PULSE NAME
Finding Related Fake "DMCA Takedown" Domains with Validin.
WHITE PetrP.73 2025-11-08 Modified: 2025-12-08
115
IOCs
HIGH VOLUME
On November 5, 2025, several prominent YouTube content creators experienced an attack involving fake DMCA takedown notices that led to malicious downloads. The domain prominently associated with this scam was http://dmca-security.com, which acted as the initial phishing site. Cybersecurity analysts, including Tanner and John Hammond, investigated this domain to uncover related malicious infrastructure and gather relevant indicators of compromise (IoCs). Analysis of the phishing domain revealed connections to additional domains and IP addresses, focusing on pivoting techniques in DNS history to trace the threat. Specifically, the IP address 101.99.92[.]246 was identified as being utilized shortly after the phishing domain's registration. This indicates a potentially organized effort by the threat actors to quickly establish a network of malicious domains.
Indicators of Compromise (115)
All FileHash-MD5 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1e69c76842689565c2c46580042f2e54 2025-11-08
FileHash-MD5 5dab1fa5f7d42e5eca2385ce3dad1f03 2025-11-08
FileHash-MD5 863a129608d053b67081c8243c72e9e1 2025-11-08
FileHash-MD5 a927b832d5f0baf0fea5a427588da6c5 2025-11-08
URL http://101.99.89.94:5000 2025-11-08
URL http://national-competition-arise00.org:443 2025-11-08
URL http://youtube-dmca.com:3009 2025-11-08
domain acceptedbetter.global 2025-11-08
domain amazon-us953.com 2025-11-08
domain appfloreal.icu 2025-11-08
domain appfree.icu 2025-11-08
domain archivespress.solutions 2025-11-08
domain augustwell.dev 2025-11-08
domain authorlong.software 2025-11-08
domain awayjan.network 2025-11-08
domain azure-expresscontainer1.com 2025-11-08
domain bookwhisp.com 2025-11-08
domain bucket-aws-s1.com 2025-11-08
domain bucket-aws-s2.com 2025-11-08
domain californiare.systems 2025-11-08
domain cavra.org 2025-11-08
domain cavradocuments.top 2025-11-08
domain checkmanagement.solutions 2025-11-08
domain cocentre.net 2025-11-08
domain collaborations.center 2025-11-08
domain commercial-agreement.info 2025-11-08
domain copify.net 2025-11-08
domain copifyright.info 2025-11-08
domain coursematerials.com 2025-11-08
domain dmca-abuse.com 2025-11-08
domain dmca-abuse.video 2025-11-08
domain dmca-global.com 2025-11-08
domain dmca-guard.com 2025-11-08
domain dmca-guardian.com 2025-11-08
domain dmca-hub.com 2025-11-08
domain dmca-security.com 2025-11-08
domain dmca-shield.com 2025-11-08
domain dmca.center 2025-11-08
domain dmca.media 2025-11-08
domain dmca.social 2025-11-08
domain doingred.global 2025-11-08
domain famousfoxfederation.com 2025-11-08
domain fast-node.com 2025-11-08
domain floreal.icu 2025-11-08
domain frontlight.cloud 2025-11-08
domain gamecall.cloud 2025-11-08
domain gameupdate-endpoint.com 2025-11-08
domain gameupdate-endpoint1.com 2025-11-08
domain health-smooth-eu1.com 2025-11-08
domain ifstates.global 2025-11-08
domain janrights.company 2025-11-08
domain likeknowledge.systems 2025-11-08
domain linuxmade.net 2025-11-08
domain mayandmary.net 2025-11-08
domain microservice-feeder1.com 2025-11-08
domain movieare.co 2025-11-08
domain ms-dns-resolver1.com 2025-11-08
domain ms-onedrive-updater1.com 2025-11-08
domain ms-onedrive-updater2.com 2025-11-08
domain ms-team-connect.com 2025-11-08
domain ms-team-connect1.com 2025-11-08
domain ms-team-connect2.com 2025-11-08
domain ms-team-connect3.com 2025-11-08
domain ms-team-ping.com 2025-11-08
domain ms-team-ping1.com 2025-11-08
domain ms-team-ping10.com 2025-11-08
domain ms-team-ping2.com 2025-11-08
domain ms-team-ping3.com 2025-11-08
domain ms-team-ping4.com 2025-11-08
domain ms-team-ping5.com 2025-11-08
domain ms-team-ping6.com 2025-11-08
domain ms-team-ping7.com 2025-11-08
domain ms-team-ping8.com 2025-11-08
domain ms-team-ping9.com 2025-11-08
domain my-team-space.com 2025-11-08
domain my-team-space1.com 2025-11-08
domain my-team-space2.com 2025-11-08
domain my-team-space3.com 2025-11-08
domain my-team-space4.com 2025-11-08
domain national-competition-arise00.org 2025-11-08
domain nextdisplay.systems 2025-11-08
domain optionsmean.io 2025-11-08
domain partners-invitation.media 2025-11-08
domain partners-invitation.social 2025-11-08
domain payarchives.systems 2025-11-08
domain payments-adsense.com 2025-11-08
domain peopleno.io 2025-11-08
domain phoenixnap-sourceforge1.com 2025-11-08
domain plangolf.solutions 2025-11-08
domain privatefebruary.company 2025-11-08
domain processa.digital 2025-11-08
domain requestpoints.org 2025-11-08
domain saygoing.cloud 2025-11-08
domain shopliokre.com 2025-11-08
domain syswolupdatesupp1.com 2025-11-08
domain takedownabuse.com 2025-11-08
domain takedownfl.com 2025-11-08
domain takedownglobal.media 2025-11-08
domain takedownsecurity.com 2025-11-08
domain technologystart.company 2025-11-08
domain throughcanada.net 2025-11-08
domain unitedreading.company 2025-11-08
domain upbaby.co 2025-11-08
domain worldwidetakedown.report 2025-11-08
domain writtendirector.solutions 2025-11-08
domain wwtakedown.media 2025-11-08
domain xfood.software 2025-11-08
domain youtube-dmca.com 2025-11-08
domain youtube-partners.com 2025-11-08
hostname partner.mayandmary.net 2025-11-08
hostname www.cavra.org 2025-11-08
hostname www.copify.net 2025-11-08
hostname www.copifyright.info 2025-11-08
hostname www.dmca-global.com 2025-11-08
hostname www.mayandmary.net 2025-11-08