ThreatFox IOC Database
You are viewing the ThreatFox database entry for url https://exovision.cc/.
Database Entry
| IOC ID: | 1867497 |
|---|---|
| IOC: | https://exovision.cc/ |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Unknown RAT |
| Confidence Level : | Confidence level is elevated (75%) |
| Is compromised? : | False |
| ASN: | AS210457 KYONIX |
| Country: | RU |
| First seen: | 2026-08-02 19:53:45 UTC |
| Last seen: | never |
| UUID: | b99b36d8-8e94-11f1-8325-42010aa4000a |
| Reporter | Anonymous |
| Reward | 5 credits from ThreatFox |
| Tags: | Android c2-panel RAT stealer |
| Reference: | https://imgur.com/a/5lgXRzZ |
Anonymous
"Exovision Panel v1.0.0" - C2 for a Windows stealer/RAT builder.Builder features: persistence via Startup + Watchdog tasks, install to %LOCALAPPDATA%,
PE version info spoofed as "Runtime Broker", cryptor-packed payloads, and a built-in
VirusTotal detection-rate check (/api/builder/vt-progress) before distribution.
Stealer exfil endpoints: /api/steals, /api/steals/download(-latest). SignalR hub /ex0vhub.
Cluster: exovision.cc + exovision.shop + citus.dev-9137-s27.icu all resolve to 2.26.252.134,
byte-identical pages (ETag 1dd1fde25e5116f, 55535 bytes, Kestrel), single TLS cert
sha256 3ecd7d7d... covering .cc + .shop SANs. Access sold via Telegram bot for crypto.
Observed 2026-08-02.
RU