ThreatFox IOCs for 2025-10-04
ThreatFox IOCs for 2025-10-04
AI Analysis
Technical Summary
The provided information relates to a set of Indicators of Compromise (IOCs) published on 2025-10-04 by the ThreatFox MISP Feed, categorized under malware with a focus on OSINT (Open Source Intelligence), network activity, and payload delivery. The data appears to be a collection of threat intelligence indicators rather than a description of a specific malware variant or exploit. No affected software versions are listed, no patches are available, and there are no known exploits in the wild associated with these IOCs. The threat level is indicated as medium (threatLevel: 2), with moderate distribution (distribution: 3) and minimal analysis (analysis: 1). The absence of concrete technical details such as attack vectors, payload specifics, or exploitation methods limits the depth of technical assessment. The IOCs are intended for use in threat detection and network defense, providing actionable intelligence to identify potential malicious activity related to payload delivery mechanisms. The TLP (Traffic Light Protocol) is white, indicating the information is publicly shareable without restriction. Overall, this entry represents a threat intelligence update rather than a direct vulnerability or active exploit, serving primarily as an OSINT resource for security teams to enhance situational awareness and detection capabilities.
Potential Impact
For European organizations, the impact of these IOCs depends largely on their integration into security monitoring and incident response workflows. Since the data pertains to indicators rather than an active exploit or vulnerability, the immediate risk is low to medium. However, failure to incorporate such intelligence could result in delayed detection of malware infections or network intrusions that use the identified payload delivery methods. Organizations with mature security operations centers (SOCs) and threat hunting capabilities can leverage these IOCs to improve detection accuracy and reduce dwell time of threats. Conversely, entities lacking such capabilities may not benefit fully, potentially increasing exposure to malware campaigns that utilize similar tactics. The absence of known exploits in the wild suggests no immediate widespread threat, but the presence of network activity and payload delivery tags indicates a potential for future exploitation attempts. European organizations in critical infrastructure, finance, and government sectors should be particularly vigilant, as these sectors are frequent targets for malware campaigns leveraging OSINT-derived indicators.
Mitigation Recommendations
To effectively mitigate risks associated with these IOCs, European organizations should: 1) Integrate the ThreatFox IOCs into existing Security Information and Event Management (SIEM) systems and Endpoint Detection and Response (EDR) tools to enable automated detection and alerting on related network activity and payload delivery attempts. 2) Conduct regular threat hunting exercises using these IOCs to proactively identify signs of compromise or suspicious behavior within the network. 3) Update firewall and intrusion detection/prevention system (IDS/IPS) signatures to recognize and block traffic patterns or payloads matching the indicators. 4) Enhance employee awareness and training on phishing and social engineering tactics that may be used to deliver payloads associated with these IOCs. 5) Maintain robust network segmentation and least privilege access controls to limit the lateral movement of malware if an infection occurs. 6) Collaborate with national and European cybersecurity information sharing organizations to stay updated on evolving threats and incorporate additional intelligence feeds. These steps go beyond generic advice by emphasizing the operationalization of threat intelligence and proactive defense measures tailored to the nature of the IOCs.
Affected Countries
Germany, France, United Kingdom, Netherlands, Italy, Spain, Poland
Indicators of Compromise
- domain: cdn-googlemanager.com
- domain: nmn.is
- domain: anl.is
- domain: snf.is
- domain: kof.one
- url: http://193.233.113.101:1111/login
- file: 193.233.113.101
- hash: 1111
- file: 124.198.132.91
- hash: 4444
- file: 107.172.132.45
- hash: 14646
- file: 172.111.131.113
- hash: 1771
- file: 209.74.72.239
- hash: 8443
- file: 54.93.126.183
- hash: 80
- file: 88.175.164.206
- hash: 49152
- file: 45.133.180.154
- hash: 4000
- file: 46.173.214.158
- hash: 8888
- file: 45.192.99.218
- hash: 80
- url: https://oriolep.pics/api
- domain: ko.nxno-7.ru
- domain: qz9.c-01e.ru
- hash: b258d37fe91f0bf078abeaefbc584cd7a08b9f09
- hash: ca10f8af17c49cb7a659badd06b529b816c59d7d6f4e1f9ec23c173fc56588ec
- hash: 86c1f5cbb41a3db91fb331bf6fee1e61
- hash: 06edc864b7c95188a07e8b9589eeaa24a9b8c0f6
- hash: a32a4ef40c949b6247cf9a0a43546d8e4e5040195db8e8157fe9f884a79e4e9e
- hash: 972899fe1db55b0efeafdfa6abed3dcf
- hash: c596ce51ebcadd3d9dab88c2d4ce49e83273350b
- hash: 8697e36a4cb7810976c72d5890abeede56a664ab741fe24c755f3648fb5f9124
- hash: b6480c04dd858a0e1596ea34180c31a5
- hash: 885ac21b684ab520b2615aef9c78b4c01844ce9f
- hash: ebc963782a30a3e6cc360a6e4fda16d2acac2de13ee0d8db863082e699dabd5a
- hash: 98a29f93295ba4d70fb0e766b1fb0572
- hash: 2d93ef9e2dde680e2834a3a9a5211c1448943d6a
- hash: 8537f934654bf1ade223878e12b62d051641dfeb47db4609b48ca819bdf10311
- hash: 241ce23db564beb28001b0c202123d8d
- hash: e7ebbca6178a27fb7c316266810b0c777fc65bdb
- hash: 3532fe525d339585e0aeeecbe2b55593e3732367ae57917513e8e5645b6854ed
- hash: 428518352a11081287f6f35a2bc661f6
- hash: 5d8b0e8e49d840b525d9e9c0041467977574fda9
- hash: 567eceb1456164eace7d2e0d15ce2deed8c41ec6279213a54174a97ba92802af
- hash: c60742616fe6341c41f9e13cb6c7d77c
- hash: 9de78184ae7742ce7d7ceb78b50340e38295eb82
- hash: 7c4072f5ae6fdf61d9f6d051a5bad41290e6e66e5a564110ec97a256fd4980b4
- hash: 65dd5102f8648aa303711d62cec6bc9a
- hash: 1331be65e2cb9f29810ac0c94605e0a069d4bb39
- hash: 25e89fe9b7a662bd7d2b4e4632c27877911daf32a05748423c3a82fbf9b6d787
- hash: 0dcb8b2dfd1f769eecb77dabcb47eb14
- hash: 8256464c3b152d7dd4a029e3371bfc95ef3ed163
- hash: 53103a831d128565133ffcd807c8aedf011367c6fb261914b5d9bed0f7382548
- hash: 0f764e2f9b54779e3bf7c3188918a2b2
- hash: 4f2df81df59fdc9ccef57aea4260f87441897a64
- hash: 0443e508c14630fca81d33c7a33555a32cc35226ebd95d10e361a22fa3beed2a
- hash: a8485008ab3c7606347c716ad0ff1afd
- hash: 557662626b8487db282c18ecdf0796b6ab24f0e9
- hash: 1285169abae30ba3d353644ed90ded5d7fe5ea119a027e8eee1aeb8511c13f06
- hash: e85ff3c8b17db2e64ca3f8b9435524c7
- hash: 19302a1262a88b306877456441fcc867eb472028
- hash: 72a869c753d3b44377b388fd12b9ba6b8345082b95db87104a218c0f92e1a978
- hash: 097631100aadc521a627f2d45ac49cb0
- hash: 21320e570f916203769e48ce3dfd753099b5ee30
- hash: bd9e7304d6154d73f77961403e3ef8596c68ab574517d1e78632ca747a0c6297
- hash: b88d42502f8415582cf02cacf9f48c98
- hash: be681c884db8a0ce0ca338554a937a76de605806
- hash: 86caabaf24738f1b63c93a374e0894b6ab36cf4f13595e5f8f2d693f168ac159
- hash: aead2b5876f531cd4df9dd1b9eb31d9e
- hash: f5558495e99af20dd4157966abba6ad24dc57c46
- hash: 9a577c544360db41918b2d1890ae1abf2407e734f77d307ef8828a151d8252d4
- hash: 3d5baa12dd0879f1f941125a32b51e0c
- hash: d93475096b39569d5721719ae4dea75f25de9e28
- hash: 5376f3fdc59befa0e3af575beb1ca43180a9edceae0a26eba338aa2b1ca37953
- hash: d72666dbb09fc973c2648a1f3699382f
- hash: feeb19126eb47fb0679b8fc95f6cabeefdea4c81
- hash: bd883a6075228d89b0c201880e1feafe73784e964720d027455e1702be6bba7c
- hash: e5e02db5a57dc49eac87c8474b83fb80
- hash: 3fa28e125ed1dfca4b3eb8daf0ebc8dd1988a2c4
- hash: 4123bedccc18eee83aa4c7d8e1b64191ddde5fc234bd3c1cbd7f998571e47112
- hash: 7daa0cbb2947346c2b8b44da29827b5a
- hash: 8ca33f8f3097d3c3d8d005c0f0060ea9606f93a7
- hash: 4206c4ded33b3137cb67d2013deb8c6d78b4a55fd16d9930904ad548d8802c19
- hash: c9f0f5c54927915dfa5be5898e7afde0
- hash: c5b9cf0275373689f2d3dd4613e82a328d5a798d
- hash: 703af985b3787f140971cccc1cfe86ed8af40a9ba9e05ab0e7e2d67ac97a79b7
- hash: 5d19a82a858cd4553f2b12abe2ee814b
- hash: c67a6a8ceb95b1d0ebe50a163bebc888b1c81dea
- hash: fcea10e54c5fc8f3cdb564bed30acf6afa46eeeede717c13b95b3e8ad7814075
- hash: 7829f99381234edea37c75995ac44551
- hash: 8688cfc123234b8abf9d41e83ca869f31df5854b
- hash: 266225722a9a978e56e824d28bd7c8908c1d95326f65d3908e2e1a8c83672f67
- hash: 03026e78fd4616c8bb6a2847c957ce0d
- hash: e398ac732ce7e89bb104b2edf9f3722a28e38dbf
- hash: 0147a292eabd1a7ae1be2bfbf0376e75e79a15111c95f2eb5cfcc50a8ae1922f
- hash: 51744370f289d940c1d51ac8ed235a37
- hash: 5fee88f41e7440dfccf0c3564f37ca586a563e7e
- hash: 08d496c06e3656f8923211d5bc5cfa001179409169674dcee32373879901d9b5
- hash: 58a9ca4eca8ebb8d5ed45fd3f7638e34
- hash: c5c54edff15b70af20bb8464640db799a57a0d80
