Skip to main content

ThreatFox IOCs for 2025-09-12

Medium
Published: Fri Sep 12 2025 (09/12/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-09-12

AI-Powered Analysis

AILast updated: 09/13/2025, 00:24:13 UTC

Technical Analysis

The provided information pertains to a set of Indicators of Compromise (IOCs) published on 2025-09-12 by the ThreatFox MISP Feed, categorized under malware with a focus on OSINT (Open Source Intelligence), payload delivery, and network activity. The data lacks specific affected versions or detailed technical indicators, suggesting this is a general intelligence update rather than a detailed vulnerability or exploit report. The threat level is rated as medium with a threatLevel score of 2 and distribution score of 3, indicating moderate dissemination potential. No patches or known exploits in the wild are reported, and no Common Weakness Enumerations (CWEs) are associated, which implies this is not a newly discovered vulnerability but rather intelligence about existing or emerging malware activity patterns. The absence of detailed technical indicators or payload specifics limits the ability to deeply analyze the malware's operational mechanisms, but the focus on payload delivery and network activity suggests the threat involves malware propagation or command and control communications. The TLP (Traffic Light Protocol) white tag indicates the information is publicly shareable without restriction, supporting its use for broad defensive measures. Overall, this threat intelligence update serves as a situational awareness tool for security teams to monitor potential malware-related network activity and prepare defenses accordingly.

Potential Impact

For European organizations, the impact of this threat is primarily related to the potential for malware infections that could disrupt network operations or lead to data exfiltration. Given the medium severity and absence of known exploits, immediate critical impact is unlikely; however, the presence of payload delivery and network activity indicators means organizations could face increased risk of malware infiltration if they do not maintain robust network monitoring and endpoint defenses. The lack of specific affected software versions or exploit details means the threat could be broad and opportunistic, targeting common network services or endpoints. European entities in sectors with high exposure to network-based threats, such as finance, telecommunications, and critical infrastructure, may experience operational disruptions or data confidentiality risks if the malware payloads are successfully delivered and executed. The threat intelligence can help organizations enhance detection capabilities and prepare incident response plans to mitigate potential infections.

Mitigation Recommendations

1. Enhance network monitoring to detect unusual payload delivery attempts and anomalous network activity, leveraging threat intelligence feeds including ThreatFox IOCs. 2. Implement strict egress and ingress filtering to limit unauthorized network communications that could facilitate malware command and control. 3. Employ endpoint detection and response (EDR) solutions capable of identifying and blocking malware payloads based on behavioral analysis rather than relying solely on signature-based detection. 4. Conduct regular threat hunting exercises using the latest OSINT and IOC data to proactively identify potential infections. 5. Maintain up-to-date security awareness training for employees to recognize and report suspicious activities that could lead to malware delivery. 6. Since no patches are available, focus on hardening network and endpoint defenses and applying general best practices for malware prevention and containment. 7. Collaborate with national and European cybersecurity centers to share intelligence and receive timely alerts about emerging threats.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
3afcb6f7-41ed-49db-9443-d5c23b0f0f6a
Original Timestamp
1757721785

