ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://45.39.33.177/peter.php.

Database Entry


IOC ID:1873745
IOC: http://45.39.33.177/peter.php
IOC Type :url
Threat Type :botnet_cc
Malware: Unknown Stealer
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS211273 csoft
Country:- HK
First seen:2026-08-13 14:25:06 UTC
Last seen:never
UUID:645b508a-9722-11f1-8a3d-42010aa4000a
Reporter Anonymous
Reward 5 credits from ThreatFox
Tags:behance decoy-pdf freelancer-scam LNK powershell swisstransfer XOR
Reference: https://any.run/report/61802c04497f157443cafe62b964f224953c527938aab3d3845acc058fcd5ae8/30b678d6-13b6-4a23-a3d2-bda8c50baa2c

Avatar
Anonymous
Delivered via Behance messaging to freelancers, impersonating a legitimate Dutch real estate company. Password-protected RAR (pw: "real estate") containing 7 decoy JPEGs and "Company_Website_Development_Project.pdf.lnk".

The LNK is self-contained: it XOR-decodes both a decoy PDF (offset 26823, len 24503, key 158) and a stage-2 PowerShell script (offset 12288, len 14535, key 231) from its own body, writes the script to %TEMP% with a random name, runs it hidden via -NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass, opens the decoy PDF, then deletes both the script and itself.

Stage 2 enumerates Win32_AntivirusProduct and POSTs hostname and process list to http://45.39.33.177/peter.php. Suricata: "ET HUNTING Suspicious POST with Common Windows Process Names - Possible Process List Exfiltration".

Final payload was not delivered during analysis (15-byte C2 response, no PE dropped, no registry persistence) - possible sandbox evasion. Family unconfirmed.

Related hashes:
RAR 6528F287924ED844DDE6AA89221CA3B9CC09F919C2721395CE787E68464CA775
LNK EA1BE43469BC6F689BF9D69490DBA13A93E0B4A5129BFE0EE370119CA2C45B49
Stage2 2B42B8CDFAB8D0E5CBBE47A85A48758B20A471450526C77C785543425CC14A0A