Skip to main content

ThreatFox IOCs for 2025-02-28

Medium
Published: Fri Feb 28 2025 (02/28/2025, 00:00:00 UTC)
Source: ThreatFox
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-02-28

AI-Powered Analysis

AILast updated: 06/19/2025, 15:34:25 UTC

Technical Analysis

The provided information pertains to a malware-related threat identified as "ThreatFox IOCs for 2025-02-28," sourced from ThreatFox, a platform known for sharing Indicators of Compromise (IOCs) and threat intelligence data. The threat is categorized under "type:osint," indicating it is primarily related to open-source intelligence gathering or dissemination rather than a specific malware family or exploit. No specific affected product versions or detailed technical indicators are provided, and there are no known exploits in the wild associated with this threat as of the publication date, 28 February 2025. The technical details include a threat level of 2 (on an unspecified scale), an analysis score of 1, and a distribution score of 3, suggesting moderate dissemination or availability of related data. The absence of CWE identifiers, patch links, or detailed technical indicators limits the ability to precisely characterize the malware's behavior, attack vectors, or payload. The threat is tagged with "tlp:white," indicating that the information is intended for unrestricted sharing. Overall, this appears to be an informational release of IOCs related to a malware threat, possibly to aid in detection and prevention, rather than a report of an active or emerging exploit campaign.

Potential Impact

Given the limited technical details and absence of known exploits in the wild, the immediate impact of this threat on European organizations is likely low to medium. However, the dissemination of IOCs can facilitate early detection and response to potential malware infections. If these IOCs correspond to malware capable of compromising confidentiality, integrity, or availability, organizations that fail to integrate this intelligence into their security monitoring may be at increased risk. The lack of specific affected products or versions makes it difficult to assess direct operational impacts. Nonetheless, organizations relying heavily on OSINT tools or threat intelligence platforms may find value in incorporating these IOCs to enhance their defensive posture. The medium severity rating suggests that while the threat is not currently critical, it warrants attention to prevent escalation or exploitation in the future.

Mitigation Recommendations

1. Integrate the provided IOCs into existing Security Information and Event Management (SIEM) systems and endpoint detection and response (EDR) tools to enhance detection capabilities. 2. Conduct targeted threat hunting exercises using the IOCs to identify any latent infections or suspicious activities within the network. 3. Maintain up-to-date threat intelligence feeds and ensure security teams are trained to interpret and act upon OSINT-derived indicators. 4. Implement network segmentation and strict access controls to limit potential lateral movement if malware is detected. 5. Regularly review and update incident response plans to incorporate procedures for handling malware infections identified through OSINT channels. 6. Since no patches or specific vulnerabilities are indicated, focus on strengthening general malware defenses such as email filtering, user awareness training, and application whitelisting. 7. Collaborate with national and European cybersecurity information sharing organizations to stay informed about evolving threats related to these IOCs.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
3eb2043e-0717-4ba4-bd21-07a0ca053b49
Original Timestamp
1740787386

