Skip to main content

ThreatFox IOCs for 2025-05-08

Medium
Published: Thu May 08 2025 (05/08/2025, 00:00:00 UTC)
Source: ThreatFox
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-05-08

AI-Powered Analysis

AILast updated: 06/19/2025, 14:48:55 UTC

Technical Analysis

The provided threat intelligence relates to a malware-type threat identified as 'ThreatFox IOCs for 2025-05-08,' sourced from ThreatFox, a platform known for sharing Indicators of Compromise (IOCs) and threat intelligence data. The threat is categorized under 'osint' (open-source intelligence) and tagged with 'type:osint' and 'tlp:white,' indicating that the information is intended for broad sharing without restrictions. There are no specific affected product versions or CWE (Common Weakness Enumeration) identifiers listed, and no patch links or known exploits in the wild have been reported. The technical details include a threat level of 2 (on an unspecified scale), an analysis rating of 1, and a distribution rating of 3, suggesting moderate dissemination or presence. The absence of concrete IOCs or detailed technical indicators limits the granularity of the analysis. The threat appears to be a medium-severity malware-related intelligence report, likely aggregating or sharing IOCs relevant for OSINT practitioners or security teams to enhance detection capabilities. Given the lack of specific affected software or vulnerabilities, this threat likely represents a general malware campaign or emerging malware family rather than a targeted zero-day or exploit. The information is dated May 8, 2025, indicating it is current and relevant for proactive defense measures. Overall, this threat intelligence serves as a situational awareness update rather than a detailed technical exploit or vulnerability disclosure.

Potential Impact

For European organizations, the impact of this threat is currently assessed as medium due to the lack of specific exploit details or known active campaigns. However, malware threats disseminated through OSINT channels can lead to increased risk of infection if organizations do not update their detection and response mechanisms accordingly. Potential impacts include unauthorized access, data exfiltration, disruption of services, or lateral movement within networks if the malware is successfully deployed. Given the absence of known exploits in the wild, immediate large-scale impact is unlikely, but the presence of distributed indicators suggests that threat actors may be preparing or conducting reconnaissance. European organizations with mature cybersecurity operations that integrate OSINT feeds into their threat hunting and detection workflows will be better positioned to mitigate risks. Conversely, organizations lacking such capabilities may face delayed detection and response, increasing potential damage. The medium severity reflects a moderate risk that warrants attention but does not indicate an imminent critical threat.

Mitigation Recommendations

1. Integrate ThreatFox and similar OSINT feeds into existing Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) platforms to enhance detection of emerging malware indicators. 2. Conduct regular threat hunting exercises focused on newly published IOCs, even if no active exploit is reported, to identify potential early signs of compromise. 3. Maintain up-to-date endpoint and network security solutions with behavioral analysis capabilities to detect anomalous activities associated with unknown or emerging malware. 4. Implement strict network segmentation and least privilege access controls to limit potential lateral movement if malware is introduced. 5. Educate security teams on interpreting and operationalizing OSINT-based threat intelligence to improve proactive defense measures. 6. Establish incident response playbooks that include procedures for handling malware infections identified through OSINT indicators. 7. Monitor relevant threat intelligence communities and update detection rules promptly as more detailed information or exploits emerge. These recommendations go beyond generic advice by emphasizing the operational integration of OSINT feeds and proactive threat hunting tailored to the nature of this intelligence.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
6e9703ed-8197-4e8f-b731-1f14206a51b9
Original Timestamp
1746748985

