Skip to main content

ThreatFox IOCs for 2025-08-02

Medium
Published: Sat Aug 02 2025 (08/02/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-08-02

AI-Powered Analysis

AILast updated: 08/03/2025, 00:32:42 UTC

Technical Analysis

The provided information pertains to a set of Indicators of Compromise (IOCs) from the ThreatFox MISP Feed dated August 2, 2025. These IOCs are categorized under 'malware' with a focus on OSINT (Open Source Intelligence), network activity, and payload delivery. However, the data lacks specific technical details such as affected software versions, exploit mechanisms, or concrete indicators like hashes, IP addresses, or domains. The threat level is marked as medium with a threatLevel value of 2 on an unspecified scale, and no known exploits are reported in the wild. The absence of patch availability and exploit details suggests this is more of an intelligence feed update rather than an active or newly discovered vulnerability or malware strain. The classification under OSINT and network activity implies these IOCs are likely used for detection and monitoring purposes rather than describing a novel or ongoing attack vector. Overall, this entry appears to be a routine update of threat intelligence data rather than a direct security threat or vulnerability that requires immediate remediation.

Potential Impact

Given the lack of specific exploit details, affected products, or active exploitation reports, the immediate impact on European organizations is minimal. The IOCs serve primarily as detection tools to enhance situational awareness and threat hunting capabilities. Organizations leveraging these IOCs can improve their network monitoring and incident response but are not facing an imminent or direct threat from this data alone. The medium severity rating likely reflects the general importance of maintaining updated threat intelligence rather than indicating a critical or high-impact event. Therefore, the impact is primarily on the operational security posture and preparedness rather than on confidentiality, integrity, or availability of systems.

Mitigation Recommendations

Organizations should integrate these IOCs into their existing security monitoring platforms such as SIEMs, IDS/IPS, and endpoint detection tools to enhance detection capabilities. Regularly updating threat intelligence feeds and correlating them with internal logs can help identify potential malicious activity early. Since no patches or exploits are associated, focus should be on proactive monitoring and incident response readiness. Additionally, security teams should validate the relevance of these IOCs within their specific network context to reduce false positives. Collaboration with information sharing groups and continuous training on interpreting OSINT feeds will further improve the effectiveness of these indicators.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
76468c40-5b12-4355-8ed0-5892970f519a
Original Timestamp
1754179385

