ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://a1136850.xsph.ru/bad89ab3.php.

Database Entry


IOC ID:1544037
IOC: http://a1136850.xsph.ru/bad89ab3.php
IOC Type :url
Threat Type :botnet_cc
Malware: DCRat
Malware alias:DarkCrystal RAT
Confidence Level : Confidence level is high (100%)
ASN:AS35278 SPRINTHOST
Country:- RU
First seen:2025-06-12 03:45:21 UTC
Last seen:never
UUID:aa766675-473f-11f0-a7f6-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:dcrat RAT

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2025-06-12 07:05:21 5a7e59ae0fa4917f94ff223e8499130923a02b0f0f6a39a02fe38dbde3a26e47
2025-06-12 03:45:26 41556fc8255feca7f1ddd424cec3c7e3f9007fea4f810db053a3886b4d7b8ec1