ThreatFox IOCs for 2025-02-13
ThreatFox IOCs for 2025-02-13
AI Analysis
Technical Summary
The provided threat intelligence relates to a malware-related report titled "ThreatFox IOCs for 2025-02-13," sourced from ThreatFox, an OSINT (Open Source Intelligence) platform. The report appears to be a collection or update of Indicators of Compromise (IOCs) relevant to malware activity as of February 13, 2025. However, the technical details are minimal, with no specific affected software versions, no identified Common Weakness Enumerations (CWEs), no patch links, and no known exploits currently observed in the wild. The threat level is indicated as 2 on an unspecified scale, with analysis and distribution scores of 1 and 3 respectively, suggesting limited analysis depth but moderate distribution potential. The absence of concrete technical indicators or detailed malware behavior limits the ability to fully characterize the threat. The tags indicate that this is an OSINT-type threat with a TLP (Traffic Light Protocol) designation of white, meaning the information is publicly shareable without restriction. Overall, this appears to be an early or generic alert about malware-related IOCs collected by ThreatFox, rather than a detailed vulnerability or exploit report.
Potential Impact
Given the lack of detailed technical information and absence of known exploits in the wild, the immediate impact on European organizations is likely limited. However, the distribution score of 3 suggests that the malware or its indicators may be moderately widespread or have potential for broader dissemination. European organizations relying on OSINT feeds for threat detection could benefit from integrating these IOCs to enhance their detection capabilities. Without specific affected products or vulnerabilities, the threat primarily poses a risk of undetected malware infections if these IOCs are not incorporated into security monitoring tools. The confidentiality, integrity, and availability impacts remain uncertain but could range from data exfiltration to system compromise if the malware is deployed successfully. The medium severity rating reflects this uncertainty and the potential for moderate impact if the malware becomes active or widespread.
Mitigation Recommendations
1. Integrate ThreatFox IOCs into existing Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) systems to improve detection of related malware activity. 2. Maintain up-to-date threat intelligence feeds and ensure automated ingestion of OSINT data to promptly identify emerging threats. 3. Conduct regular network and endpoint scans using the latest IOCs to identify potential infections early. 4. Enhance user awareness training focused on recognizing malware infection vectors, especially phishing and social engineering, as no specific exploit vectors are detailed. 5. Implement strict network segmentation and least privilege access controls to limit malware spread if infection occurs. 6. Monitor for unusual outbound network traffic patterns that could indicate data exfiltration or command and control communications. 7. Since no patches or CVEs are associated, focus on detection and response capabilities rather than patch management for this threat. 8. Collaborate with local Computer Security Incident Response Teams (CSIRTs) to share intelligence and coordinate response efforts.
Affected Countries
Germany, France, United Kingdom, Netherlands, Italy, Spain, Poland
Indicators of Compromise
- domain: check.uueye.icu
- url: https://check.uueye.icu/gkcxv.google
- domain: brixghtquest.cyou
- domain: hxappycove.cyou
- domain: trueexcho.cyou
- domain: wavessdemotion.today
- domain: creativemindsettop.top
- url: https://greennquest.cyou/api
- url: https://amasyaelmasi05.com/zjq2njg0mwjjnge0/
- file: 38.207.132.101
- hash: 8080
- file: 206.81.6.248
- hash: 4443
- file: 121.40.128.171
- hash: 37001
- file: 118.99.98.155
- hash: 10549
- file: 20.73.75.104
- hash: 443
- file: 176.65.134.77
- hash: 8089
- file: 193.105.234.195
- hash: 10000
- file: 172.86.93.192
- hash: 4000
- file: 209.38.136.123
- hash: 40056
- domain: cpanel.fithiphealthy.com
- file: 43.204.218.74
- hash: 16166
- file: 125.25.109.91
- hash: 7443
- file: 62.60.150.144
- hash: 80
- file: 212.22.86.229
- hash: 80
- file: 185.224.0.236
- hash: 33006
- file: 209.74.88.128
- hash: 4000
- domain: www.deskschoolpro.com
- file: 154.223.21.148
- hash: 4043
- file: 217.156.50.139
- hash: 17777
- file: 54.208.144.249
- hash: 443
- url: http://154.29.79.29:6677/iremotepanel
- url: http://121.36.194.30:9999/supershell/login/
- file: 66.181.36.137
- hash: 80
- file: 141.95.123.139
- hash: 2404
- file: 23.94.25.236
- hash: 8888
- file: 205.172.57.134
- hash: 8808
- file: 176.65.140.68
- hash: 8089
- file: 85.192.29.60
- hash: 222
- file: 94.156.177.91
- hash: 4449
- file: 46.246.4.2
- hash: 8080
- domain: ecs-113-44-90-0.compute.hwclouds-dns.com
- file: 157.230.225.92
- hash: 443
- domain: cnt9.stayout.life
- domain: 139-59-34-92.cprapid.com
- domain: reserved.vm
- file: 66.42.81.50
- hash: 60000
- file: 212.34.149.75
- hash: 3333
- file: 44.229.7.211
- hash: 443
- file: 142.93.223.55
- hash: 443
- file: 3.136.15.74
- hash: 8443
- file: 165.232.143.1
- hash: 443
- file: 54.86.5.48
- hash: 443
- file: 158.160.18.227
- hash: 8080
- file: 13.60.211.133
- hash: 443
- file: 3.39.104.170
- hash: 80
- file: 192.241.191.212
- hash: 443
- file: 116.254.118.155
- hash: 8888
- file: 16.171.22.28
- hash: 3333
- file: 104.234.50.59
- hash: 3311
- file: 193.143.1.121
- hash: 9669
- hash: 391d8959d1d506992ce4ede8c6ffc94a
- domain: reusable-flex.com
- domain: statistics-for-you.com
- domain: statistics-renew.com
- domain: goingfatter.com
- domain: wellfacing.com
- domain: static-open.com
- domain: morningflexpleasure.com
- domain: hidevs.co.uk
- domain: hi-devs.com
- url: https://check.ioyyu.icu/gkcxv.google
- domain: check.ioyyu.icu
- file: 101.200.38.121
- hash: 2345
- file: 122.114.169.63
- hash: 80
- file: 172.86.107.183
- hash: 31337
- url: https://softpaxth.cyou/api
- url: https://clxearnest.cyou/api
- url: http://23.94.25.236:8888/supershell/login
- domain: husodct.duckdns.org
- url: https://pastebin.com/raw/4zaietzs
- domain: cart-care.gl.at.ply.gg
- file: 147.185.221.26
- hash: 1316
- url: https://mercharena.biz/api
- url: https://generalmills.pro/api
- url: https://zefnecho.cyou/api
- url: https://stormlegue.com/api
- url: https://blastikcn.com/api
- url: https://nestlecompany.pro/api
- url: https://blast-hubs.com/api
- domain: xinyutech.org
- domain: deepsealuc.com
- domain: mail.xinyutech.org
- domain: hisolution.io
- domain: wuxiantechltd.com
- domain: pengzhoutrading.com
- url: https://breedertremnd.com/api
- url: https://whopeefreamed.com/api
- file: 103.68.109.212
- hash: 5000
- domain: check.yyiue.icu
- url: https://check.yyiue.icu/gkcxv.google
- url: https://questeformeaning.cloud/api
- file: 121.36.27.251
- hash: 80
- domain: check.yuyoi.icu
- url: https://judgesteam.icu/art.php
- url: https://check.yuyoi.icu/gkcxv.google
- file: 123.57.175.239
- hash: 80
- file: 139.180.221.1
- hash: 443
- file: 204.194.65.134
- hash: 8888
- file: 47.92.122.62
- hash: 80
- file: 185.211.4.26
- hash: 7443
- file: 219.143.134.210
- hash: 8010
- file: 35.180.133.55
- hash: 4839
- file: 212.22.86.234
- hash: 80
- file: 8.219.95.83
- hash: 8080
- domain: latenativereunion.shop
- domain: u2.latenativereunion.shop
- domain: verticaleatery.store
- file: 154.221.16.181
- hash: 8888
- file: 16.16.26.1
- hash: 443
- file: 64.69.41.70
- hash: 443
- file: 98.159.108.138
- hash: 443
- url: https://brightmhaven.cyou/api
- url: https://u1.subtyperesource.shop/ranked.mp4
- domain: mercharena.biz
- domain: trueszpark.cyou
- domain: starechoz.cyou
- domain: pureechzo.cyou
- domain: urbancraftz.cyou
- domain: softpaxth.cyou
- domain: softzspring.cyou
- domain: wqiseoasis.cyou
- domain: crispvoyazge.cyou
- domain: brizghtoasis.cyou
- domain: cyqfuy.shop
- domain: gewrye.shop
- domain: cozkeu.shop
- domain: alwaysvahead.cloud
- domain: buqowai.shop
- domain: lumfyginiu5.shop
- domain: jigateu.shop
- domain: check.ooyou.icu
- url: https://check.ooyou.icu/gkcxv.google
- domain: sailiabot.com
- url: https://steamcommunity.com/profiles/76561199825403037
- url: https://t.me/b4cha00
- url: https://95.217.246.174/
- url: https://95.216.178.57/
- url: https://78.47.75.136/
- url: https://sailiabot.com/
- file: 95.216.178.57
- hash: 443
- file: 78.47.75.136
- hash: 443
- file: 88.99.124.230
- hash: 443
- domain: check.ououe.icu
- url: https://check.ououe.icu/gkcxv.google
- domain: bakertilly.niarn.org
- domain: noerr.niarn.org
- domain: fgs.niarn.org
- domain: ebnerstolz.niarn.org
- domain: goerg.niarn.org
- domain: luther.niarn.org
- domain: fps.niarn.org
- domain: cms.niarn.org
- domain: roedl.niarn.org
- domain: beiten.niarn.org
- domain: stober.niarn.org
- domain: heitec.niarn.org
- domain: azo.niarn.org
- domain: moog.niarn.org
- domain: spie.niarn.org
