ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://213.159.64.146/5Generator/Processorline6/pipe6/7ProtonDbTemp/linuxWindows/mariadbpublic/3BetterWp/LocaluniversalWordpressdownloads/track/Universal/Secure5LocalGenerator/videoline_SecureDefaultsqlLinuxWindowsGeneratoruploads.php.

Database Entry


IOC ID:1304649
IOC: http://213.159.64.146/5Generator/Processorline6/pipe6/7ProtonDbTemp/linuxWindows/mariadbpublic/3BetterWp/LocaluniversalWordpressdownloads/track/Universal/Secure5LocalGenerator/videoline_SecureDefaultsqlLinuxWindowsGeneratoruploads.php
IOC Type :url
Threat Type :botnet_cc
Malware: DCRat
Malware alias:DarkCrystal RAT
Confidence Level : Confidence level is high (100%)
ASN:AS44477 UNKNOWN
Country:- MD
First seen:2024-07-29 03:35:14 UTC
Last seen:never
UUID:911131ac-4d5b-11ef-ae0a-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:dcrat

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2024-07-29 03:35:16 92e0f273870ba2a539d80cfc3eb811463d19aa255ba282a59846cbe842bacbe4