OTX-686e30e226ff6839b0ec5d97
high
📛 Threat Title
Villain - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to Villain C2 Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 2 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (4)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
191.101.44.120
IOC database
- Type
- ipv4
- Value
191.101.44.120- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
159.203.86.137
IOC database
- Type
- ipv4
- Value
159.203.86.137- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
152.32.188.209
IOC database
- Type
- ipv4
- Value
152.32.188.209- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
75.119.131.232
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/75.119.131.232
IOC database
- Type
- ipv4
- Value
75.119.131.232- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/75.119.131.232
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to Villain C2 Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:1337skills.com
This cheat sheet provides a comprehensive reference for using Villain C2 framework. Always ensure you have proper authorization before conducting red team operations or penetration testing.
-
web:deepwiki.com
The advanced features of the Villain C2 Framework provide operators with powerful capabilities for maintaining access, evading detection, and managing compromised hosts across distributed operations.
-
web:github.com
Purpose Villain is a high-level Stage 0/1 C2 framework that can handle multiple reverse TCP and HoaxShell-based shells, enhance their functionality with additional features (commands, utilities), and share them among connected sibling servers ( Villain instances running on different machines).
-
web:github.com
About Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers ( Villain instances running on different machines).
-
web:medium.com
Anti-virus and Windows Defender use a combination of signature-based detection, behavior-based detection, and today AI analysis solutions to detect and block malware or C2 connection attempts ...
-
web:www.helpnetsecurity.com
Villain is an open-source Stage 0/1 command-and-control ( C2 ) framework designed to manage multiple reverse TCP and HoaxShell-based shells.
-
web:www.kali.org
Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells, enhance their functionality with additional features and share them among connected sibling servers.
-
web:www.microsoft.com
CVE-2025-55182 (also referred to as React2Shell and includes CVE-2025-66478, which was merged into it) is a critical pre-authentication remote code execution (RCE) vulnerability affecting React Server Components and related frameworks.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.