logo

Beaconing Leads To Swarft Trojan & Suspicious Netblock

ID: a6198d81-4716-5751-abee-3e18dff631f2

STIX ID: report--a6198d81-4716-5751-abee-3e18dff631f2

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Observed hosts are beaconing every five minutes to 216.108.234.168/scr1p7-r5.php with large POST payloads (~20KB) and minimal responses, behavior consistent with a keylogger/ data-exfiltration drop site. Open-source correlation links the URL pattern to the Swarft banking Trojan; the hosting netblock and customer details are identified as suspicious and listed in some blocklists, and organizations are advised to block/alert on the IOC and investigate impacted hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.