Indicators of Compromise

Domain

ValueDescriptionCopy
domaincheck.lavow.icu
ClearFake payload delivery domain (confidence level: 100%)
domaingomyhalf.com
ShadowPad botnet C2 domain (confidence level: 95%)
domainsymence.org
ShadowPad botnet C2 domain (confidence level: 95%)
domain99wc.top
FAKEUPDATES payload delivery domain (confidence level: 100%)
domainhasagot.sapphiretechnologies.live
ClearFake payload delivery domain (confidence level: 80%)
domaincarloscaicedo4050202.duckdns.org
AsyncRAT botnet C2 domain (confidence level: 100%)
domainsebastiancorrea905040.duckdns.org
AsyncRAT botnet C2 domain (confidence level: 100%)
domainwww.inform-gain.sbs
Hook botnet C2 domain (confidence level: 100%)
domaincpcontacts.digitalbusineszclub.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.businesswithloyal.website
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.newzmediaworld.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.homesemupo.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.toptenufabetgames.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.ufa4games.website
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.fortnewzoutlooks.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.fortlivenewzshub.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.fieldznorms.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.trendingbstuisports.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.bookslinedzmod.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.magzineviralzhubz.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainsmartcloudnetwork.com
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.games777games.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.topthounds1.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.betufa.website
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.allthefiver.com
Havoc botnet C2 domain (confidence level: 100%)
domain23-227-202-132.static.hvvc.us
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.proonlinehub.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.superbbusiness.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.10bestufabetgames.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.top5business.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainulacine.urbananchortravel.com
ClearFake payload delivery domain (confidence level: 80%)
domainchlenvaginakz.icu
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainaiqinsights.icu
Lumma Stealer botnet C2 domain (confidence level: 50%)
domain21tradingcobd.com
ClearFake payload delivery domain (confidence level: 80%)
domainwww.environment.go.ke
ClearFake payload delivery domain (confidence level: 80%)
domainwww.extintoresadok.com
ClearFake payload delivery domain (confidence level: 80%)
domaindhysgs-101-454.123cw.cn
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainservice-a0ahsoek-1257582847.gz.tencentapigw.com.cn
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainwww.wiseequinevet.com
ClearFake payload delivery domain (confidence level: 80%)
domaincpanel.firstgamezzdiary.website
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.newzofnetworksera.com
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.magazinebookline.com
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.eragamshub.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.businessnewznetwork.com
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.topthounds.com
Havoc botnet C2 domain (confidence level: 100%)
domainec2-34-225-248-122.compute-1.amazonaws.com
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.toplavishnewz43.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.okiamwithtotogames.com
Havoc botnet C2 domain (confidence level: 100%)
domain104-168-101-23.cprapid.com
Bashlite botnet C2 domain (confidence level: 100%)
domainnhakhoalehanh.com
ClearFake payload delivery domain (confidence level: 80%)
domainapi.huangjin66.com
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainvideo-ondemand.webexglobal.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainglobalasiagroup.com
ClearFake payload delivery domain (confidence level: 80%)
domainlakikishop.duckdns.org
AsyncRAT botnet C2 domain (confidence level: 50%)
domainadvertising-interfaces.gl.at.ply.gg
Quasar RAT botnet C2 domain (confidence level: 50%)
domain21ene.ip-ddns.com
Remcos botnet C2 domain (confidence level: 50%)
domainearthsymphzony.today
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainwealthestored.icu
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainxxx-cf.pages.dev
ClearFake payload delivery domain (confidence level: 100%)
domainsmileclinic.london
ClearFake payload delivery domain (confidence level: 80%)
domainbrotesnativos.cl
ClearFake payload delivery domain (confidence level: 80%)
domainwebdisk.top10gamesofoto.com
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.businesstimehub.com
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.onlinebesttotogames.com
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.whartpzz.com
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.gamesofsportsandtoto.com
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.bestblogznews.com
Havoc botnet C2 domain (confidence level: 100%)
domaincheck.vehom.icu
ClearFake payload delivery domain (confidence level: 100%)
domainmyagentproperties.ad-wize.xyz
ClearFake payload delivery domain (confidence level: 80%)
domainwww.madraspestcontrol.com
ClearFake payload delivery domain (confidence level: 80%)
domaincheck.luboz.icu
ClearFake payload delivery domain (confidence level: 100%)
domainvinisbeautyartladiescenter.com
ClearFake payload delivery domain (confidence level: 80%)
domainlandmarkhomesearch.pro
ClearFake payload delivery domain (confidence level: 80%)
domainlp.intaarya.com
ClearFake payload delivery domain (confidence level: 80%)
domaincheck.xapus.icu
ClearFake payload delivery domain (confidence level: 100%)
domainres.microsecurity.xyz
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainwww.pontsolidari.org
ClearFake payload delivery domain (confidence level: 80%)
domainwww.fiscosmart.it
ClearFake payload delivery domain (confidence level: 80%)
domaineinfacherezepte.ssat4tech.com
ClearFake payload delivery domain (confidence level: 80%)
domaincdadiagnostico.com.br
ClearFake payload delivery domain (confidence level: 80%)
domainwowsweets.ae
ClearFake payload delivery domain (confidence level: 80%)
domaincheck.fafyd.icu
ClearFake payload delivery domain (confidence level: 100%)
domainyydsisnull.sbs
Cobalt Strike botnet C2 domain (confidence level: 100%)
domain28wm5bg94879.vicp.fun
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainapi.masjesu.zip
Mirai botnet C2 domain (confidence level: 100%)
domaincfkdfw.org
ClearFake payload delivery domain (confidence level: 80%)
domainwawanewsglobal.com
ClearFake payload delivery domain (confidence level: 80%)
domainlestimes.com
ClearFake payload delivery domain (confidence level: 80%)
domaincircujitstorm.bet
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainhardswarehub.today
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainhardrwarehaven.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincodxefusion.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaintechpxioneers.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincpcontacts.magazinebestnetworkz.com
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.hostsportstoto9.com
Havoc botnet C2 domain (confidence level: 100%)
domain246.157.59.34.bc.googleusercontent.com
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.bestnewznetworkofone.com
Havoc botnet C2 domain (confidence level: 100%)
domaincheck.nuwab.icu
ClearFake payload delivery domain (confidence level: 100%)
domainwww.rendaextradigitaltodosdias.online
ClearFake payload delivery domain (confidence level: 80%)
domainwww.orenesdistribucion.com
ClearFake payload delivery domain (confidence level: 80%)
domainhypo-dance.pages.dev
ClearFake payload delivery domain (confidence level: 100%)
domainlumichain.pro
ClearFake payload delivery domain (confidence level: 100%)
domaincheck.mijuf.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincouterfv.top
FAKEUPDATES payload delivery domain (confidence level: 100%)
domainwindows.envisionfonddulac.net
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domaincheck.cined.icu
ClearFake payload delivery domain (confidence level: 100%)
domainleafvypathways.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincheck.mosat.icu
ClearFake payload delivery domain (confidence level: 100%)
domaingoldenpeakmedia.com
ClearFake payload delivery domain (confidence level: 80%)
domainroyalmailcouriercompany.com
ClearFake payload delivery domain (confidence level: 80%)
domaincheck.myfet.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincheck.remag.icu
ClearFake payload delivery domain (confidence level: 100%)
domainbrisasdelestadio.com
ClearFake payload delivery domain (confidence level: 80%)
domainthecapitaltimes.co.ug
ClearFake payload delivery domain (confidence level: 80%)
domaincpcontacts.fivetopbusiness.website
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.topzbuscartio.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.businessnewznetwork.website
Havoc botnet C2 domain (confidence level: 100%)
domaincheck.hysuz.icu
ClearFake payload delivery domain (confidence level: 100%)
domaina1090962.xsph.ru
DCRat botnet C2 domain (confidence level: 100%)
domaina1091043.xsph.ru
DCRat botnet C2 domain (confidence level: 100%)
domaincs2weaponpaints.ru.s29.hhos.net
DCRat botnet C2 domain (confidence level: 100%)
domainporsikgq.beget.tech
DCRat botnet C2 domain (confidence level: 100%)
domainall-trans.online
DCRat botnet C2 domain (confidence level: 100%)
domaindawtastream.bet
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincheck.jixal.icu
ClearFake payload delivery domain (confidence level: 100%)
domaindoondefenceacademy.com
ClearFake payload delivery domain (confidence level: 80%)
domainsuckerity.xyz
magecart payload delivery domain (confidence level: 100%)
domaincdn.iconstaff.top
magecart payload delivery domain (confidence level: 100%)
domaincheck.qogur.icu
ClearFake payload delivery domain (confidence level: 100%)
domainpackaging.briko.com
FAKEUPDATES payload delivery domain (confidence level: 80%)
domainbocdoc.fr
ClearFake payload delivery domain (confidence level: 80%)
domainelbio.tn
ClearFake payload delivery domain (confidence level: 80%)
domainnetsolut.com
FAKEUPDATES payload delivery domain (confidence level: 100%)
domainwherever-answered-issn-garcia.trycloudflare.com
FAKEUPDATES payload delivery domain (confidence level: 100%)
domaincheck.qozil.icu
ClearFake payload delivery domain (confidence level: 100%)
domainbaca.prodigitalindo.id
ClearFake payload delivery domain (confidence level: 80%)
domainmultiwayimmigration.com
ClearFake payload delivery domain (confidence level: 80%)
domainwebdisk.time2levelz.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.paranewslivesab.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.shakdmisab.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.hostbesttech.website
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.businesspros.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.generalspotline.org
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.businesshostz.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.ashionof121.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.apexhomeimprovement.website
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.onlinegameshub.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.techspilotx.website
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.gamesofart1.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.bestonlinegamez.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.businesseshub.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.homeaddition.website
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.gameswithufabet.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.businessnewznetwork.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.bjshomeimprovement.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.eragamshub.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.businesspros.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincheck.qitub.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincheck.bipyl.icu
ClearFake payload delivery domain (confidence level: 100%)
domaind.formaxprime.co.uk
Vidar botnet C2 domain (confidence level: 100%)
domaintagol51982-62186.portmap.host
AsyncRAT botnet C2 domain (confidence level: 50%)
domainbotnet.voct.dev
Mirai botnet C2 domain (confidence level: 50%)
domain23-43449.portmap.host
NjRAT botnet C2 domain (confidence level: 50%)
domainoperates-vampire.with.playit.plus
Quasar RAT botnet C2 domain (confidence level: 50%)
domainth8q3wj9w.localto.net
Revenge RAT botnet C2 domain (confidence level: 50%)
domaincameras-happen.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domaincause-indexes.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domaincoolguy12-30292.portmap.host
XWorm botnet C2 domain (confidence level: 50%)
domainredslide-36078.portmap.host
XWorm botnet C2 domain (confidence level: 50%)
domaintransfer-grip.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)

