s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1858523 high

📛 Threat Title

Unknown malware: Domain that is used for botnet Command&control (C&C) mythickass.onthewifi.com

Category: Unknown malware Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-07-26 16:00:19 UTC. Reporter: abuse_ch. Tags: IranBot.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain mythickass.onthewifi.com UrlVoid 3 / 35

IOC database

Type
domain
Value
mythickass.onthewifi.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-07-26 16:00:19 UTC. Reporter: abuse_ch. Tags: IranBot.

Remediations (10)

  • web:101.school

    Identification of Command and Control Servers Collection of compromised internet-connected devices controlled by a third party. Command and Control (C&C) servers play a crucial role in the operation of botnets and other forms of malware . They serve as the central hub from which cybercriminals can control infected machines, known as 'bots'.

  • web:content.spamhaus.org

    About this report Spamhaus tracks both Internet Protocol (IP) addresses and domain names used by threat actors for hosting botnet command & control (C&C) servers. This data enables us to identify associated elements, including the geolocation of the botnet C&Cs , the malware associated with them, the top-level domains used when registering a domain for a botnet C&C , the sponsoring registrars ...

  • web:help.bitsighttech.com

    ⇤ Compromised Systems Findings The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navi...

  • web:threatfox.abuse.ch

    ThreatFox is a platform from abuse.ch and Spamhaus dedicated to sharing indicators of compromise (IOCs) associated with malware , with the infosec community, AV vendors and cyber threat intelligence providers. Upload IOCs and explore the database for valuable intelligence. Use the APIs to seamlessly push and pull signals, and automate bulk queries.

  • web:www.geeksforgeeks.org

    This is to gain control over a small number of devices, which will then be used to expand the attack. 3. Mobilize the Botnet Once several devices are infected, the attacker moves to the final stage. At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server.

  • web:www.malwarebytes.com

    Often, the botnet agent is ordered to download and install additional payloads or to steal data from the local computer. From the moment of infection, botnet agents keep in touch with their remote Command-and-Control server ( C&C ).

  • web:www.paloaltonetworks.com

    Learn about Command and Control (C2) in cyberattacks, its methods, and how to defend against it. Protect your systems with expert insights and strategies.

  • web:www.radware.com

    Botnet detection involves identifying networks of infected computers controlled by attackers to perform malicious activities. Early detection can prevent substantial damage to systems and networks, requiring techniques to monitor and analyze behavior patterns, traffic anomalies, and communication protocols.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware -infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

  • web:www.spamhaus.org

    Overall botnet command control (C&C) activity decreased marginally by -4% between July and December last year. China dominated the Top 20 charts with increased botnet C&C activity across domain registrars and networks, ranking #1 globally for hosting botnet C&C servers. Download the latest report to learn more.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.