Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2025-11-14

0
Medium
Published: Fri Nov 14 2025 (11/14/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-11-14

AI-Powered Analysis

AILast updated: 11/15/2025, 00:06:59 UTC

Technical Analysis

The threat information pertains to ThreatFox IOCs published on 2025-11-14, classified as malware with a medium severity level. The data originates from the ThreatFox MISP feed, focusing on OSINT-related network activity and payload delivery mechanisms. However, the report lacks specific affected products, versions, or detailed technical indicators, which limits the ability to perform a deep technical analysis. The absence of known exploits in the wild and no available patches suggest that this threat is either emerging or not yet actively exploited. The technical details indicate a low threat level (2 out of an unspecified scale), minimal analysis (1), and moderate distribution (3), implying limited current impact or spread. The lack of CWEs and indicators further restricts actionable insights. The threat likely involves the use of OSINT techniques to identify targets or deliver payloads via network vectors, which could be leveraged by attackers for reconnaissance or initial compromise stages. Without concrete payload or exploit details, the threat remains primarily informational but warrants monitoring due to its potential to facilitate subsequent attacks.

Potential Impact

For European organizations, the impact of this threat is currently moderate due to the lack of specific exploit details or known active campaigns. However, the focus on OSINT and network-based payload delivery suggests potential risks in reconnaissance and initial access phases of cyberattacks. Organizations heavily reliant on open-source intelligence or with extensive network exposure could face increased risk of targeted payload delivery attempts. The absence of patches or mitigations indicates that if exploitation occurs, it may be difficult to counteract without proactive detection. Potential impacts include unauthorized access, data exfiltration, or disruption if payloads are successfully delivered and executed. The medium severity rating reflects these possibilities but also the current limited evidence of active exploitation. European entities in critical infrastructure, finance, or government sectors should remain vigilant given their attractiveness as targets and the strategic value of OSINT in attack planning.

Mitigation Recommendations

Given the limited technical details, mitigation should focus on enhancing OSINT monitoring and network security posture. Organizations should integrate ThreatFox and similar OSINT feeds into their Security Information and Event Management (SIEM) systems to detect emerging indicators promptly. Network traffic analysis tools should be configured to identify unusual payload delivery patterns or suspicious communications. Employ strict network segmentation and enforce least privilege principles to limit payload propagation. Regularly update and patch all systems to reduce attack surface, even though no specific patches are available for this threat. Conduct employee training on recognizing phishing or social engineering attempts that may leverage OSINT-derived information. Collaborate with national Computer Security Incident Response Teams (CSIRTs) to share intelligence and receive timely alerts. Finally, implement robust endpoint detection and response (EDR) solutions to identify and contain payload execution attempts.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
0190cb35-66a9-47ba-828f-31fc2f6d780f
Original Timestamp
1763164986

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttp://154.219.123.95:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://nakaizu.com/6h8h.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://fcontrols.pro/xhamster.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://194.87.55.59/rex.odd
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://192.177.26.210/saver.odd
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dcontrols.pro/xhamster.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dcontrols.pro/xxx.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://infernolo.com/xxx.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://infernolo.com/xhamster.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://hcontrol.pro/xxx.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://hcontrol.pro/xhamster.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://194.87.55.59/dxx.odd
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://3accdomain3.ru/xhamster.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://clubdetiroelpicarcho.com/ourzz.wav
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://xxclglglglklgkxlc.com/bxx.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://talentforth.org/lalu.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://appasdmdamsdmasd.com/das
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://ototaikfffkf.com/fffa.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://wintars.com/lina.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://151.243.18.246/bcvv.wav
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://91.231.222.217/pages/login.php
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://103.97.178.243:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://65.21.87.125/48a8a6cd726abeec.php
Stealc botnet C2 (confidence level: 50%)
urlhttp://ytbulten.web.tr/
Hook botnet C2 (confidence level: 50%)
urlhttps://managecontrol.top
XWorm payload delivery URL (confidence level: 50%)
urlhttps://one-experience-database-4qma.s3.ap-northeast-2.amazonaws.com/yno0tm0enn?id=m7uiimuo2kukkfz
XWorm payload delivery URL (confidence level: 50%)
urlhttps://efficient-studio-2022.s3.us-east-1.amazonaws.com/hetneaev47?id=vkbyzhxs37ud
XWorm payload delivery URL (confidence level: 50%)
urlhttps://one-experience-database-4qma.s3.ap-northeast-2.amazonaws.com/yno0tm0enn?id=pvhjxkys34anhlb
XWorm payload delivery URL (confidence level: 50%)
urlhttps://signin-att.dynamic-iamlrr-controller.appname-success.att-com.printactive.top/
XWorm payload delivery URL (confidence level: 50%)
urlhttps://enterprise-productivity-v2.s3.us-east-2.amazonaws.com/bbbf?id=lane
XWorm payload delivery URL (confidence level: 50%)
urlhttps://ebd73a0e-d227-4e72-b385-2f28acd9f66f.server2.nisdably.com/
Glupteba botnet C2 (confidence level: 50%)
urlhttps://api.telegram.org/bot8365730823:aag9wt_xut_pm0y7fkw1cytt2wd7ckk0woi/
Agent Tesla botnet C2 (confidence level: 50%)
urlhttp://hjjpoli13.top/index.php
CryptBot botnet C2 (confidence level: 50%)
urlhttp://moraatwoo01.top/index.php
CryptBot botnet C2 (confidence level: 50%)
urlhttp://xerrrload08.top/download.php?file=lm.exe
CryptBot botnet C2 (confidence level: 50%)
urlhttps://digitline.ch/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://hx.mashrift.ru/67kf5nb9
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://ter.vrolijkecreaties.nl/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ter.hotelsinjacksonvillefl.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://95.217.25.212/
Vidar botnet C2 (confidence level: 100%)
urlhttps://49.13.35.2/
Vidar botnet C2 (confidence level: 100%)
urlhttps://5.75.220.143/
Vidar botnet C2 (confidence level: 100%)
urlhttps://91.98.239.99/
Vidar botnet C2 (confidence level: 100%)
urlhttps://sd.r.banana.vu/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ug.andreeamunteanu.com/
Vidar botnet C2 (confidence level: 100%)
urlhttp://2.58.15.233/index.php
Koi Loader botnet C2 (confidence level: 100%)
urlhttps://omgtelecom.com/6e32s.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://srimedhasoft.com/xss/buf.js
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://srimedhasoft.com/xss/index.php
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://srimedhasoft.com/xss/bof.js
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://twentyfournow.com/verify
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://www.iconconsultants.com/lopayt.zip
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urltftp://36.93.2.29/.i
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://xxx.vrolijkecreaties.nl/
Vidar botnet C2 (confidence level: 100%)
urlhttps://xxx.hotelsinnewjerseyatlanticcity.com/
Vidar botnet C2 (confidence level: 100%)
urlhttp://185.233.164.123/archer.exe
Quasar RAT payload delivery URL (confidence level: 100%)
urlhttps://afonoditrixdxcomplany.com/work/
Latrodectus botnet C2 (confidence level: 75%)
urlhttps://bistroilonalkidimosds.com/work/
Latrodectus botnet C2 (confidence level: 75%)
urlhttp://86.54.24.139
Stealc botnet C2 (confidence level: 100%)

