TF-1932789
high
📛 Threat Title
XWorm: Domain that is used for botnet Command&control (C&C) loganwolverin2042.webredirect.org
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: XWorm. Confidence: 75. First seen: 2026-09-25 10:25:23 UTC. Reporter: abuse_ch. Tags: XWorm.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
loganwolverin2042.webredirect.org
UrlVoid 2 / 36
IOC database
- Type
- domain
- Value
loganwolverin2042.webredirect.org- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to XWorm
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference ThreatFox IOCs
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: XWorm. Confidence: 75. First seen: 2026-09-25 10:25:23 UTC. Reporter: abuse_ch. Tags: XWorm.
Remediations (10)
-
web:any.run
Explore XWorm's communication encryption, uncover decryption methods, and see the data and commands the malware transmits.
-
web:cybanetix.com
Once running on a victim host, XWorm will establish contact with its command-and- control server. The RAT is usually configured with a hardcoded C Q address ( domain or IP) and port, stored in its embedded configuration.
-
web:darkwebinformer.com
A domain -based indicator has been identified leveraging Portmap.ioservices for remote port forwarding, enabling XWormmalware command-and-control communications. Portmap's free tunneling service is often abused by threat actors to disguise botnet traffic behind legitimate infrastructure. Confidence is assessed at 100%.
-
web:darkwebinformer.com
A domain -based indicator has been identified linked to XWorm command-and-control infrastructure. The domain is hosted through the Playit.gg platform, often abused by threat actors to proxy malicious traffic.
-
web:github.com
This report presents a comprehensive analysis of an XWorm malware infection. XWorm is a Remote Access Trojan (RAT) that enables attackers to gain full control over infected systems, including data theft, remote command execution, and persistence.
-
web:gurucul.com
Technical analysis of XWorm v7 RAT infection chain, C2 encryption, plugins, MITRE mapping, IOCs, and detection guidance for SOC teams.
-
web:securityarsenal.com
The pulse describes a shift from classic centralized botnet infrastructure to blockchain-resident command-and-control. The activity is attributed in OTX to an adversary identified as LenAI and centers on Aeternum, a C++ botnet loader that uses Polygon blockchain smart contracts as the instruction channel instead of a conventional C2 server.
-
web:www.fortinet.com
That module uses process hollowing to inject and execute the XWorm payload within a newly created Msbuild.exe process. This analysis also examines XWorm's encrypted network traffic, command-and-control protocol, control commands, and plugin architecture.
-
web:www.huntress.com
XWorm is a particularly nasty remote access trojan (RAT) that gives attackers the keys to your kingdom. This malware is designed to sneak onto systems, steal everything from credentials to cryptocurrency, and give threat actors full control.
-
web:www.trellix.com
Malware-As-A-Service Redefined: Why XWorm is outpacing every other RAT in the underground malware market By Boggavarapu R S S Srinivas Gupta and Ravishankar N C · March 12, 2026 Introduction In the evolving landscape of cybercrime, threat actors are constantly pursuing the "perfect" weapon: malware that is lightweight, modular, and—most importantly—stealthy. The underground market eagerly ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.