s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1861609 high

📛 Threat Title

Lynx: Domain that is used for botnet Command&control (C&C) lynxchatohmppv6au67lloc2vs6chy7nya7dsu2hhs55mcjxp2joglad.onion

Category: Lynx Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Lynx. Confidence: 100. First seen: 2026-07-28 15:29:57 UTC. Reporter: TheRavenFile. Tags: lynx, Ransomware.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain lynxchatohmppv6au67lloc2vs6chy7nya7dsu2hhs55mcjxp2joglad.onion 1 feed

IOC database

Type
domain
Value
lynxchatohmppv6au67lloc2vs6chy7nya7dsu2hhs55mcjxp2joglad.onion
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Imported from threat-intel feed: threatview.io

Open the full IOC page →

Threat Hunt — feed corroboration

Listed by 1 threat-intel feed vendor: threatview.io. Open in Threat Hunt →

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference ThreatFox IOCs
  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Lynx. Confidence: 100. First seen: 2026-07-28 15:29:57 UTC. Reporter: TheRavenFile. Tags: lynx, Ransomware.

Remediations (10)

  • web:feodotracker.abuse.ch

    Dridex, Heodo (aka Emotet), TrickBot, QakBot (aka QuakBot / Qbot) and BazarLoader (aka BazarBackdoor) botnet command&control servers (C2s) usually reside on compromised servers and such that have been rented and setup by the threat actor itself for the sole purpose of botnet hosting. Feodo Tracker offers a blocklist of IP addresses that are associated with such botnet C2s. It can be used to ...

  • web:help.bitsighttech.com

    ⇤ Compromised Systems Findings The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navi...

  • web:layerlogix.com

    Central to their operation is the Command and Control (C&C) infrastructure, which enables botmasters to issue instructions to infected machines. Understanding the mechanisms of C&C and the geolocation of botnets is crucial for developing effective countermeasures.

  • web:networkthreatdetection.com

    Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.

  • web:www.linkedin.com

    The command and control (C&C) infrastructure is the backbone of a botnet . It is how botmasters (the attackers controlling the botnet ) communicate with compromised devices.

  • web:www.radware.com

    4. Use sinkholing to study botnets and contain threats: Instead of blocking all botnet traffic immediately, redirect suspicious traffic to a controlled sinkhole server. This allows you to observe the botnet's C&C communication patterns and gather intelligence on infrastructure, malware distribution, and attacker motives. 5.

  • web:www.spamhaus.com

    What is the extended Botnet Controller List (eBCL)? This dataset contains single IPv4 addresses used by miscreants to control infected devices, otherwise known as Botnet Command and Controllers, C&Cs , or C2s. At its heart, the eBCL is a "drop all traffic" list detailing the worst of the worse.

  • web:www.spamhaus.com

    The IP address locations of botnet command and control servers being used to control computers infected with malware.

  • web:www.spamhaus.org

    About the Data The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

  • web:www.spamhaus.org

    Introduction What is Spamhaus CERT Insight Portal? Enriched data: Botnet C&C activity in your region Using the portal: Even better functionality How can I access the portal? In 2025, botnet command & controller (C&C) activity detected by Spamhaus increased 56% - a stark reminder that the botnet threat landscape is evolving faster than ever.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Reputation of linked indicators

DomScan scores the domains, AbuseIPDB + GreyNoise score the IPs. Verdicts are per-indicator — this is a roll-up, so no lookup is triggered by opening this page.

Domains scored
1 / 1
IPs scored
0 / 0
Flagged
1
IndicatorTypeVerdictScore
lynxchatohmppv6au67lloc2vs6chy7nya7dsu2hhs55mcjxp2joglad.onion domain critical 38