Domain

ValueDescriptionCopy
domaincatlover-pawpaw504.sbs
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaineasternwhiskerholdings.sbs
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainpuffyclaw2008.shop
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaincpanel.fjfrey.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainnakaizu.com
KongTuke payload delivery domain (confidence level: 100%)
domainfcontrols.pro
Unknown malware payload delivery domain (confidence level: 100%)
domaindcontrols.pro
Unknown malware payload delivery domain (confidence level: 100%)
domaininfernolo.com
Unknown malware payload delivery domain (confidence level: 100%)
domainhcontrol.pro
Unknown malware payload delivery domain (confidence level: 100%)
domain3accdomain3.ru
Unknown malware payload delivery domain (confidence level: 100%)
domainasdtvcvchcvhhhhh.com
Unknown malware payload delivery domain (confidence level: 100%)
domainxxclglglglklgkxlc.com
Unknown malware payload delivery domain (confidence level: 100%)
domainappasdmdamsdmasd.com
Unknown malware payload delivery domain (confidence level: 100%)
domainototaikfffkf.com
Unknown malware payload delivery domain (confidence level: 100%)
domainupdateday.info
Unknown malware payload delivery domain (confidence level: 100%)
domainrune.acornhollow.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwald.rowanstead.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhafen.rowanstead.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnacht.yewhollow.ru
ClearFake payload delivery domain (confidence level: 100%)
domainweiss.yewhollow.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpfad.yewhollow.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbal-rewards.xyz
Quasar RAT payload delivery domain (confidence level: 100%)
domainrauch.ashriver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfjord.ashriver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkorn.ashriver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfalke.thrushmere.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmoos.thrushmere.ru
ClearFake payload delivery domain (confidence level: 100%)
domainufer.thrushmere.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstein.boulderfield.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlicht.boulderfield.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzorn.boulderfield.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwolke.thundergrove.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpfad.thundergrove.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmoos.thundergrove.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstern.emberweide.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbach.emberweide.ru
ClearFake payload delivery domain (confidence level: 100%)
domain4gef4km41aysc.cfc-execute.bj.baidubce.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainglut.emberweide.ru
ClearFake payload delivery domain (confidence level: 100%)
domainadler.quartzfuchs.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkamm.quartzfuchs.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnacht.quartzfuchs.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbirch.cobaltspore.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintau.cobaltspore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfels.cobaltspore.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingleis.neonkiefer.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmoor.neonkiefer.ru
ClearFake payload delivery domain (confidence level: 100%)
domaineiche.neonkiefer.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhafen.auricfluss.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwind.auricfluss.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrune.auricfluss.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlicht.frostweald.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintal.frostweald.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkrone.frostweald.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsturm.cedarberg.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpfote.cedarberg.ru
ClearFake payload delivery domain (confidence level: 100%)
domainweiss.cedarberg.ru
ClearFake payload delivery domain (confidence level: 100%)
domainklee.ravenquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmsi25.dynnamn.ru
Remcos botnet C2 domain (confidence level: 100%)
domainufer.ravenquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbrentwood-operatic.com
AsyncRAT botnet C2 domain (confidence level: 50%)
domaingatex.brentwood-operatic.com
AsyncRAT botnet C2 domain (confidence level: 50%)
domaingatex.otisgrand.com
AsyncRAT botnet C2 domain (confidence level: 50%)
domainshop.atrishop.xyz
AsyncRAT botnet C2 domain (confidence level: 50%)
domainxerrrload08.top
CryptBot botnet C2 domain (confidence level: 50%)
domaincloseconection.duckdns.org
DCRat botnet C2 domain (confidence level: 50%)
domaineffects-animation.gl.at.ply.gg
DCRat botnet C2 domain (confidence level: 50%)
domainrafaborre27.duckdns.org
DCRat botnet C2 domain (confidence level: 50%)
domainv2.otisgrand.com
DCRat botnet C2 domain (confidence level: 50%)
domainv3.otisgrand.com
DCRat botnet C2 domain (confidence level: 50%)
domaincybersecuritefrance.ddns.net
Mirai botnet C2 domain (confidence level: 50%)
domainquantaservices.store
Mirai botnet C2 domain (confidence level: 50%)
domainvr3b.ddns.net
Mirai botnet C2 domain (confidence level: 50%)
domainrcdoncu1906.duckdns.org
Remcos botnet C2 domain (confidence level: 50%)
domainremcos26.dynuddns.com
Remcos botnet C2 domain (confidence level: 50%)
domainglanz.ravenquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domaineis.obsidianpfad.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbirch.obsidianpfad.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingleam.obsidianpfad.ru
ClearFake payload delivery domain (confidence level: 100%)
domainanchor.mashrift.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhx.mashrift.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlnk1man.pages.dev
Unknown malware payload delivery domain (confidence level: 50%)
domain0iz7q.mashrift.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintrust007-44490.portmap.host
Unknown RAT botnet C2 domain (confidence level: 50%)
domainhover.st0bepress.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingleam.st0bepress.ru
ClearFake payload delivery domain (confidence level: 100%)
domainter.vrolijkecreaties.nl
Vidar botnet C2 domain (confidence level: 100%)
domainter.hotelsinjacksonvillefl.com
Vidar botnet C2 domain (confidence level: 100%)
domainwww.dwf1579.vip
PumaBot botnet C2 domain (confidence level: 100%)
domainzoo.st0bepress.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshanghai.googledns.io
AhMyth payload delivery domain (confidence level: 50%)
domain3z1s.oddkraken.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshift.oddkraken.ru
ClearFake payload delivery domain (confidence level: 100%)
domain0op3s.oddkraken.ru
ClearFake payload delivery domain (confidence level: 100%)
domain0315.protohush.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvdj3j.protohush.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsd.r.banana.vu
Vidar botnet C2 domain (confidence level: 100%)
domainug.andreeamunteanu.com
Vidar botnet C2 domain (confidence level: 100%)
domain6zbr.protohush.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbyte.syrupdock.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpulse8.syrupdock.ru
ClearFake payload delivery domain (confidence level: 100%)
domainb53.syrupdock.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjarcovilokaserdrinok.com
Latrodectus botnet C2 domain (confidence level: 100%)
domainmaukateciklodasresm.com
Latrodectus botnet C2 domain (confidence level: 100%)
domainploykalofomarixcley.com
Latrodectus botnet C2 domain (confidence level: 100%)
domainsparkle9.ma-shrift.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2n62w.ma-shrift.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindefupdater.dll
Alien payload delivery domain (confidence level: 75%)
domainw1558.ma-shrift.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflux.flint-zoo.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwhlox.flint-zoo.ru
ClearFake payload delivery domain (confidence level: 100%)
domainottobattleskaldthrenody.com
donut_injector botnet C2 domain (confidence level: 100%)
domainwave.flint-zoo.ru
ClearFake payload delivery domain (confidence level: 100%)
domainu6.quantmelt.ru
ClearFake payload delivery domain (confidence level: 100%)
domain6m.quantmelt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvale.quantmelt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainz5.bl1nkswitch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlmn.bl1nkswitch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainceshioa.us.kg
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainkna.bl1nkswitch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwww.marmosfinancial.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainyw7.v0xelmint.ru
ClearFake payload delivery domain (confidence level: 100%)
domainuuf.v0xelmint.ru
ClearFake payload delivery domain (confidence level: 100%)
domainomgtelecom.com
KongTuke payload delivery domain (confidence level: 100%)
domainsb.v0xelmint.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbkp.st-0-bepress.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnova.st-0-bepress.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincms0c.st-0-bepress.ru
ClearFake payload delivery domain (confidence level: 100%)
domainconfrewdsfgfs.con-ip.com
Remcos botnet C2 domain (confidence level: 100%)
domainmr24251.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainwww.smssending.ns1.name
MimiKatz botnet C2 domain (confidence level: 100%)
domain1b8.flintzoo.ru
ClearFake payload delivery domain (confidence level: 100%)
domainecho.flintzoo.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintrail.flintzoo.ru
ClearFake payload delivery domain (confidence level: 100%)
domainq40eo.quant-melt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainblink.quant-melt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflux0.quant-melt.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine8.gleamspan.ru
ClearFake payload delivery domain (confidence level: 100%)
domainamigor.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainaudioux.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainml.gleamspan.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmockerl.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainshutsra.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainpoochse.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainoleaceg.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainnotionz.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainevasivr.qpon
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainqkund.gleamspan.ru
ClearFake payload delivery domain (confidence level: 100%)
domain01efv.odd-kraken.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvibesyncvr.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainkruipro.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainroot.kruipro.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaindock.odd-kraken.ru
ClearFake payload delivery domain (confidence level: 100%)
domainorbit.odd-kraken.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsdh3a.knotberry.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqg3q2.knotberry.ru
ClearFake payload delivery domain (confidence level: 100%)
domain053.knotberry.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsrimedhasoft.com
NetSupportManager RAT payload delivery domain (confidence level: 100%)
domaintla.gr1tmodule.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsiq.gr1tmodule.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpx.gr1tmodule.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqvm.z1ncspike.ru
ClearFake payload delivery domain (confidence level: 100%)
domaino5.z1ncspike.ru
ClearFake payload delivery domain (confidence level: 100%)
domainanchor.z1ncspike.ru
ClearFake payload delivery domain (confidence level: 100%)
domainu3z.pr0wldrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyf.pr0wldrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainquark.pr0wldrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxxx.vrolijkecreaties.nl
Vidar botnet C2 domain (confidence level: 100%)
domainxxx.hotelsinnewjerseyatlanticcity.com
Vidar botnet C2 domain (confidence level: 100%)
domainvpcp.clipmorrow.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingetinstallclient32.live
Unknown malware payload delivery domain (confidence level: 100%)
domainverificationsbycapcha.center
Unknown malware payload delivery domain (confidence level: 100%)
domainhrtf3.clipmorrow.ru
ClearFake payload delivery domain (confidence level: 100%)
domain28xr3.clipmorrow.ru
ClearFake payload delivery domain (confidence level: 100%)
domain1wd.viberspan.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmagicupdate.cfd
Aura Stealer botnet C2 domain (confidence level: 100%)
domainsearchagent.cfd
Aura Stealer botnet C2 domain (confidence level: 100%)
domainmodule7.viberspan.ru
ClearFake payload delivery domain (confidence level: 100%)
domain7u.viberspan.ru
ClearFake payload delivery domain (confidence level: 100%)
domain5lw6.lumentwist.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmail.outlook365.vip
Cobalt Strike botnet C2 domain (confidence level: 75%)
domain5z.lumentwist.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2v1.lumentwist.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindrop7.st1rlingpad.ru
ClearFake payload delivery domain (confidence level: 100%)
domain11v.st1rlingpad.ru
ClearFake payload delivery domain (confidence level: 100%)
domainknot.st1rlingpad.ru
ClearFake payload delivery domain (confidence level: 100%)
domaing0pv.saffronjet.ru
ClearFake payload delivery domain (confidence level: 100%)
domain1665s.saffronjet.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincore.saffronjet.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfdsgofgjoefjiooe.con-ip.com
Remcos botnet C2 domain (confidence level: 100%)
domainenivomarzo12.dynuddns.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainbyte8.hazebinder.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnova8.hazebinder.ru
ClearFake payload delivery domain (confidence level: 100%)
domainctr.hazebinder.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmoos.flintquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrune.flintquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindampf.flintquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainufer.ravensteg.ru
ClearFake payload delivery domain (confidence level: 100%)
domainglut.ravensteg.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhain.ravensteg.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintau.ironweide.ru
ClearFake payload delivery domain (confidence level: 100%)
domainschirm.ironweide.ru
ClearFake payload delivery domain (confidence level: 100%)
domainklee.ironweide.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindorn.silverbirke.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwolke.silverbirke.ru
ClearFake payload delivery domain (confidence level: 100%)
domainglanz.silverbirke.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfjord.wolkenhof.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstern.wolkenhof.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjustamap.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domaineiche.wolkenhof.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrauch.neonbuche.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkorn.neonbuche.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingleis.neonbuche.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbach.cobaltquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintal.cobaltquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainweald.cobaltquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsturm.obsidianufer.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpfote.obsidianufer.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlicht.obsidianufer.ru
ClearFake payload delivery domain (confidence level: 100%)
domaineis.solarpfad.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkamm.solarpfad.ru
ClearFake payload delivery domain (confidence level: 100%)
domainweiss.solarpfad.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmoor.willowgrat.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfalke.willowgrat.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrinde.willowgrat.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwolke.thunderkiesel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbach.thunderkiesel.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingrat.thunderkiesel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnebel.thunderkiesel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfunke.thunderkiesel.ru
ClearFake payload delivery domain (confidence level: 100%)

Hash

ValueDescriptionCopy
hashf89aab69e01d21b2c8ce2b8ee9909d25
Unknown malware payload (confidence level: 100%)
hash42b9f136abd20cfe07cd08a9b1631ea8
Unknown malware payload (confidence level: 100%)
hashe46f155df70c8a8c4506a2a42425c1a6
Unknown malware payload (confidence level: 100%)
hash3778
Mirai botnet C2 server (confidence level: 80%)
hash20473
Quasar RAT botnet C2 server (confidence level: 100%)
hash31975
Quasar RAT botnet C2 server (confidence level: 100%)
hash54096
Quasar RAT botnet C2 server (confidence level: 100%)
hash23
Quasar RAT botnet C2 server (confidence level: 100%)
hash28045
Quasar RAT botnet C2 server (confidence level: 100%)
hash5060
Quasar RAT botnet C2 server (confidence level: 100%)
hash1796
Quasar RAT botnet C2 server (confidence level: 100%)
hash8080
Bashlite botnet C2 server (confidence level: 100%)
hash13000
Quasar RAT botnet C2 server (confidence level: 75%)
hash13000
Quasar RAT botnet C2 server (confidence level: 75%)
hash3778
Mirai botnet C2 server (confidence level: 80%)
hash7889
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash6666
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash80
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash24321
AdaptixC2 botnet C2 server (confidence level: 100%)
hash1912
RedLine Stealer botnet C2 server (confidence level: 100%)
hash80
Ficker Stealer botnet C2 server (confidence level: 50%)
hash3289
Remcos botnet C2 server (confidence level: 50%)
hash1616
Remcos botnet C2 server (confidence level: 50%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash81
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8088
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4433
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash55550
PumaBot botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash8463
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash443
Unknown RAT botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash8080
Quasar RAT botnet C2 server (confidence level: 100%)
hash81
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash1911
RedLine Stealer botnet C2 server (confidence level: 100%)
hash8082
ERMAC botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash8888
ValleyRAT botnet C2 server (confidence level: 100%)
hash2244
XWorm botnet C2 server (confidence level: 75%)
hash2052
Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash48254
Remcos botnet C2 server (confidence level: 100%)
hash1977
Remcos botnet C2 server (confidence level: 100%)
hash83ac4cb463bbbdab3c758f9fdfe0cc52c69364ec0ad9a21a8687dac28cd74c27
BKA Trojaner payload (confidence level: 100%)
hash32962
Mirai botnet C2 server (confidence level: 80%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 90%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash80
Havoc botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
XWorm botnet C2 server (confidence level: 100%)
hash9861
Remcos botnet C2 server (confidence level: 100%)
hash81
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash8080
ERMAC botnet C2 server (confidence level: 100%)
hash4444
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Meterpreter botnet C2 server (confidence level: 75%)
hash443
Meterpreter botnet C2 server (confidence level: 75%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash5873
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash1312
Venom RAT botnet C2 server (confidence level: 100%)
hash8088
DCRat botnet C2 server (confidence level: 100%)
hash16446
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash4444
AdaptixC2 botnet C2 server (confidence level: 100%)
hash53
Cobalt Strike botnet C2 server (confidence level: 75%)
hash53
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash18443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8000
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash8443
Sliver botnet C2 server (confidence level: 100%)
hash8443
Sliver botnet C2 server (confidence level: 100%)
hash8443
Sliver botnet C2 server (confidence level: 100%)
hash443
AsyncRAT botnet C2 server (confidence level: 100%)
hash8090
DCRat botnet C2 server (confidence level: 100%)
hash35946
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash1911
RedLine Stealer botnet C2 server (confidence level: 100%)
hash80
Chaos botnet C2 server (confidence level: 100%)
hash4443
Meterpreter botnet C2 server (confidence level: 100%)
hash21969
Meterpreter botnet C2 server (confidence level: 100%)
hash44819
Meterpreter botnet C2 server (confidence level: 100%)
hash5539
ValleyRAT botnet C2 server (confidence level: 100%)
hash1912
RedLine Stealer botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8180
Cobalt Strike botnet C2 server (confidence level: 90%)
hash2107
AsyncRAT botnet C2 server (confidence level: 100%)

File

ValueDescriptionCopy
file31.58.247.201
Mirai botnet C2 server (confidence level: 80%)
file102.205.170.10
Quasar RAT botnet C2 server (confidence level: 100%)
file102.205.170.10
Quasar RAT botnet C2 server (confidence level: 100%)
file102.205.170.10
Quasar RAT botnet C2 server (confidence level: 100%)
file102.205.170.10
Quasar RAT botnet C2 server (confidence level: 100%)
file102.205.170.10
Quasar RAT botnet C2 server (confidence level: 100%)
file102.205.170.10
Quasar RAT botnet C2 server (confidence level: 100%)
file102.205.170.10
Quasar RAT botnet C2 server (confidence level: 100%)
file45.153.34.35
Bashlite botnet C2 server (confidence level: 100%)
file139.59.23.248
Quasar RAT botnet C2 server (confidence level: 75%)
file193.161.193.99
Quasar RAT botnet C2 server (confidence level: 75%)
file213.255.209.93
Mirai botnet C2 server (confidence level: 80%)
file104.168.115.89
PureLogs Stealer botnet C2 server (confidence level: 100%)
file146.56.216.116
Cobalt Strike botnet C2 server (confidence level: 100%)
file123.207.20.187
Cobalt Strike botnet C2 server (confidence level: 100%)
file91.92.243.167
Latrodectus botnet C2 server (confidence level: 100%)
file91.92.243.164
Latrodectus botnet C2 server (confidence level: 100%)
file47.104.11.241
Unknown malware botnet C2 server (confidence level: 100%)
file180.93.227.136
AsyncRAT botnet C2 server (confidence level: 100%)
file130.61.47.176
Havoc botnet C2 server (confidence level: 100%)
file155.138.162.86
AdaptixC2 botnet C2 server (confidence level: 100%)
file46.224.4.226
RedLine Stealer botnet C2 server (confidence level: 100%)
file5.79.102.209
Ficker Stealer botnet C2 server (confidence level: 50%)
file185.101.34.110
Remcos botnet C2 server (confidence level: 50%)
file195.177.94.40
Remcos botnet C2 server (confidence level: 50%)
file138.226.236.62
Cobalt Strike botnet C2 server (confidence level: 100%)
file106.75.162.108
Cobalt Strike botnet C2 server (confidence level: 100%)
file119.91.37.94
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.119.178.247
Cobalt Strike botnet C2 server (confidence level: 100%)
file117.72.206.244
Cobalt Strike botnet C2 server (confidence level: 100%)
file123.56.16.123
Cobalt Strike botnet C2 server (confidence level: 100%)
file111.228.3.39
Cobalt Strike botnet C2 server (confidence level: 100%)
file91.98.151.0
Vidar botnet C2 server (confidence level: 100%)
file156.234.207.194
PumaBot botnet C2 server (confidence level: 75%)
file47.120.67.103
Cobalt Strike botnet C2 server (confidence level: 100%)
file91.92.243.166
Latrodectus botnet C2 server (confidence level: 100%)
file216.252.238.41
Remcos botnet C2 server (confidence level: 100%)
file198.55.102.71
Remcos botnet C2 server (confidence level: 100%)
file198.23.175.60
Remcos botnet C2 server (confidence level: 100%)
file185.243.112.253
Unknown RAT botnet C2 server (confidence level: 100%)
file94.103.0.190
