ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://83.220.170.162/DownloadsServer/ProcessUniversal/7/generator1/dlewppythonsql/secure/javascriptExternalPublic/DownloadsLocallongpollapi/request/dump/Defaultbetterprocess/Wp/voiddb/8temporaryFlower6/Vmphplongpolldatalife.php.

Database Entry


IOC ID:844272
IOC: http://83.220.170.162/DownloadsServer/ProcessUniversal/7/generator1/dlewppythonsql/secure/javascriptExternalPublic/DownloadsLocallongpollapi/request/dump/Defaultbetterprocess/Wp/voiddb/8temporaryFlower6/Vmphplongpolldatalife.php
IOC Type :url
Threat Type :botnet_cc
Malware: DCRat
Malware alias:DarkCrystal RAT
Confidence Level : Confidence level is high (100%)
ASN:AS29182 RU-JSCIOT
Country:- RU
First seen:2022-08-20 17:55:32 UTC
Last seen:never
UUID:4938535e-20b1-11ed-ae73-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:dcrat

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-08-20 17:55:34 ea5b2b1a8df076e4a54e5aaa8b68ecd2e73e9f7ef4d476c5362b0a8b20698534