Scam Detective
Domain

45.135.194.23.ptr.pfcloud.network

First seen Feb 28, 2026

High Risk
  • Flagged by Google Safe Browsing
  • No SSL certificate

Campaign Intelligence

This cluster centers on 2451 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include cdn.discordapp.com, 91.92.241.152, 91.92.240.222, 158.94.208.174, 178.16.52.44, 158.94.211.102, 158.94.210.93, 158.94.208.52, i.postimg.cc, s3.us-east-2.amazonaws.com, storage.googleapis.com, 178.16.52.18, 158.94.211.101, 158.94.211.100, local-host.life, dropmefiles.com, limewire.com, 62.60.226.159, id8965.com, valfanto.com and 2431 more. 633 of these domains have been flagged by threat int...

This cluster centers on 679 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include ziaintegracion.com, three.s3.cubbit.eu, tradingmastery.info, chinasite.com.br, 185.241.208.90, sgv.app.br, bafybeidv6v7pezugmfpzwl2k2ni56nhvlyv5vaibriswtsthae5loxskpi.ipfs.dweb.link, openlineseguros.com.br, bafybeiccl6irsru52xsyiuy4pqlitflw4f57xovkfpk5w2wnhtmeaqpjuy.ipfs.dweb.link, pub-ee57b144a43f41809d8fab6adf01d8b6.r2.dev, one-graup.com, www.teslasuit.to, alzapdigoo.net, bafybeibwz6lzwo6u...

This cluster centers on 645 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include talentaclub.com, bafybeihamvbzrm2tsifa4s7xruhfnsgnkzgtk2jqwj6cwgmdxj4wqe5lm4.ipfs.dweb.link, okullu.com, dmaii.co, 87.120.219.222, fertas.com.tr, www.pastebin.cz, repost.punto-viva.info, community.gtst.gr, baritonclick.online, 96.44.159.218, floneimf.ydns.eu, sbstorage.cfd, 96.44.159.250, globalipgeneratings.com, 96.44.154.195, msidownloads.duckdns.org, 94.154.32.49, www.almacensantangel.com...

This cluster centers on 683 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include server.admirableskreen.top, ssagntroplexa.com, 136.0.213.249, pub-aa4b4a4b76964ef7b9e03a074612353a.r2.dev, post-host.screenconnect.com, 195.177.94.100, stajestetice.top, no.windowupdateservice.com, 94.154.32.89, wesneet.it.com, themaintechnician.us, 192.158.232.90, pub-563376bbe356408a8c67e226123a6095.r2.dev, ov.uqoo.nl, fidels.b-cdn.net, 31.57.147.191, 94.154.32.198, start-review-myacc.com,...

This cluster centers on 662 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include 192.210.186.208, 176.65.139.42, rewardhunt.xyz, arilprivate.storexyz.web.id, 185.252.24.15, staying-heavily-meaning-blowing.trycloudflare.com, creations-venture-traditional-stainless.trycloudflare.com, 5.61.40.97, 156.233.71.230, 195.16.44.75, 192.3.101.19, 87.120.219.222, 206.123.145.26, file.garden, 192.210.186.220, aviator-chek.online, 18.194.67.137, 34.58.195.70, 171.25.158.78, advise-vi...

This cluster centers on 2957 connected domains tagged as GuLoader, NorthKorea, censys. The domains include salelegalsteroids.com, 192.210.186.208, gharnt.com, cloflart.com, id3702579photo-image-docs.com, www.almacensantangel.com, 64.95.12.162, blue-oceans.net, sixmexicos.com, baritonclick.online, 185.252.24.15, un1rw11q4u.com, ameyiando.com, niril.sbs, bursaelektriktamir.com, blankeyeo.com, umxtxhub.za.com, sunchernical.com, 18.194.67.137, servecdn.my and 2937 more. 606 of these domains have bee...

This cluster centers on 662 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include 9103843.duckdns.org, coolcams.duckdns.org, www.neronpidaras.it.com, affectionate-easley.121-127-34-164.plesk.page, neronpidaras.it.com, arilprivate.storexyz.web.id, 84920433.duckdns.org, bobnet.exiled.fit, www.0837234.duckdns.org, www.92031819.duckdns.org, 0837234.duckdns.org, www.r34fa352.duckdns.org, docsfakegen.com, objective-roentgen.121-127-34-164.plesk.page, mailserver.ccsnetwork.cn, e...

This cluster centers on 673 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include repost.punto-viva.info, anondrop.net, openclaw.official-version.com, 45.59.113.84, visual.trueblog.sbs, rizvexeno.ws, lunhx.onters.sbs, www.sunamien.jp, getryos.com, lunt.revio.live, lunq.revio.live, uc450c98c4c09a1c00cf0340baec.dl.dropboxusercontent.com, qploits.online, lunme.onters.sbs, visuall.trueblog.sbs, lunqv.hollower.sbs, lunhx.hollower.sbs, uc3132c9008b1e5420b76bdaf758.dl.dropboxuse...