Indicators of Compromise

Domain

ValueDescriptionCopy
domaing.kilut4ou8.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpink.kuryc7yy1.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintiny.kuryc7yy1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvast.kuryc7yy1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainneat.kuryc7yy1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainftifiles.work.gd
Unknown malware payload delivery domain (confidence level: 100%)
domaindear.kuryc7yy1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrich.jibiw8aa5.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincute.jibiw8aa5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlean.jibiw8aa5.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintall.jibiw8aa5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwise.jibiw8aa5.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincalm.vudeh0ae3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkeen.vudeh0ae3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzi.we4ex.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqd.fa6eq.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqra.we4ex.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwww.4kdownload.info
Unknown Loader payload delivery domain (confidence level: 90%)
domainwww.gxh191.top
ShadowPad botnet C2 domain (confidence level: 95%)
domainlv.we4ex.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmox.we4ex.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwww.aliyunupdate.shop
Cobalt Strike botnet C2 domain (confidence level: 75%)
domaintne.we4ex.ru
ClearFake payload delivery domain (confidence level: 100%)
domainc4.b1o.it
Unknown malware botnet C2 domain (confidence level: 100%)
domainhome.messager.my
Unknown malware botnet C2 domain (confidence level: 100%)
domainoptisigns.pro
Unknown Loader payload delivery domain (confidence level: 90%)
domaintot.vumarifa.com
Vidar botnet C2 domain (confidence level: 75%)
domaindu.xe3ax.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsn.fhelp.top
Unknown RAT botnet C2 domain (confidence level: 100%)
domainzevsol.top
Unknown RAT botnet C2 domain (confidence level: 100%)
domainhelppqb.top
Unknown RAT botnet C2 domain (confidence level: 100%)
domainkri.xe3ax.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyn.fa6eq.ru
ClearFake payload delivery domain (confidence level: 100%)
domainleauab.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainlepidry.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainquavevd.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainsoyabhn.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaintarakmb.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainenfeepy.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainnerlzi.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainsuctso.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainjackaw.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainrevolxh.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainhoobow.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincommum.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainsetqvax.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainabbeys.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainselfcmi.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainplembo.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincloqfw.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainfamilef.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainpurplde.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainhurdln.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainmanticu.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainrunjhb.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainbouyeit.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainantiaix.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainjargonx.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainbellmnk.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainpoisono.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainmysidak.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainva.xe3ax.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingrewbix.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincaressv.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainprovaiy.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainconvysj.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainlifsnbu.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainclafvom.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainhfteozo.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainnonsazv.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainunknownhk1.duckdns.org
XWorm botnet C2 domain (confidence level: 100%)
domainpne.xe3ax.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstarexs.bet
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainnotebanin.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainnotebanjo.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainnotebanae.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainaeseclink.xyz
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainjoseclink.xyz
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaininweblink.xyz
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainonegodae.icu
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainonegodin.icu
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainlx.ji1im.ru
ClearFake payload delivery domain (confidence level: 100%)
domainme.fo1od.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxal.fo1od.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintr.ji1im.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrq.fo1od.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbti.fo1od.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmv.mo5un.ru
ClearFake payload delivery domain (confidence level: 100%)
domainura.vumarifa.com
Vidar botnet C2 domain (confidence level: 75%)
domaincy.fo1od.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpc.mo5un.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjo.qe3yn.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfunction-assembled.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainhtgeruyukwhyj.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainbigpappa.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainvex.qe3yn.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintht.vumarifa.com
Vidar botnet C2 domain (confidence level: 75%)
domainwebcre8.com
KongTuke payload delivery domain (confidence level: 100%)
domain4revergreen.com
NetSupportManager RAT payload delivery domain (confidence level: 100%)
domainpokelv.com
NetSupportManager RAT payload delivery domain (confidence level: 100%)
domainta.qe3yn.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpru.qe3yn.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhb.wi9ik.ru
ClearFake payload delivery domain (confidence level: 100%)
domainavapmpvegyw0c.cfc-execute.su.baidubce.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainmanageengine.su
Unknown Loader payload delivery domain (confidence level: 90%)
domainprinscibuck.s3.us-east-1.amazonaws.com
Houdini botnet C2 domain (confidence level: 100%)
domainnectixboost.xyz
Houdini botnet C2 domain (confidence level: 100%)
domainnectixboost.org
Houdini botnet C2 domain (confidence level: 100%)
domainsecure.happyhatterreviews.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainnl.qe3yn.ru
ClearFake payload delivery domain (confidence level: 100%)
