OTX-69ea063742f065ee8e738c3a
medium
📛 Threat Title
RaspberryRobin - C2 IP/Domain Tracker - 2026-04-23
Description
This pulse contains IOCs related to RaspberryRobin Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Due to the volume of indicators collected by this tracker, new pulses are created periodically. The timestamp in the title indicates when this pulse was created. Pulse contains 20 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (21)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
80.78.24.30
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/80.78.24.30
IOC database
- Type
- ipv4
- Value
80.78.24.30- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain gz.qa
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/80.78.24.30
domain
gz.qa
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/gz.qa
UrlVoid 4 / 35
1 feed
IOC database
- Type
- domain
- Value
gz.qa- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/gz.qa
domain
q0.wf
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/q0.wf
UrlVoid 3 / 35
1 feed
IOC database
- Type
- domain
- Value
q0.wf- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/q0.wf
url
http://2t.pm:8080/
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovLzJ0LnBtOjgwODAv
UrlVoid 2 / 35
IOC database
- Type
- url
- Value
http://2t.pm:8080/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovLzJ0LnBtOjgwODAv
url
http://0p.rs:8080/
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovLzBwLnJzOjgwODAv
UrlVoid 3 / 35
IOC database
- Type
- url
- Value
http://0p.rs:8080/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovLzBwLnJzOjgwODAv
url
http://a0.pm:8080/
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL2EwLnBtOjgwODAv
UrlVoid 3 / 35
IOC database
- Type
- url
- Value
http://a0.pm:8080/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL2EwLnBtOjgwODAv
url
http://w4.wf:8080/jax0jtnjb3k/desktop-et51ajo=bruno
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://w4.wf:8080/jax0jtnjb3k/desktop-et51ajo=bruno- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://w4.wf:8080/jax0jtnjb3k/desktop-dsmevvl=bruno
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://w4.wf:8080/jax0jtnjb3k/desktop-dsmevvl=bruno- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
url
http://w4.wf:8080/jax0jtnjb3k/azure-pc=azure
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL3c0LndmOjgwODAvamF4MGp0bmpiM2svYXp1cmUtcGM9YXp1cmU
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://w4.wf:8080/jax0jtnjb3k/azure-pc=azure- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL3c0LndmOjgwODAvamF4MGp0bmpiM2svYXp1cmUtcGM9YXp1cmU
url
http://w4.wf:8080/jax0jtnjb3k/walker-pc=walker
VT: not in VT
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://w4.wf:8080/jax0jtnjb3k/walker-pc=walker- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: not in VT
domain
w4.wf
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/w4.wf
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
w4.wf- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/w4.wf
url
http://gz.qa:8080/a4bxn6zetehyiwk/y72bcgijwvzcvc52h/desktop-dsmevvl
VT: not in VT
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://gz.qa:8080/a4bxn6zetehyiwk/y72bcgijwvzcvc52h/desktop-dsmevvl- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: not in VT
url
http://gz.qa:8080/a4bxn6zetehyiwk/y72bcgijwvzcvc52h/desktop-et51ajo
VT: not in VT
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://gz.qa:8080/a4bxn6zetehyiwk/y72bcgijwvzcvc52h/desktop-et51ajo- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: not in VT
url
http://gz.qa:8080/yuy2jkf8umikdlv6sisij0gu/azure-pc
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL2d6LnFhOjgwODAveXV5MmprZjh1bWlrZGx2NnNpc2lqMGd1L2F6dXJlLXBj
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://gz.qa:8080/yuy2jkf8umikdlv6sisij0gu/azure-pc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL2d6LnFhOjgwODAveXV5MmprZjh1bWlrZGx2NnNpc2lqMGd1L2F6dXJlLXBj
url
http://gz.qa:8080/yuy2jkf8umikdlv6sisij0gu/desktop-et51ajo
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL2d6LnFhOjgwODAveXV5MmprZjh1bWlrZGx2NnNpc2lqMGd1L2Rlc2t0b3AtZXQ1MWFqbw
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://gz.qa:8080/yuy2jkf8umikdlv6sisij0gu/desktop-et51ajo- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL2d6LnFhOjgwODAveXV5MmprZjh1bWlrZGx2NnNpc2lqMGd1L2Rlc2t0b3AtZXQ1MWFqbw
url
http://gz.qa:8080/yuy2jkf8umikdlv6sisij0gu/walker-pc
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL2d6LnFhOjgwODAveXV5MmprZjh1bWlrZGx2NnNpc2lqMGd1L3dhbGtlci1wYw
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://gz.qa:8080/yuy2jkf8umikdlv6sisij0gu/walker-pc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL2d6LnFhOjgwODAveXV5MmprZjh1bWlrZGx2NnNpc2lqMGd1L3dhbGtlci1wYw
url
http://gz.qa:8080/y/pb0vlagtbxhy8asrcc/b7yy4v/r7z/do52cbie/phrjlkk/desktop-et51ajo
