s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-62988acf84b9d57540fb68d5 high

📛 Threat Title

PoshC2 - C2 IP/Domain Tracker

Category: threat-intel Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

This pulse contains IOCs related to PoshC2 Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 217.154.212.25 VT 19 / 91

IOC database

Type
ipv4
Value
217.154.212.25
First seen
Last seen
Attached to this threat
Appears in
8 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Cobalt Strike

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 19 of 91 VirusTotal vendors

VendorVerdictDetection
ADMINUSLabs malicious malicious
alphaMountain.ai malicious malicious
AlphaSOC malicious malware
BitDefender malicious malware
Certego malicious malicious
Chong Lua Dao malicious malicious
CyRadar malicious malware
Emsisoft malicious malware
Forcepoint ThreatSeeker malicious malicious
Fortinet malicious malware
G-Data malicious malware
Hunt.io Intelligence malicious malicious
Lionic malicious malicious
SOCRadar malicious malicious
Sophos malicious malware
VIPRE malicious malware
Webroot malicious malicious
ESET suspicious suspicious
Gridinsoft suspicious suspicious

Details From VirusTotal

Basic Properties
Network217.154.212.0/22
CountryDE
AS ownerIONOS SE
ASN8560
Regional registryRIPE NCC
History
Last analysis2026-06-16 00:24 UTC
Last modified on VirusTotal2026-06-16 00:29 UTC
WHOIS record date2026-05-20 05:07 UTC

References (1)

  • OTX pulse AlienVaulkt OTX

    This pulse contains IOCs related to PoshC2 Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Remediations (8)

  • web:1337skills.com

    PoshC2 is a proxy-aware C2 framework developed by Nettitude for red teaming and post-exploitation activities. It features PowerShell exploitation capabilities, lateral movement tools, and comprehensive proxy support for operating in restricted network environments.

  • web:awesome.ecosyste.ms

    A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.

  • web:deepwiki.com

    PoshC2 is a proxy-aware command and control ( C2 ) framework designed for offensive security professionals. It provides a robust post-exploitation platform with various implant types and flexible communication methods to support penetration testing, red teaming, and security assessments.

  • web:github.com

    PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement. PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools, allowing an extendible and flexible C2 framework.

  • web:medium.com

    PoshC2 is natively cross-platform, providing consistent C2 capabilities regardless of the OS you compromise. It's also proxy-aware, a critical feature for navigating the complex, segmented ...

  • web:poshc2.readthedocs.io

    Overview PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement. PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools, allowing an extendible and flexible C2 framework.

  • web:www.hackingarticles.in

    Learn how to use PoshC2 as a command and control framework for Windows and Linux systems, and understand its features and techniques now.

  • web:www.kali.org

    poshc2 Proxy aware C2 framework This package contains a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement. PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools, allowing an extendible and flexible C2 framework.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…