TF-1812260
high
📛 Threat Title
Unknown malware: URL that is used for botnet Command&control (C&C) https://remotev2.whbackend.ru/ws/client
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-05-14 18:28:37 UTC. Reporter: burger. Tags: c2, WeedHack.
Indicators of Compromise (2)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
185.178.208.129
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/185.178.208.129
IOC database
- Type
- ipv4
- Value
185.178.208.129- First seen
- Last seen
- Attached to this threat
- Appears in
- 10 threats
- Description
- Resolved from url https://whbackend.ru/files/jar/elevator
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/185.178.208.129
url
https://remotev2.whbackend.ru/ws/client
UrlVoid 4 / 35
IOC database
- Type
- url
- Value
https://remotev2.whbackend.ru/ws/client- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference Threatfox IOCs/Threats
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-05-14 18:28:37 UTC. Reporter: burger. Tags: c2, WeedHack.
Remediations (10)
-
web:any.run
Botnet malware can be delivered through various means, including phishing emails, malware -infected websites, and even USB drives. Once a device becomes infected, the botnet malware establishes a connection with a command-and-control (C&C) server, essentially becoming a node in the botnet network.
-
web:ethicalhacksacademy.com
C2 Tracker is a free, community-driven Indicator of Compromise (IOC) feed designed to track IP addresses associated with known malware , botnets , and Command-and-Control (C2) infrastructure.
-
web:fidelissecurity.com
Learn how to detect and stop Command and Control (C2) attacks with the latest statistics and real-world examples.
-
web:malware-hunter.shodan.io
Malware Hunter is a specialized Shodan crawler that explores the Internet looking for command & control (C2s) servers for botnets . It does this by pretending to be an infected client that's reporting back to a C2.
-
web:networkthreatdetection.com
Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.
-
web:www.crowdstrike.com
What are command and control attacks? C&C (also known as C2) is a method that cybercriminals use to communicate with compromised devices within a target company's network. In a C&C attack, an attacker uses a server to send commands to — and receive data from — computers compromised by malware . This server is also known as a C2 or C&C server.
-
web:www.mimecast.com
Botnets are networks of computers controlled remotely by a third party, used to carry out malicious cyberattacks such as sending spam messages and launching DDoS attacks. Detection methods include network traffic analysis, signature-based detection, behavior-based detection, and machine learning algorithms. Prevention strategies involve keeping software up to date, using antivirus software ...
-
web:www.sentinelone.com
Botnet attacks can quickly overwhelm servers and take over networks. Learn how to prevent botnet attacks in this guide.
-
web:www.spamhaus.com
Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware -infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.