PULSE NAME
Finding Related Fake "DMCA Takedown" Domains with Validin.
WHITE PetrP.73 2025-11-08 Modified: 2025-12-08
115
IOCs
HIGH VOLUME
On November 5, 2025, several prominent YouTube content creators experienced an attack involving fake DMCA takedown notices that led to malicious downloads. The domain prominently associated with this scam was http://dmca-security.com, which acted as the initial phishing site. Cybersecurity analysts, including Tanner and John Hammond, investigated this domain to uncover related malicious infrastructure and gather relevant indicators of compromise (IoCs). Analysis of the phishing domain revealed connections to additional domains and IP addresses, focusing on pivoting techniques in DNS history to trace the threat. Specifically, the IP address 101.99.92[.]246 was identified as being utilized shortly after the phishing domain's registration. This indicates a potentially organized effort by the threat actors to quickly establish a network of malicious domains.
Indicators of Compromise (4 / 115 total)
All FileHash-MD5 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 1e69c76842689565c2c46580042f2e54 2025-11-08
FileHash-MD5 5dab1fa5f7d42e5eca2385ce3dad1f03 2025-11-08
FileHash-MD5 863a129608d053b67081c8243c72e9e1 2025-11-08
FileHash-MD5 a927b832d5f0baf0fea5a427588da6c5 2025-11-08