passlisted in Coinbase#3 by calls of 11 on this host
0.02 USDC
per call, as the listing declares it on eip155:
- Validation state
- pass
- Uptime, 7 / 30 / 90 days
- 100% / 100% / 100%
- Calls, trailing 30 days
- 1
- Unique payers, trailing 30 days
- 1
- Last called
- 2026-09-11 23:53 UTC
- First observed by TOLLderived
- 2026-09-12
- Pricederived
- 0.02 USDC
- Networks
- 1
How big is this endpoint among the ones like it?
No trace is drawn of this endpoint’s own volume. Its counters have changed 1 time across 18 observations, and 3 changes are the fewest this site will draw a trace through, because two points and a guess are not a series. Every observation is in the JSON.
ot malware shares ot-intel-api.onrender.com with 10 other listed endpoints and is tied 3rd by calls with 8 others.
Callers of ot malware supply the query parameter name.
The declared response carries name, aliases, confidence, first_seen, capabilities, data_sources and 2 others.
ot malware drew a single call from a single payer in the trailing 30 days.
The last call to ot malware came 4 days before the snapshot, 2026-09-11.
It is priced at 0.02 USDC on Base.
ot malware takes 7% of the calls counted across ot-intel-api.onrender.com.
TOLL files ot malware under the "other" category: a GET endpoint on ot-intel-api.onrender.com, listed in the Coinbase registry.
ot malware answered the sweep of 2026-09-15 with a valid 402, as at every sweep since 2026-09-12.
Closest in price to ot malware within the "other" category: uptime check at api.strale.io and solana fbfollowers at grov.fun.
ot malware is priced above 81% of comparable listings in the "other" category.
The wallet paid by ot malware is the payee of 11 endpoints on one host.
The price of ot malware is declared by 155 other listings in the "other" category too.
the payment options, as of 2026-09-15 21:20 UTC · method · pinnable
| registry | network | asset | amount | scheme | pay to |
|---|---|---|---|---|---|
| Coinbase | eip155: | USDC | 0.02 USDC | exact | 0x188819…7C767B |
the checks, as of 2026-09-15 04:48 UTC · method · pinnableendpoint answered HTTP 402
No named check failed.
Every sweep that observed this endpoint, newest first.
| observed, UTC | state | failed checks | sweep |
|---|---|---|---|
| 2026-09-15 04:48 UTC | pass | 0 | daily-2026-09-15 |
| 2026-09-14 04:44 UTC | pass | 0 | daily-2026-09-14 |
| 2026-09-13 04:41 UTC | pass | 0 | daily-2026-09-13 |
| 2026-09-12 06:58 UTC | pass | 0 | daily-2026-09-12 |
| 2026-09-12 05:25 UTC | pass | 0 | new-2026-09-12T05-25-11-634Z |
Presence in a registry, not liveness of the service (method). Newest first.
- listed in Coinbase
From the registry record, not validated by TOLL.the declared schema, as of 2026-09-11 23:53 UTC · method · live
The input and output block
{
"input": {
"type": "http",
"method": "GET",
"queryParams": {
"name": "PIPEDREAM"
}
},
"output": {
"type": "json",
"example": {
"name": "PIPEDREAM",
"aliases": [
"INCONTROLLER"
],
"confidence": "high",
"first_seen": "2022",
"capabilities": [
"discovery",
"lateral_movement",
"disruption",
"destruction"
],
"data_sources": [
"Dragos-Threat-Intelligence",
"OT-Intel-DB",
"MITRE-ATT&CK-ICS",
"DeepSeek-CTI-Analysis"
],
"affected_vendors": [
"Schneider Electric",
"OMRON"
],
"attributed_actor": "CHERNOVITE",
"mitre_techniques": [
"T0843",
"T0821",
"T0855"
],
"targeted_protocols": [
"Modbus",
"OPC UA",
"CODESYS",
"IEC 61850"
],
"detection_signatures": [
"YARA rule: PIPEDREAM_loader",
"Anomalous CODESYS write commands"
]
}
}
}Cite this page
The pinned URL below renders this page from the snapshot of 2026-09-15 21:20 UTC and does not change; the live page does, every six hours. Data reuse is under CC BY 4.0 (terms).
Plain text
TOLL, "ot malware on ot-intel-api.onrender.com", snapshot of 2026-09-15 21:20 UTC. https://tollindex.com/e/ot-intel-api-onrender-com-ot-malware-574aae/at/2026-09-15T21-20Z. Accessed [access date].
BibTeX
@misc{toll-e-ot-intel-api-onrender-com-ot-malware-574aae-2026-09-15T21-20Z,
author = {TOLL},
title = {ot malware on ot-intel-api.onrender.com},
howpublished = {\url{https://tollindex.com/e/ot-intel-api-onrender-com-ot-malware-574aae/at/2026-09-15T21-20Z}},
year = {2026},
month = {9},
note = {Pinned view of the snapshot of 2026-09-15 21:20 UTC. Accessed [access date].}
}None yet. Anything submitted through the form below is published here with its outcome.