ThreatFox IOC Database

You are viewing the ThreatFox database entry for url http://9837.cllt.nyashteam.ru/_Defaultwindows.php.

Database Entry


IOC ID:850326
IOC: http://9837.cllt.nyashteam.ru/_Defaultwindows.php
IOC Type :url
Threat Type :botnet_cc
Malware: DCRat
Malware alias:DarkCrystal RAT
Confidence Level : Confidence level is high (100%)
ASN:AS13335 CLOUDFLARENET
Country:- US
First seen:2022-09-18 07:10:27 UTC
Last seen:never
UUID:f93dd907-3720-11ed-ae73-42010aa4000a
Reporter abuse_ch
Reward 5 credits from ThreatFox
Tags:dcrat

Malware Samples


The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).

Time stamp (UTC)SHA256 hashBazaar
2022-10-03 08:35:17 9d23a234dbe5c77bdb7ef8c15e72dc31de7cce7a296ba4c6021fa38c860b6aa6
2022-09-18 07:10:29 8bf59bd262ec0b7bea2f012fe2baede9d93bc8d7593d5657b8d4895227d7ab6e