Skip to main content

ThreatFox IOCs for 2024-06-08

Medium
Published: Sat Jun 08 2024 (06/08/2024, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2024-06-08

AI-Powered Analysis

AILast updated: 07/05/2025, 23:24:31 UTC

Technical Analysis

The provided information pertains to a set of Indicators of Compromise (IOCs) published on June 8, 2024, by the ThreatFox MISP Feed, categorized under malware with a focus on OSINT (Open Source Intelligence), network activity, and payload delivery. The data indicates that these IOCs are intended to support threat intelligence efforts by identifying malicious network behaviors and payload delivery mechanisms. However, the details lack specific information about the malware family, attack vectors, affected software versions, or exploitation techniques. The threat level is indicated as medium, with no known exploits in the wild and no available patches. The absence of CWE identifiers and specific technical details suggests that this is an intelligence feed update rather than a newly discovered vulnerability or active exploit. The threat appears to be related to monitoring or detecting malicious network activity and payload delivery, likely serving as a resource for security teams to enhance detection capabilities rather than describing a direct, active threat. The technical metadata shows moderate distribution (3 out of an unspecified scale), low analysis (1), and a threat level of 2, implying limited immediate risk but relevance for ongoing monitoring.

Potential Impact

For European organizations, the impact of this threat is primarily in the realm of situational awareness and detection rather than direct compromise. Since the IOCs are related to OSINT and network activity, they can help organizations identify and respond to potential malware payload deliveries before they cause harm. The medium severity suggests that while the threat is not currently critical, failure to incorporate these IOCs into detection systems could result in missed opportunities to detect early-stage attacks or reconnaissance activities. European entities with extensive network infrastructures, especially those in critical sectors such as finance, energy, and government, could benefit from integrating these IOCs to enhance their threat hunting and incident response capabilities. However, the lack of known exploits and patches indicates that the immediate risk of exploitation is low, reducing the likelihood of widespread impact or operational disruption.

Mitigation Recommendations

To effectively mitigate the risks associated with this threat, European organizations should: 1) Integrate the provided IOCs into their existing Security Information and Event Management (SIEM) and Intrusion Detection/Prevention Systems (IDS/IPS) to improve detection of suspicious network activity and payload delivery attempts. 2) Regularly update threat intelligence feeds and correlate these IOCs with internal logs to identify potential compromises early. 3) Conduct proactive threat hunting exercises using these indicators to uncover latent threats within their networks. 4) Enhance network segmentation and monitoring to limit the lateral movement of potential malware payloads. 5) Train security teams on interpreting OSINT-derived IOCs and incorporating them into incident response workflows. 6) Maintain up-to-date endpoint protection and network security controls, even though no specific patches are available for this threat, to reduce the attack surface for payload delivery mechanisms.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
fbab55e4-b101-4bdf-b375-e6341544b05f
Original Timestamp
1717891386

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://dcc.olcrv.com/login/tologin
More_eggs botnet C2 (confidence level: 49%)
urlhttps://83.97.73.39/ytyxnjljzdi1yzfh/
Coper botnet C2 (confidence level: 80%)
urlhttps://97felu2ehv0r5iff3cslcamel.store/ytyxnjljzdi1yzfh/
Coper botnet C2 (confidence level: 80%)
urlhttps://6zimks6know8jihvtoa8camel.store/ytyxnjljzdi1yzfh/
Coper botnet C2 (confidence level: 80%)
urlhttps://3w0mi18gkfrf6l8a8d09camel.store/ytyxnjljzdi1yzfh/
Coper botnet C2 (confidence level: 80%)
urlhttps://brfw0g97s9mwun8juhb0camel.store/ytyxnjljzdi1yzfh/
Coper botnet C2 (confidence level: 80%)
urlhttps://re5bvyc4l6004tqmtzp4camel.store/ytyxnjljzdi1yzfh/
Coper botnet C2 (confidence level: 80%)
urlhttps://k6fvq8c11dqqjd446ck9camel.store/ytyxnjljzdi1yzfh/
Coper botnet C2 (confidence level: 80%)
urlhttps://7l19jlu5trkqndh24li4camel.store/ytyxnjljzdi1yzfh/
Coper botnet C2 (confidence level: 80%)
urlhttps://pq2trelsquu44xbpritocamel.store/ytyxnjljzdi1yzfh/
Coper botnet C2 (confidence level: 80%)
urlhttps://wlw7obu15d6ru3eqy3o8camel.store/ytyxnjljzdi1yzfh/
Coper botnet C2 (confidence level: 80%)
urlhttps://hqj6lhsgcnuxfnlj5y95camel.store/ytyxnjljzdi1yzfh/
Coper botnet C2 (confidence level: 80%)
urlhttps://inat-protv-box.net.tr/ytyxnjljzdi1yzfh/
Coper botnet C2 (confidence level: 80%)
urlhttps://hvamkulturogforsamlingshus.dk/reports.php
GootLoader payload delivery URL (confidence level: 100%)
urlhttps://hvamkulturogforsamlingshus.dk/reports.php
GootLoader payload delivery URL (confidence level: 100%)
urlhttps://hvamkulturogforsamlingshus.dk/reports.php
GootLoader payload delivery URL (confidence level: 100%)
urlhttps://hvamkulturogforsamlingshus.dk/reports.php
GootLoader payload delivery URL (confidence level: 100%)
urlhttp://saasfeerentals.com/stamping-fee-for-sp-agreement
GootLoader payload delivery URL (confidence level: 100%)
urlhttps://i-likeitalot.com/reports.php
GootLoader payload delivery URL (confidence level: 100%)
urlhttps://ikenouedojo.com/reports.php
GootLoader payload delivery URL (confidence level: 100%)
urlhttps://47.92.24.58:8001/pixel
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://64.7.199.88:10443/dot.gif
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://213.109.202.188/load
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://23.95.65.198/push
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://content.microsoft.com.w.kunlunca.com/pixel.gif
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://23.95.65.198:2222/activity
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://101.35.42.157/load
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://intranat.vhfk.se/reports.php
GootLoader payload delivery URL (confidence level: 100%)
urlhttp://39.104.230.184:6668/ga.js
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://111.231.51.250:9090/activity
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://89.116.48.173:9999/pixel.gif
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://service-o1dc3wx3-1311799005.bj.tencentapigw.com.cn/api/x
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://112.124.5.135:1234/ie9compatviewlist.xml
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://106.52.130.164:8080/updates
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://47.239.1.232/jquery-3.3.1.min.js
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://4.191.74.1/dpixel
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://124.71.153.149/assets/css/font-awesome.css
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://124.71.153.115/pixel
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://61.170.80.230/jquery-3.3.1.min.js
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://180.213.179.141/jquery-3.3.1.min.js
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://120.195.185.112/jquery-3.3.1.min.js
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://118.182.226.161/jquery-3.3.1.min.js
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://61.170.81.233/jquery-3.3.1.min.js
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://27.37.200.237/jquery-3.3.1.min.js
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://101.226.26.147/jquery-3.3.1.min.js
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://185.186.146.25/ca
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://exotours.in/read-agreement-of-being-gay-for-30-days
GootLoader payload delivery URL (confidence level: 100%)
urlhttps://cs.xfdaili.com/g.pixel
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://154.198.245.62/visit.js
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://134.122.75.115:444/push
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://23.95.65.198/g.pixel
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://iheartredteams.com/fwlink
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://www.platypus-verlag.ch/wisconsin-tax-installment-agreement/
GootLoader payload delivery URL (confidence level: 100%)
urlhttps://labstyl.nazwa.pl/reports.php
GootLoader payload delivery URL (confidence level: 100%)
urlhttps://ktweb.home.pl/reports.php
GootLoader payload delivery URL (confidence level: 100%)
