ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://37.46.130.214/Longpoll2External/Line/6/Mariadb/LinuxMariadbAuthPipe/dbvm3/CentralTowordpress/4Temporarydb/Datalifejs/lineSqlPackettemporary/CdnHttpProton/jsLineGenerator2/4Pipe6/javascriptServergeo9/Js_asyncCentral/SqlVm/securegeodefault.php.

Database Entry


IOC ID:297348
IOC: http://37.46.130.214/Longpoll2External/Line/6/Mariadb/LinuxMariadbAuthPipe/dbvm3/CentralTowordpress/4Temporarydb/Datalifejs/lineSqlPackettemporary/CdnHttpProton/jsLineGenerator2/4Pipe6/javascriptServergeo9/Js_asyncCentral/SqlVm/securegeodefault.php
IOC Type :url
Threat Type :botnet_cc
Malware: DCRat
Malware alias:DarkCrystal RAT
Confidence Level : Confidence level is high (100%)
ASN:AS29182 RU-JSCIOT
Country:- RU
First seen:2022-01-16 23:36:06 UTC
Last seen:never
UUID:1367cb3a-7725-11ec-8ab6-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:dcrat

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2023-01-02 18:15:18 d381f6edb32f269962e5ac16f8fd823052ac5e0bf0109ca2e34caf422b8d05b1
2022-01-16 23:36:08 8b28463392c4a0f9af89630bd6e72c8839e0f1684e2c0e18f93202b0a79a0d49