Skip to main content

ThreatFox IOCs for 2025-09-02

Medium
Published: Tue Sep 02 2025 (09/02/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-09-02

AI-Powered Analysis

AILast updated: 09/03/2025, 00:33:00 UTC

Technical Analysis

The provided information pertains to a set of Indicators of Compromise (IOCs) published on 2025-09-02 by the ThreatFox MISP Feed, categorized under malware with a focus on OSINT (Open Source Intelligence), payload delivery, and network activity. The entry is tagged as 'tlp:white', indicating it is intended for wide distribution without restrictions. However, the data lacks specific technical details such as affected software versions, detailed attack vectors, or exploit mechanisms. No known exploits in the wild or patches are available, and no Common Weakness Enumerations (CWEs) are listed. The threat level is indicated as 2 on an unspecified scale, with moderate distribution (3) and minimal analysis (1), suggesting early-stage or low-confidence intelligence. The absence of concrete indicators or technical specifics limits the ability to fully characterize the malware or its operational tactics, techniques, and procedures (TTPs). Given the categorization, this threat likely involves malware that uses OSINT techniques for payload delivery and network-based activities, potentially aiming to infiltrate or exfiltrate data through network channels. The lack of patch availability and known exploits suggests this may be a newly identified or emerging threat rather than an actively exploited vulnerability. Overall, the information represents preliminary threat intelligence rather than a fully developed or widely exploited malware campaign.

Potential Impact

For European organizations, the impact of this threat is currently uncertain due to the lack of detailed technical information and confirmed exploitation. However, if the malware leverages OSINT for payload delivery and network activity, it could pose risks such as unauthorized data access, network infiltration, or lateral movement within corporate networks. Medium severity suggests a moderate risk level, potentially affecting confidentiality and integrity if successful. The absence of known exploits and patches implies that organizations may not yet be targeted or that detection and prevention measures are still effective. Nonetheless, organizations relying heavily on networked systems and sensitive data could face operational disruptions or data breaches if the threat evolves or is weaponized. The broad TLP:white classification means the information is widely shareable, facilitating community awareness but also potentially alerting adversaries. European entities should remain vigilant, especially those in sectors with high exposure to network-based attacks or those that utilize OSINT tools extensively.

Mitigation Recommendations

Given the limited specifics, mitigation should focus on enhancing network security monitoring and threat intelligence integration. Organizations should: 1) Implement and regularly update network intrusion detection and prevention systems (IDS/IPS) to identify anomalous payload delivery and network activity patterns. 2) Leverage threat intelligence feeds, including ThreatFox and MISP, to update detection signatures and IOC databases promptly. 3) Conduct regular OSINT hygiene reviews to minimize exposure of sensitive information that could be exploited for payload delivery. 4) Enforce strict network segmentation and least privilege access controls to limit lateral movement if compromise occurs. 5) Train security teams to recognize early signs of emerging malware campaigns and encourage information sharing within trusted communities. 6) Maintain up-to-date endpoint protection solutions capable of detecting unknown or emerging malware behaviors. 7) Prepare incident response plans that include procedures for handling OSINT-based payload delivery threats. These measures go beyond generic advice by focusing on proactive intelligence integration, network behavior analysis, and operational readiness tailored to OSINT-related malware threats.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
46849998-3a5f-4244-b6d6-2702cde18f52
Original Timestamp
1756857786

Indicators of Compromise

Domain

ValueDescriptionCopy
domainsbv.gevicii.ru
ClearFake payload delivery domain (confidence level: 100%)
domainung.sewumoa.ru
ClearFake payload delivery domain (confidence level: 100%)
domainteb.rilefoo8.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincso.burydyu0.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnuu.qacacoe3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainre.qacacoe3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvc.rogosie4.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlm.rogosie4.ru
ClearFake payload delivery domain (confidence level: 100%)
domainx-vape.ca
Unknown malware payload delivery domain (confidence level: 100%)
domainkl.xoreniu7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjsm.mosatiy4.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbrt.velyzeu3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbcm.messager.my
Unknown malware botnet C2 domain (confidence level: 100%)
domainbu.xoreniu7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhdn.qacacoe3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqo.subozaa7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainph.safofoe5.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintransapi.tld56.cn
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainblog.xinzyun.cn
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainsctms.tld56.cn
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainwxweb.tld56.cn
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainbold-chandrasekhar.134-199-166-195.plesk.page
Unknown malware botnet C2 domain (confidence level: 100%)
domaindv.kesogio6.ru
ClearFake payload delivery domain (confidence level: 100%)
domainid.madicoo3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrq.mufabui4.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindoc.e-statement.estate
Unknown RAT botnet C2 domain (confidence level: 100%)
domainbfvfuausfo.me
Unknown RAT botnet C2 domain (confidence level: 100%)
domainwmjlive.top
Unknown RAT botnet C2 domain (confidence level: 100%)
domainserpentinelexicon.pro
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainloadinnnhr.today
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaintelluricaphelion.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainwww.0632.club
Formbook botnet C2 domain (confidence level: 50%)
domainwww.0llhs.sbs
Formbook botnet C2 domain (confidence level: 50%)
domainwww.1tnsf.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.77-matraca777.win
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ablu.pro
Formbook botnet C2 domain (confidence level: 50%)
domainwww.alloffameopen1.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.anktl.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.apital-a.group
Formbook botnet C2 domain (confidence level: 50%)
domainwww.arewajan.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.astplay.click
Formbook botnet C2 domain (confidence level: 50%)
domainwww.atchbox.exchange
Formbook botnet C2 domain (confidence level: 50%)
domainwww.attoosbymatt.studio
Formbook botnet C2 domain (confidence level: 50%)
domainwww.c0824.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.c1302.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.c2751.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.c4589.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.dfsewq.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.earches.dev
Formbook botnet C2 domain (confidence level: 50%)
domainwww.eet-new-people-21453.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.eetmoonbuggy.click
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ellgreensportseducation.info
Formbook botnet C2 domain (confidence level: 50%)
domainwww.eople-search-65430.bond
Formbook botnet C2 domain (confidence level: 50%)
domainwww.etchelpgovtw.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.etnow.sbs
Formbook botnet C2 domain (confidence level: 50%)
domainwww.etworkmodel.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.excol.vip
Formbook botnet C2 domain (confidence level: 50%)
domainwww.g-899b9.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ghhfy.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.hysicians-to-women.cfd
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ian485.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.itaslotk.cfd
Formbook botnet C2 domain (confidence level: 50%)
domainwww.iveroad.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ivn.website
Formbook botnet C2 domain (confidence level: 50%)
domainwww.jc169.app
Formbook botnet C2 domain (confidence level: 50%)
domainwww.lhet.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.livinski.pro
Formbook botnet C2 domain (confidence level: 50%)
domainwww.lossbossclean.pro
Formbook botnet C2 domain (confidence level: 50%)
domainwww.lphageek.app
Formbook botnet C2 domain (confidence level: 50%)
domainwww.mvv34z.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ngimg.vip
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ockscrm.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ogw159.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.oisturizee.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.olikujyh990.sbs
Formbook botnet C2 domain (confidence level: 50%)
domainwww.omeradar.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.oofwaterproofing462.click
Formbook botnet C2 domain (confidence level: 50%)
domainwww.orytharothis.sbs
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ososo.tech
Formbook botnet C2 domain (confidence level: 50%)
domainwww.osteam.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.oticiasdamanha.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ove678i.app
Formbook botnet C2 domain (confidence level: 50%)
domainwww.oviesnn.pro
Formbook botnet C2 domain (confidence level: 50%)
domainwww.povamu.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.rownandcleatco.shop
Formbook botnet C2 domain (confidence level: 50%)
domainwww.s667788.xyz
Formbook botnet C2 domain (confidence level: 50%)
domainwww.sy644.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.sy897.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.tudygym.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.udness.art
Formbook botnet C2 domain (confidence level: 50%)
domainwww.utihslote.cfd
Formbook botnet C2 domain (confidence level: 50%)
domainwww.vahaca.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.wn6do.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ye6cvdg.top
Formbook botnet C2 domain (confidence level: 50%)
domainwww.ystems2beyond.tech
Formbook botnet C2 domain (confidence level: 50%)
domainwww.zborderfree.net
Formbook botnet C2 domain (confidence level: 50%)
domainwww.salesmarking.com
Remcos botnet C2 domain (confidence level: 50%)
domainadvpdxapi.com
X-Agent botnet C2 domain (confidence level: 50%)
domainsecuresystemwin.com
X-Agent botnet C2 domain (confidence level: 50%)
domainebay-governance.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domainoahs8y352.com
XWorm botnet C2 domain (confidence level: 100%)
domainif-compared.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainuser0001.duckdns.org
XWorm botnet C2 domain (confidence level: 100%)
domainbell.mokveid.com
Remcos botnet C2 domain (confidence level: 100%)
domain8scom.link
NjRAT botnet C2 domain (confidence level: 100%)
domaingyr.velyzeu3.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingm.velyzeu3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainry.zelojue1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainguq.mosatiy4.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqr.nelypuu5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainask.xonulee9.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpen.luxemyy2.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintu.luxemyy2.ru
ClearFake payload delivery domain (confidence level: 100%)
domainal.luxemyy2.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjp.walowue2.ru
ClearFake payload delivery domain (confidence level: 100%)
domainznz.xexykuo2.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwv.safofoe5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmu.nelypuu5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainposted-ethnic.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainremcodit.top
Remcos botnet C2 domain (confidence level: 100%)
domainwww.libertydroid-metabu.top
ERMAC botnet C2 domain (confidence level: 100%)
domainvcsinfo.com
KongTuke payload delivery domain (confidence level: 100%)
domaininfo-2go.com
NetSupportManager RAT payload delivery domain (confidence level: 100%)
domainwood-simple.com
NetSupportManager RAT payload delivery domain (confidence level: 100%)
domainyh.qacacoe3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainthe-xxxy.uk
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainalv.lotegeo7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainremixripiolo.con-ip.com
Remcos botnet C2 domain (confidence level: 50%)
