Skip to main content

ThreatFox IOCs for 2025-02-15

Medium
Published: Sat Feb 15 2025 (02/15/2025, 00:00:00 UTC)
Source: ThreatFox
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-02-15

AI-Powered Analysis

AILast updated: 06/19/2025, 15:33:04 UTC

Technical Analysis

The provided threat intelligence pertains to a malware-related report titled 'ThreatFox IOCs for 2025-02-15,' sourced from ThreatFox, an OSINT (Open Source Intelligence) platform. The report primarily serves as a collection of Indicators of Compromise (IOCs) related to malware activity observed or compiled on the specified date. However, the technical details are minimal, indicating a threat level of 2 (on an unspecified scale), an analysis rating of 1, and a distribution rating of 3, suggesting moderate dissemination potential. No specific affected software versions, vulnerabilities, or exploit details are provided, and there are no known exploits in the wild associated with this malware at the time of publication. The absence of CWE identifiers and patch links further implies that this is an intelligence aggregation rather than a detailed vulnerability disclosure. The threat is tagged as 'type:osint' and marked with TLP:white, indicating that the information is intended for wide distribution without restrictions. Overall, this intelligence appears to be an early-stage or low-confidence alert about malware-related activity, emphasizing the presence of IOCs that could be used for detection and monitoring rather than immediate exploitation or active attacks.

Potential Impact

Given the limited technical details and the absence of known exploits, the immediate impact on European organizations is likely low to medium. However, the presence of malware-related IOCs suggests potential reconnaissance or preparatory phases of cyberattacks that could evolve into more severe incidents if leveraged by threat actors. European organizations relying on OSINT tools or threat intelligence platforms may benefit from integrating these IOCs into their detection mechanisms to enhance situational awareness. The malware’s distribution rating of 3 indicates a moderate spread, which could affect organizations with less mature cybersecurity defenses. Potential impacts include unauthorized access, data exfiltration, or disruption if the malware is later weaponized. The lack of authentication or user interaction details limits precise impact assessment, but organizations in critical infrastructure, finance, and government sectors should remain vigilant due to their strategic importance and attractiveness to threat actors.

Mitigation Recommendations

1. Integrate the provided IOCs into existing Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) systems to enable early detection of related malware activity. 2. Conduct regular threat hunting exercises focusing on the identified IOCs to uncover any latent infections or suspicious activities. 3. Enhance network segmentation and apply strict access controls to limit lateral movement in case of compromise. 4. Maintain up-to-date backups and verify their integrity to ensure rapid recovery from potential malware-induced disruptions. 5. Educate security teams on the evolving threat landscape, emphasizing the importance of OSINT in proactive defense. 6. Collaborate with national Computer Emergency Response Teams (CERTs) and share intelligence to improve collective defense capabilities. 7. Since no patches or CVEs are associated, focus on behavioral detection and anomaly monitoring rather than patch management for this specific threat.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
7e419c00-aa84-4240-9e74-debecbfa8f21
Original Timestamp
1739664187

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://check.limev.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.qahov.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://quiwetwaveso.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttp://a1083519.xsph.ru/351a63c9.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://check.qojyx.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://www.06ks7.club/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.4rcraft.online/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.92.info/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ackcleveland.biz/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ahjongwins3.cyou/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.aifunclub.fit/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.aixabank.video/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.aklandpt.net/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ancasterequinemassage.net/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.aromzeciri.shop/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.bewuxi.info/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.cassg.net/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.commerce-69321.bond/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.d97.lat/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.dhd-treatment-42199.bond/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ealthyzone.live/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.enamind.net/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.engdianertian.vip/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.estrated.xyz/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.eziser.fun/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ghkp.shop/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.havuonvanthanh.store/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.hinoplasty-solutions.sbs/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.hiteelephant.online/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.igsawgame.xyz/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.illyjolly.online/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.izalmart.shop/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.kipthegaames.online/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.laygroundsequipment.xyz/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.litz.baby/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.lossar.online/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.lugsq.info/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.lysiannails.art/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.mazonworld.store/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.nfluencer-marketing-38653.bond/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.nfoviral99.xyz/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.nitogel.skin/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.nline-advertising-37613.bond/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.obotquote.net/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.olarmedia.xyz/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.onja.shop/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ookcovers.xyz/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.oomoo.store/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.oppyworld.fun/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.panda.xyz/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.r210.info/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.rbantravelstories.online/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.regnancy-67873.bond/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.rginine555.store/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.rilby.store/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.rokidu.info/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.rotableblender.online/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.rpa.club/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.uabf.info/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.uivlio.xyz/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.unaid-jamshed.shop/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.unisitri.net/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.uto-loans-in-africa-2024.today/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.wefright.net/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.wnyourhealth.xyz/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.y01.vip/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.yallergies.online/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ynthesizerwf.store/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.yskillandyou.xyz/o10c/
Formbook botnet C2 (confidence level: 50%)
urlhttp://95.182.97.58/126d33f6b8f9bd61/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://80.85.241.225/884af7b2dd911e85/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://77.91.76.36/f059ec3d7eb90876/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://217.196.96.228/6d24030469a6b14b/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://194.87.29.53/97f9710b31d15029/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://95.215.204.229/3b4b68059f902c42/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://178.159.43.166/0028a0f3432ee7b2/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://83.222.191.225/2938eb1cc484fea4/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://grzeenbreeze.cyou/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://floweringtstrip.help/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://aheadrarry.help/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://joyfulnhest.top/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://185.215.113.209/di0her478/login.php
Amadey botnet C2 (confidence level: 50%)
urlhttp://207.174.28.89:8888/supershell/login
Unknown malware botnet C2 (confidence level: 50%)
urlhttp://194.26.192.33/
Hook botnet C2 (confidence level: 50%)
urlhttp://124.71.228.177:9991/
Chaos botnet C2 (confidence level: 50%)
urlhttp://www.sistemasinaionline.com.br/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://oceanbreoeze.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://pastebin.com/raw/xquvknar
AsyncRAT botnet C2 (confidence level: 50%)
urlhttps://u1.sulkuntie.shop/shredder.m4a
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://196.251.118.76:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://thwrivenest.top/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://lightojourney.top/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://www.sistemasinaionline.com.br/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://check.kybax.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://d1ie3z.com/login.html
Unknown Stealer botnet C2 (confidence level: 75%)
urlhttps://porannyrozruch.pl/ran_h_estia
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://check.nuviq.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.cigog.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://65.108.88.44/
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://check.falih.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.myvyt.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.zovof.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.cobyw.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.zamoq.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://80.78.26.62/
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://friendseforever.help/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://naturewsounds.help/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttp://pw402.castledev.ru/externalhttpgameflowerwordpress.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://20.74.209.192:4446/zx5v
Cobalt Strike botnet C2 (confidence level: 75%)
urlhttp://a1081046.xsph.ru/3023968f.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://ce11914.tw1.ru/53580e28.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://557844cm.nyashnyash.ru/_packetupdateapibasegeneratoruniversallocalpublic.php
DCRat botnet C2 (confidence level: 100%)

