s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1812260 high

📛 Threat Title

Unknown malware: URL that is used for botnet Command&control (C&C) https://remotev2.whbackend.ru/ws/client

Category: Unknown malware Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-05-14 18:28:37 UTC. Reporter: burger. Tags: c2, WeedHack.

Indicators of Compromise (2)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 185.178.208.129 VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/185.178.208.129

IOC database

Type
ipv4
Value
185.178.208.129
First seen
Last seen
Attached to this threat
Appears in
10 threats
Description
Resolved from url https://whbackend.ru/files/jar/elevator

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/185.178.208.129

url https://remotev2.whbackend.ru/ws/client UrlVoid 4 / 35

IOC database

Type
url
Value
https://remotev2.whbackend.ru/ws/client
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
URL that is used for botnet Command&control (C&C) attributed to Unknown malware

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference Threatfox IOCs/Threats
  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 100. First seen: 2026-05-14 18:28:37 UTC. Reporter: burger. Tags: c2, WeedHack.

Remediations (10)

  • web:any.run

    Botnet malware can be delivered through various means, including phishing emails, malware -infected websites, and even USB drives. Once a device becomes infected, the botnet malware establishes a connection with a command-and-control (C&C) server, essentially becoming a node in the botnet network.

  • web:ethicalhacksacademy.com

    C2 Tracker is a free, community-driven Indicator of Compromise (IOC) feed designed to track IP addresses associated with known malware , botnets , and Command-and-Control (C2) infrastructure.

  • web:fidelissecurity.com

    Learn how to detect and stop Command and Control (C2) attacks with the latest statistics and real-world examples.

  • web:malware-hunter.shodan.io

    Malware Hunter is a specialized Shodan crawler that explores the Internet looking for command & control (C2s) servers for botnets . It does this by pretending to be an infected client that's reporting back to a C2.

  • web:networkthreatdetection.com

    Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.

  • web:www.crowdstrike.com

    What are command and control attacks? C&C (also known as C2) is a method that cybercriminals use to communicate with compromised devices within a target company's network. In a C&C attack, an attacker uses a server to send commands to — and receive data from — computers compromised by malware . This server is also known as a C2 or C&C server.

  • web:www.mimecast.com

    Botnets are networks of computers controlled remotely by a third party, used to carry out malicious cyberattacks such as sending spam messages and launching DDoS attacks. Detection methods include network traffic analysis, signature-based detection, behavior-based detection, and machine learning algorithms. Prevention strategies involve keeping software up to date, using antivirus software ...

  • web:www.sentinelone.com

    Botnet attacks can quickly overwhelm servers and take over networks. Learn how to prevent botnet attacks in this guide.

  • web:www.spamhaus.com

    Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware -infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…