Skip to main content

Unknown Loader

Malware Family

11 142 indicators of compromise attributed to Unknown Loader across abuse.ch threat intelligence feeds.

Domains

10 691

IPs

37

URLs

137

Hashes

277

Download indicators

Indicator lists for this family. Free and anonymous downloads are a 10% sample.

Need continuous updates instead of static lists? The same IOCs ship in the STIX/TAXII threat feed, ready for OpenCTI and MISP.

Threat types

Botnet C&CCredit-Card SkimmerpayloadPayload Delivery

Associated CVEs (1)

Sample indicators

IndicatorType
jhafinancial.comdomain
granite4less.infodomain
vhncare.comdomain
ta-vani.comdomain
wigreports.comdomain
hhsta.comdomain
studycampus.orgdomain
asparpharmaceuticals.comdomain
pacs-shop.dedomain
lubov-georgievna.kiev.uadomain
mayconnect.ytdomain
adatewithhoney.comdomain
shumou.comdomain
bbeautyurbanspa.comdomain
komakdon.comdomain
digitaldesktopwallpaper.comdomain
murilloconstructionhomes.comdomain
gyorsnyomtatas.hudomain
6lovesports.comdomain
realestatevideophotopros.comdomain
120.237.147.54ip
43.240.223.126ip
124.223.33.239ip
202.112.238.106ip
80.96.59.233ip
155.102.136.155ip
163.181.46.129ip
147.45.67.141ip
147.124.202.194ip
173.211.106.164ip
147.124.213.232ip
147.124.215.131ip
147.124.212.125ip
216.250.252.163ip
216.250.252.103ip
82.25.63.146ip
87.120.219.207ip
107.182.130.226ip
94.156.152.24ip
140.233.190.106ip
https://merabs.pro/fb5fff92.exeurl
https://drive.google.com/uc?export=download&id=1CjSD0JhJj42n2yygv_75tmpvl6Uqic4ourl
https://bnsbackend.mydevsystems.com/redirecturl
https://pub-22c5fb19472741eba9206c96fcd10f9c.r2.devurl
https://checkfivem.com/runtime/VC_redist.x64.exeurl
http://202.61.138.81:443/?h=202.61.138.81&p=443&t=tcp&a=w64&stage=trueurl
https://sis.adkfarmerdan.comurl
https://rqharrrm.6np5ya.cc/DvbkeHjsj307qwg5odb48qjzp/cenmhueskkouuuxurl
https://clipvale.dex9taren.in.net/05fe317c-0981-4de2-bc8a-930d369db441/ck-3d80df5d12cdfe6450a782fc87bf66b444.googleurl
http://66.179.30.146:443/?h=66.179.30.146&p=443&t=tcp&a=w32&stage=trueurl
http://94.103.1.175/hidbqweiuybdf2836hifwoHADES/ijfcdbhjnidefarpgjbiuearhjgui9wehj38725yhfeehj.ps1url
https://nq82x0a.69mcg8.cc/Daid9H57z60z6lm5ajkp83cjq/swknnpwogegeurl
https://use-claude.com/install.ps1url
https://merabs.pro/703520a5.exeurl
http://178.132.198.200/ldr.shurl
http://43.246.210.160:443/?h=43.246.210.160&p=443&t=tcp&a=w32&stage=trueurl
https://merabs.pro/8dd99b31.exeurl
https://ub0io4.6hayo1.cc/DzovgHmxyw03d1j5d3498wov7/vhadqagyqndxvurl
https://merabs.pro/234097cf.exeurl
https://4qztty.66uc4x.cc/D6bfqH2bso0o71854a2v8hsyd/fpeixmdqwpipvcrhkhaurl

Another file to check? Run a file hash reputation check.