OTX-686e309be67630606e6c593e
high
📛 Threat Title
Pantegana - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to Pantegana Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
45.61.130.75
IOC database
- Type
- ipv4
- Value
45.61.130.75- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
209.141.37.254
IOC database
- Type
- ipv4
- Value
209.141.37.254- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to Pantegana Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:apt.etda.or.th
Last change to this tool card: 27 August 2024 Download this tool card in JSON format Previous: Pandora Next: PapaCreep All groups using tool Pantegana
-
web:cyberpress.org
Pantegana RAT, an open-source cross-platform botnet written in Golang, targets Windows, Linux, and macOS that uses HTTPS for C2 communication.
-
web:gbhackers.com
Mitigations Organizations should integrate threat intelligence to detect Pantegana and SparkRAT C2 domains in real time, prioritize patching of high-risk RCE vulnerabilities in perimeter devices and enforce strict access controls on VPN and firewall management interfaces.
-
web:github.com
When running make you will need to specify any external IP or domain to include in the SSL certificate. This ip would be the public ip of the C2 server where the pantegana server binary would run.
-
web:hunt.io
Explore Pantegana RAT, an open-source malware targeting Windows, Linux, and macOS, its deployment in cyber-espionage campaigns, and mitigation strategies.
-
web:malpedia.caad.fkie.fraunhofer.de
A multi-platform RAT written in Go. 2025-09-24 ⋅ The Hacker News ⋅ Ravie Lakshmanan Chinese Hackers RedNovember Target Global Governments Using Pantegana and Cobalt Strike Cobalt Strike Leslieloader Pantegana SparkRAT Storm-2077 2024-07-16 ⋅ Recorded Future ⋅ Insikt Group TAG-100 Uses Open-Source Tools in Suspected Global Espionage Campaign, Compromising Two Asia-Pacific ...
-
web:threatfox.abuse.ch
The table below shows all indicators of compromise (IOCs) that are associated with this particulare tag (max 1000).
-
web:www.recordedfuture.com
RedNovember, a likely Chinese state-sponsored cyber-espionage group, has targeted global government, defense, and tech sectors using advanced tools like Pantegana and Cobalt Strike. Discover the latest findings and victimology from Recorded Future's in-depth analysis.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.