Indicators of Compromise

Domain

ValueDescriptionCopy
domainbmw320ikaka.co
Unknown RAT botnet C2 domain (confidence level: 75%)
domainsecurity.flenieregurd.com
Unknown malware payload delivery domain (confidence level: 100%)
domainwensibelo.com
Unknown malware payload delivery domain (confidence level: 100%)
domainlogandlog.ddns.net
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainflexreplicahafailoverserver638891307695968072.rs-313704a4e866.postgres.database.azure.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainflexreplicahafailoverserver638891307695968072.postgres.database.azure.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainpvpz-th.com
XWorm botnet C2 domain (confidence level: 100%)
domainstudy-leasing.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainschedule-pci.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainvestcast.co
Remcos botnet C2 domain (confidence level: 100%)
domainperfectsemplegas.de
Remcos botnet C2 domain (confidence level: 100%)
domainhapafix955-45412.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainrahiwex585-45935.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainz-m-static.xx.allianz-courtage.co
ERMAC botnet C2 domain (confidence level: 100%)
domainwww1.allianz-courtage.co
ERMAC botnet C2 domain (confidence level: 100%)
domaincnm.mom
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainjavascriptnest.com
FAKEUPDATES payload delivery domain (confidence level: 100%)
domainscriptedfunctions.com
FAKEUPDATES payload delivery domain (confidence level: 100%)
domainhiphop13.ddns.net
DarkComet botnet C2 domain (confidence level: 50%)
domainwww.03bub.vip
Formbook botnet C2 domain (confidence level: 50%)
domainwww.2learn.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.2zpi6.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.58p.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.8051.pro
Formbook botnet C2 domain (confidence level: 50%)
domainwww.8ight.beauty
Formbook botnet C2 domain (confidence level: 50%)
domainwww.8tangtang.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.acredmanuscript.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.adespark.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.aisy558.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ali77vip.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.angxiaopppp.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.apakgame.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.arasrm.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.arvanaemplyomentverfi.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ayfaic.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.cngs.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.decesi.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.e403e.click
Formbook botnet C2 domain (confidence level: 50%)
domainwww.eg1jy.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ensingtonllc.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.estingpodcast.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.et-supplies-64469.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.fok062.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.hickenroadfocusw.pro
Formbook botnet C2 domain (confidence level: 50%)
domainwww.hs.tokyo
Formbook botnet C2 domain (confidence level: 50%)
domainwww.hsykj.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.iaochengxuqjzh.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ipralex.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.kc.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.lackred.tech
Formbook botnet C2 domain (confidence level: 50%)
domainwww.lean-room-hl02.click
Formbook botnet C2 domain (confidence level: 50%)
domainwww.lgopaht.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.lolaha.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ltea.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.m-yra.lat
Formbook botnet C2 domain (confidence level: 50%)
domainwww.m62nx.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.masilevich.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.mlservices.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ncyxunems.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ngehladosanttos.info
Formbook botnet C2 domain (confidence level: 50%)
domainwww.nlinefreediplom.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ntoines.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.olarlights-40039.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.orjaengenharia.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ouchrajohri.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.owfihjdad.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.qjd2s.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.racktor.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.rain.watch
Formbook botnet C2 domain (confidence level: 50%)
domainwww.reshplate.sbs
Formbook botnet C2 domain (confidence level: 50%)
domainwww.rtservice.cfd
Formbook botnet C2 domain (confidence level: 50%)
domainwww.s2025.live
Formbook botnet C2 domain (confidence level: 50%)
domainwww.sint.productions
Formbook botnet C2 domain (confidence level: 50%)
domainwww.sy442.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.trwedb.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ubertimer.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ucoarts.llc
Formbook botnet C2 domain (confidence level: 50%)
domainwww.uno.dev
Formbook botnet C2 domain (confidence level: 50%)
domainwww.urkifsalife.cfd
Formbook botnet C2 domain (confidence level: 50%)
domainwww.urovisions.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.wxmax.sbs
Formbook botnet C2 domain (confidence level: 50%)
domainwww.yconadminagent231c.vip
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ymt1s.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.zyh8g.top
Formbook botnet C2 domain (confidence level: 50%)
domainbotnet.fakepay.online
Mirai botnet C2 domain (confidence level: 50%)
domainsbd.haongmaidong.com
Mirai botnet C2 domain (confidence level: 50%)
domainxdxd.hoangmaidong.com
Mirai botnet C2 domain (confidence level: 50%)
domaindiscussion-announcement.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domainsnxppyz.ddns.net
XWorm botnet C2 domain (confidence level: 50%)
domainupdatemicfosoft.com
Unknown malware botnet C2 domain (confidence level: 50%)
domainmicrosfot.org
Unknown malware botnet C2 domain (confidence level: 50%)
domainbittsgly.my
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainprogramme-newspaper.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainnowwework.3utilities.com
Remcos botnet C2 domain (confidence level: 100%)
domainomega2.no-ip.biz
CyberGate botnet C2 domain (confidence level: 100%)
domainpub.softlinko.com
Vidar botnet C2 domain (confidence level: 75%)
domainmx2.bsqd.ru
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainshim2.vurtobix.com
Rhadamanthys botnet C2 domain (confidence level: 100%)
domainshim2.zyraq.com
Rhadamanthys botnet C2 domain (confidence level: 100%)
domainshim3.sylviaklop.com
Rhadamanthys botnet C2 domain (confidence level: 100%)
domainshim4.familygater.com
Rhadamanthys botnet C2 domain (confidence level: 100%)
domainco-homeless.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainkallichox22.duckdns.org
AsyncRAT botnet C2 domain (confidence level: 100%)
domainkecfcnyn-29266.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domain1.tcp.eu.cpolar.io
Quasar RAT botnet C2 domain (confidence level: 100%)
domainopbrghost-23030.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domaintrackopbr2.ddns.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainswgood.kro.kr
NjRAT botnet C2 domain (confidence level: 100%)
domainliangpao8541.top
ValleyRAT botnet C2 domain (confidence level: 100%)
domainaraboz.no-ip.biz
CyberGate botnet C2 domain (confidence level: 100%)
domainxxx.softlinko.com
Vidar botnet C2 domain (confidence level: 75%)
domainlog.logogogogo.click
Cobalt Strike botnet C2 domain (confidence level: 75%)

File

ValueDescriptionCopy
file47.99.94.41
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.238.233.49
Cobalt Strike botnet C2 server (confidence level: 100%)
file137.131.24.201
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.204.211.62
Ghost RAT botnet C2 server (confidence level: 100%)
file182.16.33.132
Ghost RAT botnet C2 server (confidence level: 100%)
file45.204.222.45
Ghost RAT botnet C2 server (confidence level: 100%)
file103.127.126.231
Ghost RAT botnet C2 server (confidence level: 100%)
file43.251.116.171
Ghost RAT botnet C2 server (confidence level: 100%)
file89.238.176.4
Remcos botnet C2 server (confidence level: 100%)
file64.227.26.223
Sliver botnet C2 server (confidence level: 100%)
file185.177.239.56
Sliver botnet C2 server (confidence level: 100%)
file196.251.71.245
AsyncRAT botnet C2 server (confidence level: 100%)
file164.68.120.30
AsyncRAT botnet C2 server (confidence level: 100%)
file162.244.210.176
Quasar RAT botnet C2 server (confidence level: 100%)
file187.212.217.91
Quasar RAT botnet C2 server (confidence level: 100%)
file187.212.217.91
Quasar RAT botnet C2 server (confidence level: 100%)
file187.212.217.91
Quasar RAT botnet C2 server (confidence level: 100%)
file187.212.217.91
Quasar RAT botnet C2 server (confidence level: 100%)
file187.212.217.91
Quasar RAT botnet C2 server (confidence level: 100%)
file187.212.217.91
Quasar RAT botnet C2 server (confidence level: 100%)
file187.212.217.91
Quasar RAT botnet C2 server (confidence level: 100%)
file187.212.217.91
Quasar RAT botnet C2 server (confidence level: 100%)
file187.212.217.91
Quasar RAT botnet C2 server (confidence level: 100%)
file187.212.217.91
Quasar RAT botnet C2 server (confidence level: 100%)
file187.212.217.91
Quasar RAT botnet C2 server (confidence level: 100%)
file62.169.16.199
Venom RAT botnet C2 server (confidence level: 100%)
file167.172.185.9
Unknown malware botnet C2 server (confidence level: 100%)
file35.171.186.126
Unknown malware botnet C2 server (confidence level: 100%)
file167.99.57.129
Empire Downloader botnet C2 server (confidence level: 100%)
file8.218.198.125
ValleyRAT botnet C2 server (confidence level: 100%)
file121.43.131.115
Cobalt Strike botnet C2 server (confidence level: 75%)
file39.103.62.252
Cobalt Strike botnet C2 server (confidence level: 75%)
file193.161.193.99
Quasar RAT botnet C2 server (confidence level: 100%)
file212.162.149.164
XWorm botnet C2 server (confidence level: 100%)
file120.46.72.74
Cobalt Strike botnet C2 server (confidence level: 100%)
file182.16.33.130
Ghost RAT botnet C2 server (confidence level: 75%)
file49.113.77.155
Unknown malware botnet C2 server (confidence level: 100%)
file166.88.132.69
Remcos botnet C2 server (confidence level: 100%)
file38.55.190.11
Remcos botnet C2 server (confidence level: 100%)
file196.251.81.31
Remcos botnet C2 server (confidence level: 100%)
file192.159.99.164
Remcos botnet C2 server (confidence level: 100%)
file155.2.192.215
Remcos botnet C2 server (confidence level: 100%)
file196.251.116.39
ERMAC botnet C2 server (confidence level: 100%)
file107.189.16.163
Lumma Stealer botnet C2 server (confidence level: 100%)
file196.251.115.36
MooBot botnet C2 server (confidence level: 100%)
file104.233.152.169
Unknown malware botnet C2 server (confidence level: 100%)
file13.208.190.18
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file173.212.195.226
Unknown malware botnet C2 server (confidence level: 100%)
file18.232.62.159
Unknown malware botnet C2 server (confidence level: 100%)
file203.163.253.60
Unknown malware botnet C2 server (confidence level: 100%)
file191.252.60.250
Unknown malware botnet C2 server (confidence level: 100%)
file175.27.254.96
Unknown malware botnet C2 server (confidence level: 100%)
