disobey-curly.sbs
Classification: Suspicious
disobey-curly.sbs is a suspicious hostname. Linked to Lumma Stealer malware. Reported by 2 threat sources, last seen 2025-07-04.
Current activity
- Offline β no longer resolving. Last online 2025-10-06 19:22:22.
- Command & Control server β Used by cybercriminals to control victim computers.
- Malware distribution β This indicator is distributing malware.
MITRE ATT&CK associations
Malware families: LUMMA STEALER (S1213)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Lumma stealer | Maltiverse Threat Observatory | 2024-11-26 15:10:05 | 2025-07-04 14:10:07 | country_code:br industry:education-and-nonprofits | S1213 Lumma Stealer |
| Lumma Stealer | ThreatFox Abuse.ch | 2024-11-26 14:17:10 | 2025-01-08 21:20:28 | malicious-activity | S1213 Lumma Stealer |
Tags
lumma lummac2 stealer c2 domain virustotalIP addresses resolved by this hostname
- 172.64.80.1 (2024-11-26 14:17:12)
Whois information
- AS name
- AS13335 Cloudflare, Inc.
- Domain
- disobey-curly.sbs
- TLD
- sbs
- City
- San Francisco
- State
- CA
- Country
- US β United States πΊπΈ
- First indexed
- 2024-11-26 14:17:10
- Last updated
- 2026-07-14 03:00:36