OTX-62988a48396b2c544af1d43e
high
📛 Threat Title
Responder - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to Responder Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 1 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (7)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
193.14.90.42
IOC database
- Type
- ipv4
- Value
193.14.90.42- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
58.220.90.122
IOC database
- Type
- ipv4
- Value
58.220.90.122- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
89.28.217.73
IOC database
- Type
- ipv4
- Value
89.28.217.73- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
190.210.130.10
IOC database
- Type
- ipv4
- Value
190.210.130.10- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
51.161.76.34
IOC database
- Type
- ipv4
- Value
51.161.76.34- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
160.17.6.19
IOC database
- Type
- ipv4
- Value
160.17.6.19- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
64.150.176.35
IOC database
- Type
- ipv4
- Value
64.150.176.35- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to Responder Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:ethicalhacksacademy.com
C2 Tracker is a free, community-driven Indicator of Compromise (IOC) feed designed to track IP addresses associated with known malware, botnets, and Command-and-Control ( C2 ) infrastructure.
-
web:fidelissecurity.com
Learn how to detect and stop Command and Control ( C2 ) attacks with the latest statistics and real-world examples.
-
web:github.com
C2 Tracker is a free-to-use-community-driven IOC feed that uses Shodan and Censys searches to collect IP addresses of known malware/botnet/ C2 infrastructure.
-
web:hackers-arise.com
Each of these IP addresses represents a Cobalt Strike C2 server. Summary Cyber Threat Intelligence is crucial to stay ahead of the bad guys. Tools like C2 Tracker are essential to providing you a clear picture of the threat landscape. They help by spotting threats early, aiding in incident response, and supporting overall security efforts.
-
web:hunt.io
Explore command-and-control ( C2 ) beaconing methods used by cybercriminals. Discover how to identify and prevent this persistent threat.
-
web:meterpreter.org
C2 Tracker Free to use IOC feed for various tools/malware. It started for just C2 tools but has morphed into tracking infostealers and botnets as well. It uses Shodan searches to collect the IPs. The most recent collection is always stored in data; the IPs are broken down by tool and there is an all.txt.
-
web:www.codementor.io
Learn what C2 servers are, how they operate, and the role they play in cyberattacks. This article provides insights and tips to detect, block, and neutralize C2 servers.
-
web:www.microsoft.com
These activities lead to identifying C2 servers operated by human-operated ransomware actors and botnet actors and discovering compromised IPs and domains associated with known nation-state actors. Network protection is aided by machine learning models that incriminate IP addresses used for C2 by inspecting network traffic telemetry.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.