File

ValueDescriptionCopy
file119.23.55.186
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.138.189.137
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.155.44.213
Cobalt Strike botnet C2 server (confidence level: 100%)
file27.124.19.76
Cobalt Strike botnet C2 server (confidence level: 100%)
file74.50.94.137
Remcos botnet C2 server (confidence level: 100%)
file74.50.94.137
Remcos botnet C2 server (confidence level: 100%)
file173.214.167.56
Remcos botnet C2 server (confidence level: 100%)
file156.225.26.6
Unknown malware botnet C2 server (confidence level: 100%)
file146.56.199.96
Unknown malware botnet C2 server (confidence level: 100%)
file196.251.80.3
Unknown malware botnet C2 server (confidence level: 100%)
file196.251.85.154
AsyncRAT botnet C2 server (confidence level: 100%)
file94.156.177.244
AsyncRAT botnet C2 server (confidence level: 100%)
file207.231.111.146
AsyncRAT botnet C2 server (confidence level: 100%)
file179.13.0.63
AsyncRAT botnet C2 server (confidence level: 100%)
file185.241.208.107
AsyncRAT botnet C2 server (confidence level: 100%)
file20.106.233.97
Unknown malware botnet C2 server (confidence level: 100%)
file156.244.9.190
Hook botnet C2 server (confidence level: 100%)
file193.35.17.242
Hook botnet C2 server (confidence level: 100%)
file3.142.51.239
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file3.25.233.150
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file196.251.84.254
MooBot botnet C2 server (confidence level: 100%)
file5.59.249.58
MooBot botnet C2 server (confidence level: 100%)
file94.237.98.169
MimiKatz botnet C2 server (confidence level: 100%)
file86.38.225.82
Quasar RAT botnet C2 server (confidence level: 100%)
file38.54.89.17
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.73.192.3
Remcos botnet C2 server (confidence level: 100%)
file198.37.105.224
Remcos botnet C2 server (confidence level: 100%)
file176.65.139.78
Remcos botnet C2 server (confidence level: 100%)
file139.224.102.83
Sliver botnet C2 server (confidence level: 100%)
file93.71.184.136
AsyncRAT botnet C2 server (confidence level: 100%)
file23.20.183.202
Unknown malware botnet C2 server (confidence level: 100%)
file102.117.162.185
Unknown malware botnet C2 server (confidence level: 100%)
file185.250.148.168
Hook botnet C2 server (confidence level: 100%)
file189.78.187.96
Quasar RAT botnet C2 server (confidence level: 100%)
file217.196.63.241
Havoc botnet C2 server (confidence level: 100%)
file44.209.63.85
Havoc botnet C2 server (confidence level: 100%)
file101.99.91.30
DCRat botnet C2 server (confidence level: 100%)
file109.176.207.177
Unknown malware botnet C2 server (confidence level: 100%)
file143.198.105.117
Unknown malware botnet C2 server (confidence level: 100%)
file176.188.105.70
MimiKatz botnet C2 server (confidence level: 100%)
file193.35.17.242
Hook botnet C2 server (confidence level: 100%)
file116.62.50.188
Unknown malware botnet C2 server (confidence level: 100%)
file203.101.103.185
Unknown malware botnet C2 server (confidence level: 100%)
file143.244.143.167
Unknown malware botnet C2 server (confidence level: 100%)
file123.249.19.225
Unknown malware botnet C2 server (confidence level: 100%)
file123.249.19.225
Unknown malware botnet C2 server (confidence level: 100%)
file89.111.152.234
Unknown malware botnet C2 server (confidence level: 100%)
file45.89.67.189
Unknown malware botnet C2 server (confidence level: 100%)
file202.155.238.7
Unknown malware botnet C2 server (confidence level: 100%)
file188.245.164.75
Unknown malware botnet C2 server (confidence level: 100%)
file52.57.50.216
Unknown malware botnet C2 server (confidence level: 100%)
file52.57.50.216
Unknown malware botnet C2 server (confidence level: 100%)
file138.68.75.190
Unknown malware botnet C2 server (confidence level: 100%)
file103.157.97.170
Unknown malware botnet C2 server (confidence level: 100%)
file141.11.212.114
Unknown malware botnet C2 server (confidence level: 100%)
file89.116.170.229
Unknown malware botnet C2 server (confidence level: 100%)
file143.198.105.117
Unknown malware botnet C2 server (confidence level: 100%)
file139.162.131.244
Unknown malware botnet C2 server (confidence level: 100%)
file119.23.55.186
Cobalt Strike botnet C2 server (confidence level: 50%)
file111.231.144.159
Cobalt Strike botnet C2 server (confidence level: 50%)
file1.94.63.197
Cobalt Strike botnet C2 server (confidence level: 50%)
file178.128.19.19
Cobalt Strike botnet C2 server (confidence level: 50%)
file101.35.45.108
Cobalt Strike botnet C2 server (confidence level: 50%)
file107.173.60.106
Cobalt Strike botnet C2 server (confidence level: 50%)
file103.161.35.171
Cobalt Strike botnet C2 server (confidence level: 50%)
file91.245.225.85
Sliver botnet C2 server (confidence level: 50%)
file20.75.88.91
Sliver botnet C2 server (confidence level: 50%)
file18.185.89.52
Unknown malware botnet C2 server (confidence level: 50%)
file88.31.45.5
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file129.208.156.15
Quasar RAT botnet C2 server (confidence level: 50%)
file84.154.119.178
AsyncRAT botnet C2 server (confidence level: 50%)
file139.59.228.234
NjRAT botnet C2 server (confidence level: 100%)
