Skip to main content

ThreatFox IOCs for 2025-01-25

Medium
Published: Sat Jan 25 2025 (01/25/2025, 00:00:00 UTC)
Source: ThreatFox
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-01-25

AI-Powered Analysis

AILast updated: 06/19/2025, 15:49:02 UTC

Technical Analysis

The provided threat intelligence report from ThreatFox dated 2025-01-25 details Indicators of Compromise (IOCs) related to a malware threat categorized under 'type:osint'. The report lacks specific affected versions, CWE identifiers, or patch information, and no known exploits in the wild have been reported. The threat level is indicated as 2 on an unspecified scale, with analysis and distribution scores of 1 and 3 respectively, suggesting moderate distribution but limited detailed analysis. The malware is associated with OSINT (Open Source Intelligence) tools or techniques, implying it may be used for reconnaissance or information gathering rather than direct destructive payloads. The absence of detailed technical indicators or attack vectors limits the ability to fully characterize the malware's behavior, infection vectors, or persistence mechanisms. The TLP (Traffic Light Protocol) classification is white, indicating the information is intended for public sharing without restrictions. Overall, this threat appears to be a medium-severity malware primarily focused on OSINT-related activities, with moderate distribution but no current evidence of active exploitation or widespread impact.

Potential Impact

For European organizations, the primary impact of this malware threat lies in potential unauthorized collection and exfiltration of sensitive information through OSINT techniques. This could lead to confidentiality breaches, especially if the malware is used to gather intelligence on corporate assets, intellectual property, or personal data. While the malware does not appear to cause direct disruption to system availability or integrity, the compromise of sensitive data can have downstream effects including reputational damage, regulatory penalties under GDPR, and strategic disadvantages. Given the moderate distribution score, there is a possibility of targeted or opportunistic infections, particularly in sectors where OSINT data is valuable such as finance, defense, and critical infrastructure. The lack of known exploits in the wild suggests the threat is currently more of a latent risk rather than an active widespread campaign, but vigilance is warranted to detect any escalation.

Mitigation Recommendations

1. Enhance network monitoring to detect unusual outbound traffic patterns indicative of data exfiltration, particularly focusing on OSINT-related data flows. 2. Implement strict access controls and data segmentation to limit the exposure of sensitive information that could be targeted by reconnaissance malware. 3. Employ advanced endpoint detection and response (EDR) solutions capable of identifying suspicious OSINT tool behaviors or malware signatures, even in the absence of known IOCs. 4. Conduct regular threat hunting exercises focusing on OSINT-related malware tactics and techniques, leveraging threat intelligence feeds including ThreatFox updates. 5. Train security teams and relevant staff on recognizing OSINT malware indicators and the importance of safeguarding open-source data that could be exploited. 6. Maintain up-to-date asset inventories and ensure all software and OSINT tools are patched and configured securely to reduce attack surface. 7. Collaborate with industry information sharing groups to stay informed about emerging OSINT malware threats and mitigation strategies.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
055da0eb-b7cc-47d5-9cec-74fd05311b6c
Original Timestamp
1737849788

