s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1812299 medium

📛 Threat Title

PicassoLoader: Domain that is used for botnet Command&control (C&C) attachment-storage-asset-static.needbinding.icu

Category: PicassoLoader Published: Source updated: First seen: Last updated: Source: Threatfox IOCs/Threats

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: PicassoLoader. Confidence: 50. First seen: 2026-05-14 20:10:44 UTC. Reporter: anonymous.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain attachment-storage-asset-static.needbinding.icu UrlVoid 3 / 35

IOC database

Type
domain
Value
attachment-storage-asset-static.needbinding.icu
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Domain that is used for botnet Command&control (C&C) attributed to PicassoLoader

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (3)

  • External reference Threatfox IOCs/Threats
  • Malpedia profile Threatfox IOCs/Threats
  • ThreatFox IOC page Threatfox IOCs/Threats

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: PicassoLoader. Confidence: 50. First seen: 2026-05-14 20:10:44 UTC. Reporter: anonymous.

Remediations (10)

  • web:acsmi.org

    Understand botnets—their structure, how they spread, and what security teams do to detect, dismantle, and protect against these online threats.

  • web:cybersecuritynews.com

    This second-stage script, called PicassoLoader , is a downloader the group has used across multiple campaigns and in several different programming languages. To lock in its presence on the victim's machine, PicassoLoader downloads a scheduled task template from the command-and-control server, disguised as a JPEG image file.

  • web:docs.fortinet.com

    Protection from Botnet C&C attacks This recipe uses a new FortiGuard feature: the Botnet C&C (command and control) database to protect your network from Botnet C&C attacks.

  • web:docs.fortinet.com

    Botnet C&C domain blocking FortiGuard Service continually updates the botnet C&C domain list. The botnet C&C domain blocking feature can block the botnet website access at the DNS name resolving stage. This provides additional protection for your network.

  • web:feodotracker.abuse.ch

    Dridex, Heodo (aka Emotet), TrickBot, QakBot (aka QuakBot / Qbot) and BazarLoader (aka BazarBackdoor) botnet command&control servers (C2s) usually reside on compromised servers and such that have been rented and setup by the threat actor itself for the sole purpose of botnet hosting. Feodo Tracker offers a blocklist of IP addresses that are associated with such botnet C2s. It can be used to ...

  • web:hunt.io

    Explore command-and-control (C2) beaconing methods used by cybercriminals. Discover how to identify and prevent this persistent threat.

  • web:www.cyberswissguards.com

    FrostyNeighbor has demonstrated a continued evolution in its tactics, techniques, and procedures (TTPs), leveraging over time a diverse arsenal of malware and delivery mechanisms to target entities. Key developments include the deployment of multiple variants of the group's main payload downloader, named PicassoLoader by CERT-UA. Variants of this downloader are written in .NET, PowerShell ...

  • web:www.esetngblog.com

    ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group's continual cyberespionage operationsThis blogpost covers newly discovered activities attributed to FrostyNeighbor, targeting governmental organizations in Ukraine. FrostyNeighbor has been running continual cyberoperations, changing and updating its toolset regularly ...

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

  • web:www.welivesecurity.com

    ESET researchers uncovered new activities attributed to FrostyNeighbor, updating its compromise chain to support the group's continual cyberespionage operations.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.