Skip to main content

ThreatFox IOCs for 2025-09-07

Medium
Published: Sun Sep 07 2025 (09/07/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-09-07

AI-Powered Analysis

AILast updated: 09/08/2025, 00:33:20 UTC

Technical Analysis

The provided information pertains to a set of Indicators of Compromise (IOCs) published on September 7, 2025, by the ThreatFox MISP Feed, categorized under malware with a focus on OSINT (Open Source Intelligence), payload delivery, and network activity. The data appears to be a collection of threat intelligence indicators rather than a specific vulnerability or exploit. No affected product versions or patches are listed, and there are no known exploits in the wild associated with these IOCs. The threat level is rated as medium, with a threatLevel score of 2, analysis score of 1, and distribution score of 3, indicating moderate concern and distribution. The absence of concrete technical details such as malware family, attack vectors, or exploitation methods limits the depth of technical analysis. The IOCs are intended to aid in detection and response activities by providing network and payload-related indicators that can be used to identify malicious activity or payload delivery attempts. As these IOCs are tagged with TLP:white, they are intended for broad sharing and use within the security community. Overall, this represents a proactive intelligence sharing effort rather than an active or emergent exploit or vulnerability.

Potential Impact

For European organizations, the impact of these IOCs depends largely on their integration into security monitoring and incident response processes. Since the IOCs relate to malware payload delivery and network activity, failure to incorporate them into detection systems could result in missed identification of malicious traffic or payloads, potentially leading to compromise. However, given the medium severity and lack of known active exploits, the immediate risk is moderate. Organizations with mature security operations centers (SOCs) and threat intelligence capabilities can leverage these IOCs to enhance their detection capabilities, reducing the likelihood of successful attacks. Conversely, organizations lacking such capabilities may face increased risk of undetected intrusion attempts. The absence of patches or specific vulnerable products suggests that the threat is more about detection of malicious activity rather than mitigation of a software vulnerability. Therefore, the primary impact is on the confidentiality and integrity of systems if payload delivery attempts succeed, potentially leading to malware infections or data breaches.

Mitigation Recommendations

European organizations should integrate these IOCs into their existing security infrastructure, including intrusion detection/prevention systems (IDS/IPS), firewalls, endpoint detection and response (EDR) tools, and security information and event management (SIEM) platforms. Automated ingestion of ThreatFox IOCs can improve real-time detection of suspicious network activity and payload delivery attempts. Regular updates and validation of threat intelligence feeds are essential to maintain relevance. Additionally, organizations should conduct network traffic analysis to identify anomalies that match the provided IOCs. Employee awareness and phishing prevention training remain important, as payload delivery often involves social engineering. Since no patches are available, emphasis should be on detection, containment, and response. Incident response plans should be reviewed and tested to ensure rapid reaction to detections based on these IOCs. Finally, collaboration with national and European cybersecurity centers (e.g., ENISA) can enhance collective defense efforts.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
2596598c-1e56-42f1-a1e0-0935e0abe24b
Original Timestamp
1757289785