Indicators of Compromise

Domain

ValueDescriptionCopy
domainntmmh.run
ClearFake payload delivery domain (confidence level: 100%)
domainaimpes.com
KongTuke payload delivery domain (confidence level: 100%)
domaintchmitt.live
KongTuke payload delivery domain (confidence level: 100%)
domaingfddx.run
ClearFake payload delivery domain (confidence level: 100%)
domaindf-www.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainen-koinly.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainmetatradar5.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainoptislgns.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainpaychex-us.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainbbvanetcashs.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainwww.qik.su
Unknown Loader payload delivery domain (confidence level: 90%)
domain4kdownloadl.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaintechsmlth.store
Unknown Loader payload delivery domain (confidence level: 90%)
domainccieaner.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainkoinly-en.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainzoho-us.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaindv-www.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainen-payroll.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaineasycrypto.su
Unknown Loader payload delivery domain (confidence level: 90%)
domainwww.dp-www.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainwww.cisco-us.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainaudacltyteam.org
Unknown Loader payload delivery domain (confidence level: 90%)
domaincllcktime.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainquantower.site
Unknown Loader payload delivery domain (confidence level: 90%)
domainquantower.pw
Unknown Loader payload delivery domain (confidence level: 90%)
domainadoobes.store
Unknown Loader payload delivery domain (confidence level: 90%)
domainsportsenginec.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainapachefrlends.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaindk-www.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainxrpscan-en.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaincoinomi.pw
Unknown Loader payload delivery domain (confidence level: 90%)
domainen-sdccu.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainmonadls.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainweb-chatgpt.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainccieaner.store
Unknown Loader payload delivery domain (confidence level: 90%)
domainwww.drr-www.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainmetatradar5.store
Unknown Loader payload delivery domain (confidence level: 90%)
domainkeepassw.info
Unknown Loader payload delivery domain (confidence level: 90%)
domainweb.guarda.pw
Unknown Loader payload delivery domain (confidence level: 90%)
domainfloridarealestatechool.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainwww.dq-www.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainwww.dy-www.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainbot.installs.pro
Unknown Loader payload delivery domain (confidence level: 90%)
domainweb-silkai.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainwasabiwallet.pw
Unknown Loader payload delivery domain (confidence level: 90%)
domainmoblsystems.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainopenofflce.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainmanageenglne.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaindg-www.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainnewrelic-en.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaintlger.store
Unknown Loader payload delivery domain (confidence level: 90%)
domainsultecrm.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaindo-www.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainwww.bawag-web.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainopenofflce.store
Unknown Loader payload delivery domain (confidence level: 90%)
domainninjaone-en.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaindu-www.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainadmin.prompasport.ru
Unknown Loader payload delivery domain (confidence level: 90%)
domaintechsmlth.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainapachefrlends.store
Unknown Loader payload delivery domain (confidence level: 90%)
domainbrightdata-en.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainsysaid-en.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainwww.shopmeyxchange.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaincoreidraw.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaincllcktime.store
Unknown Loader payload delivery domain (confidence level: 90%)
domainion-login.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainblendrer.org
Unknown Loader payload delivery domain (confidence level: 90%)
domainwww-yoast.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainquantower.su
Unknown Loader payload delivery domain (confidence level: 90%)
domain3cx-en.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainmoblerecharges.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainultraviewer-en.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaintlger.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainultravlewer.com
Unknown Loader payload delivery domain (confidence level: 90%)
domain4kdownloadl.store
Unknown Loader payload delivery domain (confidence level: 90%)
domaintesterscrypto.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainbitpay.pw
Unknown Loader payload delivery domain (confidence level: 90%)
domainsportsenginec.store
Unknown Loader payload delivery domain (confidence level: 90%)
domainjam-softwarec.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainpassword-en.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaindx-www.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainledgers.su
