Last seven days
- First activity
- Aug 3, 2026
- Last activity
- Aug 3, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
C2 tracking
Derp observations, rolling seven-day window
Samples
3989d8e0cf5314b9575bbf3c926b3f525fc836456b761639f2efea2c516a1528 a4a51471600fb17bc9d3e5f15509de56311b372269f1c4335cb8e3caca250c31 b2518abe972501fcc9c29617114ea1bd77e991f912c667b5744daf2ff1867fe2 e18134f304e4b3964ebfae04b8c465fd4f8628ba66f19486d64980e936d6dca3 Reported operators
Advanced Data Theft and Remote Access: A PyInstaller EXE enables file and secret extraction via FTP.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.