domainha.bi3ux.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzu.wi9ik.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmri.bi3ux.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqv.bi3ux.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzpa.bi3ux.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkj.by3iq.ru
ClearFake payload delivery domain (confidence level: 100%)
domainl.bi3ux.ru
ClearFake payload delivery domain (confidence level: 100%)
domainan.boku0.ru
ClearFake payload delivery domain (confidence level: 100%)
domainweatherforce.info
Unknown Loader botnet C2 domain (confidence level: 100%)
domainteachingbutter.info
Unknown Loader botnet C2 domain (confidence level: 100%)
domainwo.by3iq.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwebdisk.umathurman.org
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domaintitan.tail922ba4.ts.net
Havoc botnet C2 domain (confidence level: 100%)
domainupdater-internal.mooo.com
Havoc botnet C2 domain (confidence level: 100%)
domainnews.heix-energietechnik.com
Havoc botnet C2 domain (confidence level: 100%)
domainwww.lastsentinelflock.org
Venom RAT botnet C2 domain (confidence level: 100%)
domaindo.boku-0.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingo.boku-0.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhe.boku-0.ru
ClearFake payload delivery domain (confidence level: 100%)
domain1308344827-4bya137jfj.ap-guangzhou.tencentscf.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainmasmbv.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainrepzzm.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainfladiw.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainbucrew.asia
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainntv.vumarifa.com
Vidar botnet C2 domain (confidence level: 75%)
domainshiporitoy.sbs
Rhadamanthys botnet C2 domain (confidence level: 100%)
domainshiteafirs.live
Rhadamanthys botnet C2 domain (confidence level: 100%)
domainshiteathre.sbs
Rhadamanthys botnet C2 domain (confidence level: 100%)
domainshiteatwop.sbs
Rhadamanthys botnet C2 domain (confidence level: 100%)
domainqsetshi.live
Rhadamanthys botnet C2 domain (confidence level: 100%)
domainshiwa.sbs
Rhadamanthys botnet C2 domain (confidence level: 100%)
domainas.ty1un.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyassinea2-47754.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainxml-suggestions.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainyassinea-24570.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainmicroupdater.ignorelist.com
Havoc botnet C2 domain (confidence level: 100%)
domainmd.cykugeu.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingo.fe1it.ru
ClearFake payload delivery domain (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://realty.yourpgcountyliving.com/pixel.png
FAKEUPDATES botnet C2 (confidence level: 100%)
urlhttp://47.99.193.179:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://8.138.155.217:18888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://suctso.asia/xoza
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://leauab.asia/xakd
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://t.me/romalabs4
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://tot.vumarifa.com
Vidar botnet C2 (confidence level: 75%)
urlhttps://195.201.45.150
Vidar botnet C2 (confidence level: 75%)
urlhttp://91.208.197.196/ohshit.sh
Unknown malware payload delivery URL (confidence level: 75%)
urlhttp://413426cm.nyash.es/protectflowerdownloads.php
DCRat botnet C2 (confidence level: 100%)
urlhttp://47.238.239.22:443/aira
Cobalt Strike botnet C2 (confidence level: 75%)
urlhttps://ura.vumarifa.com
Vidar botnet C2 (confidence level: 75%)
urlhttps://tht.vumarifa.com
Vidar botnet C2 (confidence level: 75%)
urlhttps://webcre8.com/4r3w.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://webcre8.com/js.php
KongTuke payload delivery URL (confidence level: 100%)
urlhttp://144.31.221.88:6060/capcha9856
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://4revergreen.com/ajax/pixi.min.js
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://pokelv.com/res/partygardencapital
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttp://213.209.150.141/club/view.php
Unknown Loader botnet C2 (confidence level: 100%)
urlhttps://catalogcomx.s3.us-east-1.amazonaws.com/catalogcom.txt
Houdini payload delivery URL (confidence level: 100%)
urlhttps://secure.happyhatterreviews.com/pixel.png
FAKEUPDATES botnet C2 (confidence level: 100%)
urlhttps://185.141.216.172/gateway/o4obvot8.h7its
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttp://2.58.56.54:1888/gateway/fm5xroun.0zrtw
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttp://77.90.153.225/c9d95c9f4c224c36.php
Stealc botnet C2 (confidence level: 100%)
urlhttp://176.46.152.46/281ef81f2444fb93.php
Stealc botnet C2 (confidence level: 100%)
urlhttp://45.153.34.123/b0481cf5ba1844ec.php
Stealc botnet C2 (confidence level: 100%)
urlhttp://91.196.32.97/8a9c48a5e99a4eac.php
Stealc botnet C2 (confidence level: 100%)
urlhttp://toxwebapp.com/c1c44617e43e556b.php
Stealc botnet C2 (confidence level: 100%)
urlhttp://143.92.39.31/97dbb8f0394943c6.php
Stealc botnet C2 (confidence level: 100%)
urlhttp://96.9.125.98/cef01016566d4884.php
Stealc botnet C2 (confidence level: 100%)
urlhttp://206.123.145.165/a2d7fe84a0c94fc1.php
Stealc botnet C2 (confidence level: 100%)
urlhttp://172.236.192.27/c58d03b5de424a3f.php
Stealc botnet C2 (confidence level: 100%)
urlhttps://repzzm.asia/takz
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://ntv.vumarifa.com
Vidar botnet C2 (confidence level: 75%)
urlhttp://139.59.4.189/gateway/36hnkwg1.2kkq9
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://103.146.119.92/gateway/gm4qvawu.l2o2o
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://194.33.61.182/gateway/17culsk6.cf2hn
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://194.33.61.162/gateway/gqmrbp7r.q76cs
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttp://194.55.137.30/gateway/calh79rb.cjjfi
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttp://45.156.87.246/gateway/lxl1puu6.gj9bk
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://shiwa.sbs/gateway/uv3akw97.t5rel
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://shiporitoy.sbs/gateway/uv3akw97.t5rel
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://shiteafirs.live/gateway/uv3akw97.t5rel
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://shiteathre.sbs/gateway/uv3akw97.t5rel
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://shiteatwop.sbs/gateway/uv3akw97.t5rel
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttp://185.141.216.120:1888/gateway/ugb6ewgu.skyru
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttp://94.154.35.99:1888/gateway/ugb6ewgu.skyru
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://94.154.35.99:1888/gateway/ugb6ewgu.skyru
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttp://193.233.126.173/gateway/j2ipitfi.g7skm
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://193.233.126.173/gateway/j2ipitfi.g7skm
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://87.120.107.181/gateway/ou0gkk7n.p14tw
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://185.196.9.64/gateway/wu25gfoo.sc9q4
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://vsmoznicuj.te/gateway/araxd4kd.hakt5
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttps://37.221.66.174/gateway/araxd4kd.hakt5
Rhadamanthys botnet C2 (confidence level: 100%)
urlhttp://romcablu.com/s/luck/k.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttp://pakarabi.net/loki/panel/five/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)

File

ValueDescriptionCopy
file157.254.167.144
FAKEUPDATES botnet C2 server (confidence level: 100%)
file124.221.237.102
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.66.11.61
Remcos botnet C2 server (confidence level: 100%)
file216.144.226.242
Unknown malware botnet C2 server (confidence level: 100%)
file207.154.205.11
Unknown malware botnet C2 server (confidence level: 100%)
file31.129.42.36
Havoc botnet C2 server (confidence level: 100%)
file103.20.102.130
DCRat botnet C2 server (confidence level: 100%)
file185.221.215.43
DCRat botnet C2 server (confidence level: 100%)
file46.246.84.12
DCRat botnet C2 server (confidence level: 100%)
file46.246.84.12
DCRat botnet C2 server (confidence level: 100%)
file8.141.112.241
Chaos botnet C2 server (confidence level: 100%)
file18.199.40.209
Chaos botnet C2 server (confidence level: 100%)
file111.119.222.152
Cobalt Strike botnet C2 server (confidence level: 50%)
file190.102.43.29
Cobalt Strike botnet C2 server (confidence level: 50%)
file56.155.31.116
Meterpreter botnet C2 server (confidence level: 50%)
file15.206.158.46
Meterpreter botnet C2 server (confidence level: 50%)
file18.162.133.33
Meterpreter botnet C2 server (confidence level: 50%)
file34.234.90.240
Meterpreter botnet C2 server (confidence level: 50%)
file13.212.88.229
Meterpreter botnet C2 server (confidence level: 50%)
file13.212.88.229
Meterpreter botnet C2 server (confidence level: 50%)
file13.212.88.229
Meterpreter botnet C2 server (confidence level: 50%)
file111.230.164.244
Cobalt Strike botnet C2 server (confidence level: 75%)
file111.230.164.244
Cobalt Strike botnet C2 server (confidence level: 75%)
file111.230.164.244
Cobalt Strike botnet C2 server (confidence level: 75%)
file111.230.164.244
Cobalt Strike botnet C2 server (confidence level: 75%)
file179.43.186.228
Unknown malware botnet C2 server (confidence level: 100%)
file8.217.237.58
Unknown malware botnet C2 server (confidence level: 100%)
file65.109.89.93
Unknown malware botnet C2 server (confidence level: 100%)
file34.248.206.212
Havoc botnet C2 server (confidence level: 100%)
file46.246.84.12
DCRat botnet C2 server (confidence level: 100%)
file64.225.31.235
Unknown malware botnet C2 server (confidence level: 100%)
file49.235.210.241
Unknown malware botnet C2 server (confidence level: 100%)
file45.55.44.12
Unknown malware botnet C2 server (confidence level: 100%)
file106.14.57.121
Unknown malware botnet C2 server (confidence level: 100%)
file4.233.99.180
Unknown malware botnet C2 server (confidence level: 100%)
file34.229.168.99
Unknown malware botnet C2 server (confidence level: 100%)
file157.245.153.253
Unknown malware botnet C2 server (confidence level: 100%)
file43.138.227.137
Unknown malware botnet C2 server (confidence level: 100%)
file16.171.169.63
Unknown malware botnet C2 server (confidence level: 100%)
file54.164.119.65
Unknown malware botnet C2 server (confidence level: 100%)
file34.238.41.13
Unknown malware botnet C2 server (confidence level: 100%)
file103.197.188.41
Unknown malware botnet C2 server (confidence level: 100%)
file103.197.188.41
Unknown malware botnet C2 server (confidence level: 100%)
file42.193.131.128
Unknown malware botnet C2 server (confidence level: 100%)
file54.227.13.175
Unknown malware botnet C2 server (confidence level: 100%)
file151.80.206.100
Unknown malware botnet C2 server (confidence level: 100%)
file95.163.249.222
Unknown malware botnet C2 server (confidence level: 100%)
file188.34.197.140
Unknown malware botnet C2 server (confidence level: 100%)
file52.64.27.164
Unknown malware botnet C2 server (confidence level: 100%)
file192.142.10.27
Remcos botnet C2 server (confidence level: 100%)
file185.236.20.7
Remcos botnet C2 server (confidence level: 100%)
file196.251.115.25
Remcos botnet C2 server (confidence level: 100%)
file196.251.118.247
Remcos botnet C2 server (confidence level: 100%)
file170.187.138.168
SectopRAT botnet C2 server (confidence level: 100%)
