ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://servblog475.cfd/statweb255/index.php.

Database Entry


IOC ID:1518811
IOC: http://servblog475.cfd/statweb255/index.php
IOC Type :url
Threat Type :botnet_cc
Malware: SmokeLoader
Malware alias:Dofoil, Sharik, Smoke, Smoke Loader
Confidence Level : Confidence level is moderate (50%)
Is compromised? : False
ASN:AS22168 GOOGLE-CLOUD-PLATFORM
Country:- US
First seen:2025-05-09 16:05:03 UTC
Last seen:2025-06-21 14:36:40 UTC
UUID:5e49c584-2cef-11f0-90ee-42010aa4000a
Reporter juroots
Reward 5 credits from ThreatFox
Tags:agenda Ransomware smokeloader
Reference: https://www.trendmicro.com/en_us/research/25/e/agenda-ransomware-group-adds-smokeloader-and-netxloader-to-their.html