s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-603d237bbd5bebc72a1ef46c high

📛 Threat Title

Covenant - C2 IP/Domain Tracker

Category: threat-intel Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

This pulse contains IOCs related to Covenant Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 2 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (9)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 95.141.133.7

IOC database

Type
ipv4
Value
95.141.133.7
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 128.199.197.162 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/128.199.197.162

IOC database

Type
ipv4
Value
128.199.197.162
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain ikat.ha.cked.net

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/128.199.197.162

ipv4 217.154.212.25 VT 19 / 91

IOC database

Type
ipv4
Value
217.154.212.25
First seen
Last seen
Attached to this threat
Appears in
9 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Cobalt Strike

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 19 of 91 VirusTotal vendors

VendorVerdictDetection
ADMINUSLabs malicious malicious
alphaMountain.ai malicious malicious
AlphaSOC malicious malware
BitDefender malicious malware
Certego malicious malicious
Chong Lua Dao malicious malicious
CyRadar malicious malware
Emsisoft malicious malware
Forcepoint ThreatSeeker malicious malicious
Fortinet malicious malware
G-Data malicious malware
Hunt.io Intelligence malicious malicious
Lionic malicious malicious
SOCRadar malicious malicious
Sophos malicious malware
VIPRE malicious malware
Webroot malicious malicious
ESET suspicious suspicious
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
Network217.154.212.0/22
CountryDE
AS ownerIONOS SE
ASN8560
Regional registryRIPE NCC
History
Last analysis2026-06-16 00:24 UTC
Last modified on VirusTotal2026-06-16 00:29 UTC
WHOIS record date2026-05-20 05:07 UTC

domain web.security-core.co.uk UrlVoid 0 / 35

IOC database

Type
domain
Value
web.security-core.co.uk
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 140.99.164.101 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/140.99.164.101

IOC database

Type
ipv4
Value
140.99.164.101
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/140.99.164.101

ipv4 80.96.109.95 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/80.96.109.95
1 feed

IOC database

Type
ipv4
Value
80.96.109.95
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: Ipsum. Open in Threat Hunt →

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/80.96.109.95

ipv4 178.105.68.110

IOC database

Type
ipv4
Value
178.105.68.110
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain ikat.ha.cked.net VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ikat.ha.cked.net
UrlVoid 4 / 35

IOC database

Type
domain
Value
ikat.ha.cked.net
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ikat.ha.cked.net

ipv4 75.119.131.232 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/75.119.131.232

IOC database

Type
ipv4
Value
75.119.131.232
First seen
Last seen
Attached to this threat
Appears in
3 threats

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/75.119.131.232

References (1)

  • OTX pulse AlienVaulkt OTX

    This pulse contains IOCs related to Covenant Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Remediations (8)

  • web:1337skills.com

    Covenant is a .NET-based command and control ( C2 ) framework designed for red team operations and penetration testing. It features a web-based interface for team collaboration, supports multiple communication protocols, and provides extensive post-exploitation capabilities specifically tailored for Windows environments using .NET assemblies.

  • web:github-wiki-see.page

    Covenant is an open-source command and control ( C2 ) framework that allows you to manage and control a network of compromised machines. In this tutorial, we will go over how to set up a Covenant C2 server for use in penetration testing.

  • web:github.com

    C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/botnet/ C2 infrastructure.

  • web:hunt.io

    Explore Covenant , a .NET-based C2 framework for collaborative offensive security operations, its features, usage, and mitigation strategies.

  • web:netwerklabs.com

    Command & Control Mastery with Covenant C2 : PART-I Table of Contents This entry is part 11 of 25 in the series Red Team Engagements Views: 235 In the realm of cybersecurity, especially within red teaming and penetration testing, Command and Control ( C2 ) frameworks are pivotal.

  • web:netwrix.com

    Covenant is one of the latest and greatest command and control ( C2 ) post-exploitation frameworks. This post will walk you through the process of configuring Covenant and using it to execute payloads on compromised hosts. Note: This post demonstrates the capabilities of Covenant as of mid-September 2019. 1. Install Covenant First, we need to install Covenant on … Continued

  • web:www.microsoft.com

    These activities lead to identifying C2 servers operated by human-operated ransomware actors and botnet actors and discovering compromised IPs and domains associated with known nation-state actors. Network protection is aided by machine learning models that incriminate IP addresses used for C2 by inspecting network traffic telemetry.

  • web:www.redfoxsec.com

    Discover how the Covenant C2 framework empowers red team operators with .NET-based post-exploitation capabilities. Learn key commands, features, and how professional pentesting services can help secure your organization.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…