> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# IOC Alert: Suspicious Paste Site Used for Payload Delivery
- URL: https://darkwebinformer.com/ioc-alert-suspicious-paste-site-used-for-payload-delivery/
- Published: 2025-09-29T18:04:46.000Z
- Updated: 2025-09-29T18:04:46.000Z
- Author: Dark Web Informer
- Tags: IOC

## 📖 Overview

A domain-based indicator has been flagged as associated with potential payload delivery activity. The site masquerades as a paste service but has been observed in malicious campaigns. Confidence is assessed at 100%.

---

## 📌 Key Details

| Field           | Information                                                                                                              |
| --------------- | ------------------------------------------------------------------------------------------------------------------------ |
| **Type**        | Domain                                                                                                                   |
| **Indicator**   | paste.c-net\[.\]org                                                                                                      |
| **Threat Type** | Payload Delivery                                                                                                         |
| **Malware**     | Unknown                                                                                                                  |
| **Confidence**  | 100%                                                                                                                     |
| **Date**        | 29 Sep 2025 – 16:31:01 UTC                                                                                               |
| **Tags**        | None                                                                                                                     |
| **Reporter**    | abuse\_ch                                                                                                                |
| **Reference**   | [MalwareBazaar Sample](https://bazaar.abuse.ch/sample/f7d46c07ea06e9b2def9a048c58d8f2608842d055f69515755e7fb5e5d9fdeab/) |

---

## 🔎 URLScan Result

- **Verdict Score:** 0
- **Page Title:** No Title
- **Screenshot:** [View Screenshot](https://urlscan.io/screenshots/0199955a-a68f-7317-a64b-7eb7ca0bdb7d.png)
- **Result:** [Full Scan Report](https://urlscan.io/result/0199955a-a68f-7317-a64b-7eb7ca0bdb7d/)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/09/8762348762348961864758162-2.jpg)

---

## 📡 Domain & Certificate Info

- **DNS A Record:** 20\[.\]100\[.\]184\[.\]134

---

## 📡 Related Intelligence

- **Certificate Transparency:** [crt.sh Report](https://crt.sh/?q=paste.c-net.org)
- **VirusTotal Report:** [VirusTotal Domain Report](https://www.virustotal.com/gui/domain/paste.c-net.org)
- **URLScan Domain Overview:** [urlscan.io Domain Page](https://urlscan.io/domain/paste.c-net.org)
- **DNS Analytics:** [dnslytics.com Report](https://dnslytics.com/domain/paste.c-net.org)

---

## 🛡️ Defensive Guidance

- Block **paste.c-net\[.\]org** and associated IP (**20\[.\]100\[.\]184\[.\]134**) at DNS, proxy, and endpoint layers.
- Monitor for attempts to fetch payloads or scripts from paste services in your network traffic.
- Incorporate this domain into threat hunting queries focused on suspicious HTTP(S) requests to paste-style platforms.
- Track new infrastructure by monitoring similar domains in certificate transparency logs.

---

⚠️ This IOC highlights the continued abuse of **pastebin-like services** for payload delivery, often used by attackers to distribute malware in a low-profile manner.