TF-1811918
low
📛 Threat Title
CountLoader: Domain that is used for botnet Command&control (C&C) fileless-storage-s3.cc
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: CountLoader. Confidence: 49. First seen: 2026-05-13 18:34:41 UTC. Reporter: johannes.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
188.114.96.3
VT 0 / 92
IOC database
- Type
- ipv4
- Value
188.114.96.3- First seen
- Last seen
- Attached to this threat
- Appears in
- 105 threats
- Description
- Resolved from domain xingshang734.xyz
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Network | 188.114.96.0/22 |
| AS owner | Cloudflare, Inc. |
| ASN | 13335 |
History
| Last analysis | 2026-05-16 04:56 UTC |
| Last modified on VirusTotal | 2026-05-16 04:57 UTC |
| WHOIS record date | 2026-05-07 15:07 UTC |
ipv4
188.114.97.3
VT 8 / 92
IOC database
- Type
- ipv4
- Value
188.114.97.3- First seen
- Last seen
- Attached to this threat
- Appears in
- 105 threats
- Description
- Resolved from domain xingshang734.xyz
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 8 of 92 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| Chong Lua Dao | malicious | malicious |
| CyRadar | malicious | malicious |
| Lionic | malicious | malicious |
| Viettel Threat Intelligence | malicious | malicious |
| VIPRE | malicious | malware |
| Webroot | malicious | malicious |
| alphaMountain.ai | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 188.114.96.0/22 |
| AS owner | Cloudflare, Inc. |
| ASN | 13335 |
History
| Last analysis | 2026-05-16 04:44 UTC |
| Last modified on VirusTotal | 2026-05-16 04:46 UTC |
| WHOIS record date | 2026-05-07 01:55 UTC |
domain
fileless-storage-s3.cc
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
fileless-storage-s3.cc- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to CountLoader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: CountLoader. Confidence: 49. First seen: 2026-05-13 18:34:41 UTC. Reporter: johannes.
- External reference Threatfox IOCs/Threats
Remediations (10)
-
web:acsmi.org
A botnet's command and control (C2) structure dictates its efficiency and resilience. Centralized models use singular C2 servers that broadcast commands to infected nodes, offering simplicity but with a critical vulnerability—once identified, authorities can dismantle them.
-
web:docs.fortinet.com
From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .
-
web:github.com
Clusters and elements to attach to MISP events or attributes (like threat actors) - MISP/misp-galaxy
-
web:help.eset.com
This feed is a subset of a Botnet feed and provides information about URLs of Command and Control (C&C) servers and associated data.
-
web:networkthreatdetection.com
Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.
-
web:sites.cs.ucsb.edu
To this end, one requires techniques that can detect command and control (C&C) traffic, as well as the servers that host C&C services. Given the knowledge of a C&C server's IP address, one can use this in-formation to detect all hosts that attempt to contact such a server, and subsequently disinfect, disable, or block the infected machines.
-
web:success.trendmicro.com
A process attempted to communicate with a URL/ Domain /IP in User-defined C&C List. User-defined C&C List contains callback addresses that the administrator added for the purpose of blocking or logging any associated connections.
-
web:www.seqrite.com
Explore Seqrite's Botnet Command & Control (C&C) IP Database, designed to help detect and block malicious botnet traffic, enhancing your organization's cybersecurity defenses.
-
web:www.spamhaus.com
What is the extended Botnet Controller List (eBCL)? This dataset contains single IPv4 addresses used by miscreants to control infected devices, otherwise known as Botnet Command and Controllers, C&Cs , or C2s. At its heart, the eBCL is a "drop all traffic" list detailing the worst of the worse.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.