PULSE NAME
AVrecon Malware-Infected Routers Exploited as Residential Proxies by SocksEscort
WHITE SocksEscort Rokalien77 2026-03-18 Modified: 2026-04-17
56
IOCs
HIGH VOLUME
AVrecon Malware MD5 Hashes are described as "probable" and "unreal" by some of the people involved in developing the software for the use of malware.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
AVrecon
Indicators of Compromise (23 / 56 total)
All FileHash-MD5 domain
TYPEINDICATORDESCRIPTIONCREATED
domain advstat.cc 2026-03-18
domain atable.cc 2026-03-18
domain backdump.cc 2026-03-18
domain cleandone.cc 2026-03-18
domain critlan.cc 2026-03-18
domain dzero.cc 2026-03-18
domain evrc.space 2026-03-18
domain fpride.cc 2026-03-18
domain lups.cc 2026-03-18
domain meterstrack.cc 2026-03-18
domain netjunk.cc 2026-03-18
domain plxz.cc 2026-03-18
domain regul.cc 2026-03-18
domain rock.online 2026-03-18
domain startsun.cc 2026-03-18
domain utcp.cc 2026-03-18
domain vdem.cc 2026-03-18
domain zeroback.cc 2026-03-18
domain zeroback2.cc 2026-03-18
domain zeroback3.cc 2026-03-18
domain zeroback4.cc 2026-03-18
domain zerophone.cc 2026-03-18
domain zorc.cc 2026-03-18
References (1)
↗ avrecon_iocs.txt