TF-1811919
low
📛 Threat Title
CountLoader: Domain that is used for botnet Command&control (C&C) handle-me-sv1.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: CountLoader. Confidence: 49. First seen: 2026-05-13 18:34:42 UTC. Reporter: johannes.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
188.114.96.3
VT 0 / 92
IOC database
- Type
- ipv4
- Value
188.114.96.3- First seen
- Last seen
- Attached to this threat
- Appears in
- 105 threats
- Description
- Resolved from domain xingshang734.xyz
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
Basic Properties
| Network | 188.114.96.0/22 |
| AS owner | Cloudflare, Inc. |
| ASN | 13335 |
History
| Last analysis | 2026-05-16 04:56 UTC |
| Last modified on VirusTotal | 2026-05-16 04:57 UTC |
| WHOIS record date | 2026-05-07 15:07 UTC |
ipv4
188.114.97.3
VT 8 / 92
IOC database
- Type
- ipv4
- Value
188.114.97.3- First seen
- Last seen
- Attached to this threat
- Appears in
- 105 threats
- Description
- Resolved from domain xingshang734.xyz
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 8 of 92 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| ADMINUSLabs | malicious | malicious |
| Chong Lua Dao | malicious | malicious |
| CyRadar | malicious | malicious |
| Lionic | malicious | malicious |
| Viettel Threat Intelligence | malicious | malicious |
| VIPRE | malicious | malware |
| Webroot | malicious | malicious |
| alphaMountain.ai | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Network | 188.114.96.0/22 |
| AS owner | Cloudflare, Inc. |
| ASN | 13335 |
History
| Last analysis | 2026-05-16 04:44 UTC |
| Last modified on VirusTotal | 2026-05-16 04:46 UTC |
| WHOIS record date | 2026-05-07 01:55 UTC |
domain
handle-me-sv1.com
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/handle-me-sv1.com
UrlVoid 5 / 35
IOC database
- Type
- domain
- Value
handle-me-sv1.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to CountLoader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for domains/handle-me-sv1.com
References (3)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: CountLoader. Confidence: 49. First seen: 2026-05-13 18:34:42 UTC. Reporter: johannes.
- External reference Threatfox IOCs/Threats
Remediations (8)
-
web:docs.fortinet.com
This recipe uses a new FortiGuard feature: the Botnet C&C (command and control) database to protect your network from Botnet C&C attacks. For this recipe, you will create a new DNS Filter Profile called Botnet&Facebook, block access to all known C&C addresses, and block access to the Social Networking FortiGuard category.
-
web:docs.fortinet.com
Sample To see an example of how this works, select a botnet domain from that list. Then from your internal network PC, use a command line tool such as dig or nslookup to send a DNS query to traverse the FortiGate to see the query blocked as a botnet domain . For example:
-
web:docs.fortinet.com
From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .
-
web:engineering.purdue.edu
the computers in a network and is independent of botnet architectures and the means used for their command and control. As practically all aspects of how a botnet manifests itself in a network, such as the online bot population, bot lifetimes, and the duration and the choice of malicious activities ordered by the bot master, can be expected to ...
-
web:networkthreatdetection.com
Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.
-
web:success.trendmicro.com
A process attempted to communicate with a URL/ Domain /IP in User-defined C&C List. User-defined C&C List contains callback addresses that the administrator added for the purpose of blocking or logging any associated connections.
-
web:www.radware.com
4. Use sinkholing to study botnets and contain threats: Instead of blocking all botnet traffic immediately, redirect suspicious traffic to a controlled sinkhole server. This allows you to observe the botnet's C&C communication patterns and gather intelligence on infrastructure, malware distribution, and attacker motives. 5.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.