TF-1932695
high
📛 Threat Title
Remus: URL that is used for botnet Command&control (C&C) http://urbandm.click:4812/sessions
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-25 06:37:24 UTC. Reporter: Myrtus0x0. Tags: Remus.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://urbandm.click:4812/sessions
UrlVoid 2 / 36
IOC database
- Type
- url
- Value
http://urbandm.click:4812/sessions- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that is used for botnet Command&control (C&C) attributed to Remus
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-25 06:37:24 UTC. Reporter: Myrtus0x0. Tags: Remus.
Remediations (8)
-
web:cybersecuritynews.com
Remus Hides Its Command Server on Ethereum At the heart of this campaign is the decision to hide Remus's command server information inside an Ethereum smart contract rather than hard‑coding it in the malware.
-
web:cybersecuritynews.com
Remus Windows stealer uses ClickFix attacks to steal passwords, wallet data, files, browser information, and AI tool credentials.
-
web:flashpoint.io
Remus stealer represents a sophisticated continuation of the MaaS infostealer model left behind by Lumma's collapse. While the developer asserts independence, the overwhelming code overlaps, matching obfuscation techniques, and administrative panels indicate that Remus is either heavily inspired by, or derived from the Lumma codebase.
-
web:portal.vyprsec.ai
A new information-stealing malware, Remus , is employing an Ethereum smart contract to dynamically retrieve its command and control server address, making it harder to block.
-
web:securityboulevard.com
In this post, we explore the emergence of Remus Stealer, analyzing its structural and behavioral similarities to the infamous Lumma malware. The post Remus Stealer: A New, Not-So-New Infostealer appeared first on Flashpoint.
-
web:threatfox.abuse.ch
You are viewing the ThreatFox database entry for url http ://urbandm.click:4812/documents.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.thespacelab.tv
How Remus Malware Uses Ethereum for Command and Control Instead of keeping one control-server address inside the malware, Remus asks a hardcoded Ethereum smart contract where to connect. The contract returns encoded server information, which the malware decodes before sending stolen data over ordinary web traffic.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.