s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-686e309be67630606e6c593e high

📛 Threat Title

Pantegana - C2 IP/Domain Tracker

Category: Pantegana Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

This pulse contains IOCs related to Pantegana Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 45.61.130.75

IOC database

Type
ipv4
Value
45.61.130.75
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 209.141.37.254

IOC database

Type
ipv4
Value
209.141.37.254
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • OTX pulse AlienVaulkt OTX

    This pulse contains IOCs related to Pantegana Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Remediations (8)

  • web:apt.etda.or.th

    Last change to this tool card: 27 August 2024 Download this tool card in JSON format Previous: Pandora Next: PapaCreep All groups using tool Pantegana

  • web:cyberpress.org

    Pantegana RAT, an open-source cross-platform botnet written in Golang, targets Windows, Linux, and macOS that uses HTTPS for C2 communication.

  • web:gbhackers.com

    Mitigations Organizations should integrate threat intelligence to detect Pantegana and SparkRAT C2 domains in real time, prioritize patching of high-risk RCE vulnerabilities in perimeter devices and enforce strict access controls on VPN and firewall management interfaces.

  • web:github.com

    When running make you will need to specify any external IP or domain to include in the SSL certificate. This ip would be the public ip of the C2 server where the pantegana server binary would run.

  • web:hunt.io

    Explore Pantegana RAT, an open-source malware targeting Windows, Linux, and macOS, its deployment in cyber-espionage campaigns, and mitigation strategies.

  • web:malpedia.caad.fkie.fraunhofer.de

    A multi-platform RAT written in Go. 2025-09-24 ⋅ The Hacker News ⋅ Ravie Lakshmanan Chinese Hackers RedNovember Target Global Governments Using Pantegana and Cobalt Strike Cobalt Strike Leslieloader Pantegana SparkRAT Storm-2077 2024-07-16 ⋅ Recorded Future ⋅ Insikt Group TAG-100 Uses Open-Source Tools in Suspected Global Espionage Campaign, Compromising Two Asia-Pacific ...

  • web:threatfox.abuse.ch

    The table below shows all indicators of compromise (IOCs) that are associated with this particulare tag (max 1000).

  • web:www.recordedfuture.com

    RedNovember, a likely Chinese state-sponsored cyber-espionage group, has targeted global government, defense, and tech sectors using advanced tools like Pantegana and Cobalt Strike. Discover the latest findings and victimology from Recorded Future's in-depth analysis.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…