🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain abcdefghijklmnopqrst.net.

Database Entry


IOC ID:1889270
IOC: abcdefghijklmnopqrst.net
IOC Type :domain
Threat Type :payload_delivery
Malware: XMRIG
Confidence Level : Confidence level is high (100%)
Is compromised? : True
ASN:AS210644 AEZA-AS
Country:- RU
First seen:2026-08-27 13:17:47 UTC
Last seen:never
UUID:295bdc80-a215-11f1-9e13-42010aa4000a
Reporter d351d3r
Reward 5 credits from ThreatFox
Tags:aarch64 AEZA cryptojacking CVE-2026-60004 FreeBSD monero xmrig
Reference: https://forums.truenas.com/t/100-cpu-usage-after-update/3498

Avatar
d351d3r
Live C2 of a cryptojacking operation paid continuously since 4 March 2023 to Monero wallet 41poaCNDTvs33KCFKfekN88Ehf59ddparQdFKFT4XKrUMnc1Ude7xtvhZuKfTai8tDML6gFyTAKY5RuDDxDqLRZpT8QpQ9b. Host 92.246.139.83 is AEZA GROUP LLC; domain registered 2025-12-09 via Tucows with Njalla nameservers. Root serves a first-stage dropper (Last-Modified 2026-08-24) that selects a payload by architecture: /1 x86_64 sha256 0b8e037d160bdb0b621c975c424f680b814bc438fd492ae376ff3140e209e480, /2 aarch64 sha256 6a1f70ef89684037bb3d0536657f00a92fbbcdb9067195b060128a221df79df5, /3 FreeBSD sha256 ed23db197d907bdb6873c02b7222110321b0f859e329c420a6d0d6e50220308f. The x86_64 payload is byte-identical to the miner recovered from my own server compromised via CVE-2026-60004 in August 2026. Documented by a victim in December 2025.