Threat IntelligenceMar 24, 2026
@smica83 Also there is a related (by *.ecs-ent-aff-mgr\.in.net traffic) sample that is coming fro...
Researcher shares malware sample URLs and C2 traffic patterns related to *.ecs-ent-aff-mgr.in.net
Summary
A security researcher posted threat intelligence regarding malware samples hosted on download-version.1-4-9[.]com with multiple suspicious paths (manus, cowork, app) and noted correlating C2 traffic patterns to *.ecs-ent-aff-mgr.in.net infrastructure. The post appears to be part of ongoing malware analysis and threat tracking within the security community.
Indicators of Compromise
- domain — ecs-ent-aff-mgr.in.net
- domain — download-version.1-4-9[.]com
- url — https://download-version.1-4-9[.]com/manus
- url — https://download-version.1-4-9[.]com/cowork
- url — https://download-version.1-4-9[.]com/app