C&CMembers
C&C

New Iranian IP Completes Matched Amadey C2 Pair on AS44208

A newly added IP, 176.46.152.47, sits one address from a previously known Iranian C2 node and shares an identical panel path and payload filename. The pairing exposes a templated Amadey/RedLine backend spread across a rotating, domain-free IP pool rather than fixed infrastructure.

Sep 19, 2026, 06:33 (UTC+9)Last seenSep 19, 2026Severity100ByCTX TeamIOC37MITRE55RegionsUS

A new IP address surfaced in the latest sweep of this Amadey-and-RedLine crimeware cluster, and it doesn't open a new front — it closes a loop. 176.46.152.47 sits one address away from 176.46.152.46, both inside the same /22 block registered to Farahoosh Dena PLC under AS44208 in Iran, and both now confirmed serving the identical panel path, `/diamo/data.php, alongside a shared payload filename, /zx.exe.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence