TF-1931119
high
📛 Threat Title
Remus: URL that is used for botnet Command&control (C&C) http://vgfeden.shop:7728/sessions
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-24 00:01:09 UTC. Reporter: Myrtus0x0. Tags: Remus.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://vgfeden.shop:7728/sessions
UrlVoid 1 / 36
IOC database
- Type
- url
- Value
http://vgfeden.shop:7728/sessions- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that is used for botnet Command&control (C&C) attributed to Remus
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-24 00:01:09 UTC. Reporter: Myrtus0x0. Tags: Remus.
Remediations (10)
-
web:any.run
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
-
web:cyberpedia.reasonlabs.com
The remote command and control servers send directives to the affected systems with the help-or, more accurately, the enslavement-of Trojan software that allows remote access to the infected computer. With this, the infected system is forced into a bot (a compromised system) that is added to a larger network of affected hosts known as a botnet .
-
web:feodotracker.abuse.ch
Botnet C2 IP Blocklist Dridex, Heodo (aka Emotet), TrickBot, QakBot (aka QuakBot / Qbot) and BazarLoader (aka BazarBackdoor) botnet command&control servers (C2s) usually reside on compromised servers and such that have been rented and setup by the threat actor itself for the sole purpose of botnet hosting.
-
web:feodotracker.abuse.ch
Here you can browse the list of botnet Command&Control servers ( C&Cs ) tracked by Feodo Tracker, associated with Dridex, TrickBot, QakBot (aka QuakBot/Qbot), BazarLoader (aka BazarBackdoor) and Emotet (aka Heodo). When Feodo Tracker was launched in 2010, it was meant to track Feodo botnet C&Cs .
-
web:flashpoint.io
Remus stealer represents a sophisticated continuation of the MaaS infostealer model left behind by Lumma's collapse. While the developer asserts independence, the overwhelming code overlaps, matching obfuscation techniques, and administrative panels indicate that Remus is either heavily inspired by, or derived from the Lumma codebase.
-
web:portal.vyprsec.ai
A new information-stealing malware, Remus , is employing an Ethereum smart contract to dynamically retrieve its command and control server address, making it harder to block.
-
web:threatfox.abuse.ch
You are viewing the ThreatFox database entry for url http ://zonxh.shop:7728/sessions.
-
web:threatfox.abuse.ch
ThreatFox IOC Database You are viewing the ThreatFox database entry for url http ://vgfeden.shop:7728/subscriptions. Database Entry
-
web:www.malwarebytes.com
Botnets are networks of computers infected by a botnet agent that are under hidden control of a third party. They are used to execute various commands ordered by the attacker. Most common uses of botnets are criminal operations that require distributed resources, such as DDoS attacks on selected targets, spam campaigns, and performing click fraud.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.