Skip to main content

ThreatFox IOCs for 2025-01-05

Medium
Published: Sun Jan 05 2025 (01/05/2025, 00:00:00 UTC)
Source: ThreatFox
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-01-05

AI-Powered Analysis

AILast updated: 06/19/2025, 16:19:30 UTC

Technical Analysis

The provided information pertains to a malware-related threat identified as 'ThreatFox IOCs for 2025-01-05,' sourced from ThreatFox, a platform known for sharing Indicators of Compromise (IOCs) and threat intelligence data. The threat is categorized under 'type:osint' and 'tlp:white,' indicating that it is open-source intelligence data with no restriction on sharing. The absence of specific affected versions, CWE identifiers, or patch links suggests that this entry primarily serves as a repository or collection of IOCs rather than detailing a specific malware variant or exploit. The technical details indicate a moderate threat level (threatLevel: 2) with limited analysis (analysis: 1) but a relatively higher distribution score (distribution: 3), implying that the threat or its indicators are somewhat widespread or have been observed across multiple environments or campaigns. No known exploits in the wild have been reported, and no direct technical specifics such as attack vectors, payloads, or vulnerabilities are provided. The lack of indicators in the dataset further suggests that this entry may be a placeholder or a summary of collected intelligence rather than an active, fully characterized threat. Overall, this threat entry appears to be an OSINT-based malware intelligence update without detailed technical exploitation data, serving primarily as a situational awareness artifact for cybersecurity professionals.

Potential Impact

Given the limited technical details and absence of known exploits in the wild, the immediate impact on European organizations is likely to be low to medium. However, the distribution score indicates that the threat or its indicators have some level of presence, which could translate into potential reconnaissance or preparatory activities by threat actors targeting European entities. The lack of specific affected products or versions means that the threat is not currently linked to a particular technology stack, reducing the risk of targeted exploitation. Nevertheless, organizations relying on OSINT feeds and threat intelligence platforms should be aware that this malware-related information could be used to inform future attacks or phishing campaigns. The medium severity rating suggests that while the threat is not critical, it warrants attention to prevent escalation. European organizations in sectors with high exposure to malware threats, such as finance, critical infrastructure, and government, should consider this intelligence as part of their broader threat landscape monitoring.

Mitigation Recommendations

1. Integrate ThreatFox and similar OSINT feeds into existing Security Information and Event Management (SIEM) systems to enhance detection capabilities for emerging IOCs. 2. Conduct regular threat hunting exercises using the latest IOCs from ThreatFox to identify any signs of compromise or suspicious activity within the network. 3. Maintain up-to-date endpoint protection solutions with behavioral analysis capabilities to detect malware variants that may not yet have signatures. 4. Implement network segmentation and strict access controls to limit the lateral movement potential of malware. 5. Educate security teams on the interpretation and validation of OSINT data to avoid false positives and ensure timely response. 6. Collaborate with national and European cybersecurity information sharing organizations (e.g., ENISA, CERT-EU) to contextualize this threat within regional threat trends. 7. Since no patches or specific vulnerabilities are identified, focus on general best practices such as timely software updates, strong authentication mechanisms, and incident response readiness.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
6087aba3-0074-4c8d-bc3d-2b6df5c86131
Original Timestamp
1736121785

Indicators of Compromise

File

ValueDescriptionCopy
file147.124.216.7
XWorm botnet C2 server (confidence level: 50%)
file159.138.153.205
Cobalt Strike botnet C2 server (confidence level: 100%)
file121.40.78.32
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.249.28.111
Sliver botnet C2 server (confidence level: 100%)
file103.96.74.248
Sliver botnet C2 server (confidence level: 100%)
file185.75.240.7
Sliver botnet C2 server (confidence level: 100%)
file45.92.9.110
Unknown malware botnet C2 server (confidence level: 100%)
file188.245.220.222
Unknown malware botnet C2 server (confidence level: 100%)
file23.94.153.130
Hook botnet C2 server (confidence level: 100%)
file23.94.153.130
Hook botnet C2 server (confidence level: 100%)
file91.107.126.63
Hook botnet C2 server (confidence level: 100%)
file91.107.126.63
Hook botnet C2 server (confidence level: 100%)
file217.156.66.80
Havoc botnet C2 server (confidence level: 100%)
file186.169.66.68
DCRat botnet C2 server (confidence level: 100%)
file185.245.183.74
Unknown malware botnet C2 server (confidence level: 100%)
file103.20.235.132
MooBot botnet C2 server (confidence level: 100%)
file51.255.39.182
Sliver botnet C2 server (confidence level: 100%)
file51.255.168.95
Sliver botnet C2 server (confidence level: 100%)
file13.113.116.176
Sliver botnet C2 server (confidence level: 100%)
file104.41.60.176
Sliver botnet C2 server (confidence level: 100%)
file16.171.150.224
Sliver botnet C2 server (confidence level: 100%)
file103.103.46.10
Sliver botnet C2 server (confidence level: 100%)
file158.69.53.135
Sliver botnet C2 server (confidence level: 100%)
file16.171.35.35
Revenge RAT botnet C2 server (confidence level: 100%)
file212.85.70.235
Remcos botnet C2 server (confidence level: 100%)
file212.85.70.235
Remcos botnet C2 server (confidence level: 100%)
file150.202.2.103
Remcos botnet C2 server (confidence level: 100%)
file195.133.78.18
Remcos botnet C2 server (confidence level: 75%)
file123.57.230.183
Cobalt Strike botnet C2 server (confidence level: 50%)
file18.138.186.108
Cobalt Strike botnet C2 server (confidence level: 100%)
file165.154.134.214
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.95.221.202
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.95.221.202
Cobalt Strike botnet C2 server (confidence level: 100%)
file107.174.235.118
Cobalt Strike botnet C2 server (confidence level: 100%)
file209.74.77.244
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.238.233.168
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.95.221.201
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.95.221.201
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.209.221.211
Remcos botnet C2 server (confidence level: 100%)
file101.200.221.200
Unknown malware botnet C2 server (confidence level: 100%)
file45.138.16.236
AsyncRAT botnet C2 server (confidence level: 100%)
file150.241.83.250
AsyncRAT botnet C2 server (confidence level: 100%)
file178.215.224.100
AsyncRAT botnet C2 server (confidence level: 100%)
file54.176.66.101
Unknown malware botnet C2 server (confidence level: 100%)
file107.148.49.58
Quasar RAT botnet C2 server (confidence level: 100%)
file198.167.199.218
Quasar RAT botnet C2 server (confidence level: 100%)
file35.78.190.249
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file54.176.66.101
Unknown malware botnet C2 server (confidence level: 100%)
file156.253.250.102
MooBot botnet C2 server (confidence level: 100%)
file104.248.123.182
Sliver botnet C2 server (confidence level: 50%)
file76.74.127.147
Sliver botnet C2 server (confidence level: 50%)
file45.159.97.195
Sliver botnet C2 server (confidence level: 50%)
file87.120.113.185
Sliver botnet C2 server (confidence level: 50%)
file70.28.194.62
Ghost RAT botnet C2 server (confidence level: 50%)
file3.230.181.51
Ghost RAT botnet C2 server (confidence level: 50%)
file3.91.190.163
Hook botnet C2 server (confidence level: 50%)
file195.133.52.175
Bashlite botnet C2 server (confidence level: 75%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file209.38.39.99
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file94.130.231.97
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file172.175.208.86
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file138.68.153.153
Unknown malware botnet C2 server (confidence level: 50%)
file61.169.19.21
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file54.216.124.40
Unknown malware botnet C2 server (confidence level: 50%)
file46.21.97.120
Unknown malware botnet C2 server (confidence level: 50%)
file38.47.91.155
Unknown malware botnet C2 server (confidence level: 50%)
file34.118.255.117
Unknown malware botnet C2 server (confidence level: 50%)
file185.232.69.81
Unknown malware botnet C2 server (confidence level: 50%)
file103.86.177.53
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file46.250.248.90
Unknown malware botnet C2 server (confidence level: 50%)
file147.185.221.24
NjRAT botnet C2 server (confidence level: 75%)
file69.165.65.231
ValleyRAT botnet C2 server (confidence level: 100%)
file5.161.96.111
Sliver botnet C2 server (confidence level: 100%)
file8.218.34.120
Sliver botnet C2 server (confidence level: 100%)
file13.88.56.101
Sliver botnet C2 server (confidence level: 100%)
file13.201.40.100
Sliver botnet C2 server (confidence level: 100%)
file15.236.43.82
Sliver botnet C2 server (confidence level: 100%)
file20.212.165.132
Sliver botnet C2 server (confidence level: 100%)
file23.227.187.168
Sliver botnet C2 server (confidence level: 100%)
file38.54.50.249
Sliver botnet C2 server (confidence level: 100%)
file45.55.135.53
Sliver botnet C2 server (confidence level: 100%)
file45.79.34.31
Sliver botnet C2 server (confidence level: 100%)
file49.7.54.66
Sliver botnet C2 server (confidence level: 100%)
file49.7.54.73
Sliver botnet C2 server (confidence level: 100%)
file49.7.54.77
Sliver botnet C2 server (confidence level: 100%)
file49.13.53.116
Sliver botnet C2 server (confidence level: 100%)
file54.185.12.112
Sliver botnet C2 server (confidence level: 100%)
file64.225.19.22
Sliver botnet C2 server (confidence level: 100%)
file68.183.223.36
Sliver botnet C2 server (confidence level: 100%)
file81.161.238.242
Sliver botnet C2 server (confidence level: 100%)
file87.120.115.140
Sliver botnet C2 server (confidence level: 100%)
file89.110.97.72
Sliver botnet C2 server (confidence level: 100%)
file89.208.105.101
Sliver botnet C2 server (confidence level: 100%)
file91.92.154.39
Sliver botnet C2 server (confidence level: 100%)
file91.107.245.65
Sliver botnet C2 server (confidence level: 100%)
file94.156.189.213
Sliver botnet C2 server (confidence level: 100%)
file94.156.227.129
Sliver botnet C2 server (confidence level: 100%)
file94.159.113.15
Sliver botnet C2 server (confidence level: 100%)
file98.71.214.219
Sliver botnet C2 server (confidence level: 100%)
file100.42.182.237
Sliver botnet C2 server (confidence level: 100%)
file104.236.90.163
Sliver botnet C2 server (confidence level: 100%)
file107.174.95.172
Sliver botnet C2 server (confidence level: 100%)
file116.205.127.203
Sliver botnet C2 server (confidence level: 100%)
file117.50.172.95
Sliver botnet C2 server (confidence level: 100%)
file138.68.168.138
Sliver botnet C2 server (confidence level: 100%)
file139.9.190.100
Sliver botnet C2 server (confidence level: 100%)
file154.92.19.71
Sliver botnet C2 server (confidence level: 100%)
file154.216.17.157
Sliver botnet C2 server (confidence level: 100%)
file157.173.99.13
Sliver botnet C2 server (confidence level: 100%)
file165.227.81.66
Sliver botnet C2 server (confidence level: 100%)
file167.99.217.68
Sliver botnet C2 server (confidence level: 100%)
file167.235.236.196
Sliver botnet C2 server (confidence level: 100%)
file173.208.246.114
Sliver botnet C2 server (confidence level: 100%)
file180.188.198.185
Sliver botnet C2 server (confidence level: 100%)
file185.237.185.138
Sliver botnet C2 server (confidence level: 100%)
file188.208.197.80
Sliver botnet C2 server (confidence level: 100%)
file191.239.123.219
Sliver botnet C2 server (confidence level: 100%)
file192.109.240.185
Sliver botnet C2 server (confidence level: 100%)
file45.252.248.26
Agent Tesla botnet C2 server (confidence level: 100%)
file39.105.121.115
Cobalt Strike botnet C2 server (confidence level: 50%)
file193.233.203.153
Cobalt Strike botnet C2 server (confidence level: 100%)
file83.229.122.168
Cobalt Strike botnet C2 server (confidence level: 100%)
file124.71.152.63
Cobalt Strike botnet C2 server (confidence level: 100%)
file95.70.159.193
Hook botnet C2 server (confidence level: 100%)
file43.207.219.203
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file103.6.234.240
MooBot botnet C2 server (confidence level: 100%)
file46.175.167.116
Remcos botnet C2 server (confidence level: 100%)
file124.235.147.90
Unknown malware botnet C2 server (confidence level: 50%)
file47.243.233.19
Sliver botnet C2 server (confidence level: 50%)
file149.28.24.161
Sliver botnet C2 server (confidence level: 50%)
file64.94.84.192
Sliver botnet C2 server (confidence level: 50%)
file188.64.43.149
Sliver botnet C2 server (confidence level: 50%)
