Known malicious kithighother

CountLoader servers that redirect every visitor to www.gmx.net — scanned or contacted host, server address

family: countloader-c2-gmx-decoy-2026-10

Command-and-control servers of CountLoader, a PowerShell loader that installs further malware and keeps itself running through scheduled tasks. These servers show no page to an ordinary visitor: the web server answers every request with a permanent redirect to www.gmx[.]net, the home page of an unrelated, legitimate German webmail provider, which is not involved. The domains use uncommon top-level domains (.vg, .cc, .gl), Cloudflare name servers and a server address of their own. Public threat lists label alphastore[.]vg, twit-follow[.]vg, urugvai[.]cc, ultahost[.]gl, holiday-forever[.]cc and alpha-centavr[.]cc as CountLoader. SOCRadar's August 2026 report on the DOUBLECUP ClickFix delivery service lists alphastore[.]vg as a DOUBLECUP delivery host and CountLoader server. capsysnet[.]vg, which Microsoft Threat Intelligence named on 2026-10-03 as a later-stage server in a ClickFix campaign that hides its payload in the browser cache, answers with the same redirect. Every domain seen so far on 79.124.59[.]146 is publicly labelled CountLoader or an information stealer.

Anchors

SMQL queryrun
ip:79.124.59.146 OR domain:alphastore.vg OR domain:twit-follow.vg OR domain:urugvai.cc OR domain:ultahost.gl OR domain:holiday-forever.cc OR domain:alpha-centavr.cc OR domain:capsysnet.vg OR contacted_host:alphastore.vg OR contacted_host:twit-follow.vg OR contacted_host:urugvai.cc OR contacted_host:ultahost.gl OR contacted_host:holiday-forever.cc OR contacted_host:alpha-centavr.cc OR contacted_host:capsysnet.vg

Provenance

Added: 2026-10-04 13:29
Matches scans of these exact hostnames, pages whose browser contacted them, and scans of any host that resolved to 79.124.59.146. The redirect to the webmail provider is the operator's decoy, not a compromise of that provider. Other servers with the same redirect are not matched automatically and are added by hand. capsysnet[.]vg is included because it behaves the same way; that links Microsoft's campaign to CountLoader infrastructure by behaviour, it does not prove the same operator. The other servers' addresses are not included, because they are cloud or rented virtual servers that change tenants.

Sightings (16)

HostScanScriptMatchWhen
capsysnet.vg8baa5a6d…—query2026-10-04 13:31
alpha-centavr.ccd11fc1f0…—query2026-10-04 13:31
network-defender.cc19d15bce…—query2026-10-04 13:31
geo-foundation.vg3d106b7e…—query2026-10-04 13:31
holiday-forever.cc034179dd…—query2026-10-04 13:31
urugvai.ccbaa1a9a7…—query2026-10-04 13:31
vless-proto.ccd7d79028…—query2026-10-04 13:31
ccleaner.gla8c07b44…—query2026-10-04 13:31
fileshare.vg8f8fd4bf…—query2026-10-04 13:31
ultahost.gl1fa1db53…—query2026-10-04 13:31
memory-scanner.cc1fb118b9…—query2026-10-04 13:31
deluxe.glf16428ca…—query2026-10-04 13:31
command-center.cc1ca3d9fc…—query2026-10-04 13:31
alphastore.vga49d1193…—query2026-10-04 13:31
twit-follow.vgcf3ac2a7…—query2026-10-04 13:31
hosting-control.cc5a2a00df…—query2026-10-04 13:31