psyc operations cockpit model
NN-sc — Security/Control
← back to cases

PSYC-OTX-6a2201a331661aba15d362d1

▶ case journey

OTX: ClickFix Is Now Hiring: From Job Platform Impersonation to Python-Based RAT Delivery

The full record for one case — how Classifyline rated it, what Scoutline observed, the evidence Sealine encrypted, where Routeline may send it, and every ledger entry it produced.

how to use this view

How to use. Read the cards top-to-bottom — classification, observables, sealed package, routes, ledger. Hit ▶ case journey for the animated walk-through.

What you're seeing. Every worker line's output for this one case: how it was rated, what was observed, what was encrypted and to whom, where it would route, and the audit rows it produced.

Why it matters. Nothing sensitive leaves psyc without a human seeing the full reasoning chain — this page is that chain, for one case.

Classification

Severity
medium
TLP
GREEN
Incident type
malware
Internal class
D

Confidence

Level
medium
Source reliability
C
Information credibility
3

Source

Type
threat_intel
Reference
https://otx.alienvault.com/pulse/6a2201a331661aba15d362d1
Observed
2026-06-04 22:52 UTC
Ingested
2026-06-07 00:17 UTC

Observables

URLs

  • http://linked-hr.com/leyts.php
  • http://teamsvoicehub.com/leyts.php
  • http://ai-like.net/95126aeb-4120-56b1-8c9e-63fdf0c0b6f9
  • http://candipoker.net/ebd417db-979c-51f8-aedf-88a2bf8aa6c3
  • http://catalyst-ltd.net/95126aeb-4120-56b1-8c9e-63fdf0c0b6f9
  • http://dapala.net/95126aeb-4120-56b1-8c9e-63fdf0c0b6f9
  • http://dmtn-tv.net/95126aeb-4120-56b1-8c9e-63fdf0c0b6f9
  • http://domawe.net/95126aeb-4120-56b1-8c9e-63fdf0c0b6f9
  • http://idrci.net/95126aeb-4120-56b1-8c9e-63fdf0c0b6f9
  • http://indeed-jobs.net/leyts.php
  • http://indeedhiring.com/leyts.php
  • http://linked-on.com/leyts.php
  • http://linked-people.com/leyts.php
  • http://linkedall.org/infos.php
  • http://linkedplus.org/leyts.php
  • http://linkedwith.org/leyts.php
  • http://mtg-life.net/95126aeb-4120-56b1-8c9e-63fdf0c0b6f9
  • http://sedaliarealty.net/ebd417db-979c-51f8-aedf-88a2bf8aa6c3

Domains

  • teamsvoicehub.com
  • dapala.net
  • staruxaproruha.com
  • ai-like.net
  • mtg-life.net
  • novayastaruxa.com
  • kevinnotanother.com
  • candipoker.net
  • linkedwith.org
  • linked-on.com
  • linkedall.org
  • uslinked.org
  • linked-people.com
  • linkedplus.org
  • linked-hr.com
  • indeed-jobs.net
  • indeedhiring.com
  • crewlworkinew.com
  • catalyst-ltd.net
  • dmtn-tv.net
  • domawe.net
  • idrci.net
  • sedaliarealty.net

Hashes

  • 08a474368a2f94f347ad9e1a0a08d4258fcf49c6b9373214f7901bb770bacca4
  • 7c54bcf3aea8348e8902cac80eb0df31b43a71601a62e2514087fef40a416bfd
  • cd4a51037bf58733c0cb24b273951dd3fcea45a2aaeb8b30a3c625e183c4c0c7
  • d56b810dfacaa1630bf562ccdefd46835349710d9516334e1a182619335ddea7
  • d3e936fa36289fd1210047d8f25257bab0608825ed92908dc98c00e33bdb3db2
  • d04ae4d214531d70c634d29763a9c0b84d601cf94aaca4720363f7512995393c
  • c024a3d852b73fef5bfca7ec5c80df3d59ff9ec858e0adad80c588fe22c39dfc
  • e5e43b0830369c39fab45363486da4d21a98c5097ea262c9816997f11c73c1c4
  • ee2d34ac98eaf1451d19fdc99f0bb52db1db60f71933a91f5655af0703ff2464
  • 202f3c8cf41a627db403295874220ddd
  • 2a350525ba72ffc9fe45a05a423833d5
  • 9d740bcb290c0c70596180f05a117f594411bbdd
  • ba1740688cf1236ef29516be83593ba548944df6
  • 0e346fb46176ffce4c7dbe40a8682bc1f4a2fc70b7389be427568d97a47bd149

Routes

2 allowed · 2 blocked
MISP-Community priority 2 · stix_indicators · max_tlp AMBER
URLhaus priority 3 · malware_url_report · max_tlp GREEN
CERT-Bund country_mismatch
AbuseIPDB tlp_exceeded