- domain: nidec.niarn.org
- domain: nitta.niarn.org
- domain: mayser.niarn.org
- domain: vescon.niarn.org
- domain: lumberg.niarn.org
- domain: prettl.niarn.org
- domain: burkert.niarn.org
- domain: emz.niarn.org
- domain: technisat.niarn.org
- domain: schmersal.niarn.org
- domain: kiebackpeter.niarn.org
- domain: hermos.niarn.org
- domain: inpro.niarn.org
- domain: aumann.niarn.org
- domain: baumueller.niarn.org
- domain: vosslohschwabe.niarn.org
- domain: sgb.niarn.org
- domain: buehlermotor.niarn.org
- domain: schaltbau.niarn.org
- domain: buschjaeger.niarn.org
- domain: trumpf.niarn.org
- domain: firstsensor.niarn.org
- domain: microepsilon.niarn.org
- domain: actemium.niarn.org
- domain: check.uoyou.icu
- url: https://check.uoyou.icu/gkcxv.google
- url: https://5.75.215.216/
- url: https://t.me/cruadsummar
- url: https://t.me/pullmeundervosk2
- url: https://95.216.179.187/
- url: https://t.me/pozebsub22442
- url: https://t.me/kuskas55991
- url: https://t.me/sausage22550
- url: https://49.13.32.185/
- file: 5.75.215.216
- hash: 443
- file: 95.216.179.187
- hash: 443
- file: 49.13.32.185
- hash: 443
- domain: check.iyeeu.icu
- url: https://check.iyeeu.icu/gkcxv.google
- url: http://www.1139.loan/oi08/
- url: http://www.1powerball.lat/oi08/
- url: http://www.32zf.top/oi08/
- url: http://www.68shop.cyou/oi08/
- url: http://www.85uz.top/oi08/
- url: http://www.adeupadult.pro/oi08/
- url: http://www.almainwebdesign.info/oi08/
- url: http://www.anda-casinoyyzz.top/oi08/
- url: http://www.andscaping-services-37849.bond/oi08/
- url: http://www.angbi-ndara.info/oi08/
- url: http://www.arriage-therapy-69521.bond/oi08/
- url: http://www.asinol.press/oi08/
- url: http://www.atcatdogdog.shop/oi08/
- url: http://www.ccountant-jobs-30905.bond/oi08/
- url: http://www.cghvuwqpc.shop/oi08/
- url: http://www.dfght.xyz/oi08/
- url: http://www.dpe.bid/oi08/
- url: http://www.ealpains.info/oi08/
- url: http://www.efenselenses.info/oi08/
- url: http://www.elationship-coach-72760.bond/oi08/
- url: http://www.elegramae.beauty/oi08/
- url: http://www.errywang.shop/oi08/
- url: http://www.estimport.biz/oi08/
- url: http://www.estosteronepower.sbs/oi08/
- url: http://www.eyryi.info/oi08/
- url: http://www.fhcoy.buzz/oi08/
- url: http://www.flrt.info/oi08/
- url: http://www.futbffod.top/oi08/
- url: http://www.griculture-jobs-13665.bond/oi08/
- url: http://www.helon.net/oi08/
- url: http://www.ibrantzing.pro/oi08/
- url: http://www.ime.shop/oi08/
- url: http://www.iv-test-13045.bond/oi08/
- url: http://www.kin-rejuvenation-70531.bond/oi08/
- url: http://www.log555fastbest.shop/oi08/
- url: http://www.log88ablebest.shop/oi08/
- url: http://www.log88optionbest.shop/oi08/
- url: http://www.log99facebest.shop/oi08/
- url: http://www.lvosuperfood.info/oi08/
- url: http://www.mandlaamasha.africa/oi08/
- url: http://www.mxtx97d.shop/oi08/
- url: http://www.ocated-device.info/oi08/
- url: http://www.odafenptss.top/oi08/
- url: http://www.odfitness.net/oi08/
- url: http://www.om-ioiakwea.top/oi08/
- url: http://www.om-masshff.top/oi08/
- url: http://www.om-scseq.top/oi08/
- url: http://www.om-whupnf.top/oi08/
- url: http://www.omalaysianwebsitedirectory.shop/oi08/
- url: http://www.omfycornerco.click/oi08/
- url: http://www.onstruction-jobs-78291.bond/oi08/
- url: http://www.oreadefensearmy.net/oi08/
- url: http://www.otogel.pro/oi08/
- url: http://www.ovabridge.tech/oi08/
- url: http://www.poredmalru999romero.live/oi08/
- url: http://www.pyubxrmfgdth.shop/oi08/
- url: http://www.ravel-insurance-48465.bond/oi08/
- url: http://www.reamanddecor.net/oi08/
- url: http://www.reamgetaways234.xyz/oi08/
- url: http://www.redit-card-offers-de-5398.today/oi08/
- url: http://www.ttv2ud.cyou/oi08/
- url: http://www.uvne.info/oi08/
- url: http://www.uyukgorus.click/oi08/
- url: http://www.verafter.shop/oi08/
- url: http://www.yfeboi8.pro/oi08/
- domain: www.1139.loan
- domain: www.1powerball.lat
- domain: www.32zf.top
- domain: www.68shop.cyou
- domain: www.85uz.top
- domain: www.adeupadult.pro
- domain: www.almainwebdesign.info
- domain: www.anda-casinoyyzz.top
- domain: www.andscaping-services-37849.bond
- domain: www.angbi-ndara.info
- domain: www.arriage-therapy-69521.bond
- domain: www.asinol.press
- domain: www.atcatdogdog.shop
- domain: www.ccountant-jobs-30905.bond
- domain: www.cghvuwqpc.shop
- domain: www.dfght.xyz
- domain: www.dpe.bid
- domain: www.ealpains.info
- domain: www.efenselenses.info
- domain: www.elationship-coach-72760.bond
- domain: www.elegramae.beauty
- domain: www.errywang.shop
- domain: www.estimport.biz
- domain: www.estosteronepower.sbs
- domain: www.eyryi.info
- domain: www.fhcoy.buzz
- domain: www.flrt.info
- domain: www.futbffod.top
- domain: www.griculture-jobs-13665.bond
- domain: www.helon.net
- domain: www.ibrantzing.pro
- domain: www.ime.shop
- domain: www.iv-test-13045.bond
- domain: www.kin-rejuvenation-70531.bond
- domain: www.log555fastbest.shop
- domain: www.log88ablebest.shop
- domain: www.log88optionbest.shop
- domain: www.log99facebest.shop
- domain: www.lvosuperfood.info
- domain: www.mandlaamasha.africa
- domain: www.mxtx97d.shop
- domain: www.ocated-device.info
- domain: www.odafenptss.top
- domain: www.odfitness.net
- domain: www.om-ioiakwea.top
- domain: www.om-masshff.top
- domain: www.om-scseq.top
- domain: www.om-whupnf.top
- domain: www.omalaysianwebsitedirectory.shop
- domain: www.omfycornerco.click
- domain: www.onstruction-jobs-78291.bond
- domain: www.oreadefensearmy.net
- domain: www.otogel.pro
- domain: www.ovabridge.tech
- domain: www.poredmalru999romero.live
- domain: www.pyubxrmfgdth.shop
- domain: www.ravel-insurance-48465.bond
- domain: www.reamanddecor.net
- domain: www.reamgetaways234.xyz
- domain: www.redit-card-offers-de-5398.today
- domain: www.ttv2ud.cyou
- domain: www.uvne.info
- domain: www.uyukgorus.click
- domain: www.verafter.shop
- domain: www.yfeboi8.pro
- domain: akerusa.com
- domain: activekala.shop
- file: 77.239.117.222
- hash: 443
- url: https://77.239.117.222/
- domain: academy.entrepreneurwealthhub.com
- url: https://urbancraftz.cyou/api
- url: https://fxreshecho.cyou/api
- url: https://restfulrletreats.cyou/api
- url: https://simpleupleasures.cyou/api
- url: https://mysticjpath.cyou/api
- url: https://artisnticexpressions.cyou/api
- url: https://curitousminds.cyou/api
- url: https://softnestl.cyou/api
- url: https://frdiendlycommunity.cyou/api
- url: https://crispvoyazge.cyou/api
- url: https://clearhecho.cyou/api
- url: https://dreamswiay.cyou/api
- url: https://radiantenyergy.cyou/api
- url: https://luckyfindps.cyou/api
- url: https://starcruaft.cyou/api
- url: https://calfmhaven.cyou/api
- url: https://mystgicdawn.cyou/api
- url: https://happbytrail.cyou/api
- url: https://frershtrail.cyou/api
- url: https://cwrispbreeze.cyou/api
- url: https://spirmitedtravel.cyou/api
- url: https://softbljoom.cyou/api
- url: https://aexquisitecrafts.cyou/api
- url: https://chverishedmoments.cyou/api
- url: https://cwalmjourney.cyou/api
- url: https://wisecrakft.cyou/api
- url: https://happtyvibe.cyou/api
- url: https://mysrticwave.cyou/api
- url: https://wiesespark.cyou/api
- url: https://festivevoibes.cyou/api
- url: https://greennesqt.cyou/api
- url: https://boldmeadozw.cyou/api
- url: https://fclearcraft.cyou/api
- url: https://www.mysticjpath.cyou/api
- url: https://stafrmountain.cyou/api
- url: https://crispnefst.cyou/api
- url: https://dreamblizss.cyou/api
- url: https://brighqthorizon.cyou/api
- url: https://www.aclearbeam.cyou/api
- url: https://cleqarjourney.cyou/api
- url: https://www.zensphace.cyou/api
- url: https://fresxhhaze.cyou/api
- url: https://www.bsoldvista.cyou/api
- domain: nestlecompany.pro
- domain: blastikcn.com
- domain: clxearnest.cyou
- domain: blast-hubs.com
- domain: zefnecho.cyou
- domain: generalmills.pro
- domain: greennesqt.cyou
- domain: boldmeadozw.cyou
- domain: fclearcraft.cyou
- domain: stafrmountain.cyou
- domain: crispnefst.cyou
- domain: dreamblizss.cyou
- domain: brighqthorizon.cyou
- domain: cleqarjourney.cyou
- domain: fresxhhaze.cyou
- url: https://check.iueyo.icu/gkcxv.google
- domain: check.iueyo.icu
- file: 91.92.136.87
- hash: 26264
- domain: recaptcha-manual.shop
- file: 49.0.243.129
- hash: 8081
- file: 47.119.189.207
- hash: 8888
- file: 47.111.146.110
- hash: 8090
- file: 45.62.170.61
- hash: 2404
- file: 46.246.86.12
- hash: 2404
- file: 178.215.224.50
- hash: 2525
- file: 93.123.109.202
- hash: 4444
- file: 45.154.98.68
- hash: 6606
- file: 176.65.134.239
- hash: 80
- file: 176.65.134.239
- hash: 8089
- file: 144.34.163.218
- hash: 8001
- domain: www.timeweb25.online
- file: 3.8.96.179
- hash: 5986
- file: 194.5.192.21
- hash: 8082
- file: 154.23.163.91
- hash: 80
- file: 165.22.17.53
- hash: 80
- domain: mail.confess2.nw66.fcomet.com
- file: 158.160.18.227
- hash: 3333
- file: 113.44.48.28
- hash: 80
- domain: check.iyiao.icu
- url: https://check.iyiao.icu/gkcxv.google
