> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# IOC Alert: Suspicious Crypto-themed Command-and-Control Infrastructure
- URL: https://darkwebinformer.com/ioc-alert-suspicious-crypto-themed-command-and-control-infrastructure/
- Published: 2025-09-28T16:39:28.000Z
- Updated: 2025-09-28T16:39:28.000Z
- Author: Dark Web Informer
- Tags: IOC

## 📖 Overview

A domain-based indicator has been identified that mimics the DODOEX decentralized exchange interface. The infrastructure is associated with potential botnet command-and-control (C2) operations, using a convincing crypto-trading front. Confidence is assessed at 100%.

---

## 📌 Key Details

| Field           | Information                |
| --------------- | -------------------------- |
| **Type**        | Domain                     |
| **Indicator**   | app.dodloxex\[.\]com       |
| **Threat Type** | Botnet C2                  |
| **Malware**     | Unknown                    |
| **Confidence**  | 100%                       |
| **Date**        | 28 Sep 2025 – 16:15:37 UTC |
| **Tags**        | c2                         |
| **Reporter**    | Pamparam                   |
| **Reference**   | None                       |

---

## 🔎 URLScan Result

- **Verdict Score:** 0
- **Page Title:** Swap 1-ETH to 1-USDC at 3,983.6084 with DODOEX
- **Screenshot:** [View Screenshot](https://urlscan.io/screenshots/019980f8-3272-7548-a29b-26e148de2a22.png)
- **Result:** [Full Scan Report](https://urlscan.io/result/019980f8-3272-7548-a29b-26e148de2a22/)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/09/8672348765238765827632.jpg)

---

## 📡 Domain & Certificate Info

- **DNS A Records:** 104\[.\]21\[.\]11\[.\]130, 172\[.\]67\[.\]149\[.\]60
- **DNS AAAA Records:** 2606:4700:3034::6815:b82, 2606:4700:3030::ac43:953c
- **Recent Certificates:**
  - C=US, O=Let's Encrypt, CN=R13 (Valid: 2025-08-27 → 2025-11-25)
  - C=US, O=Let's Encrypt, CN=R13 (Valid: 2025-08-27 → 2025-11-25)

---

## 📡 Related Intelligence

- **Certificate Transparency:** [crt.sh Report](https://crt.sh/?q=app.dodloxex.com)
- **VirusTotal Report:** [VirusTotal Domain Report](https://www.virustotal.com/gui/domain/app.dodloxex.com)
- **URLScan Domain Overview:** [urlscan.io Domain Page](https://urlscan.io/domain/app.dodloxex.com)
- **DNS Analytics:** [dnslytics.com Report](https://dnslytics.com/domain/app.dodloxex.com)

---

## 🛡️ Defensive Guidance

- Block **app.dodloxex\[.\]com** and its associated IP addresses at DNS, proxy, and endpoint levels.
- Watch for outbound traffic attempting to beacon or interact with DODOEX-themed fake domains.
- Alert on user activity involving suspicious crypto swap interfaces outside known trusted exchanges.
- Track certificate transparency logs for additional domains impersonating cryptocurrency services.

---

⚠️ This IOC highlights the use of **crypto-exchange lookalike pages** as camouflage for malicious C2 infrastructure. Such setups are often used to lure victims into interacting with a familiar interface while backend traffic is leveraged for command-and-control purposes.