C&CMembers
C&C

Five-Day-Old Domain Found Hosting Full SQL Server Intrusion Kit

Registered through Namecheap on September 25, vietnam852.com was serving a complete, ready-to-run toolkit — packed trojans, batch/VBS launchers, a SQL dump, and plaintext credential files — from a single unauthenticated directory. Zero of 91 security vendors had flagged the domain itself as malicious at the time of capture.

Sep 30, 2026, 22:37 (UTC+9)Last seenSep 30, 2026Severity100ByCTX TeamIOC31RegionsBDBREGINMY

A domain registered through Namecheap on September 25 and still just five days old when it was captured is hosting a complete, ready-to-run intrusion kit — not a single payload, but an entire toolchain: packed executables, batch and VBS launchers, a SQL Server data dump, and plaintext files labeled simply "user" and "pass." The domain, vietnam852.com, resolves to one IP address, 8.230.28.79, and serves everything from a single path: site.vietnam852.com/sql/.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence