s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1815703 medium

📛 Threat Title

Unknown malware: Domain that is used for botnet Command&control (C&C) jobworkNY.com

Category: Unknown malware Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 50. First seen: 2026-05-17 18:47:17 UTC. Reporter: anonymous.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 104.21.14.13

IOC database

Type
ipv4
Value
104.21.14.13
First seen
Last seen
Attached to this threat
Appears in
5 threats
Description
Resolved from url https://jobworkny.com/dl/file/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 172.67.133.189

IOC database

Type
ipv4
Value
172.67.133.189
First seen
Last seen
Attached to this threat
Appears in
5 threats
Description
Resolved from url https://jobworkny.com/dl/file/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain jobworkny.com VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jobworkny.com

IOC database

Type
domain
Value
jobworkny.com
First seen
Last seen
Attached to this threat
Appears in
3 threats
Description
Domain that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/jobworkny.com

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 50. First seen: 2026-05-17 18:47:17 UTC. Reporter: anonymous.

Remediations (10)

  • web:blogs.cisco.com

    Learn how to defend against Command-and-Control attacks using the powerful combination of Cisco Umbrella and AMP for endpoint. Prevent malicious malware from gaining foothold in your environment and recruiting botnets to compromise systems and exfiltrate your data.

  • web:cymulate.com

    Domain Generation Algorithm - Locky Trojan C&C : The Locky Trojan is a notorious malware strain that has been used in several high-profile attacks. One of its features is a Domain Generation Algorithm (DGA), which generates a list of domain names that the malware uses to communicate with its C&C server.

  • web:fidelissecurity.com

    Learn how to detect and stop Command and Control (C2) attacks with the latest statistics and real-world examples.

  • web:help.bitsighttech.com

    ⇤ Compromised Systems Findings The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navi...

  • web:hunt.io

    Learn how to detect C2 traffic using advanced methods like network analysis and DNS monitoring to protect your network from cyber threats. Learn more.

  • web:networkthreatdetection.com

    Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.

  • web:www.paloaltonetworks.com

    Learn about Command and Control (C2) in cyberattacks, its methods, and how to defend against it. Protect your systems with expert insights and strategies.

  • web:www.radware.com

    Signature and Heuristic Detection Signature-based detection involves matching observed network or host behaviors against a database of known malware indicators, command-and-control (C&C) server IPs, or other established botnet patterns. This approach is efficient for rapidly identifying threats that have been previously documented. As malware signatures are updated continually, signature-based ...

  • web:www.spamhaus.com

    What is the extended Botnet Controller List (eBCL)? This dataset contains single IPv4 addresses used by miscreants to control infected devices, otherwise known as Botnet Command and Controllers, C&Cs , or C2s. At its heart, the eBCL is a "drop all traffic" list detailing the worst of the worse.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware -infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…