Skip to main content

ThreatFox IOCs for 2025-03-07

Medium
Published: Fri Mar 07 2025 (03/07/2025, 00:00:00 UTC)
Source: ThreatFox
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-03-07

AI-Powered Analysis

AILast updated: 06/19/2025, 16:17:14 UTC

Technical Analysis

The provided threat intelligence relates to a malware category entry titled 'ThreatFox IOCs for 2025-03-07,' sourced from ThreatFox, a platform known for sharing Indicators of Compromise (IOCs) related to various cyber threats. The entry is classified under 'malware' with a medium severity rating and is tagged as 'type:osint,' indicating that the information primarily consists of open-source intelligence data rather than detailed technical exploit descriptions or vulnerability specifics. There are no affected product versions or specific software vulnerabilities listed, and no known exploits in the wild have been reported. The technical details include a threat level of 2 (on an unspecified scale), an analysis rating of 1, and a distribution rating of 3, suggesting moderate dissemination or visibility of this threat intelligence. However, the absence of concrete indicators of compromise (IOCs), CWE identifiers, patch links, or detailed technical analysis limits the ability to fully characterize the malware's behavior, attack vectors, or payload capabilities. The lack of authentication or user interaction requirements is not explicitly stated, but given the nature of OSINT-based IOCs, this threat likely involves detection and monitoring rather than active exploitation. Overall, this entry appears to be a collection or update of threat intelligence data rather than a direct report of a new or active malware campaign.

Potential Impact

For European organizations, the impact of this threat is currently limited due to the absence of known active exploits or detailed technical information. Since the threat intelligence is primarily OSINT-based and lacks specific affected products or vulnerabilities, the immediate risk to confidentiality, integrity, or availability is low to medium. However, the distribution rating of 3 indicates that the IOCs or related information are moderately disseminated, which could facilitate detection and response efforts if the malware were to be deployed. European entities that rely heavily on threat intelligence feeds and integrate ThreatFox data into their security operations centers (SOCs) may benefit from early warnings or detection capabilities. Conversely, organizations without robust threat intelligence consumption might miss early indicators, potentially increasing exposure. The medium severity rating suggests vigilance but does not indicate an urgent or critical threat. The lack of known exploits in the wild further reduces the immediate operational risk. Nevertheless, the presence of this malware in threat intelligence repositories signals ongoing monitoring and potential future developments that European organizations should track, especially those in sectors with high-value data or critical infrastructure.

Mitigation Recommendations

Given the nature of this threat as an OSINT-based malware IOC update without specific exploitation details, mitigation should focus on enhancing threat intelligence integration and proactive detection capabilities. European organizations should: 1) Ensure their security information and event management (SIEM) and endpoint detection and response (EDR) systems are configured to ingest and correlate ThreatFox IOCs and similar OSINT feeds to improve early detection. 2) Regularly update and validate threat intelligence feeds to maintain relevance and reduce false positives. 3) Conduct threat hunting exercises using the latest IOCs to identify potential indicators within their environments. 4) Maintain robust network segmentation and least privilege access controls to limit lateral movement should malware be introduced. 5) Train security analysts to interpret OSINT data effectively and incorporate it into incident response workflows. 6) Collaborate with national and European cybersecurity information sharing organizations (e.g., ENISA, CERT-EU) to stay informed about emerging threats and coordinated mitigation strategies. These steps go beyond generic advice by emphasizing the operationalization of OSINT data and fostering collaborative defense mechanisms tailored to the evolving threat landscape.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
3b222d8f-11af-46fe-baf2-ee107dbb13d9
Original Timestamp
1741392187

