Skip to main content

ThreatFox IOCs for 2025-07-08

Medium
Published: Tue Jul 08 2025 (07/08/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-07-08

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
b371c0d7-76a4-4e01-b096-4d94563d5598
Original Timestamp
1752019387

Indicators of Compromise

Domain

ValueDescriptionCopy
domainqeel.xyz
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainlnofi.xyz
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainryxpq.xyz
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaindzyzb.xyz
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaindkkig.xyz
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainlodib.xyz
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaingenmkh.xyz
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainapi.regpad.net
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainapiprod.regpad.net
Cobalt Strike botnet C2 domain (confidence level: 75%)
domaincdn.bitttrrix.ru
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainpersonal.regpad.net
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainnet-2-45-246-28.cust.vodafonedsl.it
Unknown malware botnet C2 domain (confidence level: 100%)
domainpage4work.mywire.org
XWorm botnet C2 domain (confidence level: 100%)
domainmokveid.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainvaykhon.ddns.net
Quasar RAT botnet C2 domain (confidence level: 50%)
domainidrnmk.top
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainwhitfmz.top
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainanfdfq.pics
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainperkoj.shop
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainmetopypv.top
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainsecurity-malware.com
Lumma Stealer botnet C2 domain (confidence level: 50%)
domaincitadelcdn.pro
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainhotroutingcdn.asia
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainfiledisterbuter.icu
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainwebdevs.vip
Remcos botnet C2 domain (confidence level: 100%)
domainhunterbry.no-ip.biz
CyberGate botnet C2 domain (confidence level: 100%)
domainwww.thelist2win.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainbruconriz72.futurox.store
Umbral payload delivery domain (confidence level: 100%)
domainjareyo.duckdns.org
STRRAT botnet C2 domain (confidence level: 100%)
domainhitmanzok.net
NetSupportManager RAT botnet C2 domain (confidence level: 100%)
domainrelay.colonjars.xyz
Unknown RAT botnet C2 domain (confidence level: 100%)
domainmail.operationesim.com
Unknown RAT botnet C2 domain (confidence level: 100%)
domainxiaoshihou13.top
Unknown RAT botnet C2 domain (confidence level: 100%)
domaindraw.treetrauma.com
Unknown RAT botnet C2 domain (confidence level: 100%)
domaingbotupdate19xx.com
StrelaStealer botnet C2 domain (confidence level: 100%)
domainiwine.top
FAKEUPDATES payload delivery domain (confidence level: 100%)
domain116b1bac-dcea-42f0-befb-e4383be4037a.k8s.ondigitalocean.com
Havoc botnet C2 domain (confidence level: 100%)
domaintechnovisionpromaxx.com
Unknown RAT botnet C2 domain (confidence level: 100%)
domainhciagriitec.ddns.net
XWorm botnet C2 domain (confidence level: 100%)
domaingoogle-com-site-backup.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domaincodingoffensive.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainwww.dddddddguashjdka.top
ValleyRAT botnet C2 domain (confidence level: 100%)
domainhosts32.no-ip.biz
CyberGate botnet C2 domain (confidence level: 100%)
domainwww.bonusnewmember.fyi
Havoc botnet C2 domain (confidence level: 100%)
domainedge3.bsqb.ru
Cobalt Strike botnet C2 domain (confidence level: 75%)
domaintest10.scacasdxc.love
Cobalt Strike botnet C2 domain (confidence level: 75%)