file66.42.84.227
Unknown malware botnet C2 server (confidence level: 100%)
file194.5.78.135
Unknown malware botnet C2 server (confidence level: 100%)
file193.19.207.241
XWorm botnet C2 server (confidence level: 100%)
file176.100.36.138
XWorm botnet C2 server (confidence level: 100%)
file8.218.198.125
ValleyRAT botnet C2 server (confidence level: 100%)
file8.218.198.125
ValleyRAT botnet C2 server (confidence level: 100%)
file47.116.64.160
Cobalt Strike botnet C2 server (confidence level: 100%)
file81.70.85.113
Cobalt Strike botnet C2 server (confidence level: 100%)
file172.234.99.241
RedLine Stealer botnet C2 server (confidence level: 100%)
file92.113.21.114
Bashlite botnet C2 server (confidence level: 75%)
file120.46.72.74
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.144.245.250
Cobalt Strike botnet C2 server (confidence level: 100%)
file172.245.208.14
Remcos botnet C2 server (confidence level: 100%)
file89.187.25.171
Remcos botnet C2 server (confidence level: 100%)
file45.88.186.30
Remcos botnet C2 server (confidence level: 100%)
file13.39.23.222
Havoc botnet C2 server (confidence level: 100%)
file167.160.161.194
Venom RAT botnet C2 server (confidence level: 100%)
file45.63.20.155
Chaos botnet C2 server (confidence level: 100%)
file110.43.39.114
Xtreme RAT botnet C2 server (confidence level: 100%)
file151.115.89.35
Xtreme RAT botnet C2 server (confidence level: 100%)
file124.221.221.58
Unknown malware botnet C2 server (confidence level: 75%)
file15.207.240.147
DeimosC2 botnet C2 server (confidence level: 75%)
file186.105.118.38
QakBot botnet C2 server (confidence level: 75%)
file192.159.99.71
Sliver botnet C2 server (confidence level: 75%)
file43.141.131.169
DeimosC2 botnet C2 server (confidence level: 75%)
file99.83.209.160
DeimosC2 botnet C2 server (confidence level: 75%)
file3.127.253.86
NjRAT botnet C2 server (confidence level: 75%)
file3.121.139.82
NjRAT botnet C2 server (confidence level: 75%)
file139.224.54.133
Cobalt Strike botnet C2 server (confidence level: 50%)
file172.105.54.144
Cobalt Strike botnet C2 server (confidence level: 50%)
file165.232.124.182
Sliver botnet C2 server (confidence level: 50%)
file134.122.79.159
Sliver botnet C2 server (confidence level: 50%)
file205.198.78.177
Sliver botnet C2 server (confidence level: 50%)
file194.76.217.146
Sliver botnet C2 server (confidence level: 50%)
file46.62.162.84
Sliver botnet C2 server (confidence level: 50%)
file38.54.14.46
Sliver botnet C2 server (confidence level: 50%)
file209.38.112.227
Sliver botnet C2 server (confidence level: 50%)
file47.129.3.18
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file213.241.33.151
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file18.130.226.34
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file18.61.83.207
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file146.70.213.35
Brute Ratel C4 botnet C2 server (confidence level: 50%)
file147.185.221.30
Quasar RAT botnet C2 server (confidence level: 75%)
file107.173.9.73
PureLogs Stealer botnet C2 server (confidence level: 100%)
file173.249.194.142
Remcos botnet C2 server (confidence level: 100%)
file35.165.234.191
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file45.192.209.81
Kaiji botnet C2 server (confidence level: 100%)
file69.5.189.19
AdaptixC2 botnet C2 server (confidence level: 100%)
file159.89.97.81
Cobalt Strike botnet C2 server (confidence level: 75%)
file5.10.250.239
SectopRAT botnet C2 server (confidence level: 100%)
file45.192.208.56
ValleyRAT botnet C2 server (confidence level: 100%)
file45.192.208.56
ValleyRAT botnet C2 server (confidence level: 100%)
file43.100.1.173
ValleyRAT botnet C2 server (confidence level: 100%)
file43.100.1.173
ValleyRAT botnet C2 server (confidence level: 100%)
