> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# IOC Alert: Lumma Stealer Command-and-Control Domain Identified
- URL: https://darkwebinformer.com/ioc-alert-lumma-stealer-command-and-control-domain-identified/
- Published: 2025-09-30T19:14:22.000Z
- Updated: 2025-09-30T19:14:22.000Z
- Author: Dark Web Informer
- Tags: IOC

## 📖 Overview

A domain has been identified hosting infrastructure associated with the Lumma information stealer malware family. The site currently resolves to an active IP and is registered with Let’s Encrypt certificates. Confidence in this attribution is assessed at 100%.

---

## 📌 Key Details

| Field           | Information                |
| --------------- | -------------------------- |
| **Type**        | Domain                     |
| **Indicator**   | holdonz\[.\]pics           |
| **Threat Type** | Botnet C2                  |
| **Malware**     | win.lumma                  |
| **Confidence**  | 100%                       |
| **Date**        | 30 Sep 2025 – 14:04:52 UTC |
| **Tags**        | c2, domain, Lumma, stealer |
| **Reporter**    | DonPasci                   |
| **Reference**   | None                       |

---

## 🔎 URLScan Result

- **Verdict Score:** 0
- **Page Title:** holdonz.pics
- **Screenshot:** [View Screenshot](https://urlscan.io/screenshots/01997847-5a00-70e8-a6b2-31aed6e66040.png)
- **Result:** [Full Scan Report](https://urlscan.io/result/01997847-5a00-70e8-a6b2-31aed6e66040/)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/09/2678354876124678512124.jpg)

---

## 📡 Domain & Certificate Info

- **DNS A Record:** 164\[.\]90\[.\]129\[.\]126
- **Recent Certificates:**
  - C=US, O=Let's Encrypt, CN=R12 (Valid: 2025-09-22 → 2025-12-21)
  - C=US, O=Let's Encrypt, CN=R12 (Valid: 2025-09-22 → 2025-12-21)
  - C=US, O=Let's Encrypt, CN=R12 (Valid: 2025-09-22 → 2025-12-21)

---

## 📡 Related Intelligence

- **Certificate Transparency:** [crt.sh Report](https://crt.sh/?q=holdonz.pics)
- **VirusTotal Report:** [VirusTotal Domain Report](https://www.virustotal.com/gui/domain/holdonz.pics)
- **URLScan Domain Overview:** [urlscan.io Domain Page](https://urlscan.io/domain/holdonz.pics)
- **DNS Analytics:** [dnslytics.com Report](https://dnslytics.com/domain/holdonz.pics)

---

## 🛡️ Defensive Guidance

- Block **holdonz\[.\]pics** and its associated IP (**164\[.\]90\[.\]129\[.\]126**) at DNS, proxy, and endpoint levels.
- Monitor for traffic patterns consistent with Lumma stealer C2 communication.
- Hunt for indicators of compromise such as suspicious exfiltration activity from Windows endpoints.
- Add Lumma-related domains to detection watchlists and track new registrations using certificate transparency logs.

---

⚠️ This IOC underscores the persistent use of **cheap, quickly registered domains** to support Lumma stealer operations, leveraging Let’s Encrypt certificates for legitimacy.