s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1811881 high

📛 Threat Title

Unknown malware: URL that is used for botnet Command&control (C&C) http://109.199.111.106:5000/login

Category: Unknown malware First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-05-13 16:30:03 UTC. Reporter: antiphishorg. Tags: AS51167, Contabo GmbH, cyberaliens.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 109.199.111.106

IOC database

Type
ipv4
Value
109.199.111.106
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
ip:port combination that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

url http://109.199.111.106:5000/login

IOC database

Type
url
Value
http://109.199.111.106:5000/login
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-05-13 16:30:03 UTC. Reporter: antiphishorg. Tags: AS51167, Contabo GmbH, cyberaliens.

Remediations (8)

  • web:abuse.ch

    Varying in focus areas, all platforms are designed to help identify, track, and mitigate against malware and botnet -related cyber threats. The abuse.ch community, anti-virus vendors and threat intelligence providers can contribute and consume from the following platforms:

  • web:any.run

    Botnet malware can be delivered through various means, including phishing emails, malware -infected websites, and even USB drives. Once a device becomes infected, the botnet malware establishes a connection with a command-and-control (C&C) server, essentially becoming a node in the botnet network.

  • web:clickpatrol.com

    A botnet is a network of devices infected by malware . Malware is the malicious software used to control the device; the botnet is the collective group of infected devices acting under a single controller.

  • web:exchange.xforce.ibmcloud.com

    IBM X-Force Exchange is a threat intelligence sharing platform enabling research on security threats, aggregation of intelligence, and collaboration with peers

  • web:help.bitsighttech.com

    ⇤ Compromised Systems Findings The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navi...

  • web:networkthreatdetection.com

    Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.

  • web:www.spamhaus.com

    Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware -infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…