🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain justily.duckdns.org.

Database Entry


IOC ID:1956257
IOC: justily.duckdns.org
IOC Type :domain
Threat Type :botnet_cc
Malware: Remcos
Malware alias:RemcosRAT, Remvio, Socmer
Confidence Level : Confidence level is elevated (75%)
Is compromised? : False
ASN:AS152586 KUROIT-AS-AP
Country:- GB
First seen:2026-10-07 10:20:20 UTC
Last seen:never
UUID:b2e5fcde-c238-11f1-bd13-42010aa4000a
Reporter abuse_ch
Reward 10 credits from kiwingulam4h
10 credits from junnyemyeuchi
20 credits from anonymous
Tags:remcos
Reference: https://bazaar.abuse.ch/sample/d5d4a0b2b8ea92c1884285498006925db911881fc0d2394e43a65db9e140f8db/

Avatar
abuse_ch
remcos (aka RemcosRAT,Remvio,Socmer) botnet C2 on port 2404 TCP