malware.wicar.org
Classification: Whitelisted
malware.wicar.org is a whitelisted (trusted) hostname. Reported by 6 threat sources, last seen 2026-09-03.
Current activity
- Offline โ no longer resolving. Last online 2026-09-03 01:04:55.
- Malware distribution โ This indicator is distributing malware.
- Stores phishing content โ Phishing resources are hosted here.
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Exploit.generic | Maltiverse Threat Observatory | 2024-08-26 22:20:17 | 2026-09-03 00:21:26 | anomalous-activity country_code:ar country_code:br country_code:ec country_code:gt country_code:us country_code:uy industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:technology-and-telecommunications malicious-activity malware | |
| Exploit.agent | Maltiverse Threat Observatory | 2025-06-17 19:44:25 | 2026-06-28 15:21:36 | anomalous-activity country_code:ar country_code:br country_code:ec country_code:gt country_code:us country_code:uy industry:education-and-nonprofits industry:financial-services industry:healthcare-and-pharmaceutical industry:manufacturing industry:technology-and-telecommunications malicious-activity malware | |
| Malicious behavior | Maltiverse Threat Observatory | 2026-05-05 00:01:24 | 2026-05-05 00:01:24 | country_code:br industry:technology-and-telecommunications | |
| Trojan.downloader | Maltiverse Threat Observatory | 2025-06-17 19:44:25 | 2025-10-15 15:21:36 | country_code:ar country_code:br country_code:ec industry:financial-services industry:manufacturing industry:technology-and-telecommunications | |
| Top Popularity Site | Cisco Umbrella | 2025-08-19 13:47:43 | 2025-08-19 13:47:43 | ||
| Generic Malware | Maltiverse Threat Observatory | 2025-07-09 10:15:23 | 2025-07-11 11:15:07 | ||
| Malware Download | URLhaus Abuse.ch | 2025-04-20 12:06:05 | 2025-04-20 20:13:22 | malicious-activity | |
| Top 1M Site | Cisco Umbrella | 2024-08-19 01:21:25 | 2025-01-06 04:55:28 | benign | |
| Malicious URL | Hybrid-Analysis | 2023-11-09 14:15:06 | 2023-11-09 14:15:06 | ||
| Malicious Hostname | Cyber Threat Coalition | 2020-12-14 06:04:51 | 2021-10-29 08:48:06 | malicious-activity | |
| Malicious url | Cyber Threat Coalition | 2020-12-14 19:13:54 | 2021-03-04 13:02:54 | malicious-activity | |
| Malware | Cyber Threat Coalition | 2020-12-10 08:00:39 | 2021-01-24 08:01:49 | malicious-activity | |
| Covid19 scam | Cyber Threat Coalition | 2020-11-20 23:48:10 | 2020-12-13 19:07:15 | malicious-activity | |
| Malware site | Hybrid-Analysis | 2018-06-22 14:00:28 | 2020-08-14 16:45:14 | ||
| Malicious site | Hybrid-Analysis | 2019-05-13 21:30:06 | 2020-07-16 20:30:18 | ||
| Malicious domain | SANS Internet Storm Center | 2019-12-22 02:34:42 | 2019-12-22 02:34:42 |
Tags
covid19 coronavirus scam phishing 10pluspositivesinvtIP addresses resolved by this hostname
- 208.94.116.21 (2019-12-22 02:34:42)
- 208.94.116.246 (2026-07-28 19:57:52)
- 2607:ff18:80:6::6a08 (2026-07-28 19:57:52)
Whois information
- AS name
- AS40630 GridFury, LLC
- Domain
- wicar.org
- TLD
- org
- DNSSEC
- ['unsigned']
- Nameservers
- ns.phx4.nearlyfreespeech.net, ns.phx5.nearlyfreespeech.net
- Registrant
- PDR Ltd. d/b/a PublicDomainRegistry.com
- Address
- REDACTED
- City
- REDACTED
- State
- NSW
- Country
- AU โ Australia ๐ฆ๐บ
- Contact email
- [email protected]
- Domain created
- 2012-11-07 04:14:52
- Domain expires
- 2026-11-07 04:14:52
- First indexed
- 2018-06-22 14:00:28
- Last updated
- 2026-09-03 01:04:55