file185.241.208.84
Remcos botnet C2 server (confidence level: 100%)
file147.124.223.75
Remcos botnet C2 server (confidence level: 100%)
file87.120.93.155
Aurotun Stealer botnet C2 server (confidence level: 100%)
file103.83.87.230
Remcos botnet C2 server (confidence level: 75%)
file36.137.134.42
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.138.14.158
Cobalt Strike botnet C2 server (confidence level: 100%)
file121.41.167.80
Cobalt Strike botnet C2 server (confidence level: 100%)
file39.97.35.139
Cobalt Strike botnet C2 server (confidence level: 100%)
file39.100.64.195
Cobalt Strike botnet C2 server (confidence level: 100%)
file124.221.237.102
Cobalt Strike botnet C2 server (confidence level: 100%)
file157.20.182.24
PureRAT botnet C2 server (confidence level: 88%)
file156.254.21.126
XWorm botnet C2 server (confidence level: 100%)
file103.83.87.230
Remcos botnet C2 server (confidence level: 75%)
file148.135.195.121
Cobalt Strike botnet C2 server (confidence level: 100%)
file1.95.138.3
Cobalt Strike botnet C2 server (confidence level: 100%)
file158.94.208.23
Latrodectus botnet C2 server (confidence level: 100%)
file154.3.40.26
Remcos botnet C2 server (confidence level: 100%)
file80.64.19.129
SectopRAT botnet C2 server (confidence level: 100%)
file77.8.235.68
Unknown malware botnet C2 server (confidence level: 100%)
file196.251.115.237
Venom RAT botnet C2 server (confidence level: 100%)
file3.230.13.26
Nimplant botnet C2 server (confidence level: 100%)
file150.40.118.19
PureLogs Stealer botnet C2 server (confidence level: 100%)
file109.104.153.203
Lumma Stealer botnet C2 server (confidence level: 100%)
file116.26.11.245
DeimosC2 botnet C2 server (confidence level: 75%)
file154.214.53.58
DeimosC2 botnet C2 server (confidence level: 75%)
file20.206.138.78
Sliver botnet C2 server (confidence level: 75%)
file23.92.29.169
Sliver botnet C2 server (confidence level: 75%)
file5.8.71.125
Cobalt Strike botnet C2 server (confidence level: 75%)
file45.192.201.68
Cobalt Strike botnet C2 server (confidence level: 75%)
file111.229.118.48
Cobalt Strike botnet C2 server (confidence level: 75%)
file148.135.18.161
Cobalt Strike botnet C2 server (confidence level: 75%)
file87.120.219.241
XWorm botnet C2 server (confidence level: 100%)
file147.185.221.29
XWorm botnet C2 server (confidence level: 100%)
file96.126.191.167
XWorm botnet C2 server (confidence level: 100%)
file216.9.225.28
Remcos botnet C2 server (confidence level: 100%)
file194.195.208.43
Sliver botnet C2 server (confidence level: 100%)
file50.114.203.169
AsyncRAT botnet C2 server (confidence level: 100%)
file3.123.17.149
Havoc botnet C2 server (confidence level: 100%)
file104.194.154.39
DCRat botnet C2 server (confidence level: 100%)
file3.145.71.121
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file3.145.71.121
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file176.65.149.34
Mirai botnet C2 server (confidence level: 100%)
file185.208.159.52
Houdini botnet C2 server (confidence level: 100%)
file5.144.176.117
AsyncRAT botnet C2 server (confidence level: 100%)
file178.17.57.60
Meterpreter botnet C2 server (confidence level: 75%)
file51.81.161.229
FAKEUPDATES botnet C2 server (confidence level: 100%)
file79.174.12.88
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.137.147.224
Cobalt Strike botnet C2 server (confidence level: 100%)
file196.251.83.83
Remcos botnet C2 server (confidence level: 100%)
file162.33.179.12
pupy botnet C2 server (confidence level: 100%)
file82.77.149.125
Unknown malware botnet C2 server (confidence level: 100%)
file195.10.205.181
Hook botnet C2 server (confidence level: 100%)
file88.116.203.218
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file185.141.216.120
Rhadamanthys botnet C2 server (confidence level: 100%)
file2.58.56.54
Rhadamanthys botnet C2 server (confidence level: 100%)
file193.161.193.99
XWorm botnet C2 server (confidence level: 100%)
file147.185.221.31
XWorm botnet C2 server (confidence level: 100%)
