ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://uygprdfkttn6xhsvngx3yjn2sa5mef6czptzkxnutgo7satsjqlo5pqd.onion:50051.

Database Entry


IOC ID:1891914
IOC: http://uygprdfkttn6xhsvngx3yjn2sa5mef6czptzkxnutgo7satsjqlo5pqd.onion:50051
IOC Type :url
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
First seen:2026-08-31 15:46:47 UTC
Last seen:never
UUID:2327ca78-a551-11f1-9e13-42010aa4000a
Reporter Evwaldo
Reward 5 credits from ThreatFox
Tags:ClickFix goldengate grpc NodeJS-MaaS RAT TOR

Avatar
Evwaldo
Confirmed Tor C2 for the NodeJS MaaS modular RAT. Recovered from a multi-stage ClickFix campaign. The RAT configuration uses this onion service for gRPC command-and-control on TCP/50051. The same onion service serves the Stage 4 JavaScript RAT from TCP/8443 /bundle. Observed deployment metadata: operator=goldengate, tag=sl_x. Stage 4 SHA-256: 067E321F8018C785F2C5089807E59BB9D6A1CAF97ACA775A3B435D4FB7B564B6.