file154.216.19.144
Quasar RAT botnet C2 server (confidence level: 100%)
file47.92.150.134
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.98.39.242
Cobalt Strike botnet C2 server (confidence level: 100%)
file83.229.127.74
Cobalt Strike botnet C2 server (confidence level: 100%)
file76.74.127.192
Sliver botnet C2 server (confidence level: 100%)
file80.76.51.66
AsyncRAT botnet C2 server (confidence level: 100%)
file102.117.167.229
Unknown malware botnet C2 server (confidence level: 100%)
file89.23.99.112
Quasar RAT botnet C2 server (confidence level: 100%)
file3.88.194.54
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file3.39.223.58
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file76.71.30.145
Unknown malware botnet C2 server (confidence level: 100%)
file2.59.135.26
Unknown malware botnet C2 server (confidence level: 100%)
file89.38.225.185
BianLian botnet C2 server (confidence level: 100%)
file80.153.47.168
Unknown malware botnet C2 server (confidence level: 50%)
file106.12.116.136
Cobalt Strike botnet C2 server (confidence level: 50%)
file104.248.249.135
Sliver botnet C2 server (confidence level: 50%)
file121.36.222.101
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.19.190.184
Meterpreter botnet C2 server (confidence level: 100%)
file141.98.9.202
AMOS botnet C2 server (confidence level: 100%)
file94.156.227.116
Coper botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash7000
XWorm botnet C2 server (confidence level: 50%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash8082
Hook botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash8090
DCRat botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash333
Revenge RAT botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash10443
Remcos botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash7346
Remcos botnet C2 server (confidence level: 75%)
hash8891
Cobalt Strike botnet C2 server (confidence level: 50%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash1234
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8880
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash55513
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash81
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8880
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash45314
Remcos botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash5050
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash36218
Quasar RAT botnet C2 server (confidence level: 100%)
hash19132
Quasar RAT botnet C2 server (confidence level: 100%)
hash6443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash6443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash443
Ghost RAT botnet C2 server (confidence level: 50%)
hash80
Ghost RAT botnet C2 server (confidence level: 50%)
hash80
Hook botnet C2 server (confidence level: 50%)
hash65489
Bashlite botnet C2 server (confidence level: 75%)
hash2087
Unknown malware botnet C2 server (confidence level: 50%)
hash1926
Unknown malware botnet C2 server (confidence level: 50%)
hash31337
Unknown malware botnet C2 server (confidence level: 50%)
hash5006
Unknown malware botnet C2 server (confidence level: 50%)
hash4433
Unknown malware botnet C2 server (confidence level: 50%)
hash10443
Unknown malware botnet C2 server (confidence level: 50%)
hash9443
Unknown malware botnet C2 server (confidence level: 50%)
hash9002
Unknown malware botnet C2 server (confidence level: 50%)
hash16993
Unknown malware botnet C2 server (confidence level: 50%)
hash3001
Unknown malware botnet C2 server (confidence level: 50%)
hash2083
Unknown malware botnet C2 server (confidence level: 50%)
hash10250
Unknown malware botnet C2 server (confidence level: 50%)
hash8880
Unknown malware botnet C2 server (confidence level: 50%)
hash8443
Unknown malware botnet C2 server (confidence level: 50%)
hash3780
Unknown malware botnet C2 server (confidence level: 50%)
hash443
Unknown malware botnet C2 server (confidence level: 50%)
hash7548
Unknown malware botnet C2 server (confidence level: 50%)
hash4443
Unknown malware botnet C2 server (confidence level: 50%)
hash9898
Unknown malware botnet C2 server (confidence level: 50%)
hash443
Unknown malware botnet C2 server (confidence level: 50%)
hash8089
Unknown malware botnet C2 server (confidence level: 50%)
hash8889
Unknown malware botnet C2 server (confidence level: 50%)
hash55443
Unknown malware botnet C2 server (confidence level: 50%)
hash311
Unknown malware botnet C2 server (confidence level: 50%)
hash444
Unknown malware botnet C2 server (confidence level: 50%)
hash8009
Unknown malware botnet C2 server (confidence level: 50%)
hash4444
Unknown malware botnet C2 server (confidence level: 50%)
hash9000
Unknown malware botnet C2 server (confidence level: 50%)
hash1337
Unknown malware botnet C2 server (confidence level: 50%)
hash10000
Unknown malware botnet C2 server (confidence level: 50%)
hash5001
Unknown malware botnet C2 server (confidence level: 50%)
hash9091
Unknown malware botnet C2 server (confidence level: 50%)
hash7071
Unknown malware botnet C2 server (confidence level: 50%)
hash443
Unknown malware botnet C2 server (confidence level: 50%)
hash8140
Unknown malware botnet C2 server (confidence level: 50%)
hash7443
Unknown malware botnet C2 server (confidence level: 50%)
hash3333
Unknown malware botnet C2 server (confidence level: 50%)
hash8083
Unknown malware botnet C2 server (confidence level: 50%)
hash6443
Unknown malware botnet C2 server (confidence level: 50%)
hash8081
Unknown malware botnet C2 server (confidence level: 50%)
hash47990
Unknown malware botnet C2 server (confidence level: 50%)
hash5986
Unknown malware botnet C2 server (confidence level: 50%)
hash8181
Unknown malware botnet C2 server (confidence level: 50%)
hash9001
Unknown malware botnet C2 server (confidence level: 50%)
hash55553
Unknown malware botnet C2 server (confidence level: 50%)
hash2376
Unknown malware botnet C2 server (confidence level: 50%)
hash9943
Unknown malware botnet C2 server (confidence level: 50%)
hash9095
Unknown malware botnet C2 server (confidence level: 50%)
hash3790
Unknown malware botnet C2 server (confidence level: 50%)
hash7001
Unknown malware botnet C2 server (confidence level: 50%)
hash8834
Unknown malware botnet C2 server (confidence level: 50%)
hash1337
Unknown malware botnet C2 server (confidence level: 50%)
hash3333
Unknown malware botnet C2 server (confidence level: 50%)
hash56622
Unknown malware botnet C2 server (confidence level: 50%)
hash56722
Unknown malware botnet C2 server (confidence level: 50%)
hash8139
Unknown malware botnet C2 server (confidence level: 50%)
hash3333
Unknown malware botnet C2 server (confidence level: 50%)
hash3333
Unknown malware botnet C2 server (confidence level: 50%)
hash3333
Unknown malware botnet C2 server (confidence level: 50%)
hash443
Unknown malware botnet C2 server (confidence level: 50%)
hash3333
Unknown malware botnet C2 server (confidence level: 50%)
hash3333
Unknown malware botnet C2 server (confidence level: 50%)
hash8085
Unknown malware botnet C2 server (confidence level: 50%)
hash4434
Unknown malware botnet C2 server (confidence level: 50%)
hash3333
Unknown malware botnet C2 server (confidence level: 50%)
hash60732
NjRAT botnet C2 server (confidence level: 75%)
hash6661
ValleyRAT botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash21
Agent Tesla botnet C2 server (confidence level: 100%)
hash4433
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8899
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash58603
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash444
Remcos botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash7000
Quasar RAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash6666
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash4443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash831
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash1337
Unknown malware botnet C2 server (confidence level: 100%)
hash443
BianLian botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash1111
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4436
Meterpreter botnet C2 server (confidence level: 100%)
hash80
AMOS botnet C2 server (confidence level: 100%)
hash443
Coper botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttp://mubuzb3vvv.top/1.php
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://canseverlerinmutlulukhikayeleri.xyz/nwnlnzmzn2y4nmi2/
Coper botnet C2 (confidence level: 100%)
urlhttps://gazozsarap1d.com/mwqxmmuxnmeyymu4/
Coper botnet C2 (confidence level: 100%)
