s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1815717 medium

📛 Threat Title

Unknown malware: URL that is used for botnet Command&control (C&C) https://monstersStat.com/tracker.js

Category: Unknown malware Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 50. First seen: 2026-05-17 18:50:48 UTC. Reporter: anonymous.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain monstersstat.com VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/monstersstat.com
UrlVoid 3 / 35

IOC database

Type
domain
Value
monstersstat.com
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Domain that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/monstersstat.com

url https://monstersStat.com/tracker.js VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly9tb25zdGVyc1N0YXQuY29tL3RyYWNrZXIuanM

IOC database

Type
url
Value
https://monstersStat.com/tracker.js
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-1815717

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/urls/aHR0cHM6Ly9tb25zdGVyc1N0YXQuY29tL3RyYWNrZXIuanM

url https://monstersstat.com/tracker.js

IOC database

Type
url
Value
https://monstersstat.com/tracker.js
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 50. First seen: 2026-05-17 18:50:48 UTC. Reporter: anonymous.

Remediations (10)

  • web:abuse.ch

    Varying in focus areas, all platforms are designed to help identify, track, and mitigate against malware and botnet -related cyber threats. The abuse.ch community, anti-virus vendors and threat intelligence providers can contribute and consume from the following platforms:

  • web:any.run

    Botnet malware can be delivered through various means, including phishing emails, malware -infected websites, and even USB drives. Once a device becomes infected, the botnet malware establishes a connection with a command-and-control (C&C) server, essentially becoming a node in the botnet network.

  • web:help.bitsighttech.com

    ⇤ Compromised Systems Findings The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navi...

  • web:ismalicious.com

    Comprehensive threat intelligence database with 500M+ malicious IPs, domains, and cyberthreat data. Check phishing sites, malware , adware, tracking domains & vulnerabilities. Real-time blocklist API for cybersecurity professionals. Try free!

  • web:malware-hunter.shodan.io

    Malware Hunter is a specialized Shodan crawler that explores the Internet looking for command & control (C2s) servers for botnets . It does this by pretending to be an infected client that's reporting back to a C2.

  • web:networkthreatdetection.com

    Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.

  • web:radar.cloudflare.com

    Understand the security, performance, technology, and network details of a URL with a publicly shareable report.

  • web:www.cyfirma.com

    The use of jilas.net as the initial JavaScript payload source, combined with a trusted open source tool for encoded command retrieval, highlights a strategic approach to malware distribution.

  • web:www.spamhaus.com

    Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware -infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.