TF-1811923
low
📛 Threat Title
CountLoader: URL that is used for botnet Command&control (C&C) https://edr-security-bucket1.cc/
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: CountLoader. Confidence: 49. First seen: 2026-05-13 18:34:44 UTC. Reporter: johannes.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
104.21.28.230
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.28.230
IOC database
- Type
- ipv4
- Value
104.21.28.230- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url https://edr-security-bucket1.cc/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/104.21.28.230
ipv4
172.67.147.196
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.147.196
IOC database
- Type
- ipv4
- Value
172.67.147.196- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Resolved from url https://edr-security-bucket1.cc/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/ip_addresses/172.67.147.196
url
https://edr-security-bucket1.cc/
UrlVoid 3 / 35
IOC database
- Type
- url
- Value
https://edr-security-bucket1.cc/- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- URL that is used for botnet Command&control (C&C) attributed to CountLoader
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- Malpedia profile Threatfox IOCs/Threats
-
ThreatFox IOC page
Threatfox IOCs/Threats
Indicator that identifies a botnet command&control server (C&C). IOC type: URL that is used for botnet Command&control (C&C). Attributed malware: CountLoader. Confidence: 49. First seen: 2026-05-13 18:34:44 UTC. Reporter: johannes.
- External reference Threatfox IOCs/Threats
Remediations (10)
-
web:docs.fortinet.com
The Fortinet Cookbook contains examples of how to integrate Fortinet products into your network and use features such as security profiles, wireless networking, and VPN. Using the Cookbook, you can go from idea to execution in simple steps, configuring a secure network for better productivity with reduced risk.
-
web:docs.fortinet.com
To configure botnet C&C domain blocking in the GUI: Go to Security Profiles > DNS Filter and click Create New, or edit an existing profile. Enable Redirect botnet C&C requests to Block Portal. Optionally, click the botnet package link. The Botnet C&C Domain Definitions pane opens, which displays the latest list. Configure the other settings as ...
-
web:github.com
A fast, lightweight botnet written in pure C. Contribute to 0x1CA3/Net development by creating an account on GitHub.
-
web:github.com
Build a basic Command & Control botnet in C. Contribute to TreeHacks/ botnet -hackpack development by creating an account on GitHub.
-
web:help.eset.com
This feed is a subset of a Botnet feed and provides information about URLs of Command and Control (C&C) servers and associated data.
-
web:networkthreatdetection.com
Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.
-
web:success.trendmicro.com
A process attempted to communicate with a URL /Domain/IP in User-defined C&C List. User-defined C&C List contains callback addresses that the administrator added for the purpose of blocking or logging any associated connections.
-
web:www.seqrite.com
Explore Seqrite's Botnet Command & Control (C&C) IP Database, designed to help detect and block malicious botnet traffic, enhancing your organization's cybersecurity defenses.
-
web:www.silentpush.com
Silent Push discovered a new malware loader, we're naming " CountLoader ." The threat is served in .NET, PowerShell, and JScript versions.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.