ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://retiriu.cyou/api.

Database Entry


IOC ID:1761082
IOC: https://retiriu.cyou/api
IOC Type :url
Threat Type :botnet_cc
Malware: Lumma Stealer
Malware alias:LummaC2 Stealer
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS14956 ROUTERHOSTING
Country:- IR
First seen:2026-03-07 18:10:24 UTC
Last seen:2026-03-13 12:31:32 UTC
UUID:e9bb8eea-1a50-11f1-9af6-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:Lumma
Reference: https://bazaar.abuse.ch/sample/5c47f62de622440aa88faa2bcafd0d1af4971b02e8d39b046a573c6cbe97a6c4/

Avatar
abuse_ch
lumma (aka LummaC2 Stealer) botnet C2