From February 6th, 2026, to April 7th, 2026, the Security Alliance (SEAL) has tracked and implemented a wallet-level block via eth-phishing-detect for 164 domains associated with the Democratic People's Republic of Korea (DPRK) threat actor group, designated as UNC1069. In light of recent incidents, such as the compromise of the "axios" npm package utilizing attack vectors consistent with UNC1069 - a group primarily targeting the cryptocurrency sector - SEAL is publishing a comprehensive list of DPRK-operated domains utilized in sophisticated social engineering attacks involving fraudulent Microsoft Teams and Zoom meetings.
The complete list of Indicators of Compromise (IOCs) is appended at the end of this document. This advisory also details the currently active Tactics, Techniques, and Procedures (TTPs) deployed by the attackers to facilitate malicious payload delivery and execution.
Key Takeaways
- From February 6th, 2026 to April 7th, 2026,, SEAL has attributed 164 blocked domains to UNC1069 (BlueNoroff), a DPRK-nexus threat actor with a sustained focus on the cryptocurrency and Web3 sectors.
- UNC1069 operates multi-week, low-pressure social engineering campaigns across Telegram, LinkedIn, and Slack - either impersonating known contacts or credible brands or by leveraging access to previously compromised company and individual accounts - before delivering a fraudulent Zoom or Microsoft Teams meeting link.
- The fake meeting UI is browser-based, built on legitimate SDKs, and visually indistinguishable from real Zoom or Teams meetings. No executable or installer is involved at the point of compromise; the initial payload is a single AppleScript (
.scpt) download or a terminal copy-paste instruction. - Once executed, the implant establishes persistence, assigns the victim a UUID, beacons to command and control (C2) infrastructure approximately every 60 seconds, and awaits operator-issued tasking - enabling fully modular and targeted post-exploitation activity.
- Post-compromise capabilities include credential theft, keylogging, session token harvesting, browser extension replacement, and full exfiltration of crypto wallets, password managers, Telegram sessions, SSH keys, and cloud credentials across macOS, Windows, and Linux.
- The group has historically targeted crypto founders, VCs, and high-visibility individuals. The demonstrated willingness to weaponize the npm/OSS supply chain (see, axios compromise) signals an intentional expansion toward open-source maintainers - a significantly higher-leverage attack surface.
- Victims' compromised accounts (Telegram, Slack, LinkedIn) are subsequently used to propagate attacks to their networks, compounding exposure across trust relationships built over years.
Social Engineering
UNC1069's social engineering methodology is defined by patience, precision, and the deliberate weaponization of existing trust relationships.
Initial Contact & Persona Construction
The initial contact originates from a compromised account belonging to someone the target already knows: a conference contact, a mutual introduction, a VC or BD counterpart. Because the attacker controls the victim's prior messaging history, they can resume conversations with full context - referencing past interactions, shared contacts, and relevant business topics. This prior context is the most disarming element of the attack; targets are not cold-approached but re-engaged.

Where a compromised account is unavailable, UNC1069 impersonates credible brands with a plausible reason to reach out. On LinkedIn, this takes the form of outreach from a relevant firm (GhostHire, GhostCall campaigns); on Slack, the actor constructs a pre-staged workspace to simulate a professional environment before any call takes place. However, both of these tactics are constantly evolving and should not be considered stable.


Meeting Scheduling & Pre-Call
Once contact is established, the actor proposes a call - typically via (legitimate) Calendly - and deliberately does not rush it. Calls are scheduled one to two weeks out, sometimes rescheduled. This extended timeline normalizes the interaction and eliminates the time-pressure targets might otherwise apply to evaluate risk.
The meeting link - a fraudulent Zoom or Microsoft Teams URL, masked behind a lookalike domain - is delivered via the same channel (Telegram, Slack, LinkedIn) shortly before the scheduled time.

On-Call Execution
The fake meeting UI loads entirely in-browser. It presents real video of the supposed participants - sourced from prior recordings or public content (conference talks, podcasts) - rendered via the legitimate Zoom or Teams SDK and styled to be visually identical to the real product. No application install is required. No executable is presented.