file94.154.35.99
Rhadamanthys botnet C2 server (confidence level: 100%)
file47.242.120.79
ValleyRAT botnet C2 server (confidence level: 100%)
file94.74.164.157
Rhadamanthys botnet C2 server (confidence level: 100%)
file82.24.40.24
XWorm botnet C2 server (confidence level: 100%)
file45.91.193.160
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.218.112.112
Cobalt Strike botnet C2 server (confidence level: 100%)
file39.97.33.55
Cobalt Strike botnet C2 server (confidence level: 100%)
file144.172.112.78
Cobalt Strike botnet C2 server (confidence level: 100%)
file158.94.208.24
Latrodectus botnet C2 server (confidence level: 100%)
file107.172.132.42
Remcos botnet C2 server (confidence level: 100%)
file157.20.32.137
Remcos botnet C2 server (confidence level: 100%)
file158.94.209.241
Remcos botnet C2 server (confidence level: 100%)
file198.55.102.44
Remcos botnet C2 server (confidence level: 100%)
file149.28.70.98
pupy botnet C2 server (confidence level: 100%)
file72.14.190.211
Sliver botnet C2 server (confidence level: 100%)
file82.77.149.118
Unknown malware botnet C2 server (confidence level: 100%)
file82.77.149.113
Unknown malware botnet C2 server (confidence level: 100%)
file82.77.149.124
Unknown malware botnet C2 server (confidence level: 100%)
file62.72.22.223
Unknown malware botnet C2 server (confidence level: 100%)
file195.10.205.181
Hook botnet C2 server (confidence level: 100%)
file149.28.157.225
Havoc botnet C2 server (confidence level: 100%)
file45.197.133.28
Havoc botnet C2 server (confidence level: 100%)
file93.198.183.133
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file196.251.80.67
Bashlite botnet C2 server (confidence level: 100%)
file213.199.53.152
AdaptixC2 botnet C2 server (confidence level: 100%)
file185.196.117.168
Cobalt Strike botnet C2 server (confidence level: 100%)
file116.31.165.28
DeimosC2 botnet C2 server (confidence level: 75%)
file121.12.126.37
DeimosC2 botnet C2 server (confidence level: 75%)
file148.178.73.114
DeimosC2 botnet C2 server (confidence level: 75%)
file85.233.75.107
DeimosC2 botnet C2 server (confidence level: 75%)
file146.19.128.190
Meterpreter botnet C2 server (confidence level: 75%)
file8.213.237.239
Cobalt Strike botnet C2 server (confidence level: 75%)
file92.221.243.132
Meterpreter botnet C2 server (confidence level: 75%)
file154.91.66.235
ValleyRAT botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash443
FAKEUPDATES botnet C2 server (confidence level: 100%)
hash8082
Cobalt Strike botnet C2 server (confidence level: 100%)
hash56101
Remcos botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash8848
DCRat botnet C2 server (confidence level: 100%)
hash7777
DCRat botnet C2 server (confidence level: 100%)
hash1963
DCRat botnet C2 server (confidence level: 100%)
hash3000
DCRat botnet C2 server (confidence level: 100%)
hash47486
Chaos botnet C2 server (confidence level: 100%)
hash54681
Chaos botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 50%)
hash11101
Meterpreter botnet C2 server (confidence level: 50%)
hash44818
Meterpreter botnet C2 server (confidence level: 50%)
hash28245
Meterpreter botnet C2 server (confidence level: 50%)
hash57722
Meterpreter botnet C2 server (confidence level: 50%)
hash4592
Meterpreter botnet C2 server (confidence level: 50%)
hash9142
Meterpreter botnet C2 server (confidence level: 50%)
hash4242
Meterpreter botnet C2 server (confidence level: 50%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash4000
DCRat botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash17777
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash17777
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash13333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash7000
Remcos botnet C2 server (confidence level: 100%)
hash40482
Remcos botnet C2 server (confidence level: 100%)
hash5000
Remcos botnet C2 server (confidence level: 100%)
hash6002
