s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

TF-1932730 medium

📛 Threat Title

Unknown RAT: Domain that is used for botnet Command&control (C&C) esunager.net

Category: Unknown RAT Published: Source updated: First seen: Last updated: Source: ThreatFox IOCs

Description

Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown RAT. Confidence: 50. First seen: 2026-09-25 08:34:31 UTC. Reporter: emilstahl. Tags: ChainScript, etherhiding, NodeJS-RAT, on-chain-c2, Polygon.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain esunager.net VT: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/esunager.net
UrlVoid 3 / 36

IOC database

Type
domain
Value
esunager.net
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 401 Client Error: Unauthorized for url: https://www.virustotal.com/api/v3/domains/esunager.net

References (2)

  • Malpedia profile ThreatFox IOCs
  • ThreatFox IOC page ThreatFox IOCs

    Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: Unknown RAT. Confidence: 50. First seen: 2026-09-25 08:34:31 UTC. Reporter: emilstahl. Tags: ChainScript, etherhiding, NodeJS-RAT, on-chain-c2, Polygon.

Remediations (10)

  • web:boteraser.com

    Unknown RAT is a remote access trojan first documented in May 2021 by Palo Alto Networks Unit 42 as a lightweight .NET‑based backdoor used by the…

  • web:content.spamhaus.org

    The number of botnet command and control (C&C) servers continued to rise between July and December 2025, increasing by +24%. During this period, Remote Access Trojans ( RATs ) grew in popularity to 42% of malware associated with observed botnet C&Cs , overtaking penetration testing frameworks as the most prevalent malware type.

  • web:docs.fortinet.com

    From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .

  • web:docs.fortinet.com

    From your internal network PC, use a command line tool, such as dig or nslookup, to query this domain and verify that it is blocked by the DNS filter botnet C&C .

  • web:help.bitsighttech.com

    The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navigation Options SPM App: Finding...

  • web:networkthreatdetection.com

    Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.

  • web:www.dnsfilter.com

    What is a command and control attack? Discover how a C2 server works in a botnet C&C attack and learn how to take action to ensure your security.

  • web:www.researchgate.net

    The bots (malware infected hosts) receive commands and updates from the Command and Control (C&C) servers, and hence, contacting and communicating with these servers is an essential requirement of ...

  • web:www.spamhaus.org

    The Spamhaus Botnet Controller List (BCL) is a specialized, advisory "drop all traffic" list. It consists of IP addresses that are actively used by cybercriminals to control malware-infected computers (bots). This is a high-confidence list, with false positives being extremely rare, to block as much high-risk, malicious traffic as possible.

  • web:www.spamhaus.org

    Botnet Threat Update January to June 2026 Between Jan-Jun 2026 botnet C&C servers observed decreased -30% to 14,952. Sliver overtook Cobalt Strike for the #1 spot (+58%). Meanwhile .cn botnet C&C domains surged +771% and India's PDR registrar saw a +901% spike in abused registrations - though REGRU bucked the trend with a -90% reduction. Read the latest report to learn more.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.