file27.124.42.200
ValleyRAT botnet C2 server (confidence level: 100%)
file104.245.145.253
Remcos botnet C2 server (confidence level: 75%)
file83.229.121.103
Cobalt Strike botnet C2 server (confidence level: 100%)
file185.7.214.9
Remcos botnet C2 server (confidence level: 100%)
file162.251.123.215
Remcos botnet C2 server (confidence level: 100%)
file156.245.28.77
Sliver botnet C2 server (confidence level: 100%)
file176.65.144.103
AsyncRAT botnet C2 server (confidence level: 100%)
file176.65.141.245
AsyncRAT botnet C2 server (confidence level: 100%)
file104.161.43.108
AsyncRAT botnet C2 server (confidence level: 100%)
file154.205.151.12
Unknown malware botnet C2 server (confidence level: 100%)
file51.15.224.30
Unknown malware botnet C2 server (confidence level: 100%)
file34.59.157.246
Havoc botnet C2 server (confidence level: 100%)
file34.225.248.122
Havoc botnet C2 server (confidence level: 100%)
file115.79.236.135
Venom RAT botnet C2 server (confidence level: 100%)
file18.230.148.208
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file217.114.43.53
Unknown malware botnet C2 server (confidence level: 100%)
file41.216.189.118
Bashlite botnet C2 server (confidence level: 100%)
file107.175.75.19
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.239.152.236
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.245.28.97
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.215.212.130
ValleyRAT botnet C2 server (confidence level: 100%)
file37.27.215.10
Remcos botnet C2 server (confidence level: 75%)
file110.42.252.7
Sliver botnet C2 server (confidence level: 75%)
file162.33.178.133
Sliver botnet C2 server (confidence level: 75%)
file18.224.6.225
NetSupportManager RAT botnet C2 server (confidence level: 75%)
file35.78.206.139
NetSupportManager RAT botnet C2 server (confidence level: 75%)
file41.190.15.19
DeimosC2 botnet C2 server (confidence level: 75%)
file157.10.45.96
Mirai botnet C2 server (confidence level: 100%)
file157.10.45.96
Mirai botnet C2 server (confidence level: 100%)
file123.31.11.66
Cobalt Strike botnet C2 server (confidence level: 100%)
file189.1.217.18
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.12.22.242
Cobalt Strike botnet C2 server (confidence level: 100%)
file35.231.55.62
Cobalt Strike botnet C2 server (confidence level: 100%)
file104.243.254.101
Remcos botnet C2 server (confidence level: 100%)
file41.216.188.247
Remcos botnet C2 server (confidence level: 100%)
file204.10.160.193
Remcos botnet C2 server (confidence level: 100%)
file67.211.208.114
Remcos botnet C2 server (confidence level: 100%)
file8.133.252.165
Sliver botnet C2 server (confidence level: 100%)
file8.155.5.131
Sliver botnet C2 server (confidence level: 100%)
file107.172.131.122
Unknown malware botnet C2 server (confidence level: 100%)
file49.113.72.212
Unknown malware botnet C2 server (confidence level: 100%)
file139.159.212.103
Unknown malware botnet C2 server (confidence level: 100%)
file123.11.254.150
Unknown malware botnet C2 server (confidence level: 100%)
file51.195.231.115
AsyncRAT botnet C2 server (confidence level: 100%)
file195.206.234.36
AsyncRAT botnet C2 server (confidence level: 100%)
file166.88.90.22
AsyncRAT botnet C2 server (confidence level: 100%)
file156.244.7.92
Unknown malware botnet C2 server (confidence level: 100%)
file181.162.155.36
Quasar RAT botnet C2 server (confidence level: 100%)
file34.219.232.134
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file153.92.209.104
Unknown malware botnet C2 server (confidence level: 100%)
file147.93.56.228
Stealc botnet C2 server (confidence level: 100%)
file155.138.226.179
FAKEUPDATES botnet C2 server (confidence level: 100%)
file119.91.56.217
Cobalt Strike botnet C2 server (confidence level: 75%)
file123.31.11.66
Cobalt Strike botnet C2 server (confidence level: 75%)
file35.94.63.52
Cobalt Strike botnet C2 server (confidence level: 75%)
file54.71.7.37
Cobalt Strike botnet C2 server (confidence level: 75%)
file8.218.157.182
Cobalt Strike botnet C2 server (confidence level: 75%)
file176.113.115.6
Amadey botnet C2 server (confidence level: 100%)
file5.181.157.160
NetSupportManager RAT botnet C2 server (confidence level: 75%)
file62.60.226.15
Amadey botnet C2 server (confidence level: 100%)
file120.46.185.1
Cobalt Strike botnet C2 server (confidence level: 100%)
file107.175.75.19
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.239.64.74
Remcos botnet C2 server (confidence level: 100%)
file212.232.22.174
Remcos botnet C2 server (confidence level: 100%)
file89.213.248.62
XWorm botnet C2 server (confidence level: 100%)
file45.192.110.137
Unknown malware botnet C2 server (confidence level: 100%)
file157.20.182.12
AsyncRAT botnet C2 server (confidence level: 100%)
file51.195.231.115
AsyncRAT botnet C2 server (confidence level: 100%)
file185.143.220.126
BianLian botnet C2 server (confidence level: 100%)
file91.212.166.9
GhostSocks botnet C2 server (confidence level: 100%)
file77.238.237.190
GhostSocks botnet C2 server (confidence level: 100%)
file185.21.13.144
GhostSocks botnet C2 server (confidence level: 100%)
file195.200.28.33
GhostSocks botnet C2 server (confidence level: 100%)
file185.157.213.253
GhostSocks botnet C2 server (confidence level: 100%)
file195.200.31.22
GhostSocks botnet C2 server (confidence level: 100%)
file212.34.130.72
GhostSocks botnet C2 server (confidence level: 100%)
file185.156.72.58
Tofsee botnet C2 server (confidence level: 100%)
file89.213.248.62
XWorm botnet C2 server (confidence level: 100%)
file192.3.3.160
Venom RAT botnet C2 server (confidence level: 100%)
file185.156.72.58
Tofsee botnet C2 server (confidence level: 100%)
file185.156.72.58
Tofsee botnet C2 server (confidence level: 100%)
file8.137.117.83
Cobalt Strike botnet C2 server (confidence level: 75%)
file8.137.117.83
Cobalt Strike botnet C2 server (confidence level: 75%)
file193.143.1.19
Mirai botnet C2 server (confidence level: 75%)
file141.98.10.109
Mirai botnet C2 server (confidence level: 100%)
file3.127.181.115
NjRAT botnet C2 server (confidence level: 100%)
file3.67.62.142
NjRAT botnet C2 server (confidence level: 100%)
file3.67.112.102
NjRAT botnet C2 server (confidence level: 100%)
file18.158.58.205
NjRAT botnet C2 server (confidence level: 100%)
file83.212.67.49
Cobalt Strike botnet C2 server (confidence level: 100%)
file38.207.191.60
Cobalt Strike botnet C2 server (confidence level: 100%)
file35.177.93.204
Sliver botnet C2 server (confidence level: 100%)
file146.70.158.85
Havoc botnet C2 server (confidence level: 100%)
file23.227.202.132
Havoc botnet C2 server (confidence level: 100%)
file23.227.202.132
Havoc botnet C2 server (confidence level: 100%)
file34.59.157.246
Havoc botnet C2 server (confidence level: 100%)
file173.249.45.65
Havoc botnet C2 server (confidence level: 100%)
file171.249.230.216
Venom RAT botnet C2 server (confidence level: 100%)
file216.173.64.63
Venom RAT botnet C2 server (confidence level: 100%)
file46.246.12.9
DCRat botnet C2 server (confidence level: 100%)
file107.189.27.205
Unknown malware botnet C2 server (confidence level: 100%)
file195.211.191.181
AsyncRAT botnet C2 server (confidence level: 75%)
file101.35.45.108
Cobalt Strike botnet C2 server (confidence level: 50%)
file119.23.55.186
Cobalt Strike botnet C2 server (confidence level: 50%)
file111.231.144.159
Cobalt Strike botnet C2 server (confidence level: 50%)
file1.94.63.197
Cobalt Strike botnet C2 server (confidence level: 50%)
file162.55.216.15
Sliver botnet C2 server (confidence level: 50%)
file147.45.135.223
Sliver botnet C2 server (confidence level: 50%)
file210.16.120.89
Sliver botnet C2 server (confidence level: 50%)
file35.182.50.99
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file3.96.165.93
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file3.36.116.178
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file8.209.249.160
Unknown malware botnet C2 server (confidence level: 50%)
file3.124.67.191
AsyncRAT botnet C2 server (confidence level: 50%)
file162.243.219.170
MooBot botnet C2 server (confidence level: 75%)
file45.78.59.69
DeimosC2 botnet C2 server (confidence level: 75%)
file45.95.175.94
Cobalt Strike botnet C2 server (confidence level: 75%)
file2.49.150.25
NjRAT botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7001
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2105
Remcos botnet C2 server (confidence level: 100%)
hash3727
Remcos botnet C2 server (confidence level: 100%)
hash7335
Remcos botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash3000
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash20573
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash2052
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash8000
MimiKatz botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash45699
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash5000
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash2013
DCRat botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
MimiKatz botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash88
Unknown malware botnet C2 server (confidence level: 100%)
hash9999
Unknown malware botnet C2 server (confidence level: 100%)
hash65001
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash12345
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash50500
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50500
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50500
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50500
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash2083
Cobalt Strike botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash4443
Unknown malware botnet C2 server (confidence level: 50%)
hash6001
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash1337
Quasar RAT botnet C2 server (confidence level: 50%)
hash4449
AsyncRAT botnet C2 server (confidence level: 50%)
hash22728
NjRAT botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash60142
Remcos botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash7777
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash60000
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash6001
Venom RAT botnet C2 server (confidence level: 100%)
hash2003
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash9000
Unknown malware botnet C2 server (confidence level: 100%)
hash23
Bashlite botnet C2 server (confidence level: 100%)
hash8880
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2095
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash1331
Remcos botnet C2 server (confidence level: 75%)
hash9123
Sliver botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash2152
NetSupportManager RAT botnet C2 server (confidence level: 75%)
hash8080
NetSupportManager RAT botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash56999
Mirai botnet C2 server (confidence level: 100%)
hash1337
Mirai botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2606
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash32024
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash5873
Unknown malware botnet C2 server (confidence level: 100%)
hash888
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Quasar RAT botnet C2 server (confidence level: 100%)
hash993
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash443
FAKEUPDATES botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Amadey botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 75%)
hash80
Amadey botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2087
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash80
XWorm botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash4444
AsyncRAT botnet C2 server (confidence level: 100%)
hash222
AsyncRAT botnet C2 server (confidence level: 100%)
hash8080
BianLian botnet C2 server (confidence level: 100%)
hash30001
GhostSocks botnet C2 server (confidence level: 100%)
hash10000
GhostSocks botnet C2 server (confidence level: 100%)
hash10000
GhostSocks botnet C2 server (confidence level: 100%)
hash10000
GhostSocks botnet C2 server (confidence level: 100%)
hash10000
GhostSocks botnet C2 server (confidence level: 100%)
hash10000
GhostSocks botnet C2 server (confidence level: 100%)
hash10000
GhostSocks botnet C2 server (confidence level: 100%)
hash418
Tofsee botnet C2 server (confidence level: 100%)
hash7777
XWorm botnet C2 server (confidence level: 100%)
hash4449
Venom RAT botnet C2 server (confidence level: 100%)
hash422
Tofsee botnet C2 server (confidence level: 100%)
hash419
Tofsee botnet C2 server (confidence level: 100%)
hash7979
Cobalt Strike botnet C2 server (confidence level: 75%)
hash9091
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8769
Mirai botnet C2 server (confidence level: 75%)
hash65535
Mirai botnet C2 server (confidence level: 100%)
hash13420
NjRAT botnet C2 server (confidence level: 100%)
hash13420
NjRAT botnet C2 server (confidence level: 100%)
hash13420
NjRAT botnet C2 server (confidence level: 100%)
hash13420
NjRAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash15443
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash6000
Venom RAT botnet C2 server (confidence level: 100%)
hash2323
Venom RAT botnet C2 server (confidence level: 100%)
hash9000
DCRat botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash4449
AsyncRAT botnet C2 server (confidence level: 75%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash4321
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash2455
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash5009
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash7443
Unknown malware botnet C2 server (confidence level: 50%)
hash16165
AsyncRAT botnet C2 server (confidence level: 50%)
hash55650
MooBot botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash5552
NjRAT botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://chlenvaginakz.icu/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://aiqinsights.icu/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://pukisound.icu/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttp://193.233.48.86/849027f16851d4a2/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://185.28.119.223/55145c8889ec57f2/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://104.252.127.64/12f8d7cc8b7f3b56/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://193.233.48.86/849027f16851d4a2/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://193.233.48.86/849027f16851d4a2/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://185.28.119.223/55145c8889ec57f2/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://104.252.127.64/12f8d7cc8b7f3b56/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://185.28.119.223/55145c8889ec57f2/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://45.88.76.205/3a8d14c36ef0a8cc/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://45.88.76.205/3a8d14c36ef0a8cc/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://45.88.76.205/3a8d14c36ef0a8cc/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://104.245.240.18/263ff79562167f22/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://104.245.240.18/263ff79562167f22/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://104.245.240.18/263ff79562167f22/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://79.137.206.248/d210652e231a5729/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://45.91.200.43/b112953a9d0b6fc2/sqlite3.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://45.91.200.43/b112953a9d0b6fc2/mozglue.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttp://45.91.200.43/b112953a9d0b6fc2/vcruntime140.dll
Stealc payload delivery URL (confidence level: 50%)
urlhttps://klck.it.com/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://kick.fo/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://claim.use-tapestry.world/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://196.251.113.41/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttp://185.250.148.168/
Unknown malware botnet C2 (confidence level: 50%)
urlhttp://209.145.47.90/
Unknown malware botnet C2 (confidence level: 50%)
urlhttp://209.250.231.116/
Unknown malware botnet C2 (confidence level: 50%)
urlhttps://193.124.185.114/ljjdhimsfh/index.php
Amadey botnet C2 (confidence level: 50%)
urlhttps://94.156.177.41/scc4/five/pvqdq929bsx_a_d_m1n_a.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 50%)
urlhttps://pastebin.com/raw/knhcgrrn
AsyncRAT botnet C2 (confidence level: 50%)
urlhttps://www.mediafire.com/file_premium/d6r4c3nzfv9mgl7/glass.mp3/file
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://xxx-cf.pages.dev/fix1
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://dawtastream.bet/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://check.vehom.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.luboz.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.xapus.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.fafyd.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.nuwab.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://www.mediafire.com/file_premium/4049rt4x9zlbmy5/linkinpark.mp3/file?i=c148efec-0e63-4d9c-9074-ae06ad37aba3
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://www.mediafire.com/file_premium/wq5b3xy6upgwwk1/linkinpark.mp3/file?i=cb32b1ed-716a-40c3-8b61-e492a792c23d
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://www.mediafire.com/file_premium/wq5b3xy6upgwwk1/linkinpark.mp3/file?i=06bdb4b1-bed8-40c4-9998-bd33a30ec1b9
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://www.mediafire.com/file_premium/m35yc1jfwom3npy/sound.mp3/file
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://www.mediafire.com/file_premium/i9r0yrjgf5snbt6/linkinpark.mp3/file?i=e556c583-f716-4960-a86e-ed13b51de238
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://176.113.115.6/ni9kiput/index.php
Amadey botnet C2 (confidence level: 100%)
urlhttp://185.215.113.209/di0her478/index.php
Amadey botnet C2 (confidence level: 100%)
urlhttp://62.60.226.15/8fj482jd9/index.php
Amadey botnet C2 (confidence level: 100%)
urlhttps://check.mijuf.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://couterfv.top/work/original.js
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://couterfv.top/work/index.php
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://couterfv.top/work/ups.php
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://theneerbreak.com/comcat2.zip
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://check.cined.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://leafvypathways.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://check.mosat.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://193.233.254.53/278c2fb3d8583f0e.php
Stealc botnet C2 (confidence level: 100%)
urlhttps://blessedwirrow.org/qlzvfjfnsjfacbqafa8yg
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://check.myfet.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://176.113.115.6/ni9kiput/login.php
Amadey botnet C2 (confidence level: 100%)
urlhttps://check.remag.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.hysuz.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.jixal.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.qogur.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://netsolut.com/6t3e.js
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://netsolut.com/js.php
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://check.qozil.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://194.87.99.40/to0http/eternalauth6db/downloadswp/base/public/2cpu/pythondatalife/dle4/vmupdate/lowapi/eternalphpjavascriptlowupdatewindowstestpublic.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://check.qitub.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://d.formaxprime.co.uk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://check.bipyl.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://electronicpgioneers.live/login
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://check.woqym.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://dakdkkldkd.temp.swtest.ru/phphttpupdatepublic.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://075185cm.nyashk.ru/secureupdateservertracklocaluploads.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://47.92.211.202:4321/llwn
Cobalt Strike botnet C2 (confidence level: 75%)
urlhttp://fnafbox1gm.temp.swtest.ru/secureprotecttracklocaluploads.php
DCRat botnet C2 (confidence level: 100%)

Threat ID: 682c7dbde8347ec82d2c7318

Added to database: 5/20/2025, 1:03:57 PM

Last enriched: 6/19/2025, 3:34:25 PM

Last updated: 7/21/2025, 6:14:46 PM

Views: 11

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats