TF-1868518
high
📛 Threat Title
Unknown malware: Domain that is used for botnet Command&control (C&C) pypi-get.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-08-04 20:53:34 UTC. Reporter: threatcat_ch. Tags: npm.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
pypi-get.com
IOC database
- Type
- domain
- Value
pypi-get.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-08-04 20:53:34 UTC. Reporter: threatcat_ch. Tags: npm.
Remediations (10)
-
web:help.bitsighttech.com
⇤ Compromised Systems Findings The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navi...
-
web:securityboulevard.com
Botnet Command & Controller (C&C) activity increased 24% this period, with Remote Access Trojans (RATs) accounting for 42% of the Top 20 malware associated with botnets . Learn which Russia-based registrar saw a +9,608% surge in botnet C&C domains—and which major cloud providers are taking action. Read the full report.
-
web:threatfox.abuse.ch
Use the APIs to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware and botnet -related cyber threats.
-
web:www.dnsfilter.com
What is a Command and Control Attack? A Command and Control attack is a component of a malware attack used to establish a remote covert channel between a compromised host and the attacker's server. The attacker's server is often referred to as a Command and Control server, C2 server, or C & C server.
-
web:www.geeksforgeeks.org
At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server. The attacker can command these devices, to perform tasks like sending spam, participating in distributed denial-of-service (DDoS) attacks, or stealing data. How to Prevent Botnet Attacks?
-
web:www.malwarebytes.com
Botnets are networks of computers infected by a botnet agent that are under hidden control of a third party. They are used to execute various commands ordered by the attacker. Most common uses of botnets are criminal operations that require distributed resources, such as DDoS attacks on selected targets, spam campaigns, and performing click fraud.
-
web:www.planisys.net
How Malware Uses DNS Many malware families rely on DNS communication to locate command-and-control servers, download payloads and coordinate botnet activity. Example of malware using DNS queries to locate command-and-control infrastructure. Protective DNS systems can interrupt this communication by blocking malicious domains .
-
web:www.radware.com
Signature and Heuristic Detection Signature-based detection involves matching observed network or host behaviors against a database of known malware indicators, command-and-control (C&C) server IPs, or other established botnet patterns. This approach is efficient for rapidly identifying threats that have been previously documented. As malware signatures are updated continually, signature-based ...
-
web:www.spamhaus.org
Get the latest insights on the botnet command and controllers ( C&Cs ) our researchers are observing, including geolocation and who is hosting them. Access the full report here.
-
web:www.spamhaus.org
Botname_Malpedia - corresponding malware family name in Malpedia IP Address - of the C&C server Seen - date the C&C server was last observed This enriched data allows security teams to cross-reference suspicious activity within their constituency against known botnet C&C metadata, enabling faster identification, escalation, and remediation .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.