Indicators of Compromise

Domain

ValueDescriptionCopy
domaincountefireman.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainemptytoyreor.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainhookmowerz.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainoweshaggyerbe.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainstrattchboster.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainoj42315j346ng2134.myvnc.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmail.mindfulinvoice.online
Unknown RAT botnet C2 domain (confidence level: 100%)
domainadviseur-oakk.nl
Havoc botnet C2 domain (confidence level: 100%)
domainads.it-sharepoint.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainstatic.it-sharepoint.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainautodiscover.fithiphealthy.com
Havoc botnet C2 domain (confidence level: 100%)
domainviraluxstore.com
Bashlite botnet C2 domain (confidence level: 100%)
domainwy.gyhx.xyz
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainl3mon.dailycheapdeals.com
Unknown malware botnet C2 domain (confidence level: 100%)
domaintrumpclaim.org
Unknown malware payload delivery domain (confidence level: 50%)
domainzk-drop.com
Remcos botnet C2 domain (confidence level: 100%)
domainshowviteadobe.com
Remcos botnet C2 domain (confidence level: 100%)
domainsiste-nytt.com
Remcos botnet C2 domain (confidence level: 100%)
domainindianaroadassist.com
Remcos botnet C2 domain (confidence level: 100%)
domainww5.fithiphealthy.com
Havoc botnet C2 domain (confidence level: 100%)
domainnavylk.webmailarmy.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainsolve.xgnv.org
ClearFake payload delivery domain (confidence level: 75%)
domaintemp.opal.wtf
AsyncRAT botnet C2 domain (confidence level: 100%)
domainngoklene.duckdns.org
AsyncRAT botnet C2 domain (confidence level: 100%)
domain3x3.casacam.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domaincoinbasecrashout.ddns.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindiscotek.duckdns.org
AsyncRAT botnet C2 domain (confidence level: 100%)
domainsaleselma.freemyip.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindeadpoolstart2026.duckdns.org
AsyncRAT botnet C2 domain (confidence level: 100%)
domainpctrabajonuevo2.casacam.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainsafe-synopsis.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainc0mer.publicvm.com
XWorm botnet C2 domain (confidence level: 100%)
domaindefined-licenses.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainup-mixed.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainstory-earthquake.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainaccessories-fame.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainlogo-kerry.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainwhy-familiar.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainjamesbond123123-40026.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainwarning-found.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainreference-roll.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainsuccess-evans.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainoil-calculated.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainwindow-prize.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainuk-theory.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainring-cj.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainsuch-five.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domaintake-continually.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domaing-submit.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainwindow-prize.gl.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainchristian-betting.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domaincities-annex.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainwood-matches.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainyou-cigarette.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainrecent-keywords.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainmatch-remedies.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domaincost-hughes.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainlook-omega.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainsanek416-59257.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainmodified-begun.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainrepublic-python.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainso-trek.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainbuilt-among.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainsunday-chronicle.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainaxaxdad.ydns.eu
Remcos botnet C2 domain (confidence level: 100%)
domainmeme.linkpc.net
Remcos botnet C2 domain (confidence level: 100%)
domainrecaptha-verify-5q.pages.dev
ClearFake payload delivery domain (confidence level: 75%)
domainecs-121-36-198-211.compute.hwclouds-dns.com
Havoc botnet C2 domain (confidence level: 100%)
domainsupport.sftech.one
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainclimepunneddus.com
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainflockefaccek.org
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainguardeduppe.com
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainbabberstalek.org
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainclassyhelped.net
Lumma Stealer botnet C2 domain (confidence level: 50%)
domaincarrystuppeder.net
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainrebuildhurrte.com
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainmint-stealer.sh
MintStealer botnet C2 domain (confidence level: 100%)
domaindwnwz6ywujerd.cloudfront.net
Cobalt Strike botnet C2 domain (confidence level: 50%)
domaincutlej02.top
CryptBot botnet C2 domain (confidence level: 50%)
domainthatsofar.top
Mirai botnet C2 domain (confidence level: 50%)
domainhojex31104-23437.portmap.host
Quasar RAT botnet C2 domain (confidence level: 50%)
domainadventurestoptop.top
Lumma Stealer botnet C2 domain (confidence level: 50%)
domaincuproomymis.top
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainweighcobbweo.top
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainkgbhostpro.duckdns.org
NjRAT botnet C2 domain (confidence level: 100%)
domainveronicafola.ddns.net
NjRAT botnet C2 domain (confidence level: 100%)
domainjokernjrat.ddns.net
NjRAT botnet C2 domain (confidence level: 100%)
domainpics-accessory.gl.at.ply.gg
NjRAT botnet C2 domain (confidence level: 100%)
domainspace.richstressop.cloud
MooBot botnet C2 domain (confidence level: 100%)
domainbot.floppaonyou.fr
Mirai botnet C2 domain (confidence level: 75%)
domainfantazy.space
Mirai botnet C2 domain (confidence level: 100%)
domainbotnet.fantazy.space
Mirai botnet C2 domain (confidence level: 100%)
domainlginchimfgfckeb.top
Unknown malware botnet C2 domain (confidence level: 100%)
domainupdates.e-formsonline.com
Havoc botnet C2 domain (confidence level: 100%)
domainns1.nactrace.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainns2.nactrace.com
Cobalt Strike botnet C2 domain (confidence level: 75%)

