Back to Feed
Threat IntelligenceMar 24, 2026

@smica83 Also there is a related (by *.ecs-ent-aff-mgr\.in.net traffic) sample that is coming fro...

Researcher shares malware sample URLs and C2 traffic patterns related to *.ecs-ent-aff-mgr.in.net

Summary

A security researcher posted threat intelligence regarding malware samples hosted on download-version.1-4-9[.]com with multiple suspicious paths (manus, cowork, app) and noted correlating C2 traffic patterns to *.ecs-ent-aff-mgr.in.net infrastructure. The post appears to be part of ongoing malware analysis and threat tracking within the security community.

Indicators of Compromise

  • domain — ecs-ent-aff-mgr.in.net
  • domain — download-version.1-4-9[.]com
  • url — https://download-version.1-4-9[.]com/manus
  • url — https://download-version.1-4-9[.]com/cowork
  • url — https://download-version.1-4-9[.]com/app