Indicators of Compromise

Domain

ValueDescriptionCopy
domainqd.pylohao.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzmi.pylohao.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlt.pylohao.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincobyrose.com
SmokeLoader botnet C2 domain (confidence level: 100%)
domainvcn.pylohao.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrk.pylohao.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwa.kujywii.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbzl.kujywii.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyc.kujywii.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpqt.kujywii.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhn.kujywii.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfj.xijoxou.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkro.xijoxou.ru
ClearFake payload delivery domain (confidence level: 100%)
domainux.xijoxou.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnzi.xijoxou.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincq.xijoxou.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvl.namenyo.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsaj.namenyo.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindru.namenyo.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhex.namenyo.ru
ClearFake payload delivery domain (confidence level: 100%)
domainasfb.kixyzoo7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkhsl.kixyzoo7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpqhr.kixyzoo7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkal.biryquo.ru
ClearFake payload delivery domain (confidence level: 100%)
domainehgf.kixyzoo7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvm.cyzukae.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsstu.kixyzoo7.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingri.cyzukae.ru
ClearFake payload delivery domain (confidence level: 100%)
domainchhd.luwotaa1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxshy.luwotaa1.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindr.hulenao.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmnho.luwotaa1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmanage.tld56.cn
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainbmsmobile.tld56.cn
Cobalt Strike botnet C2 domain (confidence level: 100%)
domaintransfiles.tld56.cn
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainwww.zcuke.com
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainn8n-video-demo.keerok.tech
Unknown malware botnet C2 domain (confidence level: 100%)
domainohsp.luwotaa1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrsht.luwotaa1.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincx3fbungd.localto.net
XWorm botnet C2 domain (confidence level: 100%)
domainbox-dealer.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainhit-calculation.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainwww.gondeen.com
Remcos botnet C2 domain (confidence level: 100%)
domainanonam39-21749.portmap.io
Quasar RAT botnet C2 domain (confidence level: 100%)
domainelectronics-webmaster.gl.at.ply.gg
Quasar RAT botnet C2 domain (confidence level: 100%)
domaina6.nbdsnb2.top
FatalRat botnet C2 domain (confidence level: 100%)
domainesf.kufapoi3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainuhv.kufapoi3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainghsi.kufapoi3.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintranslate.googleegah.icu
Unknown RAT payload delivery domain (confidence level: 50%)
domaintranslate.googleegaz.icu
Unknown RAT payload delivery domain (confidence level: 50%)
domainappb-chrome.com
Unknown RAT payload delivery domain (confidence level: 75%)
domaingooglechrome-ww.com
Unknown RAT payload delivery domain (confidence level: 75%)
domainjhk.kufapoi3.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintz.vikidii.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwsxy.kufapoi3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlmh.rocixaa9.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstamrbyb.xin
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaintetrwoo.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainfigueqhk.xin
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainhffiahz.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainplataukz.xin
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainsprimvd.my
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainrenohhde.xin
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainlithfzx.my
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaintitlexy.my
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainstc.s3.masterclasstonewow.com
Vidar botnet C2 domain (confidence level: 75%)
domainabh.rocixaa9.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqn.xapomyo.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbank-danny.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainfireblazecorrect.duckdns.org
XWorm botnet C2 domain (confidence level: 100%)
domainmaintainthefeex.duckdns.org
XWorm botnet C2 domain (confidence level: 100%)
domainmasqingtestformat.gleeze.com
XWorm botnet C2 domain (confidence level: 100%)
domainpqr.rocixaa9.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsth.rocixaa9.ru
ClearFake payload delivery domain (confidence level: 100%)
domainuvwh.rocixaa9.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxyh.lypelya2.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincdh.lypelya2.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvru.xapomyo.ru
ClearFake payload delivery domain (confidence level: 100%)
domainconsnbx.su
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaindiadtuky.su
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainsirhirssg.su
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainprebwle.su
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainrhussois.su
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaintodoexy.su
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainacrislegt.su
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainaveriryvx.su
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincerasatvf.su
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainbrokencars.shop
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaincartdetails.shop
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainluxgames.shop
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainradioengineering.shop
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainsocial-vpdf.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindogcded.bet
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainmns.lypelya2.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkls.lypelya2.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhs.tyjyxie.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzom.tyjyxie.ru
ClearFake payload delivery domain (confidence level: 100%)
domainomnizplsr-22653.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainlaw-notebooks.gl.at.ply.gg
Quasar RAT botnet C2 domain (confidence level: 100%)
domainalbanakatana-48889.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainkoko7878.no-ip.biz
CyberGate botnet C2 domain (confidence level: 100%)
domainhacker-metline.no-ip.org
CyberGate botnet C2 domain (confidence level: 100%)
domaindraker.no-ip.org
CyberGate botnet C2 domain (confidence level: 100%)
domainsun.pobinei39.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpk.teziriy.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmra.teziriy.ru
ClearFake payload delivery domain (confidence level: 100%)
domainclub.pornclubnight.com
Havoc botnet C2 domain (confidence level: 100%)
domainjl.pubarey.ru
ClearFake payload delivery domain (confidence level: 100%)
domainup.sypyguu85.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsno.pubarey.ru
ClearFake payload delivery domain (confidence level: 100%)

File

ValueDescriptionCopy
file91.98.120.131
ACR Stealer botnet C2 server (confidence level: 100%)
file91.98.129.69
ACR Stealer botnet C2 server (confidence level: 100%)
file37.27.40.177
ACR Stealer botnet C2 server (confidence level: 100%)
file138.201.185.57
ACR Stealer botnet C2 server (confidence level: 100%)
file38.207.178.73
Cobalt Strike botnet C2 server (confidence level: 100%)
file134.122.155.143
Ghost RAT botnet C2 server (confidence level: 100%)
file134.122.155.141
Ghost RAT botnet C2 server (confidence level: 100%)
file95.217.97.220
Sliver botnet C2 server (confidence level: 100%)
file128.90.113.220
AsyncRAT botnet C2 server (confidence level: 100%)
file150.40.119.238
Hook botnet C2 server (confidence level: 100%)
file90.48.210.177
Havoc botnet C2 server (confidence level: 100%)
file79.241.107.250
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file40.176.189.140
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file190.134.58.58
RedLine Stealer botnet C2 server (confidence level: 100%)
file47.110.229.61
Cobalt Strike botnet C2 server (confidence level: 100%)
file134.122.155.137
Ghost RAT botnet C2 server (confidence level: 75%)
file107.150.0.56
AsyncRAT botnet C2 server (confidence level: 100%)
file15.206.72.142
Unknown malware botnet C2 server (confidence level: 100%)
file54.190.133.237
Unknown malware botnet C2 server (confidence level: 100%)
file154.127.53.68
Remcos botnet C2 server (confidence level: 100%)
file149.28.70.98
Remcos botnet C2 server (confidence level: 100%)
file142.51.243.254
Unknown malware botnet C2 server (confidence level: 100%)
file222.166.249.8
Unknown malware botnet C2 server (confidence level: 100%)
file16.171.236.166
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file128.199.85.131
Unknown malware botnet C2 server (confidence level: 100%)
file168.231.84.225
Unknown malware botnet C2 server (confidence level: 100%)
file5.187.0.35
Unknown malware botnet C2 server (confidence level: 100%)
file46.202.146.169
Unknown malware botnet C2 server (confidence level: 100%)
file139.59.92.93
Unknown malware botnet C2 server (confidence level: 100%)
file159.65.138.143
Unknown malware botnet C2 server (confidence level: 100%)
file128.199.85.74
Unknown malware botnet C2 server (confidence level: 100%)
file182.92.119.28
Unknown malware botnet C2 server (confidence level: 100%)
file167.172.77.84
Unknown malware botnet C2 server (confidence level: 100%)
file196.251.85.206
XWorm botnet C2 server (confidence level: 100%)
file84.200.87.115
Quasar RAT botnet C2 server (confidence level: 100%)
file23.249.28.119
ValleyRAT botnet C2 server (confidence level: 100%)
file172.245.112.200
XWorm botnet C2 server (confidence level: 100%)
file137.175.102.148
Cobalt Strike botnet C2 server (confidence level: 100%)
file164.92.197.38
Remcos botnet C2 server (confidence level: 100%)
file192.3.177.145
Remcos botnet C2 server (confidence level: 100%)
file193.233.113.101
XWorm botnet C2 server (confidence level: 100%)
file56.155.92.53
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file18.214.2.45
Unknown malware botnet C2 server (confidence level: 100%)
file148.178.49.203
DeimosC2 botnet C2 server (confidence level: 75%)
file148.178.53.213
DeimosC2 botnet C2 server (confidence level: 75%)
file148.178.55.222
DeimosC2 botnet C2 server (confidence level: 75%)
file148.178.66.199
DeimosC2 botnet C2 server (confidence level: 75%)
file148.178.66.219
DeimosC2 botnet C2 server (confidence level: 75%)
file148.178.82.172
DeimosC2 botnet C2 server (confidence level: 75%)
file154.216.157.172
ValleyRAT botnet C2 server (confidence level: 100%)
file43.225.47.165
ValleyRAT botnet C2 server (confidence level: 100%)
file47.115.221.235
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.60.15.107
Remcos botnet C2 server (confidence level: 100%)
file154.219.96.137
Ghost RAT botnet C2 server (confidence level: 100%)
file185.128.106.44
Remcos botnet C2 server (confidence level: 100%)
file206.123.152.103
Remcos botnet C2 server (confidence level: 100%)
file185.196.9.158
AsyncRAT botnet C2 server (confidence level: 100%)
file45.204.211.17
Kaiji botnet C2 server (confidence level: 100%)
file107.178.115.242
Rhadamanthys botnet C2 server (confidence level: 100%)
file43.225.47.165
ValleyRAT botnet C2 server (confidence level: 100%)
file43.225.47.165
ValleyRAT botnet C2 server (confidence level: 100%)
file23.249.28.119
ValleyRAT botnet C2 server (confidence level: 100%)
file23.249.28.119
ValleyRAT botnet C2 server (confidence level: 100%)
file104.233.252.10
Cobalt Strike botnet C2 server (confidence level: 75%)
file119.29.254.242
Cobalt Strike botnet C2 server (confidence level: 75%)
file43.139.65.13
Cobalt Strike botnet C2 server (confidence level: 75%)
file121.43.244.221
Cobalt Strike botnet C2 server (confidence level: 100%)
file198.55.98.77
RedLine Stealer botnet C2 server (confidence level: 100%)
file87.248.150.68
Mirai botnet C2 server (confidence level: 100%)
file147.185.221.31
XWorm botnet C2 server (confidence level: 100%)
file103.127.125.151
Ghost RAT botnet C2 server (confidence level: 100%)
file217.138.204.165
Remcos botnet C2 server (confidence level: 100%)
file159.223.171.199
Remcos botnet C2 server (confidence level: 100%)
file103.85.252.170
ShadowPad botnet C2 server (confidence level: 90%)
file121.43.104.214
AsyncRAT botnet C2 server (confidence level: 100%)
file185.18.222.5
DCRat botnet C2 server (confidence level: 100%)
file16.50.237.232
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file52.63.111.178
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file147.45.143.187
BianLian botnet C2 server (confidence level: 100%)
file147.185.221.31
Quasar RAT botnet C2 server (confidence level: 100%)
file193.161.193.99
XWorm botnet C2 server (confidence level: 100%)
file31.57.147.161
XWorm botnet C2 server (confidence level: 100%)
file186.169.40.245
XWorm botnet C2 server (confidence level: 100%)
file107.149.247.22
ValleyRAT botnet C2 server (confidence level: 100%)
file118.31.2.114
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.115.221.235
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.94.34.227
Cobalt Strike botnet C2 server (confidence level: 100%)
file209.141.62.10
Cobalt Strike botnet C2 server (confidence level: 100%)
file193.37.69.42
Cobalt Strike botnet C2 server (confidence level: 100%)
file52.63.124.130
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.190.178
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.188.198
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.191.190
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.188.189
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.190.179
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.185.189
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.187.187
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.188.204
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.188.203
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.184.178
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.184.185
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.187.180
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.189.202
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.189.185
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.190.197
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.188.176
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.190.192
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.186.195
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.188.181
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.188.182
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.186.191
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.185.185
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.184.195
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.190.193
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.187.203
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.184.202
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.187.193
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.184.187
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.189.183
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.190.199
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.184.182
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.184.176
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.188.178
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.184.184
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.185.179
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.188.194
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.188.183
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.187.186
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.188.179
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.189.176
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.185.197
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.189.182
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.184.191
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.184.181
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.89.188.186
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.86.44.136
Ghost RAT botnet C2 server (confidence level: 100%)
file103.86.44.169
Ghost RAT botnet C2 server (confidence level: 100%)
file173.249.9.44
Remcos botnet C2 server (confidence level: 100%)
file80.78.18.25
Sliver botnet C2 server (confidence level: 100%)
file135.220.19.84
Sliver botnet C2 server (confidence level: 100%)
file161.35.216.90
Sliver botnet C2 server (confidence level: 100%)
file139.84.210.208
ShadowPad botnet C2 server (confidence level: 90%)