File

ValueDescriptionCopy
file45.88.186.152
Quasar RAT botnet C2 server (confidence level: 100%)
file190.102.40.205
Quasar RAT botnet C2 server (confidence level: 100%)
file147.45.44.184
Quasar RAT botnet C2 server (confidence level: 100%)
file199.127.63.127
Unknown RAT botnet C2 server (confidence level: 100%)
file154.213.187.4
Bashlite botnet C2 server (confidence level: 75%)
file139.59.3.62
Cobalt Strike botnet C2 server (confidence level: 100%)
file124.156.193.181
Cobalt Strike botnet C2 server (confidence level: 100%)
file104.193.69.138
Sliver botnet C2 server (confidence level: 100%)
file65.38.120.146
Sliver botnet C2 server (confidence level: 100%)
file107.173.101.225
Sliver botnet C2 server (confidence level: 100%)
file69.197.145.69
AsyncRAT botnet C2 server (confidence level: 100%)
file87.120.113.143
AsyncRAT botnet C2 server (confidence level: 100%)
file213.32.110.136
AsyncRAT botnet C2 server (confidence level: 100%)
file186.169.53.160
AsyncRAT botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file66.78.40.166
Havoc botnet C2 server (confidence level: 100%)
file139.64.51.82
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file13.212.169.131
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file39.109.117.51
Cobalt Strike botnet C2 server (confidence level: 75%)
file54.144.139.77
Cobalt Strike botnet C2 server (confidence level: 75%)
file139.9.188.51
Cobalt Strike botnet C2 server (confidence level: 100%)
file84.38.133.193
AsyncRAT botnet C2 server (confidence level: 100%)
file84.247.162.141
AsyncRAT botnet C2 server (confidence level: 100%)
file111.196.130.95
Brute Ratel C4 botnet C2 server (confidence level: 100%)
file45.61.136.85
Unknown malware botnet C2 server (confidence level: 75%)
file45.61.136.52
Unknown malware botnet C2 server (confidence level: 75%)
file195.177.95.66
Stealc botnet C2 server (confidence level: 100%)
file106.52.176.245
Unknown malware botnet C2 server (confidence level: 100%)
file44.220.162.212
Unknown malware botnet C2 server (confidence level: 100%)
file13.239.83.148
Unknown malware botnet C2 server (confidence level: 100%)
file185.22.155.196
Unknown malware botnet C2 server (confidence level: 100%)
file104.155.181.114
Unknown malware botnet C2 server (confidence level: 100%)
file3.230.116.0
Unknown malware botnet C2 server (confidence level: 100%)
file139.59.25.218
Unknown malware botnet C2 server (confidence level: 100%)
file128.199.210.142
Unknown malware botnet C2 server (confidence level: 100%)
file143.198.209.25
Unknown malware botnet C2 server (confidence level: 100%)
file187.72.219.54
Unknown malware botnet C2 server (confidence level: 100%)
file35.85.136.22
Unknown malware botnet C2 server (confidence level: 100%)
file142.171.211.69
Unknown malware botnet C2 server (confidence level: 100%)
file185.105.109.183
Unknown malware botnet C2 server (confidence level: 100%)
file47.94.101.221
Unknown malware botnet C2 server (confidence level: 100%)
file181.32.39.201
Unknown malware botnet C2 server (confidence level: 100%)
file37.27.3.34
Unknown malware botnet C2 server (confidence level: 100%)
file35.157.231.78
Unknown malware botnet C2 server (confidence level: 100%)
file35.157.231.78
Unknown malware botnet C2 server (confidence level: 100%)
file138.199.155.177
Unknown malware botnet C2 server (confidence level: 100%)
file52.203.140.27
Unknown malware botnet C2 server (confidence level: 100%)
file54.206.227.175
Unknown malware botnet C2 server (confidence level: 100%)
file31.192.237.102
Unknown malware botnet C2 server (confidence level: 100%)
file31.192.237.46
Unknown malware botnet C2 server (confidence level: 100%)
file8.134.212.158
Cobalt Strike botnet C2 server (confidence level: 50%)
file94.156.167.138
Cobalt Strike botnet C2 server (confidence level: 50%)
file60.205.227.255
Sliver botnet C2 server (confidence level: 50%)
file85.90.246.69
Unknown malware botnet C2 server (confidence level: 50%)
file94.232.244.62
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file154.61.74.64
Hook botnet C2 server (confidence level: 50%)
file42.117.80.199
XWorm botnet C2 server (confidence level: 100%)
file45.141.27.118
XWorm botnet C2 server (confidence level: 100%)
file85.203.4.227
XWorm botnet C2 server (confidence level: 100%)
file87.120.114.42
XWorm botnet C2 server (confidence level: 100%)
file91.211.250.177
XWorm botnet C2 server (confidence level: 100%)
file102.129.168.25
XWorm botnet C2 server (confidence level: 100%)
file147.45.47.222
XWorm botnet C2 server (confidence level: 100%)
file159.100.20.246
XWorm botnet C2 server (confidence level: 100%)
file185.201.252.121
XWorm botnet C2 server (confidence level: 100%)
file195.10.205.186
XWorm botnet C2 server (confidence level: 100%)
file198.7.115.133
XWorm botnet C2 server (confidence level: 100%)
file207.174.40.240
XWorm botnet C2 server (confidence level: 100%)
file87.120.115.189
Remcos botnet C2 server (confidence level: 100%)
file23.94.139.99
Sliver botnet C2 server (confidence level: 100%)
file44.201.201.174
Sliver botnet C2 server (confidence level: 100%)
file44.201.201.174
Sliver botnet C2 server (confidence level: 100%)
file213.32.110.136
AsyncRAT botnet C2 server (confidence level: 100%)
file182.60.9.165
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file85.31.47.59
AsyncRAT botnet C2 server (confidence level: 100%)
file148.113.165.11
AsyncRAT botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file172.94.14.88
