> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# IOC Alert: Suspicious HTX-Themed Domain Used for Potential C2 Activity
- URL: https://darkwebinformer.com/ioc-alert-suspicious-htx-themed-domain-used-for-potential-c2-activity/
- Published: 2025-10-06T18:26:43.000Z
- Updated: 2025-10-06T18:26:43.000Z
- Author: Dark Web Informer
- Tags: IOC

## 📖 Overview

A phishing-style domain mimicking the **HTX cryptocurrency exchange login page** has been identified. While presenting itself as a legitimate portal, the infrastructure may serve dual purposes, phishing credential harvesting and potential command-and-control (C2) activity. Confidence is assessed at 75%.

---

## 📌 Key Details

| Field           | Information                |
| --------------- | -------------------------- |
| **Type**        | Domain                     |
| **Indicator**   | htx-user\[.\]at            |
| **Threat Type** | Botnet C2                  |
| **Malware**     | Unknown                    |
| **Confidence**  | 75%                        |
| **Date**        | 06 Oct 2025 – 16:41:32 UTC |
| **Tags**        | domain                     |
| **Reporter**    | anonymous                  |
| **Reference**   | None                       |

---

## 🔎 URLScan Result

- **Verdict Score:** 0
- **Page Title:** HTX Вход — Авторизация аккаунта | HTX Login & Sign In
- **Screenshot:** [View Screenshot](https://urlscan.io/screenshots/01986dbe-12f5-7598-941c-2f7f83c47b58.png)
- **Result:** [Full Scan Report](https://urlscan.io/result/01986dbe-12f5-7598-941c-2f7f83c47b58/)

![](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2025/10/879234876237685487652382-2.jpg)

---

## 📡 Domain & Certificate Info

- **DNS A Record:** 95\[.\]129\[.\]234\[.\]137
- **Recent Certificates:**
  - C=US, O=Let's Encrypt, CN=R12 (Valid: 2025-09-20 → 2025-12-19)
  - C=US, O=Let's Encrypt, CN=R12 (Valid: 2025-09-20 → 2025-12-19)
  - C=US, O=Let's Encrypt, CN=R13 (Valid: 2025-09-15 → 2025-12-14)

---

## 📡 Related Intelligence

- **Certificate Transparency:** [crt.sh Report](https://crt.sh/?q=htx-user.at)
- **VirusTotal Report:** [VirusTotal Domain Report](https://www.virustotal.com/gui/domain/htx-user.at)
- **URLScan Domain Overview:** [urlscan.io Domain Page](https://urlscan.io/domain/htx-user.at)
- **DNS Analytics:** [dnslytics.com Report](https://dnslytics.com/domain/htx-user.at)

---

## 🛡️ Defensive Guidance

- Block **htx-user\[.\]at** and its associated IP (**95\[.\]129\[.\]234\[.\]137**) at DNS, proxy, and endpoint layers.
- Watch for outbound traffic patterns or login attempts to lookalike cryptocurrency domains.
- Hunt for credentials exfiltrated to suspicious domains masquerading as crypto exchange portals.
- Track certificate transparency logs to detect and pre-emptively block newly registered HTX-themed lookalike domains.

---

⚠️ This IOC highlights the **continued abuse of cryptocurrency branding** by threat actors who stage fake login portals to capture credentials or operate C2 channels under the guise of legitimate services.