ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://vitantgroup.com/xmlrpc.php.

Database Entry


IOC ID:1355641
IOC: http://vitantgroup.com/xmlrpc.php
IOC Type :url
Threat Type :botnet_cc
Malware: Amadey
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS200000 Ukraine-AS
Country:- UA
First seen:2024-12-11 17:55:10 UTC
Last seen:2024-12-12 15:32:05 UTC
UUID:10cac414-b7e9-11ef-91ae-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Amadey APT geo Turla UKR

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2024-12-11 18:00:13 dfdc0318f3dc5ba3f960b1f338b638cd9645856d2a2af8aa33ea0f9979a9ca4c
2024-12-11 18:00:13 ced8891ea8d87005de989f25f0f94634d1fc70ebb37302cf21aa0c0b0e13350f