logo

Bulletproof Hosting Hunt

ID: cfa62f92-df2d-54f9-b07e-8c04e67eea44

STIX ID: report--cfa62f92-df2d-54f9-b07e-8c04e67eea44

Feed Name: IntelInsights (Substack)

Threat Score
72/100

Date Published: 2025-07-27

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

The report details a hunt originating from recent Lumma samples that pivots into AS213702 (QWINS LTD), identifying clusters of IPs and domains used for hosting payloads, phishing (e.g., Brex, DBeaver impersonation), and C2 across subnets such as 93.123.39.0/24 and 141.98.6.0/24. Using VT and Censys, it links multiple services, shared self-signed certificates, and ports (e.g., 5554, 3389) to ongoing activity involving infostealers and botnets (Lumma, Vidar, Amadey, Mirai, DarkGate), suggesting the ASN may function as bulletproof hosting. The author summarizes observed distribution-to-C2 flows and provides an external list of IoCs for further investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.