TF-1931112
high
📛 Threat Title
Remus: URL that is used for botnet Command&control (C&C) http://petcarv.click:8239/exports
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-23 23:45:10 UTC. Reporter: Myrtus0x0. Tags: Remus.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://petcarv.click:8239/exports
UrlVoid 2 / 36
IOC database
- Type
- url
- Value
http://petcarv.click:8239/exports- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that is used for botnet Command&control (C&C) attributed to Remus
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-23 23:45:10 UTC. Reporter: Myrtus0x0. Tags: Remus.
Remediations (10)
-
web:any.run
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
-
web:content.spamhaus.org
A 'botnet controller,' 'botnet C2' or 'botnet command & control' server is commonly abbreviated to 'botnet C&C.' Fraudsters use these to both control malware-infected machines and extract personal and valuable data from malware-infected victims.
-
web:cyberpress.org
The campaign stands out because Remus does not rely only on a hardcoded command-and-control (C2) domain. Instead, it queries an Ethereum smart contract to obtain the current C2 address, using a technique known as EtherHiding.
-
web:cybersecuritynews.com
Remus Windows stealer uses ClickFix attacks to steal passwords, wallet data, files, browser information, and AI tool credentials.
-
web:portal.vyprsec.ai
A new information-stealing malware, Remus , is employing an Ethereum smart contract to dynamically retrieve its command and control server address, making it harder to block.
-
web:threatfox.abuse.ch
You are viewing the ThreatFox database entry for url http ://petcarv.click:8239/subscriptions.
-
web:urlhaus.abuse.ch
Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware and botnet -related cyber threats.
-
web:www.gendigital.com
Key points Gen Threat Labs has identified Remus , a new 64-bit infostealer we attribute to the infamous Lumma Stealer family - emerging in the wake of Lumma's takedown and the doxxing of its alleged core members. In this technical blog post, we detail the compelling evidence tying Remus to Lumma across multiple dimensions.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.spamhaus.org
Networks hosting botnet C&Cs : Same players, same problems With every Botnet Threat Update we publish, the same networks consistently appear in the Top 20 for hosting botnet command and control (C&C) servers.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.