officeaddons.com
Classification: Malicious
officeaddons.com is a malicious hostname. Linked to Lazarus Group activity. Reported by 4 threat sources, last seen 2025-01-07.
Current activity
- Online — resolving/reachable. Last checked 2026-09-03 00:38:43.
MITRE ATT&CK associations
Intrusion sets: LAZARUS GROUP (G0032)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Top Popularity Site | Cisco Umbrella | 2023-05-07 06:01:45 | 2025-01-07 08:04:49 | benign | |
| Malicious URL | Hybrid-Analysis | 2024-01-06 01:30:04 | 2024-01-06 03:30:04 | ||
| Unknown malware | ThreatFox Abuse.ch | 2023-03-30 17:57:10 | 2023-04-01 17:19:16 | malicious-activity | |
| Lazarus Group | Maltiverse | 2023-03-31 04:32:45 | 2023-04-01 00:17:38 | malicious-activity | G0032 Lazarus Group |
Tags
3cx smoothoperator supplychainattack aptIP addresses resolved by this hostname
- 3.64.163.50 (2024-09-12 00:49:48)
- 35.186.223.180 (2024-01-20 00:37:34)
- 173.255.204.62 (2023-12-09 04:18:58)
- 45.141.152.19 (2023-10-30 20:11:53)
- 52.20.84.62 (2025-03-14 17:07:57)
- 76.223.54.146 (2025-04-10 00:40:13)
- 13.248.169.48 (2025-04-10 00:40:13)
- 88.85.82.197 (2026-09-03 00:38:43)
Whois information
- Domain
- officeaddons.com
- TLD
- com
- First indexed
- 2023-03-30 18:17:41
- Last updated
- 2026-09-03 00:38:43