TF-1932732
medium
📛 Threat Title
Unknown RAT: Domain that is used for botnet Command&control (C&C) dibardo.net
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown RAT. Confidence: 50. First seen: 2026-09-25 08:34:31 UTC. Reporter: emilstahl. Tags: ChainScript, etherhiding, NodeJS-RAT, on-chain-c2, Polygon.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
dibardo.net
VT 4 / 91
IOC database
- Type
- domain
- Value
dibardo.net- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| CRDF | malicious | malicious |
| SOCRadar | malicious | malware |
| Fortinet | suspicious | spam |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | NICENIC INTERNATIONAL GROUP CO., LIMITED |
| TLD | net |
History
| Creation date | 2026-08-24 17:31 UTC |
| Last analysis | 2026-09-25 08:48 UTC |
| Last modified on VirusTotal | 2026-09-25 17:24 UTC |
| Last WHOIS update | 2026-08-24 17:31 UTC |
| WHOIS record date | 2026-08-30 04:35 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown RAT. Confidence: 50. First seen: 2026-09-25 08:34:31 UTC. Reporter: emilstahl. Tags: ChainScript, etherhiding, NodeJS-RAT, on-chain-c2, Polygon.
Remediations (10)
-
web:feodotracker.abuse.ch
Dridex, Heodo (aka Emotet), TrickBot, QakBot (aka QuakBot / Qbot) and BazarLoader (aka BazarBackdoor) botnet command&control servers (C2s) usually reside on compromised servers and such that have been rented and setup by the threat actor itself for the sole purpose of botnet hosting. Feodo Tracker offers a blocklist of IP addresses that are associated with such botnet C2s. It can be used to ...
-
web:help.bitsighttech.com
The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navigation Options SPM App: Finding...
-
web:info.spamhaus.com
About this report Spamhaus tracks both Internet Protocol (IP) addresses and domain names used by threat actors for hosting botnet command & control (C&C) servers. This data enables us to identify associated elements, including the geolocation of the botnet C&Cs , the malware associated with them, the top-level domains used when registering a domain for a botnet C&C , the sponsoring registrars ...
-
web:networkthreatdetection.com
Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.
-
web:threatfox.abuse.ch
Use the APIs to seamlessly push and pull signals, and automate bulk queries. With this intelligence, gain insights into malware behavior, to help identify, track, and mitigate against malware and botnet -related cyber threats.
-
web:www.dnsfilter.com
What is a command and control attack? Discover how a C2 server works in a botnet C&C attack and learn how to take action to ensure your security.
-
web:www.geeksforgeeks.org
At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server. The attacker can command these devices, to perform tasks like sending spam, participating in distributed denial-of-service (DDoS) attacks, or stealing data. How to Prevent Botnet Attacks?
-
web:www.linkedin.com
The command and control (C&C) infrastructure is the backbone of a botnet . It is how botmasters (the attackers controlling the botnet ) communicate with compromised devices.
-
web:www.radware.com
Botnet detection involves identifying networks of infected computers controlled by attackers to perform malicious activities. Early detection can prevent substantial damage to systems and networks, requiring techniques to monitor and analyze behavior patterns, traffic anomalies, and communication protocols.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.