Indicators of Compromise

Domain

ValueDescriptionCopy
domaincheck.fyjig.icu
ClearFake payload delivery domain (confidence level: 100%)
domainwww.glitchhaven.tech
Remcos botnet C2 domain (confidence level: 100%)
domaincpcalendars.mtpolice12.website
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.broadcnnewz.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.apkhubnewz.com
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.toplvlnewz.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.pointtotechiworld.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.toplavishnewz43.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.trendingbstuisports.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.touchufabetgames.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.teamofufabetgames.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.sportsfootball.website
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.digitalbusineszclub.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.10bestbusiness.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.allnewznetworksofarts.com
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.generalspotline.org
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.toriters7.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincheck.hegop.icu
ClearFake payload delivery domain (confidence level: 100%)
domainwww.fuckingmovie.icu
Cobalt Strike botnet C2 domain (confidence level: 75%)
domaincpcalendars.fieldznorms.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.apexhomeimprovement.website
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.enjoyedufabet.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.techspilotx.website
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.10bestufabetgames.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.topthounds.com
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.bookslinedzmod.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.takeufagame1111.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.canvatechsports.com
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.welovetotogames.com
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.techndgadget.com
Havoc botnet C2 domain (confidence level: 100%)
domainec2-18-140-53-230.ap-southeast-1.compute.amazonaws.com
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainpagos2-tst.travelpay.cl.arkaviaredteam.cl
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainecs-115-120-250-85.compute.hwclouds-dns.com
Cobalt Strike botnet C2 domain (confidence level: 100%)
domaincheck.nyrar.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincheck.vavoj.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincheck.dalut.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincheck.xylor.icu
ClearFake payload delivery domain (confidence level: 100%)
domainwww.1gv52.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.4109a37a693.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.51je936qi.sbs
Formbook botnet C2 domain (confidence level: 50%)
domainwww.6m86.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.abysitter-service-32322.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ags-under-999516409.click
Formbook botnet C2 domain (confidence level: 50%)
domainwww.andoes.tech
Formbook botnet C2 domain (confidence level: 50%)
domainwww.anglore-flats-gov01.today
Formbook botnet C2 domain (confidence level: 50%)
domainwww.archattinfobreach2024.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.arehouse-jobs-43584.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.aybankz.click
Formbook botnet C2 domain (confidence level: 50%)
domainwww.aycrk.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.b777.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.bgripl.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ddanything.win
Formbook botnet C2 domain (confidence level: 50%)
domainwww.dtech.team
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ecurity-jobs-61871.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ell-property-32572.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.emglobal.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.enesiscorporation.tech
Formbook botnet C2 domain (confidence level: 50%)
domainwww.estdrivencompliance.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.etoxsecrets.today
Formbook botnet C2 domain (confidence level: 50%)
domainwww.exbjfpbxhjcgzsdgumh.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.fqbjnaw.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.g-poc.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.hestarterkit.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.hiseledvisions.art
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ihdwt.info
Formbook botnet C2 domain (confidence level: 50%)
domainwww.itchens-31.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ixel49.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.kin-rejuvenation-60489.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.kin-rejuvenation-67012.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.log987resultbest.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.mcb.info
Formbook botnet C2 domain (confidence level: 50%)
domainwww.nmali.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.nolises.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ntesa.group
Formbook botnet C2 domain (confidence level: 50%)
domainwww.obahrainiioyiq.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.oho.uno
Formbook botnet C2 domain (confidence level: 50%)
domainwww.olawanliao33.click
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ollipop.group
Formbook botnet C2 domain (confidence level: 50%)
domainwww.oloactive.college
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ome-loans-72725.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.onda1.cloud
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ontacttracingwristband.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.oorso.live
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ootox.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.orussiansthub987q.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.oyalthaiherb.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.parkautotransport.website
Formbook botnet C2 domain (confidence level: 50%)
domainwww.pdld.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.phconline.info
Formbook botnet C2 domain (confidence level: 50%)
domainwww.pvoqftnckomcx.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.redit-cards-46185.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ressconversation.run
Formbook botnet C2 domain (confidence level: 50%)
domainwww.rview.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.sgazaproject.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.tgr.pro
Formbook botnet C2 domain (confidence level: 50%)
domainwww.tudy-in-spain-58534.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.umpsiconi.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.urseryinfo.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.vwhay.info
Formbook botnet C2 domain (confidence level: 50%)
domainwww.wmzotvekqsnbaxvf.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.yperpigmentation-45231.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.zhexifniu.top
Formbook botnet C2 domain (confidence level: 50%)
domaingeikus.myaddr.io
XenoRAT botnet C2 domain (confidence level: 50%)
domainezlols-61193.portmap.host
XWorm botnet C2 domain (confidence level: 50%)
domainak8-20226.portmap.host
XWorm botnet C2 domain (confidence level: 50%)
domainimthat1guyfrfr-36577.portmap.host
XWorm botnet C2 domain (confidence level: 50%)
domainassociation-lectures.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domaineditor-monitoring.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domainknown-savage.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domainorders-ic.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domainplaces-y.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domainsmall-patricia.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domaintoday-modules.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domainagroecologyguide.digital
Lumma Stealer botnet C2 domain (confidence level: 50%)
domaincropcircleforum.today
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainrzegzwre.top
AsyncRAT botnet C2 domain (confidence level: 50%)
domainga1yo3wu78v48hh.top
AsyncRAT botnet C2 domain (confidence level: 50%)
domainlogchim.cc
Unknown malware botnet C2 domain (confidence level: 50%)
domaincheck.papeb.icu
ClearFake payload delivery domain (confidence level: 100%)
domainwebdisk.sportsdhub.com
Havoc botnet C2 domain (confidence level: 100%)
domainsupport-wp.shop
Unknown Webinject botnet C2 domain (confidence level: 100%)
domainaweekofromance.com
Unknown Webinject botnet C2 domain (confidence level: 100%)
domainawards2today.top
Unknown Webinject botnet C2 domain (confidence level: 100%)
domainlove-support.world
Unknown Webinject botnet C2 domain (confidence level: 100%)
domainhooptounaku.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainphoostovel.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainibaugnotseergy.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainstaltooksaus.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainmeejoocheegouw.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainstirtoakraishe.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainroubauteezavoak.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainphailsuwoa.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainglupsamexewuner.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainneeroupsautoach.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainkefensaipta.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainjikrecmoods.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainfafengimoco.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainzebsochaimtipso.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainshuhachidreghu.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainamoteehoodaumse.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainshoultaunge.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainhuptaphetch.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainglivogluksaug.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainshoutcheeksaiw.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaingloustaige.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaincoacoakookawa.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainlutchignoodra.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainnauthaizophopti.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainptuloozeebourt.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainmapixoughew.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainuchucauvoowa.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainnerteetchoubo.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaindauleegrauku.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainnertushaud.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainwautholoachedu.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainoulsaultaulert.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaingreetsordauptoa.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainpsoomsogoom.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainbestoacmoaltou.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaingoajaizolouque.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainzaunooptaips.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaindihunsomat.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainfunoursumoalse.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainwuftaidrecmaw.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainceghoajoukr.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainoodruhoufouzair.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainchiluptebauceeb.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaindauchekiptauky.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainjempeedroar.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainchoawheduch.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainhogroacheerg.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainratchaudroogna.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainzicourubsopeegh.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaintheeboudriks.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainshebsoatsoorgi.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainibouksurtu.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainbodsaitchout.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaingadsauphoadsu.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainrolouloonsie.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainwhouxaucmoon.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaingoufouzo.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainhufatsavon.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainekaizugorda.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainsheckakrak.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaincobsakraums.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaineroutsaiptaupta.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainzamauksaiw.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainphacourgee.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaingairiglouhique.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaingouchapticauru.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainfumsuvaursicu.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainaivecmumsamohe.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainoopoostos.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainhouwifoutidoub.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainmuwhamtaultacm.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainofclefairytor.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainboupheepso.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaineetamseethe.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainptookrutsams.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaineerdaultaug.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaindeeneedeptaitu.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainocaxusoapsom.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainsuksaungoo.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainashoboodegri.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainjeepaunucoast.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainjumtoatsacmoche.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainpautuchethoaby.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainnooglaikath.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainwhichoogloabsa.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainkubugroakurded.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainneetothaib.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainphaimpensaighy.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainglodreenso.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainforcombeeer.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainosteecoopsaloap.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainvaipsouthy.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainfuthuretchoa.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainchultutailsy.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainshuptakse.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaincheechorgy.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainroaphidu.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainmoavoalidepsa.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainchoutsaugroo.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaintotsoadseegn.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainoobsejirsoud.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainchotsoahy.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaineexairsughe.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainfeethousounu.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainjocunoufaubs.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainfusairgaig.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainglewheers.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainduelgyemon.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainzackoumpeels.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainvechougnuns.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainuphaupsoazoola.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainbaupsaisaivouk.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainevaugrautch.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainoognadroognun.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainsteckoaroampou.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainpsultusughy.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaindaltailtaux.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainaulsoawachi.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainjoakauphoothase.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaindousistoochifuw.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainptoastough.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainopteehoshee.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainroogrenoomob.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainpoupteps.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainkaupsouthosta.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainoubsistejaiche.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainukeltoupoophans.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainbousefopheepi.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainintogeticor.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainfonsafteel.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainmethoaftergu.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainpseensauthoapub.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaindeezoamub.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaingelrazergeksoa.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaingauthekoglu.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainphulsoofoa.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainsoogeemokulie.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaindoosoaree.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaintechansoomo.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainudighoatcha.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainshibsuheeltecoo.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainshoneecheepteka.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainwhausourtoaru.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainaumsushurti.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainkaishauglechoan.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainoahoopsist.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainveepsauh.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainuperairgothoolr.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainpsoptauzaudsa.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainpaizoaveteche.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainpteeroalurdab.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainpsoushaiftu.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaintaudatuz.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaincaugeecoth.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainmaipsenoajail.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaincaphooptee.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainpubeeksi.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainglemtaikirty.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainloaglaigridabo.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainglowheesoan.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaintoaptinogoazou.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaindephauweexauns.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainphaishuw.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainjaivauvoogra.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainaipethauftu.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainlojaurgoh.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainstisoodraulu.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainptoalsoolti.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainwoophugoawham.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainareemsoukuphoa.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainthainson.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainkeeveerove.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainjengacmauksou.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainvaushoocouw.top
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainkeedoushatho.xyz
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainpepsehangoolout.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainleewoubazaips.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainbofeeglapta.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainaunoxongucichiw.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaintautaisteesutie.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainjoglomsexurgod.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainreetotopaisa.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainhoaglaushedi.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainptoftashulsee.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainzoureephouz.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainvaupsophoa.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainmughuglifood.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaingrapsauwou.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainoamsugneets.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainusheebainaut.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainfouleechoapo.net
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainfaftooptuk.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domainjocmiglenedsupi.com
Unknown Webinject botnet C2 domain (confidence level: 75%)
domaingentlera.com
PlugX botnet C2 domain (confidence level: 75%)
domaintrumpshare.com
PlugX botnet C2 domain (confidence level: 75%)
domainporsik9j.beget.tech
DCRat botnet C2 domain (confidence level: 100%)
domainck66916.tw1.ru
DCRat botnet C2 domain (confidence level: 100%)
domainspikyscaldeo.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainsnuegglypillow.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaingold-patterns.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domaintvrcemejeff.tvrcemeheff.euinnos.com
Remcos botnet C2 domain (confidence level: 100%)
domainsmartinnovatte.com
Hook botnet C2 domain (confidence level: 100%)
domainwebmail.testmedia89.com
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.onlinebesttotogames.com
Havoc botnet C2 domain (confidence level: 100%)
domaincpanel.toplavishnewz.com
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.okiamwithtotogames.com
Havoc botnet C2 domain (confidence level: 100%)
domaincheck.jemyq.icu
ClearFake payload delivery domain (confidence level: 100%)
domainagriculthub.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainagriework.life
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainanalgcslab.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincomrfyclouds.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincozsmicjo.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincjuddlepillows.icu
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainabsoulpushx.life
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainfarmercommunity.life
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaindataexzorers.icu
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincroprojegies.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaindiscxeryspace.icu
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainfahentures.today
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainexplqngscience.life
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincropmqttools.today
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainenvirbntalstudies.shop
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainfieldies.bet
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaingengfocus.today
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaingestryfocus.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaingreenfieldsnetwork.bet
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainheritagebreeds.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainlabdizeries.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaingardeninggains.bet
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainmathinsighjts.shop
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainpuillowjourney.icu
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainscienssights.today
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainorchardinspiration.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainparadoxxedin.world
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainpermaculturepath.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainscienxonnect.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainorganicgrowershub.shop
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainossifiedreduio.shop
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainscizencehub.life
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainspitestrippe.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainsoilandseed.icu
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainscientififange.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainsocialsscesforum.icu
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincheck.jipaf.icu
ClearFake payload delivery domain (confidence level: 100%)
domainbilling.shrewsburysocialclub.org
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainmallternet.com
FAKEUPDATES payload delivery domain (confidence level: 100%)
domainmedicamentsbonmarche.top
FAKEUPDATES payload delivery domain (confidence level: 100%)
domaincheck.mepum.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincheck.vadom.icu
ClearFake payload delivery domain (confidence level: 100%)
domainbiwona3847-22770.portmap.host
XWorm botnet C2 domain (confidence level: 50%)
domaingo.f.goldenloafuae.com
Vidar botnet C2 domain (confidence level: 100%)
domaincheck.qypib.icu
ClearFake payload delivery domain (confidence level: 100%)
domainmyhost001.myddns.me
Remcos botnet C2 domain (confidence level: 50%)
domainrediffclip.duckdns.org
Remcos botnet C2 domain (confidence level: 50%)
domainsun-anime.gl.at.ply.gg
Remcos botnet C2 domain (confidence level: 50%)
domainshow-commentary.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domaincheck.remez.icu
ClearFake payload delivery domain (confidence level: 100%)
domainns01.temasek.me.uk
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainns02.temasek.me.uk
Cobalt Strike botnet C2 domain (confidence level: 75%)
domaindugong.ydns.eu
Unknown malware botnet C2 domain (confidence level: 100%)
domainortain7histas1.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainortain7histas2.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainortain7histas3.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainortain7histas4.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domaincheck.doxaf.icu
ClearFake payload delivery domain (confidence level: 100%)
domainf1099947.xsph.ru
DCRat botnet C2 domain (confidence level: 100%)
domainyourprizehere.com
PlugX botnet C2 domain (confidence level: 75%)
domaincheck.myrap.icu
ClearFake payload delivery domain (confidence level: 100%)
domaincpcalendars.gameswithufabet.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcontacts.businesseshub.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebdisk.touchufabetgames.xyz
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.businesssabart.xyz
Havoc botnet C2 domain (confidence level: 100%)
domaincpcalendars.superbbusiness.website
Havoc botnet C2 domain (confidence level: 100%)
domainwebmail.magzineviralzhubz.xyz
Havoc botnet C2 domain (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://twilightbobofoglade.xyz/ode4ytdiymy1ytdl/
Coper botnet C2 (confidence level: 100%)
urlhttps://shadowgocolospire.xyz/mzvlmgq1zjgxztc5/
Coper botnet C2 (confidence level: 100%)
urlhttps://radiantkokocopeak.xyz/mzexmzm0ytq2zgrk/
Coper botnet C2 (confidence level: 100%)
urlhttps://check.hegop.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://42.51.12.243:18443/eddp
Cobalt Strike botnet C2 (confidence level: 75%)
urlhttp://839805cm.nyashk.ru/vmjavascriptsecuregeneratordatalifecdn.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://396608cm.nyashk.ru/pipepythonauthdefaultlinuxwindowsgeneratorwordpress.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://check.nyrar.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://check.vavoj.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://xtxtpqpyaaek4p4525ksepyyy75gfvi47fptm2gftw7cn656rnfhzdqd.onion/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttp://p7teg7yh2dwxg2tsbgnki3zrt5p7wgaegtfh4cobeqbhcq55nwt2m6yd.onion/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://check.dalut.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://15.204.95.223/mk6nn70wu6hrji89.php
Stealc botnet C2 (confidence level: 50%)
urlhttp://a1097571.xsph.ru/2fa1bf7c.php
DCRat botnet C2 (confidence level: 50%)
urlhttp://176.65.137.47/
Hook botnet C2 (confidence level: 50%)
urlhttps://www.bratusferramentas.grupomoltz.com.br/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://twitch.miami/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttp://109.206.241.81/htdocs/wdwqzmbhjqntanr.exe
MASS Logger payload delivery URL (confidence level: 50%)
urlhttp://81.161.229.110/htdocs/hnykjfzszbpprhg.exe
MASS Logger payload delivery URL (confidence level: 50%)
urlhttp://81.161.229.110/htdocs/raqneqpjbnogszg.exe
MASS Logger payload delivery URL (confidence level: 50%)
urlhttp://81.161.229.110/htdocs/tehrftmzkjbpxpp.exe
MASS Logger payload delivery URL (confidence level: 50%)
urlhttp://81.161.229.110/htdocs/gtfyhanmmstrewk.exe
MASS Logger payload delivery URL (confidence level: 50%)
urlhttp://37.139.129.142/htdocs/xkqesjpetwmqwor.exe
MASS Logger payload delivery URL (confidence level: 50%)
urlhttp://37.139.129.142/htdocs/ccagzmdbfxyxjyp.exe
MASS Logger payload delivery URL (confidence level: 50%)
urlhttp://37.139.129.142/htdocs/cmdtmbhfqptykgk.exe
MASS Logger payload delivery URL (confidence level: 50%)
urlhttp://81.161.229.110/htdocs/cipqxjgngwskxjn.exe
MASS Logger payload delivery URL (confidence level: 50%)
urlhttp://109.206.241.81/htdocs/xrkxbdndgkmasms.exe
MASS Logger payload delivery URL (confidence level: 50%)
urlhttps://check.xylor.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://www.1gv52.top/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.4109a37a693.xyz/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.51je936qi.sbs/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.6m86.xyz/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.abysitter-service-32322.bond/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ags-under-999516409.click/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.andoes.tech/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.anglore-flats-gov01.today/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.archattinfobreach2024.net/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.arehouse-jobs-43584.bond/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.aybankz.click/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.aycrk.net/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.b777.top/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.bgripl.xyz/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ddanything.win/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.dtech.team/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ecurity-jobs-61871.bond/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ell-property-32572.bond/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.emglobal.net/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.enesiscorporation.tech/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.estdrivencompliance.net/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.etoxsecrets.today/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.exbjfpbxhjcgzsdgumh.shop/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.fqbjnaw.xyz/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.g-poc.net/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.hestarterkit.xyz/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.hiseledvisions.art/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ihdwt.info/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.itchens-31.bond/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ixel49.shop/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.kin-rejuvenation-60489.bond/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.kin-rejuvenation-67012.bond/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.log987resultbest.shop/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.mcb.info/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.nmali.top/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.nolises.shop/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ntesa.group/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.obahrainiioyiq.shop/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.oho.uno/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.olawanliao33.click/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ollipop.group/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.oloactive.college/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ome-loans-72725.bond/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.onda1.cloud/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ontacttracingwristband.net/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.oorso.live/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ootox.xyz/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.orussiansthub987q.shop/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.oyalthaiherb.net/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.parkautotransport.website/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.pdld.net/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.phconline.info/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.pvoqftnckomcx.shop/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.redit-cards-46185.bond/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ressconversation.run/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.rview.net/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.sgazaproject.net/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.tgr.pro/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.tudy-in-spain-58534.bond/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.umpsiconi.shop/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.urseryinfo.net/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.vwhay.info/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.wmzotvekqsnbaxvf.shop/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.yperpigmentation-45231.bond/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.zhexifniu.top/v32e/
