ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://todoexy.su/xqts.

Database Entry


IOC ID:1583395
IOC: https://todoexy.su/xqts
IOC Type :url
Threat Type :botnet_cc
Malware: Lumma Stealer
Malware alias:LummaC2 Stealer
Confidence Level : Confidence level is elevated (75%)
ASN:AS132203 TENCENT-NET-AP-CN
Country:- CN
First seen:2025-09-07 16:06:27 UTC
Last seen:2025-09-22 14:39:00 UTC
UUID:9c3830a5-8c04-11f0-bfa6-42010aa4000a
Reporter abuse_ch
Reward 50 credits from anonymous
Tags:Lumma
Reference: https://bazaar.abuse.ch/sample/2646ca597f90c084f80741cf122b58e55767582135a7d90e93cd6ffd165e9d4b/

Avatar
abuse_ch
lumma (aka LummaC2 Stealer) botnet C2