- domain: drheahmweaver.top
- domain: ahgilenexus.top
- domain: frehshecho.top
- domain: www.fireflypath.shop
- domain: check.iyyye.icu
- url: https://check.iyyye.icu/gkcxv.google
- domain: koshersincerepointy.shop
- domain: cdn.gridgatecloud.com
- domain: store.gridgatecloud.com
- file: 87.120.114.34
- hash: 443
- domain: check.duwon.icu
- url: https://check.duwon.icu/gkcxv.google
- domain: check.waxof.icu
- domain: onejj1sr.top
- domain: fivedd5vt.top
- file: 106.15.184.255
- hash: 50012
- file: 106.15.184.255
- hash: 55413
- url: https://check.waxof.icu/gkcxv.google
- domain: panelonoaltanlyanlsaydprysmaxwebnasodaskfoa.digital
- domain: sa1at.ru
- domain: sixhh6pn.top
- domain: sixpp6sb.top
- domain: eighthh8pn.top
- domain: check.vidad.icu
- url: https://check.vidad.icu/gkcxv.google
- domain: onepp1sb.top
- domain: sixuu6pn.top
- domain: onehhpn.top
- domain: oneuu1pn.top
- domain: frtndd14vt.top
- domain: eightpp8sb.top
- domain: nineuu9pn.top
- domain: ninehh9pn.top
- domain: ninepp9sb.top
- domain: eightjj8sb.top
- domain: frtgg14sb.top
- domain: onejj1sb.top
- domain: onejjsb.top
- domain: sixgg6sb.top
- domain: eightgg8th.top
- domain: sixgg6th.top
- domain: onegg1th.top
- domain: oneww1vt.top
- domain: eightww8vt.top
- domain: nineww8vt.top
- domain: sixww6vt.top
- domain: elvnjj1sr.top
- domain: ivedd5vt.top
- domain: tengg10sb.top
- domain: ninejj9sb.top
- domain: tengg10th.top
- domain: ninegg9th.top
- domain: check.bitew.icu
- url: https://check.bitew.icu/gkcxv.google
- url: https://fashionghana.shop/work/original.js
- domain: fashionghana.shop
- url: https://fashionghana.shop/work/index.php
- url: https://fashionghana.shop/work/file.php
- url: https://fashionghana.shop/work/files.zip
- url: http://cy10907.tw1.ru/8bf75526.php
- file: 95.216.180.255
- hash: 443
- url: https://95.216.180.255/
- url: https://alwaysvahead.cloud/api
- url: https://brightecfho.cyou/api
- url: https://brizghtoasis.cyou/api
- url: https://buqowai.shop/api
- url: https://cozkeu.shop/api
- url: https://cyqfuy.shop/api
- url: https://dreamneist.cyou/api
- url: https://drheahmweaver.top/api
- url: https://frehshecho.top/api
- url: https://fresqhsway.cyou/api
- url: https://gewrye.shop/api
- url: https://haqppycrest.cyou/api
- url: https://lumfyginiu5.shop/api
- url: https://mystictqrail.cyou/api
- url: https://naiftheking.xyz/api
- url: https://pureechzo.cyou/api
- url: https://purequuest.cyou/api
- url: https://puretmeadow.cyou/api
- url: https://qsoftcove.cyou/api
- url: https://quicksnhift.top/api
- url: https://quievtstream.cyou/api
- url: https://softzspring.cyou/api
- url: https://starechoz.cyou/api
- url: https://trueszpark.cyou/api
- url: https://urbanouasis.cyou/api
- url: https://wqiseoasis.cyou/api
- file: 156.226.174.246
- hash: 80
- file: 34.209.223.89
- hash: 443
- file: 170.106.136.132
- hash: 80
- file: 123.11.165.3
- hash: 5873
- file: 50.114.115.207
- hash: 8808
- file: 163.5.210.97
- hash: 8808
- file: 128.90.102.127
- hash: 5000
- file: 163.5.32.125
- hash: 8808
- file: 185.49.126.27
- hash: 8808
- file: 143.198.200.58
- hash: 7443
- file: 45.32.236.137
- hash: 80
- file: 45.61.136.67
- hash: 80
- file: 77.239.119.53
- hash: 80
- file: 149.88.80.235
- hash: 80
- file: 46.249.49.34
- hash: 443
- file: 154.223.20.58
- hash: 2087
- file: 54.232.249.182
- hash: 443
- file: 62.234.57.48
- hash: 80
- file: 116.205.98.214
- hash: 50050
- file: 8.140.239.162
- hash: 50050
- file: 87.251.79.220
- hash: 31337
- file: 193.124.47.213
- hash: 31337
- file: 91.218.50.174
- hash: 31337
- file: 188.166.237.148
- hash: 7443
- file: 181.50.73.64
- hash: 44822
- file: 34.249.158.108
- hash: 12101
- url: https://5.252.155.64/
- url: https://api.telegram.org/bot6524461406:aah3tboejg5crfe0hbcmlee4xlbl6zeatik/
- url: https://pastebin.com/raw/2nrn2bsv
- file: 3.69.115.178
- hash: 12672
- domain: ardhragirliamhereforudear.duckdns.org
- domain: moneyluck.ddns.net
- domain: service-transfert.duckdns.org
- domain: baby.uncofig.com
- url: https://pastebin.com/raw/kthpp2pd
- file: 77.93.28.66
- hash: 2323
- url: https://bit.ly/4cb3oaq
- url: https://pastebin.com/raw/vrsch5uf
- url: https://tinyurl.com/2s3b6mbb
- url: https://akmedia.in/js/mail.php
- file: 166.88.98.221
- hash: 80
- file: 185.157.162.168
- hash: 557
- file: 194.59.31.126
- hash: 3939
- file: 45.66.248.181
- hash: 2404
- file: 185.7.214.250
- hash: 2404
- file: 107.173.62.67
- hash: 8808
- file: 186.169.60.145
- hash: 11103
- file: 54.145.59.120
- hash: 7443
- file: 85.209.128.159
- hash: 80
- file: 176.65.134.77
- hash: 80
- file: 93.183.91.123
- hash: 2053
- file: 211.149.227.147
- hash: 4782
- file: 40.66.43.203
- hash: 443
- file: 192.142.18.32
- hash: 443
- file: 46.246.82.30
- hash: 8080
- file: 65.0.73.139
- hash: 35549
- file: 64.52.80.81
- hash: 80
- file: 194.147.98.238
- hash: 10081
- file: 185.156.110.13
- hash: 443
- file: 31.172.87.193
- hash: 4000
- file: 134.255.232.64
- hash: 3000
- file: 161.10.153.176
- hash: 7575
- domain: mikhail-lermontov.com
- url: https://mikhail-lermontov.com/api
- file: 150.241.113.219
- hash: 8384
- file: 154.29.138.77
- hash: 443
- file: 119.8.116.145
- hash: 8033
- file: 165.154.245.30
- hash: 60000
- file: 191.234.214.190
- hash: 31337
- file: 181.50.73.64
- hash: 44722
- file: 34.56.177.4
- hash: 443
- file: 35.205.12.222
- hash: 443
- file: 38.50.164.55
- hash: 8443
- file: 5.163.173.51
- hash: 443
- file: 98.159.108.137
- hash: 443
- file: 99.112.198.252
- hash: 8080
- domain: ns.tkzvew.tech
- domain: ns1.helneri.com
- file: 38.54.57.191
- hash: 53
- file: 44.210.161.64
- hash: 53
- file: 89.116.211.244
- hash: 53
- url: http://81.161.229.110/htdocs/dwrbrqnfnbzmpds.exe
- url: http://37.139.129.142/htdocs/crjxfnpqeefbszb.exe
- url: http://37.139.129.142/htdocs/txgqfxfgbteajcy.exe
- url: http://109.206.241.81/htdocs/gyjetxnwnpksymb.exe
- url: http://81.161.229.110/htdocs/dyrknbtomnspala.exe
- url: http://37.139.129.142/htdocs/fmqaxqtoxtcebmw.exe
- url: http://81.161.229.110/htdocs/tdmzxjjcdosllka.exe
- url: http://81.161.229.110/htdocs/gbcjzcmfmpwrsyw.exe
- url: http://81.161.229.110/htdocs/telgrehflpzpyxs.exe
- url: http://37.139.129.142/htdocs/cgenmjejgczcdaf.exe
- url: http://81.161.229.110/htdocs/ycjrkwfhsmzteek.exe
- url: http://37.139.129.142/htdocs/omlfyzflewaeppc.exe
- url: http://81.161.229.110/htdocs/fqrbnkjbpwlwagp.exe
- url: http://81.161.229.110/htdocs/yishjpcdfghrgox.exe
- url: http://81.161.229.110/htdocs/rhygfcbkjtnyxxa.exe
- url: http://81.161.229.110/htdocs/reqxebqxklhwkzs.exe
- url: http://37.139.129.142/htdocs/tgqthgjlfkxmfdl.exe
- url: http://81.161.229.110/htdocs/pjqztgahsaeqlzw.exe
- url: http://37.139.129.142/htdocs/oamsdkwxeqbnjhc.exe
- url: https://178.159.43.166/0028a0f3432ee7b2/vcruntime140.dll
- url: https://94.232.249.208/c129a6f25cb7bf9b/sqlite3.dll
- url: https://94.232.249.208/c129a6f25cb7bf9b/mozglue.dll
- url: https://94.232.249.208/c129a6f25cb7bf9b/vcruntime140.dll
- url: http://178.159.43.166/0028a0f3432ee7b2/sqlite3.dll
- url: http://95.217.125.57/557b2ce3c387a13c/mozglue.dll
- url: https://clsevermarketing.click/login
- url: https://ytdownload.resources.ink/video5314651
- url: http://www.024attdatastealmarch.net/da16/
- url: http://www.3000.xyz/b101/
- url: http://www.63738.baby/b101/
- url: http://www.692.top/b101/
- url: http://www.6ac664z.shop/b101/
- url: http://www.abbiel-february351.cfd/da16/
- url: http://www.acking-jobs-ww-230.today/da16/
- url: http://www.acklinkssites.mobi/da16/
- url: http://www.acwibdisiga.top/da16/
- url: http://www.adan.shop/da16/
- url: http://www.akeai.win/da16/
- url: http://www.amarindhn.lol/da16/
- url: http://www.ancer-treatment-13131.bond/da16/
- url: http://www.antapgan.xyz/b101/
- url: http://www.app.photography/da16/
- url: http://www.appypost.top/da16/
- url: http://www.av69.lat/b101/
- url: http://www.avoredbuysspot.shop/b101/
- url: http://www.awyer-jp-6396164.live/b101/
- url: http://www.aymentprocessinglb.top/b101/
- url: http://www.ayprocessingls.top/da16/
- url: http://www.aysidewebdesign.net/da16/
- url: http://www.ccountgnailcom.live/b101/
- url: http://www.dornmi.shop/da16/
- url: http://www.dqtfuj.info/da16/
- url: http://www.ea.tech/b101/
- url: http://www.eafq987.top/b101/
- url: http://www.echo.group/b101/
- url: http://www.edmksa.top/da16/
- url: http://www.edpwxcofxjfrkp.shop/da16/
- url: http://www.efresh.shop/da16/
- url: http://www.eleglarm.watch/b101/
- url: http://www.elegmear.click/da16/
- url: http://www.elegrams.shop/b101/
- url: http://www.endit.mobi/b101/
- url: http://www.enuvae8.pro/da16/
- url: http://www.eo3p.info/da16/
- url: http://www.et-insurance-80325.bond/b101/
- url: http://www.etrootomatik.net/b101/
- url: http://www.fdyqcoyex.shop/da16/
- url: http://www.front.biz/b101/
- url: http://www.g-36954.top/da16/
- url: http://www.gdb.bid/da16/
- url: http://www.goncca.art/da16/
- url: http://www.heap-psychic-reading-us-889.xyz/da16/
- url: http://www.hendai.top/b101/
- url: http://www.ianca.realtor/b101/
- url: http://www.iasgirls.net/da16/
- url: http://www.ienvu.net/da16/
- url: http://www.illpayfast-loan-experts.click/da16/
- url: http://www.implysharp.net/b101/
- url: http://www.ingdomsecuritysolutions.xyz/b101/
- url: http://www.inmaber.xyz/b101/
- url: http://www.irs60.top/b101/
- url: http://www.ittzofme.net/b101/
- url: http://www.ivelyglimy.pro/da16/
- url: http://www.ixtemplates.pro/da16/
- url: http://www.jgjvajurexadjw.shop/b101/
- url: http://www.jtmv.info/da16/
- url: http://www.juuwb.shop/b101/
- url: http://www.kin-rejuvenation-84789.bond/da16/
- url: http://www.kytraders.university/b101/
- url: http://www.lay-blazing-kingdom.xyz/b101/
- url: http://www.layaiverse.live/b101/
- url: http://www.lcht.bid/da16/
- url: http://www.lfatouch.shop/b101/
- url: http://www.lfstudio.xyz/b101/
- url: http://www.litedosug.top/da16/
- url: http://www.log103powerbest.shop/da16/
- url: http://www.log99fastbest.shop/da16/
- url: http://www.lossom-and-bark.net/da16/
- url: http://www.lumber-services-51937.bond/da16/
- url: http://www.mopkaruaricniosdalptcore.shop/b101/
- url: http://www.ncca.bid/b101/
- url: http://www.nfluencer.directory/b101/
- url: http://www.nfostealattmarch2024.net/da16/
- url: http://www.ni-flow.shop/da16/
- url: http://www.nipkaruaroninasdalhome.cyou/b101/
- url: http://www.nyankou.top/b101/
- url: http://www.ob-offer-46679.bond/da16/
- url: http://www.occer-camps-30515.bond/da16/
- url: http://www.odular-homes-39739.bond/da16/
- url: http://www.oinbgetw.pro/b101/
- url: http://www.olbertconsulting.pro/b101/
- url: http://www.ome-care-70823.bond/da16/
- url: http://www.ompciti.homes/da16/
- url: http://www.onopolycontracting.net/b101/
- url: http://www.onstruction-services-74050.bond/b101/
- url: http://www.oolai.homes/da16/
- url: http://www.ortis.top/da16/
- url: http://www.osmetology-degrees-002.today/b101/
- url: http://www.otten.city/da16/
- url: http://www.ouruguayaniixx0el.shop/da16/
- url: http://www.ptaxi.net/da16/
- url: http://www.r365131.xyz/da16/
- url: http://www.rahyzwjshvj.shop/b101/
- url: http://www.rain-tours-es-5078.today/da16/
- url: http://www.ravelvistasxyz234.xyz/b101/
- url: http://www.rinxelio.top/b101/
- url: http://www.rmineroyli.top/b101/
- url: http://www.rogrammer.expert/da16/
- url: http://www.rouver-un-emploi-br.buzz/b101/
- url: http://www.rowhesap.xyz/da16/
- url: http://www.rthodontist-73950.bond/b101/
- url: http://www.ruck-driver-training-42235.bond/b101/
- url: http://www.s010.net/b101/
- url: http://www.sl1.sbs/b101/
- url: http://www.stikanafenyal.xyz/da16/
- url: http://www.syylx.net/da16/
- url: http://www.tdzknmgvrvxkeyftoz.shop/b101/
- url: http://www.tellardealsshowcase.shop/b101/
- url: http://www.tnjtgmorwbvak.shop/da16/
- url: http://www.trasbv.xyz/b101/
- url: http://www.trtypoi.xyz/da16/
- url: http://www.tu1.info/b101/
- url: http://www.uel-fleet-cards-25316.bond/b101/
- url: http://www.ugworksservices.net/b101/
- url: http://www.unshangwuliujituanmei.top/b101/
- url: http://www.uoym.net/b101/
- url: http://www.urvio.shop/da16/
- url: http://www.utriments.beauty/b101/
- url: http://www.uture-intimates.today/da16/
- url: http://www.uv-deals-76094.bond/da16/
- url: http://www.xljll.bid/da16/
- url: http://www.xposvoharowvh.shop/b101/
- url: http://www.yhupbasybcxgbfbw.shop/b101/
- url: http://www.ynix.design/da16/
- url: http://www.ypothequesinversee.today/b101/
- url: http://www.ywebchallenge.info/da16/
- url: http://www.zrotzkmfbntexfg.shop/b101/
- domain: www.024attdatastealmarch.net
- domain: www.3000.xyz
- domain: www.63738.baby
- domain: www.692.top
- domain: www.6ac664z.shop
- domain: www.abbiel-february351.cfd
- domain: www.acking-jobs-ww-230.today
- domain: www.acklinkssites.mobi
- domain: www.acwibdisiga.top
- domain: www.adan.shop
- domain: www.akeai.win
- domain: www.amarindhn.lol
- domain: www.ancer-treatment-13131.bond
- domain: www.antapgan.xyz
- domain: www.app.photography
- domain: www.appypost.top
- domain: www.av69.lat
- domain: www.avoredbuysspot.shop
- domain: www.awyer-jp-6396164.live
- domain: www.aymentprocessinglb.top
- domain: www.ayprocessingls.top
- domain: www.aysidewebdesign.net
- domain: www.ccountgnailcom.live
- domain: www.dornmi.shop
- domain: www.dqtfuj.info
- domain: www.ea.tech
- domain: www.eafq987.top
- domain: www.echo.group
- domain: www.edmksa.top
- domain: www.edpwxcofxjfrkp.shop
- domain: www.efresh.shop
- domain: www.eleglarm.watch
- domain: www.elegmear.click
- domain: www.elegrams.shop
- domain: www.endit.mobi
- domain: www.enuvae8.pro
- domain: www.eo3p.info
- domain: www.et-insurance-80325.bond
- domain: www.etrootomatik.net
- domain: www.fdyqcoyex.shop
- domain: www.front.biz
- domain: www.g-36954.top
- domain: www.gdb.bid
- domain: www.goncca.art
- domain: www.heap-psychic-reading-us-889.xyz
- domain: www.hendai.top
- domain: www.ianca.realtor
- domain: www.iasgirls.net
- domain: www.ienvu.net
- domain: www.illpayfast-loan-experts.click
- domain: www.implysharp.net
- domain: www.ingdomsecuritysolutions.xyz
- domain: www.inmaber.xyz
- domain: www.irs60.top
- domain: www.ittzofme.net
- domain: www.ivelyglimy.pro
- domain: www.ixtemplates.pro
- domain: www.jgjvajurexadjw.shop
- domain: www.jtmv.info
- domain: www.juuwb.shop
- domain: www.kin-rejuvenation-84789.bond
- domain: www.kytraders.university
- domain: www.lay-blazing-kingdom.xyz
- domain: www.layaiverse.live
- domain: www.lcht.bid
- domain: www.lfatouch.shop
- domain: www.lfstudio.xyz
- domain: www.litedosug.top
- domain: www.log103powerbest.shop
- domain: www.log99fastbest.shop
- domain: www.lossom-and-bark.net
- domain: www.lumber-services-51937.bond
- domain: www.mopkaruaricniosdalptcore.shop
- domain: www.ncca.bid
- domain: www.nfluencer.directory
- domain: www.nfostealattmarch2024.net
- domain: www.ni-flow.shop
- domain: www.nipkaruaroninasdalhome.cyou
- domain: www.nyankou.top
- domain: www.ob-offer-46679.bond
- domain: www.occer-camps-30515.bond
- domain: www.odular-homes-39739.bond
- domain: www.oinbgetw.pro
- domain: www.olbertconsulting.pro
- domain: www.ome-care-70823.bond
- domain: www.ompciti.homes
- domain: www.onopolycontracting.net
- domain: www.onstruction-services-74050.bond
- domain: www.oolai.homes
- domain: www.ortis.top
- domain: www.osmetology-degrees-002.today
- domain: www.otten.city
- domain: www.ouruguayaniixx0el.shop
- domain: www.ptaxi.net
- domain: www.r365131.xyz
- domain: www.rahyzwjshvj.shop
- domain: www.rain-tours-es-5078.today
- domain: www.ravelvistasxyz234.xyz
- domain: www.rinxelio.top
- domain: www.rmineroyli.top
- domain: www.rogrammer.expert
- domain: www.rouver-un-emploi-br.buzz
- domain: www.rowhesap.xyz
- domain: www.rthodontist-73950.bond
- domain: www.ruck-driver-training-42235.bond
- domain: www.s010.net
- domain: www.sl1.sbs
- domain: www.stikanafenyal.xyz
- domain: www.syylx.net
- domain: www.tdzknmgvrvxkeyftoz.shop
- domain: www.tellardealsshowcase.shop
- domain: www.tnjtgmorwbvak.shop
- domain: www.trasbv.xyz
- domain: www.trtypoi.xyz
- domain: www.tu1.info
- domain: www.uel-fleet-cards-25316.bond
- domain: www.ugworksservices.net
- domain: www.unshangwuliujituanmei.top
- domain: www.uoym.net
- domain: www.urvio.shop
- domain: www.utriments.beauty
- domain: www.uture-intimates.today
- domain: www.uv-deals-76094.bond
- domain: www.xljll.bid
- domain: www.xposvoharowvh.shop
- domain: www.yhupbasybcxgbfbw.shop
- domain: www.ynix.design
- domain: www.ypothequesinversee.today
- domain: www.ywebchallenge.info
- domain: www.zrotzkmfbntexfg.shop
- domain: masterpoldo02.kozow.com
- domain: voltazur.ddns.net
- file: 131.0.150.232
- hash: 9000
- file: 156.226.174.246
- hash: 8080
ThreatFox IOCs for 2025-02-13
Description
ThreatFox IOCs for 2025-02-13
AI-Powered Analysis
Technical Analysis
The provided threat intelligence relates to a malware-related report titled "ThreatFox IOCs for 2025-02-13," sourced from ThreatFox, an OSINT (Open Source Intelligence) platform. The report appears to be a collection or update of Indicators of Compromise (IOCs) relevant to malware activity as of February 13, 2025. However, the technical details are minimal, with no specific affected software versions, no identified Common Weakness Enumerations (CWEs), no patch links, and no known exploits currently observed in the wild. The threat level is indicated as 2 on an unspecified scale, with analysis and distribution scores of 1 and 3 respectively, suggesting limited analysis depth but moderate distribution potential. The absence of concrete technical indicators or detailed malware behavior limits the ability to fully characterize the threat. The tags indicate that this is an OSINT-type threat with a TLP (Traffic Light Protocol) designation of white, meaning the information is publicly shareable without restriction. Overall, this appears to be an early or generic alert about malware-related IOCs collected by ThreatFox, rather than a detailed vulnerability or exploit report.