urlhttps://bloriz.prestador-xp.services/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://blufel2.nenaviste.org/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://blulunwinim.neskodny.builders/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://blumol3.maxtel.solutions/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://bluronbonxil.cuidadofinanceiro.agency/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://bluronpal.maxtel.solutions/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://brubenbonzol183.prestador-xp.services/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://brucal.nenaviste.org/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://brudensintal.vistoriaveicular.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://brudiz.neskodny.builders/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://brudiz.vistoriaveicular.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://brumengonwel.abastecimentoonline.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://brumol164.fazenda-sps.one/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://brusonroncol.chamadoregional.solutions/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://brutonlanfer.maxtel.solutions/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://brutonlinjal.nenaviste.org/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://clahenkil037.fazenda-sps.one/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://clananbel.neskodny.builders/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://clegongor2.prestador-xp.services/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://cleriz.prestador-xp.services/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://clesonqual.vistoriaveicular.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://cracal.cuidadofinanceiro.agency/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://cracal.nenaviste.org/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://cramengonwel143.businessgreat.one/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crapennal24.prestador-xp.services/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crasonnal.cuidadofinanceiro.agency/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crasonqual.atende-br.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crediz.atende-br.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://cresonrol761.vistoriaveicular.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://cretonpaz.vistoriaveicular.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crical.chamadoregional.solutions/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://criel.cuidadofinanceiro.agency/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crironcindor3.vistoriaveicular.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crironnonbil3.businessgreat.one/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crisonlinder.neskodny.builders/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crocal3.fazenda-sps.one/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crofer.prestador-xp.services/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crohal.fazenda-sps.one/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crojal.cuidadofinanceiro.agency/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://cronanbel.vistoriaveicular.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://croringungem.vistoriaveicular.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://croronqual225.vistoriaveicular.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crosonpal.businessgreat.one/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crotal.maxtel.solutions/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crotunlinder.chamadoregional.solutions/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://crovaz.abastecimentoonline.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://drabel4.maxtel.solutions/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://dralundinnal.chamadoregional.solutions/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://dratunlinfil.fazenda-sps.one/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://dratunmintil.fazenda-sps.one/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://drejal.chamadoregional.solutions/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://drelunral38.maxtel.solutions/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://dresonnal4.abastecimentoonline.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://drocangoncol.businessgreat.one/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://drocansal.fazenda-sps.one/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://dromongongor.businessgreat.one/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://dromonnancal.atende-br.chat/
Astaroth botnet C2 (confidence level: 100%)
urlhttps://drosonfinfel.nenaviste.org/
Astaroth botnet C2 (confidence level: 100%)
urlhttp://23.88.106.134/6a9f8e2503d99c04.php
Stealc botnet C2 (confidence level: 100%)
urlhttps://goodstos.com/agreement-side-effects/
GootLoader payload delivery URL (confidence level: 100%)
urlhttps://lilabrand.com/reports.php
GootLoader payload delivery URL (confidence level: 100%)
urlhttp://110.42.249.222:6666/jquery-3.3.1.min.js
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://hospitalstorage.azureedge.net/git.asp
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://34.92.25.154:8443/match
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://candycappa.store/remove
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://bad-week-gw.aws-usw2.cloud-ara.tyk.io/api/v2/login
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://58.53.128.67:82/fwlink
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://20.244.96.7/s/ref=nb_sb_noss_1/167-3294888-0262949/field-keywords=books
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://146.70.149.42:9999/j.ad
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://97.64.18.185:3333/ca
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://118.89.200.169/activity
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://185.22.152.167:8868/cx
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://sanhaozhifu.top:8443/jquery-3.3.1.min.js
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://47.92.162.69/mall_100_100.html
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://54.169.254.221/j.ad
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://58.137.140.238/g.pixel
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://49.232.249.109:81/cx
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttps://124.71.102.140/load
Cobalt Strike botnet C2 (confidence level: 100%)
urlhttp://38.180.165.153/7providerlinux/cdngenerator/jspacketupdateprocessorserverprotecttraffictestdatalifeuploads.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://505732cm.n9shteam2.top/updatesqldb.php
DCRat botnet C2 (confidence level: 100%)

File

ValueDescriptionCopy
file3.125.223.134
NjRAT botnet C2 server (confidence level: 75%)
file154.12.93.14
Ghost RAT botnet C2 server (confidence level: 100%)
file4.203.104.98
NjRAT botnet C2 server (confidence level: 100%)
file138.162.7.28
Sliver payload delivery server (confidence level: 50%)
file136.144.162.236
Sliver botnet C2 server (confidence level: 50%)
file92.243.64.130
BianLian botnet C2 server (confidence level: 50%)
file104.238.61.20
BianLian botnet C2 server (confidence level: 50%)
file93.123.39.194
Havoc botnet C2 server (confidence level: 50%)
file82.168.162.65
Havoc botnet C2 server (confidence level: 50%)
file39.96.169.89
Havoc botnet C2 server (confidence level: 50%)
file46.246.14.21
DCRat botnet C2 server (confidence level: 50%)
file16.16.206.231
Unknown malware botnet C2 server (confidence level: 50%)
file43.138.143.146
Cobalt Strike botnet C2 server (confidence level: 100%)
file124.71.153.115
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.239.1.232
Cobalt Strike botnet C2 server (confidence level: 100%)
file124.71.153.149
Cobalt Strike botnet C2 server (confidence level: 100%)
file124.71.153.115
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.97.79.97
Cobalt Strike botnet C2 server (confidence level: 100%)
file185.186.146.25
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.12.26.80
Cobalt Strike botnet C2 server (confidence level: 100%)
file37.44.238.75
Mirai botnet C2 server (confidence level: 75%)
file47.103.52.146
N-W0rm botnet C2 server (confidence level: 100%)
file105.105.234.158
NjRAT botnet C2 server (confidence level: 100%)
file158.160.11.208
FAKEUPDATES payload delivery server (confidence level: 100%)
file154.198.245.62
Cobalt Strike botnet C2 server (confidence level: 100%)
file3.64.4.198
NjRAT botnet C2 server (confidence level: 75%)
file3.125.102.39
NjRAT botnet C2 server (confidence level: 75%)
file51.81.30.54
AsyncRAT botnet C2 server (confidence level: 100%)
file18.157.68.73
NjRAT botnet C2 server (confidence level: 75%)
file18.156.13.209
NjRAT botnet C2 server (confidence level: 75%)
file152.53.20.106
Sliver botnet C2 server (confidence level: 50%)
file152.53.20.106
Sliver botnet C2 server (confidence level: 50%)
file84.129.151.24
Unknown malware botnet C2 server (confidence level: 50%)
file159.89.46.205
Cobalt Strike botnet C2 server (confidence level: 100%)
file193.124.33.239
Cobalt Strike botnet C2 server (confidence level: 100%)
file13.49.238.38
Havoc botnet C2 server (confidence level: 50%)
file20.244.96.7
Cobalt Strike botnet C2 server (confidence level: 100%)
file118.89.200.169
Cobalt Strike botnet C2 server (confidence level: 100%)
file78.178.72.163
QakBot botnet C2 server (confidence level: 50%)
file46.246.84.18
DCRat botnet C2 server (confidence level: 50%)
file165.3.87.196
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.92.162.69
Cobalt Strike botnet C2 server (confidence level: 100%)
file54.169.254.221
Cobalt Strike botnet C2 server (confidence level: 100%)
file74.48.45.204
Unknown malware botnet C2 server (confidence level: 50%)
file58.137.140.238
Cobalt Strike botnet C2 server (confidence level: 100%)
file77.221.157.6
Meduza Stealer botnet C2 server (confidence level: 50%)
file124.71.102.140
Cobalt Strike botnet C2 server (confidence level: 100%)
file185.119.196.100
Unknown malware botnet C2 server (confidence level: 50%)
file101.126.91.145
Cobalt Strike botnet C2 server (confidence level: 100%)
file77.83.196.180
Unidentified 111 (Latrodectus) botnet C2 server (confidence level: 75%)
file18.229.248.167
LimeRAT botnet C2 server (confidence level: 100%)
file5.180.148.45
CyberGate botnet C2 server (confidence level: 100%)
file18.231.93.153
LimeRAT botnet C2 server (confidence level: 100%)
file45.137.22.111
RedLine Stealer botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash12374
NjRAT botnet C2 server (confidence level: 75%)
hash1153
Ghost RAT botnet C2 server (confidence level: 100%)
hash1024
NjRAT botnet C2 server (confidence level: 100%)
hash8000
Sliver payload delivery server (confidence level: 50%)
hash8888
Sliver botnet C2 server (confidence level: 50%)
hash31205
BianLian botnet C2 server (confidence level: 50%)
hash80
BianLian botnet C2 server (confidence level: 50%)
hash443
Havoc botnet C2 server (confidence level: 50%)
hash443
Havoc botnet C2 server (confidence level: 50%)
hash443
Havoc botnet C2 server (confidence level: 50%)
hash9000
DCRat botnet C2 server (confidence level: 50%)
hash4444
Unknown malware botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash81
Mirai botnet C2 server (confidence level: 75%)
hash443
N-W0rm botnet C2 server (confidence level: 100%)
hash555
NjRAT botnet C2 server (confidence level: 100%)
hash443
FAKEUPDATES payload delivery server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash13678
NjRAT botnet C2 server (confidence level: 75%)
hash17046
NjRAT botnet C2 server (confidence level: 75%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash17435
NjRAT botnet C2 server (confidence level: 75%)
hash17435
NjRAT botnet C2 server (confidence level: 75%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash8888
Sliver botnet C2 server (confidence level: 50%)
hash3389
Unknown malware botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
QakBot botnet C2 server (confidence level: 50%)
hash9000
DCRat botnet C2 server (confidence level: 50%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Meduza Stealer botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Unidentified 111 (Latrodectus) botnet C2 server (confidence level: 75%)
hash15352
LimeRAT botnet C2 server (confidence level: 100%)
hash7159
CyberGate botnet C2 server (confidence level: 100%)
hash15352
LimeRAT botnet C2 server (confidence level: 100%)
hash55615
RedLine Stealer botnet C2 server (confidence level: 100%)

Domain

ValueDescriptionCopy
domainassets.rdntocdns.com
Unknown malware payload delivery domain (confidence level: 100%)
domaincdn.rdntocdns.com
Unknown malware payload delivery domain (confidence level: 100%)
domaincss.rdntocdns.com
Unknown malware payload delivery domain (confidence level: 100%)
domainrest1.rdntocdns.com
Unknown malware payload delivery domain (confidence level: 100%)
domainrest2.rdntocdns.com
Unknown malware payload delivery domain (confidence level: 100%)
domainservice-o1dc3wx3-1311799005.bj.tencentapigw.com.cn
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainv7yen47u2e.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainabastecimentoonline.chat
Astaroth botnet C2 domain (confidence level: 100%)
domainatende-br.chat
Astaroth botnet C2 domain (confidence level: 100%)
domainbusinessgreat.one
Astaroth botnet C2 domain (confidence level: 100%)
domainchamadoregional.solutions
Astaroth botnet C2 domain (confidence level: 100%)
domaincuidadofinanceiro.agency
Astaroth botnet C2 domain (confidence level: 100%)
domainfazenda-sps.one
Astaroth botnet C2 domain (confidence level: 100%)
domainmaxtel.solutions
Astaroth botnet C2 domain (confidence level: 100%)
domainnenaviste.org
Astaroth botnet C2 domain (confidence level: 100%)
domainneskodny.builders
Astaroth botnet C2 domain (confidence level: 100%)
domainprestador-xp.services
Astaroth botnet C2 domain (confidence level: 100%)
domainvistoriaveicular.chat
Astaroth botnet C2 domain (confidence level: 100%)
domaincv2b8uz46e.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainb9y3b7ner2.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainhospitalstorage.azureedge.net
Cobalt Strike botnet C2 domain (confidence level: 100%)
domaincandycappa.store
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainbad-week-gw.aws-usw2.cloud-ara.tyk.io
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainsanhaozhifu.top
Cobalt Strike botnet C2 domain (confidence level: 100%)

Threat ID: 68359c9e5d5f0974d01f8a10

Added to database: 5/27/2025, 11:06:06 AM

Last enriched: 7/5/2025, 11:24:31 PM

Last updated: 7/14/2025, 11:58:47 AM

Views: 6

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats