TF-1858523
high
📛 Threat Title
Unknown malware: Domain that is used for botnet Command&control (C&C) mythickass.onthewifi.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-07-26 16:00:19 UTC. Reporter: abuse_ch. Tags: IranBot.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
mythickass.onthewifi.com
UrlVoid 3 / 35
IOC database
- Type
- domain
- Value
mythickass.onthewifi.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-07-26 16:00:19 UTC. Reporter: abuse_ch. Tags: IranBot.
Remediations (10)
-
web:101.school
Identification of Command and Control Servers Collection of compromised internet-connected devices controlled by a third party. Command and Control (C&C) servers play a crucial role in the operation of botnets and other forms of malware . They serve as the central hub from which cybercriminals can control infected machines, known as 'bots'.
-
web:content.spamhaus.org
About this report Spamhaus tracks both Internet Protocol (IP) addresses and domain names used by threat actors for hosting botnet command & control (C&C) servers. This data enables us to identify associated elements, including the geolocation of the botnet C&Cs , the malware associated with them, the top-level domains used when registering a domain for a botnet C&C , the sponsoring registrars ...
-
web:help.bitsighttech.com
⇤ Compromised Systems Findings The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navi...
-
web:threatfox.abuse.ch
ThreatFox is a platform from abuse.ch and Spamhaus dedicated to sharing indicators of compromise (IOCs) associated with malware , with the infosec community, AV vendors and cyber threat intelligence providers. Upload IOCs and explore the database for valuable intelligence. Use the APIs to seamlessly push and pull signals, and automate bulk queries.
-
web:www.geeksforgeeks.org
This is to gain control over a small number of devices, which will then be used to expand the attack. 3. Mobilize the Botnet Once several devices are infected, the attacker moves to the final stage. At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server.
-
web:www.malwarebytes.com
Often, the botnet agent is ordered to download and install additional payloads or to steal data from the local computer. From the moment of infection, botnet agents keep in touch with their remote Command-and-Control server ( C&C ).
-
web:www.paloaltonetworks.com
Learn about Command and Control (C2) in cyberattacks, its methods, and how to defend against it. Protect your systems with expert insights and strategies.
-
web:www.radware.com
Botnet detection involves identifying networks of infected computers controlled by attackers to perform malicious activities. Early detection can prevent substantial damage to systems and networks, requiring techniques to monitor and analyze behavior patterns, traffic anomalies, and communication protocols.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware -infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.spamhaus.org
Overall botnet command control (C&C) activity decreased marginally by -4% between July and December last year. China dominated the Top 20 charts with increased botnet C&C activity across domain registrars and networks, ranking #1 globally for hosting botnet C&C servers. Download the latest report to learn more.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.