Potential Impact
Given the lack of detailed technical information and absence of known exploits in the wild, the immediate impact on European organizations is likely limited. However, the distribution score of 3 suggests that the malware or its indicators may be moderately widespread or have potential for broader dissemination. European organizations relying on OSINT feeds for threat detection could benefit from integrating these IOCs to enhance their detection capabilities. Without specific affected products or vulnerabilities, the threat primarily poses a risk of undetected malware infections if these IOCs are not incorporated into security monitoring tools. The confidentiality, integrity, and availability impacts remain uncertain but could range from data exfiltration to system compromise if the malware is deployed successfully. The medium severity rating reflects this uncertainty and the potential for moderate impact if the malware becomes active or widespread.
Mitigation Recommendations
1. Integrate ThreatFox IOCs into existing Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) systems to improve detection of related malware activity. 2. Maintain up-to-date threat intelligence feeds and ensure automated ingestion of OSINT data to promptly identify emerging threats. 3. Conduct regular network and endpoint scans using the latest IOCs to identify potential infections early. 4. Enhance user awareness training focused on recognizing malware infection vectors, especially phishing and social engineering, as no specific exploit vectors are detailed. 5. Implement strict network segmentation and least privilege access controls to limit malware spread if infection occurs. 6. Monitor for unusual outbound network traffic patterns that could indicate data exfiltration or command and control communications. 7. Since no patches or CVEs are associated, focus on detection and response capabilities rather than patch management for this threat. 8. Collaborate with local Computer Security Incident Response Teams (CSIRTs) to share intelligence and coordinate response efforts.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- 9f6b7c4a-b5d3-4ac2-acb6-31d0c0a6b751
- Original Timestamp
- 1739491387
Indicators of Compromise
Domain
Value | Description | Copy |
---|---|---|
domaincheck.uueye.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrixghtquest.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainhxappycove.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaintrueexcho.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainwavessdemotion.today | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaincreativemindsettop.top | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaincpanel.fithiphealthy.com | Havoc botnet C2 domain (confidence level: 100%) | |
domainwww.deskschoolpro.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainecs-113-44-90-0.compute.hwclouds-dns.com | Cobalt Strike botnet C2 domain (confidence level: 100%) | |
domaincnt9.stayout.life | ShadowPad botnet C2 domain (confidence level: 90%) | |
domain139-59-34-92.cprapid.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainreserved.vm | Havoc botnet C2 domain (confidence level: 100%) | |
domainreusable-flex.com | magecart botnet C2 domain (confidence level: 100%) | |
domainstatistics-for-you.com | magecart botnet C2 domain (confidence level: 100%) | |
domainstatistics-renew.com | magecart botnet C2 domain (confidence level: 100%) | |
domaingoingfatter.com | magecart botnet C2 domain (confidence level: 100%) | |
domainwellfacing.com | magecart botnet C2 domain (confidence level: 100%) | |
domainstatic-open.com | magecart botnet C2 domain (confidence level: 100%) | |
domainmorningflexpleasure.com | magecart botnet C2 domain (confidence level: 100%) | |
domainhidevs.co.uk | Unknown malware payload delivery domain (confidence level: 100%) | |
domainhi-devs.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domaincheck.ioyyu.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domainhusodct.duckdns.org | DarkComet botnet C2 domain (confidence level: 50%) | |
domaincart-care.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 50%) | |
domainxinyutech.org | Unknown malware payload delivery domain (confidence level: 100%) | |
domaindeepsealuc.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainmail.xinyutech.org | Unknown malware payload delivery domain (confidence level: 100%) | |
domainhisolution.io | Unknown malware payload delivery domain (confidence level: 100%) | |
domainwuxiantechltd.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainpengzhoutrading.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domaincheck.yyiue.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domaincheck.yuyoi.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domainlatenativereunion.shop | ACR Stealer botnet C2 domain (confidence level: 100%) | |
domainu2.latenativereunion.shop | ACR Stealer botnet C2 domain (confidence level: 100%) | |
domainverticaleatery.store | ACR Stealer botnet C2 domain (confidence level: 100%) | |
domainmercharena.biz | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaintrueszpark.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainstarechoz.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainpureechzo.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainurbancraftz.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainsoftpaxth.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainsoftzspring.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainwqiseoasis.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaincrispvoyazge.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainbrizghtoasis.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaincyqfuy.shop | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaingewrye.shop | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaincozkeu.shop | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainalwaysvahead.cloud | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainbuqowai.shop | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainlumfyginiu5.shop | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainjigateu.shop | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaincheck.ooyou.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domainsailiabot.com | Vidar botnet C2 domain (confidence level: 100%) | |
domaincheck.ououe.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domainbakertilly.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainnoerr.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainfgs.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainebnerstolz.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domaingoerg.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainluther.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainfps.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domaincms.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainroedl.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainbeiten.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainstober.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainheitec.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainazo.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainmoog.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainspie.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainnidec.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainnitta.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainmayser.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainvescon.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainlumberg.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainprettl.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainburkert.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainemz.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domaintechnisat.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainschmersal.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainkiebackpeter.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainhermos.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domaininpro.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainaumann.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainbaumueller.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainvosslohschwabe.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainsgb.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainbuehlermotor.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainschaltbau.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainbuschjaeger.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domaintrumpf.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainfirstsensor.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainmicroepsilon.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domainactemium.niarn.org | Venom RAT payload delivery domain (confidence level: 100%) | |
domaincheck.uoyou.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domaincheck.iyeeu.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domainwww.1139.loan | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.1powerball.lat | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.32zf.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.68shop.cyou | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.85uz.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.adeupadult.pro | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.almainwebdesign.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.anda-casinoyyzz.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.andscaping-services-37849.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.angbi-ndara.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.arriage-therapy-69521.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.asinol.press | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.atcatdogdog.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ccountant-jobs-30905.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.cghvuwqpc.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.dfght.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.dpe.bid | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ealpains.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.efenselenses.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.elationship-coach-72760.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.elegramae.beauty | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.errywang.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.estimport.biz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.estosteronepower.sbs | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.eyryi.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.fhcoy.buzz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.flrt.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.futbffod.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.griculture-jobs-13665.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.helon.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ibrantzing.pro | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ime.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.iv-test-13045.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.kin-rejuvenation-70531.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.log555fastbest.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.log88ablebest.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.log88optionbest.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.log99facebest.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.lvosuperfood.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.mandlaamasha.africa | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.mxtx97d.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ocated-device.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.odafenptss.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.odfitness.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.om-ioiakwea.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.om-masshff.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.om-scseq.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.om-whupnf.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.omalaysianwebsitedirectory.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.omfycornerco.click | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.onstruction-jobs-78291.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.oreadefensearmy.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.otogel.pro | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ovabridge.tech | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.poredmalru999romero.live | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.pyubxrmfgdth.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ravel-insurance-48465.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.reamanddecor.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.reamgetaways234.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.redit-card-offers-de-5398.today | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ttv2ud.cyou | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.uvne.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.uyukgorus.click | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.verafter.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.yfeboi8.pro | Formbook botnet C2 domain (confidence level: 50%) | |
domainakerusa.com | FAKEUPDATES payload delivery domain (confidence level: 50%) | |
domainactivekala.shop | FAKEUPDATES payload delivery domain (confidence level: 50%) | |
domainacademy.entrepreneurwealthhub.com | FAKEUPDATES payload delivery domain (confidence level: 50%) | |
domainnestlecompany.pro | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainblastikcn.com | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainclxearnest.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainblast-hubs.com | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainzefnecho.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaingeneralmills.pro | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaingreennesqt.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainboldmeadozw.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainfclearcraft.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainstafrmountain.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaincrispnefst.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaindreamblizss.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainbrighqthorizon.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaincleqarjourney.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainfresxhhaze.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaincheck.iueyo.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domainrecaptcha-manual.shop | ClearFake botnet C2 domain (confidence level: 100%) | |
domainwww.timeweb25.online | Havoc botnet C2 domain (confidence level: 100%) | |
domainmail.confess2.nw66.fcomet.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domaincheck.iyiao.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domaindrheahmweaver.top | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainahgilenexus.top | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainfrehshecho.top | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainwww.fireflypath.shop | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaincheck.iyyye.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domainkoshersincerepointy.shop | ACR Stealer botnet C2 domain (confidence level: 100%) | |
domaincdn.gridgatecloud.com | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainstore.gridgatecloud.com | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domaincheck.duwon.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domaincheck.waxof.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domainonejj1sr.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainfivedd5vt.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainpanelonoaltanlyanlsaydprysmaxwebnasodaskfoa.digital | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainsa1at.ru | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainsixhh6pn.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainsixpp6sb.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domaineighthh8pn.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domaincheck.vidad.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domainonepp1sb.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainsixuu6pn.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainonehhpn.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainoneuu1pn.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainfrtndd14vt.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domaineightpp8sb.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainnineuu9pn.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainninehh9pn.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainninepp9sb.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domaineightjj8sb.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainfrtgg14sb.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainonejj1sb.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainonejjsb.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainsixgg6sb.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domaineightgg8th.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainsixgg6th.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainonegg1th.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainoneww1vt.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domaineightww8vt.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainnineww8vt.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainsixww6vt.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainelvnjj1sr.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainivedd5vt.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domaintengg10sb.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainninejj9sb.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domaintengg10th.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domainninegg9th.top | CryptBot botnet C2 domain (confidence level: 100%) | |
domaincheck.bitew.icu | ClearFake payload delivery domain (confidence level: 100%) | |
domainfashionghana.shop | FAKEUPDATES payload delivery domain (confidence level: 100%) | |
domainardhragirliamhereforudear.duckdns.org | Remcos botnet C2 domain (confidence level: 50%) | |
domainmoneyluck.ddns.net | Remcos botnet C2 domain (confidence level: 50%) | |
domainservice-transfert.duckdns.org | Remcos botnet C2 domain (confidence level: 50%) | |
domainbaby.uncofig.com | XWorm botnet C2 domain (confidence level: 50%) | |
domainmikhail-lermontov.com | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainns.tkzvew.tech | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainns1.helneri.com | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainwww.024attdatastealmarch.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.3000.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.63738.baby | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.692.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.6ac664z.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.abbiel-february351.cfd | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.acking-jobs-ww-230.today | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.acklinkssites.mobi | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.acwibdisiga.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.adan.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.akeai.win | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.amarindhn.lol | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ancer-treatment-13131.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.antapgan.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.app.photography | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.appypost.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.av69.lat | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.avoredbuysspot.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.awyer-jp-6396164.live | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.aymentprocessinglb.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ayprocessingls.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.aysidewebdesign.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ccountgnailcom.live | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.dornmi.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.dqtfuj.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ea.tech | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.eafq987.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.echo.group | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.edmksa.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.edpwxcofxjfrkp.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.efresh.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.eleglarm.watch | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.elegmear.click | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.elegrams.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.endit.mobi | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.enuvae8.pro | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.eo3p.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.et-insurance-80325.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.etrootomatik.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.fdyqcoyex.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.front.biz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.g-36954.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.gdb.bid | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.goncca.art | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.heap-psychic-reading-us-889.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.hendai.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ianca.realtor | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.iasgirls.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ienvu.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.illpayfast-loan-experts.click | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.implysharp.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ingdomsecuritysolutions.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.inmaber.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.irs60.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ittzofme.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ivelyglimy.pro | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ixtemplates.pro | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.jgjvajurexadjw.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.jtmv.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.juuwb.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.kin-rejuvenation-84789.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.kytraders.university | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.lay-blazing-kingdom.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.layaiverse.live | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.lcht.bid | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.lfatouch.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.lfstudio.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.litedosug.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.log103powerbest.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.log99fastbest.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.lossom-and-bark.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.lumber-services-51937.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.mopkaruaricniosdalptcore.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ncca.bid | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.nfluencer.directory | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.nfostealattmarch2024.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ni-flow.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.nipkaruaroninasdalhome.cyou | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.nyankou.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ob-offer-46679.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.occer-camps-30515.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.odular-homes-39739.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.oinbgetw.pro | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.olbertconsulting.pro | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ome-care-70823.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ompciti.homes | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.onopolycontracting.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.onstruction-services-74050.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.oolai.homes | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ortis.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.osmetology-degrees-002.today | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.otten.city | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ouruguayaniixx0el.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ptaxi.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.r365131.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.rahyzwjshvj.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.rain-tours-es-5078.today | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ravelvistasxyz234.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.rinxelio.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.rmineroyli.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.rogrammer.expert | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.rouver-un-emploi-br.buzz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.rowhesap.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.rthodontist-73950.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ruck-driver-training-42235.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.s010.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.sl1.sbs | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.stikanafenyal.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.syylx.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.tdzknmgvrvxkeyftoz.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.tellardealsshowcase.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.tnjtgmorwbvak.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.trasbv.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.trtypoi.xyz | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.tu1.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.uel-fleet-cards-25316.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ugworksservices.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.unshangwuliujituanmei.top | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.uoym.net | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.urvio.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.utriments.beauty | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.uture-intimates.today | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.uv-deals-76094.bond | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.xljll.bid | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.xposvoharowvh.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.yhupbasybcxgbfbw.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ynix.design | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ypothequesinversee.today | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.ywebchallenge.info | Formbook botnet C2 domain (confidence level: 50%) | |
domainwww.zrotzkmfbntexfg.shop | Formbook botnet C2 domain (confidence level: 50%) | |
domainmasterpoldo02.kozow.com | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainvoltazur.ddns.net | DarkComet botnet C2 domain (confidence level: 50%) |
Url
Value | Description | Copy |
---|---|---|
urlhttps://check.uueye.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://greennquest.cyou/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://amasyaelmasi05.com/zjq2njg0mwjjnge0/ | Coper botnet C2 (confidence level: 100%) | |
urlhttp://154.29.79.29:6677/iremotepanel | RedLine Stealer botnet C2 (confidence level: 100%) | |
urlhttp://121.36.194.30:9999/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://check.ioyyu.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://softpaxth.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://clxearnest.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttp://23.94.25.236:8888/supershell/login | Unknown malware botnet C2 (confidence level: 50%) | |
urlhttps://pastebin.com/raw/4zaietzs | XWorm botnet C2 (confidence level: 50%) | |
urlhttps://mercharena.biz/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://generalmills.pro/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://zefnecho.cyou/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://stormlegue.com/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://blastikcn.com/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://nestlecompany.pro/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://blast-hubs.com/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://breedertremnd.com/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://whopeefreamed.com/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://check.yyiue.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://questeformeaning.cloud/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://judgesteam.icu/art.php | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://check.yuyoi.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://brightmhaven.cyou/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://u1.subtyperesource.shop/ranked.mp4 | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://check.ooyou.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://steamcommunity.com/profiles/76561199825403037 | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://t.me/b4cha00 | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://95.217.246.174/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://95.216.178.57/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://78.47.75.136/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://sailiabot.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://check.ououe.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://check.uoyou.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://5.75.215.216/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://t.me/cruadsummar | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://t.me/pullmeundervosk2 | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://95.216.179.187/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://t.me/pozebsub22442 | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://t.me/kuskas55991 | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://t.me/sausage22550 | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://49.13.32.185/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://check.iyeeu.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttp://www.1139.loan/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.1powerball.lat/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.32zf.top/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.68shop.cyou/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.85uz.top/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.adeupadult.pro/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.almainwebdesign.info/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.anda-casinoyyzz.top/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.andscaping-services-37849.bond/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.angbi-ndara.info/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.arriage-therapy-69521.bond/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.asinol.press/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.atcatdogdog.shop/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ccountant-jobs-30905.bond/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.cghvuwqpc.shop/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.dfght.xyz/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.dpe.bid/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ealpains.info/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.efenselenses.info/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.elationship-coach-72760.bond/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.elegramae.beauty/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.errywang.shop/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.estimport.biz/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.estosteronepower.sbs/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.eyryi.info/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.fhcoy.buzz/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.flrt.info/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.futbffod.top/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.griculture-jobs-13665.bond/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.helon.net/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ibrantzing.pro/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ime.shop/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.iv-test-13045.bond/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.kin-rejuvenation-70531.bond/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.log555fastbest.shop/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.log88ablebest.shop/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.log88optionbest.shop/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.log99facebest.shop/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.lvosuperfood.info/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.mandlaamasha.africa/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.mxtx97d.shop/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ocated-device.info/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.odafenptss.top/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.odfitness.net/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.om-ioiakwea.top/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.om-masshff.top/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.om-scseq.top/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.om-whupnf.top/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.omalaysianwebsitedirectory.shop/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.omfycornerco.click/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.onstruction-jobs-78291.bond/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.oreadefensearmy.net/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.otogel.pro/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ovabridge.tech/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.poredmalru999romero.live/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.pyubxrmfgdth.shop/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ravel-insurance-48465.bond/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.reamanddecor.net/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.reamgetaways234.xyz/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.redit-card-offers-de-5398.today/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ttv2ud.cyou/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.uvne.info/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.uyukgorus.click/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.verafter.shop/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.yfeboi8.pro/oi08/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttps://77.239.117.222/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://urbancraftz.