AsyncRAT botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 100%)
file201.27.181.65
Havoc botnet C2 server (confidence level: 100%)
file185.208.156.157
Havoc botnet C2 server (confidence level: 100%)
file196.120.15.148
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file84.154.190.128
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file112.16.250.188
DeimosC2 botnet C2 server (confidence level: 75%)
file147.45.47.167
Brute Ratel C4 botnet C2 server (confidence level: 75%)
file45.137.81.202
DanaBot botnet C2 server (confidence level: 75%)
file64.225.61.173
Sliver botnet C2 server (confidence level: 75%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 50%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 50%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 50%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 50%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 50%)
file124.222.39.154
Cobalt Strike botnet C2 server (confidence level: 100%)
file152.136.159.25
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.204.177.84
Cobalt Strike botnet C2 server (confidence level: 100%)
file182.92.119.172
Cobalt Strike botnet C2 server (confidence level: 100%)
file185.208.159.240
AsyncRAT botnet C2 server (confidence level: 75%)
file185.196.10.170
XWorm botnet C2 server (confidence level: 100%)
file3.125.188.168
NjRAT botnet C2 server (confidence level: 75%)
file3.124.67.191
NjRAT botnet C2 server (confidence level: 75%)
file193.181.23.127
Unknown Stealer botnet C2 server (confidence level: 100%)
file154.216.20.182
AsyncRAT botnet C2 server (confidence level: 100%)
file2.56.109.146
AsyncRAT botnet C2 server (confidence level: 100%)
file20.224.66.176
AsyncRAT botnet C2 server (confidence level: 100%)
file89.84.63.139
AsyncRAT botnet C2 server (confidence level: 100%)
file178.173.246.113
XWorm botnet C2 server (confidence level: 100%)
file95.169.204.123
XWorm botnet C2 server (confidence level: 100%)
file147.185.221.24
XWorm botnet C2 server (confidence level: 100%)
file147.185.221.23
XWorm botnet C2 server (confidence level: 100%)
file194.59.31.87
XWorm botnet C2 server (confidence level: 100%)
file23.27.201.57
XWorm botnet C2 server (confidence level: 100%)
file156.224.26.29
ValleyRAT botnet C2 server (confidence level: 100%)
file119.8.116.145
Cobalt Strike botnet C2 server (confidence level: 100%)
file216.128.146.203
Remcos botnet C2 server (confidence level: 100%)
file13.201.30.7
Havoc botnet C2 server (confidence level: 100%)
file57.129.65.114
Venom RAT botnet C2 server (confidence level: 100%)
file52.89.199.16
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file154.12.25.152
Unknown malware botnet C2 server (confidence level: 100%)
file193.200.78.35
Bashlite botnet C2 server (confidence level: 100%)
file111.230.5.199
Cobalt Strike botnet C2 server (confidence level: 75%)
file170.64.134.129
Cobalt Strike botnet C2 server (confidence level: 75%)
file185.102.172.203
Mirai botnet C2 server (confidence level: 75%)
file104.234.205.134
AsyncRAT botnet C2 server (confidence level: 100%)
file199.204.161.37
AsyncRAT botnet C2 server (confidence level: 100%)
file84.247.162.141
AsyncRAT botnet C2 server (confidence level: 100%)
file45.94.31.215
AsyncRAT botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file185.196.8.68
Hook botnet C2 server (confidence level: 100%)
file156.244.16.227
Havoc botnet C2 server (confidence level: 100%)
file52.197.164.145
Brute Ratel C4 botnet C2 server (confidence level: 100%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 50%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 50%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 50%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 50%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 50%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 50%)
file182.60.5.9
Unknown malware botnet C2 server (confidence level: 50%)
file118.122.8.154
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file197.44.133.250
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file3.34.83.49
Unknown malware botnet C2 server (confidence level: 50%)
file176.110.208.212
NjRAT botnet C2 server (confidence level: 100%)
file87.120.125.56
Mirai botnet C2 server (confidence level: 100%)
file87.120.117.141
Mirai botnet C2 server (confidence level: 100%)
file94.103.125.184
Mirai botnet C2 server (confidence level: 100%)
file94.103.125.184
Mirai botnet C2 server (confidence level: 100%)
file154.62.226.5
Mirai botnet C2 server (confidence level: 100%)
file45.139.104.177
Mirai botnet C2 server (confidence level: 75%)
file193.26.115.238
AsyncRAT botnet C2 server (confidence level: 100%)
file128.90.113.141
AsyncRAT botnet C2 server (confidence level: 100%)
file149.102.147.106
AsyncRAT botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file117.215.247.241
Unknown malware botnet C2 server (confidence level: 100%)
file194.102.104.88
MooBot botnet C2 server (confidence level: 100%)
file188.49.61.79
QakBot botnet C2 server (confidence level: 75%)
file54.38.94.225
Eye Pyramid botnet C2 server (confidence level: 75%)
file54.38.94.225
Eye Pyramid botnet C2 server (confidence level: 75%)
file8.222.163.56
Viper RAT botnet C2 server (confidence level: 75%)
file192.169.69.26
NjRAT botnet C2 server (confidence level: 100%)
file165.232.122.80
Cobalt Strike botnet C2 server (confidence level: 75%)
file18.117.146.34
Meterpreter botnet C2 server (confidence level: 75%)

Hash

ValueDescriptionCopy
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash5552
Quasar RAT botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash8041
Unknown RAT botnet C2 server (confidence level: 100%)
hash2222
Bashlite botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash443
AsyncRAT botnet C2 server (confidence level: 100%)
hash888
AsyncRAT botnet C2 server (confidence level: 100%)
hash2222
AsyncRAT botnet C2 server (confidence level: 100%)
hash11102
AsyncRAT botnet C2 server (confidence level: 100%)
hash8090
Unknown malware botnet C2 server (confidence level: 100%)
hash2079
Unknown malware botnet C2 server (confidence level: 100%)
hash88
Unknown malware botnet C2 server (confidence level: 100%)
hash10042
Unknown malware botnet C2 server (confidence level: 100%)
hash1963
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash29745
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash53
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
AsyncRAT botnet C2 server (confidence level: 100%)
hash8443
Brute Ratel C4 botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 75%)
hash80
Unknown malware botnet C2 server (confidence level: 75%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3334
Unknown malware botnet C2 server (confidence level: 100%)
hash10443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash8081
Unknown malware botnet C2 server (confidence level: 100%)
hash9998
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash8000
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash4443
Unknown malware botnet C2 server (confidence level: 50%)
hash444
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash80
Hook botnet C2 server (confidence level: 50%)
hash1987
XWorm botnet C2 server (confidence level: 100%)
hash7777
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash3991
XWorm botnet C2 server (confidence level: 100%)
hash6382
XWorm botnet C2 server (confidence level: 100%)
hash5555
XWorm botnet C2 server (confidence level: 100%)
hash6699
XWorm botnet C2 server (confidence level: 100%)
hash7772
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash65104
Sliver botnet C2 server (confidence level: 100%)
hash80
Sliver botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash888
AsyncRAT botnet C2 server (confidence level: 100%)
hash18333
Unknown malware botnet C2 server (confidence level: 100%)
hash1201
Unknown malware botnet C2 server (confidence level: 100%)
hash5902
Unknown malware botnet C2 server (confidence level: 100%)
hash1000
Unknown malware botnet C2 server (confidence level: 100%)
hash2612
Unknown malware botnet C2 server (confidence level: 100%)
hash11211
Unknown malware botnet C2 server (confidence level: 100%)
hash18444
Unknown malware botnet C2 server (confidence level: 100%)
hash8848
AsyncRAT botnet C2 server (confidence level: 100%)
hash4040
AsyncRAT botnet C2 server (confidence level: 100%)
hash13434
Unknown malware botnet C2 server (confidence level: 100%)
hash4449
AsyncRAT botnet C2 server (confidence level: 100%)
hash832
Unknown malware botnet C2 server (confidence level: 100%)
hash4567
Unknown malware botnet C2 server (confidence level: 100%)
hash771
Unknown malware botnet C2 server (confidence level: 100%)
hash3277
Unknown malware botnet C2 server (confidence level: 100%)
hash8389
Unknown malware botnet C2 server (confidence level: 100%)
hash8020
Unknown malware botnet C2 server (confidence level: 100%)
hash1912
Unknown malware botnet C2 server (confidence level: 100%)
hash3950
Unknown malware botnet C2 server (confidence level: 100%)
hash8008
Unknown malware botnet C2 server (confidence level: 100%)
hash20000
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash1080
Unknown malware botnet C2 server (confidence level: 100%)
hash2004
Unknown malware botnet C2 server (confidence level: 100%)
hash101
Unknown malware botnet C2 server (confidence level: 100%)
hash789
Unknown malware botnet C2 server (confidence level: 100%)
hash5900
Unknown malware botnet C2 server (confidence level: 100%)
hash8081
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash82
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash4506
DeimosC2 botnet C2 server (confidence level: 75%)
hash24637
Brute Ratel C4 botnet C2 server (confidence level: 75%)
hash443
DanaBot botnet C2 server (confidence level: 75%)
hash9999
Sliver botnet C2 server (confidence level: 75%)
hash3790
Unknown malware botnet C2 server (confidence level: 50%)
hash3780
Unknown malware botnet C2 server (confidence level: 50%)
hash10250
Unknown malware botnet C2 server (confidence level: 50%)
hash4433
Unknown malware botnet C2 server (confidence level: 50%)
hash8140
Unknown malware botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7777
Cobalt Strike botnet C2 server (confidence level: 100%)
hash56001
AsyncRAT botnet C2 server (confidence level: 75%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash19931
NjRAT botnet C2 server (confidence level: 75%)
hash19931
NjRAT botnet C2 server (confidence level: 75%)
hash5555
Unknown Stealer botnet C2 server (confidence level: 100%)
hash8000
AsyncRAT botnet C2 server (confidence level: 100%)
hash4449
AsyncRAT botnet C2 server (confidence level: 100%)
hash4784
AsyncRAT botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash4444
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash35724
XWorm botnet C2 server (confidence level: 100%)
hash36343
XWorm botnet C2 server (confidence level: 100%)
hash1111
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash8888
ValleyRAT botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash8080
Havoc botnet C2 server (confidence level: 100%)
hash4449
Venom RAT botnet C2 server (confidence level: 100%)
hash2004
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Bashlite botnet C2 server (confidence level: 100%)
hash2087
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash5555
Mirai botnet C2 server (confidence level: 75%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash9090
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash1080
Unknown malware botnet C2 server (confidence level: 100%)
hash3276
Unknown malware botnet C2 server (confidence level: 100%)
hash9201
Unknown malware botnet C2 server (confidence level: 100%)
hash103
Unknown malware botnet C2 server (confidence level: 100%)
hash1311
Unknown malware botnet C2 server (confidence level: 100%)
hash4242
Unknown malware botnet C2 server (confidence level: 100%)
hash7987
Unknown malware botnet C2 server (confidence level: 100%)
hash465
Unknown malware botnet C2 server (confidence level: 100%)
hash2080
Unknown malware botnet C2 server (confidence level: 100%)
hash3499
Unknown malware botnet C2 server (confidence level: 100%)
hash18444
Unknown malware botnet C2 server (confidence level: 100%)
hash554
Unknown malware botnet C2 server (confidence level: 100%)
hash3299
Unknown malware botnet C2 server (confidence level: 100%)
hash5671
Unknown malware botnet C2 server (confidence level: 100%)
hash16652
Unknown malware botnet C2 server (confidence level: 100%)
hash1098
Unknown malware botnet C2 server (confidence level: 100%)
hash2077
Unknown malware botnet C2 server (confidence level: 100%)
hash2266
Unknown malware botnet C2 server (confidence level: 100%)
hash2403
Unknown malware botnet C2 server (confidence level: 100%)
hash4841
Unknown malware botnet C2 server (confidence level: 100%)
hash11101
Unknown malware botnet C2 server (confidence level: 100%)
hash1433
Unknown malware botnet C2 server (confidence level: 100%)
hash6008
Unknown malware botnet C2 server (confidence level: 100%)
hash3035
Unknown malware botnet C2 server (confidence level: 100%)
hash4730
Unknown malware botnet C2 server (confidence level: 100%)
hash9200
Unknown malware botnet C2 server (confidence level: 100%)
hash9768
Unknown malware botnet C2 server (confidence level: 100%)
hash102
Unknown malware botnet C2 server (confidence level: 100%)
hash2087
Unknown malware botnet C2 server (confidence level: 100%)
hash2380
Unknown malware botnet C2 server (confidence level: 100%)
hash3049
Unknown malware botnet C2 server (confidence level: 100%)
hash101
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash80
Brute Ratel C4 botnet C2 server (confidence level: 100%)
hash4444
Unknown malware botnet C2 server (confidence level: 50%)
hash8009
Unknown malware botnet C2 server (confidence level: 50%)
hash7443
Unknown malware botnet C2 server (confidence level: 50%)
hash8139
Unknown malware botnet C2 server (confidence level: 50%)
hash3001
Unknown malware botnet C2 server (confidence level: 50%)
hash311
Unknown malware botnet C2 server (confidence level: 50%)
hash10000
Unknown malware botnet C2 server (confidence level: 50%)
hash10042
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash6000
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash80
Unknown malware botnet C2 server (confidence level: 50%)
hash25565
NjRAT botnet C2 server (confidence level: 100%)
hash38241
Mirai botnet C2 server (confidence level: 100%)
hash38241
Mirai botnet C2 server (confidence level: 100%)
hash3778
Mirai botnet C2 server (confidence level: 100%)
hash101
Mirai botnet C2 server (confidence level: 100%)
hash3778
Mirai botnet C2 server (confidence level: 100%)
hash1995
Mirai botnet C2 server (confidence level: 75%)
hash8088
AsyncRAT botnet C2 server (confidence level: 100%)
hash5000
AsyncRAT botnet C2 server (confidence level: 100%)
hash5505
AsyncRAT botnet C2 server (confidence level: 100%)
hash21
Unknown malware botnet C2 server (confidence level: 100%)
hash6324
Unknown malware botnet C2 server (confidence level: 100%)
hash8594
Unknown malware botnet C2 server (confidence level: 100%)
hash17297
Unknown malware botnet C2 server (confidence level: 100%)
hash18577
Unknown malware botnet C2 server (confidence level: 100%)
hash8001
Unknown malware botnet C2 server (confidence level: 100%)
hash17573
Unknown malware botnet C2 server (confidence level: 100%)
hash7474
Unknown malware botnet C2 server (confidence level: 100%)
hash16992
Unknown malware botnet C2 server (confidence level: 100%)
hash5211
Unknown malware botnet C2 server (confidence level: 100%)
hash10470
Unknown malware botnet C2 server (confidence level: 100%)
hash13000
Unknown malware botnet C2 server (confidence level: 100%)
hash771
Unknown malware botnet C2 server (confidence level: 100%)
hash808
Unknown malware botnet C2 server (confidence level: 100%)
hash2628
Unknown malware botnet C2 server (confidence level: 100%)
hash9023
Unknown malware botnet C2 server (confidence level: 100%)
hash9999
Unknown malware botnet C2 server (confidence level: 100%)
hash12824
Unknown malware botnet C2 server (confidence level: 100%)
hash2405
Unknown malware botnet C2 server (confidence level: 100%)
hash7001
Unknown malware botnet C2 server (confidence level: 100%)
hash1963
Unknown malware botnet C2 server (confidence level: 100%)
hash13465
Unknown malware botnet C2 server (confidence level: 100%)
hash19214
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash9142
Unknown malware botnet C2 server (confidence level: 100%)
hash11112
Unknown malware botnet C2 server (confidence level: 100%)
hash6575
Unknown malware botnet C2 server (confidence level: 100%)
hash18080
Unknown malware botnet C2 server (confidence level: 100%)
hash3456
Unknown malware botnet C2 server (confidence level: 100%)
hash7028
Unknown malware botnet C2 server (confidence level: 100%)
hash17291
Unknown malware botnet C2 server (confidence level: 100%)
hash1962
Unknown malware botnet C2 server (confidence level: 100%)
hash2454
Unknown malware botnet C2 server (confidence level: 100%)
hash6006
Unknown malware botnet C2 server (confidence level: 100%)
hash18246
Unknown malware botnet C2 server (confidence level: 100%)
hash1244
Unknown malware botnet C2 server (confidence level: 100%)
hash5080
Unknown malware botnet C2 server (confidence level: 100%)
hash9601
Unknown malware botnet C2 server (confidence level: 100%)
hash10260
Unknown malware botnet C2 server (confidence level: 100%)
hash12113
Unknown malware botnet C2 server (confidence level: 100%)
hash1801
Unknown malware botnet C2 server (confidence level: 100%)
hash1883
Unknown malware botnet C2 server (confidence level: 100%)
hash19500
Unknown malware botnet C2 server (confidence level: 100%)
hash5984
Unknown malware botnet C2 server (confidence level: 100%)
hash19263
Unknown malware botnet C2 server (confidence level: 100%)
hash4444
Unknown malware botnet C2 server (confidence level: 100%)
hash5000
Unknown malware botnet C2 server (confidence level: 100%)
hash8636
Unknown malware botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash8880
Eye Pyramid botnet C2 server (confidence level: 75%)
hash8888
Eye Pyramid botnet C2 server (confidence level: 75%)
hash60000
Viper RAT botnet C2 server (confidence level: 75%)
hash1984
NjRAT botnet C2 server (confidence level: 100%)
hash53
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Meterpreter botnet C2 server (confidence level: 75%)

Url

ValueDescriptionCopy
urlhttps://comtekinc.com/51w3.js
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://comtekinc.com/js.php
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://gacisosh75.xyz/y2vkndy3otixnjc0/
Coper botnet C2 (confidence level: 100%)
urlhttps://116.203.125.44/55f8f885bc7c41c8/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://193.233.134.93/2bbda8fbc3a204ca/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://45.152.113.10/15a25e53742510fe/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://64.95.13.166/c262c2557c712ca5/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://64.95.13.166/c262c2557c712ca5/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://trumpclaim.org/5-58324124/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://trumpclaim.org/file.mp3
Unknown malware payload delivery URL (confidence level: 50%)
urlhttp://175.178.123.40:8888/supershell/login
Unknown malware botnet C2 (confidence level: 50%)
urlhttp://1.94.105.216:8000/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://karaakcan242.xyz/ntfknjvmntmyoddh/
Coper botnet C2 (confidence level: 80%)
urlhttps://barcelonacokhojdur34.com/ntfknjvmntmyoddh/
Coper botnet C2 (confidence level: 80%)
urlhttps://pejo106gtialsana34.com/ntfknjvmntmyoddh/
Coper botnet C2 (confidence level: 80%)
urlhttps://reksonailemutluol434.com/ntfknjvmntmyoddh/
Coper botnet C2 (confidence level: 80%)
urlhttps://cocolaickeyflen34.com/ntfknjvmntmyoddh/
Coper botnet C2 (confidence level: 80%)
urlhttp://154.61.74.64/
Hook botnet C2 (confidence level: 50%)
urlhttps://solve.xgnv.org/awjsx.captcha
ClearFake payload delivery URL (confidence level: 75%)
urlhttps://api.telegram.org/bot7653235193:aaerxt3f2w-qztimivxt1ds_f7pbhdxw3fc/sendmessage
AsyncRAT botnet C2 (confidence level: 100%)
urlhttp://147.45.44.190
Stealc botnet C2 (confidence level: 100%)
urlhttp://cf17360.tw1.ru/l1nc0in.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://climepunneddus.com/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://flockefaccek.org/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://guardeduppe.com/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://babberstalek.org/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://classyhelped.net/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://carrystuppeder.net/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://rebuildhurrte.com/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttp://176.123.1.211/dbdatalifeprivatecdn.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://8.210.146.82:18888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://93.123.39.132/cdb52cf952e86d4b/sqlite3.dll
Stealc botnet C2 (confidence level: 50%)
urlhttp://85.28.47.70/c10a74a0c2f42c12/vcruntime140.dll
Stealc botnet C2 (confidence level: 50%)
urlhttp://139.196.206.41:8080/
Chaos botnet C2 (confidence level: 50%)
urlhttp://faodrt28.top/index.php
CryptBot botnet C2 (confidence level: 50%)
urlhttp://cutlej02.top/download.php?file=wapude.exe
CryptBot payload delivery URL (confidence level: 50%)
urlhttp://pole4udes.ru/externalvideotosecurepacketgeoapiserverwordpressdle.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://lginchimfgfckeb.top/t9s1nq4j3lhtr.php
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://799615cm.nyashnyash.ru/linecpuprocessorlongpollprotectdbdatalifetemptemporary.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://188.120.225.2/apidbdlecdntemporary.php
DCRat botnet C2 (confidence level: 100%)

Threat ID: 682c7dc1e8347ec82d2db12d

Added to database: 5/20/2025, 1:04:01 PM

Last enriched: 6/19/2025, 3:49:02 PM

Last updated: 8/6/2025, 7:15:17 AM

Views: 11

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats