ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain ti.twilight.zip.

Database Entry


IOC ID:1358808
IOC: ti.twilight.zip
IOC Type :domain
Threat Type :botnet_cc
Malware: More_eggs
Malware alias:SpicyOmelette, SKID
Confidence Level : Confidence level is moderate (49%)
Is compromised? : False
ASN:AS4134 CHINANET-BACKBONE
Country:- CN
First seen:2024-12-20 10:20:06 UTC
Last seen:2025-11-13 12:04:20 UTC
UUID:0b2bb746-beac-11ef-91ae-42010aa4000a
Reporter johannes
Reward 5 credits from ThreatFox
Reference: https://www.esentire.com/blog/winos4-0-online-module-staging-component-used-in-cleversoar-campaign

Avatar
johannes
Winos4.0 stager C2, from the eSentire report "Winos4.0 “Online Module” Staging Component Used in CleverSoar Campaign". See all IOC from that report at https://rosti.bin.re/reports/fOdsme1A