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL2d6LnFhOjgwODAveS9wYjB2bGFndGJ4aHk4YXNyY2MvYjd5eTR2L3I3ei9kbzUyY2JpZS9waHJqbGtrL2Rlc2t0b3AtZXQ1MWFqbw
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://gz.qa:8080/y/pb0vlagtbxhy8asrcc/b7yy4v/r7z/do52cbie/phrjlkk/desktop-et51ajo- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL2d6LnFhOjgwODAveS9wYjB2bGFndGJ4aHk4YXNyY2MvYjd5eTR2L3I3ei9kbzUyY2JpZS9waHJqbGtrL2Rlc2t0b3AtZXQ1MWFqbw
url
http://gz.qa:8080/y/pb0vlagtbxhy8asrcc/b7yy4v/r7z/do52cbie/phrjlkk/walker-pc
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL2d6LnFhOjgwODAveS9wYjB2bGFndGJ4aHk4YXNyY2MvYjd5eTR2L3I3ei9kbzUyY2JpZS9waHJqbGtrL3dhbGtlci1wYw
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://gz.qa:8080/y/pb0vlagtbxhy8asrcc/b7yy4v/r7z/do52cbie/phrjlkk/walker-pc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for urls/aHR0cDovL2d6LnFhOjgwODAveS9wYjB2bGFndGJ4aHk4YXNyY2MvYjd5eTR2L3I3ei9kbzUyY2JpZS9waHJqbGtrL3dhbGtlci1wYw
url
https://foo.bar:8081/
VT 0 / 90
UrlVoid 0 / 35
IOC database
- Type
- url
- Value
https://foo.bar:8081/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| TLD | bar |
| Final URL | https://foo.bar:8081/ |
History
| First seen on VirusTotal | 2023-09-23 00:16 UTC |
| Last submission | 2023-09-23 00:16 UTC |
| Last analysis | 2023-09-23 00:16 UTC |
| Last modified on VirusTotal | 2023-09-23 00:21 UTC |
url
http://jzm.pw:8080/
VT 11 / 98
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://jzm.pw:8080/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 11 of 98 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| BitDefender | malicious | malware |
| CyRadar | malicious | malicious |
| ESET | malicious | malware |
| Forcepoint ThreatSeeker | malicious | phishing |
| Fortinet | malicious | malware |
| G-Data | malicious | malware |
| Lionic | malicious | malicious |
| Seclookup | malicious | malicious |
| Sophos | malicious | malware |
| VIPRE | malicious | malware |
| Webroot | malicious | malicious |
Details From VirusTotal
Basic Properties
| TLD | pw |
| Final URL | http://jzm.pw:8080/ |
History
| First seen on VirusTotal | 2022-03-14 15:38 UTC |
| Last submission | 2025-10-03 15:14 UTC |
| Last analysis | 2025-10-03 15:14 UTC |
| Last modified on VirusTotal | 2025-10-03 19:12 UTC |
url
http://gz.qa:8080/a4bxn6zetehyiwk/y72bcgijwvzcvc52h/azure-pc
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
http://gz.qa:8080/a4bxn6zetehyiwk/y72bcgijwvzcvc52h/azure-pc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to RaspberryRobin Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Due to the volume of indicators collected by this tracker, new pulses are created periodically. The timestamp in the title indicates when this pulse was created.
Remediations (8)
-
web:any.run
Raspberry Robin is a trojan that primarily spreads through infected USB drives and exploits legitimate Windows commands. This malware is known for its advanced obfuscation techniques, anti-debugging mechanisms, and ability to gain persistence on infected systems. Raspberry Robin often communicates with command-and-control servers over the TOR network and can download additional malicious payloads.
-
web:cyberpress.org
In a significant development in cybersecurity research, Silent Push has identified nearly 200 unique command and control ( C2 ) domains associated with the Raspberry Robin malware. This discovery, made through the identification of key nameservers, domain naming conventions, and IP and ASN diversity patterns, provides crucial insights into the infrastructure of this sophisticated threat actor ...
-
web:cybersecsentinel.com
Overview Raspberry Robin, first detected in 2021, has rapidly evolved from a relatively straightforward USB worm into a full-fledged Initial Access Broker (IAB) and malware loader used by cybercriminals and nation-state actors alike. Most recently, its infrastructure has been linked to over 180 active command-and-control domains and is being used by threat groups such as LockBit, Clop, and ...
-
web:who.is
Find information on any domain name or website. Large database of whois information, RDAP, DNS, domain names, name servers, IPs, and tools for searching and monitoring domain names.
-
web:whois.domaintools.com
Research domain ownership with Whois Lookup: Get ownership info, IP address history, rank, traffic, SEO & more. Find available domains & domains for sale.
-
web:www.iptrackeronline.com
Instant WHOIS lookup for any domain. Find owner details, registration dates, nameservers, and expiry info. Free unlimited searches.
-
web:www.picussecurity.com
Raspberry Robin evolves from a USB worm into a top initial access broker, using phishing, exploits, and resilient C2 to enable major attacks.
-
web:www.zscaler.com
Raspberry Robin's latest updates include enhanced obfuscation, ChaCha-20 encryption, new exploits, & campaign-specific anti-analysis techniques.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.