ThreatFox IOC Database
You are viewing the ThreatFox database entry for url http://45.39.33.177/peter.php.
Database Entry
| IOC ID: | 1873745 |
|---|---|
| IOC: | http://45.39.33.177/peter.php |
| IOC Type : | url |
| Threat Type : | botnet_cc |
| Malware: | Unknown Stealer |
| Confidence Level : | Confidence level is high (100%) |
| Is compromised? : | False |
| ASN: | AS211273 csoft |
| Country: | HK |
| First seen: | 2026-08-13 14:25:06 UTC |
| Last seen: | never |
| UUID: | 645b508a-9722-11f1-8a3d-42010aa4000a |
| Reporter | Anonymous |
| Reward | 5 credits from ThreatFox |
| Tags: | behance decoy-pdf freelancer-scam LNK powershell swisstransfer XOR |
| Reference: | https://any.run/report/61802c04497f157443cafe62b964f224953c527938aab3d3845acc058fcd5ae8/30b678d6-13b6-4a23-a3d2-bda8c50baa2c |
Anonymous
Delivered via Behance messaging to freelancers, impersonating a legitimate Dutch real estate company. Password-protected RAR (pw: "real estate") containing 7 decoy JPEGs and "Company_Website_Development_Project.pdf.lnk".The LNK is self-contained: it XOR-decodes both a decoy PDF (offset 26823, len 24503, key 158) and a stage-2 PowerShell script (offset 12288, len 14535, key 231) from its own body, writes the script to %TEMP% with a random name, runs it hidden via -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass, opens the decoy PDF, then deletes both the script and itself.
Stage 2 enumerates Win32_AntivirusProduct and POSTs hostname and process list to http://45.39.33.177/peter.php. Suricata: "ET HUNTING Suspicious POST with Common Windows Process Names - Possible Process List Exfiltration".
Final payload was not delivered during analysis (15-byte C2 response, no PE dropped, no registry persistence) - possible sandbox evasion. Family unconfirmed.
Related hashes:
RAR 6528F287924ED844DDE6AA89221CA3B9CC09F919C2721395CE787E68464CA775
LNK EA1BE43469BC6F689BF9D69490DBA13A93E0B4A5129BFE0EE370119CA2C45B49
Stage2 2B42B8CDFAB8D0E5CBBE47A85A48758B20A471450526C77C785543425CC14A0A
HK