Unknown Loader payload delivery domain (confidence level: 90%)
domainmanageenglne.store
Unknown Loader payload delivery domain (confidence level: 90%)
domainbamboohr-en.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainweb-goodcrypto.com
Unknown Loader payload delivery domain (confidence level: 90%)
domainsymblosis.com
Unknown Loader payload delivery domain (confidence level: 90%)
domaintesterscrypto.store
Unknown Loader payload delivery domain (confidence level: 90%)
domainbbssj.run
ClearFake payload delivery domain (confidence level: 100%)
domainhspmj.run
ClearFake payload delivery domain (confidence level: 100%)
domainh1.glitzyentire.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainimprovxf.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaintribunap.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaintremelzxiy.live
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainthinkellk.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainapronsxrum.digital
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainec2-18-166-31-74.ap-east-1.compute.amazonaws.com
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainnl-2.193.27.90.134.nip.io
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainec2-44-246-89-112.us-west-2.compute.amazonaws.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainrazesec.com
Unknown malware botnet C2 domain (confidence level: 100%)
domaindotfoods.socalmediazone.com
Hook botnet C2 domain (confidence level: 100%)
domainsci.socalmediazone.com
Hook botnet C2 domain (confidence level: 100%)
domainxmlvm.run
ClearFake payload delivery domain (confidence level: 100%)
domaindjrtt.run
ClearFake payload delivery domain (confidence level: 100%)
domainpersongiants.icu
Unknown Loader botnet C2 domain (confidence level: 100%)
domainpreyinthewild.online
Unknown RAT botnet C2 domain (confidence level: 100%)
domainrkblm.run
ClearFake payload delivery domain (confidence level: 100%)
domainegiftshop.cloud
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainhighcouncipl.live
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaintapandshop.shop
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaintavernfolkk.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaintowerstozne.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainunmutezcx.live
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainviscosityobserving.shop
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainpmglw.run
ClearFake payload delivery domain (confidence level: 100%)
domainxkpdf.run
ClearFake payload delivery domain (confidence level: 100%)
domainqmzks.run
ClearFake payload delivery domain (confidence level: 100%)
domainjamesrockky.ydns.eu
AsyncRAT botnet C2 domain (confidence level: 50%)
domainriches20.kozow.com
AsyncRAT botnet C2 domain (confidence level: 50%)
domainsteveswiths.freemyip.com
AsyncRAT botnet C2 domain (confidence level: 50%)
domainbotnet.ethoneservices.xyz
Mirai botnet C2 domain (confidence level: 50%)
domainspec.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domainlenovo-sync.com
Unknown Stealer payload delivery domain (confidence level: 50%)
domainlife.judyfay.com
FAKEUPDATES payload delivery domain (confidence level: 50%)
domainnpknn.run
ClearFake payload delivery domain (confidence level: 100%)
domainnshpd.run
ClearFake payload delivery domain (confidence level: 100%)
domainsnhnv.run
ClearFake payload delivery domain (confidence level: 100%)
domainnoxajb.top
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainvoznessxyy.life
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainclatteqrpq.digital
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainninepicchf.bet
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincolliel.live
KongTuke payload delivery domain (confidence level: 100%)
domainfhtnt.run
ClearFake payload delivery domain (confidence level: 100%)
domainxtkdt.run
ClearFake payload delivery domain (confidence level: 100%)
domainmzrln.run
ClearFake payload delivery domain (confidence level: 100%)
domainsetup.bestoffersfortoday.store
Havoc botnet C2 domain (confidence level: 100%)
domain37-72-168-146.static.hvvc.us
Havoc botnet C2 domain (confidence level: 100%)
domainwizardly-cannon.51-195-229-85.plesk.page
Unknown malware botnet C2 domain (confidence level: 100%)
domainmobile-cff.app
Coper payload delivery domain (confidence level: 100%)
domainjohnoton.live
KongTuke payload delivery domain (confidence level: 100%)
domainmotocyclenews.top
NetSupportManager RAT payload delivery domain (confidence level: 100%)
domainterritoirespaysagistes.com
NetSupportManager RAT payload delivery domain (confidence level: 100%)
domainttxch.run
ClearFake payload delivery domain (confidence level: 100%)
domainwww.thefertilemine.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domain53d6c5e5e04f7e079df5d5d77bc259ea.us
Coper botnet C2 domain (confidence level: 100%)
domaindaqev.run
ClearFake payload delivery domain (confidence level: 100%)
domaincagom.run
ClearFake payload delivery domain (confidence level: 100%)
domainappli-cff.com
Coper payload delivery domain (confidence level: 100%)
domainmehig.run
ClearFake payload delivery domain (confidence level: 100%)
domainjodob.run
ClearFake payload delivery domain (confidence level: 100%)
domainsihen.run
ClearFake payload delivery domain (confidence level: 100%)
domainmyspecialdot.com
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainsohaeidacademy.com
Lumma Stealer botnet C2 domain (confidence level: 50%)
domaingenow.run
ClearFake payload delivery domain (confidence level: 100%)
domainfanpuy.com
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainminak.run
ClearFake payload delivery domain (confidence level: 100%)
domainfecif.run
ClearFake payload delivery domain (confidence level: 100%)
domainmskisdakw.top
SpyNote botnet C2 domain (confidence level: 100%)
domainfsdlaowaa.top
SpyNote botnet C2 domain (confidence level: 100%)
domainolympusgo.com
Cobalt Strike botnet C2 domain (confidence level: 75%)

Url

ValueDescriptionCopy
urlhttps://aimpes.com/6t4g.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://aimpes.com/js.php
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://tchmitt.live/log/in
KongTuke payload delivery URL (confidence level: 100%)
urlhttp://23.27.48.113:443/jquery-3.3.2.slim.min.js
Cobalt Strike botnet C2 (confidence level: 75%)
urlhttp://137.184.35.179:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://rocketlump.com/hdz
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://fanpuy.com/zxod
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://medikalbitkisel.org/pek
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://victoreqs.run/xapw
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://viridisw.top/qwed
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://toptalentw.top/qena
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://crocodilefg.top/qeji
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://wolverineas.top/xadw
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://steamcommunity.com/profiles/76561199845513035
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://t.me/kubasex
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttp://chongmei33.myddns.rocks:7046/is-ready
Houdini botnet C2 (confidence level: 100%)
urlhttps://2vecturar.top/zsia
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://agrizzlqzuk.live/qhbu
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://insidegrah.run/ieop
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttp://a1106686.xsph.ru/l1nc0in.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://baleturn.com/front.php
Satacom botnet C2 (confidence level: 100%)
urlhttps://fmecoutsm.com/diagnostics.php
Satacom botnet C2 (confidence level: 100%)
urlhttps://brotherreligion.xyz/art.php
Unknown Loader botnet C2 (confidence level: 100%)
urlhttp://troublesisters.xyz/oils.php
Unknown Loader botnet C2 (confidence level: 100%)
urlhttps://9octalfbsh.bet/mben
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://apronsxrum.digital/pwq
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://egrizzlqzuk.live/qhbu
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://grizzlqzuk.live/qhbu
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://oorijinalecza.net/kazd
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://tremelzxiy.live/atok
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttp://51.195.229.85/pages/login.php
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://ctortoisgfe.top/paxk
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://mariosefqcu.shop/wrqo
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://ohomewappzb.top/tqba
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://3k0monemiltxny.shop/tqiw
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://3yoctalfbsh.bet/mben
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://joctalfbsh.bet/mben
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://mstuffgull.top/qwio
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttp://85.192.48.2:50555/
Hook botnet C2 (confidence level: 50%)
urlhttp://103.74.101.88/
Hook botnet C2 (confidence level: 50%)
urlhttp://kruasanpcs.mywebcommunity.org/providerjavascriptupdategamebigloaddblinux.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://colliel.live/log/in
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://taskrunp.run/xnzbd
Lumma Stealer botnet C2 (confidence level: 50%)
urlhttps://johnoton.live/log/in
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://motocyclenews.top/jse/minjs.js
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://motocyclenews.top/jse/select.js
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://motocyclenews.top/jse/lll.php
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://territoirespaysagistes.com/buts.zip
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://www.thefertilemine.com/profilelayout
FAKEUPDATES botnet C2 (confidence level: 100%)
urlhttps://wishspy.xyz/art.php
Unknown Loader botnet C2 (confidence level: 100%)
urlhttps://3homewappzb.top/tqba
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://clatteqrpq.digital/kljz
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://ninepicchf.bet/lznd
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://tclatteqrpq.digital/kljz
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://voznessxyy.life/bnaz
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://8stuffgull.top/qwio
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://finsidegrah.run/ieop
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://ggrizzlqzuk.live/qhbu
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttp://92.63.102.85/2providertemporaryprivate/httpapitemporary6/4publicsecureauth/lowwindows/9/lowjsvoiddb/temporaryproton/videojavascripthttpserverprotectflowergeneratortrafficuploadsdownloads.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://raeneasq.live/nmgj
Lumma Stealer botnet C2 (confidence level: 75%)

File

ValueDescriptionCopy
file101.126.144.111
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.245.27.240
Cobalt Strike botnet C2 server (confidence level: 100%)
file104.37.4.100
Remcos botnet C2 server (confidence level: 100%)
file161.132.68.248
Sliver botnet C2 server (confidence level: 100%)
file196.251.73.133
AsyncRAT botnet C2 server (confidence level: 100%)
file176.65.142.198
AsyncRAT botnet C2 server (confidence level: 100%)
file176.65.142.198
AsyncRAT botnet C2 server (confidence level: 100%)
file196.251.117.82
AsyncRAT botnet C2 server (confidence level: 100%)
file85.192.48.2
Hook botnet C2 server (confidence level: 100%)
file212.224.107.135
Hook botnet C2 server (confidence level: 100%)
file192.121.246.166
Quasar RAT botnet C2 server (confidence level: 100%)
file191.13.208.53
Havoc botnet C2 server (confidence level: 100%)
file192.227.217.227
Venom RAT botnet C2 server (confidence level: 100%)
file139.84.132.65
MimiKatz botnet C2 server (confidence level: 100%)
file185.208.159.141
Latrodectus botnet C2 server (confidence level: 90%)
file101.35.235.124
Cobalt Strike botnet C2 server (confidence level: 100%)
file1.13.156.116
Cobalt Strike botnet C2 server (confidence level: 100%)
file111.230.212.37
Cobalt Strike botnet C2 server (confidence level: 100%)
file80.64.18.161
Lumma Stealer botnet C2 server (confidence level: 50%)
file46.246.84.12
Vjw0rm botnet C2 server (confidence level: 100%)
file46.246.84.12
AsyncRAT botnet C2 server (confidence level: 100%)
file152.42.199.84
Cobalt Strike botnet C2 server (confidence level: 75%)
file192.3.12.168
Cobalt Strike botnet C2 server (confidence level: 75%)
file192.3.12.168
Cobalt Strike botnet C2 server (confidence level: 75%)
file3.236.12.85
Sliver botnet C2 server (confidence level: 90%)
file186.169.63.68
AsyncRAT botnet C2 server (confidence level: 100%)
file94.26.90.245
AsyncRAT botnet C2 server (confidence level: 100%)
file176.65.142.198
AsyncRAT botnet C2 server (confidence level: 100%)
file196.251.71.236
AsyncRAT botnet C2 server (confidence level: 100%)
file89.40.31.57
Remcos botnet C2 server (confidence level: 100%)
file45.11.229.12
MooBot botnet C2 server (confidence level: 100%)
file159.69.199.17
Unknown malware botnet C2 server (confidence level: 100%)
file3.141.231.53
Unknown malware botnet C2 server (confidence level: 100%)
file15.164.18.179
Unknown malware botnet C2 server (confidence level: 100%)
file203.193.174.94
Unknown malware botnet C2 server (confidence level: 100%)
file46.38.254.23
Unknown malware botnet C2 server (confidence level: 100%)
file4.237.239.110
Unknown malware botnet C2 server (confidence level: 100%)
file34.249.182.250
Unknown malware botnet C2 server (confidence level: 100%)
file52.210.91.186
Unknown malware botnet C2 server (confidence level: 100%)
file146.190.118.96
Unknown malware botnet C2 server (confidence level: 100%)
file38.55.198.29
Unknown malware botnet C2 server (confidence level: 100%)
file124.71.7.106
Unknown malware botnet C2 server (confidence level: 100%)
file192.241.135.51
Unknown malware botnet C2 server (confidence level: 100%)
file43.135.76.103
Unknown malware botnet C2 server (confidence level: 100%)
file1.92.158.252
Unknown malware botnet C2 server (confidence level: 100%)
file117.88.102.214
Unknown malware botnet C2 server (confidence level: 100%)
file37.27.242.2
Unknown malware botnet C2 server (confidence level: 100%)
file188.166.255.201
Unknown malware botnet C2 server (confidence level: 100%)
file103.175.217.17
Unknown malware botnet C2 server (confidence level: 100%)
file3.39.87.72
Unknown malware botnet C2 server (confidence level: 100%)
file13.124.234.4
Unknown malware botnet C2 server (confidence level: 100%)
file8.138.46.58
Cobalt Strike botnet C2 server (confidence level: 100%)
file20.205.16.222
Cobalt Strike botnet C2 server (confidence level: 100%)
file150.158.108.220
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.251.100.146
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.92.216.212
Cobalt Strike botnet C2 server (confidence level: 100%)
file101.37.80.173
Cobalt Strike botnet C2 server (confidence level: 100%)
file147.79.20.62
Cobalt Strike botnet C2 server (confidence level: 100%)
file176.65.141.210
Mirai botnet C2 server (confidence level: 75%)
file43.132.216.81
ValleyRAT botnet C2 server (confidence level: 100%)
file185.196.11.181
Cobalt Strike botnet C2 server (confidence level: 50%)
file24.199.73.199
Sliver botnet C2 server (confidence level: 50%)
file158.247.218.220
Sliver botnet C2 server (confidence level: 50%)
file15.168.9.236
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file176.82.189.27
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file37.72.168.146
Havoc botnet C2 server (confidence level: 50%)
file169.150.155.228
Havoc botnet C2 server (confidence level: 50%)
file51.21.245.196
Unknown malware botnet C2 server (confidence level: 50%)
file158.247.202.109
Kimsuky botnet C2 server (confidence level: 50%)
file158.247.207.197
Kimsuky botnet C2 server (confidence level: 50%)
file220.71.102.113
Nanocore RAT botnet C2 server (confidence level: 50%)
file15.222.3.45
BlackShades botnet C2 server (confidence level: 50%)
file117.209.241.134
Mozi botnet C2 server (confidence level: 50%)
file91.200.14.226
Cobalt Strike botnet C2 server (confidence level: 100%)
file121.36.228.26
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.219.119.63
Cobalt Strike botnet C2 server (confidence level: 100%)
file27.102.127.136
Remcos botnet C2 server (confidence level: 100%)
file89.40.31.225
Remcos botnet C2 server (confidence level: 100%)
file66.42.44.50
pupy botnet C2 server (confidence level: 100%)
file120.26.243.135
Sliver botnet C2 server (confidence level: 100%)
file167.172.94.208
Unknown malware botnet C2 server (confidence level: 100%)
file134.199.169.177
Unknown malware botnet C2 server (confidence level: 100%)
file47.129.144.57
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file46.101.236.176
Remcos botnet C2 server (confidence level: 50%)
file79.110.62.113
Remcos botnet C2 server (confidence level: 50%)
file95.135.153.175
DeimosC2 botnet C2 server (confidence level: 75%)
file110.41.60.33
Cobalt Strike botnet C2 server (confidence level: 75%)
file81.17.20.66
Meterpreter botnet C2 server (confidence level: 75%)
file202.95.12.160
Cobalt Strike botnet C2 server (confidence level: 100%)
file116.62.205.141
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.140.154.238
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.107.49.44
Cobalt Strike botnet C2 server (confidence level: 100%)
file139.224.30.125
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.139.240.201
Cobalt Strike botnet C2 server (confidence level: 100%)
file92.63.100.74
Sliver botnet C2 server (confidence level: 100%)
file45.61.165.249
Quasar RAT botnet C2 server (confidence level: 100%)
file75.119.159.249
Havoc botnet C2 server (confidence level: 100%)
file31.220.44.127
Havoc botnet C2 server (confidence level: 100%)
file15.152.54.240
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file23.26.201.169
Unknown malware botnet C2 server (confidence level: 100%)
file154.201.90.76
MooBot botnet C2 server (confidence level: 100%)
file111.230.233.129
Cobalt Strike botnet C2 server (confidence level: 75%)
file77.90.153.228
Coper botnet C2 server (confidence level: 75%)
file160.30.44.124
MooBot botnet C2 server (confidence level: 100%)
file160.30.44.174
MooBot botnet C2 server (confidence level: 100%)
file166.88.164.201
FAKEUPDATES botnet C2 server (confidence level: 100%)
file196.251.117.50
Ave Maria botnet C2 server (confidence level: 100%)
file137.220.135.67
ValleyRAT botnet C2 server (confidence level: 100%)
file149.88.71.241
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.204.35.210
Cobalt Strike botnet C2 server (confidence level: 100%)
file166.88.100.85
Cobalt Strike botnet C2 server (confidence level: 100%)
file185.49.126.223
Remcos botnet C2 server (confidence level: 100%)
file45.13.38.142
Remcos botnet C2 server (confidence level: 100%)
file89.111.173.134
Sliver botnet C2 server (confidence level: 100%)
file196.251.71.236
AsyncRAT botnet C2 server (confidence level: 100%)
file202.95.14.161
DCRat botnet C2 server (confidence level: 100%)
file18.133.246.144
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file113.44.132.115
Cobalt Strike botnet C2 server (confidence level: 75%)
file39.105.6.249
Cobalt Strike botnet C2 server (confidence level: 75%)
file77.232.38.204
Mirai botnet C2 server (confidence level: 100%)
file103.12.149.123
ValleyRAT botnet C2 server (confidence level: 100%)
file47.109.190.151
Cobalt Strike botnet C2 server (confidence level: 100%)
file212.69.86.8
Remcos botnet C2 server (confidence level: 100%)
file5.35.125.77
Sliver botnet C2 server (confidence level: 100%)
file116.62.30.120
Unknown malware botnet C2 server (confidence level: 100%)
file196.251.118.253
AsyncRAT botnet C2 server (confidence level: 100%)
file176.65.134.77
AsyncRAT botnet C2 server (confidence level: 100%)
file45.80.158.238
Hook botnet C2 server (confidence level: 100%)
file52.79.126.186
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file54.187.139.165
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file172.171.241.227
MimiKatz botnet C2 server (confidence level: 100%)
file199.247.6.61
SpyNote botnet C2 server (confidence level: 100%)
file101.226.27.147
DeimosC2 botnet C2 server (confidence level: 75%)
file103.159.50.30
Havoc botnet C2 server (confidence level: 75%)
file185.195.64.68
WarmCookie botnet C2 server (confidence level: 100%)
file116.26.10.55
DeimosC2 botnet C2 server (confidence level: 75%)
file158.160.26.151
DeimosC2 botnet C2 server (confidence level: 75%)
file189.140.41.58
QakBot botnet C2 server (confidence level: 75%)
file43.141.130.132
DeimosC2 botnet C2 server (confidence level: 75%)
file70.31.125.238
QakBot botnet C2 server (confidence level: 75%)
file167.86.109.240
Meterpreter botnet C2 server (confidence level: 75%)
file213.226.113.235
RedLine Stealer botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash505
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash7777
AsyncRAT botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash50555
Hook botnet C2 server (confidence level: 100%)
hash2053
Hook botnet C2 server (confidence level: 100%)
hash443
Quasar RAT botnet C2 server (confidence level: 100%)
hash8081
Havoc botnet C2 server (confidence level: 100%)
hash53018
Venom RAT botnet C2 server (confidence level: 100%)
hash10001
MimiKatz botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 90%)
hash123
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Lumma Stealer botnet C2 server (confidence level: 50%)
hash7046
Vjw0rm botnet C2 server (confidence level: 100%)
hash2703
AsyncRAT botnet C2 server (confidence level: 100%)
hash1089
Cobalt Strike botnet C2 server (confidence level: 75%)
hash43256
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Sliver botnet C2 server (confidence level: 90%)
hash9999
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash5555
AsyncRAT botnet C2 server (confidence level: 100%)
hash9373
Remcos botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash1234
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash10002
Unknown malware botnet C2 server (confidence level: 100%)
hash1234
Unknown malware botnet C2 server (confidence level: 100%)
hash9999
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash1724
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8086
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash15390
Mirai botnet C2 server (confidence level: 75%)
hash635
ValleyRAT botnet C2 server (confidence level: 100%)
hash9922
Cobalt Strike botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash2002
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash6001
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash10443
Havoc botnet C2 server (confidence level: 50%)
hash55553
Havoc botnet C2 server (confidence level: 50%)
hash12284
Unknown malware botnet C2 server (confidence level: 50%)
hash443
Kimsuky botnet C2 server (confidence level: 50%)
hash443
Kimsuky botnet C2 server (confidence level: 50%)
hash54984
Nanocore RAT botnet C2 server (confidence level: 50%)
hash12112
BlackShades botnet C2 server (confidence level: 50%)
hash49682
Mozi botnet C2 server (confidence level: 50%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash9373
Remcos botnet C2 server (confidence level: 100%)
hash53
pupy botnet C2 server (confidence level: 100%)
hash8080
Sliver botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash636
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash1853
Remcos botnet C2 server (confidence level: 50%)
hash4836
Remcos botnet C2 server (confidence level: 50%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash4431
Meterpreter botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash33949
Sliver botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash8000
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash20547
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Coper botnet C2 server (confidence level: 75%)
hash2023
MooBot botnet C2 server (confidence level: 100%)
hash2023
MooBot botnet C2 server (confidence level: 100%)
hash443
FAKEUPDATES botnet C2 server (confidence level: 100%)
hash5213
Ave Maria botnet C2 server (confidence level: 100%)
hash6064
ValleyRAT botnet C2 server (confidence level: 100%)
hasha539275d837cf5501e0d98abce56f16ca8f97c9d06662162278c0dffb783d7de
Unknown malware payload (confidence level: 50%)
hashbec378cef9cbb85f127691385517b659
AMOS payload (confidence level: 100%)
hashb92960006ed39ecd4a7a403b44064c01
AMOS payload (confidence level: 100%)
hashd99840757365a6c5045a870980e5fdf8
AMOS payload (confidence level: 100%)
hashc402f62212873f3a7e6fce5d490f6ddb
Unknown malware payload (confidence level: 100%)
hashb03211f6feccd3a62273368b52f6079d
Unknown malware payload (confidence level: 100%)
hash2fde001f4c17c8613480091fa48b55a0
Unknown malware payload (confidence level: 100%)
hasha3d8e4f55c50bc916f6410f31a811e2d
Unknown malware payload (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8001
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash2222
AsyncRAT botnet C2 server (confidence level: 100%)
hash8848
DCRat botnet C2 server (confidence level: 100%)
hash1244
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash37215
Mirai botnet C2 server (confidence level: 100%)
hash8080
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash5061
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash11872
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash113
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash8787
MimiKatz botnet C2 server (confidence level: 100%)
hash80
SpyNote botnet C2 server (confidence level: 100%)
hash4506
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
Havoc botnet C2 server (confidence level: 75%)
hash443
WarmCookie botnet C2 server (confidence level: 100%)
hash36166
DeimosC2 botnet C2 server (confidence level: 75%)
hash1720
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash10250
DeimosC2 botnet C2 server (confidence level: 75%)
hash2078
QakBot botnet C2 server (confidence level: 75%)
hash8888
Meterpreter botnet C2 server (confidence level: 75%)
hash1912
RedLine Stealer botnet C2 server (confidence level: 100%)

Threat ID: 682c7db2e8347ec82d2a0b30

Added to database: 5/20/2025, 1:03:46 PM

Last enriched: 6/19/2025, 2:48:55 PM

Last updated: 8/10/2025, 12:53:24 PM

Views: 13

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats