ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://37.252.1.137/DumpprotectVm6/requestCpulongpoll/processPublic/2CpuProviderbetter/5sql7/Dump/Test/http23/base58/PhpVmJavascript/api/PrivateVmTrackWordpress/RequestUpdatePrivate/Processor1Cdn3/Geo/protect/Externalprocessordefault.php.

Database Entry


IOC ID:608327
IOC: http://37.252.1.137/DumpprotectVm6/requestCpulongpoll/processPublic/2CpuProviderbetter/5sql7/Dump/Test/http23/base58/PhpVmJavascript/api/PrivateVmTrackWordpress/RequestUpdatePrivate/Processor1Cdn3/Geo/protect/Externalprocessordefault.php
IOC Type :url
Threat Type :botnet_cc
Malware: DCRat
Malware alias:DarkCrystal RAT
Confidence Level : Confidence level is high (100%)
ASN:AS12722 RECONN
Country:- RU
First seen:2022-05-19 22:43:44 UTC
Last seen:never
UUID:2330cfea-d7c5-11ec-ae87-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:dcrat

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-05-19 22:43:47 60fca7278d05665e12c9183b8aabc62442fd48dc7b87752e52ef1cee134b9173