TF-1932702
high
📛 Threat Title
Remus: URL that is used for botnet Command&control (C&C) http://novxlse.click:9820/addresses
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-25 07:18:38 UTC. Reporter: Myrtus0x0. Tags: Remus.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://novxlse.click:9820/addresses
VT 3 / 91
UrlVoid 2 / 36
IOC database
- Type
- url
- Value
http://novxlse.click:9820/addresses- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that is used for botnet Command&control (C&C) attributed to Remus
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 3 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| Fortinet | malicious | malware |
| alphaMountain.ai | suspicious | suspicious |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| TLD | click |
| Final URL | http://novxlse.click:9820/addresses |
| Page title | 404 Not Found |
| Last HTTP status | 404 |
History
| First seen on VirusTotal | 2026-09-25 06:02 UTC |
| Last submission | 2026-09-25 07:19 UTC |
| Last analysis | 2026-09-25 07:19 UTC |
| Last modified on VirusTotal | 2026-09-25 20:56 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-25 07:18:38 UTC. Reporter: Myrtus0x0. Tags: Remus.
Remediations (10)
-
web:any.run
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
-
web:cyberpress.org
The campaign stands out because Remus does not rely only on a hardcoded command-and-control (C2) domain. Instead, it queries an Ethereum smart contract to obtain the current C2 address, using a technique known as EtherHiding.
-
web:cybersecuritynews.com
Remus Hides Its Command Server on Ethereum At the heart of this campaign is the decision to hide Remus's command server information inside an Ethereum smart contract rather than hard‑coding it in the malware.
-
web:feodotracker.abuse.ch
Dridex, Heodo (aka Emotet), TrickBot, QakBot (aka QuakBot / Qbot) and BazarLoader (aka BazarBackdoor) botnet command&control servers (C2s) usually reside on compromised servers and such that have been rented and setup by the threat actor itself for the sole purpose of botnet hosting. Feodo Tracker offers a blocklist of IP addresses that are associated with such botnet C2s. It can be used to ...
-
web:portal.vyprsec.ai
A new information-stealing malware, Remus , is employing an Ethereum smart contract to dynamically retrieve its command and control server address, making it harder to block.
-
web:urlhaus.abuse.ch
URLhaus URLhaus is a platform from abuse.ch and Spamhaus dedicated to sharing malicious URLs that are being used for malware distribution. Report URLs and explore the database for valuable intelligence. Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware ...
-
web:www.gendigital.com
Key points Gen Threat Labs has identified Remus , a new 64-bit infostealer we attribute to the infamous Lumma Stealer family - emerging in the wake of Lumma's takedown and the doxxing of its alleged core members. In this technical blog post, we detail the compelling evidence tying Remus to Lumma across multiple dimensions.
-
web:www.spamhaus.com
Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.spamhaus.org
NEW: Enriched Botnet C&C report - View the data in JSON, or use your API key to download a JSON file containing the botnet C&C listings and contextual data. Your API Key is accessed via your account to retrieve the threat intelligence data through Spamhaus APIs.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.