hyperforge.digital
Classification: Malicious
hyperforge.digital is a malicious hostname. Linked to Lumma Stealer malware. Reported by 1 threat source, last seen 2025-04-29.
Current activity
- Online — resolving/reachable. Last checked 2026-09-21 12:33:59.
- Command & Control server — Used by cybercriminals to control victim computers.
MITRE ATT&CK associations
Malware families: LUMMA STEALER (S1213)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Lumma Stealer | ThreatFox Abuse.ch | 2025-04-27 12:12:12 | 2025-04-29 12:25:57 | malicious-activity | S1213 Lumma Stealer |
Tags
domain lumma lumma stealer stealer lummac2 stealerIP addresses resolved by this hostname
- 104.21.48.203 (2025-04-27 17:24:10)
- 172.67.156.45 (2025-04-27 17:24:10)
- 172.64.80.1 (2025-04-29 09:25:46)
- 40.91.108.115 (2026-09-21 12:33:59)
Whois information
- Domain
- hyperforge.digital
- TLD
- digital
- DNSSEC
- ['unsigned, Unsigned']
- Nameservers
- decker.ns.cloudflare.com, ainsley.ns.cloudflare.com
- Registrant
- PDR Ltd. d/b/a PublicDomainRegistry.com
- Address
- REDACTED, Eliseevskaya
- City
- REDACTED, Krasnojarsk
- State
- Krasnojarskiy kray
- Country
- RU — Russian Federation 🇷🇺
- Contact email
- [email protected], [email protected], [email protected]
- Domain created
- 2025-04-09 19:14:23
- Domain expires
- 2026-04-09 19:14:23
- First indexed
- 2025-04-27 12:17:08
- Last updated
- 2026-09-21 12:33:59