The hook is an audio issue on the target’s system. The target cannot hear the call. The UI surfaces a prompt to resolve this. Simultaneously, the attacker - operating the compromised or impersonated account on Telegram or Slack - messages the target directly:
"What's up?" "Oh, Zoom is acting up?" "Yeah, don't worry. I've had this happen before too." "You just need to update the SDK. It's very simple."
If the target expresses hesitation or skepticism, the attacker immediately de-escalates: "Just use the web version," "My company's security team checked it," "Don't worry." Screenshots are sometimes provided showing exactly what to click. The attacker is patient, reassuring, and technically credible.
This social layer - a real person actively coaching the target through the compromise in real time - is what distinguishes UNC1069's methodology from passive phishing.



Malware Payloads
Initial Delivery
The initial stage payload is intentionally minimal. Depending on the variant, the target either clicks a UI button in the fake meeting - triggering a download of a .scpt file (AppleScript) - or is instructed to paste a command into their terminal. In both cases, the visible code is padded with benign-looking lines to obscure the single malicious instruction. The dropper calls out to attacker-controlled infrastructure and retrieves the second-stage implant. Attackers are protective of their C2 infrastructure. It is designed for a single download per assigned UUID; if operators determine the interaction is with a security researcher or SOC team rather than a genuine victim, they will immediately disable the entire infrastructure.



Implant Behavior
The second-stage implant - observed in Nim-based variants as well as macOS-native formats — performs the following on execution:
- Assigns the host a UUID for individualized tracking and tasking
- Collects basic system reconnaissance (hardware, OS, running processes)
- Establishes persistence via standard macOS persistence mechanisms
- Begins beaconing to C2 infrastructure on an approximately 60-second interval
The beacon loop is simple: the implant wakes, checks in with the C2, and either receives a task to execute or sleeps and repeats. Critically, received tasks are executed directly and without validation - whatever the C2 returns is run. This design enables the operators to deliver arbitrary follow-on capability post-compromise, tailored to the specific victim.
Post-Compromise Modules
UNC1069 operates a modular post-exploitation framework. Operators review incoming victim data and selectively deploy modules based on assessed value. Observed and documented capabilities include:
- Full credential stealers — targeting browser-stored passwords, crypto wallet files, seed phrases, and API keys
- Keyloggers
- Session token harvesters — specifically targeting Telegram authentication tokens to enable account takeover and downstream propagation
- Password manager extraction — Keychain, 1Password, Bitwarden, Apple Notes
- Browser extension replacement — silently swapping legitimate extensions on disk with malicious equivalents
- SSH key and AWS credential exfiltration
- Custom payloads — operators have demonstrated willingness to write target-specific modules when standard tooling is insufficient
The platform scope is broad: macOS is the primary observed target surface given the prevalence of Apple hardware in the crypto/Web3 sector, but variants supporting Windows and Linux have been documented.
Post-Compromise
Operators deliberately do not act immediately following initial access. The implant is left dormant or passive for a period following compromise. The target typically reschedules the failed call and continues normal operations, unaware the device is compromised. This patience extends the operational window and maximizes the value extracted before any incident response is triggered.
IOCs
SEAL attributes to UNC1069 based on victim reports (both public and private), which allows us to consistently update detection signatures for utilized domains and hostnames. All Indicators of Compromise and Tactics, Techniques, and Procedures are then verified against the known profile of this particular threat actor group. Any deviations from the established group profiles are either deconflicted to prevent misattribution or used to update the existing profile (Adaptation).
[1] DNS A record set only on subdomain (teams.[root-domain].[tld])
[2] Hosts classified as “SEDO-AS SEDO GmbH” were either short lived or A record was only set for a specific subdomain. The historical DNS data coverage of such domains by different threat intelligence providers is highly variable. These domains were deployed in rapid bursts in what we suspect was attackers attempting to adapt to our detection techniques before changing domain naming patterns completely.
[3] Lower confidence
[4] used in axios’ developer attack
| # | Domain | First Seen (UTC) | ASN IP | ASN # | Hosting Provider | Registrar |
|---|---|---|---|---|---|---|
| 1 | micrusoft[.]us | 2026-04-07 13:13:13 | 68.65.123[.]117 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NameSilo, LLC |
| 2 | uk05live[.]us | 2026-04-06 17:33:40 | 66.29.141[.]223 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NAMECHEAP INC |
| 3 | web-meet[.]live | 2026-04-06 03:32:56 | 198.187.29[.]26 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NAMECHEAP INC |
| 4 | livehuddle01[.]us | 2026-04-03 03:48:08 | 162.0.215[.]196 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NAMECHEAP INC |
| 5 | oneasu[.]com | 2026-04-03 03:01:27 | 68.65.121[.]244 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NAMECHEAP INC |
| 6 | teamslivc[.]com | 2026-04-02 17:02:39 | 198.54.116[.]166 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NameSilo, LLC |
| 7 | teamsync[.]live | 2026-04-02 13:34:29 | 132.148.217[.]168 | 26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC | GoDaddy.com, LLC |
| 8 | teamslivs[.]com | 2026-04-02 07:31:23 | 198.54.116[.]166 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NameSilo, LLC |
| 9 | microcall[.]us | 2026-04-02 06:52:17 | 198.54.116[.]40 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NAMECHEAP INC |
| 10 | teamsliveo[.]com | 2026-04-02 06:08:14 | 198.54.115[.]166 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NameSilo, LLC |
| 11 | outms[.]com | 2026-04-02 05:34:33 | 2.57.91[.]62 | 47583 | AS-HOSTINGER Hostinger International Limited | NameSilo, LLC |
| 12 | annaelsa[.]xyz | 2026-04-01 15:25:56 | 23.254.167[.]21 | 54290 | HOSTWINDS - Hostwinds LLC. | NAMECHEAP INC |
| 13 | callshere[.]com | 2026-04-01 15:07:04 | 198.54.116[.]40 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NAMECHEAP INC |
| 14 | teams-meet[.]xyz | 2026-04-01 14:26:06 | 83.136.210[.]87 | 400897 | PETROSKY - PETROSKY CLOUD LLC | NAMECHEAP INC |
| 15 | inmsed[.]com | 2026-04-01 10:01:49 | 23.254.167[.]21 | 54290 | HOSTWINDS - Hostwinds LLC. | NameSilo, LLC |
| 16 | teemslive[.]com | 2026-04-01 09:43:27 | 198.54.116[.]166 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NameSilo, LLC |
| 17 | mslivecall[.]us | 2026-04-01 06:12:14 | 198.54.116[.]40 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NAMECHEAP INC |
| 18 | onmsed[.]com | 2026-04-01 05:47:13 | 64.187.97[.]203 | 400343 | NAMESILONNET - NAMESILO, L.L.C. | NameSilo, LLC |
| 19 | linelive[.]us | 2026-04-01 01:03:09 | 141.136.43[.]165 | 47583 | AS-HOSTINGER Hostinger International Limited | NameSilo, LLC |
| 20 | linelive[.]us | 2026-04-01 01:03:09 | 141.136.43[.]165 | 47583 | AS-HOSTINGER Hostinger International Limited | NameSilo, LLC |
| 21 | teamslivex[.]com | 2026-03-31 23:37:31 | 107.180.119[.]82 | 26496 | AS-26496-GO-DADDY-COM-LLC - GoDaddy.com, LLC | NameSilo, LLC |
| 22 | teamslivos[.]com | 2026-03-31 18:06:49 | 198.54.115[.]40 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NameSilo, LLC |
| 23 | uswebob[.]com | 2026-03-31 13:54:02 | 107.180.119[.]82 | 26496 | GoDaddy | NameSilo, LLC |
| 24 | premuims[.]live [3] | 2026-03-31 12:16:01 | 172.86.91[.]195 | 14956 | RouterHosting | NameSilo, LLC |
| 25 | ms-meeting[.]us | 2026-03-30 13:34:12 | 192.64.119[.]167 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 26 | teemslivo[.]com | 2026-03-27 12:24:54 | 68.65.122[.]191 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 27 | reallivecall[.]us[1] | 2026-03-27 12:07:35 | 68.65.123[.]168 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 28 | ms-teams[.]us[.]com | 2026-03-26 14:11:36 | 83.136.210[.]87 | 400897 | PETROSKY CLOUD LLC | NAMECHEAP INC |
