s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1931095 high

📛 Threat Title

Remus: URL that is used for botnet Command&control (C&C) http://jxewele.shop:4262/collections

Category: Remus Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-23 22:43:13 UTC. Reporter: Myrtus0x0. Tags: Remus.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

url http://jxewele.shop:4262/collections UrlVoid 1 / 36

IOC database

Type
url
Value
http://jxewele.shop:4262/collections
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that is used for botnet Command&control (C&C) attributed to Remus

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-23 22:43:13 UTC. Reporter: Myrtus0x0. Tags: Remus.

Remediations (10)

  • web:any.run

    Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.

  • web:cyberpress.org

    The campaign stands out because Remus does not rely only on a hardcoded command-and-control (C2) domain. Instead, it queries an Ethereum smart contract to obtain the current C2 address, using a technique known as EtherHiding.

  • web:feodotracker.abuse.ch

    Botnet C2 IP Blocklist Dridex, Heodo (aka Emotet), TrickBot, QakBot (aka QuakBot / Qbot) and BazarLoader (aka BazarBackdoor) botnet command&control servers (C2s) usually reside on compromised servers and such that have been rented and setup by the threat actor itself for the sole purpose of botnet hosting.

  • web:feodotracker.abuse.ch

    Here you can browse the list of botnet Command&Control servers ( C&Cs ) tracked by Feodo Tracker, associated with Dridex, TrickBot, QakBot (aka QuakBot/Qbot), BazarLoader (aka BazarBackdoor) and Emotet (aka Heodo). When Feodo Tracker was launched in 2010, it was meant to track Feodo botnet C&Cs .

  • web:flashpoint.io

    Remus stealer represents a sophisticated continuation of the MaaS infostealer model left behind by Lumma's collapse. While the developer asserts independence, the overwhelming code overlaps, matching obfuscation techniques, and administrative panels indicate that Remus is either heavily inspired by, or derived from the Lumma codebase.

  • web:portal.vyprsec.ai

    A new information-stealing malware, Remus , is employing an Ethereum smart contract to dynamically retrieve its command and control server address, making it harder to block.

  • web:threatfox.abuse.ch

    ThreatFox IOC Database You are viewing the ThreatFox database entry for url http ://jxewele.shop:4262/addresses. Database Entry

  • web:www.ituonline.com

    The infrastructure through which botnets are controlled and managed by attackers. C&C servers send commands to compromised machines (bots) to execute malicious activities. A botnet C&C (Command and Control) is the infrastructure that allows cybercriminals to manage and control a network of compromised computers or devices, known as bots.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

  • web:www.spamhaus.org

    Botnet Threat Update July to December 2025 Botnet Command & Controller (C&C) activity increased 24% this period, with Remote Access Trojans (RATs) accounting for 42% of the Top 20 malware associated with botnets .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.