- hash: 5654aa9cb45d8fbdd37d400357b57ec96c0865d62b2698fe6c317ad6448b17d4
- hash: ae54148a1344747c1d0acdf22d1cd71f
- hash: 7894100f080b62098a9206e64d24ea3e91b92748
- hash: cb464455cbb783df8da5d7e1cee51cde3b42f5cd1c4c5cb6559aa56cbb1007fe
- hash: 269bb75dbbaa3feaa4bdc4c895acfdaa
- hash: d04a50323d45d0c7eb3def56fcbfa00669855465
- hash: c793a3aa1211f65a43658ad4dac17f25dbbd1035f54bb44e366871fbfefca74f
- hash: edc388f738f38d8901db005bfbe13338
- hash: 697382ed9a10c708dfc3a314285839434e1ce453
- hash: c376028af619aec083e473b00abf62fe6be3bb60d081b6479982388ee1664008
- hash: f6b9d0e2906097dbc626997e6ddfc68b
- hash: 00f15663add14c17d37b9973ddca84d9c1edb2f8
- hash: 6ac3a2007fbcf5ba7cac6208a74c67c0aa16651109b4fd971a4f23742f3bf2ad
- hash: 3983464bf4b5ab81574d7a56a3ed79d2
- hash: 0280e4fc1b285d4614c37615faf7a5792144b4fe
- hash: b87932a6ec2499d7d36ca764a64e5b38a209d1bb97346ef65226082db6830194
- hash: 81d348e269973aa9d46fdc3651b01245
- hash: dc7fa2955f5ac6d81f2d9619ad4b268d4136bd3c
- hash: 1b2a2c0a20f38ab07813d01f49c8e57f3c4c514a59571d7c60bf9952085ea43a
- hash: 3c56e449a4423c77d528bfc41560bd87
- hash: 3ccbba0d6c4060de32646505ae1baeaedadfce88
- hash: 0368450303b2da9adaa02276d18fcfc46616f17b773c8c487d4b02a0f7dc5bb7
- hash: 36b04539ba991e1fe77c2d03b866c5e0
- hash: 410a1c5fa50e33fc4d39ae3219a608cef5258a7c
- hash: f4a2ff30755f15ff9c9e1ea5fdabd00f3c2755bb9d28829390833b07fc1cdce1
- hash: cc6f7e44970b582bdb7d8c03aeb7aab5
- hash: 143f1ce5c907aacd9736871f73c2631e00d62498
- hash: e45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e
- hash: 1dd3800afc130f58d1795cd845e120d9
- hash: 3501fba08b5fb390fa6fef0401f637c32b2148a5
- hash: 35609862a6c28f3fa0e24dfc564dd3515c539cd1f8387de051055abbaef90ff5
- hash: 3d93088de48469a4491ad6d87cf2c360
- hash: 480327c278995074240e7ffc29d50a5cd2a73f6c
- hash: e97233f6c7b7497a0fe4d6a916dde92ade0cc0f92d73e424af88b0bd855b23db
- hash: 3f7841733addbcb2c9ce682c97e6ae6c
- hash: 9c83124088df8b65abe05fd560abd761ebae42b9
- hash: 41e4dd0218aed625e7883bd3dbe43a95796360bda2e2b7fcf020af9fe5e1f1dc
- hash: 99260f7647b97c22974702b600e79c89
- hash: d69e24632c04501d628bd99724a06c5310c498b7
- hash: 386e075c4b38ed2f8a1288d41f3d3508ff84337a0f9507c51f46ad01eb0c1613
- hash: 6d625bf33b348fe4ef8a7a14f1cc52b2
- hash: cfd47e1aebcf6beea8c4fae741543f1d3ea6ccc1
- hash: 0015911fab4e4cedd52c9fca15fc8556407bb92b23673dd4463e95f766c7349a
- hash: 9323f7a482830e191c832f174865dfbf
- hash: e773e7a4289a8ee16edb16e343498678375c7192
- hash: 2b5f0b503296a0cdd046c13d95dcce62ae6f3dda1bbc7c493c7208645c720145
- hash: ce921c9fac365ff27d186669a3ee8f64
- hash: 753e529afb4bc21682b1fd337e938f4d79b59564
- hash: b3690299060ea7e26e69b74e5e458078030ec48d10bd0a1c6de0bff49a8fa921
- hash: 4aca13fa04cd4a5a745740404cda3329
- hash: 329b043b6f7c783aa125ba419d1044e476491be9
- hash: 95f94f5fce45a96e5eecc8f778deea373a47cadaa3da5c2342c6c6855dcae485
- hash: 321d1dab9de520b7a35e953f29a33642
- hash: 0bffa61b9d1579c2a359b3d376d339284074ab5e
- hash: 1ba6a9571b806d0941c6c7f4ef5a9a58d9085c8f0d42ef977e4c0de0119b39e2
- hash: 12e4badb183ad5fa54e7ded4210fd2e8
- hash: c2a9b9be95d39289f72fca96580ca7e3ceace19a
- hash: 83989cd752c38c8cfc6dc52cf7535c417068c7e1b89ff9cfb23f6eb6d52dc4f6
- hash: c473dc2256befa2c730d92b4c26e6a58
- hash: 2cde8303d35b5ba774c2d1c81400e37ae851b951
- hash: 38ce63f584c09d26d888ee142ab7811371dbdaaa90c0ad5b74eee7a450200b55
- hash: ecbb88ffa71f4829ea853ff2548f4f93
- hash: 63e6ff1edd9e0eb6550a37a9f7aa06e5aa153889
- hash: 05b636682bbe2b0798bf3bf5941fd038db982b8b194271e8935c202bc20c243e
- hash: a45e296431b54c2aec1fb7b2ea02629e
- hash: 4fdcf17e047dcc914ad814c44049fd9b66b3a122
- hash: db2df3c05c4e4a8994170acc8080e3bf2e8f6264d89d116b38eb41d4fce6ae39
- hash: 01c27a3a714a4982a3f73caf0f230f9d
- hash: 172f1b749ffca64a0093777d0c75fbe9715c1c42
- hash: c42db72d2988d5fd007df2e7818513332c6da6742f84d25d257e509f657f923f
- hash: 0762e267487dc9e8de5107de9ecc05bb
- hash: 2ab812fe4bfa6d3809d8f45cc8e31b4cf7fcb03a
- hash: 22180988710ffdb322ae5541948e19d57bc389f7d6449528a571c7649646f55c
- hash: 10087b45406ce4aa12220dceb441731d
- hash: 46663e0e1a2539d106d40d04bd5bf13970aa3712
- hash: 38b3e72b281ef95654f393e99e4055f16e7e9f00024b0a5775b3c21a9420f9a3
- hash: 11afeb7e6da93238e34e78f9243bcdfa
- hash: 670c7013eedc3c82463f3d7d95bbdb4cff54e9fb
- hash: 7b0a2e00bf3fd70be17903b9e31da9bc400dcbc45d634181cec4d5729fb55834
- hash: ae512f255a842dbd62c88cdf2983eced
- hash: eb2c78f987bcb68cb5b53f47e29511b581e9caea
- hash: 37d76cb5bb08886c0547e8178cd321ea50cee60967a2cc86b1d497d1571ee9a3
- hash: 5df63e566f1a8d4d4a52a4194cb41bcf
- hash: a6d52e12f523d3ce3402a07e175bd56d7ee44f0b
- hash: 9b0d3d68ca37e152eb3148e9fb2faa822d19e48d5424c3ef6e1a67b0a86602f9
- hash: d039857b576c7d8770bd8584f4aae4df
- hash: 5423d914bec04dabe2f50b4b3b5bfbfe5a89ce7c
- hash: fb7ac76835a087e27d1bc40090085f88000c7b8c38debd584c2671f6abb2f059
- hash: d453c4330635bdd79be0cedff1024038
- hash: 3e9cfd34649925b4e5992a829717b425128d0b9f
- hash: e7a90443585c21b46479d7b00af903cd4b886fa214e0c0d0b0bfc72a34848749
- hash: 35a8a46aae7e40f74701a61d67750783
- hash: dff10360ca080a7315a1a1e1ac47049a12342b91
- hash: 90423a4fcf200e6bb908d2efd3c11c373a72a0f1f582332a9e911eeb01b941f6
- hash: 2b11aead3af532dd8a4250e8966b649a
- hash: a8f49a7f144f592406c545f8e3519523f9282262
- hash: 942c8369d6fb52e184622d28061bfd09e9b303127038517724e57414bb20d0ee
- hash: c095dd36fece94032e258a52b0a053d6
- hash: 2282892646d65189b1def93d4a50276ca567736b
- hash: 864871d4967db39a0c2117d47bae57456526d891db9f1a3ad1cc6fc1ac85e7b1
- hash: f65f303c4bcd97817af086c959ba6d05
- hash: 3430164fa5cb65f2101f790224b804ae702f1458
- hash: c43d4a837aebd7d6c3d0f185770200010aa856d91968e6d39b38248505375a10
- hash: 7b0f8b1fc25740bf1a595474a990e0c5
- hash: b29ffd6c8c2f0d1160eef3b19b819adbfa7fca3e
- hash: 05e274ec9eb3e295c5bf0661f578346555d8951b04a3afedf6197cab72dcf1c2
- hash: 68c8a9def230d440f3946cbd327d6201
- hash: 157f06a82512c82d69f4daf6222713ed5b3dfef2
- hash: a3f73a0db96757a49aeaed8efa37b8685804b4def03a31485e21091b59b9bd41
- hash: 407fc9101b2babdcb13fbf015452ad84
- hash: 425d6d855b5f3068d6a47a1db260d5062d65665b
- hash: 7d1f1a4202066fc4c5b3940f5a3716115b0eaee3e4f0c7d0b1b6d52a7dc9f191
- hash: 01f9960dfe8d4e1878cc857830d86b22
- domain: ku.nxno-7.ru
- domain: t1.c-01e.ru
- domain: ky.nxno-7.ru
- domain: le.nxno-7.ru
- domain: hm.c-01e.ru
- domain: lu.khhu-8.ru
- domain: d.m-89a.ru
- domain: ly.khhu-8.ru
- domain: w4.m-89a.ru
- file: 2.55.98.253
- hash: 47550
- file: 104.21.63.165
- hash: 80
- url: http://45.201.0.209:8443/kunkun/jquery-3.3.1.min.js
- domain: wss.xahweh.info
- file: 85.208.84.240
- hash: 80
- file: 209.74.72.239
- hash: 888
- file: 206.82.9.243
- hash: 8808
- domain: bounty.blackhatethicalhacking.com
- file: 147.93.102.225
- hash: 7443
- file: 95.165.144.221
- hash: 80
- file: 78.71.115.65
- hash: 9090
- file: 172.111.137.163
- hash: 2404
- file: 196.251.69.196
- hash: 2404
- file: 46.173.214.158
- hash: 4444
- file: 194.113.75.56
- hash: 8000
- file: 37.114.37.177
- hash: 80
- file: 107.175.219.151
- hash: 60000
- file: 47.121.130.232
- hash: 60000
- file: 75.130.127.157
- hash: 3333
- file: 3.142.149.20
- hash: 3333
- file: 82.223.102.88
- hash: 443
- file: 101.43.209.150
- hash: 3333
- file: 64.225.105.204
- hash: 443
- file: 85.208.9.49
- hash: 3333
- file: 3.8.133.40
- hash: 2222
- file: 82.138.112.121
- hash: 443
- file: 43.133.201.202
- hash: 3333
- file: 34.175.22.135
- hash: 443
- file: 18.196.246.28
- hash: 80
- file: 51.91.76.147
- hash: 3333
- file: 103.103.23.161
- hash: 443
- file: 23.94.61.165
- hash: 3333
- url: https://steamcommunity.com/profiles/76561198782513619
- url: https://telegram.me/dobbl7
- file: 193.233.113.101
- hash: 6000
- domain: ni.khhu-8.ru
- domain: pz8.m-89a.ru
- domain: ny.khhu-8.ru
- domain: pu.khhu-8.ru
- domain: h1.m-89a.ru
- file: 124.220.48.168
- hash: 2379
- file: 47.98.129.151
- hash: 50050
- file: 47.108.239.86
- hash: 31337
- file: 89.169.165.136
- hash: 31337
- file: 93.95.226.224
- hash: 31337
- file: 139.162.165.77
- hash: 31337
- file: 52.201.163.22
- hash: 80
- file: 172.111.136.37
- hash: 6000
- domain: venusmastermind.servehttp.com
- domain: texas-illinois.gl.at.ply.gg
- domain: sports-thumbnails.gl.at.ply.gg
- domain: development-unsigned.gl.at.ply.gg
- file: 51.194.181.61
- hash: 1239
- file: 51.194.181.61
- hash: 6000
- url: https://lorrieobrien.com/reg
- url: http://bridgestoneideas.eu/
- file: 202.79.171.36
- hash: 6666
- file: 202.79.171.36
- hash: 8888
- file: 202.79.171.36
- hash: 80
- file: 151.243.219.251
- hash: 5551
- url: https://pastebin.com/raw/bzg5zj8n
- domain: length-coverage.gl.at.ply.gg
- domain: core.r6ms.pw
- url: http://lockbit5eevg7vec4vwwtzgkl4kulap6oxbic2ye4mnmlq6njnpc47qd.onion
- url: http://lockbit74beza5z3e3so7qmjnvlgoemscp7wtp33xo7xv7f7xtlqbkqd.onion
- url: http://lockbit75naln4yj44rg6ez6vjmdcrt7up4kxmmmuvilcg4ak3zihxid.onion
- url: http://lockbit7a2g6ve7etbcy6iyizjnuleffz4szgmxaawcbfauluavi5jqd.onion
- url: http://lockbitaa46gwjck2xzmi2xops6x4x3aqn6ez7yntitero2k7ae6yoyd.onion
- url: http://lockbitb42tkml3ipianjbs6e33vhcshb7oxm2stubfvdzn3y2yqgbad.onion
- url: http://lockbitcuo23q7qrymbk6dsp2sadltspjvjxgcyp4elbnbr6tcnwq7qd.onion
- file: 23.140.36.124
- hash: 48192
- url: http://47.115.137.166:8888/supershell/login/
- domain: py.mzvo-7.ru
- domain: at.cns-3-u.ru
- domain: aa.m-89a.ru
- domain: qa.mzvo-7.ru
- domain: l.p-62i.ru
- domain: qe.mzvo-7.ru
- domain: c5.p-62i.ru
- domain: aw.cns-3-u.ru
- url: https://claim.defai-dao.xyz/send.php
- url: https://qa.mzvo-7.ru/lb.google
- url: https://qa.mzvo-7.ru/lb.google?t=k1xhdpa9
- url: https://qa.mzvo-7.ru/lb.google?t=qn1qkm3f
- url: https://vvsviden.dk/
- url: https://www.comolube.com/up/
- url: https://irp.cdn-website.com/24fc562c/files/uploaded/34.ps1
- url: https://shopbrills.com/
- file: 178.236.252.109
- hash: 443
- file: 80.97.160.205
- hash: 443
- file: 192.142.0.64
- hash: 8888
- domain: qo.mzvo-7.ru
- domain: ax.cns-3-u.ru
- domain: xq0.p-62i.ru
- file: 37.221.66.101
- hash: 443
- file: 164.68.120.30
- hash: 111
- file: 45.192.99.249
- hash: 80
- domain: aa9.p-62i.ru
- domain: qu.mzvo-7.ru
- domain: qy.nzki-7.ru
- domain: ay.cns-3-u.ru
- domain: ra.nzki-7.ru
- domain: ri.nzki-7.ru
- domain: m2.p-62i.ru
- file: 178.87.193.163
- hash: 443
- file: 187.170.177.19
- hash: 995
- file: 206.82.9.213
- hash: 443
- file: 68.65.240.220
- hash: 443
- file: 121.4.83.253
- hash: 443
- domain: ba.cns-3-u.ru
- domain: ro.nzki-7.ru
- file: 1.94.59.190
- hash: 80
- domain: g.l-75y.ru
- domain: ru.nzki-7.ru
- domain: v2.l-75y.ru
- file: 91.219.238.149
- hash: 7000
- domain: ry.phpa-3.ru
- file: 69.42.220.38
- hash: 443
- domain: aa9.l-75y.ru
- domain: sa.phpa-3.ru
- file: 23.94.252.239
- hash: 443
- domain: k7.l-75y.ru
- domain: se.phpa-3.ru
- domain: su.phpa-3.ru
- domain: be.xxx-2-u.ru
- domain: sy.phpa-3.ru
- domain: bi.xxx-2-u.ru
- file: 45.141.84.5
- hash: 54184
- file: 54.185.227.180
- hash: 8080
- domain: r3.l-75y.ru
- domain: te.pvzi-1.ru
- domain: shim1.enrouteltd.com
- domain: shim1.umbandung.ac.id
- domain: bo.xxx-2-u.ru
- domain: dctask8000.ydns.eu
- domain: tu.pvzi-1.ru
- file: 118.118.118.118
- hash: 8080
- url: http://929693cm.nyash.es/windowstemp.php
- domain: r.m-49e.ru
- domain: ty.pvzi-1.ru
- domain: u5.m-49e.ru
- domain: va.pvzi-1.ru
- domain: qk2.m-49e.ru
- domain: ve.pvzi-1.ru
- file: 82.26.74.222
- hash: 162
- file: 156.238.229.81
- hash: 4567
- file: 185.184.27.137
- hash: 1516
- file: 98.66.208.52
- hash: 8000
- file: 51.15.15.47
- hash: 2222
- file: 3.145.163.124
- hash: 443
- domain: effect-meet.gl.at.ply.gg
- domain: northern-unwrap.gl.at.ply.gg
- file: 115.167.64.10
- hash: 80
- file: 154.219.96.137
- hash: 6666
- file: 154.219.96.137
- hash: 8888
- file: 154.219.96.137
- hash: 80
- domain: na.vwjy-7.ru
- domain: e1.m-49e.ru
- domain: my.vwjy-7.ru
- domain: mu.vwjy-7.ru
- domain: n0.m-49e.ru
- domain: mo.vwjy-7.ru
- domain: x.n-82o.ru
- file: 46.246.13.172
- hash: 8888
- domain: mm.vwjy-7.ru
- domain: b2.n-82o.ru
- domain: mi.tvti-0.ru
- domain: tq1.n-82o.ru
- file: 156.239.14.156
- hash: 5562
- domain: me.tvti-0.ru
- domain: m7.n-82o.ru
- domain: ma.tvti-0.ru
- domain: lo.tvti-0.ru
- domain: k9.n-82o.ru
- domain: li.tvti-0.ru
- file: 147.185.221.211
- hash: 51639
- file: 77.37.65.33
- hash: 8888
- file: 181.235.14.141
- hash: 4000
- file: 185.196.11.223
- hash: 777
- file: 181.161.20.99
- hash: 8080
- domain: n.j-31u.ru
- domain: c7.j-31u.ru
- domain: in.xrxo2.ru
- domain: if.xrxo2.ru
- domain: wq9.j-31u.ru
- domain: ho.xrxo2.ru
- domain: r2.j-31u.ru
- domain: hi.xrxo2.ru
- domain: e.focove.ru
- domain: zd.j-31u.ru
- domain: n3.focove.ru
- domain: ch.xxx-2-u.ru
- domain: zt.focove.ru
- file: 31.57.97.83
- hash: 1111
- domain: mean-disease.gl.at.ply.gg
- domain: january-sitemap.gl.at.ply.gg
- url: http://193.233.132.139
- url: http://147.45.47.70
- file: 90.243.202.193
- hash: 4782
- domain: listings-stop.gl.at.ply.gg
- domain: h.p-13a.ru
- domain: a1.focove.ru
- domain: da.tqh-2-e.ru
- domain: pv.focove.ru
- domain: u1.p-13a.ru
- domain: h7.focove.ru
- domain: qm9.p-13a.ru
- file: 122.225.32.46
- hash: 10250
- file: 134.209.157.90
- hash: 40000
- file: 46.6.8.68
- hash: 10880
- file: 75.108.166.103
- hash: 8080
- domain: g.kudaxy.ru
- domain: z3.p-13a.ru
- domain: q7.kudaxy.ru
- domain: k4.p-13a.ru
- domain: bd.kudaxy.ru
- domain: z1.kudaxy.ru
- domain: k.0-g845.ru
- domain: tq.kudaxy.ru
- domain: v2.0-g845.ru
- domain: h9m.kudaxy.ru
- file: 206.237.3.222
- hash: 6789
- file: 119.29.177.237
- hash: 8080
- file: 103.176.197.6
- hash: 8080
- file: 45.83.31.107
- hash: 8000
- file: 80.76.49.107
- hash: 8000
- file: 72.176.170.113
- hash: 80
- file: 72.176.170.113
- hash: 443
- file: 45.77.137.24
- hash: 9000
- file: 196.251.73.223
- hash: 80
- domain: x.kudaxy.ru
- domain: qz9.0-g845.ru
- domain: b.faqyhi.ru
- domain: t1.0-g845.ru
- domain: n5.faqyhi.ru
- domain: hm.0-g845.ru
- domain: xt.faqyhi.ru
- domain: d.0-c448.ru
- domain: w4.0-c448.ru
- url: https://65.109.242.28
ThreatFox IOCs for 2025-10-04
Description
ThreatFox IOCs for 2025-10-04
AI-Powered Analysis
Technical Analysis
The provided information relates to a set of Indicators of Compromise (IOCs) published on 2025-10-04 by the ThreatFox MISP Feed, categorized under malware with a focus on OSINT (Open Source Intelligence), network activity, and payload delivery. The data appears to be a collection of threat intelligence indicators rather than a description of a specific malware variant or exploit. No affected software versions are listed, no patches are available, and there are no known exploits in the wild associated with these IOCs. The threat level is indicated as medium (threatLevel: 2), with moderate distribution (distribution: 3) and minimal analysis (analysis: 1). The absence of concrete technical details such as attack vectors, payload specifics, or exploitation methods limits the depth of technical assessment. The IOCs are intended for use in threat detection and network defense, providing actionable intelligence to identify potential malicious activity related to payload delivery mechanisms. The TLP (Traffic Light Protocol) is white, indicating the information is publicly shareable without restriction. Overall, this entry represents a threat intelligence update rather than a direct vulnerability or active exploit, serving primarily as an OSINT resource for security teams to enhance situational awareness and detection capabilities.
Potential Impact
For European organizations, the impact of these IOCs depends largely on their integration into security monitoring and incident response workflows. Since the data pertains to indicators rather than an active exploit or vulnerability, the immediate risk is low to medium. However, failure to incorporate such intelligence could result in delayed detection of malware infections or network intrusions that use the identified payload delivery methods. Organizations with mature security operations centers (SOCs) and threat hunting capabilities can leverage these IOCs to improve detection accuracy and reduce dwell time of threats. Conversely, entities lacking such capabilities may not benefit fully, potentially increasing exposure to malware campaigns that utilize similar tactics. The absence of known exploits in the wild suggests no immediate widespread threat, but the presence of network activity and payload delivery tags indicates a potential for future exploitation attempts. European organizations in critical infrastructure, finance, and government sectors should be particularly vigilant, as these sectors are frequent targets for malware campaigns leveraging OSINT-derived indicators.
Mitigation Recommendations
To effectively mitigate risks associated with these IOCs, European organizations should: 1) Integrate the ThreatFox IOCs into existing Security Information and Event Management (SIEM) systems and Endpoint Detection and Response (EDR) tools to enable automated detection and alerting on related network activity and payload delivery attempts. 2) Conduct regular threat hunting exercises using these IOCs to proactively identify signs of compromise or suspicious behavior within the network. 3) Update firewall and intrusion detection/prevention system (IDS/IPS) signatures to recognize and block traffic patterns or payloads matching the indicators. 4) Enhance employee awareness and training on phishing and social engineering tactics that may be used to deliver payloads associated with these IOCs. 5) Maintain robust network segmentation and least privilege access controls to limit the lateral movement of malware if an infection occurs. 6) Collaborate with national and European cybersecurity information sharing organizations to stay updated on evolving threats and incorporate additional intelligence feeds. These steps go beyond generic advice by emphasizing the operationalization of threat intelligence and proactive defense measures tailored to the nature of the IOCs.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- bf15d248-b9b8-450c-b762-5f4d0f2fda9f
