ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://plagnol-charpentier.fr/wp-includes/random_compat/random_compata0zW7Q.

Database Entry


IOC ID:1356257
IOC: https://plagnol-charpentier.fr/wp-includes/random_compat/random_compata0zW7Q
IOC Type :url
Threat Type :botnet_cc
Malware: Amadey
Confidence Level : Confidence level is moderate (49%)
Is compromised? : False
ASN:AS16276 OVH
Country:- FR
First seen:2024-12-12 19:47:52 UTC
Last seen:never
UUID:3db6c225-b89e-11ef-91ae-42010aa4000a
Reporter johannes
Reward 5 credits from ThreatFox
Tags:Wipbot
Reference: https://www.microsoft.com/en-us/security/blog/2024/12/11/frequent-freeloader-part-ii-russian-actor-secret-blizzard-using-tools-of-other-groups-to-attack-ukraine/

Avatar
johannes
KazuarV2 C2 Secret Blizzard June, from the Microsoft report "Frequent freeloader part II: Russian actor Secret Blizzard using tools of other groups to attack Ukraine". See all IOC from that report at https://rosti.bin.re/reports/GcSswmyc