ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain coolarition.com.

Database Entry


IOC ID:1316570
IOC: coolarition.com
IOC Type :domain
Threat Type :botnet_cc
Malware: Latrodectus
Malware alias:BLACKWIDOW, IceNova, Latrodectus, Lotus
Confidence Level : Confidence level is moderate (49%)
Is compromised? : False
First seen:2024-08-27 11:38:16 UTC
Last seen:2024-10-28 15:37:46 UTC
UUID:67c4a3ee-6465-11ef-ac38-42010aa4000a
Reporter johannes
Reward 5 credits from ThreatFox
Reference: https://hunt.io/blog/latrodectus-malware-masquerades-as-ahnlab-security-software-to-infect-victims

Avatar
johannes
PDR Ltd. / CloudFlare, Hostgnome Ltd / C2 for MeDExt.dll, from the Hunt.io report "Latrodectus Malware Masquerades as AhnLab Security Software to Infect Victims". See all IOC from that report at https://rosti.bin.re/reports/plIQZGXF