| 29 | msteamcall[.]com | 2026-03-26 00:32:14 | 199.188.205[.]45 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 30 | msteamcall[.]com | 2026-03-25 23:28:47 | 199.188.205[.]45 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NAMECHEAP INC |
| 31 | microc[.]click [3] | 2026-03-25 05:36:36 | CloudFlare | 13335 | CloudFlare | NameSilo, LLC |
| 32 | microt[.]click [3] | 2026-03-25 05:36:33 | CloudFlare | 13335 | CloudFlare | NameSilo, LLC |
| 33 | microi[.]click [3] | 2026-03-25 05:36:27 | CloudFlare | 13335 | CloudFlare | NameSilo, LLC |
| 34 | microg[.]click [3] | 2026-03-25 04:59:04 | CloudFlare | 13335 | CloudFlare | NameSilo, LLC |
| 35 | microb[.]click [3] | 2026-03-25 04:18:23 | CloudFlare | 13335 | CloudFlare | NameSilo, LLC |
| 36 | ms-meets[.]us[.]com | 2026-03-25 03:54:35 | 83.136.208[.]87 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 37 | microp[.]click [3] | 2026-03-25 02:00:29 | CloudFlare | 13335 | CloudFlare | NameSilo, LLC |
| 38 | microe[.]click [3] | 2026-03-24 23:57:11 | CloudFlare | 13335 | CloudFlare | NameSilo, LLC |
| 39 | micror[.]click [3] | 2026-03-24 23:55:17 | CloudFlare | 13335 | CloudFlare | NameSilo, LLC |
| 40 | microh[.]click [3] | 2026-03-24 23:48:05 | CloudFlare | 13335 | CloudFlare | NameSilo, LLC |
| 41 | onreallive[.]com | 2026-03-24 17:26:21 | 199.188.200[.]43 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NAMECHEAP INC |
| 42 | microsslcheck[.]com | 2026-03-23 12:19:00 | CloudFlare | 13335 | Cloudflare | NAMECHEAP INC |
| 43 | usweb0l[.]us | 2026-03-23 02:36:19 | 148.72.73[.]98 | 26496 | GoDaddy | NameSilo, LLC |
| 44 | micrlive[.]online | 2026-03-23 01:22:21 | 192.64.119[.]144 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 45 | mslivecall[.]com | 2026-03-22 12:19:00 | 199.188.205[.]45 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 46 | uswebob[.]us | 2026-03-20 16:17:09 | 148.72.73[.]98 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 47 | ww-live[.]com | 2026-03-19 19:51:32 | 162.255.119[.]134 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 48 | teemsliivc[.]com | 2026-03-19 17:29:09 | 66.29.153[.]159 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 49 | onlivemeet[.]com[1] | 2026-03-18 12:53:50 | 69.57.162[.]193 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 50 | mslivemeet[.]com[1] | 2026-03-17 14:01:49 | 199.188.205[.]45 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 51 | teamsiiwe[.]com | 2026-03-16 18:40:28 | 66.29.153[.]158 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 52 | teamsliwe[.]com | 2026-03-16 18:40:28 | 66.29.153[.]159 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 53 | lievec[.]com | 2026-03-16 15:22:01 | 69.57.162[.]186 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 54 | teams-us[.]live | 2026-03-16 11:58:22 | 198.54.120[.]79 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 55 | nicrosofm[.]com | 2026-03-16 03:08:11 | 198.54.114[.]236 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 56 | nisrosodf[.]com[1] | 2026-03-16 02:55:30 | 69.57.162[.]186 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 57 | nicrosolf[.]com[1] | 2026-03-15 18:34:33 | 198.54.115[.]108 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 58 | liivoe[.]com | 2026-03-15 11:58:22 | 69.57.162[.]186 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 59 | nicrosolt[.]com[1] | 2026-03-14 18:34:33 | 68.65.121[.]250 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 60 | ms-meets[.]xyz | 2026-03-14 13:08:43 | 83.136.210[.]29 | 400897 | PETROSKY CLOUD LLC | NAMECHEAP INC |
| 61 | microsout[.]com | 2026-03-14 12:55:01 | 68.65.121[.]248 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 62 | microcodf[.]com | 2026-03-14 12:55:01 | 68.65.121[.]250 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 63 | microszlt[.]com | 2026-03-13 19:32:27 | 66.29.141[.]6 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 64 | microcoll[.]com[1] | 2026-03-13 14:02:30 | 66.29.141[.]6 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 65 | msquickcall[.]com[1] | 2026-03-12 18:53:05 | 68.65.122[.]242 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 66 | liuesus[.]com | 2026-03-12 14:57:55 | 68.65.121[.]187 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NameSilo, LLC |
| 67 | liues[.]us | 2026-03-12 06:37:50 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 68 | microselt[.]com[1] | 2026-03-11 18:27:58 | 68.65.123[.]193 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 69 | microsdb[.]com[1] | 2026-03-11 15:43:16 | 162.255.119[.]153 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 70 | microshen[.]com[1] | 2026-03-10 20:24:54 | 68.65.123[.]193 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 71 | liueus[.]com[1] | 2026-03-09 08:04:18 | 68.65.121[.]187 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 72 | microsall[.]com[1] | 2026-03-09 01:14:00 | 68.65.123[.]193 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 73 | microsall[.]com | 2026-03-09 01:14:00 | 68.65.123[.]193 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 74 | msquickcall[.]com[1] | 2026-03-06 18:08:46 | 68.65.123[.]178 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 75 | web22n[.]us | 2026-03-05 22:04:56 | 68.65.121[.]244 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 76 | microsinfos[.]com | 2026-03-05 15:00:25 | 68.65.123[.]163 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 77 | dencall[.]xyz | 2026-03-05 05:08:23 | 23.254.167[.]21 | 54290 | HOSTWINDS - Hostwinds LLC. | NAMECHEAP INC |
| 78 | us03live[.]com | 2026-03-05 00:24:15 | 64.187.97[.]203 | 400343 | NAMESILO, L.L.C. | NameSilo, LLC |
| 79 | www-live[.]us | 2026-03-04 22:06:45 | 192.64.119[.]220 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 80 | microshlop[.]com | 2026-03-04 16:02:52 | 192.64.119[.]5 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 81 | micstmeet[.]com | 2026-03-03 15:51:03 | 64.187.97[.]203 | 400343 | NAMESILO, L.L.C. | NameSilo, LLC |
| 82 | www-live[.]xyz | 2026-03-03 09:37:43 | 192.64.119[.]249 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 83 | usweb0b[.]us | 2026-03-01 07:39:47 | 64.187.97[.]203 | 400343 | NAMESILO, L.L.C. | NameSilo, LLC |
| 84 | onlivecall[.]com | 2026-02-28 18:29:43 | 68.65.123[.]114 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 85 | microschats[.]com | 2026-02-27 22:09:12 | 68.65.123[.]75 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 86 | usobweb[.]us | 2026-02-27 16:21:11 | 68.65.123[.]50 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 87 | renaworkshard[.]xyz | 2026-02-27 08:20:29 | 23.254.167[.]21 | 54290 | HOSTWINDS - Hostwinds LLC. | NAMECHEAP INC |
| 88 | msmeet[.]us | 2026-02-27 08:16:10 | 23.254.167[.]21 | 54290 | Hostwinds LLC. | NAMECHEAP INC |
| 89 | microsomeet[.]com | 2026-02-26 18:39:33 | 68.65.122[.]242 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 90 | microca11[.]com | 2026-02-26 14:32:43 | 184.94.213[.]200 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 91 | ms-live[.]team | 2026-02-26 12:20:39 | 162.255.119[.]192 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 92 | uz04web[.]us | 2026-02-26 10:31:53 | 162.213.255[.]41 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 93 | livescall[.]us | 2026-02-26 07:51:04 | 184.94.213[.]200 | 22612 | Namecheap, Inc. | NameSilo, LLC |
| 94 | livescall[.]xyz | 2026-02-25 08:13:09 | 67.223.118[.]42 | 22612 | NAMECHEAP-NET - Namecheap, Inc. | NAMECHEAP INC |
| 95 | olafsven[.]xyz | 2026-02-25 00:58:55 | 23.254.167[.]21 | 54290 | HOSTWINDS - Hostwinds LLC. | NAMECHEAP INC |
| 96 | web05us[.]online | 2026-02-21 10:30:32 | 84.32.84[.]32 | 47583 | AS-HOSTINGER Hostinger International Limited | Hostinger UAB |
| 97 | us05web[.]site | 2026-02-21 10:24:02 | 84.32.84[.]32 | 47583 | AS-HOSTINGER Hostinger International Limited | Hostinger UAB |
| 98 | un01web[.]us | 2026-02-13 15:28:37 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 99 | uo01web[.]us | 2026-02-13 13:14:29 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 100 | uo05web[.]us | 2026-02-13 12:36:24 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 101 | ue02web[.]us | 2026-02-13 05:38:06 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 102 | ue03web[.]us | 2026-02-12 23:29:59 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 103 | uc02web[.]us | 2026-02-12 16:54:09 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 104 | us05webszoom[.]us | 2026-02-12 13:08:11 | 192.64.119[.]40 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 105 | uc06web[.]us | 2026-02-12 12:56:11 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 106 | uc04web[.]us | 2026-02-12 05:20:50 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 107 | uc03web[.]us | 2026-02-12 02:13:27 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 108 | ux02web[.]us | 2026-02-11 23:58:22 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 109 | microcal1[.]com | 2026-02-11 16:45:12 | 198.54.116[.]214 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 110 | ux01web[.]us | 2026-02-11 16:37:24 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 111 | ux03web[.]us | 2026-02-11 15:51:13 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 112 | uz03web[.]us | 2026-02-11 14:29:03 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 113 | uz01web[.]us | 2026-02-11 12:37:27 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 114 | livesmeets[.]us[1] | 2026-02-11 02:10:24 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 115 | uc01web[.]us | 2026-02-10 23:24:56 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 116 | us0lwebzoom[.]us | 2026-02-10 16:53:52 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 117 | ucweb05[.]us | 2026-02-10 14:12:05 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 118 | ue06web[.]us | 2026-02-10 13:15:45 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 119 | ue04web[.]us | 2026-02-10 12:31:53 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 120 | livesmeet[.]us[1] | 2026-02-10 10:06:03 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 121 | ue01web[.]us | 2026-02-10 07:35:25 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 122 | micromeet[.]us | 2026-02-10 00:36:06 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 123 | microscalls[.]com[1] | 2026-02-09 15:30:11 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 124 | uz06web[.]us | 2026-02-09 12:09:31 | 66.29.132[.]149 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 125 | web-zoom[.]uk | 2026-02-09 10:47:47 | 84.32.84[.]32 | 47583 | AS-HOSTINGER Hostinger International Limited | Hostinger UAB |
| 126 | liue[.]us | 2026-02-09 02:26:02 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 127 | us05websoom[.]us | 2026-02-09 00:25:19 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 128 | us03websoom[.]us | 2026-02-08 23:15:14 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 129 | us06websoom[.]us | 2026-02-06 13:36:08 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 130 | uc02websoom[.]us | 2026-02-06 12:46:14 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 131 | us02websoom[.]us | 2026-02-06 05:48:18 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 132 | us03webuoom[.]us | 2026-02-06 01:24:35 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 133 | uae04webzoom[.]us | 2026-02-06 00:28:18 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 134 | uc05websoom[.]us | 2026-02-06 00:01:46 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 135 | us05webxoom[.]us | 2026-02-05 23:13:52 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 136 | ueo4webzoom[.]us | 2026-02-05 17:20:45 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 137 | uco4webzoom[.]us | 2026-02-05 13:15:47 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 138 | uco6webzoom[.]us | 2026-02-05 05:05:13 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 139 | uco5webzoom[.]us | 2026-02-05 02:04:17 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 140 | use05webzoom[.]us | 2026-02-05 00:51:01 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NAMECHEAP INC |
| 141 | uso06webzoom[.]us | 2026-02-04 23:29:59 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 142 | uso04webzoom[.]us | 2026-02-04 16:28:37 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NAMECHEAP INC |
| 143 | microsmeet[.]com | 2026-02-04 15:25:47 | 67.223.118[.]116 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 144 | uso05webzoom[.]us | 2026-02-04 14:08:05 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 145 | us07web[.]me | 2026-02-04 08:45:26 | 84.32.84[.]32 | 47583 | AS-HOSTINGER Hostinger International Limited | Hostinger UAB |
| 146 | usa04webzoom[.]us | 2026-02-04 02:59:15 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 147 | usa06webzoom[.]us | 2026-02-03 23:27:39 | 188.227.197[.]32 | 400897 | PETROSKY CLOUD LLC | NameSilo, LLC |
| 148 | ww-live[.]us | 2026-01-31 17:24:59 | 192.64.119[.]220 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 149 | ww-live[.]online | 2026-01-29 10:42:27 | 162.255.119[.]19 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 150 | ww-live[.]xyz | 2026-01-29 08:34:20 | 192.64.119[.]88 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 151 | os-live[.]us | 2026-01-23 13:22:21 | 162.255.119[.]35 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 152 | os-live[.]online | 2026-01-21 10:39:32 | 162.255.119[.]184 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 153 | os-live[.]xyz | 2026-01-21 08:19:54 | 162.255.119[.]45 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 154 | ms-meet[.]xyz[1][2] | 2025-12-19 08:17:21 | 192.64.119[.]93 | 22612 | NAMECHEAP-NET | NAMECHEAP INC |
| 155 | ms-live[.]site[1][2] | 2025-12-16 14:52:56 | 192.64.119[.]22 | 22612 | NAMECHEAP-NET | NAMECHEAP INC |
| 156 | ms-teams[.]xyz | 2025-12-11 09:37:07 | 162.255.119[.]95 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 157 | ms-teams[.]live | 2025-09-12 07:05:11 | 162.255.119[.]223 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 158 | uswe05[.]us | 2025-07-29 03:06:13 | 84.32.84[.]157 | 47583 | AS-HOSTINGER Hostinger International Limited | NAMECHEAP INC |
| 159 | us10web[.]us | 2024-09-03 23:33:09 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 160 | live-meet[.]online[2] | 2024-02-03 05:10:26 | 162.255.119[.]204 | 22612 | NAMECHEAP-NET | NAMECHEAP INC |
| 161 | uso4web[.]us | 2021-07-01 18:14:52 | 91.195.240[.]123 | 47846 | SEDO-AS SEDO GmbH | NameSilo, LLC |
| 162 | os-live[.]com[2] | 2020-10-26 01:23:24 | 192.64.119[.]29 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 163 | join-uk[.]com | 2020-01-27 00:57:20 | 198.54.117[.]242 | 22612 | Namecheap, Inc. | NAMECHEAP INC |
| 164 | microscell[.]com[2] | 2018-08-01 23:11:30 | 68.65.123[.]163 | 22612 | Namecheap, Inc. | NameSilo, LLC |