s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1811921 low

📛 Threat Title

CountLoader: Domain that is used for botnet Command&control (C&C) memory-protection-layer1.cc

Category: CountLoader First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: CountLoader. Confidence: 49. First seen: 2026-05-13 18:34:43 UTC. Reporter: johannes.

Indicators of Compromise (3)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 104.21.17.53 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.17.53

IOC database

Type
ipv4
Value
104.21.17.53
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain memory-protection-layer1.cc

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.17.53

ipv4 172.67.222.83 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.222.83

IOC database

Type
ipv4
Value
172.67.222.83
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Resolved from domain memory-protection-layer1.cc

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.222.83

domain memory-protection-layer1.cc VT: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/memory-protection-layer1.cc (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))
UrlVoid 4 / 35

IOC database

Type
domain
Value
memory-protection-layer1.cc
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to CountLoader

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: SSLError: HTTPSConnectionPool(host='www.virustotal.com', port=443): Max retries exceeded with url: /api/v3/domains/memory-protection-layer1.cc (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate is not yet valid (_ssl.c:992)')))

References (3)

  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: CountLoader. Confidence: 49. First seen: 2026-05-13 18:34:43 UTC. Reporter: johannes.

  • External reference Threatfox IOCs/Threats

Remediations (10)

  • web:community.fortinet.com

    DescriptionThis article describes how to block C&C domain traffic.SolutionFortiGuard service continually updates the Botnet C&C domain list ( Domain DB). The botnet C&C domain blocking feature can block the botnet web site access at the DNS name resolving stage. This provides additional p...

  • web:community.fortinet.com

    In V6.2 on CLI: To configure Botnet C&C IP blocking: config ips sensor now has a new scan- botnet -connections option: config ips sensor edit "Demo" set scan- botnet -connections <disable | block | monitor> next end The scan- botnet -connections command is no longer available in the following CLI commands: config firewall policy config firewall ...

  • web:docs.fortinet.com

    The Botnet C&C section consolidates multiple botnet options in the IPS profile. This allows you to enable botnet blocking across all traffic that matches the policy by configuring one setting in the GUI, or by the scan- botnet -connection command in the CLI.

  • web:docs.fortinet.com

    Protection from Botnet C&C attacks This recipe uses a new FortiGuard feature: the Botnet C&C (command and control) database to protect your network from Botnet C&C attacks.

  • web:docs.fortinet.com

    Botnet C&C domain blocking FortiGuard Service continually updates the Botnet C&C domain list ( Domain DB). The botnet C&C domain blocking feature can block the botnet website access at the DNS name resolving stage. This provides additional protection for your network.

  • web:docs.fortinet.com

    Botnet C&C domain blocking FortiGuard Service continually updates the botnet C&C domain list. The botnet C&C domain blocking feature can block the botnet website access at the DNS name resolving stage. This provides additional protection for your network.

  • web:docs.fortinet.com

    Botnet C&C domain blocking FortiGuard Service continually updates the botnet C&C domain list. The botnet C&C domain blocking feature can block the botnet website access at the DNS name resolving stage. This provides additional protection for your network.

  • web:networkthreatdetection.com

    Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.

  • web:success.trendmicro.com

    A process attempted to communicate with a URL/ Domain /IP in User-defined C&C List. User-defined C&C List contains callback addresses that the administrator added for the purpose of blocking or logging any associated connections.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…