ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://expansiveuser.com/api.

Database Entry


IOC ID:1605299
IOC: https://expansiveuser.com/api
IOC Type :url
Threat Type :botnet_cc
Malware: Lumma Stealer
Malware alias:LummaC2 Stealer
Confidence Level : Confidence level is elevated (75%)
ASN:AS29802 HVC-AS
Country:- US
First seen:2025-10-02 05:10:41 UTC
Last seen:never
UUID:693145b5-9ef3-11f0-9671-42010aa4000a
Reporter ninjacatcher
Reward 5 credits from ThreatFox
Tags:c2 Lumma