s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1868515 high

📛 Threat Title

Unknown malware: Domain that is used for botnet Command&control (C&C) awqhnjewqjkl.icu

Category: Unknown malware Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-08-04 20:38:31 UTC. Reporter: threatcat_ch. Tags: npm.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain awqhnjewqjkl.icu UrlVoid 0 / 35

IOC database

Type
domain
Value
awqhnjewqjkl.icu
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-08-04 20:38:31 UTC. Reporter: threatcat_ch. Tags: npm.

  • External reference ThreatFox IOCs

Remediations (10)

  • web:help.bitsighttech.com

    ⇤ Compromised Systems Findings The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navi...

  • web:networkthreatdetection.com

    Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.

  • web:securityboulevard.com

    Botnet Command & Controller (C&C) activity increased 24% this period, with Remote Access Trojans (RATs) accounting for 42% of the Top 20 malware associated with botnets . Learn which Russia-based registrar saw a +9,608% surge in botnet C&C domains—and which major cloud providers are taking action. Read the full report.

  • web:support.sophos.com

    Overview If a C2 detection alert has been triggered, Sophos Endpoint Security and Control has detected communication with a suspected Command and Control (C2) site. As the suspicious traffic has just been detected, we might not have a sample or signature of the malware causing the C2 traffic during the time of detection The following sections are covered: C2/Generic-A C2/Generic-B C2/Generic-C ...

  • web:www.geeksforgeeks.org

    At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server. The attacker can command these devices, to perform tasks like sending spam, participating in distributed denial-of-service (DDoS) attacks, or stealing data. How to Prevent Botnet Attacks?

  • web:www.radware.com

    Organizations deploy botnet defense tools to identify infected devices, disrupt command-and-control (C&C) communications, and block malicious traffic originating from these networks.

  • web:www.spamhaus.com

    Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware -infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

  • web:www.spamhaus.org

    With every Botnet Threat Update we publish, the same networks consistently appear in the Top 20 for hosting botnet command and control (C&C) servers. But why does this keep happening?

  • web:www.spamhaus.org

    Botname_Malpedia - corresponding malware family name in Malpedia IP Address - of the C&C server Seen - date the C&C server was last observed This enriched data allows security teams to cross-reference suspicious activity within their constituency against known botnet C&C metadata, enabling faster identification, escalation, and remediation .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.