s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1812293 medium

📛 Threat Title

PicassoLoader: Domain that is used for botnet Command&control (C&C) shinesafar.sardk.icu

Category: PicassoLoader Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: PicassoLoader. Confidence: 50. First seen: 2026-05-14 20:10:44 UTC. Reporter: anonymous.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 104.21.3.85 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.3.85

IOC database

Type
ipv4
Value
104.21.3.85
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain shinesafar.sardk.icu

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.3.85

ipv4 172.67.130.129 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.130.129

IOC database

Type
ipv4
Value
172.67.130.129
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain shinesafar.sardk.icu

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.130.129

domain shinesafar.sardk.icu VT 22 / 91 UrlVoid 3 / 35

IOC database

Type
domain
Value
shinesafar.sardk.icu
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to PicassoLoader

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 22 of 91 VirusTotal vendors

VendorVerdictDetection
ADMINUSLabs malicious malicious
AlphaSOC malicious malware
ArcSight Threat Intelligence malicious malware
BitDefender malicious malware
Certego malicious malicious
Chong Lua Dao malicious malicious
CRDF malicious malicious
CyRadar malicious malware
ESET malicious malware
ESTsecurity malicious malicious
Forcepoint ThreatSeeker malicious malicious
Fortinet malicious malware
G-Data malicious malware
Kaspersky malicious malware
Lionic malicious malicious
SOCRadar malicious phishing
Sophos malicious malware
Viettel Threat Intelligence malicious malicious
VIPRE malicious malware
Webroot malicious malicious
alphaMountain.ai suspicious suspicious
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
TLDicu
History
Creation date2026-03-11 00:00 UTC
Last analysis2026-07-27 13:13 UTC
Last modified on VirusTotal2026-07-29 11:18 UTC

References (3)

  • External reference Threatfox IOCs/Threats
  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: PicassoLoader. Confidence: 50. First seen: 2026-05-14 20:10:44 UTC. Reporter: anonymous.

Remediations (10)

  • web:assets.kpmg.com

    The PicassoLoader malware employs sophisticated techniques, initiating its intrusion through phishing emails with misleading attachments posing as familiar file types like Excel or PowerPoint documents. Once opened, these attachments trigger hidden code, setting off a complex chain of actions. This includes the deployment of a ".LNK" file via an embedded VBA macro or by leveraging regsvr32.exe ...

  • web:blog.polyswarm.io

    PicassoLoader , a downloader, was observed targeting government, military, and civilian entities in Ukraine and Poland. CERT-UA attributed this activity to GhostWriter. Key Takeaways PicassoLoader is a downloader used to target government, military, and civilian entities in Ukraine and Poland. The attacks occurred between April 2022 and July 2023.

  • web:docs.fortinet.com

    From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .

  • web:ethicalhacksacademy.com

    C2 Tracker is a free, community-driven Indicator of Compromise (IOC) feed designed to track IP addresses associated with known malware, botnets , and Command-and-Control (C2) infrastructure.

  • web:feodotracker.abuse.ch

    Dridex, Heodo (aka Emotet), TrickBot, QakBot (aka QuakBot / Qbot) and BazarLoader (aka BazarBackdoor) botnet command&control servers (C2s) usually reside on compromised servers and such that have been rented and setup by the threat actor itself for the sole purpose of botnet hosting. Feodo Tracker offers a blocklist of IP addresses that are associated with such botnet C2s. It can be used to ...

  • web:networkthreatdetection.com

    Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.

  • web:nicolascoolman.eu

    PicassoLoader is a malware downloader used to distribute other malware to infected systems. It is capable of bypassing security mechanisms and deploying varied payloads, thereby facilitating the installation of spyware, ransomware or other malicious tools.

  • web:www.cybermaterial.com

    Execution and Communication Upon successful execution, PICASSOLOADER establishes communication with its command-and-control (C2) server. This server acts as the central hub for managing the malware's activities, enabling attackers to issue commands, deliver additional payloads, and receive stolen data from the compromised system.

  • web:www.radware.com

    4. Use sinkholing to study botnets and contain threats: Instead of blocking all botnet traffic immediately, redirect suspicious traffic to a controlled sinkhole server. This allows you to observe the botnet's C&C communication patterns and gather intelligence on infrastructure, malware distribution, and attacker motives. 5.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…