ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://cobyrose.com/tmp/.

Database Entry


IOC ID:1590664
IOC: http://cobyrose.com/tmp/
IOC Type :url
Threat Type :botnet_cc
Malware: SmokeLoader
Malware alias:Dofoil, Sharik, Smoke, Smoke Loader
Confidence Level : Confidence level is moderate (49%)
Is compromised? : False
ASN:AS215703 FREAKHOSTING
Country:- GB
First seen:2025-09-16 06:48:40 UTC
Last seen:2025-09-17 05:56:13 UTC
UUID:a9e541b1-9254-11f0-bfa6-42010aa4000a
Reporter johannes
Reward 5 credits from ThreatFox
Reference: https://www.zscaler.com/blogs/security-research/smokeloader-rises-ashes

Avatar
johannes
SmokeLoader C2, from the ZScaler report "SmokeLoader Rises From the Ashes". See all IOC from that report at https://rosti.bin.re/reports/r5BsP9eH