domainuq.xexykuo2.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsamples.salondeguitaredemontreal.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainupdates.highendmark.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainwb.kesogio6.ru
ClearFake payload delivery domain (confidence level: 100%)
domainszh.saqehyo1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainauf.nelypuu5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainup.xonulee9.ru
ClearFake payload delivery domain (confidence level: 100%)
domainec2-63-178-148-142.eu-central-1.compute.amazonaws.com
Havoc botnet C2 domain (confidence level: 100%)
domainkws4.messager.my
Unknown malware botnet C2 domain (confidence level: 100%)
domaindfm.qacacoe3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainashigaruwallet.rs
Unknown malware payload delivery domain (confidence level: 100%)
domainkwk.burydyu0.ru
ClearFake payload delivery domain (confidence level: 100%)
domainload.granivit.hu
Vidar botnet C2 domain (confidence level: 100%)
domainzip.sewumoa.ru
ClearFake payload delivery domain (confidence level: 100%)
domainchange-america.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainbrand-courses.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainclick-constraints.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainfund-eyes.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainmanual-terminology.gl.at.ply.gg
Quasar RAT botnet C2 domain (confidence level: 100%)
domaincrisp.cucy.ru
ClearFake payload delivery domain (confidence level: 100%)
domainns1.microoosoft.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainns2.microoosoft.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainewg.jujosuu4.ru
ClearFake payload delivery domain (confidence level: 100%)
domainloe.jujosuu4.ru
ClearFake payload delivery domain (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttp://85.209.129.105:2020/test112
KongTuke payload delivery URL (confidence level: 100%)
urlhttp://188.245.167.86/second.html
KongTuke payload delivery URL (confidence level: 100%)
urlhttp://discord.com/is-ready
Houdini botnet C2 (confidence level: 100%)
urlhttp://coffeinoffice.xyz/cup/wish.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttp://www.kitchenaria.com/modules/gateway2/protx/response.php
Pony botnet C2 (confidence level: 100%)
urlhttp://134.122.207.42:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://ph.safofoe5.ru
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://avast.cucy.ru
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://cyber-v10getcyber.live/webpanel/
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttps://uhcprovider.com.content-provider.temp-perform.top/
XWorm botnet C2 (confidence level: 50%)
urlhttps://128.199.113.162/panel/index.php
Amadey botnet C2 (confidence level: 50%)
urlhttps://134.122.207.42:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 50%)
urlhttps://103.147.14.89:8888/
Unknown malware botnet C2 (confidence level: 50%)
urlhttps://47.116.64.160:8888/
Unknown malware botnet C2 (confidence level: 50%)
urlhttps://api.telegram.org/bot7968139020:aahz3sn_tjts4yohrr6feyywcqx7wzz3nbw/sendmessage?chat_id=7406080547
Prynt Stealer botnet C2 (confidence level: 50%)
urlhttp://www.0llhs.sbs/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.1tnsf.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.77-matraca777.win/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ablu.pro/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.alloffameopen1.net/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.anktl.net/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.apital-a.group/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.arewajan.xyz/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.astplay.click/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.atchbox.exchange/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.attoosbymatt.studio/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.c0824.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.c1302.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.c2751.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.c4589.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.dfsewq.xyz/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.earches.dev/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.eet-new-people-21453.bond/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.eetmoonbuggy.click/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ellgreensportseducation.info/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.eople-search-65430.bond/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.etchelpgovtw.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.etnow.sbs/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.etworkmodel.net/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.excol.vip/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.g-899b9.xyz/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ghhfy.xyz/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.hysicians-to-women.cfd/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ian485.xyz/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.itaslotk.cfd/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.iveroad.xyz/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ivn.website/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.jc169.app/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.lhet.net/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.livinski.pro/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.lossbossclean.pro/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.lphageek.app/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.mvv34z.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ngimg.vip/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ockscrm.xyz/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ogw159.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.oisturizee.shop/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.olikujyh990.sbs/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.omeradar.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.oofwaterproofing462.click/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.orytharothis.sbs/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ososo.tech/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.osteam.net/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.oticiasdamanha.shop/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ove678i.app/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.oviesnn.pro/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.povamu.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.rownandcleatco.shop/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.s667788.xyz/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.sy644.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.sy897.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.tudygym.net/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.udness.art/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.utihslote.cfd/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.vahaca.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.wn6do.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ye6cvdg.top/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.ystems2beyond.tech/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.zborderfree.net/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://www.0632.club/fa27/
Formbook botnet C2 (confidence level: 50%)
urlhttp://forums.lolapps.com/includes/cron/response.php
Pony botnet C2 (confidence level: 50%)
urlhttps://pastebin.com/raw/qpq6ifbn
XWorm botnet C2 (confidence level: 50%)
urlhttps://raw.githubusercontent.com/igor65afk/text/refs/heads/main/text.txt
XWorm botnet C2 (confidence level: 50%)
urlhttps://wesyjzn.top/zalr
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttp://a1164019.xsph.ru/61a9212d.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://185.102.115.69/48e.lim
Lumma Stealer payload delivery URL (confidence level: 100%)
urlhttps://5.75.210.161
Vidar botnet C2 (confidence level: 75%)
urlhttps://vcsinfo.com/4r6y.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://vcsinfo.com/js.php
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://info-2go.com/ajax/pixi.min.js
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://wood-simple.com/res/dampthere
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://wood-simple.com/drip.sym
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://wood-simple.com/assets/img/1957b95c3.res
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://samples.salondeguitaredemontreal.com/pixel.png
FAKEUPDATES botnet C2 (confidence level: 100%)
urlhttp://a1165370.xsph.ru/ee3f5b4f.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://load.granivit.hu
Vidar botnet C2 (confidence level: 75%)
urlhttp://45.153.34.30
Stealc botnet C2 (confidence level: 100%)
urlhttp://a1163876.xsph.ru/588d5684.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://45.153.34.30/dad3a40e52e74806.php
Stealc botnet C2 (confidence level: 100%)
urlhttp://newhousepanel.info/too/five/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)

File

ValueDescriptionCopy
file67.220.85.157
SparkRAT botnet C2 server (confidence level: 100%)
file8.135.13.184
Cobalt Strike botnet C2 server (confidence level: 100%)
file134.122.189.164
Ghost RAT botnet C2 server (confidence level: 100%)
file172.245.95.32
Remcos botnet C2 server (confidence level: 100%)
file195.177.94.33
Remcos botnet C2 server (confidence level: 100%)
file167.172.190.13
Sliver botnet C2 server (confidence level: 100%)
file172.94.59.38
AsyncRAT botnet C2 server (confidence level: 100%)
file194.165.16.8
SectopRAT botnet C2 server (confidence level: 100%)
file197.224.235.75
Unknown malware botnet C2 server (confidence level: 100%)
file18.158.94.111
Unknown malware botnet C2 server (confidence level: 100%)
file185.170.58.214
Unknown malware botnet C2 server (confidence level: 100%)
file194.48.140.13
MooBot botnet C2 server (confidence level: 100%)
file104.21.54.114
NjRAT botnet C2 server (confidence level: 100%)
file117.72.159.96
Cobalt Strike botnet C2 server (confidence level: 75%)
file68.64.176.42
Cobalt Strike botnet C2 server (confidence level: 75%)
file140.143.131.180
Cobalt Strike botnet C2 server (confidence level: 100%)
file107.174.232.95
Cobalt Strike botnet C2 server (confidence level: 100%)
file91.210.108.135
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.205.151.171
Cobalt Strike botnet C2 server (confidence level: 100%)
file180.76.244.55
Cobalt Strike botnet C2 server (confidence level: 100%)
file134.195.90.78
Sliver botnet C2 server (confidence level: 90%)
file50.108.119.33
Unknown malware botnet C2 server (confidence level: 100%)
file8.134.138.108
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.39.117
Unknown malware botnet C2 server (confidence level: 100%)
file8.134.139.219
Unknown malware botnet C2 server (confidence level: 100%)
file8.134.139.219
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.36.245
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.36.245
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.36.245
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.36.245
Unknown malware botnet C2 server (confidence level: 100%)
file196.251.73.138
Remcos botnet C2 server (confidence level: 100%)
file8.148.23.202
Unknown malware botnet C2 server (confidence level: 100%)
file8.148.23.202
Unknown malware botnet C2 server (confidence level: 100%)
file8.148.23.202
Unknown malware botnet C2 server (confidence level: 100%)
file8.148.23.202
Unknown malware botnet C2 server (confidence level: 100%)
file8.148.23.202
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.34.44
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.34.44
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.34.44
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.34.44
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.34.44
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.34.44
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.34.44
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.34.44
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.34.44
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.34.44
Unknown malware botnet C2 server (confidence level: 100%)
file8.130.34.44
Unknown malware botnet C2 server (confidence level: 100%)
file8.140.53.30
Unknown malware botnet C2 server (confidence level: 100%)
file43.160.197.87
Unknown malware botnet C2 server (confidence level: 100%)
file37.27.217.136
Unknown malware botnet C2 server (confidence level: 100%)
file35.220.228.241
Unknown malware botnet C2 server (confidence level: 100%)
file3.106.221.246
Unknown malware botnet C2 server (confidence level: 100%)
file54.175.22.89
Unknown malware botnet C2 server (confidence level: 100%)
file185.132.53.41
Unknown malware botnet C2 server (confidence level: 100%)
file178.128.115.139
Unknown malware botnet C2 server (confidence level: 100%)
file52.3.43.146
Unknown malware botnet C2 server (confidence level: 100%)
file147.139.206.21
Unknown malware botnet C2 server (confidence level: 100%)
file79.112.58.117
Unknown malware botnet C2 server (confidence level: 100%)
file79.107.156.181
QakBot botnet C2 server (confidence level: 100%)
file47.99.196.178
AdaptixC2 botnet C2 server (confidence level: 100%)
file81.70.230.219
Cobalt Strike botnet C2 server (confidence level: 100%)
file163.44.196.179
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.133.32.96
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.207.192.246
Cobalt Strike botnet C2 server (confidence level: 100%)
file110.40.176.194
Cobalt Strike botnet C2 server (confidence level: 50%)
file47.120.45.216
Cobalt Strike botnet C2 server (confidence level: 50%)
file43.139.169.60
Cobalt Strike botnet C2 server (confidence level: 50%)
file45.142.152.235
Cobalt Strike botnet C2 server (confidence level: 50%)
file47.121.137.8
Cobalt Strike botnet C2 server (confidence level: 50%)
file149.30.255.119
Cobalt Strike botnet C2 server (confidence level: 50%)
file47.103.109.70
Cobalt Strike botnet C2 server (confidence level: 50%)
file13.67.132.99
Cobalt Strike botnet C2 server (confidence level: 50%)
file99.80.82.80
Cobalt Strike botnet C2 server (confidence level: 50%)
file124.220.205.147
Cobalt Strike botnet C2 server (confidence level: 50%)
file202.95.9.141
Cobalt Strike botnet C2 server (confidence level: 50%)
file202.95.9.132
Cobalt Strike botnet C2 server (confidence level: 50%)
file202.95.9.149
Cobalt Strike botnet C2 server (confidence level: 50%)
file202.95.9.142
Cobalt Strike botnet C2 server (confidence level: 50%)
file202.95.9.156
Cobalt Strike botnet C2 server (confidence level: 50%)
file202.95.9.144
Cobalt Strike botnet C2 server (confidence level: 50%)
file202.95.9.147
Cobalt Strike botnet C2 server (confidence level: 50%)
file121.43.57.122
Cobalt Strike botnet C2 server (confidence level: 50%)
file121.43.57.122
Cobalt Strike botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file167.99.148.49
Sliver botnet C2 server (confidence level: 50%)
file185.241.208.218
Sliver botnet C2 server (confidence level: 50%)
file176.108.241.162
Sliver botnet C2 server (confidence level: 50%)
file49.232.95.245
Sliver botnet C2 server (confidence level: 50%)
file59.88.230.62
Mozi botnet C2 server (confidence level: 50%)
file117.248.26.27
Mozi botnet C2 server (confidence level: 50%)
file149.210.3.10
Ghost RAT botnet C2 server (confidence level: 50%)
file115.190.35.210
Unknown malware botnet C2 server (confidence level: 50%)
file156.208.77.43
Unknown malware botnet C2 server (confidence level: 50%)
file205.185.114.104
Unknown malware botnet C2 server (confidence level: 50%)
file178.63.215.79
ERMAC botnet C2 server (confidence level: 50%)
file45.204.218.149
DCRat botnet C2 server (confidence level: 50%)
file45.55.67.254
XWorm botnet C2 server (confidence level: 75%)
file212.7.208.129
NetWire RC botnet C2 server (confidence level: 50%)
file185.241.208.92
SpyNote botnet C2 server (confidence level: 50%)
file147.185.221.31
XWorm botnet C2 server (confidence level: 50%)
file178.16.55.70
XWorm botnet C2 server (confidence level: 100%)
file178.16.55.70
AsyncRAT botnet C2 server (confidence level: 100%)
file178.16.55.70
Quasar RAT botnet C2 server (confidence level: 100%)
file94.154.35.207
Quasar RAT botnet C2 server (confidence level: 100%)
file178.16.55.70
NjRAT botnet C2 server (confidence level: 100%)
file154.94.233.72
ValleyRAT botnet C2 server (confidence level: 100%)
file123.253.110.42
ValleyRAT botnet C2 server (confidence level: 100%)
file123.253.110.42
ValleyRAT botnet C2 server (confidence level: 100%)
file123.253.110.42
ValleyRAT botnet C2 server (confidence level: 100%)
file5.83.218.136
MetaStealer botnet C2 server (confidence level: 75%)
file5.75.211.226
Vidar botnet C2 server (confidence level: 100%)
file5.75.222.189
Vidar botnet C2 server (confidence level: 100%)
file58.181.59.43
Ghost RAT botnet C2 server (confidence level: 100%)
file54.255.211.150
Cobalt Strike botnet C2 server (confidence level: 100%)
file60.205.5.254
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.113.218.85
Cobalt Strike botnet C2 server (confidence level: 100%)
file110.42.32.88
Unknown malware botnet C2 server (confidence level: 100%)
file178.19.236.179
AsyncRAT botnet C2 server (confidence level: 100%)
file185.168.129.114
Havoc botnet C2 server (confidence level: 100%)
file102.96.188.215
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file31.192.107.185
PoshC2 botnet C2 server (confidence level: 100%)
file93.143.174.237
Chaos botnet C2 server (confidence level: 100%)
file206.123.152.99
Remcos botnet C2 server (confidence level: 100%)
file172.94.96.90
Remcos botnet C2 server (confidence level: 75%)
file201.202.66.177
QakBot botnet C2 server (confidence level: 75%)
file94.49.219.115
QakBot botnet C2 server (confidence level: 75%)
file104.233.252.17
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.2
Cobalt Strike botnet C2 server (confidence level: 75%)
file59.110.83.22
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.116.34.55
Cobalt Strike botnet C2 server (confidence level: 100%)
file163.5.169.217
Remcos botnet C2 server (confidence level: 100%)
file134.195.90.78
Sliver botnet C2 server (confidence level: 100%)
file154.205.133.142
ShadowPad botnet C2 server (confidence level: 90%)
file47.110.244.42
AdaptixC2 botnet C2 server (confidence level: 100%)
file185.22.154.73
BianLian botnet C2 server (confidence level: 100%)
file45.204.197.202
ValleyRAT botnet C2 server (confidence level: 100%)
file38.242.236.116
AsyncRAT botnet C2 server (confidence level: 100%)
file45.156.87.14
Rhadamanthys botnet C2 server (confidence level: 100%)
file103.172.26.89
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.1
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.10
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.11
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.14
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.15
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.16
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.18
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.20
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.21
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.23
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.24
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.25
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.27
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.28
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.29
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.3
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.5
Cobalt Strike botnet C2 server (confidence level: 75%)
file104.233.252.7
Cobalt Strike botnet C2 server (confidence level: 75%)
file111.229.35.131
Cobalt Strike botnet C2 server (confidence level: 50%)
file182.92.131.115
Cobalt Strike botnet C2 server (confidence level: 50%)
file175.27.137.94
Cobalt Strike botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file94.98.224.81
Xtreme RAT botnet C2 server (confidence level: 50%)
file64.227.191.31
Sliver botnet C2 server (confidence level: 50%)
file34.118.203.82
Sliver botnet C2 server (confidence level: 50%)
file185.216.27.22
Sliver botnet C2 server (confidence level: 50%)
file109.117.245.166
Unknown malware botnet C2 server (confidence level: 50%)
file54.90.255.198
NetSupportManager RAT botnet C2 server (confidence level: 50%)
file94.131.130.193
Quasar RAT botnet C2 server (confidence level: 50%)
file51.75.85.20
Ghost RAT botnet C2 server (confidence level: 50%)
file34.22.85.55
AdaptixC2 botnet C2 server (confidence level: 50%)
file45.55.67.254
Remcos botnet C2 server (confidence level: 50%)
file157.254.167.136
FAKEUPDATES botnet C2 server (confidence level: 100%)
file196.251.83.209
AsyncRAT botnet C2 server (confidence level: 100%)
file185.222.58.49
Remcos botnet C2 server (confidence level: 75%)
file45.159.248.167
ACR Stealer botnet C2 server (confidence level: 100%)
file95.164.69.234
ACR Stealer botnet C2 server (confidence level: 100%)
file77.91.123.244
ACR Stealer botnet C2 server (confidence level: 100%)
file45.144.29.250
ACR Stealer botnet C2 server (confidence level: 100%)
file95.164.69.191
ACR Stealer botnet C2 server (confidence level: 100%)
file185.214.74.93
ACR Stealer botnet C2 server (confidence level: 100%)
file87.120.219.212
ACR Stealer botnet C2 server (confidence level: 100%)
file161.97.68.73
AsyncRAT botnet C2 server (confidence level: 100%)
file196.251.85.246
Mirai botnet C2 server (confidence level: 100%)
file23.95.227.215
Cobalt Strike botnet C2 server (confidence level: 100%)
file134.122.189.174
Ghost RAT botnet C2 server (confidence level: 100%)
