TF-1868486
high
📛 Threat Title
RevStealer: Domain that is used for botnet Command&control (C&C) health.sigmacoast.one
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: RevStealer. Confidence: 75. First seen: 2026-08-04 19:24:34 UTC. Reporter: Myrtus0x0. Tags: RevStealer.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
health.sigmacoast.one
UrlVoid 0 / 35
IOC database
- Type
- domain
- Value
health.sigmacoast.one- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: RevStealer. Confidence: 75. First seen: 2026-08-04 19:24:34 UTC. Reporter: Myrtus0x0. Tags: RevStealer.
Remediations (10)
-
web:abuse.ch
Varying in focus areas, all platforms are designed to help identify, track, and mitigate against malware and botnet -related cyber threats. The abuse.ch community, anti-virus vendors and threat intelligence providers can contribute and consume from the following platforms:
-
web:feodotracker.abuse.ch
Here you can browse the list of botnet Command&Control servers ( C&Cs ) tracked by Feodo Tracker, associated with Dridex, TrickBot, QakBot (aka QuakBot/Qbot), BazarLoader (aka BazarBackdoor) and Emotet (aka Heodo). When Feodo Tracker was launched in 2010, it was meant to track Feodo botnet C&Cs .
-
web:ismalicious.com
11 indicators (11 domains , 0 IPs, 0 URLs, 0 hashes) attributed to the RevStealer malware family.
-
web:networkthreatdetection.com
How can you recognize botnet command and control when dealing with C&C servers or a botnet control server? Recognizing botnet command and control often comes down to spotting odd traffic patterns tied to C&C servers.
-
web:www.edxsecurityhub.org
What is a Botnet ? A botnet (robot network) is a network of compromised computers, servers, IoT devices, and other internet-connected devices (bots or zombies) controlled remotely by an attacker (botmaster or bot herder). Each bot is infected with malware that allows the botmaster to issue commands via Command & Control (C2 or C&C ) servers. Botnets are used to perform large-scale cyberattacks ...
-
web:www.geeksforgeeks.org
At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server. The attacker can command these devices, to perform tasks like sending spam, participating in distributed denial-of-service (DDoS) attacks, or stealing data. How to Prevent Botnet Attacks?
-
web:www.linkedin.com
The command and control (C&C) infrastructure is the backbone of a botnet . It is how botmasters (the attackers controlling the botnet ) communicate with compromised devices.
-
web:www.radware.com
4. Use sinkholing to study botnets and contain threats: Instead of blocking all botnet traffic immediately, redirect suspicious traffic to a controlled sinkhole server. This allows you to observe the botnet's C&C communication patterns and gather intelligence on infrastructure, malware distribution, and attacker motives. 5.
-
web:www.spamhaus.org
About the Data The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.spamhaus.org
With every Botnet Threat Update we publish, the same networks consistently appear in the Top 20 for hosting botnet command and control (C&C) servers. But why does this keep happening? In this Botnet Spotlight, we look into the root causes behind this persistent issue and what networks must do to break the cycle. Botnet C&C Malware
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.