🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain shift-api-control.com.

Database Entry


IOC ID:1891106
IOC: shift-api-control.com
IOC Type :domain
Threat Type :botnet_cc
Malware: Unknown RAT
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS209413 DEDIK-CH
First seen:2026-08-30 07:09:45 UTC
Last seen:2026-08-30 08:25:32 UTC
UUID:b3950262-a3c9-11f1-9e13-42010aa4000a
Reporter Justice_Hammer
Reward 5 credits from ThreatFox
Tags:ComponentTask33 etherhiding MSI-loader NodeJS-RAT on-chain-c2 Polygon
Reference: https://github.com/Justice-Hammer/threat-hunting-detections/blob/main/30-research/RES-0007%20-%20ComponentTask33%20MSI%20Loader%20with%20On-Chain%20C2%20Discovery.md

Avatar
Justice_Hammer
WebSocket C2 panel (Node.js Express), TCP/3847. Wire-observed in a 2026-08-27 detonation PCAP.