> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# IOC Alert: win.netsupportmanager_rat Payload Delivery
- URL: https://darkwebinformer.com/ioc-alert-win-netsupportmanager_rat-payload-delivery/
- Published: 2025-08-28T17:33:24.000Z
- Updated: 2025-09-04T22:19:43.000Z
- Author: Dark Web Informer
- Tags: IOC

📖 **Overview**  
A new URL-based indicator has been identified associated with payload delivery activity tied to the malware *win.netsupportmanager\_rat*. This malicious URL, hosted under the domain **linomu\[.\]com**, masquerades as a legitimate JavaScript resource but instead delivers a remote access trojan with full control capabilities.

---

📌 **Key Details**

| Field           | Information                     |
| --------------- | ------------------------------- |
| **Type**        | URL                             |
| **Indicator**   | linomu\[.\]com/ajax/pixi.min.js |
| **Threat Type** | Payload Delivery                |
| **Malware**     | win.netsupportmanager\_rat      |
| **Confidence**  | 100%                            |
| **Date**        | 28 Aug 2025 – 14:02:09 UTC      |
| **Tags**        | SmartApeSG                      |
| **Reporter**    | monitorsg                       |

---

🔎 **URLScan Result**

- **Page Title:** Home Page
- **Screenshot:** <https://urlscan.io/screenshots/0198f104-03d0-74e7-a2c9-00439dce91e1.png>
- **Result:** <https://urlscan.io/result/0198f104-03d0-74e7-a2c9-00439dce91e1/>

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/08/987461864987126497853689798172-2.jpg)

---

📡 **Related Intelligence**

- **VirusTotal Report:** <https://www.virustotal.com/gui/url-analysis/u-d6003ff5bcebc6d398a9ec864edb9e27579e22f2141e5b22b99b04817420d8ff-1756402617>

---

🛡️ **Defensive Guidance**

- Block `linomu[.]com` at the network and endpoint level.
- Monitor for suspicious script loads from unexpected domains.
- Hunt for *win.netsupportmanager\_rat* persistence artifacts in endpoint telemetry.
- Review proxy/firewall logs for attempted outbound requests to malicious JS payloads.