s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1868518 high

📛 Threat Title

Unknown malware: Domain that is used for botnet Command&control (C&C) pypi-get.com

Category: Unknown malware Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-08-04 20:53:34 UTC. Reporter: threatcat_ch. Tags: npm.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain pypi-get.com

IOC database

Type
domain
Value
pypi-get.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-08-04 20:53:34 UTC. Reporter: threatcat_ch. Tags: npm.

Remediations (10)

  • web:help.bitsighttech.com

    ⇤ Compromised Systems Findings The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navi...

  • web:securityboulevard.com

    Botnet Command & Controller (C&C) activity increased 24% this period, with Remote Access Trojans (RATs) accounting for 42% of the Top 20 malware associated with botnets . Learn which Russia-based registrar saw a +9,608% surge in botnet C&C domains—and which major cloud providers are taking action. Read the full report.

  • web:threatfox.abuse.ch

    Use the APIs to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware and botnet -related cyber threats.

  • web:www.dnsfilter.com

    What is a Command and Control Attack? A Command and Control attack is a component of a malware attack used to establish a remote covert channel between a compromised host and the attacker's server. The attacker's server is often referred to as a Command and Control server, C2 server, or C & C server.

  • web:www.geeksforgeeks.org

    At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server. The attacker can command these devices, to perform tasks like sending spam, participating in distributed denial-of-service (DDoS) attacks, or stealing data. How to Prevent Botnet Attacks?

  • web:www.malwarebytes.com

    Botnets are networks of computers infected by a botnet agent that are under hidden control of a third party. They are used to execute various commands ordered by the attacker. Most common uses of botnets are criminal operations that require distributed resources, such as DDoS attacks on selected targets, spam campaigns, and performing click fraud.

  • web:www.planisys.net

    How Malware Uses DNS Many malware families rely on DNS communication to locate command-and-control servers, download payloads and coordinate botnet activity. Example of malware using DNS queries to locate command-and-control infrastructure. Protective DNS systems can interrupt this communication by blocking malicious domains .

  • web:www.radware.com

    Signature and Heuristic Detection Signature-based detection involves matching observed network or host behaviors against a database of known malware indicators, command-and-control (C&C) server IPs, or other established botnet patterns. This approach is efficient for rapidly identifying threats that have been previously documented. As malware signatures are updated continually, signature-based ...

  • web:www.spamhaus.org

    Get the latest insights on the botnet command and controllers ( C&Cs ) our researchers are observing, including geolocation and who is hosting them. Access the full report here.

  • web:www.spamhaus.org

    Botname_Malpedia - corresponding malware family name in Malpedia IP Address - of the C&C server Seen - date the C&C server was last observed This enriched data allows security teams to cross-reference suspicious activity within their constituency against known botnet C&C metadata, enabling faster identification, escalation, and remediation .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.