sc.c1s.su
Checking live DNS resolution...
100/100
CRITICAL RISK
21
Malware URLs
0
Resolved IPs
0
Abuse Reports
4
Active URLs

Threat Intelligence Summary: sc.c1s.su

Risk Level: CRITICALThreat Score: 100/100

Assessment: sc.c1s.su currently hosts 4 active malware URLs. While the volume is moderate, the presence of multiple active payloads indicates intentional malicious use rather than a one-time compromise. Blocking is recommended for enterprise environments. Malware families associated with this domain include gafgyt, elf, mirai.

Recommendation: Block immediately at DNS and firewall level


Total Malware URLs: 21 — Active: 4 — Resolved IPs: 0 — Abuse Reports: 0

First Seen: 2026-07-11T10:16:32 — Last Online: 2026-07-17T07:17:40

Data aggregated from threat intelligence feeds including URLhaus and community reports.

Domain Threat Analysis

sc.c1s.su has been associated with 21 malware URLs , of which 4 are currently active . The primary threat types are malware_download, malware.

Active threat. This domain is currently serving malicious content. Multiple malware URLs have been identified on this domain. Network administrators should consider blocking this domain or monitoring traffic to it closely.

Look Up Another Domain or IP

Check any domain or IP address against our threat intelligence database.

Access This Data via API

Integrate WAYSCloud domain threat intelligence into your security tools, SIEM, or firewall rules. Query any domain programmatically for malware URLs, resolved IPs, and threat scores.

API Documentation Integration Guide

See how we classify and verify threats →

Related Threat Intelligence

Top Threats Today Latest Attacks Active Malware Domains Understanding Botnets SSH Attack Explainer How to Block Threats What is a Phishing Domain? About Malware Distribution Check Another Domain
Timeline
First Seen
2026-07-11T10:16:32
Last Seen Online
2026-07-17T07:17:40
Data Last Updated
2026-07-27T05:00:23.306138
Status Activity Timeline (37 changes recorded)

Complete history of all status changes detected for URLs on this domain. Tracking online/offline transitions helps identify malware lifecycle patterns.

ONLINE OFFLINE
http://sc.c1s.su/x86
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/no_killer/arm7
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/no_killer/arm5
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/massload
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/tplink.sh
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/mipsel
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/arm7
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/mpsl
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/arm
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/arm5
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/aarch64
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/no_killer/mpsl
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/no_killer/x86
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/no_killer/mips
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/mips
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/tftp.sh
Status changed from online to offline
OFFLINE ONLINE
http://sc.c1s.su/tplink.sh
Status changed from offline to online
OFFLINE ONLINE
http://sc.c1s.su/no_killer/arm7
Status changed from offline to online
ONLINE OFFLINE
http://sc.c1s.su/no_killer/arm7
Status changed from online to offline
ONLINE OFFLINE
http://sc.c1s.su/tplink.sh
Status changed from online to offline
Showing 20 most recent changes of 37 total
Associated IP Addresses
No IP address resolution history available for this domain. However, this domain has been reported 21 time(s) in threat intelligence feeds. All reported malware URLs have been taken down or are no longer accessible.
Malware Classification
gafgyt
IoT botnet malware also known as BASHLITE or Lizkebab. Targets Linux-based IoT devices through default credentials and known exploits. Used for launching large-scale DDoS attacks. Competes with Mirai for control of vulnerable devices.
elf
Malware family "elf" detected in threat intelligence feeds. This threat is actively monitored. Exercise caution - infrastructure may be compromised or intentionally malicious.
mirai
Infamous IoT botnet source code released in 2016, spawning thousands of variants. Responsible for record-breaking DDoS attacks exceeding 1 Tbps. Spreads by scanning for devices with default credentials. Target routers, cameras, DVRs globally.
botnetdomain
Generic botnet command-and-control infrastructure. Domain used to coordinate infected devices, issue commands, and exfiltrate stolen data. Part of distributed botnet network infrastructure.
sh
Malicious shell script campaign. Bash/sh scripts used for initial access, downloading additional malware, establishing persistence, or cryptocurrency mining. Common in Linux server compromises.
ua-wget
Automated malware download campaign using wget user-agent strings. Indicates command-line driven infection attempts, typically part of shell script malware loaders targeting servers and IoT devices.
Malware URLs (21)

All malicious URLs identified on this domain. Status reflects last known state from threat intelligence feeds.

https://sc.c1s.su/
Active Threat
Type: malware
https://sc.c1s.su/
Active Threat
Type: malware
https://sc.c1s.su/
Active Threat
Type: malware
http://sc.c1s.su/mpsl
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf mirai
http://sc.c1s.su/arm
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf mirai
http://sc.c1s.su/arm5
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf mirai
http://sc.c1s.su/x86
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf mirai
http://sc.c1s.su/arm7
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf mirai
http://sc.c1s.su/mips
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf mirai
http://sc.c1s.su/mipsel
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf mirai
http://sc.c1s.su/tftp.sh
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain sh ua-wget
http://sc.c1s.su/massload
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain mirai sh ua-wget
http://sc.c1s.su/ftpget.sh
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain sh ua-wget
http://sc.c1s.su/no_killer/arm5
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf mirai ua-wget
http://sc.c1s.su/no_killer/x86
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf gafgyt ua-wget
http://sc.c1s.su/tplink.sh
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain mirai sh ua-wget
http://sc.c1s.su/aarch64
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf mirai ua-wget
http://sc.c1s.su/no_killer/arm7
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf mirai ua-wget
http://sc.c1s.su/no_killer/mips
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf gafgyt ua-wget
http://sc.c1s.su/no_killer/mpsl
Taken Down
Type: malware_download
First Seen: 2026-07-11
botnetdomain elf mirai ua-wget
Showing 20 of 21 URLs