ThreatFox IOC Database

You are viewing the ThreatFox database entry for url https://ws.upgifter.pro/c.

Database Entry


IOC ID:1853663
IOC: https://ws.upgifter.pro/c
IOC Type :url
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS219502 STORMCLOUD-AS
Country:- US
First seen:2026-07-19 07:08:21 UTC
Last seen:never
UUID:09903aef-833d-11f1-8973-42010aa4000a
Reporter Anonymous
Reward 5 credits from ThreatFox
Tags:backdoor mtproto python stealer telegram
Reference: https://ws.upgifter.pro/c

Avatar
Anonymous
Static IOC extracted from two related samples targeting Telegram MTProto sessions. The URL is hard-coded as a credential-exfiltration endpoint. The newer sample also contains a Python backdoor using the same host for C2; that exact delivered file has malformed metadata literals and may fail to load, while an earlier syntactically valid sample reused the same endpoint. Newer sample SHA-256: ff7e08d4f087bd15e7a6a1d7fe3fff46eaf1ed2adea08d1f94920c6fc633d09e.