NordVPN Promotion

Home / Industry

DNS Footprinting: SourTrade Distributes Unfinished Malware through Malvertising

Confiant recently reported on a campaign where threat actors distributed unfinished malware through SourTrade malvertisements in a bid to defeat file fingerprinting, the most widely used security detection technique today. Active since late 2024, SourTrade has become known for mimicking TradingView, Solana, and Luno to go after retail traders and crypto investors.

The researchers listed 96 network IoCs—all domain names— connected to the threat. We analyzed them all after learning that none were owned by legitimate companies based on the results of our WhoisXML API MCP Server check. Our investigation led to these findings:

  • One client IP address that communicated with a domain IoC
  • Four domain IoCs that appeared in four typosquatting groups
  • 14 domain IoCs that were likely registered with malicious intent
  • 348 email-connected domains, 131 were confirmed malicious
  • 186 IP addresses, 184 were confirmed malicious
  • 728 string-connected domains, five were confirmed malicious

A sample of the additional artifacts obtained from our analysis is available for download from our website.

SourTrade Domain IoC Analysis

We began our investigation by looking more closely at the 96 domain IoCs.

First, sample network traffic data from the IASC revealed that one client IP address communicated with the domain IoC form-networktool[.]digital via two DNS queries made on 7 July 2026.

Based on the results of our Typosquatting Data Feed searches, four of the domain IoCs appeared in four typosquatting groups with 3–4 members each. The typosquatting domains were created between 8 February and 14 May 2026.

Check out more details about the typosquatting groups below.

DOMAIN IoCGROUP NUMBER IDGROUP MEMBER NUMBERGROUP MEMBERS OTHER THAN THE IoCsCREATION DATE
beacon-net[.]digital69333beaconset[.]llc
beaconmeet[.]com
02/08/26
(1 had no date)
form-engine[.]digital65204forgeengine[.]digital
forgeengine[.]net
formsengine[.]app
05/13/26–05/14/26

Our First Watch Malicious Domains Data Feed searches, meanwhile, showed that 14 of the domain IoCs appeared on the feeds 139–207 days before they were dubbed as IoCs. Here are more details for five examples.

DOMAIN IoCFIRST WATCH DATENUMBER OF DAYS BEFORE THE REPORT DATE
asiadataintelligencelab[.]digital12/29/25207
syscodeapi[.]digital01/11/26194
beacon-net[.]digital02/08/26166
insight-radiant[.]digital02/12/26162
acuitycore[.]digital02/17/26157

The domain IoCs that were likely registered with malicious intent were created between 29 December 2025 and 7 March 2026.

After that, we queried the domain IoCs on WHOIS API and discovered that:

  • They were created between 29 December 2025 and 15 June 2026.
  • They were administered by three registrars.

  • They were registered in 12 countries.

DNS Chronicle API queries for the domain IoCs revealed that they all recorded 2,217 historical domain-to-IP resolutions over time. Take a look at more information for five examples below.

DOMAIN IoCNUMBER OF DOMAIN-TO-IP RESOLUTIONSDATES SEEN
dotlor[.]site7603/27/26–07/06/26
nebive[.]site5604/06/26–05/18/26
prolega[.]site8403/23/26–07/25/26
qumoro[.]site6403/26/26–07/10/26
transoe[.]site8803/24/26–07/13/26

Consistent with the domain IoCs’ creation dates, the date of the oldest historical resolution was 29 December 2025. The rest were all posted in 2026.

Search for New SourTrade Artifacts

After knowing more about the IoCs, we began hunting for new artifacts.

First, we queried the domain IoCs on WHOIS History API and found out that 47 had 34 unique public email addresses in their historical records.

We then queried the public email addresses on Reverse WHOIS API and uncovered 348 distinct email-connected domains after those already named as IoCs were filtered out.

Threat Intelligence API queries for the email-connected domains showed that 131 have already been weaponized for various attacks. Here are more details for five examples.

MALICIOUS EMAIL-CONNECTED DOMAINASSOCIATED THREATDATES SEEN
alarde[.]digitalMalware distribution07/28/26–08/09/26
balomboa[.]siteMalware distribution07/28/26–08/09/26
calvexis[.]infoMalware distribution07/28/26–08/09/26
dinexa[.]digitalMalware distribution07/28/26–08/09/26
enterlock[.]digitalMalware distribution07/28/26–08/09/26

Next, we queried the domain IoCs on DNS Lookup API and learned that 95 resolved to 186 distinct IP addresses. Of these, 184 turned out to be malicious according to Threat Intelligence API. Take a look at more information for five examples below.

MALICIOUS ADDITIONAL IP ADDRESSASSOCIATED THREATDATES SEEN
104[.]21[.]0[.]150Malware distribution03/29/23–08/09/26
172[.]67[.]129[.]18Malware distribution
Phishing
Generic threat
03/29/23–08/09/26
07/22/23–08/09/26
05/17/25–08/03/26
104[.]21[.]1[.]243Malware distribution
Phishing
04/03/23–08/09/26
05/25/23–05/28/26
172[.]67[.]129[.]27Malware distribution09/07/24–08/09/26
104[.]21[.]15[.]11Malware distribution
C&C
Generic threat
03/09/23–08/09/26
04/06/23–08/05/26
03/30/23–05/28/26

This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.

NORDVPN DISCOUNT - CircleID x NordVPN
Get NordVPN  [74% +3 extra months, from $2.99/month]
By WhoisXML API, A Domain Research, Whois, DNS, and Threat Intelligence API and Data Provider

Whois API, Inc. (WhoisXML API) is a big data and API company that provides domain research & monitoring, Whois, DNS, IP, and threat intelligence API, data and tools to a variety of industries.

Visit Page

Filed Under

Comments

Commenting is not available in this channel entry.
CircleID Newsletter The Weekly Wrap

More and more professionals are choosing to publish critical posts on CircleID from all corners of the Internet industry. If you find it hard to keep up daily, consider subscribing to our weekly digest. We will provide you a convenient summary report once a week sent directly to your inbox. It's a quick and easy read.

Related

Topics

Brand Protection

Sponsored byCSC

DNS Security

Sponsored byWhoisXML API

DNS

Sponsored byDNIB.com

New TLDs

Sponsored byRadix

Domain Names

Sponsored byVerisign

Cybersecurity

Sponsored byVerisign

IPv4 Markets

Sponsored byIPv4.Global

NordVPN Promotion