Remcos botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash7374
Remcos botnet C2 server (confidence level: 100%)
hash62404
Remcos botnet C2 server (confidence level: 100%)
hash7712
Aurotun Stealer botnet C2 server (confidence level: 100%)
hash8091
Remcos botnet C2 server (confidence level: 75%)
hash5555
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9999
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8081
Cobalt Strike botnet C2 server (confidence level: 100%)
hash1976
PureRAT botnet C2 server (confidence level: 88%)
hash443
XWorm botnet C2 server (confidence level: 100%)
hash9180
Remcos botnet C2 server (confidence level: 75%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8091
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash6009
Venom RAT botnet C2 server (confidence level: 100%)
hash443
Nimplant botnet C2 server (confidence level: 100%)
hash5888
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash443
Lumma Stealer botnet C2 server (confidence level: 100%)
hash36153
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash8080
Sliver botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash8110
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8030
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash1443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash1337
XWorm botnet C2 server (confidence level: 100%)
hash6000
XWorm botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash2125
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
Havoc botnet C2 server (confidence level: 100%)
hash6000
DCRat botnet C2 server (confidence level: 100%)
hash808
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash8008
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash81
Mirai botnet C2 server (confidence level: 100%)
hash9090
Houdini botnet C2 server (confidence level: 100%)
hash1341bdc1465fdec9d644c23affc85c9a3483e3adaa92739760e920ff7e7cb230
Houdini payload (confidence level: 100%)
hash77f54192232041a16afdc1fac62c2dcf063cd35c6bf4eece9bb214726710f9a8
Unknown Stealer payload (confidence level: 100%)
hash6707
AsyncRAT botnet C2 server (confidence level: 100%)
hash8443
Meterpreter botnet C2 server (confidence level: 75%)
hash443
FAKEUPDATES botnet C2 server (confidence level: 100%)
hash8058
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash5000
Remcos botnet C2 server (confidence level: 100%)
hash8443
pupy botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash5500
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash1888
Rhadamanthys botnet C2 server (confidence level: 100%)
hash1888
Rhadamanthys botnet C2 server (confidence level: 100%)
hash47754
XWorm botnet C2 server (confidence level: 100%)
hash52336
XWorm botnet C2 server (confidence level: 100%)
hash1888
Rhadamanthys botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash8888
Rhadamanthys botnet C2 server (confidence level: 100%)
hash5000
XWorm botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8082
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash5902
Remcos botnet C2 server (confidence level: 100%)
hash14650
Remcos botnet C2 server (confidence level: 100%)
hash443
pupy botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash81
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash23
Bashlite botnet C2 server (confidence level: 100%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash36037
DeimosC2 botnet C2 server (confidence level: 75%)
hash10250
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash1720
DeimosC2 botnet C2 server (confidence level: 75%)
hash8888
Meterpreter botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Meterpreter botnet C2 server (confidence level: 75%)
hash9000
ValleyRAT botnet C2 server (confidence level: 100%)

Threat ID: 68c4b61a6da8ad0abf37a4ba

Added to database: 9/13/2025, 12:08:58 AM

Last enriched: 9/13/2025, 12:24:13 AM

Last updated: 9/13/2025, 2:23:58 AM

Views: 2

Actions

PRO

Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats