C2 Command and Control from the site transfer.sh #3

Closed
opened 2026-01-19 18:28:36 +00:00 by michael · 1 comment
Owner

Originally created by @chaosgmd3-wiss on GitHub.

Hi everyone,

I've noticed some unusual activity related to transfer.sh, and I'm wondering if the main domain itself (not the uploaded files or subdirectories) is possibly being abused.

Does anyone have more information or similar observations?
Is the site still actively maintained, or could it be compromised or misused?

For example, my endpoint protection flagged it as a "2C activity" just by visiting https://transfer.sh.
If you're planning to test this yourself, please use Windows Sandbox or an isolated virtual machine, just to be safe.

Looking forward to hearing your thoughts.

Best regards

Originally created by @chaosgmd3-wiss on GitHub. Hi everyone, I've noticed some unusual activity related to transfer.sh, and I'm wondering if the main domain itself (not the uploaded files or subdirectories) is possibly being abused. Does anyone have more information or similar observations? Is the site still actively maintained, or could it be compromised or misused? For example, my endpoint protection flagged it as a "2C activity" just by visiting https://transfer.sh. If you're planning to test this yourself, please use Windows Sandbox or an isolated virtual machine, just to be safe. Looking forward to hearing your thoughts. Best regards
Author
Owner

@paolafrancesca commented on GitHub:

I've no idea, as written everywhere the repo has nothing to do with the website, @stefanbenten just happens to be as much a maintainer here (with very low involvement, even less than me) and the person hosting the website.

as soon as i will have some energy i will get rid of any reference to the website and write in bigger fonts that the repo has nothing to do with it.

;)

@paolafrancesca commented on GitHub: I've no idea, as written everywhere the repo has nothing to do with the website, @stefanbenten just happens to be as much a maintainer here (with very low involvement, even less than me) and the person hosting the website. as soon as i will have some energy i will get rid of any reference to the website and write in bigger fonts that the repo has nothing to do with it. ;)
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: dutchcoders/transfer.sh#3