Domain

ValueDescriptionCopy
domaincheck.qahov.icu
ClearFake payload delivery domain (confidence level: 100%)
domainboldquestq.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincalmquzest.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaingrzeenbreeze.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainsoftdaqwn.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainsoftpafthway.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaintruefbloom.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainurbantraoil.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainzengardxen.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainskywarddnream.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainflourishpyoint.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainswafeharbor.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainjoyfulnhest.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainhoarmonynest.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainpurehnorizon.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainechhopoint.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainwww.assignmenttelevision.info
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainminndfulpath.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainwisyefuture.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainviytalburst.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainimoaginesphere.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainelevatemyind.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainmotivaotedsoul.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainkindsprohut.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincld.cnkalciwcm.online
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainega.serveblog.net
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainhook.dayangpay.com
Hook botnet C2 domain (confidence level: 100%)
domainsso.demoforecl.in
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainec2-52-74-224-241.ap-southeast-1.compute.amazonaws.com
Hook botnet C2 domain (confidence level: 100%)
domaincheck.qojyx.icu
ClearFake payload delivery domain (confidence level: 100%)
domainwww.-avi.art
Formbook botnet C2 domain (confidence level: 50%)
domainwww.06ks7.club
Formbook botnet C2 domain (confidence level: 50%)
domainwww.4rcraft.online
Formbook botnet C2 domain (confidence level: 50%)
domainwww.92.info
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ackcleveland.biz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ahjongwins3.cyou
Formbook botnet C2 domain (confidence level: 50%)
domainwww.aifunclub.fit
Formbook botnet C2 domain (confidence level: 50%)
domainwww.aixabank.video
Formbook botnet C2 domain (confidence level: 50%)
domainwww.aklandpt.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ancasterequinemassage.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.aromzeciri.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.bewuxi.info
Formbook botnet C2 domain (confidence level: 50%)
domainwww.cassg.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.commerce-69321.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.d97.lat
Formbook botnet C2 domain (confidence level: 50%)
domainwww.dhd-treatment-42199.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ealthyzone.live
Formbook botnet C2 domain (confidence level: 50%)
domainwww.enamind.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.engdianertian.vip
Formbook botnet C2 domain (confidence level: 50%)
domainwww.estrated.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.eziser.fun
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ghkp.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.havuonvanthanh.store
Formbook botnet C2 domain (confidence level: 50%)
domainwww.hinoplasty-solutions.sbs
Formbook botnet C2 domain (confidence level: 50%)
domainwww.hiteelephant.online
Formbook botnet C2 domain (confidence level: 50%)
domainwww.igsawgame.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.illyjolly.online
Formbook botnet C2 domain (confidence level: 50%)
domainwww.izalmart.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.kipthegaames.online
Formbook botnet C2 domain (confidence level: 50%)
domainwww.laygroundsequipment.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.litz.baby
Formbook botnet C2 domain (confidence level: 50%)
domainwww.lossar.online
Formbook botnet C2 domain (confidence level: 50%)
domainwww.lugsq.info
Formbook botnet C2 domain (confidence level: 50%)
domainwww.lysiannails.art
Formbook botnet C2 domain (confidence level: 50%)
domainwww.mazonworld.store
Formbook botnet C2 domain (confidence level: 50%)
domainwww.nfluencer-marketing-38653.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.nfoviral99.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.nitogel.skin
Formbook botnet C2 domain (confidence level: 50%)
domainwww.nline-advertising-37613.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.obotquote.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.olarmedia.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.onja.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ookcovers.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.oomoo.store
Formbook botnet C2 domain (confidence level: 50%)
domainwww.oppyworld.fun
Formbook botnet C2 domain (confidence level: 50%)
domainwww.panda.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.r210.info
Formbook botnet C2 domain (confidence level: 50%)
domainwww.rbantravelstories.online
Formbook botnet C2 domain (confidence level: 50%)
domainwww.regnancy-67873.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.rginine555.store
Formbook botnet C2 domain (confidence level: 50%)
domainwww.rilby.store
Formbook botnet C2 domain (confidence level: 50%)
domainwww.rokidu.info
Formbook botnet C2 domain (confidence level: 50%)
domainwww.rotableblender.online
Formbook botnet C2 domain (confidence level: 50%)
domainwww.rpa.club
Formbook botnet C2 domain (confidence level: 50%)
domainwww.uabf.info
Formbook botnet C2 domain (confidence level: 50%)
domainwww.uivlio.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.unaid-jamshed.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.unisitri.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.uto-loans-in-africa-2024.today
Formbook botnet C2 domain (confidence level: 50%)
domainwww.wefright.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.wnyourhealth.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.y01.vip
Formbook botnet C2 domain (confidence level: 50%)
domainwww.yallergies.online
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ynthesizerwf.store
Formbook botnet C2 domain (confidence level: 50%)
domainwww.yskillandyou.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainhoneypie.r-e.kr
Mirai botnet C2 domain (confidence level: 50%)
domainhwhm.cc5.us.kg
Mirai botnet C2 domain (confidence level: 50%)
domainzcjs888.cfd
Mirai botnet C2 domain (confidence level: 50%)
domainfevereiro2025.duckdns.org
NjRAT botnet C2 domain (confidence level: 50%)
domaintown-brand.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domaineecsys.com
FAKEUPDATES payload delivery domain (confidence level: 50%)
domain11111111111111111111111111111111111111112ewdsacafa-32954.portmap.host
AsyncRAT botnet C2 domain (confidence level: 50%)
domainmirai.cinquento.publicvm.com
Mirai botnet C2 domain (confidence level: 50%)
domainoctothl.ddnsfree.com
Quasar RAT botnet C2 domain (confidence level: 50%)
domainu1.sulkuntie.shop
ClearFake payload delivery domain (confidence level: 100%)
domaindynamicyspace.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainnewhoriozons.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainlightojourney.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainboldcyanvas.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainopenncanvas.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainkaleoidoscopewa.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincheck.kybax.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincheck.nuviq.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincheck.cigog.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincs.lihualihua266.us.kg
Cobalt Strike botnet C2 domain (confidence level: 75%)
domaincheck.falih.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincheck.myvyt.icu
ClearFake payload delivery domain (confidence level: 100%)
domainwww.iq-insitute.org
Unknown Stealer payload delivery domain (confidence level: 100%)
domaindamn.biggay.space
Mirai botnet C2 domain (confidence level: 75%)
domaincheck.zovof.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincheck.cobyw.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincheck.zamoq.icu
ClearFake payload delivery domain (confidence level: 100%)
domaingoshow.click
Unknown malware payload delivery domain (confidence level: 100%)
domainprograms.edlester.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainshewaswalking.ddns.net
AsyncRAT botnet C2 domain (confidence level: 50%)
domainbot.weizaipay.xyz
Mirai botnet C2 domain (confidence level: 50%)
domainmikeykarby-41864.portmap.host
Quasar RAT botnet C2 domain (confidence level: 50%)
domainapply-sand.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domainrighqthorizon.cyou
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainarea51.at.bitthebyte.com
Cobalt Strike botnet C2 domain (confidence level: 75%)