urlhttp://31.177.109.24/wplongpoll/voiddbimage8/mariadb0auth3/javascriptprocessor/asyncimage/packet/protontolocal/low0lowsql/9public8/vmrequestgeogeneratorwplocal.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://reflectsurmise.cfd/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://185.219.81.132/40b6c4848ca5e8ed/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://185.219.81.132/40b6c4848ca5e8ed/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://185.219.81.132/40b6c4848ca5e8ed/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://95.215.204.123/6da61cc9df0e0899/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://185.219.81.135/de4fe4f133a5af6f/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://185.219.81.135/de4fe4f133a5af6f/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://85.28.47.70/c10a74a0c2f42c12/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://185.172.128.151/8420e83ceb95f3af/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://5.42.66.25/287dbd4538093b9e/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://91.211.250.231/b0fce2118167e296/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://185.237.165.47/9b5e67be63d48ab6/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://185.237.165.47/9b5e67be63d48ab6/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://185.237.165.47/9b5e67be63d48ab6/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://91.107.196.27/88e91184e089da83/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://46.8.238.240/11f084e893b710ed/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://185.250.207.28/5e97a37cac206894/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://147.45.47.72/9f244f7bc6ab2605/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://147.45.47.59/04e11569f3f575cf/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://91.211.250.231/b0fce2118167e296/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://162.248.227.2/de64a059f7fa0776/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://162.248.227.2/de64a059f7fa0776/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://185.216.71.4/01210a7d1761b27e/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://185.216.71.4/01210a7d1761b27e/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://77.83.175.91/18e58bd9b3a5293b/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://77.83.175.91/18e58bd9b3a5293b/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://178.63.215.77/a43eb2d9880da9a6/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://95.217.125.57/557b2ce3c387a13c/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://87.120.115.7/
Hook botnet C2 (confidence level: 50%)
urlhttp://45.204.218.173/
Hook botnet C2 (confidence level: 50%)
urlhttp://91.107.146.68/
Hook botnet C2 (confidence level: 50%)
urlhttps://webhook.my/hi.txt
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://webhook.my/words.txt
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://quils.shop/
Vidar botnet C2 (confidence level: 100%)
urlhttp://cyber.pmd-offc.info/791918/pn/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://efes-mindef-gov-pk.dowmload.org/personaldataform/85678990/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://efes-mindef-gov-pk.dowmload.org/personaldataform/85678990/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://heatwave.paknavy.store/pn/510426/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://investigation04.session-out.com/fbd901_harassment/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://kenaikan.portdedjibouti.live/notice_483075/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mod-gov-bd.dowmload.co/127888/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-np.dirctt88.co/41882813/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-np.dirctt888.info/99839932/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-pk.dowmload.info/869469_apt/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-pk.dowmload.info/869469_apt/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-pk.download.info/869469_apt/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moitt-gov-pk.dytt88.co/3b7a9398/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moittadvisory.pmd-offc.info/moitt/755092/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mora.pdfadobe.com/d8149d32/mora/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://notice.portdedjibouti.live/portmaster/64addde1/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://notice.portdedjibouti.live/portmaster/772f2e19/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://office.document-viewer.info/97051770/customs/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://paknavy-gov-pk.dirctt888.info/757293-advisory/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://passagensv.sslblindado.com/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://reports.dgps-govtpk.com/63645534-case/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://salary-cutting.session-out.com/37656199_notice/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://salary-cuxxing.session-out.com/37656199_notice/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://sgad-punjab-gov-pk.dirctt888.info/95a7d2b5-instructions/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://sgad-punjab-gov-pk.dirctt888.info/95a7d2b5-instructions/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://stae-org-mz.document-viewer.live/65739039-voter-verified/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://stae-org-mz.document-viewer.live/73126439-voter-verified/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://stae-org-mz.document-viewer.live/75789039-voter-verified/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://update.ms-office.app/997511_plugin/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://www-airport-lk.mail-gov.org/8e8f2a7a/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://www-army-mil-bd.dirctt88.co/65048925/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://213.183.55.52/moitt/755092/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://chinghsiang.com/proti/gmbsll75a44d611l/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://cyber.pmd-offc.info/791918/pn/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://efes-mindef-gov-pk.dowmload.org/personaldataform/85678990/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://efes-mindef-gov-pk.dowmload.org/personaldataform/85678990/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://efes-mindef-qov-pk.dowmload.org/personaldataform/85678990/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://floridaprotiles.com/fauna/clmfnc73e06g273a/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://investigation04.session-out.com/fbd901_harassment/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://kenaikan.portdedjibouti.live/notice_483075/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://marthayfabrizio.com/fibra/03727640983/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://mod-gov-bd.dowmload.co/127888/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://mofa-gov-np.dirctt88.co/41882813/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://mofa-gov-np.dirctt888.info/99839932/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://mofa-gov-pk.dowmload.info/869469_apt/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://mofa-gov-pk.dowmload.info/869469_apt/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://mofa-gov-pk.download.info/869469_apt/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://moitt-gov-pk.dytt88.co/3b7a9398/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://moittadvisory.pmd-offc.info/moitt/755092/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://myriamherman.com/whooma/01035710928/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://notice.portdedjibouti.live/portmaster/64addde1/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://office.document-viewer.info/97051770/customs/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://paknavy-gov-pk.dirctt888.info/757293-advisory/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://passagensv.sslblindado.com/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://reports.dgps-govtpk.com/63645534-case/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://salary-cutting.session-out.com/37656199_notice/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://salary-cuxxing.session-out.com/37656199_notice/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://sgad-punjab-gov-pk.dirctt888.info/95a7d2b5-instructions/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://sgad-punjab-gov-pk.dirctt888.info/95a7d2b5-instructions/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://stae-org-mz.document-viewer.live/65739039-voter-verified/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://stae-org-mz.document-viewer.live/73126439-voter-verified/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://stae-org-mz.document-viewer.live/75789039-voter-verified/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://update.ms-office.app/997511_plugin/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://www-airport-lk.mail-gov.org/8e8f2a7a/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://www-army-mil-bd.dirctt88.co/65048925/doc.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://defence-lk.military-bd.org/medicalgrantform/11d601c6/profile.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://defence-lk.military-bd.org/medicalgrantform/11d601c6/profile.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://www-mof-gov-np.mail-govt.com/ccc14f983948/profile.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://defence-lk.military-bd.org/medicalgrantform/11d601c6/profile.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://defence-lk.military-bd.org/medicalgrantform/11d601c6/profile.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttps://www-mof-gov-np.mail-govt.com/ccc14f983948/profile.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://bangladeshmarineacademylibrary.ppinewsagency.live/5083/1/3417/2/0/0/0/m/files-76793138/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://bdmil.alit.live/3398/1/50073/2/0/0/0/m/files-ac995f17/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://bdmil.alit.live/3398/1/54346/2/0/0/0/m/files-491dc489/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://behr.ppinewsagency.live/5098/1/1069/2/0/0/0/m/files-3607001e/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://behr.ppinewsagency.live/5098/1/1069/2/0/0/m/files-3607001e/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://behr.ppinewsagency.live/5098/1/1084/2/0/0/0/m/files-bd31fa80/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://cabinet-division-pk.fia-gov.com/eidholiday/351972/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://cabinet-gov-pk.ministry-pk.net/14300/1/1273/2/0/0/0/m/files-68ebf815/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://careitservices.paknvay-pk.net/5359/1/4586/2/0/0/0/m/files-266ad911/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://cmm.int-secure.org/2557/1/51442/2/0/0/0/files-0a14cf32/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://cnmm.int-secure.org/2557/1/51442/2/0/0/0/files-0a14cf32/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://commerce-gov-pk.directt888.com/kpis_fd0531ab/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://commerce-gov-pk.directt888.com/kpis_fd3531ab/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://commerce-gov-pk.directt888.com/kpis_fd3531ab/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://commerce-gov-pk.directt888.com/kpis_fd3931ab/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://cstc-spares-vip-163.dowmload.net/14668/1/1228/2/0/0/0/m/files-403a1120/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://dbms.crclab-bahria.org/5397/1/1322/2/0/0/0/m/files-54cc58cd/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://defencelk.cvix.live/3023/1/54082/2/0/0/0/m/files-0c31ed2d/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://dgmp-paknavy.mod-pk.com/14325/1/10/2/0/0/0/m/files-5291bef6/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://dgms.paknavy-gov.com/5733/1/5051/2/0/0/0/m/files-73bdca4d/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://dgpr.paknvay-pk.net/5330/1/1330/2/0/0/0/m/files-4d9d0395/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://forecast.comsats-net.com/5760/1/5034/2/0/0/0/m/files-e9745687/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://forecast.comsats-net.com/5760/1/5035/2/0/0/0/m/files-4a0480ae/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://forecast.comsats-net.com/5760/1/5036/2/0/0/0/m/files-2ad09cbd/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://forecast.comsats-net.com/5760/1/5037/2/0/0/0/m/files-3a06489f/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://forecast.comsats-net.com/5760/1/5038/2/0/0/0/m/files-4623b4d2/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://forecast.comsats-net.com/5760/1/5039/2/0/0/0/m/files-d7c7dda1/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://forecast.comsats-net.com/5760/1/5040/2/0/0/0/m/files-f3b20b30/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://forecast.comsats-net.com/5760/1/5041/2/0/0/0/m/files-dd96433f/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://invitation-letter.govpk.info/invitation_447093/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://karachishipyard.krlwin.org/14231/1/3025/2/0/0/0/m/files-5ad64a22/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://ksew.kpt-gov.org/5663/1/3275/2/0/0/0/m/files-937950ad/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://ksew.org/5471/1/1101/2/0/0/0/m/files-cd6e6dbd/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mail-dmp-navy-pk.dytt88.org/14459/1/23/2/0/0/0/m/files-14333226/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mailaplf.cvix.live/2968/1/50390/2/0/0/0/m/files-7630e91a/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mailarmylk.mods.email/ltr86-1aadeec4/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mailarmylk.mods.email/ltr86-1aadeec4/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mailarmylk.mods.email/ltr86-laadeec4/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mailmfa.mofa-gov.info/letterhead-55228949/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mailmofagovmm.mofa.email/hybridwarfare-866394/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mailnavybd.govpk.net/5845/1/12/2/0/0/0/m/files-ca78574e/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mailnavymilbd.govpk.net/5848/1/13/2/0/0/0/m/files-57d837e4/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mailoutlookcom.cvix.live/2912/1/53734/2/0/0/0/m/files-74a3adce/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mailrta.mfagov.org/3818/1/53382/2/0/0/0/m/files-c78a6966/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://maritimepakistan.kpt-pk.net/5434/1/&3694/2/0/0/0/m/files-ce32ed85/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://maritimepakistan.kpt-pk.net/5434/1/3694/2/0/0/0/m/files-ce32ed85/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://ministryofforeignaffairs-mofa-gov-pk.dytt88.org/14444/1/2454/2/0/0/0/m/files-9ba90b7f/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moemaldives.pmd-office.com/aa2076dc/circular/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-np.fia-gob.net/notice/74b78aee/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-np.fia-gov.net/notice/74b78aee/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-pk.directt888.com/82890988/protocolhandbook/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-pk.donwloaded.com/40493692/updatedlist/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-pk.donwloaded.com/40493692/updatedlist/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-pk.donwloaded.com/cg/016424/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-pk.donwloaded.com/cg/016424/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-pk.donwloaded.com/negativerepoting/b8dfd8db/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-pk.donwloaded.com/negativerepoting/b8dfd8db/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov-sa.direct888.net/680225_consulategz/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa-gov.interior-pk.org/14419/1/6/2/0/0/0/m/files-07b01f9b/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofa.iugur.live/2623/1/45326/2/0/0/0/files-5d797627/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofabn.ksewpk.com/5511/1/4993/2/0/0/0/m/files-18e5db65/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mofadividion.ptcl-gov.com/5724/1/3268/2/0/0/0/m/files-11e30891/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mohgovsg.bahariafoundation.live/5320/1/13/2/0/0/0/m/files-1ddf5195/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moitt-gov-pk.fia-gov.net/364896null/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moitt-gov-pk.fia-gov.net/659949null/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moitt.paknavy-govpk.info/22259257-moitt/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moma.comsats-net.com:443/5753/1/4371/2/0/0/0/m/files-b62d382f/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moma.comsats-net.com:443/5753/1/4373/2/0/0/0/m/files-6eee3f68/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moma.comsats-net.com/5753/1/4367/2/0/0/0/m/files-0b066736/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moma.comsats-net.com/5753/1/4368/2/0/0/0/m/files-e5f0d8da/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moma.comsats-net.com/5753/1/4369/2/0/0/0/m/files-4afe6b27/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moma.comsats-net.com/5753/1/4370/2/0/0/0/m/files-e05c563f/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moma.comsats-net.com/5753/1/4371/2/0/0/0/m/files-b62d382f/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moma.comsats-net.com/5753/1/4372/2/0/0/0/m/files-d2e0a1dc/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moma.comsats-net.com/5753/1/4373/2/0/0/0/m/files-6eee3f68/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moma.comsats-net.com/5753/1/4374/2/0/0/0/m/files-2fe05aad/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moma.comsats-net.com/5753/1/4375/2/0/0/0/m/files-8062311a/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://moma.comsats-net.com/5753/1/4376/2/0/0/0/m/files-f85db74c/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://msacn.ntcpk.net/6825/report/7176/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://mtss.bol-south.org/5974/1/8682/2/0/0/0/m/files-b2dff0ca/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://navy-lk.direct888.net/report/29476965/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://navy-mil-bd.jmicc.xyz/5625/1/8145/2/0/0/0/m/files-b11074b7/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://nima.ppra.live/5133/1/3272/2/0/0/0/m/files-41b31573/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://opmcm-gov-np.fia-gov.net/37841677/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://opmcm-gov-np.fia-gov.net/37841677null/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://paknavy-gov-pk.downld.net/14578/1/6277/2/0/0/0/m/files-75dc2b1e/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://paknavy-gov-pkp.downld.net/14578/1/6277/2/0/0/0/m/files-75dc2b1e/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://paknavy.comsats.xyz/5552/1/5037/2/0/0/0/m/files-1b5c7556/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://paknavy.defpak.org/5973/1/8665/2/0/0/0/m/files-f8fd19ec/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://paknavy.edu-cx.org/2862/1/35022/2/0/0/0/m/files-5c23f212/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://paknavy.jmicc.xyz/5627/1/4367/2/0/0/0/m/files-9e0912cc/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://president-gov-ik.donwloaded.net/a4884a53/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://president-gov-lk.donwloaded.net/a4884a53/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://president-gov-lk.donwloaded.net/a4884a53/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://promotionlist.comsats-net.com:443/5756/1/8887/2/0/0/0/m/files-3d1dff0f/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://promotionlist.comsats-net.com/5756/1/8887/2/0/0/0/m/files-3d1dff0f/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://sarabanmithnavvtni-mil.com/importanmail/78571/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://sarabanmithnavy.tni-mil.com/importanmail/785871/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://sl-navy.office-drive.live/45/1/334/2/0/0/0/m/files-fe9dade2/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://sl-navy.officedrive.live/45/1/334/2/0/0/0/m/filesfe9dade2/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5769/2/0/0/0/m/files-2f6b9c9a/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5770/2/0/0/0/m/files-2d21c32e/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5771/2/0/0/0/m/files-5995311a/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5772/2/0/0/0/m/files-84c4942a/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5773/2/0/0/0/m/files-5a31d681/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5774/2/0/0/0/m/files-12eca223/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5775/2/0/0/0/m/files-fca3cc50/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5776/2/0/0/0/m/files-175c56e7/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5777/2/0/0/0/m/files-7f2e758b/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5778/2/0/0/0/m/files-27d5c7d3/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5779/2/0/0/0/m/files-2f2e186d/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5780/2/0/0/0/m/files-20bba5af/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5781/2/0/0/0/m/files-62caea91/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5782/2/0/0/0/m/files-78d7e141/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5783/2/0/0/0/m/files-a26663eb/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5784/2/0/0/0/m/files-94153639/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5785/2/0/0/0/m/files-76f11745/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5786/2/0/0/0/m/files-5def1d52/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5787/2/0/0/0/m/files-fb528413/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5788/2/0/0/0/m/files-3acec3be/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5789/2/0/0/0/m/files-8822f8ff/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5790/2/0/0/0/m/files-a3d0041a/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5791/2/0/0/0/m/files-bda6f896/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5792/2/0/0/0/m/files-da7756e4/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5793/2/0/0/0/m/files-f2d0617e/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5794/2/0/0/0/m/files-60cb1621/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5795/2/0/0/0/m/files-c9dddc54/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5796/2/0/0/0/m/files-97e02960/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5797/2/0/0/0/m/files-875e140b/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5798/2/0/0/0/m/files-c3178f3d/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5799/2/0/0/0/m/files-03dd18bd/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://slpa.mod-gov.org/5946/1/5804/2/0/0/0/m/files-c43dece3/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://sppc.moma-pk.org/5281/1/2302/2/0/0/0/m/files-01fd94b4/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://sppc.moma-pk.org/5281/1/4265/2/0/0/0/m/files-d2608a99/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://paknavy.paknavy.live/5516/1/4367/2/0/0/0/m/files-db71f6b3/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://pmd.paknavy-gov.com:443/5751/1/8533/2/0/0/0/m/files-c6e52942/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://pmd.paknavy-gov.com/5751/1/8529/2/0/0/0/m/files-f8ba0c1e/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://pmd.paknavy-gov.com/5751/1/8530/2/0/0/0/m/files-87e4d5b5/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://pmd.paknavy-gov.com/5751/1/8531/2/0/0/0/m/files-bc3cf7c3/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://pmd.paknavy-gov.com/5751/1/8532/2/0/0/0/m/files-d18c58ac/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://pmd.paknavy-gov.com/5751/1/8533/2/0/0/0/m/files-c6e52942/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://pnwc.bahariafoundation.live/5239/1/4004/2/0/0/0/m/files-f36a387a/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://pnwc.bahriafoundation.live/5610/1/2776/2/0/0/0/m/files-9747049b/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://pnwc.bahriafoundation.live/5610/1/4203/2/0/0/0/m/files-2fc0caf2/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://training.detru.info/cyberdiplomacytraining_993638/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://ww25.mail-dmp-navy-pk.dytt88.org/14459/1/23/2/0/0/0/m/files-14333226/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://ww25.ministryofforeignaffairs-mofa-gov-pk.dytt88.org/14444/1/2454/2/0/0/0/m/files-9ba90b7f/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://www-moha-gov-lk.direct888.net/article237/34b922ab/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://www-moha-gov-lk.direct888.net/article237/34b922ab/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://www-opmcm-gov-np.direct888.net/552565_26thmangsir2080/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://paknavy-gov-pk.downld.net/14578/1/6277/2/0/0/0/m/files-75dc2b1e/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://pnwc.bol-north.com/5808/1/3686/2/0/0/0/m/files-a2e589d2/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://pqa.gov.pakmarines.com/4958/1/2657/2/0/0/0/files-f8032b2c/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://srilanka-navy.lforvk.com/135/1/334/2/0/0/0/m/files-4fdaf6c7/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://srilankanavy.ksew.org/5471/1/1101/2/0/0/0/m/files-cd6e6dbd/file.rtf
SideWinder botnet C2 (confidence level: 75%)
urlhttp://advisories-sgcustoms.d0cumentview.info/notifications_430507/document.rtf
SideWinder botnet C2 (confidence level: 100%)
urlhttp://notifications-khmod.d0cumentview.info/circular-d9e305/document.rtf
SideWinder botnet C2 (confidence level: 100%)
urlhttps://xaides.com/5yu7.js
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://xaides.com/js.php
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttp://91.107.126.63/
Hook botnet C2 (confidence level: 50%)
urlhttp://23.94.153.130/
Hook botnet C2 (confidence level: 50%)
urlhttp://3.91.190.163/
Hook botnet C2 (confidence level: 50%)
urlhttps://185.215.113.202/zu7junko/login.php
Amadey botnet C2 (confidence level: 50%)
urlhttp://kcehmenjdibnmni.top/ezj9dlfynohtr.php
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://gajaechkfhfghal.top/x4rnfo376ghtr.php
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://gajaechkfhfghal.top/3rst52x0jghtr.php
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://cmacnnkfbhlcncm.top/i1a2ts9zlyhtr.php
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://swingybeattyz.sbs/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttp://phoeni13.beget.tech/19bd75f9.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://cellardesiresso.sbs/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://displayclubby.sbs/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://caliandentistry.com/updater.php
Satacom botnet C2 (confidence level: 100%)
urlhttp://takiqskiqg.temp.swtest.ru/cfdd5789.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://141.98.9.202/joinsystem
AMOS botnet C2 (confidence level: 100%)

Domain

ValueDescriptionCopy
domainimg6.mllcrosoft.com
Havoc botnet C2 domain (confidence level: 100%)
domaingui.microsoft.upgrade1.zip
Havoc botnet C2 domain (confidence level: 100%)
domainreporting.microsoft.upgrade1.zip
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.sumup.live
Hook botnet C2 domain (confidence level: 100%)
domainvm4.deneb.it
Havoc botnet C2 domain (confidence level: 100%)
domainlogin.microsoft-onedrive.trunetkings.xyz.trunetkings.xyz
Unknown malware botnet C2 domain (confidence level: 100%)
domainboth-foundations.gl.at.ply.gg
NjRAT botnet C2 domain (confidence level: 75%)
domainquils.shop
Vidar botnet C2 domain (confidence level: 100%)
domainrodgersluciecassy.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainalondrabowmanjake.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainevents.api.mllcrosoft.com
Havoc botnet C2 domain (confidence level: 100%)
domainpaknavy.mofa.live
SideWinder botnet C2 domain (confidence level: 75%)
domainbangladeshmarineacademylibrary.ppinewsagency.live
SideWinder botnet C2 domain (confidence level: 75%)
domainbdmil.alit.live
SideWinder botnet C2 domain (confidence level: 75%)
domainbehr.ppinewsagency.live
SideWinder botnet C2 domain (confidence level: 75%)
domaincabinet-division-pk.fia-gov.com
SideWinder botnet C2 domain (confidence level: 75%)
domaincabinet-gov-pk.ministry-pk.net
SideWinder botnet C2 domain (confidence level: 75%)
domaincareitservices.paknvay-pk.net
SideWinder botnet C2 domain (confidence level: 75%)
domaincmm.int-secure.org
SideWinder botnet C2 domain (confidence level: 75%)
domaincnmm.int-secure.org
SideWinder botnet C2 domain (confidence level: 75%)
domaincommerce-gov-pk.directt888.com
SideWinder botnet C2 domain (confidence level: 75%)
domaincstc-spares-vip-163.dowmload.net
SideWinder botnet C2 domain (confidence level: 75%)
domaincyber.pmd-offc.info
SideWinder botnet C2 domain (confidence level: 75%)
domaindbms.crclab-bahria.org
SideWinder botnet C2 domain (confidence level: 75%)
domaindefence-lk.military-bd.org
SideWinder botnet C2 domain (confidence level: 75%)
domaindefencelk.cvix.live
SideWinder botnet C2 domain (confidence level: 75%)
domaindgmp-paknavy.mod-pk.com
SideWinder botnet C2 domain (confidence level: 75%)
domaindgms.paknavy-gov.com
SideWinder botnet C2 domain (confidence level: 75%)
domaindgpr.paknvay-pk.net
SideWinder botnet C2 domain (confidence level: 75%)
domainefes-mindef-gov-pk.dowmload.org
SideWinder botnet C2 domain (confidence level: 75%)
domainforecast.com
SideWinder botnet C2 domain (confidence level: 75%)
domainheatwave.paknavy.store
SideWinder botnet C2 domain (confidence level: 75%)
domaininvestigation04.session-out.com
SideWinder botnet C2 domain (confidence level: 75%)
domaininvitation-letter.govpk.info
SideWinder botnet C2 domain (confidence level: 75%)
domainkarachishipyard.krlwin.org
SideWinder botnet C2 domain (confidence level: 75%)
domainkenaikan.portdedjibouti.live
SideWinder botnet C2 domain (confidence level: 75%)
domainksew.kpt-gov.org
SideWinder botnet C2 domain (confidence level: 75%)
domainksew.org
SideWinder botnet C2 domain (confidence level: 75%)
domainmail-dmp-navy-pk.dytt88.org
SideWinder botnet C2 domain (confidence level: 75%)
domainmailaplf.cvix.live
SideWinder botnet C2 domain (confidence level: 75%)
domainmailarmylk.mods.email
SideWinder botnet C2 domain (confidence level: 75%)
domainmailmfa.mofa-gov.info
SideWinder botnet C2 domain (confidence level: 75%)
domainmailmofagovmm.mofa.email
SideWinder botnet C2 domain (confidence level: 75%)
domainmailnavybd.govpk.net
SideWinder botnet C2 domain (confidence level: 75%)
domainmailnavymilbd.govpk.net
SideWinder botnet C2 domain (confidence level: 75%)
domainmailoutlookcom.cvix.live
SideWinder botnet C2 domain (confidence level: 75%)
domainmailrta.mfagov.org
SideWinder botnet C2 domain (confidence level: 75%)
domainmaritimepakistan.kpt-pk.net
SideWinder botnet C2 domain (confidence level: 75%)
domainministryofforeignaffairs-mofa-gov-pk.dytt88.org
SideWinder botnet C2 domain (confidence level: 75%)
domainmod-gov-bd.dowmload.co
SideWinder botnet C2 domain (confidence level: 75%)
domainmoemaldives.pmd-office.com
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-np.dirctt88.co
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-np.dirctt888.info
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-np.fia-gob.net
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-np.fia-gov.net
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-pk.directt888.com
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-pk.donwloaded.com
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-pk.dowmload.info
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-pk.download.info
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-sa.direct888.net
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov.interior-pk.org
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa.iugur.live
SideWinder botnet C2 domain (confidence level: 75%)
domainmofabn.ksewpk.com
SideWinder botnet C2 domain (confidence level: 75%)
domainmofadividion.ptcl-gov.com
SideWinder botnet C2 domain (confidence level: 75%)
domainmohgovsg.bahariafoundation.live
SideWinder botnet C2 domain (confidence level: 75%)
domainmoitt-gov-pk.dytt88.co
SideWinder botnet C2 domain (confidence level: 75%)
domainmoitt-gov-pk.fia-gov.net
SideWinder botnet C2 domain (confidence level: 75%)
domainmoitt.paknavy-govpk.info
SideWinder botnet C2 domain (confidence level: 75%)
domainmoittadvisory.pmd-offc.info
SideWinder botnet C2 domain (confidence level: 75%)
domainmoma.com
SideWinder botnet C2 domain (confidence level: 75%)
domainmora.pdfadobe.com
SideWinder botnet C2 domain (confidence level: 75%)
domainmsacn.ntcpk.net
SideWinder botnet C2 domain (confidence level: 75%)
domainmtss.bol-south.org
SideWinder botnet C2 domain (confidence level: 75%)
domainnavy-lk.direct888.net
SideWinder botnet C2 domain (confidence level: 75%)
domainnavy-mil-bd.jmicc.xyz
SideWinder botnet C2 domain (confidence level: 75%)
domainnima.ppra.live
SideWinder botnet C2 domain (confidence level: 75%)
domainnotice.portdedjibouti.live
SideWinder botnet C2 domain (confidence level: 75%)
domainoffice.document-viewer.info
SideWinder botnet C2 domain (confidence level: 75%)
domainopmcm-gov-np.fia-gov.net
SideWinder botnet C2 domain (confidence level: 75%)
domainpaknavy-gov-pk.dirctt888.info
SideWinder botnet C2 domain (confidence level: 75%)
domainpaknavy-gov-pk.downld.net
SideWinder botnet C2 domain (confidence level: 75%)
domainpaknavy-gov-pkp.downld.net
SideWinder botnet C2 domain (confidence level: 75%)
domainpaknavy.com
SideWinder botnet C2 domain (confidence level: 75%)
domainpaknavy.defpak.org
SideWinder botnet C2 domain (confidence level: 75%)
domainpaknavy.edu-cx.org
SideWinder botnet C2 domain (confidence level: 75%)
domainpaknavy.jmicc.xyz
SideWinder botnet C2 domain (confidence level: 75%)
domainpaknavy.paknavy.live
SideWinder botnet C2 domain (confidence level: 75%)
domainpassagensv.sslblindado.com
SideWinder botnet C2 domain (confidence level: 75%)
domainpmd.paknavy-gov.com
SideWinder botnet C2 domain (confidence level: 75%)
domainpnwc.bahariafoundation.live
SideWinder botnet C2 domain (confidence level: 75%)
domainpnwc.bahriafoundation.live
SideWinder botnet C2 domain (confidence level: 75%)
domainpnwc.bol-north.com
SideWinder botnet C2 domain (confidence level: 75%)
domainpqa.gov.pakmarines.com
SideWinder botnet C2 domain (confidence level: 75%)
domainpresident-gov-ik.donwloaded.net
SideWinder botnet C2 domain (confidence level: 75%)
domainpresident-gov-lk.donwloaded.net
SideWinder botnet C2 domain (confidence level: 75%)
domainpromotionlist.com
SideWinder botnet C2 domain (confidence level: 75%)
domainreports.dgps-govtpk.com
SideWinder botnet C2 domain (confidence level: 75%)
domainsalary-cutting.session-out.com
SideWinder botnet C2 domain (confidence level: 75%)
domainsalary-cuxxing.session-out.com
SideWinder botnet C2 domain (confidence level: 75%)
domainsarabanmithnavvtni-mil.com
SideWinder botnet C2 domain (confidence level: 75%)
domainsarabanmithnavy.tni-mil.com
SideWinder botnet C2 domain (confidence level: 75%)
domainsgad-punjab-gov-pk.dirctt888.info
SideWinder botnet C2 domain (confidence level: 75%)
domainsl-navy.office-drive.live
SideWinder botnet C2 domain (confidence level: 75%)
domainsl-navy.officedrive.live
SideWinder botnet C2 domain (confidence level: 75%)
domainslpa.mod-gov.org
SideWinder botnet C2 domain (confidence level: 75%)
domainsppc.moma-pk.org
SideWinder botnet C2 domain (confidence level: 75%)
domainsrilanka-navy.lforvk.com
SideWinder botnet C2 domain (confidence level: 75%)
domainsrilankanavy.ksew.org
SideWinder botnet C2 domain (confidence level: 75%)
domainstae-org-mz.document-viewer.live
SideWinder botnet C2 domain (confidence level: 75%)
domainsuezcanal.portdedjibouti.live
SideWinder botnet C2 domain (confidence level: 75%)
domaintraining.detru.info
SideWinder botnet C2 domain (confidence level: 75%)
domainupdate.ms-office.app
SideWinder botnet C2 domain (confidence level: 75%)
domainww25.mail-dmp-navy-pk.dytt88.org
SideWinder botnet C2 domain (confidence level: 75%)
domainww25.ministryofforeignaffairs-mofa-gov-pk.dytt88.org
SideWinder botnet C2 domain (confidence level: 75%)
domainwww-airport-lk.mail-gov.org
SideWinder botnet C2 domain (confidence level: 75%)
domainwww-army-mil-bd.dirctt88.co
SideWinder botnet C2 domain (confidence level: 75%)
domainwww-mof-gov-np.mail-govt.com
SideWinder botnet C2 domain (confidence level: 75%)
domainwww-moha-gov-lk.direct888.net
SideWinder botnet C2 domain (confidence level: 75%)
domainwww-opmcm-gov-np.direct888.net
SideWinder botnet C2 domain (confidence level: 75%)
domainchinghsiang.com
SideWinder botnet C2 domain (confidence level: 75%)
domaincyber.pmd-offc.info
SideWinder botnet C2 domain (confidence level: 75%)
domaindefence-lk.military-bd.org
SideWinder botnet C2 domain (confidence level: 75%)
domainefes-mindef-gov-pk.dowmload.org
SideWinder botnet C2 domain (confidence level: 75%)
domainefes-mindef-qov-pk.dowmload.org
SideWinder botnet C2 domain (confidence level: 75%)
domainfloridaprotiles.com
SideWinder botnet C2 domain (confidence level: 75%)
domaininvestigation04.session-out.com
SideWinder botnet C2 domain (confidence level: 75%)
domainmarthayfabrizio.com
SideWinder botnet C2 domain (confidence level: 75%)
domainmod-gov-bd.dowmload.co
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-np.dirctt88.co
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-np.dirctt888.info
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-pk.dowmload.info
SideWinder botnet C2 domain (confidence level: 75%)
domainmofa-gov-pk.download.info
SideWinder botnet C2 domain (confidence level: 75%)
domainmoitt-gov-pk.dytt88.co
SideWinder botnet C2 domain (confidence level: 75%)
domainmoittadvisory.pmd-offc.info
SideWinder botnet C2 domain (confidence level: 75%)
domainmyriamherman.com
SideWinder botnet C2 domain (confidence level: 75%)
domainoffice.document-viewer.info
SideWinder botnet C2 domain (confidence level: 75%)
domainpaknavy-gov-pk.dirctt888.info
SideWinder botnet C2 domain (confidence level: 75%)
domainreports.dgps-govtpk.com
SideWinder botnet C2 domain (confidence level: 75%)
domainsalary-cutting.session-out.com
SideWinder botnet C2 domain (confidence level: 75%)
domainsalary-cuxxing.session-out.com
SideWinder botnet C2 domain (confidence level: 75%)
domainsgad-punjab-gov-pk.dirctt888.info
SideWinder botnet C2 domain (confidence level: 75%)
domainstae-org-mz.document-viewer.live
SideWinder botnet C2 domain (confidence level: 75%)
domainupdate.ms-office.app
SideWinder botnet C2 domain (confidence level: 75%)
domainwww-airport-lk.mail-gov.org
SideWinder botnet C2 domain (confidence level: 75%)
domainwww-army-mil-bd.dirctt88.co
SideWinder botnet C2 domain (confidence level: 75%)
domainwww-mof-gov-np.mail-govt.com
SideWinder botnet C2 domain (confidence level: 75%)
domainxaides.com
FAKEUPDATES payload delivery domain (confidence level: 100%)
domainec2-3-91-190-163.compute-1.amazonaws.com
Hook botnet C2 domain (confidence level: 100%)
domaincool-mclaren.154-216-18-93.plesk.page
Hook botnet C2 domain (confidence level: 100%)
domaingop.mllcrosoft.com
Havoc botnet C2 domain (confidence level: 100%)
domainimg1.upgrade1.zip
Havoc botnet C2 domain (confidence level: 100%)
domainkcehmenjdibnmni.top
Unknown malware botnet C2 domain (confidence level: 100%)
domaininfomsghub.com
Unknown malware payload delivery domain (confidence level: 100%)
domainmyfilebuilders.com
Unknown malware payload delivery domain (confidence level: 100%)
domain212a947ce8a77f478fc25a920d4cf6e0.com
Coper botnet C2 domain (confidence level: 100%)

Threat ID: 682c7dc3e8347ec82d2e41f6

Added to database: 5/20/2025, 1:04:03 PM

Last enriched: 6/19/2025, 4:19:30 PM

Last updated: 8/11/2025, 6:38:08 AM

Views: 11

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats