Indicator of Compromise Search
Bulk Lookup
✦ IPv4 Address ✦ Domain ✦ MD5/SHA1/SHA256 Hash ✦ URL
INDICATOR
litellm.cloud
Domain ⚠ 4 PULSE HITS ⚡ CACHED
↓ CSV ↓ JSON
55
/100
HIGH
CONFIDENCE LEVEL
THREAT CONFIDENCE ANALYSIS
HIGH 55/100 confidence
Strong evidence of malicious activity across multiple sources. Prioritise investigation.
CLEAN LOW MED HIGH CRIT
0 25 50 75 100
OTX
20/30
4 pulses
VIRUSTOTAL
35/35
19/94 detected
ABUSEIPDB
/25
IPv4 only
URLHAUS
0/10
NOT LISTED
General Information
Indicatorlitellm.cloud
Whois Domainhttp://whois.domaintools.com/litellm.cloud
Typedomain
AlienVault OTX Analysis ↗ View on OTX
4
PULSE HITS
Pulse Hits 4
Indicator Type Domain
Threat Level
Source ⚡ CACHED
ASSOCIATED PULSES
PULSE NAMEDATE
URLert Daily Threat Intel — 2026-03-25 2026-03-25
How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM 2026-03-24
How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM 2026-03-24
How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM 2026-03-24
VirusTotal Analysis ↗ View on VirusTotal
19/94
DETECTIONS
MALICIOUS
Malicious 19
Suspicious 1
Harmless 45
Undetected 29
Reputation 0
TOP DETECTIONS
VENDORRESULT
ADMINUSLabs malicious
BitDefender malware
CRDF malicious
Certego malicious
Chong Lua Dao malicious
CyRadar malware
Dr.Web malicious
ESET malware
Forcepoint ThreatSeeker malicious
Fortinet malware
URLhaus (abuse.ch) ↗ View on URLhaus
✓ NOT LISTED No malicious activity found in URLhaus database.