TF-1932734
medium
📛 Threat Title
Unknown RAT: Domain that is used for botnet Command&control (C&C) remuloz.net
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown RAT. Confidence: 50. First seen: 2026-09-25 08:34:29 UTC. Reporter: emilstahl. Tags: ChainScript, etherhiding, NodeJS-RAT, on-chain-c2, Polygon.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
remuloz.net
VT 3 / 91
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
remuloz.net- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 3 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| MalwareURL | malicious | malware |
| Fortinet | suspicious | spam |
| SOCRadar | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | NICENIC INTERNATIONAL GROUP CO., LIMITED |
| TLD | net |
History
| Creation date | 2026-09-02 22:05 UTC |
| Last analysis | 2026-09-25 08:48 UTC |
| Last modified on VirusTotal | 2026-09-25 23:41 UTC |
| Last WHOIS update | 2026-09-02 22:05 UTC |
| WHOIS record date | 2026-09-09 08:01 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown RAT. Confidence: 50. First seen: 2026-09-25 08:34:29 UTC. Reporter: emilstahl. Tags: ChainScript, etherhiding, NodeJS-RAT, on-chain-c2, Polygon.
Remediations (10)
-
web:boteraser.com
Unknown RAT is a remote access trojan first documented in May 2021 by Palo Alto Networks Unit 42 as a lightweight .NET‑based backdoor used by the…
-
web:content.spamhaus.org
A 'botnet controller,' 'botnet C2' or 'botnet command & control' server is commonly abbreviated to 'botnet C&C.' Fraudsters use these to both control malware-infected machines and extract personal and valuable data from malware-infected victims.
-
web:docs.fortinet.com
From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .
-
web:feodotracker.abuse.ch
Here you can browse the list of botnet Command&Control servers ( C&Cs ) tracked by Feodo Tracker, associated with Dridex, TrickBot, QakBot (aka QuakBot/Qbot), BazarLoader (aka BazarBackdoor) and Emotet (aka Heodo). When Feodo Tracker was launched in 2010, it was meant to track Feodo botnet C&Cs .
-
web:github.com
Initial Reconnaissance Analysis: Identifying calls to external geolocation services (geoplugin.net), which is a common first step for many RATs to gather victim context. C2 Channel Identification: Pinpointing the Command & Control server's IP address and domain , along with the specific ports and protocols used for communication.
-
web:help.bitsighttech.com
The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navigation Options SPM App: Finding...
-
web:www.spamhaus.com
Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.spamhaus.org
With every Botnet Threat Update we publish, the same networks consistently appear in the Top 20 for hosting botnet command and control (C&C) servers. But why does this keep happening? In this Botnet Spotlight, we look into the root causes behind this persistent issue and what networks must do to break the cycle. Botnet C&C Malware Service providers
-
web:www.spamhaus.org
Botnet Threat Update July to December 2025 Botnet Command & Controller (C&C) activity increased 24% this period, with Remote Access Trojans ( RATs ) accounting for 42% of the Top 20 malware associated with botnets .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.