TF-1932704
high
📛 Threat Title
Remus: URL that is used for botnet Command&control (C&C) http://vgfeden.shop:7728/webhooks
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-25 07:18:39 UTC. Reporter: Myrtus0x0. Tags: Remus.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
url
http://vgfeden.shop:7728/webhooks
VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cDovL3ZnZmVkZW4uc2hvcDo3NzI4L3dlYmhvb2tz
UrlVoid 1 / 36
IOC database
- Type
- url
- Value
http://vgfeden.shop:7728/webhooks- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that is used for botnet Command&control (C&C) attributed to Remus
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/urls/aHR0cDovL3ZnZmVkZW4uc2hvcDo3NzI4L3dlYmhvb2tz
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: Remus. Confidence: 75. First seen: 2026-09-25 07:18:39 UTC. Reporter: Myrtus0x0. Tags: Remus.
Remediations (10)
-
web:any.run
Remus Stealer is a sophisticated 64-bit information stealer operating under a Malware-as-a-Service (MaaS) model. Identified as a direct evolution of the infamous Lumma Stealer, Remus specializes in harvesting credentials, cookies, and cryptocurrency wallets while utilizing blockchain technology for command-and-control (C2) resilience.
-
web:cyberpress.org
The campaign stands out because Remus does not rely only on a hardcoded command-and-control (C2) domain. Instead, it queries an Ethereum smart contract to obtain the current C2 address, using a technique known as EtherHiding.
-
web:cybersecuritynews.com
Remus Hides Its Command Server on Ethereum At the heart of this campaign is the decision to hide Remus's command server information inside an Ethereum smart contract rather than hard‑coding it in the malware.
-
web:portal.vyprsec.ai
A new information-stealing malware, Remus , is employing an Ethereum smart contract to dynamically retrieve its command and control server address, making it harder to block.
-
web:threatfox.abuse.ch
ThreatFox IOC Database You are viewing the ThreatFox database entry for url http ://vgfeden.shop:7728/categories. Database Entry
-
web:threatfox.abuse.ch
You are viewing the ThreatFox database entry for url http ://vgfeden.shop:7728/comments.
-
web:threatfox.abuse.ch
You are viewing the ThreatFox database entry for url http://vgfeden.shop:7728/webhooks .
-
web:urlhaus.abuse.ch
Use the APIs, to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware and botnet -related cyber threats.
-
web:www.gendigital.com
Key points Gen Threat Labs has identified Remus , a new 64-bit infostealer we attribute to the infamous Lumma Stealer family - emerging in the wake of Lumma's takedown and the doxxing of its alleged core members. In this technical blog post, we detail the compelling evidence tying Remus to Lumma across multiple dimensions.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.