Formbook botnet C2 (confidence level: 50%)
urlhttps://pastebin.com/raw/ckhqqfk6
XWorm botnet C2 (confidence level: 50%)
urlhttps://pastebin.com/raw/kesyt2qf
XWorm botnet C2 (confidence level: 50%)
urlhttps://pastebin.com/raw/m2frwqcp
XWorm botnet C2 (confidence level: 50%)
urlhttps://pastebin.com/raw/ku06s0rk
XWorm botnet C2 (confidence level: 50%)
urlhttps://check.papeb.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://spikyscaldeo.cyou/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://snuegglypillow.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://check.jemyq.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://agriculthub.run/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://agriework.life/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://arisechairedd.shop/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://analgcslab.run/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://comrfyclouds.run/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://cozsmicjo.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://cjuddlepillows.icu/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://absoulpushx.life/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://farmercommunity.life/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://dataexzorers.icu/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://croprojegies.run/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://discxeryspace.icu/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://fahentures.today/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://explqngscience.life/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://cropmqttools.today/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://envirbntalstudies.shop/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://fieldies.bet/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://gengfocus.today/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://modelshiverd.icu/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://gestryfocus.run/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://greenfieldsnetwork.bet/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://heritagebreeds.run/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://garagedrootz.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://labdizeries.run/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://gardeninggains.bet/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://mathinsighjts.shop/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://puillowjourney.icu/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://scienssights.today/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://orchardinspiration.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://paradoxxedin.world/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://permaculturepath.run/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://scienxonnect.run/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://organicgrowershub.shop/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://ossifiedreduio.shop/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://scizencehub.life/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://spitestrippe.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://soilandseed.icu/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://scientififange.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://citxresearchers.icu/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://fuurxchnologies.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://farfinable.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://moderzysics.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://reseagetwork.top/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://check.jipaf.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://eearthsymphzony.today/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://explorebieology.run/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://hphygcsforum.life/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://ktechspherxe.top/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://techworld2025.top/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttp://baitfurniture.xyz/lod.php
Unknown Loader botnet C2 (confidence level: 100%)
urlhttp://baitfurniture.xyz/dol.php
Unknown Loader botnet C2 (confidence level: 100%)
urlhttps://mallternet.com/6t5t.js
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://mallternet.com/js.php
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://medicamentsbonmarche.top/files/original.js
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://medicamentsbonmarche.top/files/index.php
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://medicamentsbonmarche.top/files/fill.php
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://urethaneai.com/euler.zip
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://neckscissors.icu/art.php
Unknown Loader botnet C2 (confidence level: 100%)
urlhttps://check.mepum.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttp://110.41.78.57:8443/signin
Cobalt Strike botnet C2 (confidence level: 75%)
urlhttp://housescherries.xyz/lod.php
Unknown Loader botnet C2 (confidence level: 100%)
urlhttp://housescherries.xyz/dol.php
Unknown Loader botnet C2 (confidence level: 100%)
urlhttp://achieverocean.icu/rido.php
Unknown Loader botnet C2 (confidence level: 100%)
urlhttps://followfauc.cyou/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://check.vadom.icu/gkcxv.google
ClearFake payload delivery URL (confidence level: 100%)
urlhttps://api.telegram.org/bot7351654760:aafbpzozsrkzkocjv2by7hbybl3xngeouru/
Agent Tesla botnet C2 (confidence level: 50%)
urlhttps://pastebin.com/raw/fgmkahud
XWorm botnet C2 (confidence level: 50%)
urlhttp://cz91472.tw1.ru/584c48a0.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://6catterjur.run/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://9garagedrootz.top/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://agroecologyguide.digital/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://bcodxefusion.top/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://begindecafer.world/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://bexarthynature.run/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://bquietswtreams.life/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://bz2ncodxefusion.top/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://catterjur.run/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://cropcircleforum.today/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://defaulemot.run/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://fostinjec.today/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://gmodelshiverd.icu/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://j8arisechairedd.shop/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://jquietswtreams.life/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://kmoderzysics.top/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://ksterpickced.digital/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://orangemyther.live/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://pgadgethgfub.icu/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://phygcsforum.life/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://rcodxefusion.top/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://seedsxouts.shop/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://shardrwarehaven.run/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://sterpickced.digital/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://utechspherxe.top/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://xcollapimga.fun/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://xexarthynature.run/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://acatterjur.run/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://nebdulaq.digital/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://8sterpickced.digital/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://vyafostinjec.today/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://6sterpickced.digital/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://fcatterjur.run/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://6naturewsounds.help/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://fxreshideas.tech/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://iblastikcn.com/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://lestagames.world/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://nbdsfljsdfjewf.info/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://oblastikcn.com/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://pstormlegue.com/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://qblastikcn.com/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://unaturewsounds.help/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://yshiningrstars.help/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://actiothreaz.com/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://bgarulouscuto.com/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://inputrreparnt.com/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://rebeldettern.com/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://sbreedertremnd.com/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://torpdidebar.com/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://voicesharped.com/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://zimportenptoc.com/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://go.f.goldenloafuae.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://begindecafer.world/qwdzdf
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://arisechairedd.shop/jnshy
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://garisechairedd.shop/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://0modelshiverd.icu/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://googlesupport.info/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://twitch.care/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://kick.ngo/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://linktree.bz/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://linktree.bz/djdaniel
Unknown malware payload delivery URL (confidence level: 50%)
urlhttp://42.233.146.156:41970/mozi.m
Mozi payload delivery URL (confidence level: 50%)
urlhttp://dugong.ydns.eu//gtthfbsb2h.php
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://95.164.53.3/contact
AMOS botnet C2 (confidence level: 100%)
urlhttps://agriwellness.world/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://jcropcircleforum.today/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://rseedsxouts.shop/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://zfurrycomp.top/api
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://astralconnec.icu/api
Lumma Stealer botnet C2 (confidence level: 50%)

File

ValueDescriptionCopy
file39.105.6.249
Cobalt Strike botnet C2 server (confidence level: 100%)
file188.166.245.198
Cobalt Strike botnet C2 server (confidence level: 100%)
file107.173.203.208
Cobalt Strike botnet C2 server (confidence level: 100%)
file189.150.90.39
DarkComet botnet C2 server (confidence level: 100%)
file163.5.32.240
Remcos botnet C2 server (confidence level: 100%)
file142.93.68.220
Sliver botnet C2 server (confidence level: 100%)
file157.20.182.12
AsyncRAT botnet C2 server (confidence level: 100%)
file128.90.106.143
AsyncRAT botnet C2 server (confidence level: 100%)
file164.92.184.13
Unknown malware botnet C2 server (confidence level: 100%)
file20.63.112.130
Unknown malware botnet C2 server (confidence level: 100%)
file95.111.243.2
Havoc botnet C2 server (confidence level: 100%)
file201.43.190.225
Havoc botnet C2 server (confidence level: 100%)
file46.246.86.12
DCRat botnet C2 server (confidence level: 100%)
file196.251.71.233
DCRat botnet C2 server (confidence level: 100%)
file196.251.72.206
DCRat botnet C2 server (confidence level: 100%)
file101.32.60.83
Unknown malware botnet C2 server (confidence level: 100%)
file43.153.203.11
MimiKatz botnet C2 server (confidence level: 100%)
file108.61.229.202
BianLian botnet C2 server (confidence level: 100%)
file42.51.12.243
Meterpreter botnet C2 server (confidence level: 100%)
file23.235.165.5
ValleyRAT botnet C2 server (confidence level: 100%)
file1.12.233.147
Cobalt Strike botnet C2 server (confidence level: 100%)
file196.251.70.67
Remcos botnet C2 server (confidence level: 100%)
file190.144.146.90
Remcos botnet C2 server (confidence level: 100%)
file5.180.27.6
Sliver botnet C2 server (confidence level: 100%)
file74.50.120.69
AsyncRAT botnet C2 server (confidence level: 100%)
file74.50.120.69
AsyncRAT botnet C2 server (confidence level: 100%)
file144.172.113.109
AsyncRAT botnet C2 server (confidence level: 100%)
file94.232.246.119
Unknown malware botnet C2 server (confidence level: 100%)
file195.177.94.87
Hook botnet C2 server (confidence level: 100%)
file45.92.1.37
Hook botnet C2 server (confidence level: 100%)
file198.244.227.72
Quasar RAT botnet C2 server (confidence level: 100%)
file46.246.86.8
DCRat botnet C2 server (confidence level: 100%)
file166.108.236.192
DCRat botnet C2 server (confidence level: 100%)
file3.99.139.81
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file152.32.239.207
Brute Ratel C4 botnet C2 server (confidence level: 100%)
file77.90.153.24
Meduza Stealer botnet C2 server (confidence level: 100%)
file84.200.17.247
Unknown malware botnet C2 server (confidence level: 100%)
file8.137.34.11
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.154.208.36
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.237.92.118
DCRat botnet C2 server (confidence level: 100%)
file139.159.212.103
Unknown malware botnet C2 server (confidence level: 100%)
file3.37.199.32
Unknown malware botnet C2 server (confidence level: 100%)
file142.93.193.20
Unknown malware botnet C2 server (confidence level: 100%)
file167.86.87.83
Unknown malware botnet C2 server (confidence level: 100%)
file165.232.183.120
Unknown malware botnet C2 server (confidence level: 100%)
file45.143.234.81
Unknown malware botnet C2 server (confidence level: 100%)
file213.199.62.93
Unknown malware botnet C2 server (confidence level: 100%)
file3.16.88.170
Unknown malware botnet C2 server (confidence level: 100%)
file101.200.86.176
Unknown malware botnet C2 server (confidence level: 100%)
file154.44.10.137
Unknown malware botnet C2 server (confidence level: 100%)
file188.245.162.206
Unknown malware botnet C2 server (confidence level: 100%)
file34.199.213.212
Unknown malware botnet C2 server (confidence level: 100%)
file119.91.249.127
Unknown malware botnet C2 server (confidence level: 100%)
file13.60.206.246
Unknown malware botnet C2 server (confidence level: 100%)
file68.183.76.62
Unknown malware botnet C2 server (confidence level: 100%)
file52.29.22.28
Unknown malware botnet C2 server (confidence level: 100%)
file195.211.98.236
Unknown malware botnet C2 server (confidence level: 100%)
file52.59.145.165
Unknown malware botnet C2 server (confidence level: 100%)
file52.59.145.165
Unknown malware botnet C2 server (confidence level: 100%)
file138.68.187.212
Unknown malware botnet C2 server (confidence level: 100%)
file88.202.247.87
Bashlite botnet C2 server (confidence level: 90%)
file162.252.173.253
BianLian botnet C2 server (confidence level: 100%)
file196.251.80.197
Remcos botnet C2 server (confidence level: 100%)
file196.251.89.42
XWorm botnet C2 server (confidence level: 50%)
file193.161.193.99
XWorm botnet C2 server (confidence level: 50%)
file193.161.193.99
XWorm botnet C2 server (confidence level: 50%)
file147.185.221.26
XWorm botnet C2 server (confidence level: 50%)
file147.185.221.26
XWorm botnet C2 server (confidence level: 50%)
file172.233.26.237
Cobalt Strike botnet C2 server (confidence level: 100%)
file40.81.23.3
Cobalt Strike botnet C2 server (confidence level: 100%)
file4.201.156.203
Remcos botnet C2 server (confidence level: 100%)
file185.202.173.24
Remcos botnet C2 server (confidence level: 100%)
file196.251.73.236
Remcos botnet C2 server (confidence level: 100%)
file107.155.93.118
AsyncRAT botnet C2 server (confidence level: 100%)
file198.23.158.69
AsyncRAT botnet C2 server (confidence level: 100%)
file172.81.133.157
AsyncRAT botnet C2 server (confidence level: 100%)
file172.81.133.157
AsyncRAT botnet C2 server (confidence level: 100%)
file13.201.109.246
Unknown malware botnet C2 server (confidence level: 100%)
file161.248.87.218
ValleyRAT botnet C2 server (confidence level: 100%)
file172.232.58.169
QakBot botnet C2 server (confidence level: 75%)
file171.22.124.148
Unknown malware botnet C2 server (confidence level: 75%)
file188.49.85.130
QakBot botnet C2 server (confidence level: 75%)
file70.27.138.78
QakBot botnet C2 server (confidence level: 75%)
file96.62.89.102
DeimosC2 botnet C2 server (confidence level: 75%)
file103.79.120.81
PlugX botnet C2 server (confidence level: 75%)
file103.79.120.81
PlugX botnet C2 server (confidence level: 75%)
file38.55.194.217
Cobalt Strike botnet C2 server (confidence level: 100%)
file124.70.161.86
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.217.240.48
Cobalt Strike botnet C2 server (confidence level: 100%)
file119.8.123.163
Cobalt Strike botnet C2 server (confidence level: 100%)
file51.15.15.47
Cobalt Strike botnet C2 server (confidence level: 50%)
file48.209.24.173
Cobalt Strike botnet C2 server (confidence level: 50%)
file154.204.58.62
Cobalt Strike botnet C2 server (confidence level: 50%)
file43.154.208.36
Cobalt Strike botnet C2 server (confidence level: 50%)
file80.78.28.74
Sliver botnet C2 server (confidence level: 50%)
file151.115.54.25
Sliver botnet C2 server (confidence level: 50%)
file191.238.215.146
Sliver botnet C2 server (confidence level: 50%)
file45.61.169.127
Sliver botnet C2 server (confidence level: 50%)
file107.170.47.47
Sliver botnet C2 server (confidence level: 50%)
file65.109.6.39
Sliver botnet C2 server (confidence level: 50%)
file150.95.104.230
Sliver botnet C2 server (confidence level: 50%)
file78.47.55.114
Sliver botnet C2 server (confidence level: 50%)
file39.106.64.161
Cobalt Strike botnet C2 server (confidence level: 50%)
file121.40.25.10
Cobalt Strike botnet C2 server (confidence level: 50%)
file46.101.97.133
Unknown malware botnet C2 server (confidence level: 50%)
file91.228.113.199
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file196.251.80.231
Quasar RAT botnet C2 server (confidence level: 50%)
file104.168.19.195
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.85.225.159
Cobalt Strike botnet C2 server (confidence level: 100%)
file128.199.162.141
Cobalt Strike botnet C2 server (confidence level: 100%)
file117.72.123.75
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.238.82.255
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.8.160.34
Cobalt Strike botnet C2 server (confidence level: 100%)
file139.155.239.97
Cobalt Strike botnet C2 server (confidence level: 100%)
file54.177.153.237
Unknown malware botnet C2 server (confidence level: 50%)
file165.154.236.59
pupy botnet C2 server (confidence level: 100%)
file47.238.99.93
Sliver botnet C2 server (confidence level: 100%)
file196.251.83.66
AsyncRAT botnet C2 server (confidence level: 100%)
file185.241.208.107
AsyncRAT botnet C2 server (confidence level: 100%)
file196.251.73.154
Unknown malware botnet C2 server (confidence level: 100%)
file176.65.137.47
Hook botnet C2 server (confidence level: 100%)
file192.117.9.22
Havoc botnet C2 server (confidence level: 100%)
file195.82.146.19
DCRat botnet C2 server (confidence level: 100%)
file195.82.146.19
DCRat botnet C2 server (confidence level: 100%)
file195.82.147.35
DCRat botnet C2 server (confidence level: 100%)
file18.195.207.4
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file47.109.40.109
Chaos botnet C2 server (confidence level: 100%)
file47.108.221.225
Chaos botnet C2 server (confidence level: 100%)
file146.185.233.97
Remcos botnet C2 server (confidence level: 75%)
file81.19.131.95
Remcos botnet C2 server (confidence level: 75%)
file112.29.119.178
Cobalt Strike botnet C2 server (confidence level: 75%)
file117.135.134.251
Cobalt Strike botnet C2 server (confidence level: 75%)
file119.147.148.209
Cobalt Strike botnet C2 server (confidence level: 75%)
file119.84.72.217
Cobalt Strike botnet C2 server (confidence level: 75%)
file139.170.201.74
Cobalt Strike botnet C2 server (confidence level: 75%)
file182.242.63.197
Cobalt Strike botnet C2 server (confidence level: 75%)
file192.241.195.81
Cobalt Strike botnet C2 server (confidence level: 75%)
file220.181.166.212
Cobalt Strike botnet C2 server (confidence level: 75%)
file36.102.212.122
Cobalt Strike botnet C2 server (confidence level: 75%)
file52.255.166.103
Cobalt Strike botnet C2 server (confidence level: 75%)
file58.220.52.248
Cobalt Strike botnet C2 server (confidence level: 75%)
file198.135.50.146
Remcos botnet C2 server (confidence level: 75%)
file103.198.26.27
Remcos botnet C2 server (confidence level: 75%)
file147.124.212.231
XWorm botnet C2 server (confidence level: 75%)
file193.32.177.63
XWorm botnet C2 server (confidence level: 75%)
file45.55.147.15
Sliver botnet C2 server (confidence level: 50%)
file108.252.227.16
DCRat botnet C2 server (confidence level: 50%)
file13.126.242.222
Unknown malware botnet C2 server (confidence level: 50%)
file54.204.231.234
Unknown malware botnet C2 server (confidence level: 50%)
file193.161.193.99
XWorm botnet C2 server (confidence level: 50%)
file47.122.38.153
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.122.38.153
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.63.1.46
pupy botnet C2 server (confidence level: 100%)
file143.198.249.246
Sliver botnet C2 server (confidence level: 100%)
file23.102.57.55
Sliver botnet C2 server (confidence level: 100%)
file196.251.71.233
AsyncRAT botnet C2 server (confidence level: 100%)
file196.251.90.23
AsyncRAT botnet C2 server (confidence level: 100%)
file157.173.195.46
AsyncRAT botnet C2 server (confidence level: 100%)
file86.38.225.152
AsyncRAT botnet C2 server (confidence level: 100%)
file191.17.93.118
Quasar RAT botnet C2 server (confidence level: 100%)
file38.132.122.177
Havoc botnet C2 server (confidence level: 100%)
file38.132.122.177
Havoc botnet C2 server (confidence level: 100%)
file179.43.180.114
Quasar RAT botnet C2 server (confidence level: 100%)
file154.23.184.30
ValleyRAT botnet C2 server (confidence level: 75%)
file107.189.27.66
Amadey botnet C2 server (confidence level: 75%)
file18.222.225.114
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file82.116.44.82
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file5.180.148.33
Sliver botnet C2 server (confidence level: 50%)
file147.185.221.25
XWorm botnet C2 server (confidence level: 50%)
file176.113.115.96
Socks5 Systemz botnet C2 server (confidence level: 75%)
file5.180.155.29
XWorm botnet C2 server (confidence level: 75%)
file13.214.5.139
Cobalt Strike botnet C2 server (confidence level: 75%)
file185.156.73.73
GCleaner botnet C2 server (confidence level: 75%)
file8.218.113.210
Ghost RAT botnet C2 server (confidence level: 75%)
file38.180.229.217
Unknown malware botnet C2 server (confidence level: 75%)
file95.164.53.3
AMOS botnet C2 server (confidence level: 75%)
file193.233.113.70
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file45.137.22.249
RedLine Stealer botnet C2 server (confidence level: 100%)
file47.95.8.59
Cobalt Strike botnet C2 server (confidence level: 100%)
file198.46.178.132
Remcos botnet C2 server (confidence level: 75%)
file198.46.178.132
Remcos botnet C2 server (confidence level: 75%)
file74.50.94.137
Remcos botnet C2 server (confidence level: 100%)
file120.27.223.96
Sliver botnet C2 server (confidence level: 100%)
file94.237.67.85
Sliver botnet C2 server (confidence level: 100%)
file18.97.23.200
Havoc botnet C2 server (confidence level: 100%)
file54.183.190.151
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file20.229.103.183
XWorm botnet C2 server (confidence level: 100%)
file20.229.103.183
XWorm botnet C2 server (confidence level: 100%)
file151.236.16.20
BianLian botnet C2 server (confidence level: 100%)
file18.213.45.241
DeimosC2 botnet C2 server (confidence level: 75%)
file46.246.134.27
QakBot botnet C2 server (confidence level: 75%)
file88.232.102.73
QakBot botnet C2 server (confidence level: 75%)
file45.137.22.163
RedLine Stealer botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash8787
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash1604
DarkComet botnet C2 server (confidence level: 100%)
hash30360
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash4443
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash8081
Havoc botnet C2 server (confidence level: 100%)
hash9000
DCRat botnet C2 server (confidence level: 100%)
hash2000
DCRat botnet C2 server (confidence level: 100%)
hash2000
DCRat botnet C2 server (confidence level: 100%)
hash4000
Unknown malware botnet C2 server (confidence level: 100%)
hash8088
MimiKatz botnet C2 server (confidence level: 100%)
hash1433
BianLian botnet C2 server (confidence level: 100%)
hash18443
Meterpreter botnet C2 server (confidence level: 100%)
hash443
ValleyRAT botnet C2 server (confidence level: 100%)
hash8081
Cobalt Strike botnet C2 server (confidence level: 100%)
hash789
Remcos botnet C2 server (confidence level: 100%)
hash5509
Remcos botnet C2 server (confidence level: 100%)
hash8443
Sliver botnet C2 server (confidence level: 100%)
hash2004
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash443
Quasar RAT botnet C2 server (confidence level: 100%)
hash2000
DCRat botnet C2 server (confidence level: 100%)
hash8848
DCRat botnet C2 server (confidence level: 100%)
hash16992
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash50000
Brute Ratel C4 botnet C2 server (confidence level: 100%)
hash80
Meduza Stealer botnet C2 server (confidence level: 100%)
hash4000
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
DCRat botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash9090
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash65007
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash23
Bashlite botnet C2 server (confidence level: 90%)
hash5619
BianLian botnet C2 server (confidence level: 100%)
hash3914
Remcos botnet C2 server (confidence level: 100%)
hash2121
XWorm botnet C2 server (confidence level: 50%)
hash36577
XWorm botnet C2 server (confidence level: 50%)
hash61193
XWorm botnet C2 server (confidence level: 50%)
hash32463
XWorm botnet C2 server (confidence level: 50%)
hash19376
XWorm botnet C2 server (confidence level: 50%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash80
Remcos botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash10443
ValleyRAT botnet C2 server (confidence level: 100%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash60000
Unknown malware botnet C2 server (confidence level: 75%)
hash995
QakBot botnet C2 server (confidence level: 75%)
hash2222
QakBot botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash5000
PlugX botnet C2 server (confidence level: 75%)
hash443
PlugX botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash1234
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8088
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash8764
Cobalt Strike botnet C2 server (confidence level: 50%)
hash9443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Unknown malware botnet C2 server (confidence level: 50%)
hash9028
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash9001
Quasar RAT botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash11255
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8085
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 50%)
hash443
pupy botnet C2 server (confidence level: 100%)
hash39601
Sliver botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash100
AsyncRAT botnet C2 server (confidence level: 100%)
hash9000
Unknown malware botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash8443
Havoc botnet C2 server (confidence level: 100%)
hash8090
DCRat botnet C2 server (confidence level: 100%)
hash4443
DCRat botnet C2 server (confidence level: 100%)
hash8080
DCRat botnet C2 server (confidence level: 100%)
hash8000
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash54681
Chaos botnet C2 server (confidence level: 100%)
hash54681
Chaos botnet C2 server (confidence level: 100%)
hash6856
Remcos botnet C2 server (confidence level: 75%)
hash6856
Remcos botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash59786
Remcos botnet C2 server (confidence level: 75%)
hash9373
Remcos botnet C2 server (confidence level: 75%)
hash6262
XWorm botnet C2 server (confidence level: 75%)
hash6000
XWorm botnet C2 server (confidence level: 75%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash3001
DCRat botnet C2 server (confidence level: 50%)
hash2067
Unknown malware botnet C2 server (confidence level: 50%)
hash443
Unknown malware botnet C2 server (confidence level: 50%)
hash22770
XWorm botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9999
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
pupy botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash8888
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash1888
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash5000
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash15443
Havoc botnet C2 server (confidence level: 100%)
hash4050
Quasar RAT botnet C2 server (confidence level: 100%)
hash10443
ValleyRAT botnet C2 server (confidence level: 75%)
hash80
Amadey botnet C2 server (confidence level: 75%)
hash8649
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash65
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash19243
XWorm botnet C2 server (confidence level: 50%)
hash443
Socks5 Systemz botnet C2 server (confidence level: 75%)
hash6666
XWorm botnet C2 server (confidence level: 75%)
hash53
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
GCleaner botnet C2 server (confidence level: 75%)
hash8080
Ghost RAT botnet C2 server (confidence level: 75%)
hash80
Unknown malware botnet C2 server (confidence level: 75%)
hash80
AMOS botnet C2 server (confidence level: 75%)
hash1488
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash55615
RedLine Stealer botnet C2 server (confidence level: 100%)
hash808
Cobalt Strike botnet C2 server (confidence level: 100%)
hash16446
Remcos botnet C2 server (confidence level: 75%)
hash16454
Remcos botnet C2 server (confidence level: 75%)
hash9774
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash8000
Sliver botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash5671
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash80
XWorm botnet C2 server (confidence level: 100%)
hash443
XWorm botnet C2 server (confidence level: 100%)
hash52395
BianLian botnet C2 server (confidence level: 100%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash995
QakBot botnet C2 server (confidence level: 75%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash55615
RedLine Stealer botnet C2 server (confidence level: 100%)

Threat ID: 682c7dbce8347ec82d2c4d94

Added to database: 5/20/2025, 1:03:56 PM

Last enriched: 6/19/2025, 4:17:14 PM

Last updated: 7/14/2025, 2:01:31 PM

Views: 22

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats