|
||
|
||
Confiant recently reported on a campaign where threat actors distributed unfinished malware through SourTrade malvertisements in a bid to defeat file fingerprinting, the most widely used security detection technique today. Active since late 2024, SourTrade has become known for mimicking TradingView, Solana, and Luno to go after retail traders and crypto investors.
The researchers listed 96 network IoCs—all domain names— connected to the threat. We analyzed them all after learning that none were owned by legitimate companies based on the results of our WhoisXML API MCP Server check. Our investigation led to these findings:
A sample of the additional artifacts obtained from our analysis is available for download from our website.
We began our investigation by looking more closely at the 96 domain IoCs.
First, sample network traffic data from the IASC revealed that one client IP address communicated with the domain IoC form-networktool[.]digital via two DNS queries made on 7 July 2026.

Based on the results of our Typosquatting Data Feed searches, four of the domain IoCs appeared in four typosquatting groups with 3–4 members each. The typosquatting domains were created between 8 February and 14 May 2026.

Check out more details about the typosquatting groups below.
| DOMAIN IoC | GROUP NUMBER ID | GROUP MEMBER NUMBER | GROUP MEMBERS OTHER THAN THE IoCs | CREATION DATE |
|---|---|---|---|---|
| beacon-net[.]digital | 6933 | 3 | beaconset[.]llc beaconmeet[.]com | 02/08/26 (1 had no date) |
| form-engine[.]digital | 6520 | 4 | forgeengine[.]digital forgeengine[.]net formsengine[.]app | 05/13/26–05/14/26 |
Our First Watch Malicious Domains Data Feed searches, meanwhile, showed that 14 of the domain IoCs appeared on the feeds 139–207 days before they were dubbed as IoCs. Here are more details for five examples.
| DOMAIN IoC | FIRST WATCH DATE | NUMBER OF DAYS BEFORE THE REPORT DATE |
|---|---|---|
| asiadataintelligencelab[.]digital | 12/29/25 | 207 |
| syscodeapi[.]digital | 01/11/26 | 194 |
| beacon-net[.]digital | 02/08/26 | 166 |
| insight-radiant[.]digital | 02/12/26 | 162 |
| acuitycore[.]digital | 02/17/26 | 157 |
The domain IoCs that were likely registered with malicious intent were created between 29 December 2025 and 7 March 2026.
After that, we queried the domain IoCs on WHOIS API and discovered that:

They were administered by three registrars.

They were registered in 12 countries.

DNS Chronicle API queries for the domain IoCs revealed that they all recorded 2,217 historical domain-to-IP resolutions over time. Take a look at more information for five examples below.
| DOMAIN IoC | NUMBER OF DOMAIN-TO-IP RESOLUTIONS | DATES SEEN |
|---|---|---|
| dotlor[.]site | 76 | 03/27/26–07/06/26 |
| nebive[.]site | 56 | 04/06/26–05/18/26 |
| prolega[.]site | 84 | 03/23/26–07/25/26 |
| qumoro[.]site | 64 | 03/26/26–07/10/26 |
| transoe[.]site | 88 | 03/24/26–07/13/26 |
Consistent with the domain IoCs’ creation dates, the date of the oldest historical resolution was 29 December 2025. The rest were all posted in 2026.
After knowing more about the IoCs, we began hunting for new artifacts.
First, we queried the domain IoCs on WHOIS History API and found out that 47 had 34 unique public email addresses in their historical records.
We then queried the public email addresses on Reverse WHOIS API and uncovered 348 distinct email-connected domains after those already named as IoCs were filtered out.
Threat Intelligence API queries for the email-connected domains showed that 131 have already been weaponized for various attacks. Here are more details for five examples.
| MALICIOUS EMAIL-CONNECTED DOMAIN | ASSOCIATED THREAT | DATES SEEN |
|---|---|---|
| alarde[.]digital | Malware distribution | 07/28/26–08/09/26 |
| balomboa[.]site | Malware distribution | 07/28/26–08/09/26 |
| calvexis[.]info | Malware distribution | 07/28/26–08/09/26 |
| dinexa[.]digital | Malware distribution | 07/28/26–08/09/26 |
| enterlock[.]digital | Malware distribution | 07/28/26–08/09/26 |
Next, we queried the domain IoCs on DNS Lookup API and learned that 95 resolved to 186 distinct IP addresses. Of these, 184 turned out to be malicious according to Threat Intelligence API. Take a look at more information for five examples below.
| MALICIOUS ADDITIONAL IP ADDRESS | ASSOCIATED THREAT | DATES SEEN |
|---|---|---|
| 104[.]21[.]0[.]150 | Malware distribution | 03/29/23–08/09/26 |
| 172[.]67[.]129[.]18 | Malware distribution Phishing Generic threat | 03/29/23–08/09/26 07/22/23–08/09/26 05/17/25–08/03/26 |
| 104[.]21[.]1[.]243 | Malware distribution Phishing | 04/03/23–08/09/26 05/25/23–05/28/26 |
| 172[.]67[.]129[.]27 | Malware distribution | 09/07/24–08/09/26 |
| 104[.]21[.]15[.]11 | Malware distribution C&C Generic threat | 03/09/23–08/09/26 04/06/23–08/05/26 03/30/23–05/28/26 |
This post only contains a snapshot of the full research. Download the complete findings and a sample of the additional artifacts on our website or contact us to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.
Disclaimer: We take a cautionary stance toward threat detection and aim to provide relevant information to help protect against potential dangers. Consequently, it is possible that some entities identified as “threats” or “malicious” may eventually be deemed harmless upon further investigation or changes in context. We strongly recommend conducting supplementary investigations to corroborate the information provided herein.
Sponsored byCSC
Sponsored byWhoisXML API
Sponsored byDNIB.com
Sponsored byRadix
Sponsored byVerisign
Sponsored byVerisign
Sponsored byIPv4.Global