PULSE NAME
Finding Related Fake "DMCA Takedown" Domains with Validin.
WHITE PetrP.73 2025-11-08 Modified: 2025-12-08
115
IOCs
HIGH VOLUME
On November 5, 2025, several prominent YouTube content creators experienced an attack involving fake DMCA takedown notices that led to malicious downloads. The domain prominently associated with this scam was http://dmca-security.com, which acted as the initial phishing site. Cybersecurity analysts, including Tanner and John Hammond, investigated this domain to uncover related malicious infrastructure and gather relevant indicators of compromise (IoCs). Analysis of the phishing domain revealed connections to additional domains and IP addresses, focusing on pivoting techniques in DNS history to trace the threat. Specifically, the IP address 101.99.92[.]246 was identified as being utilized shortly after the phishing domain's registration. This indicates a potentially organized effort by the threat actors to quickly establish a network of malicious domains.
Indicators of Compromise (3 / 115 total)
All FileHash-MD5 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
URL http://101.99.89.94:5000 2025-11-08
URL http://national-competition-arise00.org:443 2025-11-08
URL http://youtube-dmca.com:3009 2025-11-08