🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain moweros.net.

Database Entry


IOC ID:1892723
IOC: moweros.net
IOC Type :domain
Threat Type :botnet_cc
Malware: Unknown RAT
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS209413 DEDIK-CH
First seen:2026-09-02 05:50:09 UTC
Last seen:never
UUID:1bd9b8b1-a661-11f1-b569-42010aa4000a
Reporter Justice_Hammer
Reward 5 credits from ThreatFox
Tags:ComponentTask33 etherhiding NodeJS-RAT
Reference: https://github.com/Justice-Hammer/threat-hunting-detections/blob/main/30-research/RES-0007%20-%20ComponentTask33%20MSI%20Loader%20with%20On-Chain%20C2%20Discovery.md

Avatar
Justice_Hammer
ComponentTask33 C2 resolver domains. bedotiq.net (port 3854) is current as of 2026-09-01; moweros.net (3851) was set and replaced 16 minutes later on 2026-08-31. Both resolve to 176.65.144.127 (AS209413) alongside the original shift-api-control.com. Both were batch-registered 2026-08-24 four seconds apart via NiceNIC on NS*.ERANS.RU and held unused for seven days - a pre-staged reserve pool, so expect more unactivated names in that batch. Both also carry MX and SPF pointing at the C2 host: treat them as mail-capable, not only as C2. The agent does not hardcode its C2: it resolves the panel URL at runtime from a Polygon contract (EtherHiding) 0xf9099d0d747368cce8C10226CC9AF2bFD4DDbCF4, getPanelUrl() selector 0x4ab7874e. setPanelUrl emits event topic0 0xb441e97002ff45bf8194f5209fab03d6ea838f98f2e8bf3392956dfc76103f6e, which publishes each new C2 on-chain the moment it is written - so the next C2 is readable before it appears on the wire.