Security reporting identified enter-press-cdn.info as a high-confidence suspicious domain tied to botnet command-and-control activity, with ThreatFox tagging it as C2 and ErrTraffic and URLScan observing it resolving to 178.16.52.101 and returning direct 403 responses. Investigators said alerts involving the domain do not by themselves prove endpoint compromise, because traffic may stem from blocked browser requests, abused notification permissions, malicious extensions, redirects, service workers, or user execution of a ClickFix-style copied command.
Separate threat-intelligence records classified rinomobile.ink and cosmetic-deals.store as dangerous Botnet C&C infrastructure associated with Trojan.Win64.Agentb and Trojan.Win64.Agent, respectively. Both domains were registered through NameCheap and use Cloudflare name servers, while telemetry linked them to multiple URLs, dozens of IPv4 addresses, and significant hit volumes, reinforcing concerns that newly registered consumer-themed domains are being used for malware operations and should not be allowlisted; defenders were advised to review browser artifacts first and escalate to endpoint investigation if there are signs of execution or persistence.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
The Trojan Killer article states that ThreatFox recorded enter-press-cdn.info as first seen on July 31, 2026. It describes the domain as a high-confidence botnet command-and-control indicator tagged c2 and ErrTraffic and associated with an unknown loader.
WHOIS data in the Kaspersky report states that cosmetic-deals.store was created on 28 March 2026. The report classifies the domain as dangerous and categorizes it as Botnet C&C associated with Trojan.Win64.Agent.
WHOIS data in the Kaspersky report states that rinomobile.ink was created on 28 March 2026. The same report classifies the domain as dangerous and as Botnet C&C associated with Trojan.Win64.Agentb.
The Kaspersky report says the WHOIS record for rinomobile.ink was updated on 27 May 2026. The domain is listed in the report as dangerous Botnet C&C infrastructure.
The Kaspersky report says the WHOIS record for cosmetic-deals.store was updated on 2 April 2026. The domain remained registered through NameCheap and used Cloudflare name servers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
trojan-killer.net
Open sourceopentip.kaspersky.com
Open sourceopentip.kaspersky.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.