🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

ThreatFox IOC Database

You are viewing the ThreatFox database entry for domain 9bf7j6bzrzzg.ifuckurmomjaffacakes.win.

Database Entry


IOC ID:1959648
IOC: 9bf7j6bzrzzg.ifuckurmomjaffacakes.win
IOC Type :domain
Threat Type :botnet_cc
Malware: Unknown malware
Confidence Level : Confidence level is high (100%)
Is compromised? : False
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2026-10-10 06:01:53 UTC
Last seen:never
UUID:e162ca55-c444-11f1-bd13-42010aa4000a
Reporter secuJay
Reward 5 credits from ThreatFox
Tags:bytenode Discord Electron fake-game Hades RAT stealer

Avatar
secuJay
Fake game 'RacingSimulator' spread via Discord DMs (tinyurl -> Dropbox). NSIS/electron-builder installer, main code bytenode-compiled (app.protected.jsc); strings AES-256-CBC, key 35f200b7aa3507c966974f294d0af690b20474457e753236a9536c39a8036ebd. Self-named 'HADES' (build tag HADES_ramezzx_DC52BF09CD1EAF810E9681BEA33BEDBD). C2 https://9bf7j6bzrzzg.ifuckurmomjaffacakes.win (/api/v1/... + socket.io). Browser creds/cookies/cards, Discord tokens + client injection, wallets, keylogger, clipboard, screen/webcam capture, remote cmd, UAC/TaskMgr disable.