- Original Timestamp
- 1759622586
Indicators of Compromise
Domain
Value | Description | Copy |
---|---|---|
domaincdn-googlemanager.com | magecart credit card skimming domain (confidence level: 100%) | |
domainnmn.is | magecart credit card skimming domain (confidence level: 100%) | |
domainanl.is | magecart credit card skimming domain (confidence level: 100%) | |
domainsnf.is | magecart credit card skimming domain (confidence level: 100%) | |
domainkof.one | magecart credit card skimming domain (confidence level: 100%) | |
domainko.nxno-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqz9.c-01e.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainku.nxno-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaint1.c-01e.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainky.nxno-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainle.nxno-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhm.c-01e.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlu.khhu-8.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaind.m-89a.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainly.khhu-8.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainw4.m-89a.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwss.xahweh.info | Cobalt Strike botnet C2 domain (confidence level: 100%) | |
domainbounty.blackhatethicalhacking.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainni.khhu-8.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpz8.m-89a.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainny.khhu-8.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpu.khhu-8.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainh1.m-89a.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvenusmastermind.servehttp.com | XWorm botnet C2 domain (confidence level: 100%) | |
domaintexas-illinois.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainsports-thumbnails.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domaindevelopment-unsigned.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainlength-coverage.gl.at.ply.gg | DCRat botnet C2 domain (confidence level: 50%) | |
domaincore.r6ms.pw | Unknown malware botnet C2 domain (confidence level: 50%) | |
domainpy.mzvo-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainat.cns-3-u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainaa.m-89a.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqa.mzvo-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainl.p-62i.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqe.mzvo-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainc5.p-62i.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainaw.cns-3-u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqo.mzvo-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainax.cns-3-u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxq0.p-62i.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainaa9.p-62i.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqu.mzvo-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqy.nzki-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainay.cns-3-u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainra.nzki-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainri.nzki-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainm2.p-62i.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainba.cns-3-u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainro.nzki-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaing.l-75y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainru.nzki-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainv2.l-75y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainry.phpa-3.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainaa9.l-75y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsa.phpa-3.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaink7.l-75y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainse.phpa-3.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsu.phpa-3.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbe.xxx-2-u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsy.phpa-3.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbi.xxx-2-u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainr3.l-75y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainte.pvzi-1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshim1.enrouteltd.com | Rhadamanthys botnet C2 domain (confidence level: 100%) | |
domainshim1.umbandung.ac.id | Rhadamanthys botnet C2 domain (confidence level: 100%) | |
domainbo.xxx-2-u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindctask8000.ydns.eu | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaintu.pvzi-1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainr.m-49e.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainty.pvzi-1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainu5.m-49e.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainva.pvzi-1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqk2.m-49e.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainve.pvzi-1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineffect-meet.gl.at.ply.gg | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainnorthern-unwrap.gl.at.ply.gg | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainna.vwjy-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaine1.m-49e.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmy.vwjy-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmu.vwjy-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainn0.m-49e.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmo.vwjy-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainx.n-82o.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmm.vwjy-7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainb2.n-82o.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmi.tvti-0.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintq1.n-82o.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainme.tvti-0.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainm7.n-82o.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainma.tvti-0.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlo.tvti-0.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaink9.n-82o.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainli.tvti-0.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainn.j-31u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainc7.j-31u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainin.xrxo2.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainif.xrxo2.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwq9.j-31u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainho.xrxo2.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainr2.j-31u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhi.xrxo2.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaine.focove.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzd.j-31u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainn3.focove.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainch.xxx-2-u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzt.focove.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmean-disease.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainjanuary-sitemap.gl.at.ply.gg | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainlistings-stop.gl.at.ply.gg | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainh.p-13a.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaina1.focove.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainda.tqh-2-e.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpv.focove.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainu1.p-13a.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainh7.focove.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqm9.p-13a.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaing.kudaxy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainz3.p-13a.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainq7.kudaxy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaink4.p-13a.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbd.kudaxy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainz1.kudaxy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaink.0-g845.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintq.kudaxy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainv2.0-g845.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainh9m.kudaxy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainx.kudaxy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqz9.0-g845.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainb.faqyhi.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaint1.0-g845.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainn5.faqyhi.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhm.0-g845.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxt.faqyhi.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaind.0-c448.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainw4.0-c448.ru | ClearFake payload delivery domain (confidence level: 100%) |
Url
Value | Description | Copy |
---|---|---|
urlhttp://193.233.113.101:1111/login | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://oriolep.pics/api | Lumma Stealer botnet C2 (confidence level: 75%) | |
urlhttp://45.201.0.209:8443/kunkun/jquery-3.3.1.min.js | Cobalt Strike botnet C2 (confidence level: 75%) | |
urlhttps://steamcommunity.com/profiles/76561198782513619 | Vidar botnet C2 (confidence level: 75%) | |
urlhttps://telegram.me/dobbl7 | Vidar botnet C2 (confidence level: 75%) | |
urlhttps://lorrieobrien.com/reg | Broomstick botnet C2 (confidence level: 50%) | |
urlhttp://bridgestoneideas.eu/ | Broomstick botnet C2 (confidence level: 50%) | |
urlhttps://pastebin.com/raw/bzg5zj8n | AsyncRAT botnet C2 (confidence level: 50%) | |
urlhttp://lockbit5eevg7vec4vwwtzgkl4kulap6oxbic2ye4mnmlq6njnpc47qd.onion | LockBit botnet C2 (confidence level: 50%) | |
urlhttp://lockbit74beza5z3e3so7qmjnvlgoemscp7wtp33xo7xv7f7xtlqbkqd.onion | LockBit botnet C2 (confidence level: 50%) | |
urlhttp://lockbit75naln4yj44rg6ez6vjmdcrt7up4kxmmmuvilcg4ak3zihxid.onion | LockBit botnet C2 (confidence level: 50%) | |
urlhttp://lockbit7a2g6ve7etbcy6iyizjnuleffz4szgmxaawcbfauluavi5jqd.onion | LockBit botnet C2 (confidence level: 50%) | |
urlhttp://lockbitaa46gwjck2xzmi2xops6x4x3aqn6ez7yntitero2k7ae6yoyd.onion | LockBit botnet C2 (confidence level: 50%) | |
urlhttp://lockbitb42tkml3ipianjbs6e33vhcshb7oxm2stubfvdzn3y2yqgbad.onion | LockBit botnet C2 (confidence level: 50%) | |
urlhttp://lockbitcuo23q7qrymbk6dsp2sadltspjvjxgcyp4elbnbr6tcnwq7qd.onion | LockBit botnet C2 (confidence level: 50%) | |
urlhttp://47.115.137.166:8888/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://claim.defai-dao.xyz/send.php | Unknown malware botnet C2 (confidence level: 50%) | |
urlhttps://qa.mzvo-7.ru/lb.google | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://qa.mzvo-7.ru/lb.google?t=k1xhdpa9 | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://qa.mzvo-7.ru/lb.google?t=qn1qkm3f | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://vvsviden.dk/ | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://www.comolube.com/up/ | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://irp.cdn-website.com/24fc562c/files/uploaded/34.ps1 | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://shopbrills.com/ | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttp://929693cm.nyash.es/windowstemp.php | DCRat botnet C2 (confidence level: 100%) | |
urlhttp://193.233.132.139 | Amadey botnet C2 (confidence level: 100%) | |
urlhttp://147.45.47.70 | Amadey botnet C2 (confidence level: 100%) | |
urlhttps://65.109.242.28 | Vidar botnet C2 (confidence level: 75%) |
File
Value | Description | Copy |
---|---|---|
file193.233.113.101 | Unknown malware botnet C2 server (confidence level: 100%) | |
file124.198.132.91 | Remcos botnet C2 server (confidence level: 100%) | |
file107.172.132.45 | Remcos botnet C2 server (confidence level: 100%) | |
file172.111.131.113 | Remcos botnet C2 server (confidence level: 100%) | |
file209.74.72.239 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file54.93.126.183 | Hook botnet C2 server (confidence level: 100%) | |
file88.175.164.206 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file45.133.180.154 | DCRat botnet C2 server (confidence level: 100%) | |
file46.173.214.158 | DCRat botnet C2 server (confidence level: 100%) | |
file45.192.99.218 | MooBot botnet C2 server (confidence level: 100%) | |
file2.55.98.253 | Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%) | |
file104.21.63.165 | Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%) | |
file85.208.84.240 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file209.74.72.239 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file206.82.9.243 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file147.93.102.225 | Unknown malware botnet C2 server (confidence level: 100%) | |
file95.165.144.221 | Unknown malware botnet C2 server (confidence level: 100%) | |
file78.71.115.65 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file172.111.137.163 | Remcos botnet C2 server (confidence level: 100%) | |
file196.251.69.196 | Remcos botnet C2 server (confidence level: 100%) | |
file46.173.214.158 | DCRat botnet C2 server (confidence level: 100%) | |
file194.113.75.56 | Sliver botnet C2 server (confidence level: 100%) | |
file37.114.37.177 | MooBot botnet C2 server (confidence level: 100%) | |
file107.175.219.151 | Unknown malware botnet C2 server (confidence level: 100%) | |
file47.121.130.232 | Unknown malware botnet C2 server (confidence level: 100%) | |
file75.130.127.157 | Unknown malware botnet C2 server (confidence level: 100%) | |
file3.142.149.20 | Unknown malware botnet C2 server (confidence level: 100%) | |
file82.223.102.88 | Unknown malware botnet C2 server (confidence level: 100%) | |
file101.43.209.150 | Unknown malware botnet C2 server (confidence level: 100%) | |
file64.225.105.204 | Unknown malware botnet C2 server (confidence level: 100%) | |
file85.208.9.49 | Unknown malware botnet C2 server (confidence level: 100%) | |
file3.8.133.40 | Unknown malware botnet C2 server (confidence level: 100%) | |
file82.138.112.121 | Unknown malware botnet C2 server (confidence level: 100%) | |
file43.133.201.202 | Unknown malware botnet C2 server (confidence level: 100%) | |
file34.175.22.135 | Unknown malware botnet C2 server (confidence level: 100%) | |
file18.196.246.28 | Unknown malware botnet C2 server (confidence level: 100%) | |
file51.91.76.147 | Unknown malware botnet C2 server (confidence level: 100%) | |
file103.103.23.161 | Unknown malware botnet C2 server (confidence level: 100%) | |
file23.94.61.165 | Unknown malware botnet C2 server (confidence level: 100%) | |
file193.233.113.101 | XWorm botnet C2 server (confidence level: 100%) | |
file124.220.48.168 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file47.98.129.151 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
file47.108.239.86 | Sliver botnet C2 server (confidence level: 50%) | |
file89.169.165.136 | Sliver botnet C2 server (confidence level: 50%) | |
file93.95.226.224 | Sliver botnet C2 server (confidence level: 50%) | |
file139.162.165.77 | Sliver botnet C2 server (confidence level: 50%) | |
file52.201.163.22 | Ghost RAT botnet C2 server (confidence level: 50%) | |
file172.111.136.37 | XWorm botnet C2 server (confidence level: 100%) | |
file51.194.181.61 | XWorm botnet C2 server (confidence level: 100%) | |
file51.194.181.61 | XWorm botnet C2 server (confidence level: 100%) | |
file202.79.171.36 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file202.79.171.36 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file202.79.171.36 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file151.243.219.251 | SpyNote botnet C2 server (confidence level: 100%) | |
file23.140.36.124 | Remcos botnet C2 server (confidence level: 50%) | |
file178.236.252.109 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file80.97.160.205 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file192.142.0.64 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file37.221.66.101 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file164.68.120.30 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file45.192.99.249 | MooBot botnet C2 server (confidence level: 100%) | |
file178.87.193.163 | QakBot botnet C2 server (confidence level: 75%) | |
file187.170.177.19 | QakBot botnet C2 server (confidence level: 75%) | |
file206.82.9.213 | Havoc botnet C2 server (confidence level: 75%) | |
file68.65.240.220 | QakBot botnet C2 server (confidence level: 75%) | |
file121.4.83.253 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file1.94.59.190 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file91.219.238.149 | XWorm botnet C2 server (confidence level: 100%) | |
file69.42.220.38 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file23.94.252.239 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file45.141.84.5 | pupy botnet C2 server (confidence level: 100%) | |
file54.185.227.180 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file118.118.118.118 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file82.26.74.222 | XWorm botnet C2 server (confidence level: 100%) | |
file156.238.229.81 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file185.184.27.137 | Remcos botnet C2 server (confidence level: 100%) | |
file98.66.208.52 | Sliver botnet C2 server (confidence level: 100%) | |
file51.15.15.47 | Sliver botnet C2 server (confidence level: 100%) | |
file3.145.163.124 | Havoc botnet C2 server (confidence level: 100%) | |
file115.167.64.10 | Bashlite botnet C2 server (confidence level: 100%) | |
file154.219.96.137 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file154.219.96.137 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file154.219.96.137 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file46.246.13.172 | Meterpreter botnet C2 server (confidence level: 75%) | |
file156.239.14.156 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file147.185.221.211 | XWorm botnet C2 server (confidence level: 100%) | |
file77.37.65.33 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file181.235.14.141 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file185.196.11.223 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file181.161.20.99 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file31.57.97.83 | XWorm botnet C2 server (confidence level: 100%) | |
file90.243.202.193 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file122.225.32.46 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file134.209.157.90 | Havoc botnet C2 server (confidence level: 75%) | |
file46.6.8.68 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file75.108.166.103 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file206.237.3.222 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file119.29.177.237 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file103.176.197.6 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file45.83.31.107 | Remcos botnet C2 server (confidence level: 100%) | |
file80.76.49.107 | Sliver botnet C2 server (confidence level: 100%) | |
file72.176.170.113 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file72.176.170.113 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file45.77.137.24 | SectopRAT botnet C2 server (confidence level: 100%) | |
file196.251.73.223 | Havoc botnet C2 server (confidence level: 100%) |
Hash
Value | Description | Copy |
---|---|---|
hash1111 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash4444 | Remcos botnet C2 server (confidence level: 100%) | |
hash14646 | Remcos botnet C2 server (confidence level: 100%) | |
hash1771 | Remcos botnet C2 server (confidence level: 100%) | |
hash8443 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash80 | Hook botnet C2 server (confidence level: 100%) | |
hash49152 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash4000 | DCRat botnet C2 server (confidence level: 100%) | |
hash8888 | DCRat botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hashb258d37fe91f0bf078abeaefbc584cd7a08b9f09 | Luca Stealer payload (confidence level: 95%) | |
hashca10f8af17c49cb7a659badd06b529b816c59d7d6f4e1f9ec23c173fc56588ec | Luca Stealer payload (confidence level: 95%) | |
hash86c1f5cbb41a3db91fb331bf6fee1e61 | Luca Stealer payload (confidence level: 95%) | |
hash06edc864b7c95188a07e8b9589eeaa24a9b8c0f6 | Luca Stealer payload (confidence level: 95%) | |
hasha32a4ef40c949b6247cf9a0a43546d8e4e5040195db8e8157fe9f884a79e4e9e | Luca Stealer payload (confidence level: 95%) | |
hash972899fe1db55b0efeafdfa6abed3dcf | Luca Stealer payload (confidence level: 95%) | |
hashc596ce51ebcadd3d9dab88c2d4ce49e83273350b | XWorm payload (confidence level: 95%) | |
hash8697e36a4cb7810976c72d5890abeede56a664ab741fe24c755f3648fb5f9124 | XWorm payload (confidence level: 95%) | |
hashb6480c04dd858a0e1596ea34180c31a5 | XWorm payload (confidence level: 95%) | |
hash885ac21b684ab520b2615aef9c78b4c01844ce9f | Formbook payload (confidence level: 95%) | |
hashebc963782a30a3e6cc360a6e4fda16d2acac2de13ee0d8db863082e699dabd5a | Formbook payload (confidence level: 95%) | |
hash98a29f93295ba4d70fb0e766b1fb0572 | Formbook payload (confidence level: 95%) | |
hash2d93ef9e2dde680e2834a3a9a5211c1448943d6a | SalatStealer payload (confidence level: 95%) | |
hash8537f934654bf1ade223878e12b62d051641dfeb47db4609b48ca819bdf10311 | SalatStealer payload (confidence level: 95%) | |
hash241ce23db564beb28001b0c202123d8d | SalatStealer payload (confidence level: 95%) | |
hashe7ebbca6178a27fb7c316266810b0c777fc65bdb | SalatStealer payload (confidence level: 95%) | |
hash3532fe525d339585e0aeeecbe2b55593e3732367ae57917513e8e5645b6854ed | SalatStealer payload (confidence level: 95%) | |
hash428518352a11081287f6f35a2bc661f6 | SalatStealer payload (confidence level: 95%) | |
hash5d8b0e8e49d840b525d9e9c0041467977574fda9 | SalatStealer payload (confidence level: 95%) | |
hash567eceb1456164eace7d2e0d15ce2deed8c41ec6279213a54174a97ba92802af | SalatStealer payload (confidence level: 95%) | |
hashc60742616fe6341c41f9e13cb6c7d77c | SalatStealer payload (confidence level: 95%) | |
hash9de78184ae7742ce7d7ceb78b50340e38295eb82 | Agent Tesla payload (confidence level: 95%) | |
hash7c4072f5ae6fdf61d9f6d051a5bad41290e6e66e5a564110ec97a256fd4980b4 | Agent Tesla payload (confidence level: 95%) | |
hash65dd5102f8648aa303711d62cec6bc9a | Agent Tesla payload (confidence level: 95%) | |
hash1331be65e2cb9f29810ac0c94605e0a069d4bb39 | Cobalt Strike payload (confidence level: 95%) | |
hash25e89fe9b7a662bd7d2b4e4632c27877911daf32a05748423c3a82fbf9b6d787 | Cobalt Strike payload (confidence level: 95%) | |
hash0dcb8b2dfd1f769eecb77dabcb47eb14 | Cobalt Strike payload (confidence level: 95%) | |
hash8256464c3b152d7dd4a029e3371bfc95ef3ed163 | ValleyRAT payload (confidence level: 95%) | |
hash53103a831d128565133ffcd807c8aedf011367c6fb261914b5d9bed0f7382548 | ValleyRAT payload (confidence level: 95%) | |
hash0f764e2f9b54779e3bf7c3188918a2b2 | ValleyRAT payload (confidence level: 95%) | |
hash4f2df81df59fdc9ccef57aea4260f87441897a64 | KrakenKeylogger payload (confidence level: 95%) | |
hash0443e508c14630fca81d33c7a33555a32cc35226ebd95d10e361a22fa3beed2a | KrakenKeylogger payload (confidence level: 95%) | |
hasha8485008ab3c7606347c716ad0ff1afd | KrakenKeylogger payload (confidence level: 95%) | |
hash557662626b8487db282c18ecdf0796b6ab24f0e9 | Vidar payload (confidence level: 95%) | |
hash1285169abae30ba3d353644ed90ded5d7fe5ea119a027e8eee1aeb8511c13f06 | Vidar payload (confidence level: 95%) | |
hashe85ff3c8b17db2e64ca3f8b9435524c7 | Vidar payload (confidence level: 95%) | |
hash19302a1262a88b306877456441fcc867eb472028 | Amadey payload (confidence level: 95%) | |
hash72a869c753d3b44377b388fd12b9ba6b8345082b95db87104a218c0f92e1a978 | Amadey payload (confidence level: 95%) | |
hash097631100aadc521a627f2d45ac49cb0 | Amadey payload (confidence level: 95%) | |
hash21320e570f916203769e48ce3dfd753099b5ee30 | ValleyRAT payload (confidence level: 95%) | |
hashbd9e7304d6154d73f77961403e3ef8596c68ab574517d1e78632ca747a0c6297 | ValleyRAT payload (confidence level: 95%) | |
hashb88d42502f8415582cf02cacf9f48c98 | ValleyRAT payload (confidence level: 95%) | |
hashbe681c884db8a0ce0ca338554a937a76de605806 | AsyncRAT payload (confidence level: 95%) | |
hash86caabaf24738f1b63c93a374e0894b6ab36cf4f13595e5f8f2d693f168ac159 | AsyncRAT payload (confidence level: 95%) | |
hashaead2b5876f531cd4df9dd1b9eb31d9e | AsyncRAT payload (confidence level: 95%) | |
hashf5558495e99af20dd4157966abba6ad24dc57c46 | GCleaner payload (confidence level: 95%) | |
hash9a577c544360db41918b2d1890ae1abf2407e734f77d307ef8828a151d8252d4 | GCleaner payload (confidence level: 95%) | |
hash3d5baa12dd0879f1f941125a32b51e0c | GCleaner payload (confidence level: 95%) | |
hashd93475096b39569d5721719ae4dea75f25de9e28 | Remcos payload (confidence level: 95%) | |
hash5376f3fdc59befa0e3af575beb1ca43180a9edceae0a26eba338aa2b1ca37953 | Remcos payload (confidence level: 95%) | |
hashd72666dbb09fc973c2648a1f3699382f | Remcos payload (confidence level: 95%) | |
hashfeeb19126eb47fb0679b8fc95f6cabeefdea4c81 | Formbook payload (confidence level: 95%) | |
hashbd883a6075228d89b0c201880e1feafe73784e964720d027455e1702be6bba7c | Formbook payload (confidence level: 95%) | |
hashe5e02db5a57dc49eac87c8474b83fb80 | Formbook payload (confidence level: 95%) | |
hash3fa28e125ed1dfca4b3eb8daf0ebc8dd1988a2c4 | Formbook payload (confidence level: 95%) | |
hash4123bedccc18eee83aa4c7d8e1b64191ddde5fc234bd3c1cbd7f998571e47112 | Formbook payload (confidence level: 95%) | |
