C&CMembers
C&C

Bot Panel's Command Menu Exposed in Plain URL Parameters

A PHP-based C2 panel tied to malware masquerading as Microsoft files lists its own functions — enumerate, download, shell, DDoS — in plain query strings under one bot ID. The readability suggests a disposable panel built for speed, not stealth.

Sep 2, 2026, 23:06 (UTC+9)Last seenSep 2, 2026Severity92ByCTX TeamActorGamaredon GroupCTIGIOC15MITRE27RegionsUA

A command-and-control server rarely tells a researcher what it can do before it is even queried, but the PHP panel sitting behind 5.175.209.151 does exactly that. Six URLs observed against the IP all funnel through the same script, /ft/si.php, and the query strings read like an operator's own feature list rather than obfuscated traffic: a listing function, a version check, a download trigger, a shell-execution flag, and a distributed-denial-of-service tasking flag, all addressed to a single bot…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence