TROYANOSYVIRUS
Back to domains

nelark.icu

Domain associated with malicious URLs

Domain Detail

Statusactive
Sourceurlhaus
Associated URLs6
First seen3/17/2026, 6:17:11 AM
Last seen3/17/2026, 8:43:54 PM

Associated IPs

None

Related URLs

URLHostStatusThreatDate
https://nelark.icu/xftaswx/res/post_proc.php?fpath=a.ps1nelark.icuofflinemalware_download3/17/2026
https://nelark.icu/xftaswx/res/get-command.phpnelark.icuofflinemalware_download3/17/2026
https://nelark.icu/xftaswx/res/post_proc.php?fpath=bypass.bnelark.icuofflinemalware_download3/17/2026
https://nelark.icu/xftaswx/res/post_proc.php?fpath=bpersist.ps1nelark.icuofflinemalware_download3/17/2026
https://nelark.icu/xftaswx/res/bb.phpnelark.icuofflinemalware_download3/17/2026
https://nelark.icu/xftaswx/res/post_proc.php?fpath=scheduler-oncenelark.icuofflinemalware_download3/17/2026

IOC Correlations

url4eb3dd3bb607e0c731b1d5ef6e0cc57ff34cc4e3c8b1250e21a9c1e8d3860b8cdomainnelark.icuhosted_on
urlab6f865a3b0e7e6cc07ce1a99b0eab277089d8309df688c8a90dbb32d7216c7adomainnelark.icuhosted_on
url9985b63641e1ebdce84efaa476d22fca484ceb3ae52e2f7b68d99e95d2be6eabdomainnelark.icuhosted_on
urle33a7f3e856ac18ce71528a2df9d2f793c8e511a9474dc089d89e9b94f18a02cdomainnelark.icuhosted_on
url90fe35417a2034a8f4cfd5d9de6461317cdc8ac7ae8b714e4ab4d2a7dfcaa17edomainnelark.icuhosted_on
url95989439cac2e6ce61b2d8091f3d4b563a009c9977e057e1abdc01473fc840a6domainnelark.icuhosted_on