s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1811916 low

📛 Threat Title

CountLoader: Domain that is used for botnet Command&control (C&C) bucket-aws-s1.com

Category: CountLoader First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: CountLoader. Confidence: 49. First seen: 2026-05-13 18:34:41 UTC. Reporter: johannes.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 104.21.9.208 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.9.208

IOC database

Type
ipv4
Value
104.21.9.208
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain bucket-aws-s1.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.9.208

ipv4 172.67.131.8 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.131.8

IOC database

Type
ipv4
Value
172.67.131.8
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain bucket-aws-s1.com

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.131.8

domain bucket-aws-s1.com UrlVoid 5 / 35

IOC database

Type
domain
Value
bucket-aws-s1.com
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to CountLoader

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: CountLoader. Confidence: 49. First seen: 2026-05-13 18:34:41 UTC. Reporter: johannes.

  • External reference Threatfox IOCs/Threats

Remediations (10)

  • web:docs.aws.amazon.com

    Botnets are networks of bots that are infected by malware and are under the control of a single party, known as the bot herder or bot operator. From one central point, the operator can command every computer on its botnet to simultaneously carry out a coordinated action, which is why botnets are also referred to as command-and-control (C2) systems.

  • web:docs.fortinet.com

    From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .

  • web:ethicalhacksacademy.com

    C2 Tracker is a free, community-driven Indicator of Compromise (IOC) feed designed to track IP addresses associated with known malware, botnets , and Command-and-Control (C2) infrastructure.

  • web:exchange.xforce.ibmcloud.com

    IBM X-Force Exchange is a threat intelligence sharing platform enabling research on security threats, aggregation of intelligence, and collaboration with peers

  • web:feodotracker.abuse.ch

    Dridex, Heodo (aka Emotet), TrickBot, QakBot (aka QuakBot / Qbot) and BazarLoader (aka BazarBackdoor) botnet command&control servers (C2s) usually reside on compromised servers and such that have been rented and setup by the threat actor itself for the sole purpose of botnet hosting. Feodo Tracker offers a blocklist of IP addresses that are associated with such botnet C2s. It can be used to ...

  • web:hunt.io

    Use a Threat Hunting Platform to Detect C2s Using a threat hunting platform is an advanced way to detect command and control servers in your network. These platforms are designed to proactively look for potential threats including C2 traffic by using threat intelligence and data analysis.

  • web:networkthreatdetection.com

    Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.

  • web:thehackernews.com

    CountLoader enables Russian ransomware gangs to deploy Cobalt Strike and PureHVNC RAT via Ukraine phishing campaigns.

  • web:www.seqrite.com

    Explore Seqrite's Botnet Command & Control (C&C) IP Database, designed to help detect and block malicious botnet traffic, enhancing your organization's cybersecurity defenses.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…

Reputation of linked indicators

DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.

Domains scored
1 / 1
IPs scored
0 / 2
Flagged
0