216.126.225.243 appears to host malware C2 and exfiltration infrastructure. Static deobfuscation of ...
show more216.126.225.243 appears to host malware C2 and exfiltration infrastructure. Static deobfuscation of a malicious Node.js payload recovered HTTP and WebSocket endpoints on ports 8085, 8086, and 8087 used for browser credential theft, crypto wallet extension collection, sensitive file upload, .env search and upload, clipboard monitoring, host notification, logging, WebSocket C2, and remote command execution. Payload source was https://www.jsonkeeper.com/b/W61DU. I did not execute the payload or send authenticated traffic to the C2.
show less
Exploited HostHacking
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.