TF-1868537
high
📛 Threat Title
DCRat: URL that is used for botnet Command&control (C&C) http://ck077996.tw1.ru/L1nc0In.php
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: DCRat (aliases: DarkCrystal RAT). Confidence: 100. First seen: 2026-08-04 21:45:14 UTC. Reporter: abuse_ch. Tags: dcrat, RAT.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://ck077996.tw1.ru/l1nc0in.php
UrlVoid 1 / 35
IOC database
- Type
- url
- Value
http://ck077996.tw1.ru/l1nc0in.php- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that is used for botnet Command&control (C&C) attributed to DCRat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: DCRat (aliases: DarkCrystal RAT). Confidence: 100. First seen: 2026-08-04 21:45:14 UTC. Reporter: abuse_ch. Tags: dcrat, RAT.
Remediations (10)
-
web:any.run
DCRat can exfiltrate information from browsers, such as session cookies, auto-fill credentials, and credit card details. The malware can transmit the contents of the victim's clipboard to its command-and-control server ( C&C ).
-
web:cloud.google.com
The FireEye Mandiant Threat Intelligence Team helps protect our customers by tracking cyber attackers and the malware they use. The FLARE Team helps augment our threat intelligence by reverse engineering malware samples. Recently, FLARE worked on a new C# variant of Dark Crystal RAT ( DCRat ) that the threat intel team passed to us. We reviewed open source intelligence and prior work, performed ...
-
web:cyberint.com
DCRat's components consist of a stealer/client executable, a single PHP page that serves as the command-and-control (C2) interface, and an administrator tool. DCRat's Targets It has been observed targeting Russian-speaking victims, particularly by installing crypto-mining software on their endpoints, among other malicious purposes.
-
web:gbhackers.com
DCRat's modular architecture allows attackers to customize its behavior with plugins for specific malicious activities. Its comprehensive capabilities include remote system control, file and process management, browser data harvesting, credential theft, keylogging, and screenshot capture.
-
web:hunt.io
DCRat , also known as DarkCrystal RAT, is a Remote Access Trojan (RAT) that emerged in 2018. Notably, it operates as Malware-as-a-Service (MaaS), allowing cybercriminals to purchase and deploy it with ease. Its modular design enables a wide range of malicious activities, including data theft, espionage, and remote surveillance.
-
web:muha2xmad.github.io
start "" "C:\Users\username\Start Menu\SearchProtocolHost.exe": launch a new process of the SearchProtocolHost.exe and the window has an empty title. del /a /q /f "C:\Users\username\AppData\Local\Temp\\sr3bn8JpP4.bat": Then delete the .bat file. After writing the script into the BAT file, it is launched in a new process (with admin privileges).
-
web:threatfox.abuse.ch
The table below documents recent malware samples observed that are associated with this indicator of compromise (IOC).
-
web:threatfox.abuse.ch
You are viewing the ThreatFox database entry for url http://ck077996.tw1.ru/L1nc0In.php .
-
web:www.manageengine.com
2) The PHP page serving as an intermediate The PHP page serves as a C&C endpoint or interface; i.e. the page controlled by the attacker which is used to send commands to the compromised systems. 3) The DCRat client The DCRat client, or stealer, is perfectly suited for delivering to the victim's machine and is written in .NET binaries programmed ...
-
web:www.splunk.com
The Splunk Threat Research Team (STRT) analyzed and developed Splunk analytics for this RAT to help defenders identify signs of compromise within their networks. Remote Access Trojans (RATs) are one of the most common tools used by threat actors as a malicious payload to attack targeted hosts and steal information. One example is the Dark Crystal RAT ( DCRat ) that is capable of remote access ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.