🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://ln6b9.shop/LN341/index.php.

Database Entry


IOC ID:1317142
IOC: http://ln6b9.shop/LN341/index.php
IOC Type :url
Threat Type :botnet_cc
Malware: Azorult
Malware alias:PuffStealer, Rultazo
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
First seen:2024-08-29 10:05:04 UTC
Last seen:2024-10-17 19:57:35 UTC
UUID:29be1edc-65ee-11ef-ac38-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:AZORult
Reference: https://bazaar.abuse.ch/sample/af44fccdfe3d6e7f65283d47f4a121bd70000dbcf1d8d91aead1c124cd808554/

Avatar
abuse_ch
azorult (aka PuffStealer,Rultazo) botnet C2

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2024-08-29 21:40:19 7c5bd51d549520223a57177f6dde2feea2a8e48077a36d73b1c96701360a68a6
2024-08-29 20:45:25 4a0dc5e1271e90a5fa81a2b042bb1b6f3eaef6159a8a3b07c563a8ca90fa7a74