File

ValueDescriptionCopy
file115.190.147.158
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.154.98.13
Remcos botnet C2 server (confidence level: 100%)
file80.64.19.202
SectopRAT botnet C2 server (confidence level: 100%)
file178.128.204.138
Unknown malware botnet C2 server (confidence level: 100%)
file128.199.152.169
Havoc botnet C2 server (confidence level: 100%)
file159.223.21.58
Havoc botnet C2 server (confidence level: 100%)
file148.66.21.236
DCRat botnet C2 server (confidence level: 100%)
file121.41.113.184
AdaptixC2 botnet C2 server (confidence level: 100%)
file34.42.252.91
Empire Downloader botnet C2 server (confidence level: 100%)
file147.45.218.49
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file78.128.112.206
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file176.9.34.165
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file147.45.218.3
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file194.156.79.202
XWorm botnet C2 server (confidence level: 100%)
file118.112.10.110
Cobalt Strike botnet C2 server (confidence level: 75%)
file143.110.175.226
Cobalt Strike botnet C2 server (confidence level: 75%)
file171.43.169.243
Cobalt Strike botnet C2 server (confidence level: 75%)
file196.251.87.191
Cobalt Strike botnet C2 server (confidence level: 75%)
file61.160.192.88
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.122.80.99
Cobalt Strike botnet C2 server (confidence level: 100%)
file106.53.52.127
Cobalt Strike botnet C2 server (confidence level: 100%)
file113.44.252.170
Cobalt Strike botnet C2 server (confidence level: 100%)
file49.65.96.18
Cobalt Strike botnet C2 server (confidence level: 100%)
file165.154.225.50
Cobalt Strike botnet C2 server (confidence level: 100%)
file172.98.23.21
Ghost RAT botnet C2 server (confidence level: 75%)
file172.98.23.73
Ghost RAT botnet C2 server (confidence level: 75%)
file91.232.103.206
DarkComet botnet C2 server (confidence level: 100%)
file194.59.31.128
AsyncRAT botnet C2 server (confidence level: 100%)
file172.86.105.40
Hook botnet C2 server (confidence level: 100%)
file23.227.199.118
Havoc botnet C2 server (confidence level: 100%)
file148.66.21.237
DCRat botnet C2 server (confidence level: 100%)
file86.54.42.116
DCRat botnet C2 server (confidence level: 100%)
file103.201.130.85
Unknown malware botnet C2 server (confidence level: 100%)
file98.70.57.40
Unknown malware botnet C2 server (confidence level: 100%)
file34.229.94.154
Unknown malware botnet C2 server (confidence level: 100%)
file38.56.209.142
Unknown malware botnet C2 server (confidence level: 100%)
file83.229.122.24
Unknown malware botnet C2 server (confidence level: 100%)
file20.96.168.68
Unknown malware botnet C2 server (confidence level: 100%)
file94.102.8.83
Unknown malware botnet C2 server (confidence level: 100%)
file78.12.5.9
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file3.127.89.233
Unknown malware botnet C2 server (confidence level: 100%)
file50.16.93.216
Unknown malware botnet C2 server (confidence level: 100%)
file176.46.157.64
RedLine Stealer botnet C2 server (confidence level: 100%)
file8.139.5.62
Chaos botnet C2 server (confidence level: 100%)
file118.107.244.105
Xtreme RAT botnet C2 server (confidence level: 100%)
file5.101.81.63
Remcos botnet C2 server (confidence level: 100%)
file101.182.12.32
AsyncRAT botnet C2 server (confidence level: 100%)
file5.181.171.222
Nanocore RAT botnet C2 server (confidence level: 100%)
file1.15.25.148
Cobalt Strike botnet C2 server (confidence level: 50%)
file13.60.104.211
Sliver botnet C2 server (confidence level: 50%)
file107.150.20.224
Sliver botnet C2 server (confidence level: 50%)
file64.227.142.218
Sliver botnet C2 server (confidence level: 50%)
file77.51.219.187
Unknown malware botnet C2 server (confidence level: 50%)
file18.219.22.52
Unknown malware botnet C2 server (confidence level: 50%)
file205.185.114.104
Unknown malware botnet C2 server (confidence level: 50%)
file192.121.16.196
Nanocore RAT botnet C2 server (confidence level: 50%)
file91.228.113.199
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file61.3.107.155
Mozi botnet C2 server (confidence level: 50%)
file27.102.138.169
Kimsuky botnet C2 server (confidence level: 50%)
file192.140.166.27
Cobalt Strike botnet C2 server (confidence level: 100%)
file123.56.252.42
Cobalt Strike botnet C2 server (confidence level: 100%)
file213.209.150.216
Cobalt Strike botnet C2 server (confidence level: 100%)
file213.209.150.216
Cobalt Strike botnet C2 server (confidence level: 100%)
file91.99.174.2
Vidar botnet C2 server (confidence level: 100%)
file91.99.201.76
Vidar botnet C2 server (confidence level: 100%)
file8.137.80.215
Cobalt Strike botnet C2 server (confidence level: 100%)
file18.162.56.61
Cobalt Strike botnet C2 server (confidence level: 100%)
file176.46.157.34
Remcos botnet C2 server (confidence level: 100%)
file1.197.72.42
Sliver botnet C2 server (confidence level: 100%)
file206.123.145.154
Hook botnet C2 server (confidence level: 100%)
file13.38.84.98
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file95.179.130.254
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file172.105.24.242
Eye Pyramid botnet C2 server (confidence level: 75%)
file18.254.197.10
DeimosC2 botnet C2 server (confidence level: 75%)
file67.71.30.106
QakBot botnet C2 server (confidence level: 75%)
file68.106.44.135
QakBot botnet C2 server (confidence level: 75%)
file147.45.198.44
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file66.179.10.197
STRRAT botnet C2 server (confidence level: 100%)
file91.204.224.232
ValleyRAT botnet C2 server (confidence level: 100%)
file185.149.233.28
Remcos botnet C2 server (confidence level: 100%)
file61.245.10.155
Meterpreter botnet C2 server (confidence level: 75%)
file45.125.66.123
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file115.29.162.71
Cobalt Strike botnet C2 server (confidence level: 100%)
file115.29.162.71
Cobalt Strike botnet C2 server (confidence level: 100%)
file196.251.69.245
Remcos botnet C2 server (confidence level: 100%)
file142.147.97.173
Remcos botnet C2 server (confidence level: 100%)
file198.135.51.107
Remcos botnet C2 server (confidence level: 100%)
file107.172.44.146
Remcos botnet C2 server (confidence level: 100%)
file38.60.208.184
ShadowPad botnet C2 server (confidence level: 90%)
file134.122.183.217
AsyncRAT botnet C2 server (confidence level: 100%)
file16.171.147.206
AsyncRAT botnet C2 server (confidence level: 100%)
file134.199.166.195
Unknown malware botnet C2 server (confidence level: 100%)
file71.175.176.100
Quasar RAT botnet C2 server (confidence level: 100%)
file27.254.164.212
Havoc botnet C2 server (confidence level: 100%)
file18.191.218.224
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file179.95.204.243
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file124.156.166.6
Nimplant botnet C2 server (confidence level: 100%)
file85.209.195.214
Xtreme RAT botnet C2 server (confidence level: 100%)
file62.210.113.45
Xtreme RAT botnet C2 server (confidence level: 100%)
file54.219.186.229
BianLian botnet C2 server (confidence level: 100%)
file154.37.214.53
ValleyRAT botnet C2 server (confidence level: 100%)
file154.37.214.53
ValleyRAT botnet C2 server (confidence level: 100%)
file154.37.214.53
ValleyRAT botnet C2 server (confidence level: 100%)
file134.122.189.56
ValleyRAT botnet C2 server (confidence level: 100%)
file134.122.189.56
ValleyRAT botnet C2 server (confidence level: 100%)
file134.122.189.56
ValleyRAT botnet C2 server (confidence level: 100%)
file146.70.226.130
Nanocore RAT botnet C2 server (confidence level: 100%)
file202.79.173.94
ValleyRAT botnet C2 server (confidence level: 100%)
file160.153.178.204
Umbral payload delivery server (confidence level: 100%)
file160.153.178.204
Umbral payload delivery server (confidence level: 100%)
file45.133.174.35
Remcos botnet C2 server (confidence level: 100%)
file156.229.125.160
Mirai botnet C2 server (confidence level: 100%)
file95.216.69.187
NetSupportManager RAT botnet C2 server (confidence level: 75%)
file147.124.215.2
Remcos botnet C2 server (confidence level: 75%)
file107.150.0.234
Unknown RAT botnet C2 server (confidence level: 75%)
file154.82.85.102
Unknown RAT botnet C2 server (confidence level: 75%)
file107.150.0.218
Unknown RAT botnet C2 server (confidence level: 75%)
file107.172.232.83
Remcos botnet C2 server (confidence level: 75%)
file185.185.71.66
StrelaStealer botnet C2 server (confidence level: 75%)
file101.43.62.241
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.149.137.211
AsyncRAT botnet C2 server (confidence level: 100%)
file156.238.243.16
Hook botnet C2 server (confidence level: 100%)
file156.238.243.16
Hook botnet C2 server (confidence level: 100%)
file51.195.123.116
Unknown RAT botnet C2 server (confidence level: 75%)
file87.120.113.179
XWorm botnet C2 server (confidence level: 100%)
file104.131.57.194
Remcos botnet C2 server (confidence level: 100%)
file51.38.29.129
Remcos botnet C2 server (confidence level: 100%)
file194.26.192.233
Quasar RAT botnet C2 server (confidence level: 100%)
file45.207.39.135
ValleyRAT botnet C2 server (confidence level: 100%)
file45.207.39.135
ValleyRAT botnet C2 server (confidence level: 100%)
file47.76.115.9
ValleyRAT botnet C2 server (confidence level: 100%)
file217.60.39.163
Mirai botnet C2 server (confidence level: 100%)
file217.60.248.199
Mirai botnet C2 server (confidence level: 100%)
file194.113.37.21
Mirai botnet C2 server (confidence level: 100%)
file217.60.249.53
Mirai botnet C2 server (confidence level: 100%)
file31.59.120.38
Mirai botnet C2 server (confidence level: 100%)
file212.192.221.236
Mirai botnet C2 server (confidence level: 100%)
file217.60.248.115
Mirai botnet C2 server (confidence level: 100%)
file45.88.9.32
XWorm botnet C2 server (confidence level: 100%)
file62.60.226.204
PureLogs Stealer botnet C2 server (confidence level: 100%)
file124.70.86.82
Cobalt Strike botnet C2 server (confidence level: 100%)
file27.17.188.137
Cobalt Strike botnet C2 server (confidence level: 100%)
file115.126.83.252
Cobalt Strike botnet C2 server (confidence level: 100%)
file39.100.86.107
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.226.79.54
Ghost RAT botnet C2 server (confidence level: 100%)
file212.23.222.49
Remcos botnet C2 server (confidence level: 100%)
file47.245.126.17
Sliver botnet C2 server (confidence level: 100%)
file156.246.2.188
Unknown malware botnet C2 server (confidence level: 100%)
file156.246.2.169
Unknown malware botnet C2 server (confidence level: 100%)
file156.246.2.166
Unknown malware botnet C2 server (confidence level: 100%)
file156.246.2.185
Unknown malware botnet C2 server (confidence level: 100%)
file156.246.3.165
Unknown malware botnet C2 server (confidence level: 100%)
file45.146.253.150
Hook botnet C2 server (confidence level: 100%)
file82.66.75.169
Havoc botnet C2 server (confidence level: 100%)
file52.63.73.110
Havoc botnet C2 server (confidence level: 100%)
file35.180.37.142
Havoc botnet C2 server (confidence level: 100%)
file181.235.10.10
DCRat botnet C2 server (confidence level: 100%)
file192.140.188.34
Kaiji botnet C2 server (confidence level: 100%)
file2.56.127.153
Stealc botnet C2 server (confidence level: 100%)
file104.193.69.173
Unknown malware botnet C2 server (confidence level: 100%)
file39.98.204.142
MimiKatz botnet C2 server (confidence level: 100%)
file83.255.8.92
Empire Downloader botnet C2 server (confidence level: 100%)
file89.168.126.249
Xtreme RAT botnet C2 server (confidence level: 100%)
file213.209.150.11
Rhadamanthys botnet C2 server (confidence level: 100%)
file87.120.126.122
Rhadamanthys botnet C2 server (confidence level: 100%)
file109.120.137.42
WarmCookie botnet C2 server (confidence level: 100%)
file159.0.45.255
QakBot botnet C2 server (confidence level: 75%)
file45.77.231.137
Havoc botnet C2 server (confidence level: 75%)
file88.129.151.109
DeimosC2 botnet C2 server (confidence level: 75%)
file94.49.43.20
QakBot botnet C2 server (confidence level: 75%)
file51.89.166.173
NjRAT botnet C2 server (confidence level: 100%)
file116.203.96.2
Cobalt Strike botnet C2 server (confidence level: 75%)
file85.209.128.97
XWorm botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash8001
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash80
DCRat botnet C2 server (confidence level: 100%)
hash8443
AdaptixC2 botnet C2 server (confidence level: 100%)
hash80
Empire Downloader botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash9999
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash5647
XWorm botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4433
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9999
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Ghost RAT botnet C2 server (confidence level: 75%)
hash80
Ghost RAT botnet C2 server (confidence level: 75%)
hash5000
DarkComet botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash12443
Havoc botnet C2 server (confidence level: 100%)
hash80
DCRat botnet C2 server (confidence level: 100%)
hash8855
DCRat botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash5700
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3390
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash1911
RedLine Stealer botnet C2 server (confidence level: 100%)
hash54681
Chaos botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash1515
Remcos botnet C2 server (confidence level: 100%)
hash1703
AsyncRAT botnet C2 server (confidence level: 100%)
hash53
Nanocore RAT botnet C2 server (confidence level: 100%)
hash9080
Cobalt Strike botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash3333
Unknown malware botnet C2 server (confidence level: 50%)
hash8589
Unknown malware botnet C2 server (confidence level: 50%)
hash18107
Unknown malware botnet C2 server (confidence level: 50%)
hash54984
Nanocore RAT botnet C2 server (confidence level: 50%)
hash9035
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash45555
Mozi botnet C2 server (confidence level: 50%)
hash80
Kimsuky botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash5555
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash40000
Sliver botnet C2 server (confidence level: 100%)
hash8082
Hook botnet C2 server (confidence level: 100%)
hash50994
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash8080
Eye Pyramid botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash2222
QakBot botnet C2 server (confidence level: 75%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash5555
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash5610
STRRAT botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash2405
Remcos botnet C2 server (confidence level: 100%)
hash443
Meterpreter botnet C2 server (confidence level: 75%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8088
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash6751
Remcos botnet C2 server (confidence level: 100%)
hash45456
Remcos botnet C2 server (confidence level: 100%)
hash443
ShadowPad botnet C2 server (confidence level: 90%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash4582
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash9990
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash80
Nimplant botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash443
BianLian botnet C2 server (confidence level: 100%)
hash4080
ValleyRAT botnet C2 server (confidence level: 100%)
hash4090
ValleyRAT botnet C2 server (confidence level: 100%)
hash1123
ValleyRAT botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash8888
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
ValleyRAT botnet C2 server (confidence level: 100%)
hash42475
Nanocore RAT botnet C2 server (confidence level: 100%)
hash9090
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
Umbral payload delivery server (confidence level: 100%)
hash443
Umbral payload delivery server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash3778
Mirai botnet C2 server (confidence level: 100%)
hash5555
NetSupportManager RAT botnet C2 server (confidence level: 75%)
hash5577
Remcos botnet C2 server (confidence level: 75%)
hash8041
Unknown RAT botnet C2 server (confidence level: 75%)
hash8083
Unknown RAT botnet C2 server (confidence level: 75%)
hash8041
Unknown RAT botnet C2 server (confidence level: 75%)
hash13047
Remcos botnet C2 server (confidence level: 75%)
hash80
StrelaStealer botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash8041
Unknown RAT botnet C2 server (confidence level: 75%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash5577
Remcos botnet C2 server (confidence level: 100%)
hash7000
Remcos botnet C2 server (confidence level: 100%)
hash4781
Quasar RAT botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash8888
ValleyRAT botnet C2 server (confidence level: 100%)
hash443
ValleyRAT botnet C2 server (confidence level: 100%)
hash38242
Mirai botnet C2 server (confidence level: 100%)
hash38242
Mirai botnet C2 server (confidence level: 100%)
hash38242
Mirai botnet C2 server (confidence level: 100%)
hash38242
Mirai botnet C2 server (confidence level: 100%)
hash38242
Mirai botnet C2 server (confidence level: 100%)
hash38242
Mirai botnet C2 server (confidence level: 100%)
hash38242
Mirai botnet C2 server (confidence level: 100%)
hash7874
XWorm botnet C2 server (confidence level: 100%)
hash7705
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash56245
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8000
Ghost RAT botnet C2 server (confidence level: 100%)
hash4040
Remcos botnet C2 server (confidence level: 100%)
hash8443
Sliver botnet C2 server (confidence level: 100%)
hash9397
Unknown malware botnet C2 server (confidence level: 100%)
hash9397
Unknown malware botnet C2 server (confidence level: 100%)
hash9397
Unknown malware botnet C2 server (confidence level: 100%)
hash9397
Unknown malware botnet C2 server (confidence level: 100%)
hash9397
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash8010
DCRat botnet C2 server (confidence level: 100%)
hash808
Kaiji botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
MimiKatz botnet C2 server (confidence level: 100%)
hash443
Empire Downloader botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash19086
Rhadamanthys botnet C2 server (confidence level: 100%)
hash5900
Rhadamanthys botnet C2 server (confidence level: 100%)
hash443
WarmCookie botnet C2 server (confidence level: 100%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash443
Havoc botnet C2 server (confidence level: 75%)
hash8080
DeimosC2 botnet C2 server (confidence level: 75%)
hash995
QakBot botnet C2 server (confidence level: 75%)
hash6522
NjRAT botnet C2 server (confidence level: 100%)
hash53
Cobalt Strike botnet C2 server (confidence level: 75%)
hash5001
XWorm botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttp://a1143266.xsph.ru/64e9d1b1.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://leehpfe.shop/uhbv
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttp://cz27224.tw1.ru/80e9378c.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://aliondrifdions.com/work/
Latrodectus botnet C2 (confidence level: 75%)
urlhttps://gorahripliys.com/work/
Latrodectus botnet C2 (confidence level: 75%)
urlhttps://posbym.top/xldf
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://matfqht.lat/auwq
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://dkkig.xyz/xjau
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://dzyzb.xyz/anby
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://genmkh.xyz/towq
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://lnofi.xyz/qoei
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://lodib.xyz/towq
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://ryxpq.xyz/tpaz
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://t.me/fhsdf6
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://www.thelist2win.com/viewdashboard
FAKEUPDATES botnet C2 (confidence level: 100%)
urlhttps://reckdp.pics/xiar
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://t.me/baibai9054
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://iwine.top/kll/index.php
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttps://iwine.top/kll/buf.js
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttp://cc81860.tw1.ru/b2e12f58.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://ngbmrq.pics/xozh
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://sciezka.sbs/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://bedazq.pics/toow
Lumma Stealer botnet C2 (confidence level: 100%)

Threat ID: 686db32e6f40f0eb72fcbb4f

Added to database: 7/9/2025, 12:09:18 AM

Last updated: 7/9/2025, 12:09:18 AM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats