ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://3.79.245.165/async/Longpollsecure/7Async5/WpCpuLocalCpu/7geoprovider/5Universal/CdntempDbjs/2RequestSecureProtect/Central/Cdnmulti/Generatorbetter2Universal/6FlowerApitrack/Default/20/7api/updategenerator3geo/Private/imageVmPhpJs_SqlBaselocalCentralTemporary.php.

Database Entry


IOC ID:1232456
IOC: http://3.79.245.165/async/Longpollsecure/7Async5/WpCpuLocalCpu/7geoprovider/5Universal/CdntempDbjs/2RequestSecureProtect/Central/Cdnmulti/Generatorbetter2Universal/6FlowerApitrack/Default/20/7api/updategenerator3geo/Private/imageVmPhpJs_SqlBaselocalCentralTemporary.php
IOC Type :url
Threat Type :botnet_cc
Malware: DCRat
Malware alias:DarkCrystal RAT
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS16509 AMAZON-02
Country:- US
First seen:2024-01-21 07:00:36 UTC
Last seen:never
UUID:c6eab07e-b82a-11ee-b6e4-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:dcrat

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2024-01-21 07:00:38 4b28df1a5c72982b065966aed5bb123abd06189dffb52822458451d01cd2c80d