file45.74.8.89
AsyncRAT botnet C2 server (confidence level: 100%)
file91.198.77.151
Hook botnet C2 server (confidence level: 100%)
file63.178.148.142
Havoc botnet C2 server (confidence level: 100%)
file206.189.80.194
Havoc botnet C2 server (confidence level: 100%)
file18.181.96.254
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file118.184.187.163
Chaos botnet C2 server (confidence level: 100%)
file118.184.187.174
Chaos botnet C2 server (confidence level: 100%)
file91.212.166.160
Lumma Stealer botnet C2 server (confidence level: 100%)
file5.75.210.165
Vidar botnet C2 server (confidence level: 50%)
file193.233.171.27
XWorm botnet C2 server (confidence level: 100%)
file193.233.171.27
XWorm botnet C2 server (confidence level: 100%)
file134.19.178.162
Quasar RAT botnet C2 server (confidence level: 100%)
file46.4.27.174
RedLine Stealer botnet C2 server (confidence level: 100%)
file47.98.240.25
ValleyRAT botnet C2 server (confidence level: 100%)
file47.236.159.248
Cobalt Strike botnet C2 server (confidence level: 75%)
file45.86.153.106
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.16.52.81
Latrodectus botnet C2 server (confidence level: 100%)
file103.176.197.131
Ghost RAT botnet C2 server (confidence level: 100%)
file134.122.189.163
Ghost RAT botnet C2 server (confidence level: 100%)
file216.9.224.34
Remcos botnet C2 server (confidence level: 100%)
file212.192.221.76
Sliver botnet C2 server (confidence level: 100%)
file103.241.74.160
Unknown malware botnet C2 server (confidence level: 100%)
file45.141.215.69
AsyncRAT botnet C2 server (confidence level: 100%)
file217.160.241.22
AsyncRAT botnet C2 server (confidence level: 100%)
file186.190.211.108
AsyncRAT botnet C2 server (confidence level: 100%)
file84.200.73.108
AsyncRAT botnet C2 server (confidence level: 100%)
file185.196.10.243
Unknown malware botnet C2 server (confidence level: 100%)
file196.251.85.187
Hook botnet C2 server (confidence level: 100%)
file107.191.60.202
Havoc botnet C2 server (confidence level: 100%)
file107.191.60.202
Havoc botnet C2 server (confidence level: 100%)
file46.246.82.12
DCRat botnet C2 server (confidence level: 100%)
file118.184.187.173
Chaos botnet C2 server (confidence level: 100%)
file162.243.204.23
AsyncRAT botnet C2 server (confidence level: 100%)
file106.55.104.79
Unknown malware botnet C2 server (confidence level: 75%)
file112.93.133.97
DeimosC2 botnet C2 server (confidence level: 75%)
file116.26.10.18
DeimosC2 botnet C2 server (confidence level: 75%)
file197.0.85.219
QakBot botnet C2 server (confidence level: 75%)
file39.40.153.104
QakBot botnet C2 server (confidence level: 75%)
file92.161.137.94
Havoc botnet C2 server (confidence level: 75%)
file43.139.65.13
Cobalt Strike botnet C2 server (confidence level: 75%)
file156.254.21.146
ValleyRAT botnet C2 server (confidence level: 100%)
file107.172.172.225
XWorm botnet C2 server (confidence level: 100%)
file185.163.204.202
XWorm botnet C2 server (confidence level: 100%)
file147.185.221.31
XWorm botnet C2 server (confidence level: 100%)
file191.96.224.156
XWorm botnet C2 server (confidence level: 100%)
file216.9.224.169
PureLogs Stealer botnet C2 server (confidence level: 100%)
file147.124.195.98
XWorm botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash6001
SparkRAT botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Ghost RAT botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2323
Remcos botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash222
AsyncRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash909
MooBot botnet C2 server (confidence level: 100%)
hash443
NjRAT botnet C2 server (confidence level: 100%)
hash8081
Cobalt Strike botnet C2 server (confidence level: 75%)
hash5566
Cobalt Strike botnet C2 server (confidence level: 75%)
hash18443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8089
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 90%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash179
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash8090
Unknown malware botnet C2 server (confidence level: 100%)
hash1913
Unknown malware botnet C2 server (confidence level: 100%)
hash8088
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash749
Unknown malware botnet C2 server (confidence level: 100%)
hash1099
Unknown malware botnet C2 server (confidence level: 100%)
hash5000
Remcos botnet C2 server (confidence level: 100%)
hash2632
Unknown malware botnet C2 server (confidence level: 100%)
hash49152
Unknown malware botnet C2 server (confidence level: 100%)
hash51005
Unknown malware botnet C2 server (confidence level: 100%)
hash52200
Unknown malware botnet C2 server (confidence level: 100%)
hash58157
Unknown malware botnet C2 server (confidence level: 100%)
hash42306
Unknown malware botnet C2 server (confidence level: 100%)
hash6006
Unknown malware botnet C2 server (confidence level: 100%)
hash6699
Unknown malware botnet C2 server (confidence level: 100%)
hash8088
Unknown malware botnet C2 server (confidence level: 100%)
hash16993
Unknown malware botnet C2 server (confidence level: 100%)
hash33113
Unknown malware botnet C2 server (confidence level: 100%)
hash8880
Unknown malware botnet C2 server (confidence level: 100%)
hash22291
Unknown malware botnet C2 server (confidence level: 100%)
hash27861
Unknown malware botnet C2 server (confidence level: 100%)
hash32772
Unknown malware botnet C2 server (confidence level: 100%)
hash43620
Unknown malware botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash995
QakBot botnet C2 server (confidence level: 100%)
hash7001
AdaptixC2 botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9999
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8099
Cobalt Strike botnet C2 server (confidence level: 50%)
hash8032
Cobalt Strike botnet C2 server (confidence level: 50%)
hash8009
Cobalt Strike botnet C2 server (confidence level: 50%)
hash8889
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash4443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash10001
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash50050
Cobalt Strike botnet C2 server (confidence level: 50%)
hash4434
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash8916
Xtreme RAT botnet C2 server (confidence level: 50%)
hash20121
Xtreme RAT botnet C2 server (confidence level: 50%)
hash7801
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9203
Xtreme RAT botnet C2 server (confidence level: 50%)
hash10911
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3030
Xtreme RAT botnet C2 server (confidence level: 50%)
hash49152
Xtreme RAT botnet C2 server (confidence level: 50%)
hash5917
Xtreme RAT botnet C2 server (confidence level: 50%)
hash2224
Xtreme RAT botnet C2 server (confidence level: 50%)
hash440
Xtreme RAT botnet C2 server (confidence level: 50%)
hash175
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9022
Xtreme RAT botnet C2 server (confidence level: 50%)
hash32303
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9189
Xtreme RAT botnet C2 server (confidence level: 50%)
hash10087
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3137
Xtreme RAT botnet C2 server (confidence level: 50%)
hash2221
Xtreme RAT botnet C2 server (confidence level: 50%)
hash15151
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3076
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8156
Xtreme RAT botnet C2 server (confidence level: 50%)
hash16052
Xtreme RAT botnet C2 server (confidence level: 50%)
hash264
Xtreme RAT botnet C2 server (confidence level: 50%)
hash2567
Xtreme RAT botnet C2 server (confidence level: 50%)
hash21311
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8150
Xtreme RAT botnet C2 server (confidence level: 50%)
hash1292
Xtreme RAT botnet C2 server (confidence level: 50%)
hash42901
Xtreme RAT botnet C2 server (confidence level: 50%)
hash18068
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3183
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9090
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3590
Xtreme RAT botnet C2 server (confidence level: 50%)
hash5903
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8161
Xtreme RAT botnet C2 server (confidence level: 50%)
hash10009
Xtreme RAT botnet C2 server (confidence level: 50%)
hash5998
Xtreme RAT botnet C2 server (confidence level: 50%)
hash21263
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8144
Xtreme RAT botnet C2 server (confidence level: 50%)
hash21242
Xtreme RAT botnet C2 server (confidence level: 50%)
hash777
Xtreme RAT botnet C2 server (confidence level: 50%)
hash50160
Xtreme RAT botnet C2 server (confidence level: 50%)
hash5400
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8859
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8562
Xtreme RAT botnet C2 server (confidence level: 50%)
hash2550
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9163
Xtreme RAT botnet C2 server (confidence level: 50%)
hash2086
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8017
Xtreme RAT botnet C2 server (confidence level: 50%)
hash12397
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9447
Xtreme RAT botnet C2 server (confidence level: 50%)
hash427
Xtreme RAT botnet C2 server (confidence level: 50%)
hash55443
Xtreme RAT botnet C2 server (confidence level: 50%)
hash59012
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3176
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8023
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3173
Xtreme RAT botnet C2 server (confidence level: 50%)
hash7687
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9307
Xtreme RAT botnet C2 server (confidence level: 50%)
hash52311
Xtreme RAT botnet C2 server (confidence level: 50%)
hash12295
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8025
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9532
Xtreme RAT botnet C2 server (confidence level: 50%)
hash1723
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8026
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9797
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8005
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8853
Xtreme RAT botnet C2 server (confidence level: 50%)
hash21236
Xtreme RAT botnet C2 server (confidence level: 50%)
hash4085
Xtreme RAT botnet C2 server (confidence level: 50%)
hash12242
Xtreme RAT botnet C2 server (confidence level: 50%)
hash11401
Xtreme RAT botnet C2 server (confidence level: 50%)
hash45786
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9376
Xtreme RAT botnet C2 server (confidence level: 50%)
hash16104
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3305
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9135
Xtreme RAT botnet C2 server (confidence level: 50%)
hash12479
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9710
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3510
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8117
Xtreme RAT botnet C2 server (confidence level: 50%)
hash5558
Xtreme RAT botnet C2 server (confidence level: 50%)
hash55475
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8622
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3342
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9106
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3403
Xtreme RAT botnet C2 server (confidence level: 50%)
hash92
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9245
Xtreme RAT botnet C2 server (confidence level: 50%)
hash63256
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8866
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3189
Xtreme RAT botnet C2 server (confidence level: 50%)
hash263
Xtreme RAT botnet C2 server (confidence level: 50%)
hash11002
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8556
Xtreme RAT botnet C2 server (confidence level: 50%)
hash6686
Xtreme RAT botnet C2 server (confidence level: 50%)
hash6352
Xtreme RAT botnet C2 server (confidence level: 50%)
hash10022
Xtreme RAT botnet C2 server (confidence level: 50%)
hash5224
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9019
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9048
Xtreme RAT botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash57781
Mozi botnet C2 server (confidence level: 50%)
hash48002
Mozi botnet C2 server (confidence level: 50%)
hash443
Ghost RAT botnet C2 server (confidence level: 50%)
hash80
Unknown malware botnet C2 server (confidence level: 50%)
hash81
Unknown malware botnet C2 server (confidence level: 50%)
hash8098
Unknown malware botnet C2 server (confidence level: 50%)
hash8089
ERMAC botnet C2 server (confidence level: 50%)
hash65503
DCRat botnet C2 server (confidence level: 50%)
hash4580
XWorm botnet C2 server (confidence level: 75%)
hash4951
NetWire RC botnet C2 server (confidence level: 50%)
hash3344
SpyNote botnet C2 server (confidence level: 50%)
hash40501
XWorm botnet C2 server (confidence level: 50%)
hash6000
XWorm botnet C2 server (confidence level: 100%)
hash4449
AsyncRAT botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash5552
NjRAT botnet C2 server (confidence level: 100%)
hash0443
ValleyRAT botnet C2 server (confidence level: 100%)
hash9090
ValleyRAT botnet C2 server (confidence level: 100%)
hash9091
ValleyRAT botnet C2 server (confidence level: 100%)
hash9092
ValleyRAT botnet C2 server (confidence level: 100%)
hash443
MetaStealer botnet C2 server (confidence level: 75%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash9735
Ghost RAT botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash81
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash33333
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash443
PoshC2 botnet C2 server (confidence level: 100%)
hash8080
Chaos botnet C2 server (confidence level: 100%)
hash3421
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 75%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash443
ShadowPad botnet C2 server (confidence level: 90%)
hash7001
AdaptixC2 botnet C2 server (confidence level: 100%)
hash443
BianLian botnet C2 server (confidence level: 100%)
hash1677
ValleyRAT botnet C2 server (confidence level: 100%)
hash1137
AsyncRAT botnet C2 server (confidence level: 100%)
hash8213
Rhadamanthys botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8000
Cobalt Strike botnet C2 server (confidence level: 50%)
hash8081
Cobalt Strike botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 50%)
hash1935
Xtreme RAT botnet C2 server (confidence level: 50%)
hash12329
Xtreme RAT botnet C2 server (confidence level: 50%)
hash12455
Xtreme RAT botnet C2 server (confidence level: 50%)
hash21307
Xtreme RAT botnet C2 server (confidence level: 50%)
hash35002
Xtreme RAT botnet C2 server (confidence level: 50%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 50%)
hash12580
Xtreme RAT botnet C2 server (confidence level: 50%)
hash1207
Xtreme RAT botnet C2 server (confidence level: 50%)
hash6443
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8789
Xtreme RAT botnet C2 server (confidence level: 50%)
hash12559
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9054
Xtreme RAT botnet C2 server (confidence level: 50%)
hash1200
Xtreme RAT botnet C2 server (confidence level: 50%)
hash8024
Xtreme RAT botnet C2 server (confidence level: 50%)
hash12393
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9939
Xtreme RAT botnet C2 server (confidence level: 50%)
hash9164
Xtreme RAT botnet C2 server (confidence level: 50%)
hash12425
Xtreme RAT botnet C2 server (confidence level: 50%)
hash3500
Xtreme RAT botnet C2 server (confidence level: 50%)
hash43009
Xtreme RAT botnet C2 server (confidence level: 50%)
hash97
Xtreme RAT botnet C2 server (confidence level: 50%)
hash2762
Xtreme RAT botnet C2 server (confidence level: 50%)
hash44306
Xtreme RAT botnet C2 server (confidence level: 50%)
hash14895
Xtreme RAT botnet C2 server (confidence level: 50%)
hash10047
Xtreme RAT botnet C2 server (confidence level: 50%)
hash2064
Xtreme RAT botnet C2 server (confidence level: 50%)
hash1433
Xtreme RAT botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash4444
Unknown malware botnet C2 server (confidence level: 50%)
hash17000
NetSupportManager RAT botnet C2 server (confidence level: 50%)
hash1337
Quasar RAT botnet C2 server (confidence level: 50%)
hash443
Ghost RAT botnet C2 server (confidence level: 50%)
hash6443
AdaptixC2 botnet C2 server (confidence level: 50%)
hash6377
Remcos botnet C2 server (confidence level: 50%)
hash443
FAKEUPDATES botnet C2 server (confidence level: 100%)
hash9003
AsyncRAT botnet C2 server (confidence level: 100%)
hash465
Remcos botnet C2 server (confidence level: 75%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash3329
AsyncRAT botnet C2 server (confidence level: 100%)
hash3778
Mirai botnet C2 server (confidence level: 100%)
hash56874
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Ghost RAT botnet C2 server (confidence level: 100%)
hash1001
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash80
Havoc botnet C2 server (confidence level: 100%)
hash1135
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash47486
Chaos botnet C2 server (confidence level: 100%)
hash47486
Chaos botnet C2 server (confidence level: 100%)
hash443
Lumma Stealer botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 50%)
hash4444
XWorm botnet C2 server (confidence level: 100%)
hash5555
XWorm botnet C2 server (confidence level: 100%)
hash5700
Quasar RAT botnet C2 server (confidence level: 100%)
hash16639
RedLine Stealer botnet C2 server (confidence level: 100%)
hash1234
ValleyRAT botnet C2 server (confidence level: 100%)
hash53
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash14994
Ghost RAT botnet C2 server (confidence level: 100%)
hash443
Ghost RAT botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash888
AsyncRAT botnet C2 server (confidence level: 100%)
hash1231
AsyncRAT botnet C2 server (confidence level: 100%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash80
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash1963
DCRat botnet C2 server (confidence level: 100%)
hash47486
Chaos botnet C2 server (confidence level: 100%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 75%)
hash23293
DeimosC2 botnet C2 server (confidence level: 75%)
hash36122
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash995
QakBot botnet C2 server (confidence level: 75%)
hash4443
Havoc botnet C2 server (confidence level: 75%)
hash5557
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8088
ValleyRAT botnet C2 server (confidence level: 100%)
hash6542
XWorm botnet C2 server (confidence level: 100%)
hash45000
XWorm botnet C2 server (confidence level: 100%)
hash29739
XWorm botnet C2 server (confidence level: 100%)
hash100
XWorm botnet C2 server (confidence level: 100%)
hash2090
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)

Threat ID: 68b7891ead5a09ad00e9d59a

Added to database: 9/3/2025, 12:17:34 AM

Last enriched: 9/3/2025, 12:33:00 AM

Last updated: 9/3/2025, 1:39:58 PM

Views: 9

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats