OTX-686e30c27139d8b5a932170a
high
📛 Threat Title
Unam Web Panel - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to Unam Web Panel Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 2 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (10)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
80.78.19.238
IOC database
- Type
- ipv4
- Value
80.78.19.238- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
130.162.224.102
IOC database
- Type
- ipv4
- Value
130.162.224.102- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Quasar RAT
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
37.183.212.80
IOC database
- Type
- ipv4
- Value
37.183.212.80- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
5.88.124.39
IOC database
- Type
- ipv4
- Value
5.88.124.39- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
138.124.29.208
IOC database
- Type
- ipv4
- Value
138.124.29.208- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
176.100.37.216
IOC database
- Type
- ipv4
- Value
176.100.37.216- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
185.157.162.187
IOC database
- Type
- ipv4
- Value
185.157.162.187- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
192.253.248.10
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/192.253.248.10
IOC database
- Type
- ipv4
- Value
192.253.248.10- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/192.253.248.10
ipv4
145.241.198.20
IOC database
- Type
- ipv4
- Value
145.241.198.20- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
217.60.38.147
IOC database
- Type
- ipv4
- Value
217.60.38.147- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to Unam Web Panel Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:darkwebinformer.com
A domain-based indicator has been identified hosting a Unam Web Panel login interface, commonly leveraged for botnet and malware C2 operations. The infrastructure is hosted by Namecheap (AS22612) and is associated with remote administration and credential theft activity.
-
web:github.com
Upload the contents of the UnamWebPanel folder to your webhosts "public_html" folder or the respective folder for your specific webhost. Your web panel should now be up and running, you can browse to the URL or IP of your website and you should see the login screen if everything went correctly.
-
web:github.com
Rewrote almost all the code of the web panel to make it easier for others to edit Added new functionality called IP Blocking with its own page that allows blocking IP addresses from connecting to the web panel
-
web:github.com
Rewrote almost all the code of the web panel to make it easier for others to edit Added new functionality called IP Blocking with its own page that allows blocking IP addresses from connecting to the web panel
-
web:hunt.io
Beginner's guide to hunting exposed C2 dashboards like Supershell, HookBot, Chaos, Unam , Mythic, and Metasploit using paths, titles, and hashes
-
web:isske.medium.com
Abusing indexing errors to view the workings Unam Web Panel Firstly, hi! it's certainly been a while but I put a lot of time into other areas in my life so unfortunately I can't put out much with this, but I promise I try. The main topic about this article is the Unam Web Panel , a popular assistant for the now disabled SilentCryptoMiner. This panel allows for a remote configuration of the ...
-
web:sechub.in
By visiting tracker .viriback.com, you'll be able to see many different C2 servers that were exposed and still operates: One day I decided to go check on the security posture of C2 server, specifically the server of the UNAM malware.
-
web:undercodetesting.com
This article explores practical techniques for tracking C2 infrastructure, attributing threats, and protecting networks. Learning Objectives Understand how to fingerprint malware C2 infrastructure using network-based indicators. Learn to apply custom Tags for tracking threats like Neptune Loader, Gremlin Stealer, and Unam Web Panel .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.