OTX-603d237bbd5bebc72a1ef46c
high
📛 Threat Title
Covenant - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to Covenant Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 2 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (9)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
95.141.133.7
IOC database
- Type
- ipv4
- Value
95.141.133.7- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
128.199.197.162
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/128.199.197.162
IOC database
- Type
- ipv4
- Value
128.199.197.162- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain ikat.ha.cked.net
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/128.199.197.162
ipv4
217.154.212.25
VT 19 / 91
IOC database
- Type
- ipv4
- Value
217.154.212.25- First seen
- Last seen
- Attached to this threat
- Appears in
- 9 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Cobalt Strike
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 19 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| BitDefender | malicious | malware |
| Certego | malicious | malicious |
| Chong Lua Dao | malicious | malicious |
| CyRadar | malicious | malware |
| Emsisoft | malicious | malware |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | malware |
| Hunt.io Intelligence | malicious | malicious |
| Lionic | malicious | malicious |
| SOCRadar | malicious | malicious |
| Sophos | malicious | malware |
| VIPRE | malicious | malware |
| Webroot | malicious | malicious |
| ESET | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 217.154.212.0/22 |
| Country | DE |
| AS owner | IONOS SE |
| ASN | 8560 |
| Regional registry | RIPE NCC |
History
| Last analysis | 2026-06-16 00:24 UTC |
| Last modified on VirusTotal | 2026-06-16 00:29 UTC |
| WHOIS record date | 2026-05-20 05:07 UTC |
domain
web.security-core.co.uk
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
web.security-core.co.uk- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
140.99.164.101
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/140.99.164.101
IOC database
- Type
- ipv4
- Value
140.99.164.101- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/140.99.164.101
ipv4
80.96.109.95
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/80.96.109.95
1 feed
IOC database
- Type
- ipv4
- Value
80.96.109.95- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: Ipsum. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/80.96.109.95
ipv4
178.105.68.110
IOC database
- Type
- ipv4
- Value
178.105.68.110- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
ikat.ha.cked.net
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ikat.ha.cked.net
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
ikat.ha.cked.net- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/ikat.ha.cked.net
ipv4
75.119.131.232
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/75.119.131.232
IOC database
- Type
- ipv4
- Value
75.119.131.232- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/75.119.131.232
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to Covenant Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:1337skills.com
Covenant is a .NET-based command and control ( C2 ) framework designed for red team operations and penetration testing. It features a web-based interface for team collaboration, supports multiple communication protocols, and provides extensive post-exploitation capabilities specifically tailored for Windows environments using .NET assemblies.
-
web:github-wiki-see.page
Covenant is an open-source command and control ( C2 ) framework that allows you to manage and control a network of compromised machines. In this tutorial, we will go over how to set up a Covenant C2 server for use in penetration testing.
-
web:github.com
C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/botnet/ C2 infrastructure.
-
web:hunt.io
Explore Covenant , a .NET-based C2 framework for collaborative offensive security operations, its features, usage, and mitigation strategies.
-
web:netwerklabs.com
Command & Control Mastery with Covenant C2 : PART-I Table of Contents This entry is part 11 of 25 in the series Red Team Engagements Views: 235 In the realm of cybersecurity, especially within red teaming and penetration testing, Command and Control ( C2 ) frameworks are pivotal.
-
web:netwrix.com
Covenant is one of the latest and greatest command and control ( C2 ) post-exploitation frameworks. This post will walk you through the process of configuring Covenant and using it to execute payloads on compromised hosts. Note: This post demonstrates the capabilities of Covenant as of mid-September 2019. 1. Install Covenant First, we need to install Covenant on … Continued
-
web:www.microsoft.com
These activities lead to identifying C2 servers operated by human-operated ransomware actors and botnet actors and discovering compromised IPs and domains associated with known nation-state actors. Network protection is aided by machine learning models that incriminate IP addresses used for C2 by inspecting network traffic telemetry.
-
web:www.redfoxsec.com
Discover how the Covenant C2 framework empowers red team operators with .NET-based post-exploitation capabilities. Learn key commands, features, and how professional pentesting services can help secure your organization.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.