download.cyberlearn.academy
Classification: Suspicious
download.cyberlearn.academy is a suspicious hostname. Linked to Cobalt Strike, Avaddon malware. Reported by 2 threat sources, last seen 2026-07-09.
Current activity
- Offline — no longer resolving. Last online 2026-08-24 14:28:37.
- Command & Control server — Used by cybercriminals to control victim computers.
- Malware distribution — This indicator is distributing malware.
MITRE ATT&CK associations
Malware families: COBALT STRIKE (S0154) AVADDON (S0640) ASYNCRAT (S1087) MAZE (S0449)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Maltiverse Threat Observatory | 2026-02-07 19:10:06 | 2026-07-09 16:05:15 | anomalous-activity botnet country_code:br country_code:do industry:education-and-nonprofits industry:financial-services industry:professional-services | |
| Maze | Triage | 2026-07-09 15:47:41 | 2026-07-09 15:47:41 | malicious-activity | S0449 Maze |
| Asyncrat | Maltiverse Threat Observatory | 2026-03-11 22:10:07 | 2026-06-11 04:15:20 | anomalous-activity country_code:br country_code:ec country_code:us industry:education-and-nonprofits industry:professional-services industry:technology-and-telecommunications malware | S1087 AsyncRAT |
| Asyncrat | Triage | 2026-03-11 21:32:40 | 2026-06-11 03:15:46 | malicious-activity | S1087 AsyncRAT |
| Avaddon | Triage | 2026-05-02 18:45:09 | 2026-05-02 18:45:09 | malicious-activity | S0640 Avaddon |
| Malicious URL | Triage | 2026-03-04 12:26:10 | 2026-03-18 00:01:55 | malicious-activity | |
| Cobalt strike | Maltiverse Threat Observatory | 2026-03-13 14:05:09 | 2026-03-13 14:15:09 | anomalous-activity country_code:br country_code:ec country_code:us industry:education-and-nonprofits industry:professional-services industry:technology-and-telecommunications malware | S0154 Cobalt Strike |
| Cobalt Strike | Triage | 2026-03-13 13:30:56 | 2026-03-13 13:30:56 | malicious-activity | S0154 Cobalt Strike |
| Metasploit | Triage | 2026-02-07 18:50:38 | 2026-02-07 18:50:38 | malicious-activity |
Tags
metasploit backdoor discovery trojan asyncrat venom clients rat cobaltstrike 0 execution persistence ransomware avaddon adware spyware maze credential_access defense_evasion impact stealerIP addresses resolved by this hostname
- 172.64.80.1 (2026-08-16 13:09:35)
- 2606:4700:130:436c:6f75:6466:6c61:7265 (2026-08-16 13:09:35)
Whois information
- Domain
- cyberlearn.academy
- TLD
- academy
- First indexed
- 2026-02-07 18:55:12
- Last updated
- 2026-08-24 14:28:37