ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://46.3.199.52/1secure/Wordpress/50bigload0/7javascriptPython/Pipe/Apidefaultexternalmariadb/Multipipe/Php3Tracklocal/linevoiddb/1_7/Central/9Publicdle/Protonupdate/temp/Privatebaselongpoll/Vm9/Better/Proton/LowGeoTestcdn.php.

Database Entry


IOC ID:844003
IOC: http://46.3.199.52/1secure/Wordpress/50bigload0/7javascriptPython/Pipe/Apidefaultexternalmariadb/Multipipe/Php3Tracklocal/linevoiddb/1_7/Central/9Publicdle/Protonupdate/temp/Privatebaselongpoll/Vm9/Better/Proton/LowGeoTestcdn.php
IOC Type :url
Threat Type :botnet_cc
Malware: DCRat
Malware alias:DarkCrystal RAT
Confidence Level : Confidence level is high (100%)
ASN:AS209372 WSTelecom_Customers
Country:- LV
First seen:2022-08-18 20:20:17 UTC
Last seen:never
UUID:2ca290b0-1f33-11ed-ae73-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:dcrat

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-08-18 20:25:19 c7bd8900ecae8ea0a3a4ebee38692c1ebdd89642fae0830e45827672801ce32d