hash7daa0cbb2947346c2b8b44da29827b5a | Formbook payload (confidence level: 95%) | |
hash8ca33f8f3097d3c3d8d005c0f0060ea9606f93a7 | DarkTortilla payload (confidence level: 95%) | |
hash4206c4ded33b3137cb67d2013deb8c6d78b4a55fd16d9930904ad548d8802c19 | DarkTortilla payload (confidence level: 95%) | |
hashc9f0f5c54927915dfa5be5898e7afde0 | DarkTortilla payload (confidence level: 95%) | |
hashc5b9cf0275373689f2d3dd4613e82a328d5a798d | Formbook payload (confidence level: 95%) | |
hash703af985b3787f140971cccc1cfe86ed8af40a9ba9e05ab0e7e2d67ac97a79b7 | Formbook payload (confidence level: 95%) | |
hash5d19a82a858cd4553f2b12abe2ee814b | Formbook payload (confidence level: 95%) | |
hashc67a6a8ceb95b1d0ebe50a163bebc888b1c81dea | MyDoom payload (confidence level: 95%) | |
hashfcea10e54c5fc8f3cdb564bed30acf6afa46eeeede717c13b95b3e8ad7814075 | MyDoom payload (confidence level: 95%) | |
hash7829f99381234edea37c75995ac44551 | MyDoom payload (confidence level: 95%) | |
hash8688cfc123234b8abf9d41e83ca869f31df5854b | Luca Stealer payload (confidence level: 95%) | |
hash266225722a9a978e56e824d28bd7c8908c1d95326f65d3908e2e1a8c83672f67 | Luca Stealer payload (confidence level: 95%) | |
hash03026e78fd4616c8bb6a2847c957ce0d | Luca Stealer payload (confidence level: 95%) | |
hashe398ac732ce7e89bb104b2edf9f3722a28e38dbf | GoGoogle payload (confidence level: 95%) | |
hash0147a292eabd1a7ae1be2bfbf0376e75e79a15111c95f2eb5cfcc50a8ae1922f | GoGoogle payload (confidence level: 95%) | |
hash51744370f289d940c1d51ac8ed235a37 | GoGoogle payload (confidence level: 95%) | |
hash5fee88f41e7440dfccf0c3564f37ca586a563e7e | DBatLoader payload (confidence level: 95%) | |
hash08d496c06e3656f8923211d5bc5cfa001179409169674dcee32373879901d9b5 | DBatLoader payload (confidence level: 95%) | |
hash58a9ca4eca8ebb8d5ed45fd3f7638e34 | DBatLoader payload (confidence level: 95%) | |
hashc5c54edff15b70af20bb8464640db799a57a0d80 | Remcos payload (confidence level: 95%) | |
hash5654aa9cb45d8fbdd37d400357b57ec96c0865d62b2698fe6c317ad6448b17d4 | Remcos payload (confidence level: 95%) | |
hashae54148a1344747c1d0acdf22d1cd71f | Remcos payload (confidence level: 95%) | |
hash7894100f080b62098a9206e64d24ea3e91b92748 | DBatLoader payload (confidence level: 95%) | |
hashcb464455cbb783df8da5d7e1cee51cde3b42f5cd1c4c5cb6559aa56cbb1007fe | DBatLoader payload (confidence level: 95%) | |
hash269bb75dbbaa3feaa4bdc4c895acfdaa | DBatLoader payload (confidence level: 95%) | |
hashd04a50323d45d0c7eb3def56fcbfa00669855465 | SalatStealer payload (confidence level: 95%) | |
hashc793a3aa1211f65a43658ad4dac17f25dbbd1035f54bb44e366871fbfefca74f | SalatStealer payload (confidence level: 95%) | |
hashedc388f738f38d8901db005bfbe13338 | SalatStealer payload (confidence level: 95%) | |
hash697382ed9a10c708dfc3a314285839434e1ce453 | XWorm payload (confidence level: 95%) | |
hashc376028af619aec083e473b00abf62fe6be3bb60d081b6479982388ee1664008 | XWorm payload (confidence level: 95%) | |
hashf6b9d0e2906097dbc626997e6ddfc68b | XWorm payload (confidence level: 95%) | |
hash00f15663add14c17d37b9973ddca84d9c1edb2f8 | XWorm payload (confidence level: 95%) | |
hash6ac3a2007fbcf5ba7cac6208a74c67c0aa16651109b4fd971a4f23742f3bf2ad | XWorm payload (confidence level: 95%) | |
hash3983464bf4b5ab81574d7a56a3ed79d2 | XWorm payload (confidence level: 95%) | |
hash0280e4fc1b285d4614c37615faf7a5792144b4fe | HijackLoader payload (confidence level: 95%) | |
hashb87932a6ec2499d7d36ca764a64e5b38a209d1bb97346ef65226082db6830194 | HijackLoader payload (confidence level: 95%) | |
hash81d348e269973aa9d46fdc3651b01245 | HijackLoader payload (confidence level: 95%) | |
hashdc7fa2955f5ac6d81f2d9619ad4b268d4136bd3c | Formbook payload (confidence level: 95%) | |
hash1b2a2c0a20f38ab07813d01f49c8e57f3c4c514a59571d7c60bf9952085ea43a | Formbook payload (confidence level: 95%) | |
hash3c56e449a4423c77d528bfc41560bd87 | Formbook payload (confidence level: 95%) | |
hash3ccbba0d6c4060de32646505ae1baeaedadfce88 | Formbook payload (confidence level: 95%) | |
hash0368450303b2da9adaa02276d18fcfc46616f17b773c8c487d4b02a0f7dc5bb7 | Formbook payload (confidence level: 95%) | |
hash36b04539ba991e1fe77c2d03b866c5e0 | Formbook payload (confidence level: 95%) | |
hash410a1c5fa50e33fc4d39ae3219a608cef5258a7c | Formbook payload (confidence level: 95%) | |
hashf4a2ff30755f15ff9c9e1ea5fdabd00f3c2755bb9d28829390833b07fc1cdce1 | Formbook payload (confidence level: 95%) | |
hashcc6f7e44970b582bdb7d8c03aeb7aab5 | Formbook payload (confidence level: 95%) | |
hash143f1ce5c907aacd9736871f73c2631e00d62498 | VIP Keylogger payload (confidence level: 95%) | |
hashe45a11dfd7e9b1a6dbd2f2a75c669ae8b7a6912cd0ca5e30e37510d20dd04e2e | VIP Keylogger payload (confidence level: 95%) | |
hash1dd3800afc130f58d1795cd845e120d9 | VIP Keylogger payload (confidence level: 95%) | |
hash3501fba08b5fb390fa6fef0401f637c32b2148a5 | Formbook payload (confidence level: 95%) | |
hash35609862a6c28f3fa0e24dfc564dd3515c539cd1f8387de051055abbaef90ff5 | Formbook payload (confidence level: 95%) | |
hash3d93088de48469a4491ad6d87cf2c360 | Formbook payload (confidence level: 95%) | |
hash480327c278995074240e7ffc29d50a5cd2a73f6c | Formbook payload (confidence level: 95%) | |
hashe97233f6c7b7497a0fe4d6a916dde92ade0cc0f92d73e424af88b0bd855b23db | Formbook payload (confidence level: 95%) | |
hash3f7841733addbcb2c9ce682c97e6ae6c | Formbook payload (confidence level: 95%) | |
hash9c83124088df8b65abe05fd560abd761ebae42b9 | Formbook payload (confidence level: 95%) | |
hash41e4dd0218aed625e7883bd3dbe43a95796360bda2e2b7fcf020af9fe5e1f1dc | Formbook payload (confidence level: 95%) | |
hash99260f7647b97c22974702b600e79c89 | Formbook payload (confidence level: 95%) | |
hashd69e24632c04501d628bd99724a06c5310c498b7 | VIP Keylogger payload (confidence level: 95%) | |
hash386e075c4b38ed2f8a1288d41f3d3508ff84337a0f9507c51f46ad01eb0c1613 | VIP Keylogger payload (confidence level: 95%) | |
hash6d625bf33b348fe4ef8a7a14f1cc52b2 | VIP Keylogger payload (confidence level: 95%) | |
hashcfd47e1aebcf6beea8c4fae741543f1d3ea6ccc1 | KrakenKeylogger payload (confidence level: 95%) | |
hash0015911fab4e4cedd52c9fca15fc8556407bb92b23673dd4463e95f766c7349a | KrakenKeylogger payload (confidence level: 95%) | |
hash9323f7a482830e191c832f174865dfbf | KrakenKeylogger payload (confidence level: 95%) | |
hashe773e7a4289a8ee16edb16e343498678375c7192 | Agent Tesla payload (confidence level: 95%) | |
hash2b5f0b503296a0cdd046c13d95dcce62ae6f3dda1bbc7c493c7208645c720145 | Agent Tesla payload (confidence level: 95%) | |
hashce921c9fac365ff27d186669a3ee8f64 | Agent Tesla payload (confidence level: 95%) | |
hash753e529afb4bc21682b1fd337e938f4d79b59564 | SalatStealer payload (confidence level: 95%) | |
hashb3690299060ea7e26e69b74e5e458078030ec48d10bd0a1c6de0bff49a8fa921 | SalatStealer payload (confidence level: 95%) | |
hash4aca13fa04cd4a5a745740404cda3329 | SalatStealer payload (confidence level: 95%) | |
hash329b043b6f7c783aa125ba419d1044e476491be9 | Kimsuky payload (confidence level: 95%) | |
hash95f94f5fce45a96e5eecc8f778deea373a47cadaa3da5c2342c6c6855dcae485 | Kimsuky payload (confidence level: 95%) | |
hash321d1dab9de520b7a35e953f29a33642 | Kimsuky payload (confidence level: 95%) | |
hash0bffa61b9d1579c2a359b3d376d339284074ab5e | KrakenKeylogger payload (confidence level: 95%) | |
hash1ba6a9571b806d0941c6c7f4ef5a9a58d9085c8f0d42ef977e4c0de0119b39e2 | KrakenKeylogger payload (confidence level: 95%) | |
hash12e4badb183ad5fa54e7ded4210fd2e8 | KrakenKeylogger payload (confidence level: 95%) | |
hashc2a9b9be95d39289f72fca96580ca7e3ceace19a | Vidar payload (confidence level: 95%) | |
hash83989cd752c38c8cfc6dc52cf7535c417068c7e1b89ff9cfb23f6eb6d52dc4f6 | Vidar payload (confidence level: 95%) | |
hashc473dc2256befa2c730d92b4c26e6a58 | Vidar payload (confidence level: 95%) | |
hash2cde8303d35b5ba774c2d1c81400e37ae851b951 | PadCrypt payload (confidence level: 95%) | |
hash38ce63f584c09d26d888ee142ab7811371dbdaaa90c0ad5b74eee7a450200b55 | PadCrypt payload (confidence level: 95%) | |
hashecbb88ffa71f4829ea853ff2548f4f93 | PadCrypt payload (confidence level: 95%) | |
hash63e6ff1edd9e0eb6550a37a9f7aa06e5aa153889 | StrelaStealer payload (confidence level: 95%) | |
hash05b636682bbe2b0798bf3bf5941fd038db982b8b194271e8935c202bc20c243e | StrelaStealer payload (confidence level: 95%) | |
hasha45e296431b54c2aec1fb7b2ea02629e | StrelaStealer payload (confidence level: 95%) | |
hash4fdcf17e047dcc914ad814c44049fd9b66b3a122 | KrakenKeylogger payload (confidence level: 95%) | |
hashdb2df3c05c4e4a8994170acc8080e3bf2e8f6264d89d116b38eb41d4fce6ae39 | KrakenKeylogger payload (confidence level: 95%) | |
hash01c27a3a714a4982a3f73caf0f230f9d | KrakenKeylogger payload (confidence level: 95%) | |
hash172f1b749ffca64a0093777d0c75fbe9715c1c42 | Rhadamanthys payload (confidence level: 95%) | |
hashc42db72d2988d5fd007df2e7818513332c6da6742f84d25d257e509f657f923f | Rhadamanthys payload (confidence level: 95%) | |
hash0762e267487dc9e8de5107de9ecc05bb | Rhadamanthys payload (confidence level: 95%) | |
hash2ab812fe4bfa6d3809d8f45cc8e31b4cf7fcb03a | Rhadamanthys payload (confidence level: 95%) | |
hash22180988710ffdb322ae5541948e19d57bc389f7d6449528a571c7649646f55c | Rhadamanthys payload (confidence level: 95%) | |
hash10087b45406ce4aa12220dceb441731d | Rhadamanthys payload (confidence level: 95%) | |
hash46663e0e1a2539d106d40d04bd5bf13970aa3712 | Rhadamanthys payload (confidence level: 95%) | |
hash38b3e72b281ef95654f393e99e4055f16e7e9f00024b0a5775b3c21a9420f9a3 | Rhadamanthys payload (confidence level: 95%) | |
hash11afeb7e6da93238e34e78f9243bcdfa | Rhadamanthys payload (confidence level: 95%) | |
hash670c7013eedc3c82463f3d7d95bbdb4cff54e9fb | Rhadamanthys payload (confidence level: 95%) | |
hash7b0a2e00bf3fd70be17903b9e31da9bc400dcbc45d634181cec4d5729fb55834 | Rhadamanthys payload (confidence level: 95%) | |
hashae512f255a842dbd62c88cdf2983eced | Rhadamanthys payload (confidence level: 95%) | |
hasheb2c78f987bcb68cb5b53f47e29511b581e9caea | KrakenKeylogger payload (confidence level: 95%) | |
hash37d76cb5bb08886c0547e8178cd321ea50cee60967a2cc86b1d497d1571ee9a3 | KrakenKeylogger payload (confidence level: 95%) | |
hash5df63e566f1a8d4d4a52a4194cb41bcf | KrakenKeylogger payload (confidence level: 95%) | |
hasha6d52e12f523d3ce3402a07e175bd56d7ee44f0b | XWorm payload (confidence level: 95%) | |
hash9b0d3d68ca37e152eb3148e9fb2faa822d19e48d5424c3ef6e1a67b0a86602f9 | XWorm payload (confidence level: 95%) | |
hashd039857b576c7d8770bd8584f4aae4df | XWorm payload (confidence level: 95%) | |
hash5423d914bec04dabe2f50b4b3b5bfbfe5a89ce7c | AsyncRAT payload (confidence level: 95%) | |
hashfb7ac76835a087e27d1bc40090085f88000c7b8c38debd584c2671f6abb2f059 | AsyncRAT payload (confidence level: 95%) | |
hashd453c4330635bdd79be0cedff1024038 | AsyncRAT payload (confidence level: 95%) | |
hash3e9cfd34649925b4e5992a829717b425128d0b9f | GCleaner payload (confidence level: 95%) | |
hashe7a90443585c21b46479d7b00af903cd4b886fa214e0c0d0b0bfc72a34848749 | GCleaner payload (confidence level: 95%) | |
hash35a8a46aae7e40f74701a61d67750783 | GCleaner payload (confidence level: 95%) | |
hashdff10360ca080a7315a1a1e1ac47049a12342b91 | Vidar payload (confidence level: 95%) | |
hash90423a4fcf200e6bb908d2efd3c11c373a72a0f1f582332a9e911eeb01b941f6 | Vidar payload (confidence level: 95%) | |
hash2b11aead3af532dd8a4250e8966b649a | Vidar payload (confidence level: 95%) | |
hasha8f49a7f144f592406c545f8e3519523f9282262 | StrelaStealer payload (confidence level: 95%) | |
hash942c8369d6fb52e184622d28061bfd09e9b303127038517724e57414bb20d0ee | StrelaStealer payload (confidence level: 95%) | |
hashc095dd36fece94032e258a52b0a053d6 | StrelaStealer payload (confidence level: 95%) | |
hash2282892646d65189b1def93d4a50276ca567736b | Stealc payload (confidence level: 95%) | |
hash864871d4967db39a0c2117d47bae57456526d891db9f1a3ad1cc6fc1ac85e7b1 | Stealc payload (confidence level: 95%) | |
hashf65f303c4bcd97817af086c959ba6d05 | Stealc payload (confidence level: 95%) | |
hash3430164fa5cb65f2101f790224b804ae702f1458 | Vidar payload (confidence level: 95%) | |
hashc43d4a837aebd7d6c3d0f185770200010aa856d91968e6d39b38248505375a10 | Vidar payload (confidence level: 95%) | |
hash7b0f8b1fc25740bf1a595474a990e0c5 | Vidar payload (confidence level: 95%) | |
hashb29ffd6c8c2f0d1160eef3b19b819adbfa7fca3e | Supper payload (confidence level: 95%) | |
hash05e274ec9eb3e295c5bf0661f578346555d8951b04a3afedf6197cab72dcf1c2 | Supper payload (confidence level: 95%) | |
hash68c8a9def230d440f3946cbd327d6201 | Supper payload (confidence level: 95%) | |
hash157f06a82512c82d69f4daf6222713ed5b3dfef2 | Luca Stealer payload (confidence level: 95%) | |
hasha3f73a0db96757a49aeaed8efa37b8685804b4def03a31485e21091b59b9bd41 | Luca Stealer payload (confidence level: 95%) | |
hash407fc9101b2babdcb13fbf015452ad84 | Luca Stealer payload (confidence level: 95%) | |
hash425d6d855b5f3068d6a47a1db260d5062d65665b | Rhadamanthys payload (confidence level: 95%) | |
hash7d1f1a4202066fc4c5b3940f5a3716115b0eaee3e4f0c7d0b1b6d52a7dc9f191 | Rhadamanthys payload (confidence level: 95%) | |
hash01f9960dfe8d4e1878cc857830d86b22 | Rhadamanthys payload (confidence level: 95%) | |
hash47550 | Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%) | |
hash80 | Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash888 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash9090 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash4444 | DCRat botnet C2 server (confidence level: 100%) | |
hash8000 | Sliver botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hash60000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash60000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash2222 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash6000 | XWorm botnet C2 server (confidence level: 100%) | |
hash2379 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash50050 | Cobalt Strike botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash31337 | Sliver botnet C2 server (confidence level: 50%) | |
hash80 | Ghost RAT botnet C2 server (confidence level: 50%) | |
hash6000 | XWorm botnet C2 server (confidence level: 100%) | |
hash1239 | XWorm botnet C2 server (confidence level: 100%) | |
hash6000 | XWorm botnet C2 server (confidence level: 100%) | |
hash6666 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash8888 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash80 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash5551 | SpyNote botnet C2 server (confidence level: 100%) | |
hash48192 | Remcos botnet C2 server (confidence level: 50%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash8888 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash111 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hash443 | QakBot botnet C2 server (confidence level: 75%) | |
hash995 | QakBot botnet C2 server (confidence level: 75%) | |
hash443 | Havoc botnet C2 server (confidence level: 75%) | |
hash443 | QakBot botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash54184 | pupy botnet C2 server (confidence level: 100%) | |
hash8080 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash162 | XWorm botnet C2 server (confidence level: 100%) | |
hash4567 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash1516 | Remcos botnet C2 server (confidence level: 100%) | |
hash8000 | Sliver botnet C2 server (confidence level: 100%) | |
hash2222 | Sliver botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash80 | Bashlite botnet C2 server (confidence level: 100%) | |
hash6666 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash8888 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash80 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash8888 | Meterpreter botnet C2 server (confidence level: 75%) | |
hash5562 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash51639 | XWorm botnet C2 server (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash4000 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash777 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8080 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash1111 | XWorm botnet C2 server (confidence level: 100%) | |
hash4782 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash10250 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash40000 | Havoc botnet C2 server (confidence level: 75%) | |
hash10880 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash8080 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash6789 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8080 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash8000 | Remcos botnet C2 server (confidence level: 100%) | |
hash8000 | Sliver botnet C2 server (confidence level: 100%) | |
hash80 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash443 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash80 | Havoc botnet C2 server (confidence level: 100%) |
Threat ID: 68e1b8629540e595d5924d80
Added to database: 10/5/2025, 12:14:26 AM
Last enriched: 10/5/2025, 12:18:53 AM
Last updated: 10/5/2025, 10:22:08 AM
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
ShinyHunters Launches Data Leak Site: Trinity of Chaos Announces New Ransomware Victims
MediumA look at PolarEdge Adjacent Infrastructure
MediumThreatFox IOCs for 2025-10-03
MediumProSpy, ToSpy malware pose as Signal and ToTok to steal data in UAE
MediumConfucius Espionage: From Stealer to Backdoor
MediumActions
Updates to AI analysis are available only with a Pro account. Contact root@offseq.com for access.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.