Maltrail IOC - IP Address
mediumDetects outbound network connections to IP addresses identified in the Maltrail IOC list.
Detection queries are available on the platform. Get full rules →
Indicators of compromise
28
domain
12
ip
10
url
| Type | Value |
|---|---|
| url | https://api.github.com/repos/stamparm/maltrail/commits/484a67f82c9fb6aee55dfbbe865032e4b3c81fda |
| domain | bbople.icu |
| domain | cdn.yybane.icu |
| domain | erggan.icu |
| domain | uunuyi.icu |
| url | https://api.github.com/repos/stamparm/maltrail/commits/2b9b6ebebaecced2a25887a8cf51a9f1694d50ce |
| domain | hardsmi.cyou |
| url | https://api.github.com/repos/stamparm/maltrail/commits/2057cc51864653becaf294ed2f4c36035dd70384 |
| domain | fbclickgo.win |
| domain | fbids.com |
| url | https://api.github.com/repos/stamparm/maltrail/commits/8cd965be64c35bc228b269bcaa2bf34c2098ea55 |
| ip | 188.137.254.82 |
| ip | 193.233.82.76 |
| ip | 89.124.108.104 |
| ip | 89.124.99.84 |
| url | https://api.github.com/repos/stamparm/maltrail/commits/b1b1344523bb6d1dbaa289536850160ad3fa76e0 |
| ip | 147.124.211.143 |
| ip | 147.124.212.178 |
| ip | 147.124.212.180 |
| ip | 147.124.212.207 |
| ip | 176.9.174.137 |
| ip | 37.48.102.17 |
| ip | 45.43.11.214 |
| ip | 66.235.168.158 |
| url | https://api.github.com/repos/stamparm/maltrail/commits/80f920f0722b5e0119e623a821bf8ca87d57e468 |
| domain | crowddaughter.info |
| domain | quarterants.xyz |
| domain | supportbottle.info |
| domain | volcanosisters.xyz |
| url | https://api.github.com/repos/stamparm/maltrail/commits/db96fead13ebcfdce283f6c938561ab5222d7c36 |
| domain | cepeek.yoga |
| url | https://api.github.com/repos/stamparm/maltrail/commits/366a806dc553ea1a326db541ce4bac4dc5c3e6d5 |
| domain | maxoria.cyou |
| domain | sraspadinhagratuito2026.cyou |
| url | https://api.github.com/repos/stamparm/maltrail/commits/0b35c7b4b34c4899425eab70294fb1c141ab8efa |
| url | https://app.validin.com/detail?find=edc16e04a8ca23706e25&type=hash&ref_id=b74105f13c2#tab=host_pairs |
| domain | a9v8p0.cloudmellow.cc |
| domain | adjust-work.cc |
| domain | adjust-work.help |
| domain | adjust-work.one |
| domain | adjust-work.qpon |
| domain | adjust-work.rest |
| domain | b9r8y5.laseo.top |
| domain | circuitcoiltech.com |
| domain | cloudmellow.cc |
| domain | emjratezdraw.com |
| domain | flavorforgekitchencom.com |
| domain | getaivira.com |
| domain | homelabss.com |
| domain | laseo.top |