file103.192.179.40
ValleyRAT botnet C2 server (confidence level: 100%)
file37.107.165.38
Xtreme RAT botnet C2 server (confidence level: 50%)
file37.107.165.38
Xtreme RAT botnet C2 server (confidence level: 50%)
file37.107.165.38
Xtreme RAT botnet C2 server (confidence level: 50%)
file37.107.165.38
Xtreme RAT botnet C2 server (confidence level: 50%)
file118.107.9.237
Unknown malware botnet C2 server (confidence level: 50%)
file185.219.84.239
Unknown malware botnet C2 server (confidence level: 50%)
file45.194.37.194
AdaptixC2 botnet C2 server (confidence level: 50%)
file80.253.251.138
ACR Stealer botnet C2 server (confidence level: 100%)
file185.214.74.169
ACR Stealer botnet C2 server (confidence level: 100%)
file185.76.243.5
ACR Stealer botnet C2 server (confidence level: 100%)
file185.76.243.64
ACR Stealer botnet C2 server (confidence level: 100%)
file80.253.251.139
ACR Stealer botnet C2 server (confidence level: 100%)
file45.95.232.57
ACR Stealer botnet C2 server (confidence level: 100%)
file89.23.107.212
ACR Stealer botnet C2 server (confidence level: 100%)
file176.46.158.23
GCleaner botnet C2 server (confidence level: 100%)
file43.251.116.128
Ghost RAT botnet C2 server (confidence level: 100%)
file160.202.242.210
Ghost RAT botnet C2 server (confidence level: 100%)
file144.172.101.98
Remcos botnet C2 server (confidence level: 100%)
file171.250.25.56
AsyncRAT botnet C2 server (confidence level: 100%)
file196.251.115.244
AsyncRAT botnet C2 server (confidence level: 100%)
file196.251.115.36
MooBot botnet C2 server (confidence level: 100%)
file13.210.0.111
Xtreme RAT botnet C2 server (confidence level: 100%)
file94.158.244.156
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file45.77.91.238
XWorm botnet C2 server (confidence level: 100%)
file83.136.210.100
XWorm botnet C2 server (confidence level: 100%)
file113.45.177.81
Cobalt Strike botnet C2 server (confidence level: 100%)
file118.178.187.223
Cobalt Strike botnet C2 server (confidence level: 100%)
file123.56.11.129
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.210.2.232
Ghost RAT botnet C2 server (confidence level: 100%)
file177.255.89.53
Remcos botnet C2 server (confidence level: 100%)
file107.172.132.44
Remcos botnet C2 server (confidence level: 100%)
file69.5.189.18
Remcos botnet C2 server (confidence level: 100%)
file94.237.98.123
Sliver botnet C2 server (confidence level: 100%)
file185.167.61.249
AsyncRAT botnet C2 server (confidence level: 100%)
file196.251.72.103
AsyncRAT botnet C2 server (confidence level: 100%)
file185.149.120.38
AsyncRAT botnet C2 server (confidence level: 100%)
file196.251.115.244
AsyncRAT botnet C2 server (confidence level: 100%)
file45.156.27.209
Unknown malware botnet C2 server (confidence level: 100%)
file54.207.216.190
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file45.131.108.217
MooBot botnet C2 server (confidence level: 100%)
file217.154.202.181
Empire Downloader botnet C2 server (confidence level: 100%)
file67.223.117.247
Empire Downloader botnet C2 server (confidence level: 100%)
file45.137.98.176
XWorm botnet C2 server (confidence level: 100%)
file13.248.198.19
DeimosC2 botnet C2 server (confidence level: 75%)
file194.34.97.38
DeimosC2 botnet C2 server (confidence level: 75%)
file196.251.83.162
Sliver botnet C2 server (confidence level: 75%)
file2.50.53.88
QakBot botnet C2 server (confidence level: 75%)
file34.249.83.124
DeimosC2 botnet C2 server (confidence level: 75%)
file47.113.147.96
Unknown malware botnet C2 server (confidence level: 75%)
file63.40.48.152
DeimosC2 botnet C2 server (confidence level: 75%)
file23.27.98.151
XWorm botnet C2 server (confidence level: 100%)
file47.242.129.79
Cobalt Strike botnet C2 server (confidence level: 75%)

Hash

ValueDescriptionCopy
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Ghost RAT botnet C2 server (confidence level: 100%)
hash2100
Ghost RAT botnet C2 server (confidence level: 100%)
hash80
Ghost RAT botnet C2 server (confidence level: 100%)
hash80
Ghost RAT botnet C2 server (confidence level: 100%)
hash80
Ghost RAT botnet C2 server (confidence level: 100%)
hash50542
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash9999
AsyncRAT botnet C2 server (confidence level: 100%)
hash5000
Quasar RAT botnet C2 server (confidence level: 100%)
hash995
Quasar RAT botnet C2 server (confidence level: 100%)
hash1962
Quasar RAT botnet C2 server (confidence level: 100%)
hash2271
Quasar RAT botnet C2 server (confidence level: 100%)
hash2592
Quasar RAT botnet C2 server (confidence level: 100%)
hash2080
Quasar RAT botnet C2 server (confidence level: 100%)
hash4443
Quasar RAT botnet C2 server (confidence level: 100%)
hash4567
Quasar RAT botnet C2 server (confidence level: 100%)
hash808
Quasar RAT botnet C2 server (confidence level: 100%)
hash1224
Quasar RAT botnet C2 server (confidence level: 100%)
hash4369
Quasar RAT botnet C2 server (confidence level: 100%)
hash788
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Venom RAT botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Empire Downloader botnet C2 server (confidence level: 100%)
hash12010
ValleyRAT botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash45935
Quasar RAT botnet C2 server (confidence level: 100%)
hash4018
XWorm botnet C2 server (confidence level: 100%)
hash666
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2100
Ghost RAT botnet C2 server (confidence level: 75%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash16547
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2003
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash80
ERMAC botnet C2 server (confidence level: 100%)
hash80
Lumma Stealer botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash1911
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash3334
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash9443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
XWorm botnet C2 server (confidence level: 100%)
hash8080
XWorm botnet C2 server (confidence level: 100%)
hash12020
ValleyRAT botnet C2 server (confidence level: 100%)
hash12030
ValleyRAT botnet C2 server (confidence level: 100%)
hash800
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
RedLine Stealer botnet C2 server (confidence level: 100%)
hash5060
Bashlite botnet C2 server (confidence level: 75%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash30233
Remcos botnet C2 server (confidence level: 100%)
hash7000
Remcos botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash2198
Venom RAT botnet C2 server (confidence level: 100%)
hash8080
Chaos botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash10250
DeimosC2 botnet C2 server (confidence level: 75%)
hash8129
DeimosC2 botnet C2 server (confidence level: 75%)
hash16995
NjRAT botnet C2 server (confidence level: 75%)
hash16995
NjRAT botnet C2 server (confidence level: 75%)
hash8333
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash902
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash5172
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash2628
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash7634
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash4433
Brute Ratel C4 botnet C2 server (confidence level: 50%)
hash45898
Quasar RAT botnet C2 server (confidence level: 75%)
hash8899
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash3717
Remcos botnet C2 server (confidence level: 100%)
hash15443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash8888
Kaiji botnet C2 server (confidence level: 100%)
hash443
AdaptixC2 botnet C2 server (confidence level: 100%)
hash53
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
SectopRAT botnet C2 server (confidence level: 100%)
hash25836
ValleyRAT botnet C2 server (confidence level: 100%)
hash14725
ValleyRAT botnet C2 server (confidence level: 100%)
hash9999
ValleyRAT botnet C2 server (confidence level: 100%)
hash8888
ValleyRAT botnet C2 server (confidence level: 100%)
hash9091
ValleyRAT botnet C2 server (confidence level: 100%)
hash2020
Xtreme RAT botnet C2 server (confidence level: 50%)
hash19
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9800
Xtreme RAT botnet C2 server (confidence level: 50%)
hash11920
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8443
Unknown malware botnet C2 server (confidence level: 50%)
hash4433
Unknown malware botnet C2 server (confidence level: 50%)
hash9595
AdaptixC2 botnet C2 server (confidence level: 50%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash80
GCleaner botnet C2 server (confidence level: 100%)
hash80
Ghost RAT botnet C2 server (confidence level: 100%)
hash1000
Ghost RAT botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash2004
MooBot botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash11452
XWorm botnet C2 server (confidence level: 100%)
hash963
XWorm botnet C2 server (confidence level: 100%)
hash8899
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8088
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9090
Cobalt Strike botnet C2 server (confidence level: 100%)
hash10086
Ghost RAT botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash8089
Sliver botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash2080
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash80
Empire Downloader botnet C2 server (confidence level: 100%)
hash80
Empire Downloader botnet C2 server (confidence level: 100%)
hash111
XWorm botnet C2 server (confidence level: 100%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash8443
DeimosC2 botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash60000
Unknown malware botnet C2 server (confidence level: 75%)
hash50040
DeimosC2 botnet C2 server (confidence level: 75%)
hash3248
XWorm botnet C2 server (confidence level: 100%)
hash2083
Cobalt Strike botnet C2 server (confidence level: 75%)

Url

ValueDescriptionCopy
urlhttps://egomdbj.asia/zkjr/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://server13.localstats.org/
Glupteba botnet C2 (confidence level: 50%)
urlhttps://server10.cdneurops.buzz/
Glupteba botnet C2 (confidence level: 50%)
urlhttps://server15.cdneurops.buzz/
Glupteba botnet C2 (confidence level: 50%)
urlhttps://45.154.13.94/
Unknown malware botnet C2 (confidence level: 50%)
urlhttp://www.03bub.vip/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.2learn.net/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.2zpi6.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.58p.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.8051.pro/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.8ight.beauty/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.8tangtang.xyz/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.acredmanuscript.shop/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.adespark.xyz/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.aisy558.shop/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ali77vip.net/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.angxiaopppp.xyz/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.apakgame.xyz/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.arasrm.shop/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.arvanaemplyomentverfi.net/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ayfaic.net/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.cngs.xyz/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.decesi.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.e403e.click/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.eg1jy.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ensingtonllc.net/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.estingpodcast.xyz/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.et-supplies-64469.bond/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.fok062.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.hickenroadfocusw.pro/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.hs.tokyo/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.hsykj.net/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.iaochengxuqjzh.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ipralex.xyz/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.kc.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.lackred.tech/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.lean-room-hl02.click/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.lgopaht.xyz/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.lolaha.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ltea.shop/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.m-yra.lat/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.m62nx.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.masilevich.net/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.mlservices.net/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ncyxunems.shop/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ngehladosanttos.info/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.nlinefreediplom.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ntoines.shop/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.olarlights-40039.bond/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.orjaengenharia.net/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ouchrajohri.shop/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.owfihjdad.shop/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.qjd2s.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.racktor.net/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.rain.watch/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.reshplate.sbs/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.rtservice.cfd/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.s2025.live/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.sint.productions/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.sy442.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.trwedb.xyz/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ubertimer.net/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ucoarts.llc/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.uno.dev/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.urkifsalife.cfd/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.urovisions.net/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.wxmax.sbs/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.yconadminagent231c.vip/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ymt1s.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.zyh8g.top/rk29/
Formbook botnet C2 (confidence level: 50%)
urlhttps://pub.softlinko.com
Vidar botnet C2 (confidence level: 75%)
urlhttp://35.194.117.29:8080/
Chaos botnet C2 (confidence level: 50%)
urlhttp://weathersouth.shop
Stealc botnet C2 (confidence level: 100%)
urlhttps://xxx.softlinko.com
Vidar botnet C2 (confidence level: 75%)
urlhttps://gavavknq.beer/ator/api
Lumma Stealer botnet C2 (confidence level: 75%)

Threat ID: 688eaa9dad5a09ad00d6ba1a

Added to database: 8/3/2025, 12:17:33 AM

Last enriched: 8/3/2025, 12:32:42 AM

Last updated: 8/5/2025, 1:17:13 AM

Views: 9

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats