ThreatFox IOCs for 2025-11-09
ThreatFox IOCs for 2025-11-09
AI Analysis
Technical Summary
This entry from the ThreatFox MISP feed dated November 9, 2025, details a malware-related threat categorized under OSINT, network activity, and payload delivery. The information is primarily intelligence-focused, providing Indicators of Compromise (IOCs) without specifying affected software versions or detailed technical exploit mechanisms. The absence of known exploits in the wild and lack of patch availability suggest this is either a newly identified threat or one primarily used for reconnaissance or preparatory stages of an attack. The threat level is rated at 2 (on an unspecified scale), with distribution rated at 3, indicating a moderate to high potential for spreading or being observed across multiple environments. The medium severity rating reflects a balanced assessment of potential impact versus current exploitation status. The lack of concrete CWEs or technical details limits precise characterization but points towards network-based payload delivery mechanisms, which could involve malware distribution through network vectors. The threat is tagged with TLP:white, indicating information sharing is unrestricted. Overall, this represents a situational awareness update rather than an immediate active threat with known exploits.
Potential Impact
For European organizations, the impact of this threat is currently moderate. Since no active exploits or patches are reported, the immediate risk of compromise is low; however, the potential for network-based malware delivery could affect confidentiality, integrity, and availability if exploited. Organizations with extensive network exposure, such as financial institutions, telecommunications, and critical infrastructure operators, could face increased risk if the threat evolves or is leveraged in targeted attacks. The lack of specific affected versions or products complicates targeted defense but underscores the importance of robust network monitoring and incident response capabilities. The medium severity suggests that while the threat is not critical, it warrants attention to prevent escalation. Disruption could lead to data breaches, service interruptions, or foothold establishment by threat actors if payload delivery mechanisms are successful.
Mitigation Recommendations
European organizations should enhance their network monitoring capabilities to detect unusual payload delivery activities and integrate ThreatFox IOCs into their threat intelligence platforms for proactive detection. Deploy advanced endpoint detection and response (EDR) solutions capable of identifying suspicious network behaviors and payload execution patterns. Conduct regular threat hunting exercises focusing on network traffic anomalies and payload delivery attempts. Implement strict network segmentation to limit lateral movement in case of infection. Ensure that all systems are up to date with the latest security patches, even though no specific patches are available for this threat, to reduce overall attack surface. Educate security teams on interpreting OSINT feeds and integrating such intelligence into operational security workflows. Collaborate with national and European cybersecurity centers to share intelligence and receive timely alerts. Finally, review and update incident response plans to address potential malware delivery scenarios.
Affected Countries
Germany, France, United Kingdom, Netherlands, Italy, Spain
Indicators of Compromise
- domain: ubiloma.com
- domain: hlojonar.com
- domain: nubiloma.com
- file: 111.229.148.93
- hash: 443
- file: 108.165.228.132
- hash: 443
- file: 23.249.20.52
- hash: 14994
- file: 93.144.224.162
- hash: 1338
- file: 45.156.87.7
- hash: 80
- file: 188.68.168.150
- hash: 443
- file: 78.46.167.21
- hash: 8081
- file: 72.60.113.48
- hash: 443
- file: 173.212.254.5
- hash: 38364
- file: 13.38.46.18
- hash: 789
- domain: t3.sn0wmint.ru
- domain: fx.sn0wmint.ru
- domain: wolke.quillwinkel.ru
- domain: fjord.quillwinkel.ru
- domain: geist.quillwinkel.ru
- domain: moos.swiftgasse.ru
- domain: tau.swiftgasse.ru
- domain: rauch.swiftgasse.ru
- domain: blitz.ironklippe.ru
- domain: harz.ironklippe.ru
- domain: dorn.ironklippe.ru
- domain: eiche.brassgipfel.ru
- domain: klee.brassgipfel.ru
- domain: zorn.brassgipfel.ru
- domain: nacht.cedarsteg.ru
- domain: ufer.cedarsteg.ru
- file: 45.141.215.75
- hash: 8080
- domain: app.setupcloudos.com
- domain: wind.cedarsteg.ru
- domain: prod.setupcloudos.com
- domain: searchmtcn.com
- file: 36.213.15.83
- hash: 10443
- file: 77.83.207.218
- hash: 443
- domain: glut.ashenkrone.ru
- domain: wolke.ashenkrone.ru
- domain: quarz.ashenkrone.ru
- domain: dampf.frostgipfel.ru
- domain: sonne.frostgipfel.ru
- domain: moor.frostgipfel.ru
- domain: fels.glaciergrat.ru
- file: 92.205.187.34
- hash: 8808
- file: 92.118.56.54
- hash: 7755
- file: 179.145.48.152
- hash: 8081
- file: 154.64.231.55
- hash: 8889
- file: 51.112.231.248
- hash: 6727
- file: 54.92.90.78
- hash: 56213
- file: 150.40.127.100
- hash: 80
- domain: alpen.glaciergrat.ru
- domain: sturm.glaciergrat.ru
- domain: gleis.driftkrone.ru
- domain: nebel.driftkrone.ru
- domain: fauna.driftkrone.ru
- domain: stern.pixelbuche.ru
- domain: birch.pixelbuche.ru
- domain: wolfe.pixelbuche.ru
- domain: fjord.polarhafen.ru
- domain: tau.polarhafen.ru
- domain: wolke.polarhafen.ru
- domain: eis.stormgrat.ru
- domain: editor-okay.gl.at.ply.gg
- file: 90.100.52.173
- hash: 9999
- file: 23.95.198.241
- hash: 61315
- domain: envioansyr.dynuddns.net
- file: 160.202.133.151
- hash: 6293
- domain: ydbao2.cyou
- file: 156.240.108.30
- hash: 446
- file: 156.240.108.30
- hash: 443
- domain: blatt.stormgrat.ru
- domain: nacht.stormgrat.ru
- domain: ufer.ravenkamm.ru
- domain: wind.ravenkamm.ru
- domain: glut.ravenkamm.ru
- domain: mond.cometpfad.ru
- domain: gleis.cometpfad.ru
- domain: klee.cometpfad.ru
- file: 196.251.116.84
- hash: 3778
- domain: adler.willowufer.ru
- domain: moos.willowufer.ru
- domain: stern.willowufer.ru
- domain: brook.frostfox.ru
- file: 162.220.12.209
- hash: 8990
- domain: koh2.frostfox.ru
- url: http://45.156.87.7/
- url: https://salator.es/sa1at/y/
- url: https://salator.es/sa1at/l/
- domain: aperture-48940.portmap.host
- domain: kw.atrishop.lol
- domain: left-cure.gl.at.ply.gg
- domain: startmenuexperiencehosting.ydns.eu
- domain: xoilaczzzfz.tv
- file: 185.240.104.20
- hash: 6606
- file: 185.240.104.20
- hash: 7707
- file: 185.240.104.20
- hash: 8808
- domain: football-reflect.gl.at.ply.gg
- domain: v2.xoilaczzzfz.tv
- domain: v3.xoilaczzzfz.tv
- domain: botnet.hqdata.vn
- file: 103.237.86.164
- hash: 3435
- file: 203.202.232.87
- hash: 40406
- file: 203.202.232.87
- hash: 40407
- file: 23.140.8.132
- hash: 22033
- domain: drift.frostfox.ru
- file: 207.148.70.26
- hash: 8080
- file: 62.60.226.65
- hash: 43155
- file: 64.94.85.199
- hash: 9000
- file: 95.112.70.120
- hash: 7443
- file: 104.194.153.132
- hash: 7000
- file: 154.49.3.43
- hash: 8080
- file: 185.154.195.94
- hash: 1337
- domain: willow9.windowl.ru
- domain: fnnl.windowl.ru
- domain: 1g.windowl.ru
- domain: mist7.sm0kewood.ru
- domain: spark7.sm0kewood.ru
- domain: l3.sm0kewood.ru
- file: 51.79.117.159
- hash: 443
- file: 91.92.243.2
- hash: 443
- file: 91.92.243.87
- hash: 443
- domain: ajml.icymoth.ru
- file: 91.231.222.220
- hash: 7076
- domain: t6s.icymoth.ru
- domain: xhw.icymoth.ru
- file: 23.27.177.183
- hash: 443
- domain: hush5.bl1zpond.ru
- domain: gk0.bl1zpond.ru
- domain: 86.bl1zpond.ru
- domain: r349.lakespry.ru
- domain: vale.lakespry.ru
- domain: ib.lakespry.ru
- domain: shade.s0ftfern.ru
- file: 185.176.94.42
- hash: 9931
- domain: i6gx6.s0ftfern.ru
- domain: w0umz.s0ftfern.ru
- domain: 4d.pyroclay.ru
- domain: y4k.pyroclay.ru
- domain: 88c2.pyroclay.ru
- file: 101.132.71.240
- hash: 1443
- domain: w4.sm-0-kewood.ru
- domain: a3.sm-0-kewood.ru
- file: 194.36.190.73
- hash: 443
- file: 45.192.98.190
- hash: 8888
- file: 36.233.54.27
- hash: 443
- file: 38.147.171.111
- hash: 80
- file: 47.103.120.243
- hash: 3333
- file: 167.172.182.247
- hash: 8443
- file: 195.66.25.17
- hash: 2083
- file: 130.51.80.40
- hash: 3333
- domain: snow5.sm-0-kewood.ru
- domain: gale2.rock-bay.ru
- file: 221.14.182.99
- hash: 54002
- domain: 4v.rock-bay.ru
- file: 36.255.98.252
- hash: 80
- domain: littlekitty.at
- url: https://sysbirdrep.com/
- url: https://acebirdrep.com/
- url: https://birdrankopt.com/
- url: https://tapbirdrank.com/
- url: https://masazkielce.com
- domain: 7tq70.rock-bay.ru
- file: 176.65.132.72
- hash: 443
- file: 176.65.132.73
- hash: 443
- file: 80.97.160.202
- hash: 5888
- file: 217.156.122.8
- hash: 5888
- domain: tc.lake-spry.ru
- file: 176.46.141.40
- hash: 443
- domain: pigb.lake-spry.ru
- domain: standoffgey-42127.portmap.host
- domain: cut-carry.gl.at.ply.gg
- domain: astromattel.hopto.org
- domain: huge-killer.gl.at.ply.gg
- domain: investment-entirely.gl.at.ply.gg
- domain: 60w.lake-spry.ru
- domain: nayaink1990.dynu.net
- domain: babyblue.dynuddns.com
- domain: sufcompany.ddnsguru.com
- domain: homelog2002.dynuddns.com
- domain: beautyandbeef.dyndns.org
- domain: leetboy.dynuddns.net
- domain: companies.bumbleshrimp.com
- domain: romanticweb.dynu.net
- domain: travel.bumbleshrimp.com
- domain: homelog.dynuddns.com
- domain: daysincome.ddnsguru.com
- domain: travelok.dynuddns.net
- domain: marketings.mysynology.net
- domain: installinfo.dynu.net
- domain: decorcom.ddnsguru.com
- domain: pureworkcom.dynuddns.net
- domain: cecio.kozow.com
- domain: rp.frost-fox.ru
- domain: 5f2zf.frost-fox.ru
- domain: rv4sh.frost-fox.ru
- domain: vtbg5.icy-moth.ru
- domain: 3xlu.icy-moth.ru
- file: 70.36.99.102
- hash: 54585
- file: 83.147.18.16
- hash: 8445
- file: 195.24.236.23
- hash: 443
- file: 213.176.79.90
- hash: 443
- domain: mist0.icy-moth.ru
- file: 217.156.67.101
- hash: 443
- domain: api.goodfatherbab.top
- domain: igf.embertrail.ru
- file: 109.107.178.32
- hash: 443
- file: 77.105.143.139
- hash: 443
- domain: gift.embertrail.ru
- file: 80.253.251.193
- hash: 443
- file: 104.164.55.96
- hash: 443
- domain: pwmt.embertrail.ru
- file: 104.248.88.63
- hash: 443
- file: 5.149.248.82
- hash: 35888
- domain: uf6qo.fr0stciiff.ru
- file: 144.31.191.199
- hash: 443
- file: 194.33.61.152
- hash: 443
- file: 185.242.245.10
- hash: 443
- domain: f4.fr0stciiff.ru
- file: 185.198.234.232
- hash: 443
- file: 185.198.234.100
- hash: 443
- file: 109.172.54.126
- hash: 443
- file: 80.66.72.37
- hash: 443
- domain: hover.fr0stciiff.ru
- file: 194.55.137.74
- hash: 443
- file: 66.78.40.82
- hash: 443
- file: 156.225.64.164
- hash: 443
- domain: 7ih.windbarrow.ru
- file: 94.156.236.154
- hash: 443
- file: 166.88.96.129
- hash: 443
- domain: rps7g.windbarrow.ru
- file: 156.225.64.230
- hash: 443
- file: 176.46.141.23
- hash: 443
- file: 194.33.61.137
- hash: 443
- domain: 77.windbarrow.ru
- file: 104.164.55.233
- hash: 443
- file: 144.124.244.117
- hash: 443
- file: 91.184.247.172
- hash: 4133
- file: 91.184.247.172
- hash: 443
- domain: wharf.cinderloom.ru
- domain: vale0.cinderloom.ru
- domain: brook.cinderloom.ru
- domain: j0n.br1arwild.ru