This cluster centers on 687 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include lunq.revio.live, qploits.online, getryos.com, deusxeno.ws, visuals.trueblog.sbs, visual.trueblog.sbs, visuall.trueblog.sbs, lunqv.hollower.sbs, lungx.hollower.sbs, lunhx.onters.sbs, lunt.revio.live, lunme.onters.sbs, lun.marvek.live, lunhx.hollower.sbs, visualls.trueblog.sbs, lunts.hollower.sbs, rizvexeno.ws, 45.59.113.84, vaultx.lol, defragglerupdate.com and 667 more. 687 of these domains h...

This cluster centers on 649 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include lunme.onters.sbs, lungx.hollower.sbs, lun.marvek.live, lunt.revio.live, lunq.revio.live, lunts.hollower.sbs, lunqv.hollower.sbs, lunhx.onters.sbs, lunhx.hollower.sbs, mytaxclientcopy.com, file-herunterladen.site, 62.133.62.176, 194.156.102.210, 45.225.187.6, 2.192.102.162, transfer.weepee.io, 109.205.213.2, pastee.dev, easyhostweb.com, heavens-gate.top and 629 more. 649 of these domains have...

This cluster centers on 654 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include id3702579photo-image-docs.com, 188.137.254.207, qploits.online, 185.182.82.13, app.enekora.com, 80.89.238.200, 45.131.182.242, keitarocheats.com, 80.89.237.190, qsve.cyrd.live, shop.pestodo.de, getryos.com, 103.27.157.144, 45.131.182.252, 188.137.229.136, 188.137.252.155, 188.137.224.92, bf-chromefdghd.oss-cn-hongkong.aliyuncs.com, sgnfyn.oss-cn-shenzhen.aliyuncs.com, www.irbis2000.com and 6...

This cluster centers on 2107 connected domains tagged as GuLoader, NorthKorea, censys. The domains include storage.googleapis.com, cdn.discordapp.com, pastes.io, s3.us-east-2.amazonaws.com, dl.dropboxusercontent.com, 188.137.230.45, touchskins.io, 158.94.208.7, 74.0.32.149, 74.0.32.141, api.touchskins.io, 80.89.237.190, 188.137.254.207, api.wewpwsw.su, 188.137.229.136, 196.251.107.24, 104.194.152.180, link.storjshare.io, s3.g.s4.mega.io, 62.60.226.159 and 2087 more. 562 of these domains have bee...

This cluster centers on 2121 connected domains tagged as GuLoader, NorthKorea, censys. The domains include 59.182.90.199, 178.50.166.61, 113.168.249.76, 123.209.193.86, 113.165.6.38, 120.157.72.234, 171.235.194.253, 120.157.159.171, 37.142.77.163, 46.124.33.133, 46.124.40.3, 83.224.151.243, 88.86.246.233, 41.146.1.154, 59.182.119.128, 14.236.247.68, 120.157.72.59, 95.127.248.192, 116.110.179.199, cdn.discordapp.com and 2101 more. 576 of these domains have been flagged by threat intelligence feed...

This cluster centers on 2141 connected domains tagged as GuLoader, NorthKorea, censys. The domains include 59.182.90.199, 91.80.129.100, 123.28.175.23, 120.61.247.2, 178.50.166.61, 113.168.249.76, 123.209.193.86, 113.165.6.38, 120.157.72.234, 171.235.194.253, 120.157.159.171, 37.142.77.163, 171.241.208.124, 120.157.229.220, 171.117.30.233, 91.80.136.9, 46.124.33.133, 46.124.40.3, 83.224.151.243, 88.86.246.233 and 2121 more. 596 of these domains have been flagged by threat intelligence feeds incl...

This cluster centers on 2559 connected domains tagged as GuLoader, NorthKorea, trojan. The domains include 83.224.148.34, 14.236.247.68, 120.157.72.59, 95.127.248.192, 116.110.179.199, 116.101.73.68, 95.127.250.241, 152.173.199.182, 91.80.129.100, 59.88.45.188, 117.216.5.20, 182.60.11.164, 41.146.14.165, 120.157.46.38, 59.182.90.199, 113.168.249.76, 78.132.114.25, 171.241.208.124, 120.157.229.220, 14.236.84.25 and 2539 more. 640 of these domains have been flagged by threat intelligence feeds inc...

Details

Safe Browsing
malware
First Seen
2/28/2026

Related Domains

Community Reports

No community reports yet. Be the first to share your experience.

Share Your Experience

What's Your Exposure?

Know your risk exposure to this message with a Thorough Analysis. It returns a detailed report covering the complaint history, your data breach exposure, related scam entities, and risk signals tied to this email message. Check the box and enter your email address now.