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://fxreshecho.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://restfulrletreats.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://simpleupleasures.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://mysticjpath.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://artisnticexpressions.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://curitousminds.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://softnestl.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://frdiendlycommunity.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://crispvoyazge.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://clearhecho.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://dreamswiay.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://radiantenyergy.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://luckyfindps.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://starcruaft.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://calfmhaven.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://mystgicdawn.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://happbytrail.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://frershtrail.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://cwrispbreeze.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://spirmitedtravel.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://softbljoom.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://aexquisitecrafts.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://chverishedmoments.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://cwalmjourney.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://wisecrakft.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://happtyvibe.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://mysrticwave.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://wiesespark.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://festivevoibes.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://greennesqt.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://boldmeadozw.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://fclearcraft.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://www.mysticjpath.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://stafrmountain.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://crispnefst.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://dreamblizss.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://brighqthorizon.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://www.aclearbeam.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://cleqarjourney.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://www.zensphace.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://fresxhhaze.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://www.bsoldvista.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://check.iueyo.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://check.iyiao.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://check.iyyye.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://check.duwon.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://check.waxof.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://check.vidad.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://check.bitew.icu/gkcxv.google | ClearFake payload delivery URL (confidence level: 100%) | |
urlhttps://fashionghana.shop/work/original.js | FAKEUPDATES payload delivery URL (confidence level: 100%) | |
urlhttps://fashionghana.shop/work/index.php | FAKEUPDATES payload delivery URL (confidence level: 100%) | |
urlhttps://fashionghana.shop/work/file.php | FAKEUPDATES payload delivery URL (confidence level: 100%) | |
urlhttps://fashionghana.shop/work/files.zip | FAKEUPDATES payload delivery URL (confidence level: 100%) | |
urlhttp://cy10907.tw1.ru/8bf75526.php | DCRat botnet C2 (confidence level: 100%) | |
urlhttps://95.216.180.255/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://alwaysvahead.cloud/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://brightecfho.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://brizghtoasis.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://buqowai.shop/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://cozkeu.shop/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://cyqfuy.shop/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://dreamneist.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://drheahmweaver.top/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://frehshecho.top/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://fresqhsway.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://gewrye.shop/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://haqppycrest.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://lumfyginiu5.shop/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://mystictqrail.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://naiftheking.xyz/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://pureechzo.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://purequuest.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://puretmeadow.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://qsoftcove.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://quicksnhift.top/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://quievtstream.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://softzspring.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://starechoz.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://trueszpark.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://urbanouasis.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://wqiseoasis.cyou/api | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://5.252.155.64/ | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://api.telegram.org/bot6524461406:aah3tboejg5crfe0hbcmlee4xlbl6zeatik/ | Agent Tesla botnet C2 (confidence level: 50%) | |
urlhttps://pastebin.com/raw/2nrn2bsv | DCRat botnet C2 (confidence level: 50%) | |
urlhttps://pastebin.com/raw/kthpp2pd | XWorm botnet C2 (confidence level: 50%) | |
urlhttps://bit.ly/4cb3oaq | GlobeImposter botnet C2 (confidence level: 50%) | |
urlhttps://pastebin.com/raw/vrsch5uf | GlobeImposter botnet C2 (confidence level: 50%) | |
urlhttps://tinyurl.com/2s3b6mbb | GlobeImposter botnet C2 (confidence level: 50%) | |
urlhttps://akmedia.in/js/mail.php | GlobeImposter botnet C2 (confidence level: 50%) | |
urlhttps://mikhail-lermontov.com/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttp://81.161.229.110/htdocs/dwrbrqnfnbzmpds.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://37.139.129.142/htdocs/crjxfnpqeefbszb.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://37.139.129.142/htdocs/txgqfxfgbteajcy.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://109.206.241.81/htdocs/gyjetxnwnpksymb.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://81.161.229.110/htdocs/dyrknbtomnspala.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://37.139.129.142/htdocs/fmqaxqtoxtcebmw.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://81.161.229.110/htdocs/tdmzxjjcdosllka.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://81.161.229.110/htdocs/gbcjzcmfmpwrsyw.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://81.161.229.110/htdocs/telgrehflpzpyxs.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://37.139.129.142/htdocs/cgenmjejgczcdaf.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://81.161.229.110/htdocs/ycjrkwfhsmzteek.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://37.139.129.142/htdocs/omlfyzflewaeppc.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://81.161.229.110/htdocs/fqrbnkjbpwlwagp.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://81.161.229.110/htdocs/yishjpcdfghrgox.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://81.161.229.110/htdocs/rhygfcbkjtnyxxa.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://81.161.229.110/htdocs/reqxebqxklhwkzs.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://37.139.129.142/htdocs/tgqthgjlfkxmfdl.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://81.161.229.110/htdocs/pjqztgahsaeqlzw.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttp://37.139.129.142/htdocs/oamsdkwxeqbnjhc.exe | MASS Logger payload delivery URL (confidence level: 50%) | |
urlhttps://178.159.43.166/0028a0f3432ee7b2/vcruntime140.dll | Stealc payload delivery URL (confidence level: 50%) | |
urlhttps://94.232.249.208/c129a6f25cb7bf9b/sqlite3.dll | Stealc payload delivery URL (confidence level: 50%) | |
urlhttps://94.232.249.208/c129a6f25cb7bf9b/mozglue.dll | Stealc payload delivery URL (confidence level: 50%) | |
urlhttps://94.232.249.208/c129a6f25cb7bf9b/vcruntime140.dll | Stealc payload delivery URL (confidence level: 50%) | |
urlhttp://178.159.43.166/0028a0f3432ee7b2/sqlite3.dll | Stealc payload delivery URL (confidence level: 50%) | |
urlhttp://95.217.125.57/557b2ce3c387a13c/mozglue.dll | Stealc payload delivery URL (confidence level: 50%) | |
urlhttps://clsevermarketing.click/login | Lumma Stealer botnet C2 (confidence level: 50%) | |
urlhttps://ytdownload.resources.ink/video5314651 | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttp://www.024attdatastealmarch.net/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.3000.xyz/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.63738.baby/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.692.top/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.6ac664z.shop/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.abbiel-february351.cfd/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.acking-jobs-ww-230.today/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.acklinkssites.mobi/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.acwibdisiga.top/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.adan.shop/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.akeai.win/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.amarindhn.lol/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ancer-treatment-13131.bond/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.antapgan.xyz/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.app.photography/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.appypost.top/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.av69.lat/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.avoredbuysspot.shop/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.awyer-jp-6396164.live/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.aymentprocessinglb.top/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ayprocessingls.top/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.aysidewebdesign.net/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ccountgnailcom.live/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.dornmi.shop/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.dqtfuj.info/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ea.tech/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.eafq987.top/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.echo.group/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.edmksa.top/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.edpwxcofxjfrkp.shop/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.efresh.shop/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.eleglarm.watch/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.elegmear.click/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.elegrams.shop/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.endit.mobi/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.enuvae8.pro/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.eo3p.info/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.et-insurance-80325.bond/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.etrootomatik.net/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.fdyqcoyex.shop/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.front.biz/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.g-36954.top/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.gdb.bid/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.goncca.art/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.heap-psychic-reading-us-889.xyz/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.hendai.top/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ianca.realtor/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.iasgirls.net/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ienvu.net/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.illpayfast-loan-experts.click/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.implysharp.net/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ingdomsecuritysolutions.xyz/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.inmaber.xyz/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.irs60.top/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ittzofme.net/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ivelyglimy.pro/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ixtemplates.pro/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.jgjvajurexadjw.shop/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.jtmv.info/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.juuwb.shop/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.kin-rejuvenation-84789.bond/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.kytraders.university/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.lay-blazing-kingdom.xyz/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.layaiverse.live/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.lcht.bid/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.lfatouch.shop/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.lfstudio.xyz/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.litedosug.top/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.log103powerbest.shop/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.log99fastbest.shop/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.lossom-and-bark.net/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.lumber-services-51937.bond/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.mopkaruaricniosdalptcore.shop/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ncca.bid/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.nfluencer.directory/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.nfostealattmarch2024.net/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ni-flow.shop/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.nipkaruaroninasdalhome.cyou/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.nyankou.top/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ob-offer-46679.bond/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.occer-camps-30515.bond/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.odular-homes-39739.bond/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.oinbgetw.pro/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.olbertconsulting.pro/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ome-care-70823.bond/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ompciti.homes/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.onopolycontracting.net/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.onstruction-services-74050.bond/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.oolai.homes/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ortis.top/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.osmetology-degrees-002.today/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.otten.city/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ouruguayaniixx0el.shop/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ptaxi.net/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.r365131.xyz/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.rahyzwjshvj.shop/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.rain-tours-es-5078.today/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ravelvistasxyz234.xyz/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.rinxelio.top/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.rmineroyli.top/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.rogrammer.expert/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.rouver-un-emploi-br.buzz/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.rowhesap.xyz/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.rthodontist-73950.bond/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ruck-driver-training-42235.bond/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.s010.net/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.sl1.sbs/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.stikanafenyal.xyz/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.syylx.net/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.tdzknmgvrvxkeyftoz.shop/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.tellardealsshowcase.shop/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.tnjtgmorwbvak.shop/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.trasbv.xyz/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.trtypoi.xyz/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.tu1.info/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.uel-fleet-cards-25316.bond/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ugworksservices.net/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.unshangwuliujituanmei.top/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.uoym.net/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.urvio.shop/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.utriments.beauty/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.uture-intimates.today/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.uv-deals-76094.bond/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.xljll.bid/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.xposvoharowvh.shop/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.yhupbasybcxgbfbw.shop/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ynix.design/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ypothequesinversee.today/b101/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.ywebchallenge.info/da16/ | Formbook botnet C2 (confidence level: 50%) | |
urlhttp://www.zrotzkmfbntexfg.shop/b101/ | Formbook botnet C2 (confidence level: 50%) |
File
Value | Description | Copy |
---|---|---|
file38.207.132.101 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file206.81.6.248 | Sliver botnet C2 server (confidence level: 100%) | |
file121.40.128.171 | Sliver botnet C2 server (confidence level: 100%) | |
file118.99.98.155 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file20.73.75.104 | Unknown malware botnet C2 server (confidence level: 100%) | |
file176.65.134.77 | Hook botnet C2 server (confidence level: 100%) | |
file193.105.234.195 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file172.86.93.192 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file209.38.136.123 | Havoc botnet C2 server (confidence level: 100%) | |
file43.204.218.74 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file125.25.109.91 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file62.60.150.144 | Meduza Stealer botnet C2 server (confidence level: 100%) | |
file212.22.86.229 | MooBot botnet C2 server (confidence level: 100%) | |
file185.224.0.236 | MooBot botnet C2 server (confidence level: 100%) | |
file209.74.88.128 | Unknown malware botnet C2 server (confidence level: 100%) | |
file154.223.21.148 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file217.156.50.139 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file54.208.144.249 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file66.181.36.137 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file141.95.123.139 | Remcos botnet C2 server (confidence level: 100%) | |
file23.94.25.236 | Unknown malware botnet C2 server (confidence level: 100%) | |
file205.172.57.134 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file176.65.140.68 | Hook botnet C2 server (confidence level: 100%) | |
file85.192.29.60 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file94.156.177.91 | Venom RAT botnet C2 server (confidence level: 100%) | |
file46.246.4.2 | DCRat botnet C2 server (confidence level: 100%) | |
file157.230.225.92 | Sliver botnet C2 server (confidence level: 90%) | |
file66.42.81.50 | Unknown malware botnet C2 server (confidence level: 100%) | |
file212.34.149.75 | Unknown malware botnet C2 server (confidence level: 100%) | |
file44.229.7.211 | Unknown malware botnet C2 server (confidence level: 100%) | |
file142.93.223.55 | Unknown malware botnet C2 server (confidence level: 100%) | |
file3.136.15.74 | Unknown malware botnet C2 server (confidence level: 100%) | |
file165.232.143.1 | Unknown malware botnet C2 server (confidence level: 100%) | |
file54.86.5.48 | Unknown malware botnet C2 server (confidence level: 100%) | |
file158.160.18.227 | Unknown malware botnet C2 server (confidence level: 100%) | |
file13.60.211.133 | Unknown malware botnet C2 server (confidence level: 100%) | |
file3.39.104.170 | Unknown malware botnet C2 server (confidence level: 100%) | |
file192.241.191.212 | Unknown malware botnet C2 server (confidence level: 100%) | |
file116.254.118.155 | Unknown malware botnet C2 server (confidence level: 100%) | |
file16.171.22.28 | Unknown malware botnet C2 server (confidence level: 100%) | |
file104.234.50.59 | Unknown malware botnet C2 server (confidence level: 100%) | |
file193.143.1.121 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file101.200.38.121 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file122.114.169.63 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file172.86.107.183 | Sliver botnet C2 server (confidence level: 50%) | |
file147.185.221.26 | XWorm botnet C2 server (confidence level: 50%) | |
file103.68.109.212 | XWorm botnet C2 server (confidence level: 75%) | |
file121.36.27.251 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file123.57.175.239 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file139.180.221.1 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file204.194.65.134 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file47.92.122.62 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file185.211.4.26 | Unknown malware botnet C2 server (confidence level: 100%) | |
file219.143.134.210 | Havoc botnet C2 server (confidence level: 100%) | |
file35.180.133.55 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file212.22.86.234 | MooBot botnet C2 server (confidence level: 100%) | |
file8.219.95.83 | MimiKatz botnet C2 server (confidence level: 100%) | |
file154.221.16.181 | Sliver botnet C2 server (confidence level: 75%) | |
file16.16.26.1 | Sliver botnet C2 server (confidence level: 75%) | |
file64.69.41.70 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file98.159.108.138 | DanaBot botnet C2 server (confidence level: 75%) | |
file95.216.178.57 | Vidar botnet C2 server (confidence level: 100%) | |
file78.47.75.136 | Vidar botnet C2 server (confidence level: 100%) | |
file88.99.124.230 | Vidar botnet C2 server (confidence level: 100%) | |
file5.75.215.216 | Vidar botnet C2 server (confidence level: 100%) | |
file95.216.179.187 | Vidar botnet C2 server (confidence level: 100%) | |
file49.13.32.185 | Vidar botnet C2 server (confidence level: 100%) | |
file77.239.117.222 | Vidar botnet C2 server (confidence level: 100%) | |
file91.92.136.87 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
file49.0.243.129 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file47.119.189.207 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file47.111.146.110 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file45.62.170.61 | Remcos botnet C2 server (confidence level: 100%) | |
file46.246.86.12 | Remcos botnet C2 server (confidence level: 100%) | |
file178.215.224.50 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file93.123.109.202 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file45.154.98.68 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file176.65.134.239 | Hook botnet C2 server (confidence level: 100%) | |
file176.65.134.239 | Hook botnet C2 server (confidence level: 100%) | |
file144.34.163.218 | Havoc botnet C2 server (confidence level: 100%) | |
file3.8.96.179 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file194.5.192.21 | ERMAC botnet C2 server (confidence level: 100%) | |
file154.23.163.91 | MooBot botnet C2 server (confidence level: 100%) | |
file165.22.17.53 | MooBot botnet C2 server (confidence level: 100%) | |
file158.160.18.227 | Unknown malware botnet C2 server (confidence level: 100%) | |
file113.44.48.28 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file87.120.114.34 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file106.15.184.255 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file106.15.184.255 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file95.216.180.255 | Vidar botnet C2 server (confidence level: 100%) | |
file156.226.174.246 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file34.209.223.89 | Sliver botnet C2 server (confidence level: 100%) | |
file170.106.136.132 | Sliver botnet C2 server (confidence level: 100%) | |
file123.11.165.3 | Unknown malware botnet C2 server (confidence level: 100%) | |
file50.114.115.207 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file163.5.210.97 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file128.90.102.127 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file163.5.32.125 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file185.49.126.27 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file143.198.200.58 | Unknown malware botnet C2 server (confidence level: 100%) | |
file45.32.236.137 | Unknown malware botnet C2 server (confidence level: 100%) | |
file45.61.136.67 | Unknown malware botnet C2 server (confidence level: 75%) | |
file77.239.119.53 | Meduza Stealer botnet C2 server (confidence level: 100%) | |
file149.88.80.235 | MooBot botnet C2 server (confidence level: 100%) | |
file46.249.49.34 | Latrodectus botnet C2 server (confidence level: 75%) | |
file154.223.20.58 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file54.232.249.182 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file62.234.57.48 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file116.205.98.214 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file8.140.239.162 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file87.251.79.220 | Sliver botnet C2 server (confidence level: 50%) | |
file193.124.47.213 | Sliver botnet C2 server (confidence level: 50%) | |
file91.218.50.174 | Sliver botnet C2 server (confidence level: 50%) | |
file188.166.237.148 | Unknown malware botnet C2 server (confidence level: 50%) | |
file181.50.73.64 | Unknown malware botnet C2 server (confidence level: 50%) | |
file34.249.158.108 | NetSupportManager RAT botnet C2 server (confidence level: 50%) | |
file3.69.115.178 | DCRat botnet C2 server (confidence level: 50%) | |
file77.93.28.66 | XWorm botnet C2 server (confidence level: 50%) | |
file166.88.98.221 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file185.157.162.168 | Remcos botnet C2 server (confidence level: 100%) | |
file194.59.31.126 | Remcos botnet C2 server (confidence level: 100%) | |
file45.66.248.181 | Remcos botnet C2 server (confidence level: 100%) | |
file185.7.214.250 | Remcos botnet C2 server (confidence level: 100%) | |
file107.173.62.67 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file186.169.60.145 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file54.145.59.120 | Unknown malware botnet C2 server (confidence level: 100%) | |
file85.209.128.159 | Unknown malware botnet C2 server (confidence level: 100%) | |
file176.65.134.77 | Hook botnet C2 server (confidence level: 100%) | |
file93.183.91.123 | Hook botnet C2 server (confidence level: 100%) | |
file211.149.227.147 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file40.66.43.203 | Havoc botnet C2 server (confidence level: 100%) | |
file192.142.18.32 | Havoc botnet C2 server (confidence level: 100%) | |
file46.246.82.30 | DCRat botnet C2 server (confidence level: 100%) | |
file65.0.73.139 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file64.52.80.81 | Unknown malware botnet C2 server (confidence level: 75%) | |
file194.147.98.238 | Kaiji botnet C2 server (confidence level: 100%) | |
file185.156.110.13 | Stealc botnet C2 server (confidence level: 100%) | |
file31.172.87.193 | Unknown malware botnet C2 server (confidence level: 100%) | |
file134.255.232.64 | Unknown malware botnet C2 server (confidence level: 100%) | |
file161.10.153.176 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file150.241.113.219 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file154.29.138.77 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file119.8.116.145 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file165.154.245.30 | Unknown malware botnet C2 server (confidence level: 75%) | |
file191.234.214.190 | Sliver botnet C2 server (confidence level: 50%) | |
file181.50.73.64 | Unknown malware botnet C2 server (confidence level: 50%) | |
file34.56.177.4 | DanaBot botnet C2 server (confidence level: 75%) | |
file35.205.12.222 | DanaBot botnet C2 server (confidence level: 75%) | |
file38.50.164.55 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file5.163.173.51 | QakBot botnet C2 server (confidence level: 75%) | |
file98.159.108.137 | DanaBot botnet C2 server (confidence level: 75%) | |
file99.112.198.252 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file38.54.57.191 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file44.210.161.64 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file89.116.211.244 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file131.0.150.232 | NjRAT botnet C2 server (confidence level: 100%) | |
file156.226.174.246 | Cobalt Strike botnet C2 server (confidence level: 75%) |
Hash
Value | Description | Copy |
---|---|---|
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash4443 | Sliver botnet C2 server (confidence level: 100%) | |
hash37001 | Sliver botnet C2 server (confidence level: 100%) | |
hash10549 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8089 | Hook botnet C2 server (confidence level: 100%) | |
hash10000 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash4000 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash40056 | Havoc botnet C2 server (confidence level: 100%) | |
hash16166 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash7443 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash80 | Meduza Stealer botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hash33006 | MooBot botnet C2 server (confidence level: 100%) | |
hash4000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash4043 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash17777 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8089 | Hook botnet C2 server (confidence level: 100%) | |
hash222 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash4449 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash8080 | DCRat botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 90%) | |
hash60000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8080 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3311 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash9669 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash391d8959d1d506992ce4ede8c6ffc94a | 8Base payload (confidence level: 50%) | |
hash2345 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash1316 | XWorm botnet C2 server (confidence level: 50%) | |
hash5000 | XWorm botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8010 | Havoc botnet C2 server (confidence level: 100%) | |
hash4839 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hash8080 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash8888 | Sliver botnet C2 server (confidence level: 75%) | |
hash443 | Sliver botnet C2 server (confidence level: 75%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | DanaBot botnet C2 server (confidence level: 75%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash26264 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
hash8081 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8090 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash2525 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash4444 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash6606 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash80 | Hook botnet C2 server (confidence level: 100%) | |
hash8089 | Hook botnet C2 server (confidence level: 100%) | |
hash8001 | Havoc botnet C2 server (confidence level: 100%) | |
hash5986 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash8082 | ERMAC botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash50012 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash55413 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash80 | Sliver botnet C2 server (confidence level: 100%) | |
hash5873 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash5000 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash80 | Meduza Stealer botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hash443 | Latrodectus botnet C2 server (confidence level: 75%) | |
hash2087 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash50050 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash50050 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 50%) | |
hash44822 | Unknown malware botnet C2 server (confidence level: 50%) | |
hash12101 | NetSupportManager RAT botnet C2 server (confidence level: 50%) | |
hash12672 | DCRat botnet C2 server (confidence level: 50%) | |
hash2323 | XWorm botnet C2 server (confidence level: 50%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash557 | Remcos botnet C2 server (confidence level: 100%) | |
hash3939 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash11103 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Hook botnet C2 server (confidence level: 100%) | |
hash2053 | Hook botnet C2 server (confidence level: 100%) | |
hash4782 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash8080 | DCRat botnet C2 server (confidence level: 100%) | |
hash35549 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash10081 | Kaiji botnet C2 server (confidence level: 100%) | |
hash443 | Stealc botnet C2 server (confidence level: 100%) | |
hash4000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash7575 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8384 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash8033 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash60000 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash44722 | Unknown malware botnet C2 server (confidence level: 50%) | |
hash443 | DanaBot botnet C2 server (confidence level: 75%) | |
hash443 | DanaBot botnet C2 server (confidence level: 75%) | |
hash8443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | QakBot botnet C2 server (confidence level: 75%) | |
hash443 | DanaBot botnet C2 server (confidence level: 75%) | |
hash8080 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash53 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash53 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash53 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash9000 | NjRAT botnet C2 server (confidence level: 100%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 75%) |
Threat ID: 682c7dc0e8347ec82d2d460b
Added to database: 5/20/2025, 1:04:00 PM
Last enriched: 6/19/2025, 4:18:15 PM
Last updated: 7/31/2025, 2:08:50 PM
Views: 7
Related Threats
ThreatFox IOCs for 2025-08-16
MediumScammers Compromised by Own Malware, Expose $4.67M Operation and Identities
MediumThreatFox IOCs for 2025-08-15
MediumThreat Actor Profile: Interlock Ransomware
Medium'Blue Locker' Analysis: Ransomware Targeting Oil & Gas Sector in Pakistan
MediumActions
Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.