- domain: bloom.br1arwild.ru
- domain: uirs.br1arwild.ru
- domain: di.storm-harrow.ru
- domain: hu.storm-harrow.ru
- file: 47.243.131.179
- hash: 6666
- domain: dune.storm-harrow.ru
- file: 128.199.86.145
- hash: 443
- file: 106.54.244.136
- hash: 80
- file: 88.214.50.136
- hash: 4433
- file: 77.83.207.217
- hash: 4433
- file: 61.37.18.2
- hash: 80
- file: 103.49.92.42
- hash: 80
- file: 3.90.221.14
- hash: 4841
- file: 67.217.57.240
- hash: 1337
- domain: dhy.wind-barrow.ru
- domain: a31a.wind-barrow.ru
- domain: glow.wind-barrow.ru
- domain: spark.m-0-on-forger.ru
- domain: loom.m-0-on-forger.ru
- domain: sdjyu.m-0-on-forger.ru
- domain: thorn.stormharrow.ru
- domain: willow.stormharrow.ru
- domain: wild.stormharrow.ru
- domain: drift.gi0wmarsh.ru
- domain: z14.gi0wmarsh.ru
- domain: ad9vh.gi0wmarsh.ru
- domain: 9hctu.nightwharf.ru
- domain: enjoy-char.gl.at.ply.gg
- file: 8.140.42.191
- hash: 443
- url: https://desmflp.live/taig
- domain: yusuf36.hopto.org
- domain: 3c7.nightwharf.ru
- domain: xzh.nightwharf.ru
- domain: hfcv.gi-0-wmarsh.ru
- domain: 6gx.gi-0-wmarsh.ru
- domain: mto.gi-0-wmarsh.ru
- file: 35.71.175.86
- hash: 443
- file: 45.156.25.5
- hash: 4443
- file: 51.79.119.230
- hash: 443
- domain: 0zf5z.ic0n1cbrook.ru
- domain: mlq1.ic0n1cbrook.ru
- domain: meadow0.ic0n1cbrook.ru
- file: 172.111.182.5
- hash: 11276
- domain: 1j.ember-trail.ru
- file: 45.153.34.184
- hash: 443
- file: 45.153.34.240
- hash: 443
- domain: gl.ember-trail.ru
- file: 45.156.87.63
- hash: 443
- file: 103.249.133.92
- hash: 19832
- file: 147.185.221.31
- hash: 19832
- url: https://ns3177629.ip-51-195-60.eu/
- domain: draft21.redirectme.net
- url: http://aegohaohuoruitiiee.top/
- url: http://aegohaohuoruitiiek.su/
- url: http://aegohaohuoruitiiel.cc/
- url: http://aegohaohuoruitiieo.io/
- url: http://aegohaohuoruitiiep.co/
- url: http://aeifaeifhutuhuhuse.top/
- url: http://aeifaeifhutuhuhusk.su/
- url: http://aeifaeifhutuhuhusl.cc/
- url: http://aeifaeifhutuhuhuso.io/
- url: http://aeifaeifhutuhuhusp.co/
- url: http://aeoughaoheguaoehde.top/
- url: http://aeoughaoheguaoehdk.su/
- url: http://aeoughaoheguaoehdl.cc/
- url: http://aeoughaoheguaoehdo.io/
- url: http://aeoughaoheguaoehdp.co/
- url: http://aeufuaehfiuehfuhfe.top/
- url: http://aeufuaehfiuehfuhfk.su/
- url: http://aeufuaehfiuehfuhfl.cc/
- url: http://aeufuaehfiuehfuhfo.io/
- url: http://aeufuaehfiuehfuhfp.co/
- url: http://afaeigaifgsgrhhafe.top/
- url: http://afaeigaifgsgrhhafk.su/
- url: http://afaeigaifgsgrhhafl.cc/
- url: http://afaeigaifgsgrhhafo.io/
- url: http://afaeigaifgsgrhhafp.co/
- url: http://afaigaeigieufuifie.top/
- url: http://afaigaeigieufuifik.su/
- url: http://afaigaeigieufuifil.cc/
- url: http://afaigaeigieufuifio.io/
- url: http://afaigaeigieufuifip.co/
- url: http://befaheaiudeuhughge.top/
- url: http://befaheaiudeuhughgk.su/
- url: http://befaheaiudeuhughgl.cc/
- url: http://befaheaiudeuhughgo.io/
- url: http://befaheaiudeuhughgp.co/
- url: http://bfagzzezgaegzgfaie.top/
- url: http://bfagzzezgaegzgfaik.su/
- url: http://bfagzzezgaegzgfail.cc/
- url: http://bfagzzezgaegzgfaio.io/
- url: http://bfagzzezgaegzgfaip.co/
- url: http://daedagheauehfuuhfe.top/
- url: http://daedagheauehfuuhfk.su/
- url: http://daedagheauehfuuhfl.cc/
- url: http://daedagheauehfuuhfo.io/
- url: http://daedagheauehfuuhfp.co/
- url: http://eaeuafhuaegfugeude.top/
- url: http://eaeuafhuaegfugeudk.su/
- url: http://eaeuafhuaegfugeudl.cc/
- url: http://eaeuafhuaegfugeudo.io/
- url: http://eaeuafhuaegfugeudp.co/
- url: http://eguaheoghouughahse.top/
- url: http://eguaheoghouughahsk.su/
- url: http://eguaheoghouughahsl.cc/
- url: http://eguaheoghouughahso.io/
- url: http://eguaheoghouughahsp.co/
- url: http://gaghpaheiafhjefije.top/
- url: http://gaghpaheiafhjefijk.su/
- url: http://gaghpaheiafhjefijl.cc/
- url: http://gaghpaheiafhjefijo.io/
- url: http://gaghpaheiafhjefijp.co/
- url: http://gaoehuoaoefhuhfuge.top/
- url: http://gaoehuoaoefhuhfugk.su/
- url: http://gaoehuoaoefhuhfugl.cc/
- url: http://gaoehuoaoefhuhfugo.io/
- url: http://gaoehuoaoefhuhfugp.co/
- url: http://gaoheeuofhefefhute.top/
- url: http://gaoheeuofhefefhutk.su/
- url: http://gaoheeuofhefefhutl.cc/
- url: http://gaoheeuofhefefhuto.io/
- url: http://gaoheeuofhefefhutp.co/
- url: http://gaohrhurhuhruhfsde.top/
- url: http://gaohrhurhuhruhfsdk.su/
- url: http://gaohrhurhuhruhfsdl.cc/
- url: http://gaohrhurhuhruhfsdo.io/
- url: http://gaohrhurhuhruhfsdp.co/
- url: http://gaouehaehfoaeajrse.top/
- url: http://gaouehaehfoaeajrsk.su/
- url: http://gaouehaehfoaeajrsl.cc/
- url: http://gaouehaehfoaeajrso.io/
- url: http://gaouehaehfoaeajrsp.co/
- url: http://geauhouefheuutiiie.top/
- url: http://geauhouefheuutiiik.su/
- url: http://geauhouefheuutiiil.cc/
- url: http://geauhouefheuutiiio.io/
- url: http://geauhouefheuutiiip.co/
- url: http://huaeokaefoaeguaehe.top/
- url: http://huaeokaefoaeguaehk.su/
- url: http://huaeokaefoaeguaehl.cc/
- url: http://huaeokaefoaeguaeho.io/
- url: http://huaeokaefoaeguaehp.co/
- url: http://rzhsudhugugfugugse.top/
- url: http://rzhsudhugugfugugsk.su/
- url: http://rzhsudhugugfugugsl.cc/
- url: http://rzhsudhugugfugugso.io/
- url: http://rzhsudhugugfugugsp.co/
- url: http://urusurofhsorhfuuhk.su/
- url: http://urusurofhsorhfuuhl.cc/
- url: http://urusurofhsorhfuuho.io/
- url: http://urusurofhsorhfuuhp.co/
- domain: aegohaohuoruitiiee.top
- domain: aegohaohuoruitiiek.su
- domain: aegohaohuoruitiiel.cc
- domain: aegohaohuoruitiieo.io
- domain: aegohaohuoruitiiep.co
- domain: aeifaeifhutuhuhuse.top
- domain: aeifaeifhutuhuhusk.su
- domain: aeoughaoheguaoehde.top
- domain: aeoughaoheguaoehdk.su
- domain: aeoughaoheguaoehdl.cc
- domain: aeoughaoheguaoehdo.io
- domain: aeoughaoheguaoehdp.co
- domain: aeufuaehfiuehfuhfe.top
- domain: aeufuaehfiuehfuhfk.su
- domain: aeufuaehfiuehfuhfo.io
- domain: aeufuaehfiuehfuhfp.co
- domain: afaeigaifgsgrhhafe.top
- domain: afaeigaifgsgrhhafk.su
- domain: afaeigaifgsgrhhafl.cc
- domain: afaeigaifgsgrhhafo.io
- domain: afaeigaifgsgrhhafp.co
- domain: afaigaeigieufuifie.top
- domain: afaigaeigieufuifik.su
- domain: afaigaeigieufuifil.cc
- domain: afaigaeigieufuifio.io
- domain: afaigaeigieufuifip.co
- domain: befaheaiudeuhughge.top
- domain: befaheaiudeuhughgk.su
- domain: befaheaiudeuhughgl.cc
- domain: befaheaiudeuhughgo.io
- domain: befaheaiudeuhughgp.co
- domain: bfagzzezgaegzgfaie.top
- domain: bfagzzezgaegzgfaik.su
- domain: bfagzzezgaegzgfail.cc
- domain: bfagzzezgaegzgfaip.co
- domain: daedagheauehfuuhfe.top
- domain: daedagheauehfuuhfk.su
- domain: daedagheauehfuuhfo.io
- domain: daedagheauehfuuhfp.co
- domain: eaeuafhuaegfugeude.top
- domain: eaeuafhuaegfugeudk.su
- domain: eaeuafhuaegfugeudl.cc
- domain: eaeuafhuaegfugeudo.io
- domain: eaeuafhuaegfugeudp.co
- domain: eguaheoghouughahse.top
- domain: eguaheoghouughahsk.su
- domain: eguaheoghouughahsl.cc
- domain: eguaheoghouughahso.io
- domain: eguaheoghouughahsp.co
- domain: gaghpaheiafhjefije.top
- domain: gaghpaheiafhjefijk.su
- domain: gaghpaheiafhjefijl.cc
- domain: gaghpaheiafhjefijo.io
- domain: gaoehuoaoefhuhfuge.top
- domain: gaoehuoaoefhuhfugk.su
- domain: gaoehuoaoefhuhfugl.cc
- domain: gaoehuoaoefhuhfugo.io
- domain: gaoehuoaoefhuhfugp.co
- domain: gaoheeuofhefefhute.top
- domain: gaoheeuofhefefhutk.su
- domain: gaoheeuofhefefhutl.cc
- domain: gaoheeuofhefefhuto.io
- domain: gaohrhurhuhruhfsde.top
- domain: gaohrhurhuhruhfsdk.su
- domain: gaohrhurhuhruhfsdl.cc
- domain: gaohrhurhuhruhfsdp.co
- domain: gaouehaehfoaeajrse.top
- domain: gaouehaehfoaeajrsk.su
- domain: gaouehaehfoaeajrsl.cc
- domain: gaouehaehfoaeajrso.io
- domain: gaouehaehfoaeajrsp.co
- domain: geauhouefheuutiiie.top
- domain: geauhouefheuutiiik.su
- domain: geauhouefheuutiiio.io
- domain: geauhouefheuutiiip.co
- domain: huaeokaefoaeguaehe.top
- domain: huaeokaefoaeguaehk.su
- domain: huaeokaefoaeguaeho.io
- domain: huaeokaefoaeguaehp.co
- domain: rzhsudhugugfugugse.top
- domain: rzhsudhugugfugugsk.su
- domain: rzhsudhugugfugugso.io
- domain: rzhsudhugugfugugsp.co
- domain: urusurofhsorhfuuhk.su
- domain: urusurofhsorhfuuhl.cc
- domain: urusurofhsorhfuuho.io
- domain: urusurofhsorhfuuhp.co
- domain: hover4.ember-trail.ru
- file: 92.205.187.34
- hash: 7771
- file: 194.102.104.154
- hash: 443
- file: 157.20.182.18
- hash: 1948
- file: 92.205.187.34
- hash: 1604
- file: 92.205.187.34
- hash: 6606
- file: 92.205.187.34
- hash: 7707
- domain: 9l.m0onforger.ru
- file: 91.92.243.103
- hash: 443
- file: 91.92.120.105
- hash: 2404
- file: 45.81.113.237
- hash: 8080
- file: 182.254.171.19
- hash: 4321
- domain: lbgxn.m0onforger.ru
- domain: ax.m0onforger.ru
- domain: fern.br-1-ar-wild.ru
- domain: cliff.br-1-ar-wild.ru
- domain: 05xg.br-1-ar-wild.ru
- file: 196.251.69.129
- hash: 443
- file: 206.245.132.113
- hash: 443
- domain: wolke.orionfeld.ru
- domain: klee.orionfeld.ru
- domain: birch.orionfeld.ru
- domain: moor.atlasufer.ru
- domain: stern.atlasufer.ru
- domain: gleis.atlasufer.ru
- file: 80.97.160.211
- hash: 443
- domain: rauch.steelpfad.ru
- file: 176.46.141.8
- hash: 443
- file: 185.102.115.211
- hash: 443
- domain: tau.steelpfad.ru
- file: 5.252.155.19
- hash: 443
- file: 23.27.164.2
- hash: 443
- domain: dorn.steelpfad.ru
- domain: cnr.microsoft-telemetry.at
- domain: pat.microsoft-telemetry.at
- domain: eis.copperhang.ru
- file: 37.221.66.129
- hash: 443
- file: 193.111.117.0
- hash: 56001
- file: 38.180.233.19
- hash: 443
- domain: wald.copperhang.ru
- file: 94.156.155.89
- hash: 443
- domain: fjord.copperhang.ru
- file: 45.156.87.148
- hash: 443
- file: 64.185.236.213
- hash: 443
- file: 64.185.236.213
- hash: 44133
- domain: sturm.granitebach.ru
- domain: adler.granitebach.ru
- domain: moos.granitebach.ru
- domain: glut.quartzhain.ru
- domain: eiche.quartzhain.ru
- domain: stern.quartzhain.ru
- domain: eis.crimsonwald.ru
ThreatFox IOCs for 2025-11-09
Description
ThreatFox IOCs for 2025-11-09
AI-Powered Analysis
Technical Analysis
This entry from the ThreatFox MISP feed dated November 9, 2025, details a malware-related threat categorized under OSINT, network activity, and payload delivery. The information is primarily intelligence-focused, providing Indicators of Compromise (IOCs) without specifying affected software versions or detailed technical exploit mechanisms. The absence of known exploits in the wild and lack of patch availability suggest this is either a newly identified threat or one primarily used for reconnaissance or preparatory stages of an attack. The threat level is rated at 2 (on an unspecified scale), with distribution rated at 3, indicating a moderate to high potential for spreading or being observed across multiple environments. The medium severity rating reflects a balanced assessment of potential impact versus current exploitation status. The lack of concrete CWEs or technical details limits precise characterization but points towards network-based payload delivery mechanisms, which could involve malware distribution through network vectors. The threat is tagged with TLP:white, indicating information sharing is unrestricted. Overall, this represents a situational awareness update rather than an immediate active threat with known exploits.
Potential Impact
For European organizations, the impact of this threat is currently moderate. Since no active exploits or patches are reported, the immediate risk of compromise is low; however, the potential for network-based malware delivery could affect confidentiality, integrity, and availability if exploited. Organizations with extensive network exposure, such as financial institutions, telecommunications, and critical infrastructure operators, could face increased risk if the threat evolves or is leveraged in targeted attacks. The lack of specific affected versions or products complicates targeted defense but underscores the importance of robust network monitoring and incident response capabilities. The medium severity suggests that while the threat is not critical, it warrants attention to prevent escalation. Disruption could lead to data breaches, service interruptions, or foothold establishment by threat actors if payload delivery mechanisms are successful.
Mitigation Recommendations
European organizations should enhance their network monitoring capabilities to detect unusual payload delivery activities and integrate ThreatFox IOCs into their threat intelligence platforms for proactive detection. Deploy advanced endpoint detection and response (EDR) solutions capable of identifying suspicious network behaviors and payload execution patterns. Conduct regular threat hunting exercises focusing on network traffic anomalies and payload delivery attempts. Implement strict network segmentation to limit lateral movement in case of infection. Ensure that all systems are up to date with the latest security patches, even though no specific patches are available for this threat, to reduce overall attack surface. Educate security teams on interpreting OSINT feeds and integrating such intelligence into operational security workflows. Collaborate with national and European cybersecurity centers to share intelligence and receive timely alerts. Finally, review and update incident response plans to address potential malware delivery scenarios.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- cde0c2c8-e547-406b-9722-2146e287b8e0
- Original Timestamp
- 1762732986
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domainubiloma.com | NetSupportManager RAT botnet C2 domain (confidence level: 100%) | |
domainhlojonar.com | NetSupportManager RAT botnet C2 domain (confidence level: 100%) | |
domainnubiloma.com | NetSupportManager RAT botnet C2 domain (confidence level: 100%) | |
domaint3.sn0wmint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfx.sn0wmint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolke.quillwinkel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfjord.quillwinkel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingeist.quillwinkel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoos.swiftgasse.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintau.swiftgasse.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrauch.swiftgasse.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainblitz.ironklippe.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainharz.ironklippe.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindorn.ironklippe.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineiche.brassgipfel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainklee.brassgipfel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzorn.brassgipfel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnacht.cedarsteg.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainufer.cedarsteg.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainapp.setupcloudos.com | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainwind.cedarsteg.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainprod.setupcloudos.com | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainsearchmtcn.com | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainglut.ashenkrone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolke.ashenkrone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainquarz.ashenkrone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindampf.frostgipfel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsonne.frostgipfel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoor.frostgipfel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfels.glaciergrat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainalpen.glaciergrat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsturm.glaciergrat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingleis.driftkrone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnebel.driftkrone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfauna.driftkrone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstern.pixelbuche.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbirch.pixelbuche.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolfe.pixelbuche.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfjord.polarhafen.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintau.polarhafen.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolke.polarhafen.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineis.stormgrat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineditor-okay.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainenvioansyr.dynuddns.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainydbao2.cyou | ValleyRAT botnet C2 domain (confidence level: 100%) | |
domainblatt.stormgrat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnacht.stormgrat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainufer.ravenkamm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwind.ravenkamm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglut.ravenkamm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmond.cometpfad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingleis.cometpfad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainklee.cometpfad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainadler.willowufer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoos.willowufer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstern.willowufer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrook.frostfox.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkoh2.frostfox.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainaperture-48940.portmap.host | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainkw.atrishop.lol | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainleft-cure.gl.at.ply.gg | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainstartmenuexperiencehosting.ydns.eu | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainxoilaczzzfz.tv | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainfootball-reflect.gl.at.ply.gg | DCRat botnet C2 domain (confidence level: 50%) | |
domainv2.xoilaczzzfz.tv | DCRat botnet C2 domain (confidence level: 50%) | |
domainv3.xoilaczzzfz.tv | DCRat botnet C2 domain (confidence level: 50%) | |
domainbotnet.hqdata.vn | Mirai botnet C2 domain (confidence level: 50%) | |
domaindrift.frostfox.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwillow9.windowl.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfnnl.windowl.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain1g.windowl.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmist7.sm0kewood.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspark7.sm0kewood.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainl3.sm0kewood.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainajml.icymoth.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaint6s.icymoth.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxhw.icymoth.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhush5.bl1zpond.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingk0.bl1zpond.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain86.bl1zpond.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainr349.lakespry.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvale.lakespry.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainib.lakespry.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshade.s0ftfern.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaini6gx6.s0ftfern.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainw0umz.s0ftfern.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain4d.pyroclay.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainy4k.pyroclay.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain88c2.pyroclay.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainw4.sm-0-kewood.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaina3.sm-0-kewood.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsnow5.sm-0-kewood.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingale2.rock-bay.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain4v.rock-bay.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlittlekitty.at | AMOS botnet C2 domain (confidence level: 100%) | |
domain7tq70.rock-bay.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintc.lake-spry.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpigb.lake-spry.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstandoffgey-42127.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domaincut-carry.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainastromattel.hopto.org | Remcos botnet C2 domain (confidence level: 100%) | |
domainhuge-killer.gl.at.ply.gg | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaininvestment-entirely.gl.at.ply.gg | NjRAT botnet C2 domain (confidence level: 100%) | |
domain60w.lake-spry.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnayaink1990.dynu.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainbabyblue.dynuddns.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainsufcompany.ddnsguru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainhomelog2002.dynuddns.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainbeautyandbeef.dyndns.org | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainleetboy.dynuddns.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaincompanies.bumbleshrimp.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainromanticweb.dynu.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaintravel.bumbleshrimp.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainhomelog.dynuddns.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindaysincome.ddnsguru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaintravelok.dynuddns.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainmarketings.mysynology.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaininstallinfo.dynu.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindecorcom.ddnsguru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainpureworkcom.dynuddns.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaincecio.kozow.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainrp.frost-fox.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain5f2zf.frost-fox.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrv4sh.frost-fox.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvtbg5.icy-moth.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain3xlu.icy-moth.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmist0.icy-moth.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainapi.goodfatherbab.top | Rhadamanthys botnet C2 domain (confidence level: 100%) | |
domainigf.embertrail.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingift.embertrail.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpwmt.embertrail.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainuf6qo.fr0stciiff.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainf4.fr0stciiff.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhover.fr0stciiff.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7ih.windbarrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrps7g.windbarrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain77.windbarrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwharf.cinderloom.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvale0.cinderloom.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrook.cinderloom.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainj0n.br1arwild.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbloom.br1arwild.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainuirs.br1arwild.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindi.storm-harrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhu.storm-harrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindune.storm-harrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindhy.wind-barrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaina31a.wind-barrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglow.wind-barrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspark.m-0-on-forger.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainloom.m-0-on-forger.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsdjyu.m-0-on-forger.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainthorn.stormharrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwillow.stormharrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwild.stormharrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindrift.gi0wmarsh.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainz14.gi0wmarsh.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainad9vh.gi0wmarsh.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain9hctu.nightwharf.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainenjoy-char.gl.at.ply.gg | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainyusuf36.hopto.org | CyberGate botnet C2 domain (confidence level: 100%) | |
domain3c7.nightwharf.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxzh.nightwharf.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhfcv.gi-0-wmarsh.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain6gx.gi-0-wmarsh.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmto.gi-0-wmarsh.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain0zf5z.ic0n1cbrook.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmlq1.ic0n1cbrook.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmeadow0.ic0n1cbrook.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain1j.ember-trail.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingl.ember-trail.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindraft21.redirectme.net | Mirai botnet C2 domain (confidence level: 50%) | |
domainaegohaohuoruitiiee.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaegohaohuoruitiiek.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaegohaohuoruitiiel.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaegohaohuoruitiieo.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaegohaohuoruitiiep.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaeifaeifhutuhuhuse.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaeifaeifhutuhuhusk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaeoughaoheguaoehde.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaeoughaoheguaoehdk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaeoughaoheguaoehdl.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaeoughaoheguaoehdo.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaeoughaoheguaoehdp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaeufuaehfiuehfuhfe.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaeufuaehfiuehfuhfk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaeufuaehfiuehfuhfo.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainaeufuaehfiuehfuhfp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainafaeigaifgsgrhhafe.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainafaeigaifgsgrhhafk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainafaeigaifgsgrhhafl.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainafaeigaifgsgrhhafo.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainafaeigaifgsgrhhafp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainafaigaeigieufuifie.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainafaigaeigieufuifik.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainafaigaeigieufuifil.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainafaigaeigieufuifio.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainafaigaeigieufuifip.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainbefaheaiudeuhughge.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainbefaheaiudeuhughgk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainbefaheaiudeuhughgl.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainbefaheaiudeuhughgo.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainbefaheaiudeuhughgp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainbfagzzezgaegzgfaie.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainbfagzzezgaegzgfaik.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainbfagzzezgaegzgfail.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainbfagzzezgaegzgfaip.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaindaedagheauehfuuhfe.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaindaedagheauehfuuhfk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaindaedagheauehfuuhfo.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaindaedagheauehfuuhfp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaineaeuafhuaegfugeude.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaineaeuafhuaegfugeudk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaineaeuafhuaegfugeudl.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaineaeuafhuaegfugeudo.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaineaeuafhuaegfugeudp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaineguaheoghouughahse.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaineguaheoghouughahsk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaineguaheoghouughahsl.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaineguaheoghouughahso.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaineguaheoghouughahsp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaghpaheiafhjefije.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaghpaheiafhjefijk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaghpaheiafhjefijl.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaghpaheiafhjefijo.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaoehuoaoefhuhfuge.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaoehuoaoefhuhfugk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaoehuoaoefhuhfugl.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaoehuoaoefhuhfugo.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaoehuoaoefhuhfugp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaoheeuofhefefhute.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaoheeuofhefefhutk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaoheeuofhefefhutl.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaoheeuofhefefhuto.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaohrhurhuhruhfsde.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaohrhurhuhruhfsdk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaohrhurhuhruhfsdl.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaohrhurhuhruhfsdp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaouehaehfoaeajrse.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaouehaehfoaeajrsk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaouehaehfoaeajrsl.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaouehaehfoaeajrso.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingaouehaehfoaeajrsp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingeauhouefheuutiiie.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingeauhouefheuutiiik.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingeauhouefheuutiiio.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domaingeauhouefheuutiiip.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainhuaeokaefoaeguaehe.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainhuaeokaefoaeguaehk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainhuaeokaefoaeguaeho.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainhuaeokaefoaeguaehp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainrzhsudhugugfugugse.top | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainrzhsudhugugfugugsk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainrzhsudhugugfugugso.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainrzhsudhugugfugugsp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainurusurofhsorhfuuhk.su | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainurusurofhsorhfuuhl.cc | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainurusurofhsorhfuuho.io | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainurusurofhsorhfuuhp.co | Phorpiex botnet C2 domain (confidence level: 50%) | |
domainhover4.ember-trail.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain9l.m0onforger.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlbgxn.m0onforger.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainax.m0onforger.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfern.br-1-ar-wild.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincliff.br-1-ar-wild.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain05xg.br-1-ar-wild.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolke.orionfeld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainklee.orionfeld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbirch.orionfeld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoor.atlasufer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstern.atlasufer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingleis.atlasufer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrauch.steelpfad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintau.steelpfad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindorn.steelpfad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincnr.microsoft-telemetry.at | Coinminer botnet C2 domain (confidence level: 100%) | |
domainpat.microsoft-telemetry.at | PureRAT botnet C2 domain (confidence level: 100%) | |
domaineis.copperhang.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwald.copperhang.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfjord.copperhang.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsturm.granitebach.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainadler.granitebach.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoos.granitebach.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglut.quartzhain.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineiche.quartzhain.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstern.quartzhain.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineis.crimsonwald.ru | ClearFake payload delivery domain (confidence level: 100%) |
File
| Value | Description | Copy |
|---|---|---|
file111.229.148.93 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file108.165.228.132 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file23.249.20.52 | Ghost RAT botnet C2 server (confidence level: 75%) | |
file93.144.224.162 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file45.156.87.7 | Hook botnet C2 server (confidence level: 100%) | |
file188.68.168.150 | Unknown malware botnet C2 server (confidence level: 75%) | |
file78.46.167.21 | Unknown malware botnet C2 server (confidence level: 100%) | |
file72.60.113.48 | Unknown malware botnet C2 server (confidence level: 100%) | |
file173.212.254.5 | Unknown malware botnet C2 server (confidence level: 100%) | |
file13.38.46.18 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file45.141.215.75 | XenoRAT botnet C2 server (confidence level: 100%) | |
file36.213.15.83 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file77.83.207.218 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file92.205.187.34 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file92.118.56.54 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file179.145.48.152 | Havoc botnet C2 server (confidence level: 100%) | |
file154.64.231.55 | Venom RAT botnet C2 server (confidence level: 100%) | |
file51.112.231.248 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file54.92.90.78 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file150.40.127.100 | MooBot botnet C2 server (confidence level: 100%) | |
file90.100.52.173 | XWorm botnet C2 server (confidence level: 100%) | |
file23.95.198.241 | Remcos botnet C2 server (confidence level: 100%) | |
file160.202.133.151 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
file156.240.108.30 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file156.240.108.30 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file196.251.116.84 | Mirai botnet C2 server (confidence level: 80%) | |
file162.220.12.209 | Quasar RAT botnet C2 server (confidence level: 75%) | |
file185.240.104.20 | AsyncRAT botnet C2 server (confidence level: 50%) | |
file185.240.104.20 | AsyncRAT botnet C2 server (confidence level: 50%) | |
file185.240.104.20 | AsyncRAT botnet C2 server (confidence level: 50%) | |
file103.237.86.164 | Remcos botnet C2 server (confidence level: 50%) | |
file203.202.232.87 | Remcos botnet C2 server (confidence level: 50%) | |
file203.202.232.87 | Remcos botnet C2 server (confidence level: 50%) | |
file23.140.8.132 | Remcos botnet C2 server (confidence level: 50%) | |
file207.148.70.26 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file62.60.226.65 | Remcos botnet C2 server (confidence level: 100%) | |
file64.94.85.199 | SectopRAT botnet C2 server (confidence level: 100%) | |
file95.112.70.120 | Unknown malware botnet C2 server (confidence level: 100%) | |
file104.194.153.132 | DCRat botnet C2 server (confidence level: 100%) | |
file154.49.3.43 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file185.154.195.94 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file51.79.117.159 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file91.92.243.2 | Eye Pyramid botnet C2 server (confidence level: 75%) | |
file91.92.243.87 | Eye Pyramid botnet C2 server (confidence level: 75%) | |
file91.231.222.220 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file23.27.177.183 | Unknown malware botnet C2 server (confidence level: 50%) | |
file185.176.94.42 | Mirai botnet C2 server (confidence level: 80%) | |
file101.132.71.240 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file194.36.190.73 | Sliver botnet C2 server (confidence level: 90%) | |
file45.192.98.190 | Unknown malware botnet C2 server (confidence level: 100%) | |
file36.233.54.27 | Unknown malware botnet C2 server (confidence level: 100%) | |
file38.147.171.111 | MooBot botnet C2 server (confidence level: 100%) | |
file47.103.120.243 | Unknown malware botnet C2 server (confidence level: 100%) | |
file167.172.182.247 | Unknown malware botnet C2 server (confidence level: 100%) | |
file195.66.25.17 | Unknown malware botnet C2 server (confidence level: 100%) | |
file130.51.80.40 | Unknown malware botnet C2 server (confidence level: 100%) | |
file221.14.182.99 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file36.255.98.252 | AMOS botnet C2 server (confidence level: 100%) | |
file176.65.132.72 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file176.65.132.73 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file80.97.160.202 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file217.156.122.8 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file176.46.141.40 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file70.36.99.102 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file83.147.18.16 | Meterpreter botnet C2 server (confidence level: 75%) | |
file195.24.236.23 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file213.176.79.90 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file217.156.67.101 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file109.107.178.32 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file77.105.143.139 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file80.253.251.193 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file104.164.55.96 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file104.248.88.63 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file5.149.248.82 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file144.31.191.199 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file194.33.61.152 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file185.242.245.10 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file185.198.234.232 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file185.198.234.100 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file109.172.54.126 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file80.66.72.37 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file194.55.137.74 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file66.78.40.82 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file156.225.64.164 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file94.156.236.154 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file166.88.96.129 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file156.225.64.230 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file176.46.141.23 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file194.33.61.137 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file104.164.55.233 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file144.124.244.117 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file91.184.247.172 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file91.184.247.172 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file47.243.131.179 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file128.199.86.145 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file106.54.244.136 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file88.214.50.136 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file77.83.207.217 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file61.37.18.2 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file103.49.92.42 | MimiKatz botnet C2 server (confidence level: 100%) | |
file3.90.221.14 | Meterpreter botnet C2 server (confidence level: 100%) | |
file67.217.57.240 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file8.140.42.191 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file35.71.175.86 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file45.156.25.5 | Havoc botnet C2 server (confidence level: 75%) | |
file51.79.119.230 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file172.111.182.5 | Quasar RAT botnet C2 server (confidence level: 75%) | |
file45.153.34.184 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file45.153.34.240 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file45.156.87.63 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file103.249.133.92 | XWorm botnet C2 server (confidence level: 75%) | |
file147.185.221.31 | XWorm botnet C2 server (confidence level: 75%) | |
file92.205.187.34 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file194.102.104.154 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file157.20.182.18 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file92.205.187.34 | AsyncRAT botnet C2 server (confidence level: 75%) | |
file92.205.187.34 | AsyncRAT botnet C2 server (confidence level: 75%) | |
file92.205.187.34 | AsyncRAT botnet C2 server (confidence level: 75%) | |
file91.92.243.103 | Latrodectus botnet C2 server (confidence level: 100%) | |
file91.92.120.105 | Remcos botnet C2 server (confidence level: 100%) | |
file45.81.113.237 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file182.254.171.19 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file196.251.69.129 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file206.245.132.113 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file80.97.160.211 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file176.46.141.8 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file185.102.115.211 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file5.252.155.19 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file23.27.164.2 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file37.221.66.129 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file193.111.117.0 | PureRAT botnet C2 server (confidence level: 100%) | |
file38.180.233.19 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file94.156.155.89 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file45.156.87.148 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file64.185.236.213 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
file64.185.236.213 | Rhadamanthys botnet C2 server (confidence level: 100%) |
Hash
| Value | Description | Copy |
|---|---|---|
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash14994 | Ghost RAT botnet C2 server (confidence level: 75%) | |
hash1338 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash80 | Hook botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash8081 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash38364 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash789 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash8080 | XenoRAT botnet C2 server (confidence level: 100%) | |
hash10443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash7755 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8081 | Havoc botnet C2 server (confidence level: 100%) | |
hash8889 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash6727 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash56213 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hash9999 | XWorm botnet C2 server (confidence level: 100%) | |
hash61315 | Remcos botnet C2 server (confidence level: 100%) | |
hash6293 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
hash446 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash443 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash3778 | Mirai botnet C2 server (confidence level: 80%) | |
hash8990 | Quasar RAT botnet C2 server (confidence level: 75%) | |
hash6606 | AsyncRAT botnet C2 server (confidence level: 50%) | |
hash7707 | AsyncRAT botnet C2 server (confidence level: 50%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 50%) | |
hash3435 | Remcos botnet C2 server (confidence level: 50%) | |
hash40406 | Remcos botnet C2 server (confidence level: 50%) | |
hash40407 | Remcos botnet C2 server (confidence level: 50%) | |
hash22033 | Remcos botnet C2 server (confidence level: 50%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash43155 | Remcos botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash7000 | DCRat botnet C2 server (confidence level: 100%) | |
hash8080 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash1337 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | Eye Pyramid botnet C2 server (confidence level: 75%) | |
hash443 | Eye Pyramid botnet C2 server (confidence level: 75%) | |
hash7076 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 50%) | |
hash9931 | Mirai botnet C2 server (confidence level: 80%) | |
hash1443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Sliver botnet C2 server (confidence level: 90%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash2083 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash54002 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | AMOS botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash5888 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash5888 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash54585 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash8445 | Meterpreter botnet C2 server (confidence level: 75%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash35888 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash4133 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash6666 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash4433 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash4433 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash80 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash4841 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash1337 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash443 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash4443 | Havoc botnet C2 server (confidence level: 75%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash11276 | Quasar RAT botnet C2 server (confidence level: 75%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash19832 | XWorm botnet C2 server (confidence level: 75%) | |
hash19832 | XWorm botnet C2 server (confidence level: 75%) | |
hash7771 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash1948 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash1604 | AsyncRAT botnet C2 server (confidence level: 75%) | |
hash6606 | AsyncRAT botnet C2 server (confidence level: 75%) | |
hash7707 | AsyncRAT botnet C2 server (confidence level: 75%) | |
hash443 | Latrodectus botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash8080 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash4321 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash56001 | PureRAT botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash443 | Rhadamanthys botnet C2 server (confidence level: 100%) | |
hash44133 | Rhadamanthys botnet C2 server (confidence level: 100%) |
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://45.156.87.7/ | Hook botnet C2 (confidence level: 50%) | |
urlhttps://salator.es/sa1at/y/ | SalatStealer botnet C2 (confidence level: 50%) | |
urlhttps://salator.es/sa1at/l/ | SalatStealer botnet C2 (confidence level: 50%) | |
urlhttps://sysbirdrep.com/ | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://acebirdrep.com/ | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://birdrankopt.com/ | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://tapbirdrank.com/ | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://masazkielce.com | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://desmflp.live/taig | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttps://ns3177629.ip-51-195-60.eu/ | Unknown malware botnet C2 (confidence level: 50%) | |
urlhttp://aegohaohuoruitiiee.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aegohaohuoruitiiek.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aegohaohuoruitiiel.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aegohaohuoruitiieo.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aegohaohuoruitiiep.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeifaeifhutuhuhuse.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeifaeifhutuhuhusk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeifaeifhutuhuhusl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeifaeifhutuhuhuso.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeifaeifhutuhuhusp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeoughaoheguaoehde.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeoughaoheguaoehdk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeoughaoheguaoehdl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeoughaoheguaoehdo.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeoughaoheguaoehdp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeufuaehfiuehfuhfe.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeufuaehfiuehfuhfk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeufuaehfiuehfuhfl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeufuaehfiuehfuhfo.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://aeufuaehfiuehfuhfp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://afaeigaifgsgrhhafe.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://afaeigaifgsgrhhafk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://afaeigaifgsgrhhafl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://afaeigaifgsgrhhafo.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://afaeigaifgsgrhhafp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://afaigaeigieufuifie.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://afaigaeigieufuifik.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://afaigaeigieufuifil.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://afaigaeigieufuifio.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://afaigaeigieufuifip.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://befaheaiudeuhughge.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://befaheaiudeuhughgk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://befaheaiudeuhughgl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://befaheaiudeuhughgo.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://befaheaiudeuhughgp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://bfagzzezgaegzgfaie.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://bfagzzezgaegzgfaik.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://bfagzzezgaegzgfail.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://bfagzzezgaegzgfaio.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://bfagzzezgaegzgfaip.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://daedagheauehfuuhfe.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://daedagheauehfuuhfk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://daedagheauehfuuhfl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://daedagheauehfuuhfo.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://daedagheauehfuuhfp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://eaeuafhuaegfugeude.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://eaeuafhuaegfugeudk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://eaeuafhuaegfugeudl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://eaeuafhuaegfugeudo.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://eaeuafhuaegfugeudp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://eguaheoghouughahse.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://eguaheoghouughahsk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://eguaheoghouughahsl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://eguaheoghouughahso.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://eguaheoghouughahsp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaghpaheiafhjefije.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaghpaheiafhjefijk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaghpaheiafhjefijl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaghpaheiafhjefijo.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaghpaheiafhjefijp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaoehuoaoefhuhfuge.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaoehuoaoefhuhfugk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaoehuoaoefhuhfugl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaoehuoaoefhuhfugo.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaoehuoaoefhuhfugp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaoheeuofhefefhute.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaoheeuofhefefhutk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaoheeuofhefefhutl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaoheeuofhefefhuto.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaoheeuofhefefhutp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaohrhurhuhruhfsde.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaohrhurhuhruhfsdk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaohrhurhuhruhfsdl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaohrhurhuhruhfsdo.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaohrhurhuhruhfsdp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaouehaehfoaeajrse.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaouehaehfoaeajrsk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaouehaehfoaeajrsl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaouehaehfoaeajrso.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://gaouehaehfoaeajrsp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://geauhouefheuutiiie.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://geauhouefheuutiiik.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://geauhouefheuutiiil.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://geauhouefheuutiiio.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://geauhouefheuutiiip.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://huaeokaefoaeguaehe.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://huaeokaefoaeguaehk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://huaeokaefoaeguaehl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://huaeokaefoaeguaeho.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://huaeokaefoaeguaehp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://rzhsudhugugfugugse.top/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://rzhsudhugugfugugsk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://rzhsudhugugfugugsl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://rzhsudhugugfugugso.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://rzhsudhugugfugugsp.co/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://urusurofhsorhfuuhk.su/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://urusurofhsorhfuuhl.cc/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://urusurofhsorhfuuho.io/ | Phorpiex botnet C2 (confidence level: 50%) | |
urlhttp://urusurofhsorhfuuhp.co/ | Phorpiex botnet C2 (confidence level: 50%) |
Threat ID: 69112f0da0a00dcacbf6b766
Added to database: 11/10/2025, 12:17:17 AM
Last enriched: 11/10/2025, 12:26:48 AM
Last updated: 11/10/2025, 8:08:00 AM
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
ThreatFox IOCs for 2025-11-08
Medium'Landfall' Malware Targeted Samsung Galaxy Users
MediumThreatsDay Bulletin: AI Tools in Malware, Botnets, GDI Flaws, Election Attacks & More
MediumTrojanized ESET Installers Drop Kalambur Backdoor in Phishing Attacks on Ukraine
MediumHidden Logic Bombs in Malware-Laced NuGet Packages Set to Detonate Years After Installation
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.