TF-1815701
medium
📛 Threat Title
Unknown malware: Domain that is used for botnet Command&control (C&C) infoworkerOne.com
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 50. First seen: 2026-05-17 18:47:17 UTC. Reporter: anonymous.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
infoworkerone.com
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/infoworkerone.com
UrlVoid 4 / 35
IOC database
- Type
- domain
- Value
infoworkerone.com- First seen
- Last seen
- Attached to this threat
- Appears in
- 3 threats
- Description
- Domain that is used for botnet Command&control (C&C) attributed to Unknown malware
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/infoworkerone.com
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown malware. Confidence: 50. First seen: 2026-05-17 18:47:17 UTC. Reporter: anonymous.
Remediations (10)
-
web:community.fortinet.com
DescriptionThis article describes how to block C&C domain traffic.SolutionFortiGuard service continually updates the Botnet C&C domain list ( Domain DB). The botnet C&C domain blocking feature can block the botnet web site access at the DNS name resolving stage. This provides additional p...
-
web:cymulate.com
Domain Generation Algorithm - Locky Trojan C&C : The Locky Trojan is a notorious malware strain that has been used in several high-profile attacks. One of its features is a Domain Generation Algorithm (DGA), which generates a list of domain names that the malware uses to communicate with its C&C server.
-
web:fidelissecurity.com
Learn how to detect and stop Command and Control (C2) attacks with the latest statistics and real-world examples.
-
web:help.bitsighttech.com
⇤ Compromised Systems Findings The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navi...
-
web:networkthreatdetection.com
Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.
-
web:success.trendmicro.com
Some malware communicate with their C&C server to send and receive information. If a C&C callback is detected by the product, there is a high possibility that the host is infected. This article will tell you what to do in case of C&C callback detection.
-
web:www.crowdstrike.com
What are command and control attacks? C&C (also known as C2) is a method that cybercriminals use to communicate with compromised devices within a target company's network. In a C&C attack, an attacker uses a server to send commands to — and receive data from — computers compromised by malware . This server is also known as a C2 or C&C server.
-
web:www.paloaltonetworks.com
Learn about Command and Control (C2) in cyberattacks, its methods, and how to defend against it. Protect your systems with expert insights and strategies.
-
web:www.radware.com
Botnet detection involves identifying networks of infected computers controlled by attackers to perform malicious activities. Early detection can prevent substantial damage to systems and networks, requiring techniques to monitor and analyze behavior patterns, traffic anomalies, and communication protocols.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware -infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.