Skip to content Dark Web Informer - Cyber Threat Intelligence
IOC

IOC Alert: Suspicious Paste Site Used for Payload Delivery

📖 Overview

A domain-based indicator has been flagged as associated with potential payload delivery activity. The site masquerades as a paste service but has been observed in malicious campaigns. Confidence is assessed at 100%.


📌 Key Details

FieldInformation
TypeDomain
Indicatorpaste.c-net[.]org
Threat TypePayload Delivery
MalwareUnknown
Confidence100%
Date29 Sep 2025 – 16:31:01 UTC
TagsNone
Reporterabuse_ch
ReferenceMalwareBazaar Sample

🔎 URLScan Result


📡 Domain & Certificate Info

  • DNS A Record: 20[.]100[.]184[.]134


🛡️ Defensive Guidance

  • Block paste.c-net[.]org and associated IP (20[.]100[.]184[.]134) at DNS, proxy, and endpoint layers.
  • Monitor for attempts to fetch payloads or scripts from paste services in your network traffic.
  • Incorporate this domain into threat hunting queries focused on suspicious HTTP(S) requests to paste-style platforms.
  • Track new infrastructure by monitoring similar domains in certificate transparency logs.

⚠️ This IOC highlights the continued abuse of pastebin-like services for payload delivery, often used by attackers to distribute malware in a low-profile manner.

Latest