File

ValueDescriptionCopy
file124.71.228.177
Chaos botnet C2 server (confidence level: 100%)
file51.15.15.47
Cobalt Strike botnet C2 server (confidence level: 100%)
file176.65.141.64
Remcos botnet C2 server (confidence level: 100%)
file172.111.216.71
Remcos botnet C2 server (confidence level: 100%)
file172.111.137.68
Remcos botnet C2 server (confidence level: 100%)
file206.123.152.48
Remcos botnet C2 server (confidence level: 100%)
file45.133.180.154
AsyncRAT botnet C2 server (confidence level: 100%)
file191.96.207.227
AsyncRAT botnet C2 server (confidence level: 100%)
file18.143.214.68
Hook botnet C2 server (confidence level: 100%)
file52.74.224.241
Hook botnet C2 server (confidence level: 100%)
file88.80.148.30
Quasar RAT botnet C2 server (confidence level: 100%)
file78.135.93.218
Havoc botnet C2 server (confidence level: 100%)
file201.43.52.170
Havoc botnet C2 server (confidence level: 100%)
file91.209.135.199
Unknown malware botnet C2 server (confidence level: 100%)
file24.152.38.77
NjRAT botnet C2 server (confidence level: 100%)
file18.130.134.61
Cobalt Strike botnet C2 server (confidence level: 75%)
file40.112.213.212
Cobalt Strike botnet C2 server (confidence level: 75%)
file52.71.181.100
Cobalt Strike botnet C2 server (confidence level: 75%)
file95.179.141.132
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.239.165.225
Cobalt Strike botnet C2 server (confidence level: 100%)
file193.23.3.29
Remcos botnet C2 server (confidence level: 100%)
file191.96.207.75
AsyncRAT botnet C2 server (confidence level: 100%)
file181.41.194.91
AsyncRAT botnet C2 server (confidence level: 100%)
file18.118.47.63
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file194.85.251.38
Bashlite botnet C2 server (confidence level: 100%)
file96.9.124.130
Latrodectus botnet C2 server (confidence level: 75%)
file144.24.203.92
Unknown malware botnet C2 server (confidence level: 100%)
file139.162.8.226
Unknown malware botnet C2 server (confidence level: 100%)
file45.56.126.247
Unknown malware botnet C2 server (confidence level: 100%)
file139.144.198.214
Unknown malware botnet C2 server (confidence level: 100%)
file172.233.120.84
Unknown malware botnet C2 server (confidence level: 100%)
file45.56.67.65
Unknown malware botnet C2 server (confidence level: 100%)
file172.236.32.251
Unknown malware botnet C2 server (confidence level: 100%)
file139.144.210.30
Unknown malware botnet C2 server (confidence level: 100%)
file172.235.174.215
Unknown malware botnet C2 server (confidence level: 100%)
file172.236.212.22
Unknown malware botnet C2 server (confidence level: 100%)
file45.56.126.27
Unknown malware botnet C2 server (confidence level: 100%)
file172.236.131.202
Unknown malware botnet C2 server (confidence level: 100%)
file172.233.120.168
Unknown malware botnet C2 server (confidence level: 100%)
file45.79.22.72
Unknown malware botnet C2 server (confidence level: 100%)
file170.187.142.123
Unknown malware botnet C2 server (confidence level: 100%)
file91.208.240.178
Unknown malware botnet C2 server (confidence level: 100%)
file44.229.7.211
Unknown malware botnet C2 server (confidence level: 100%)
file45.152.65.126
Unknown malware botnet C2 server (confidence level: 100%)
file64.23.191.114
Unknown malware botnet C2 server (confidence level: 100%)
file3.209.210.98
Unknown malware botnet C2 server (confidence level: 100%)
file191.113.105.175
Unknown malware botnet C2 server (confidence level: 100%)
file18.188.97.184
Unknown malware botnet C2 server (confidence level: 100%)
file113.45.247.53
Unknown malware botnet C2 server (confidence level: 100%)
file13.61.104.185
Unknown malware botnet C2 server (confidence level: 100%)
file3.80.158.35
Unknown malware botnet C2 server (confidence level: 100%)
file195.13.250.6
Unknown malware botnet C2 server (confidence level: 100%)
file52.28.140.148
Unknown malware botnet C2 server (confidence level: 100%)
file130.193.38.97
Unknown malware botnet C2 server (confidence level: 100%)
file13.212.252.171
Unknown malware botnet C2 server (confidence level: 100%)
file129.148.50.46
Unknown malware botnet C2 server (confidence level: 100%)
file45.128.233.86
Bashlite botnet C2 server (confidence level: 75%)
file54.225.170.245
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file181.50.73.64
Unknown malware botnet C2 server (confidence level: 50%)
file172.94.53.178
Remcos botnet C2 server (confidence level: 100%)
file196.251.118.49
Remcos botnet C2 server (confidence level: 100%)
file85.239.232.11
AsyncRAT botnet C2 server (confidence level: 50%)
file45.154.98.68
AsyncRAT botnet C2 server (confidence level: 50%)
file196.251.116.95
AsyncRAT botnet C2 server (confidence level: 50%)
file45.137.194.110
AsyncRAT botnet C2 server (confidence level: 50%)
file192.3.238.130
AsyncRAT botnet C2 server (confidence level: 50%)
file185.49.126.52
AsyncRAT botnet C2 server (confidence level: 100%)
file185.49.126.166
AsyncRAT botnet C2 server (confidence level: 100%)
file185.49.126.166
AsyncRAT botnet C2 server (confidence level: 100%)
file36.50.233.24
Quasar RAT botnet C2 server (confidence level: 100%)
file20.62.9.174
Sliver botnet C2 server (confidence level: 50%)
file20.173.41.208
Sliver botnet C2 server (confidence level: 50%)
file67.217.228.7
Sliver botnet C2 server (confidence level: 50%)
file94.131.101.85
Unknown malware botnet C2 server (confidence level: 75%)
file31.171.131.83
MooBot botnet C2 server (confidence level: 100%)
file95.38.89.121
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file13.208.172.53
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file13.208.172.53
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file209.97.146.219
BianLian botnet C2 server (confidence level: 100%)
file209.97.146.219
BianLian botnet C2 server (confidence level: 100%)
file103.243.25.70
Cobalt Strike botnet C2 server (confidence level: 50%)
file39.105.211.255
Cobalt Strike botnet C2 server (confidence level: 50%)
file13.40.64.210
BlackShades botnet C2 server (confidence level: 50%)
file185.196.8.77
Broomstick botnet C2 server (confidence level: 50%)
file13.246.194.171
NetSupportManager RAT botnet C2 server (confidence level: 75%)
file154.92.19.71
Sliver botnet C2 server (confidence level: 75%)
file193.124.47.213
Sliver botnet C2 server (confidence level: 75%)
file216.235.95.100
DeimosC2 botnet C2 server (confidence level: 75%)
file216.235.95.100
DeimosC2 botnet C2 server (confidence level: 75%)
file216.235.95.100
DeimosC2 botnet C2 server (confidence level: 75%)
file216.235.95.100
DeimosC2 botnet C2 server (confidence level: 75%)
file216.235.95.100
DeimosC2 botnet C2 server (confidence level: 75%)
file216.235.95.100
DeimosC2 botnet C2 server (confidence level: 75%)
file216.235.95.100
DeimosC2 botnet C2 server (confidence level: 75%)
file216.235.95.100
DeimosC2 botnet C2 server (confidence level: 75%)
file216.235.95.100
DeimosC2 botnet C2 server (confidence level: 75%)
file216.235.95.100
DeimosC2 botnet C2 server (confidence level: 75%)
file216.235.95.100
DeimosC2 botnet C2 server (confidence level: 75%)
file216.235.95.100
DeimosC2 botnet C2 server (confidence level: 75%)
file3.113.143.58
DeimosC2 botnet C2 server (confidence level: 75%)
file70.31.125.182
QakBot botnet C2 server (confidence level: 75%)
file159.89.98.93
Meterpreter botnet C2 server (confidence level: 75%)
file39.106.5.215
Cobalt Strike botnet C2 server (confidence level: 75%)
file189.14.46.162
Quasar RAT botnet C2 server (confidence level: 100%)
file193.161.193.99
AsyncRAT botnet C2 server (confidence level: 50%)
file118.122.8.157
Unknown malware botnet C2 server (confidence level: 50%)
file117.212.114.253
Ghost RAT botnet C2 server (confidence level: 50%)
file166.88.55.54
Cobalt Strike botnet C2 server (confidence level: 50%)
file198.98.54.209
Cobalt Strike botnet C2 server (confidence level: 50%)
file107.172.140.197
Cobalt Strike botnet C2 server (confidence level: 50%)
file47.100.68.73
Cobalt Strike botnet C2 server (confidence level: 50%)
file144.48.8.190
Cobalt Strike botnet C2 server (confidence level: 50%)
file218.30.103.130
Cobalt Strike botnet C2 server (confidence level: 50%)
file45.144.214.126
Remcos botnet C2 server (confidence level: 100%)
file66.181.36.133
Cobalt Strike botnet C2 server (confidence level: 100%)
file101.36.117.41
Cobalt Strike botnet C2 server (confidence level: 100%)
file50.114.115.207
AsyncRAT botnet C2 server (confidence level: 100%)
file108.181.174.200
AsyncRAT botnet C2 server (confidence level: 100%)
file69.48.202.241
AsyncRAT botnet C2 server (confidence level: 100%)
file163.5.32.127
AsyncRAT botnet C2 server (confidence level: 100%)
file69.166.230.200
AsyncRAT botnet C2 server (confidence level: 100%)
file4.234.160.148
Havoc botnet C2 server (confidence level: 100%)
file196.251.90.56
DCRat botnet C2 server (confidence level: 100%)
file196.251.90.57
DCRat botnet C2 server (confidence level: 100%)
file13.208.181.173
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file156.238.230.148
Unknown malware botnet C2 server (confidence level: 100%)
file43.242.203.34
Cobalt Strike botnet C2 server (confidence level: 100%)
file195.88.218.77
Unknown Stealer botnet C2 server (confidence level: 75%)
file73.192.73.7
Unknown Stealer botnet C2 server (confidence level: 75%)
file89.117.38.234
Cobalt Strike botnet C2 server (confidence level: 75%)
file156.229.232.154
Mirai botnet C2 server (confidence level: 75%)
file103.214.71.8
Mirai botnet C2 server (confidence level: 75%)
file106.15.184.255
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.98.175.135
Cobalt Strike botnet C2 server (confidence level: 100%)
file175.178.114.8
Cobalt Strike botnet C2 server (confidence level: 100%)
file3.27.46.197
Sliver botnet C2 server (confidence level: 100%)
file185.49.126.245
AsyncRAT botnet C2 server (confidence level: 100%)
file191.96.207.172
AsyncRAT botnet C2 server (confidence level: 100%)
file191.96.207.172
AsyncRAT botnet C2 server (confidence level: 100%)
file34.174.254.138
AsyncRAT botnet C2 server (confidence level: 100%)
file185.49.126.235
AsyncRAT botnet C2 server (confidence level: 100%)
file191.96.207.75
AsyncRAT botnet C2 server (confidence level: 100%)
file191.96.207.75
AsyncRAT botnet C2 server (confidence level: 100%)
file108.61.217.60
AsyncRAT botnet C2 server (confidence level: 100%)
file191.96.207.168
AsyncRAT botnet C2 server (confidence level: 100%)
file191.96.207.168
AsyncRAT botnet C2 server (confidence level: 100%)
file185.211.4.26
Unknown malware botnet C2 server (confidence level: 100%)
file176.65.140.68
Hook botnet C2 server (confidence level: 100%)
file35.78.180.139
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file147.45.178.55
Stealc botnet C2 server (confidence level: 100%)
file147.185.221.25
NjRAT botnet C2 server (confidence level: 100%)
file185.222.58.36
RedLine Stealer botnet C2 server (confidence level: 100%)
file101.36.117.41
Cobalt Strike botnet C2 server (confidence level: 50%)
file196.251.116.95
AsyncRAT botnet C2 server (confidence level: 50%)
file20.74.209.192
Meterpreter botnet C2 server (confidence level: 100%)
file45.137.22.234
RedLine Stealer botnet C2 server (confidence level: 100%)
file195.211.190.227
Quasar RAT botnet C2 server (confidence level: 100%)
file51.15.15.47
Cobalt Strike botnet C2 server (confidence level: 75%)

Hash

ValueDescriptionCopy
hash9991
Chaos botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2889
Remcos botnet C2 server (confidence level: 100%)
hash3191
Remcos botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8888
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash1604
Quasar RAT botnet C2 server (confidence level: 100%)
hash8443
Havoc botnet C2 server (confidence level: 100%)
hash8081
Havoc botnet C2 server (confidence level: 100%)
hash4000
Unknown malware botnet C2 server (confidence level: 100%)
hash481
NjRAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2004
AsyncRAT botnet C2 server (confidence level: 100%)
hash6004
AsyncRAT botnet C2 server (confidence level: 100%)
hash4840
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash8080
Bashlite botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 75%)
hash5000
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash1497
Unknown malware botnet C2 server (confidence level: 100%)
hash771
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash830
Unknown malware botnet C2 server (confidence level: 100%)
hash103
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash536
Unknown malware botnet C2 server (confidence level: 100%)
hash286
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash88
Unknown malware botnet C2 server (confidence level: 100%)
hash623
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash33335
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash18080
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash666
Bashlite botnet C2 server (confidence level: 75%)
hash443
Unknown malware botnet C2 server (confidence level: 50%)
hash49322
Unknown malware botnet C2 server (confidence level: 50%)
hash44622
Unknown malware botnet C2 server (confidence level: 50%)
hash17527
Remcos botnet C2 server (confidence level: 100%)
hash789
Remcos botnet C2 server (confidence level: 100%)
hash5555
AsyncRAT botnet C2 server (confidence level: 50%)
hash5555
AsyncRAT botnet C2 server (confidence level: 50%)
hash5555
AsyncRAT botnet C2 server (confidence level: 50%)
hash5555
AsyncRAT botnet C2 server (confidence level: 50%)
hash5555
AsyncRAT botnet C2 server (confidence level: 50%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash60002
Quasar RAT botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash80
Unknown malware botnet C2 server (confidence level: 75%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash6000
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash2570
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash70
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash443
BianLian botnet C2 server (confidence level: 100%)
hash1433
BianLian botnet C2 server (confidence level: 100%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash4445
Cobalt Strike botnet C2 server (confidence level: 50%)
hash2090
BlackShades botnet C2 server (confidence level: 50%)
hash80
Broomstick botnet C2 server (confidence level: 50%)
hash6443
NetSupportManager RAT botnet C2 server (confidence level: 75%)
hash19082
Sliver botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash10443
DeimosC2 botnet C2 server (confidence level: 75%)
hash12000
DeimosC2 botnet C2 server (confidence level: 75%)
hash18068
DeimosC2 botnet C2 server (confidence level: 75%)
hash18333
DeimosC2 botnet C2 server (confidence level: 75%)
hash18628
DeimosC2 botnet C2 server (confidence level: 75%)
hash19611
DeimosC2 botnet C2 server (confidence level: 75%)
hash19887
DeimosC2 botnet C2 server (confidence level: 75%)
hash20000
DeimosC2 botnet C2 server (confidence level: 75%)
hash21135
DeimosC2 botnet C2 server (confidence level: 75%)
hash24010
DeimosC2 botnet C2 server (confidence level: 75%)
hash30919
DeimosC2 botnet C2 server (confidence level: 75%)
hash3216
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash2222
QakBot botnet C2 server (confidence level: 75%)
hash389
Meterpreter botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash1182
Quasar RAT botnet C2 server (confidence level: 100%)
hash32954
AsyncRAT botnet C2 server (confidence level: 50%)
hash1911
Unknown malware botnet C2 server (confidence level: 50%)
hash443
Ghost RAT botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash34473
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash8011
Cobalt Strike botnet C2 server (confidence level: 50%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash4126
Remcos botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8085
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash2345
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash2000
DCRat botnet C2 server (confidence level: 100%)
hash2000
DCRat botnet C2 server (confidence level: 100%)
hash46174
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash801
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9999
Unknown Stealer botnet C2 server (confidence level: 75%)
hash9999
Unknown Stealer botnet C2 server (confidence level: 75%)
hash9cd423fedfcc7209236ea4cab06b4d9437b7785254297352c0655fae346a6f75
Unknown Stealer payload (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash51325
Mirai botnet C2 server (confidence level: 75%)
hash9931
Mirai botnet C2 server (confidence level: 75%)
hash50011
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8000
Sliver botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash8888
AsyncRAT botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash5432
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash49564
NjRAT botnet C2 server (confidence level: 100%)
hash55615
RedLine Stealer botnet C2 server (confidence level: 100%)
hash8086
Cobalt Strike botnet C2 server (confidence level: 50%)
hash444
AsyncRAT botnet C2 server (confidence level: 50%)
hash4446
Meterpreter botnet C2 server (confidence level: 100%)
hash55615
RedLine Stealer botnet C2 server (confidence level: 100%)
hash2484
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)

Threat ID: 682c7dbee8347ec82d2cedfe

Added to database: 5/20/2025, 1:03:58 PM

Last enriched: 6/19/2025, 3:33:04 PM

Last updated: 8/12/2025, 12:07:02 PM

Views: 15

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats