ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://u13794788m.ha003.t.justns.ru/ksalex.php.

Database Entry


IOC ID:391220
IOC: http://u13794788m.ha003.t.justns.ru/ksalex.php
IOC Type :url
Threat Type :botnet_cc
Malware: DCRat
Malware alias:DarkCrystal RAT
Confidence Level : Confidence level is high (100%)
First seen:2022-02-28 05:55:51 UTC
Last seen:never
UUID:15f97950-985b-11ec-a022-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:dcrat

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-02-28 18:00:31 bd201923cb73953bf498fa38605be4f38e617e1dea209ab124a0f3c7b3a14f79
2022-02-28 05:55:54 cfa36f8b69b482615ce9dfe611d1670c37a29959c6070d7da92fb6418c6136ce