s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932734 medium

📛 Threat Title

Unknown RAT: Domain that is used for botnet Command&control (C&C) remuloz.net

Category: Unknown RAT Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown RAT. Confidence: 50. First seen: 2026-09-25 08:34:29 UTC. Reporter: emilstahl. Tags: ChainScript, etherhiding, NodeJS-RAT, on-chain-c2, Polygon.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain remuloz.net VT 3 / 91 UrlVoid 3 / 36

IOC database

Type
domain
Value
remuloz.net
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Flagged by 3 of 91 VirusTotal vendors

VendorVerdictDetection
MalwareURL malicious malware
Fortinet suspicious spam
SOCRadar suspicious suspicious

Details From VirusTotal

Basic Properties
RegistrarNICENIC INTERNATIONAL GROUP CO., LIMITED
TLDnet
History
Creation date2026-09-02 22:05 UTC
Last analysis2026-09-25 08:48 UTC
Last modified on VirusTotal2026-09-25 23:41 UTC
Last WHOIS update2026-09-02 22:05 UTC
WHOIS record date2026-09-09 08:01 UTC

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown RAT. Confidence: 50. First seen: 2026-09-25 08:34:29 UTC. Reporter: emilstahl. Tags: ChainScript, etherhiding, NodeJS-RAT, on-chain-c2, Polygon.

Remediations (10)

  • web:boteraser.com

    Unknown RAT is a remote access trojan first documented in May 2021 by Palo Alto Networks Unit 42 as a lightweight .NET‑based backdoor used by the…

  • web:content.spamhaus.org

    A 'botnet controller,' 'botnet C2' or 'botnet command & control' server is commonly abbreviated to 'botnet C&C.' Fraudsters use these to both control malware-infected machines and extract personal and valuable data from malware-infected victims.

  • web:docs.fortinet.com

    From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .

  • web:feodotracker.abuse.ch

    Here you can browse the list of botnet Command&Control servers ( C&Cs ) tracked by Feodo Tracker, associated with Dridex, TrickBot, QakBot (aka QuakBot/Qbot), BazarLoader (aka BazarBackdoor) and Emotet (aka Heodo). When Feodo Tracker was launched in 2010, it was meant to track Feodo botnet C&Cs .

  • web:github.com

    Initial Reconnaissance Analysis: Identifying calls to external geolocation services (geoplugin.net), which is a common first step for many RATs to gather victim context. C2 Channel Identification: Pinpointing the Command & Control server's IP address and domain , along with the specific ports and protocols used for communication.

  • web:help.bitsighttech.com

    The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navigation Options SPM App: Finding...

  • web:www.spamhaus.com

    Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

  • web:www.spamhaus.org

    With every Botnet Threat Update we publish, the same networks consistently appear in the Top 20 for hosting botnet command and control (C&C) servers. But why does this keep happening? In this Botnet Spotlight, we look into the root causes behind this persistent issue and what networks must do to break the cycle. Botnet C&C Malware Service providers

  • web:www.spamhaus.org

    Botnet Threat Update July to December 2025 Botnet Command & Controller (C&C) activity increased 24% this period, with Remote Access Trojans ( RATs ) accounting for 42% of the Top 20 malware associated with botnets .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.