s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-686e30c27139d8b5a932170a high

📛 Threat Title

Unam Web Panel - C2 IP/Domain Tracker

Category: Unam Web Panel Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

This pulse contains IOCs related to Unam Web Panel Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 2 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (10)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 80.78.19.238

IOC database

Type
ipv4
Value
80.78.19.238
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 130.162.224.102

IOC database

Type
ipv4
Value
130.162.224.102
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Quasar RAT

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 37.183.212.80

IOC database

Type
ipv4
Value
37.183.212.80
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 5.88.124.39

IOC database

Type
ipv4
Value
5.88.124.39
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 138.124.29.208

IOC database

Type
ipv4
Value
138.124.29.208
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 176.100.37.216

IOC database

Type
ipv4
Value
176.100.37.216
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 185.157.162.187

IOC database

Type
ipv4
Value
185.157.162.187
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 192.253.248.10 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/192.253.248.10

IOC database

Type
ipv4
Value
192.253.248.10
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/192.253.248.10

ipv4 145.241.198.20

IOC database

Type
ipv4
Value
145.241.198.20
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 217.60.38.147

IOC database

Type
ipv4
Value
217.60.38.147
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • OTX pulse AlienVaulkt OTX

    This pulse contains IOCs related to Unam Web Panel Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Remediations (8)

  • web:darkwebinformer.com

    A domain-based indicator has been identified hosting a Unam Web Panel login interface, commonly leveraged for botnet and malware C2 operations. The infrastructure is hosted by Namecheap (AS22612) and is associated with remote administration and credential theft activity.

  • web:github.com

    Upload the contents of the UnamWebPanel folder to your webhosts "public_html" folder or the respective folder for your specific webhost. Your web panel should now be up and running, you can browse to the URL or IP of your website and you should see the login screen if everything went correctly.

  • web:github.com

    Rewrote almost all the code of the web panel to make it easier for others to edit Added new functionality called IP Blocking with its own page that allows blocking IP addresses from connecting to the web panel

  • web:github.com

    Rewrote almost all the code of the web panel to make it easier for others to edit Added new functionality called IP Blocking with its own page that allows blocking IP addresses from connecting to the web panel

  • web:hunt.io

    Beginner's guide to hunting exposed C2 dashboards like Supershell, HookBot, Chaos, Unam , Mythic, and Metasploit using paths, titles, and hashes

  • web:isske.medium.com

    Abusing indexing errors to view the workings Unam Web Panel Firstly, hi! it's certainly been a while but I put a lot of time into other areas in my life so unfortunately I can't put out much with this, but I promise I try. The main topic about this article is the Unam Web Panel , a popular assistant for the now disabled SilentCryptoMiner. This panel allows for a remote configuration of the ...

  • web:sechub.in

    By visiting tracker .viriback.com, you'll be able to see many different C2 servers that were exposed and still operates: One day I decided to go check on the security posture of C2 server, specifically the server of the UNAM malware.

  • web:undercodetesting.com

    This article explores practical techniques for tracking C2 infrastructure, attributing threats, and protecting networks. Learning Objectives Understand how to fingerprint malware C2 infrastructure using network-based indicators. Learn to apply custom Tags for tracking threats like Neptune Loader, Gremlin Stealer, and Unam Web Panel .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…