TF-1812297
medium
📛 Threat Title
PicassoLoader: Domain that is used for botnet Command&control (C&C) nama-belakang.nebao.icu
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: PicassoLoader. Confidence: 50. First seen: 2026-05-14 20:10:44 UTC. Reporter: anonymous.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
104.21.75.203
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.75.203
IOC database
- Type
- ipv4
- Value
104.21.75.203- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Resolved from domain nama-belakang.nebao.icu
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.75.203
ipv4
172.67.181.86
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.181.86
IOC database
- Type
- ipv4
- Value
172.67.181.86- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Resolved from domain nama-belakang.nebao.icu
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.181.86
domain
nama-belakang.nebao.icu
UrlVoid 3 / 35
IOC database
- Type
- domain
- Value
nama-belakang.nebao.icu- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Domain that is used for botnet Command&control (C&C) attributed to PicassoLoader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- External reference Threatfox IOCs/Threats
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: PicassoLoader. Confidence: 50. First seen: 2026-05-14 20:10:44 UTC. Reporter: anonymous.
Remediations (10)
-
web:assets.kpmg.com
The PicassoLoader malware employs sophisticated techniques, initiating its intrusion through phishing emails with misleading attachments posing as familiar file types like Excel or PowerPoint documents. Once opened, these attachments trigger hidden code, setting off a complex chain of actions. This includes the deployment of a ".LNK" file via an embedded VBA macro or by leveraging regsvr32.exe ...
-
web:blog.polyswarm.io
PicassoLoader , a downloader, was observed targeting government, military, and civilian entities in Ukraine and Poland. CERT-UA attributed this activity to GhostWriter. Key Takeaways PicassoLoader is a downloader used to target government, military, and civilian entities in Ukraine and Poland. The attacks occurred between April 2022 and July 2023.
-
web:cybersecuritynews.com
This second-stage script, called PicassoLoader , is a downloader the group has used across multiple campaigns and in several different programming languages. To lock in its presence on the victim's machine, PicassoLoader downloads a scheduled task template from the command-and-control server, disguised as a JPEG image file.
-
web:docs.fortinet.com
From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .
-
web:networkthreatdetection.com
Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.
-
web:nicolascoolman.eu
PicassoLoader is a malware downloader used to distribute other malware to infected systems. It is capable of bypassing security mechanisms and deploying varied payloads, thereby facilitating the installation of spyware, ransomware or other malicious tools.
-
web:threatfox.abuse.ch
PicassoLoader IOC: nama-belakang.nebao.icu ( domain ) You are viewing the ThreatFox database entry for domain nama-belakang.nebao.icu .
-
web:www.cybermaterial.com
Execution and Communication Upon successful execution, PICASSOLOADER establishes communication with its command-and-control (C2) server. This server acts as the central hub for managing the malware's activities, enabling attackers to issue commands, deliver additional payloads, and receive stolen data from the compromised system.
-
web:www.cyberswissguards.com
FrostyNeighbor is a long-running cyberespionage actor apparently aligned with the interests of Belarus. The group primarily targets governmental, military, and key sectors in Eastern Europe. This report documents new activity observed that started in March 2026, showing continued evolution of tooling and compromise chains. FrostyNeighbor uses server-side validation of its victims before ...
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.