file43.225.157.146
AsyncRAT botnet C2 server (confidence level: 100%)
file138.197.29.190
Unknown malware botnet C2 server (confidence level: 100%)
file90.48.210.177
Unknown malware botnet C2 server (confidence level: 100%)
file181.161.2.146
Quasar RAT botnet C2 server (confidence level: 100%)
file13.39.104.25
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file18.204.79.137
Nimplant botnet C2 server (confidence level: 100%)
file185.229.32.120
MooBot botnet C2 server (confidence level: 100%)
file94.237.93.73
MimiKatz botnet C2 server (confidence level: 100%)
file172.235.190.63
Empire Downloader botnet C2 server (confidence level: 100%)
file159.203.90.17
Empire Downloader botnet C2 server (confidence level: 100%)
file147.185.221.31
XWorm botnet C2 server (confidence level: 100%)
file118.107.9.63
ValleyRAT botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash443
ACR Stealer botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash14994
Ghost RAT botnet C2 server (confidence level: 100%)
hash14994
Ghost RAT botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash80
Havoc botnet C2 server (confidence level: 100%)
hash82
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash11102
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash097a5601056afd48bdb3db24d8a7c773fc2afc87
XWorm payload (confidence level: 95%)
hash68a367884639037f1e1e7619df3ae3fcc6177034e8bd3d0da2f62383762b3dc8
XWorm payload (confidence level: 95%)
hashd3c223256f7a719ecf40f5054e6ecdef
XWorm payload (confidence level: 95%)
hashcd9002c13ddb6aefe04f64d716bbf30ee31c7124
XWorm payload (confidence level: 95%)
hash16504ecdf01e0666a5a41542568fb228f23d2f65a8fe499c7924f28f4422dc72
XWorm payload (confidence level: 95%)
hash135ffe18f7b1349db0d9d2346db1bdcd
XWorm payload (confidence level: 95%)
hash1b2654b1d795b8ce647942ec20f2373ddf08ab89
ValleyRAT payload (confidence level: 95%)
hash3f61f2626ae164481484e1145ab87bf220e38f7dfd425fd3e533f03803a44189
ValleyRAT payload (confidence level: 95%)
hash8a1ff5d1961a6b050e0a9085d63134ef
ValleyRAT payload (confidence level: 95%)
hashcc227585010c85d6cf43e177286b393a3c06798f
DCRat payload (confidence level: 95%)
hashec699fa4b29083c2d0da8a87b589ebe130b195f022d6f0de2d43372409bdc34f
DCRat payload (confidence level: 95%)
hash8a4202a16c07c695263573334268537d
DCRat payload (confidence level: 95%)
hash1fbc2860bca76bdef90f0f75e05b0683c4466792
Amadey payload (confidence level: 95%)
hash254abb6da9296f8c6f8e567186e3d59ddba2392fa4baf791492f7e76b4ff5af7
Amadey payload (confidence level: 95%)
hashffaf1f8b43d407644b320b846f02ee5b
Amadey payload (confidence level: 95%)
hashbfe717ebbbc728e186b57e5511742730b9504422
DCRat payload (confidence level: 95%)
hashb9168974aee96f657950455bf1933cf18500ae8b1da94a90860fcdafc91b95b4
DCRat payload (confidence level: 95%)
hash51752b978a87046aa62ee99d97750733
DCRat payload (confidence level: 95%)
hash0aa29f7d8c4a04f5e9071827fa97decce8d72c20
XWorm payload (confidence level: 95%)
hash9a657f8a9e75786f58aa9775b5b403544fc15249a22bc13165472f4ec7c20b6b
XWorm payload (confidence level: 95%)
hash6ecb301ad38ad9de49026c559e980385
XWorm payload (confidence level: 95%)
hashff39b785672ec33edd2c0a7e4a69ab9f87a2e6c8d96b9f0e941f35fa33f13c77
Rhadamanthys payload (confidence level: 95%)
hash03e6abbc712b66dbe311ada954f0cb05
Rhadamanthys payload (confidence level: 95%)
hash872a708c000d1aee5a20a2c59247bec980e62528
XWorm payload (confidence level: 95%)
hashb641d47cd7188049c6a4cc259919d95d84205f4d4e6b32d5580b1c462a87cf30
XWorm payload (confidence level: 95%)
hash0756de1b9c8f99dcb477d7b49feae2a0
XWorm payload (confidence level: 95%)
hashbb43805f01696bcc15fdcd2ca80891ae46417cbe
DCRat payload (confidence level: 95%)
hash566c604f26742adb324f674132c9e3d7ae9015ad8e3301e7d5b9fc98b7c2e8f8
DCRat payload (confidence level: 95%)
hash4c24dd197672d324717c15c7fb7afc11
DCRat payload (confidence level: 95%)
hasha651c1b0e9b0307c21f13a0d786c58974e7484af
DCRat payload (confidence level: 95%)
hash05af274a83acfef260398e86ef52f2a889c6dd7d2818e54b20e90ee535019b5b
DCRat payload (confidence level: 95%)
hash47a64e9978009dfdcaba6f4ea71264a2
DCRat payload (confidence level: 95%)
hashec259063f9999d8569781cea00cbff7da90f088ed04c79c494754949d3e07fa9
DCRat payload (confidence level: 95%)
hash32a3d3b3333c2ed9bd7ca58de1ced447
DCRat payload (confidence level: 95%)
hash185f8cd0fbc5178dedfbb4fb0cb99c0fde8aefdf
XWorm payload (confidence level: 95%)
hashb5e110bed3f60078521c8cfbdf0a41b6634f463cf360c62af52027dec5b00e27
XWorm payload (confidence level: 95%)
hash26b61ddfc75c8119d7a37b77513d3b35
XWorm payload (confidence level: 95%)
hash60fee55ae8ea754751f63aeeb4a7b58a8a3de960
XWorm payload (confidence level: 95%)
hash7ebf3abd2208ff479bd6b3a546833f757c90519c377ef13a7f08549d6d32437a
XWorm payload (confidence level: 95%)
hash04f19d542018fbee2f0cf1da0114be7c
XWorm payload (confidence level: 95%)
hash385ec9be75ec9770a6bec409b974a05b9ae9c919
XWorm payload (confidence level: 95%)
hash45ba32fcb65201e7cae3d05f77178e08fd41380624edd777e355c63ac1d126b7
XWorm payload (confidence level: 95%)
hasha10581709b8c51bc370f89015d3943ad
XWorm payload (confidence level: 95%)
hashe0adde054cc93b39d695a183154ff18358c716c6
Luca Stealer payload (confidence level: 95%)
hash780140c1796fee3b8b3be4733f2c25edeaca0ba0018f7ee33ab3bf97b8752d27
Luca Stealer payload (confidence level: 95%)
hashcba007a4e1393227619570ba20a20d3e
Luca Stealer payload (confidence level: 95%)
hash3310817b398cdcee1fa2e8e05847d00ba886962e
GCleaner payload (confidence level: 95%)
hash512b629f01ce1668bcc60ea305e93fb264cf2b7f2f87bb3aafef29beeb604cce
GCleaner payload (confidence level: 95%)
hash4f54221d07efacf249a70b02ee5fd3ed
GCleaner payload (confidence level: 95%)
hash6d702fe228a47e01198fee387a2baecacac706f8
troystealer payload (confidence level: 95%)
hashd5e20fc37dd77dd0360fd32446799978048a2c60e036dbfbf5e671333ebd81f1
troystealer payload (confidence level: 95%)
hashf2b790302bfb0e7f97f36a387eaeb227
troystealer payload (confidence level: 95%)
hash62d8a45bf63671bfba5b3659056c4fe609b1bd07
troystealer payload (confidence level: 95%)
hash3446c814aea4dc67cddefe0629d90a89fce9f754093561ab47aa3e32db3be63c
troystealer payload (confidence level: 95%)
hashde792f45754f684e3591e0e54aea20bc
troystealer payload (confidence level: 95%)
hash307fe35ae8ede9f6846dab4c7bc7aba0a5cc8191
DCRat payload (confidence level: 95%)
hash26fbcc5e8567054c4de9a8514704645e69ffe5eaf91b595d047c90150175c0fa
DCRat payload (confidence level: 95%)
hash45e6c886a0d9e4379a8ea2396ad4d5ae
DCRat payload (confidence level: 95%)
hash7b9a8659abb69e366bae293ff868646682315b47
ValleyRAT payload (confidence level: 95%)
hashdb53b8facfc960e2654dd0d69f34f9a8c8f2d4344addde1d41cf3f84ef83dc5a
ValleyRAT payload (confidence level: 95%)
hash223a287a0b678e96c78dd91c2ad49b7f
ValleyRAT payload (confidence level: 95%)
hash6bc971abefbd5bf5b5b8c2b542a0c6b511a16121
DCRat payload (confidence level: 95%)
hash2d460e887cab8b04d177abcde12caaf3fc92da243a8774b04a46ae77fa0f2891
DCRat payload (confidence level: 95%)
hash25b32c1cf2dfa18426d5836631f7ae80
DCRat payload (confidence level: 95%)
hash4cd5ea09aeeeed828b3615329e100e7bd749fe35
DCRat payload (confidence level: 95%)
hash41cbadacf6d3c6d992783009923ceaca6c2148439fa043a260ab5928b8996f10
DCRat payload (confidence level: 95%)
hash461a8951de7f9c3a534a75364b6d927e
DCRat payload (confidence level: 95%)
hash18a00f067a652d2d54bee92f3aace0b29c918cd6
Stealc payload (confidence level: 95%)
hashd0e31b51c7d4acc0dc409886dc78bd8a416c475fe10adfe1521d200562380148
Stealc payload (confidence level: 95%)
hashe5c2eacf5ac079e2299d04e40863ffd2
Stealc payload (confidence level: 95%)
hashbcfb8b5f2634ee518d391d7dfeafcb4415d0350d
DCRat payload (confidence level: 95%)
hashdac7e634f21237813b6404768ea1915ce233f2fdc68a5a29f8b286045379543a
DCRat payload (confidence level: 95%)
hash243b4833c5acbc26b75e03c637b5368f
DCRat payload (confidence level: 95%)
hash0d06a1ad345ac1fbcacf23447730117f5989bfb6
Coinminer payload (confidence level: 95%)
hash6b9c96d17440e42f88ae48999c0d2dbcc32c6c7b05e253f12c2059125f40175c
Coinminer payload (confidence level: 95%)
hasha6d0b3ea5887015f7816884671bdea22
Coinminer payload (confidence level: 95%)
hashd5460fea25777cdd2da306e80bc1da3ccc413f1f
ValleyRAT payload (confidence level: 95%)
hash8ff7bf8dfda2d9edd97a9793a4cc24970b7ddb6661e545b159dbdaaccd029299
ValleyRAT payload (confidence level: 95%)
hash46a027251f0398e24c4d231fe276face
ValleyRAT payload (confidence level: 95%)
hashc30ecdd93d46f9e1cd73548ccdb0028be77b47c4
DCRat payload (confidence level: 95%)
hash01cf3732fc2dda453bc38f2e3ee9d92d75e15c4559625bd1ffd209516128bf41
DCRat payload (confidence level: 95%)
hash397b043a23c671c37a243fabd9c5d195
DCRat payload (confidence level: 95%)
hash32c6f723f325150d66c745e8b108bf5add4fad0c
DCRat payload (confidence level: 95%)
hashc5168a141c82061514060cda27a45cb8d59be5465974f5e5477b5fd000ee1c29
DCRat payload (confidence level: 95%)
hash2c191e89fee1a7389513f59bb78633e3
DCRat payload (confidence level: 95%)
hashc54060e19a17aac0b5b06487306c3ad3d01c2b27
DCRat payload (confidence level: 95%)
hashc22ffc1b974658f59a252e303a22ea383a888911c8147fbc470c3e8120029fc8
DCRat payload (confidence level: 95%)
hash377477f3a0d8a97a70d1238b15980e43
DCRat payload (confidence level: 95%)
hasha9560c3cf39acef15c730eb88481c891c056817d
XWorm payload (confidence level: 95%)
hashc434a0f3a771bf9bec45d96f45dd26dbd3a49eb5c9021e0a07d329f62ff2ac1e
XWorm payload (confidence level: 95%)
hash00cec42c3a78d6af1b457ab11dba5f75
XWorm payload (confidence level: 95%)
hashafe7dd313d86c684074d764d0729de177b90061b
DCRat payload (confidence level: 95%)
hash2049b554fa0475b934d928927c95dbb42a979ad1e9356f0897ea83533575aec2
DCRat payload (confidence level: 95%)
hash2b99e89063d4a905985f69f8d160a2b6
DCRat payload (confidence level: 95%)
hashd11a5f88dbb8f19fd0e12af7b9a803b6219460e4
NjRAT payload (confidence level: 95%)
hash91c93315b9bbe7f15ea0a21e32e5a7c06a675b2ba53a1b5f01307a9b7060acb2
NjRAT payload (confidence level: 95%)
hash0e8e6d6db8715dd2220107b5c9aa1585
NjRAT payload (confidence level: 95%)
hash4a5117805f5cf6ad879661545a4ec2d6d34273cb
XWorm payload (confidence level: 95%)
hashcc517fde471895786ec1ed2d1c5b192849565d7c6725bcc19579613b8ad2d564
XWorm payload (confidence level: 95%)
hash498606d6a25ffc776d54e59b26a9c3d5
XWorm payload (confidence level: 95%)
hash462dbd5d02542f713a67000d327cc04f52e4f704
DCRat payload (confidence level: 95%)
hash164406a15fdde9b61ff47c268b9853bde4284f854b50975e2ccd648180d1dd97
DCRat payload (confidence level: 95%)
hash57ac1a209a55298720bf050812c1ec40
DCRat payload (confidence level: 95%)
hash468651d386103398b4cdd2c7101e143cb84887a9
ValleyRAT payload (confidence level: 95%)
hashb6d6ff28ef103da5f794d27841f13b790329616cea55b7ec8f181585b5beb638
ValleyRAT payload (confidence level: 95%)
hash3b65f71401b8373be7bd0f43b0e81717
ValleyRAT payload (confidence level: 95%)
hash0db6d6e1074e34b4dbf2954303aa5c77bd571935
Amadey payload (confidence level: 95%)
hash3f7a457324893c033e7c5db5e31cdf188346ed1c8716445745e54e6fe9ff9152
Amadey payload (confidence level: 95%)
hash1f045de1aaef00c26e1c30f05bf70141
Amadey payload (confidence level: 95%)
hasha3ca6db514465da457bf303e36e20720563e2b19
AsyncRAT payload (confidence level: 95%)
hashdfd94151544cfefdfdfc52c9904e295d76d3240b4f6b77728e45096e84da4339
AsyncRAT payload (confidence level: 95%)
hash8341c41df42418a3e60b58aeada9382c
AsyncRAT payload (confidence level: 95%)
hashca30408e1e1556ce101ca7fc705a986905bd11d1
Rhadamanthys payload (confidence level: 95%)
hash3f937a7720a54b3ad3bc117f7d2e3263ed0ac02a4b599068daeba19e1752c239
Rhadamanthys payload (confidence level: 95%)
hash227d4c71233e512e96b9441535d2afcc
Rhadamanthys payload (confidence level: 95%)
hasha58afced8d17763bbd88ddb12c8097bcdb9ac1f5
Rhadamanthys payload (confidence level: 95%)
hash8564679e9d6496c632214d21c8f3357936f5f5fa47226d6f770ad6889bdaf27b
Rhadamanthys payload (confidence level: 95%)
hasheb12568ee795a5602acfc19b0f3efc86
Rhadamanthys payload (confidence level: 95%)
hash351a8752ed0f7fe72601270ff8e539390568ab39
Agent Tesla payload (confidence level: 95%)
hash730ebab239774a3efa19746a887c8ac39c2e17841bbbe38caf07df9e6b82bb47
Agent Tesla payload (confidence level: 95%)
hashb93b16f19cf612cb0e5a85f82c83c2c1
Agent Tesla payload (confidence level: 95%)
hash9abc939f08fd5f8fa62be9465311fec212e9d806
Formbook payload (confidence level: 95%)
hash9ac440eeabd2ebc8e3ca9bdb8588cbb173f3c1c71c4bef922f59f547e4ac70b1
Formbook payload (confidence level: 95%)
hashcdbe4af95f7a48f000691d3a3bbc8fa8
Formbook payload (confidence level: 95%)
hasha536764df1e4fe8c099f0539cd0822f9b96a5cea
Luca Stealer payload (confidence level: 95%)
hashf6f9759e408b5e2329e17e673e60dd8190c9031b073b35b042bc4e10280bfab1
Luca Stealer payload (confidence level: 95%)
hash727797a88b0671783d75f2de94b00afc
Luca Stealer payload (confidence level: 95%)
hash22cffe71cbad5739242df3cea95a982bb22ae61c
Rhadamanthys payload (confidence level: 95%)
hash09774a8fdc58fb31fbd0089b328ada61acee072e9e4137dce49d62544b025535
Rhadamanthys payload (confidence level: 95%)
hash9672ad7032d4deb7550a7e3cbbea1b5c
Rhadamanthys payload (confidence level: 95%)
hash72bc8034e0556cb499539e30af692a79791ae2fa
Vidar payload (confidence level: 95%)
hash4bb04c7fce48557862f9f8b5001e669bafd79cabebc57cef099fab4c4a748efc
Vidar payload (confidence level: 95%)
hash2d35b471ec48644afab19ea81d505b52
Vidar payload (confidence level: 95%)
hash25920
RedLine Stealer botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash14994
Ghost RAT botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash20256
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash5800
XWorm botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash53
ValleyRAT botnet C2 server (confidence level: 100%)
hash9870
XWorm botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash3578
Remcos botnet C2 server (confidence level: 100%)
hash9090
Remcos botnet C2 server (confidence level: 100%)
hash4444
XWorm botnet C2 server (confidence level: 100%)
hash47851
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash8088
ValleyRAT botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash8088
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2005
Remcos botnet C2 server (confidence level: 100%)
hash8080
Ghost RAT botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2565
Remcos botnet C2 server (confidence level: 100%)
hash4504
AsyncRAT botnet C2 server (confidence level: 100%)
hash808
Kaiji botnet C2 server (confidence level: 100%)
hash1199
Rhadamanthys botnet C2 server (confidence level: 100%)
hash8888
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
ValleyRAT botnet C2 server (confidence level: 100%)
hash90
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
ValleyRAT botnet C2 server (confidence level: 100%)
hash81
Cobalt Strike botnet C2 server (confidence level: 75%)
hash5556
Cobalt Strike botnet C2 server (confidence level: 75%)
hash5556
Cobalt Strike botnet C2 server (confidence level: 75%)
hash7777
Cobalt Strike botnet C2 server (confidence level: 100%)
hash1912
RedLine Stealer botnet C2 server (confidence level: 100%)
hash8020
Mirai botnet C2 server (confidence level: 100%)
hash49654
XWorm botnet C2 server (confidence level: 100%)
hash80
Ghost RAT botnet C2 server (confidence level: 100%)
hash54533
Remcos botnet C2 server (confidence level: 100%)
hash5000
Remcos botnet C2 server (confidence level: 100%)
hash80
ShadowPad botnet C2 server (confidence level: 90%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8848
DCRat botnet C2 server (confidence level: 100%)
hash790
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash31022
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash80
BianLian botnet C2 server (confidence level: 100%)
hash49685
Quasar RAT botnet C2 server (confidence level: 100%)
hash22653
XWorm botnet C2 server (confidence level: 100%)
hash33642
XWorm botnet C2 server (confidence level: 100%)
hash1515
XWorm botnet C2 server (confidence level: 100%)
hash8080
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8090
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2396
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8843
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Ghost RAT botnet C2 server (confidence level: 100%)
hash80
Ghost RAT botnet C2 server (confidence level: 100%)
hash2961
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash8888
Sliver botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash80
ShadowPad botnet C2 server (confidence level: 90%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Quasar RAT botnet C2 server (confidence level: 100%)
hash9779
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash80
Nimplant botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash8080
MimiKatz botnet C2 server (confidence level: 100%)
hash80
Empire Downloader botnet C2 server (confidence level: 100%)
hash1337
Empire Downloader botnet C2 server (confidence level: 100%)
hash45434
XWorm botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttp://45.153.34.123
Stealc botnet C2 (confidence level: 100%)
urlhttps://stc.s3.masterclasstonewow.com
Vidar botnet C2 (confidence level: 75%)
urlhttps://plataukz.xin/nbvg
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://tetrwoo.asia/niuo
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://figueqhk.xin/qyvv
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://hffiahz.asia/pppm
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://sprimvd.my/zcbh
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://renohhde.xin/nvhu
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://lithfzx.my/bvcg
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://titlexy.my/bavg
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://stamrbyb.xin/uioa
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttp://gamesarena.gdn/autoconfig/level3sp/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttps://acrislegt.su/tazd
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://averiryvx.su/zadr
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://cerasatvf.su/qtpd
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://consnbx.su/sawo
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://diadtuky.su/texz
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://prebwle.su/xazd
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://rhussois.su/tatr
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://sirhirssg.su/xzde
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://todoexy.su/xqts
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttp://176.65.148.186/ohshit.sh
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://smashaj.qpon/xieq
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://facilin.qpon/asdk
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://t.me/vhutdfghytrd
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://denimmi.qpon/zdk
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttp://knowkeren.xyz/adi/panel/five/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttps://fadoklismokley.com/work/
Latrodectus botnet C2 (confidence level: 75%)
urlhttps://gasrobariokley.com/work/
Latrodectus botnet C2 (confidence level: 75%)

Threat ID: 68be20b5e3f0bafba8aa5d9f

Added to database: 9/8/2025, 12:17:57 AM

Last enriched: 9/8/2025, 12:33:20 AM

Last updated: 9/8/2025, 2:46:12 PM

Views: 13

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats