
Same Femo IT Hosting Block Swaps Phishing for Amadey-Stealc Crimeware
AS214351, a German netblock run by Femo IT Solutions and previously tied to cert-rotating phishing infrastructure, now hosts nine entirely new malware files across its same three IPs. The payload has shifted to an Amadey downloader feeding Stealc v2 and a clipboard hijacker, with one panel IP wearing a TLS certificate typosquatting KuCoin.
The AS214351 hosting block operated out of Femo IT Solutions Limited's German netblocks has appeared in CTX Team's tracking before, tied to rapid certificate rotation behind phishing infrastructure. This snapshot shows the same three IPs — 62.60.226.159, 196.251.107.104, and 196.251.107.130 — still live, but every one of the nine files riding them is new. The ASN hasn't moved.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read