OTX-62988acf84b9d57540fb68d5
high
📛 Threat Title
PoshC2 - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to PoshC2 Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
217.154.212.25
VT 19 / 91
IOC database
- Type
- ipv4
- Value
217.154.212.25- First seen
- Last seen
- Attached to this threat
- Appears in
- 8 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Cobalt Strike
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 19 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| alphaMountain.ai | malicious | malicious |
| AlphaSOC | malicious | malware |
| BitDefender | malicious | malware |
| Certego | malicious | malicious |
| Chong Lua Dao | malicious | malicious |
| CyRadar | malicious | malware |
| Emsisoft | malicious | malware |
| Forcepoint ThreatSeeker | malicious | malicious |
| Fortinet | malicious | malware |
| G-Data | malicious | malware |
| Hunt.io Intelligence | malicious | malicious |
| Lionic | malicious | malicious |
| SOCRadar | malicious | malicious |
| Sophos | malicious | malware |
| VIPRE | malicious | malware |
| Webroot | malicious | malicious |
| ESET | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 217.154.212.0/22 |
| Country | DE |
| AS owner | IONOS SE |
| ASN | 8560 |
| Regional registry | RIPE NCC |
History
| Last analysis | 2026-06-16 00:24 UTC |
| Last modified on VirusTotal | 2026-06-16 00:29 UTC |
| WHOIS record date | 2026-05-20 05:07 UTC |
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to PoshC2 Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:1337skills.com
PoshC2 is a proxy-aware C2 framework developed by Nettitude for red teaming and post-exploitation activities. It features PowerShell exploitation capabilities, lateral movement tools, and comprehensive proxy support for operating in restricted network environments.
-
web:awesome.ecosyste.ms
A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.
-
web:deepwiki.com
PoshC2 is a proxy-aware command and control ( C2 ) framework designed for offensive security professionals. It provides a robust post-exploitation platform with various implant types and flexible communication methods to support penetration testing, red teaming, and security assessments.
-
web:github.com
PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement. PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools, allowing an extendible and flexible C2 framework.
-
web:medium.com
PoshC2 is natively cross-platform, providing consistent C2 capabilities regardless of the OS you compromise. It's also proxy-aware, a critical feature for navigating the complex, segmented ...
-
web:poshc2.readthedocs.io
Overview PoshC2 is a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement. PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools, allowing an extendible and flexible C2 framework.
-
web:www.hackingarticles.in
Learn how to use PoshC2 as a command and control framework for Windows and Linux systems, and understand its features and techniques now.
-
web:www.kali.org
poshc2 Proxy aware C2 framework This package contains a proxy aware C2 framework used to aid penetration testers with red teaming, post-exploitation and lateral movement. PoshC2 is primarily written in Python3 and follows a modular format to enable users to add their own modules and tools, allowing an extendible and flexible C2 framework.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.