TF-1932733
medium
📛 Threat Title
Unknown RAT: Domain that is used for botnet Command&control (C&C) medonaz.net
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown RAT. Confidence: 50. First seen: 2026-09-25 08:34:30 UTC. Reporter: emilstahl. Tags: ChainScript, etherhiding, NodeJS-RAT, on-chain-c2, Polygon.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
medonaz.net
VT 4 / 91
UrlVoid 3 / 36
IOC database
- Type
- domain
- Value
medonaz.net- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Flagged by 4 of 91 VirusTotal vendors
| Vendor | Verdict | Detection |
|---|---|---|
| CRDF | malicious | malicious |
| SOCRadar | malicious | malicious |
| Fortinet | suspicious | spam |
| Gridinsoft | suspicious | suspicious |
Details From VirusTotal
Basic Properties
| Registrar | NICENIC INTERNATIONAL GROUP CO., LIMITED |
| TLD | net |
History
| Creation date | 2026-08-24 17:31 UTC |
| Last analysis | 2026-09-25 08:48 UTC |
| Last modified on VirusTotal | 2026-09-25 23:41 UTC |
| Last WHOIS update | 2026-08-24 17:31 UTC |
| WHOIS record date | 2026-08-31 01:31 UTC |
References (2)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown RAT. Confidence: 50. First seen: 2026-09-25 08:34:30 UTC. Reporter: emilstahl. Tags: ChainScript, etherhiding, NodeJS-RAT, on-chain-c2, Polygon.
Remediations (10)
-
web:blog.sucuri.net
Command-and-control communication Once a RAT has infiltrated a system, it establishes a connection to a C&C server. This server, controlled by the attacker, serves as the central point from which commands are sent to the infected system and data is collected:
-
web:feodotracker.abuse.ch
Dridex, Heodo (aka Emotet), TrickBot, QakBot (aka QuakBot / Qbot) and BazarLoader (aka BazarBackdoor) botnet command&control servers (C2s) usually reside on compromised servers and such that have been rented and setup by the threat actor itself for the sole purpose of botnet hosting. Feodo Tracker offers a blocklist of IP addresses that are associated with such botnet C2s. It can be used to ...
-
web:help.bitsighttech.com
The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navigation Options SPM App: Finding...
-
web:info.spamhaus.com
A 'botnet controller,' 'botnet C2' or 'botnet command & control' server is commonly abbreviated to 'botnet C&C.' Fraudsters use these to both control malware-infected machines and extract personal and valuable data from malware-infected victims.
-
web:splinternetmarketing.com
In this guide, you'll explore strategies to monitor and block botnet Command and Control (C&C) callbacks on servers. We'll delve into identifying indicators of compromise, leveraging cutting-edge tools, and implementing robust network defenses.
-
web:www.radware.com
4. Use sinkholing to study botnets and contain threats: Instead of blocking all botnet traffic immediately, redirect suspicious traffic to a controlled sinkhole server. This allows you to observe the botnet's C&C communication patterns and gather intelligence on infrastructure, malware distribution, and attacker motives. 5.
-
web:www.radware.com
Organizations deploy botnet defense tools to identify infected devices, disrupt command-and-control (C&C) communications, and block malicious traffic originating from these networks.
-
web:www.spamhaus.com
Explore the Spamhaus Live Botnet Threat Map. Track global botnet activity in real time and see where malware and infected devices are operating worldwide.
-
web:www.spamhaus.org
The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.
-
web:www.spamhaus.org
Botnet Threat Update July to December 2025 Botnet Command & Controller (C&C) activity increased 24% this period, with Remote Access Trojans ( RATs ) accounting for 42% of the Top 20 malware associated with botnets .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.