s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-1868486 high

📛 Threat Title

RevStealer: Domain that is used for botnet Command&control (C&C) health.sigmacoast.one

Category: RevStealer Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: RevStealer. Confidence: 75. First seen: 2026-08-04 19:24:34 UTC. Reporter: Myrtus0x0. Tags: RevStealer.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain health.sigmacoast.one UrlVoid 0 / 35

IOC database

Type
domain
Value
health.sigmacoast.one
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: RevStealer. Confidence: 75. First seen: 2026-08-04 19:24:34 UTC. Reporter: Myrtus0x0. Tags: RevStealer.

Remediations (10)

  • web:abuse.ch

    Varying in focus areas, all platforms are designed to help identify, track, and mitigate against malware and botnet -related cyber threats. The abuse.ch community, anti-virus vendors and threat intelligence providers can contribute and consume from the following platforms:

  • web:feodotracker.abuse.ch

    Here you can browse the list of botnet Command&Control servers ( C&Cs ) tracked by Feodo Tracker, associated with Dridex, TrickBot, QakBot (aka QuakBot/Qbot), BazarLoader (aka BazarBackdoor) and Emotet (aka Heodo). When Feodo Tracker was launched in 2010, it was meant to track Feodo botnet C&Cs .

  • web:ismalicious.com

    11 indicators (11 domains , 0 IPs, 0 URLs, 0 hashes) attributed to the RevStealer malware family.

  • web:networkthreatdetection.com

    How can you recognize botnet command and control when dealing with C&C servers or a botnet control server? Recognizing botnet command and control often comes down to spotting odd traffic patterns tied to C&C servers.

  • web:www.edxsecurityhub.org

    What is a Botnet ? A botnet (robot network) is a network of compromised computers, servers, IoT devices, and other internet-connected devices (bots or zombies) controlled remotely by an attacker (botmaster or bot herder). Each bot is infected with malware that allows the botmaster to issue commands via Command & Control (C2 or C&C ) servers. Botnets are used to perform large-scale cyberattacks ...

  • web:www.geeksforgeeks.org

    At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server. The attacker can command these devices, to perform tasks like sending spam, participating in distributed denial-of-service (DDoS) attacks, or stealing data. How to Prevent Botnet Attacks?

  • web:www.linkedin.com

    The command and control (C&C) infrastructure is the backbone of a botnet . It is how botmasters (the attackers controlling the botnet ) communicate with compromised devices.

  • web:www.radware.com

    4. Use sinkholing to study botnets and contain threats: Instead of blocking all botnet traffic immediately, redirect suspicious traffic to a controlled sinkhole server. This allows you to observe the botnet's C&C communication patterns and gather intelligence on infrastructure, malware distribution, and attacker motives. 5.

  • web:www.spamhaus.org

    About the Data The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

  • web:www.spamhaus.org

    With every Botnet Threat Update we publish, the same networks consistently appear in the Top 20 for hosting botnet command and control (C&C) servers. But why does this keep happening? In this Botnet Spotlight, we look into the root causes behind this persistent issue and what networks must do to break the cycle. Botnet C&C Malware

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.