Known malicious kitmediumphishing

RCFH AiTM toolkit — Hostinger hosting IPs (Payroll Pirates / Storm-2755, low-confidence)

family: rcfh-aitm-storm2755

The seven Hostinger addresses that served the published redirectors and AiTM proxies. Redirectors: 187.124.129.44 (idp.keyreniao.com), 194.5.157.204 (idp.korminel.com), 145.223.100.123 (idp.kualabemo.com). Proxies: 153.92.1.166 (mslogin.milocaroline.com), 31.97.76.103 (msauth.monlinelogicaline.com), 177.7.56.248 (msonline.logicalineonline.com), 72.62.0.181 (office.ofreace.com and office.ofercarc.com, two proxies co-located).

Anchors

SMQL queryrun
ip:145.223.100.123 OR ip:153.92.1.166 OR ip:177.7.56.248 OR ip:187.124.129.44 OR ip:194.5.157.204 OR ip:31.97.76.103 OR ip:72.62.0.181

Provenance

Added: 2026-08-10 20:57
Filed at medium and split into its own row ON PURPOSE — do not merge it back into the domains row. An ip: term normally earns its place because it keeps firing after the operator rotates to a fresh domain on the same box, but that argument only holds for dedicated infrastructure. This is Hostinger shared hosting: the domains were all sub-ten-day Hostinger registrations, 72.62.0.181 was already serving two campaign proxies at once, and the same address will be serving unrelated paying tenants. Treat a sighting from this row as 'a Hostinger IP that once hosted this kit', which is a lead, not a verdict — read it together with whether the domains or the YARA rows also fired. Same failure mode already documented for *.host.ultaserver.net in the DOUBLECUP infra hunt and for the shared-platform-apex IoC reach problem generally. No YARA anchor on this row: the point of the row is to isolate the noisy half so it can be triaged separately. 7 filter nodes.

Sightings (0)

No sightings recorded yet.