OTX-686e307eb0514486e9b244f4
high
📛 Threat Title
Hookbot - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to Hookbot Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
185.187.235.122
IOC database
- Type
- ipv4
- Value
185.187.235.122- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
185.99.255.17
IOC database
- Type
- ipv4
- Value
185.99.255.17- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to ERMAC
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to Hookbot Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:cebrf.knf.gov.pl
HookBuilder - let's create a HookBot Our latest findings of complex infrastructure elements and panels for building malicious Android apps associated with HookBot underscore the continued evolution and adaptation of this threat.
-
web:cyberpress.org
HookBot , a mobile banking Trojan, exploits Android devices to steal sensitive financial and personal data. As part of a larger cybercrime network, it poses a significant global threat due to its stealthy nature and ability to bypass security measures. Malicious apps, often disguised as legitimate software, are installed on victim devices, which establish communication with a C2 server to ...
-
web:cybersecuritynews.com
Once installed, the " HookBot -infected app" establishes communication with a " C2 " server that allows it to "receive updates," "new payloads," and "gather device information," before employing various attack techniques to extract user data.
-
web:darkwebinformer.com
A new domain-based indicator has been identified linked to botnet command-and-control infrastructure for apk.hook ( HookBot ). The domain, hosted under Hetzner (AS24940), is tied to ERMAC v3.0 activity and represents a high-confidence threat to Android devices targeted by banking trojans.
-
web:github.com
Automatically created C2 Feeds. Contribute to drb-ra/C2IntelFeeds development by creating an account on GitHub.
-
web:github.com
C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/botnet/ C2 infrastructure.
-
web:hunt.io
Beginner's guide to hunting exposed C2 dashboards like Supershell, HookBot , Chaos, Unam, Mythic, and Metasploit using paths, titles, and hashes
-
web:www.netcraft.com
Key data This article explores Netcraft's research into the HookBot malware family and associated attacks on Android devices, including examples of: Typical HookBot behaviors, such as the use of overlay attacks The types of brands and apps being impersonated How HookBot utilizes Command and Control ( C2 ) servers to continuously evolve A builder tool that enables threat actors to develop and ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.