TF-1811920
low
📛 Threat Title
CountLoader: Domain that is used for botnet Command&control (C&C) health-smooth-eu1.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: CountLoader. Confidence: 49. First seen: 2026-05-13 18:34:42 UTC. Reporter: johannes.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
31.59.139.111
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/31.59.139.111
IOC database
- Type
- ipv4
- Value
31.59.139.111- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from domain health-smooth-eu1.com
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/31.59.139.111
domain
health-smooth-eu1.com
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
health-smooth-eu1.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to CountLoader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: CountLoader. Confidence: 49. First seen: 2026-05-13 18:34:42 UTC. Reporter: johannes.
- External reference Threatfox IOCs/Threats
Remediations (10)
-
web:acsmi.org
A botnet's command and control (C2) structure dictates its efficiency and resilience. Centralized models use singular C2 servers that broadcast commands to infected nodes, offering simplicity but with a critical vulnerability—once identified, authorities can dismantle them.
-
web:docs.fortinet.com
The Fortinet Cookbook contains examples of how to integrate Fortinet products into your network and use features such as security profiles, wireless networking, and VPN. Using the Cookbook, you can go from idea to execution in simple steps, configuring a secure network for better productivity with reduced risk.
-
web:docs.fortinet.com
From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .
-
web:networkthreatdetection.com
Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.
-
web:success.trendmicro.com
A process attempted to communicate with a URL/ Domain /IP in User-defined C&C List. User-defined C&C List contains callback addresses that the administrator added for the purpose of blocking or logging any associated connections.
-
web:www.blackhat.com
This research is primarily focused on the use of penetration testing approach to nd fundamental weaknesses and con guration aws re-siding in Command and Control (C&C) panels used by bot herders to manage botnets . This paper generalizes the ndings that have been noticed during testing and analysis of several C&C panels.
-
web:www.cyberly.org
One key component of large-scale DoS and Distributed Denial of Service (DDoS) attacks is the use of command-and-control (C&C) servers. These servers play a critical role in coordinating attacks, particularly when attackers use a network of compromised devices, known as a botnet .
-
web:www.mcafee.com
Sinkholing Sinkholing is a defensive technique in which researchers take control of malicious domains or infrastructure used by malware. Instead of allowing infected systems to communicate with attacker controlled C2 servers, the traffic is redirected to a researcher controlled server. This approach enables researchers to monitor infected hosts, collect telemetry, measure the scale and spread ...
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.spamhaus.org
Botnet command & control domain registrations go through the roof in 2018 When Spamhaus Malware Labs observe a 40% increase in the number of domains that are being registered by cybercriminals to host a botnet command & control (C&C) it's time to understand where the threats are coming from in the top-level domains (TLDs) space and learn how you can protect against them.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.