logo

DanaBot Infrastructure

ID: df2eb20d-8c27-5b74-a99d-f50a2e027b5c

STIX ID: report--df2eb20d-8c27-5b74-a99d-f50a2e027b5c

Feed Name: IntelInsights (Substack)

Threat Score
72/100

Date Published: 2024-11-20

Date Updated: 2026-04-19

Author: Vasilis Orlof

...
...

The report reviews recent DanaBot banking trojan activity, providing multiple late-2024 sample hashes, identifying active C2 infrastructure (notably 185.117.90.36 with an SSL certificate for srv51934.yourbestnetwork.net and 23.95.182.47), and a malicious URL (https://altraonline.com/SKOblik.exe). It highlights distribution via phishing and malicious ads (including ClickFix-style lures) and concludes the operation appears active, offering IOCs (hashes, IPs, domain) to aid detection and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.