Sliver botnet C2 server (confidence level: 100%)
file45.150.108.93
Sliver botnet C2 server (confidence level: 100%)
file5.180.81.66
Hook botnet C2 server (confidence level: 100%)
file181.162.150.252
Quasar RAT botnet C2 server (confidence level: 100%)
file84.154.188.167
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file91.92.243.215
RedLine Stealer botnet C2 server (confidence level: 100%)
file5.180.81.66
ERMAC botnet C2 server (confidence level: 100%)
file95.217.25.212
Vidar botnet C2 server (confidence level: 100%)
file49.13.35.2
Vidar botnet C2 server (confidence level: 100%)
file5.75.220.143
Vidar botnet C2 server (confidence level: 100%)
file91.98.239.99
Vidar botnet C2 server (confidence level: 100%)
file151.242.20.91
ValleyRAT botnet C2 server (confidence level: 100%)
file185.222.58.49
XWorm botnet C2 server (confidence level: 75%)
file212.7.200.238
Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%)
file101.42.31.153
Cobalt Strike botnet C2 server (confidence level: 75%)
file120.24.61.117
Cobalt Strike botnet C2 server (confidence level: 75%)
file146.56.194.84
Cobalt Strike botnet C2 server (confidence level: 75%)
file5.101.86.3
Remcos botnet C2 server (confidence level: 100%)
file198.23.177.196
Remcos botnet C2 server (confidence level: 100%)
file193.26.115.214
Mirai botnet C2 server (confidence level: 80%)
file180.76.240.53
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.79.34.160
Cobalt Strike botnet C2 server (confidence level: 100%)
file212.80.213.212
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.103.21.230
Sliver botnet C2 server (confidence level: 90%)
file104.234.204.20
AsyncRAT botnet C2 server (confidence level: 100%)
file206.81.21.81
Unknown malware botnet C2 server (confidence level: 100%)
file77.110.115.14
Hook botnet C2 server (confidence level: 100%)
file5.180.81.66
Hook botnet C2 server (confidence level: 100%)
file4.218.10.81
Havoc botnet C2 server (confidence level: 100%)
file183.90.150.110
Unknown malware botnet C2 server (confidence level: 100%)
file44.223.143.23
Unknown malware botnet C2 server (confidence level: 100%)
file159.69.211.99
Unknown malware botnet C2 server (confidence level: 100%)
file159.69.211.99
Unknown malware botnet C2 server (confidence level: 100%)
file143.110.187.42
Unknown malware botnet C2 server (confidence level: 100%)
file149.3.170.50
Unknown malware botnet C2 server (confidence level: 100%)
file104.248.24.98
Unknown malware botnet C2 server (confidence level: 100%)
file39.106.42.38
Unknown malware botnet C2 server (confidence level: 100%)
file54.155.189.199
Unknown malware botnet C2 server (confidence level: 100%)
file202.151.176.128
Unknown malware botnet C2 server (confidence level: 100%)
file202.151.176.128
Unknown malware botnet C2 server (confidence level: 100%)
file159.65.48.193
Unknown malware botnet C2 server (confidence level: 100%)
file51.77.192.147
Unknown malware botnet C2 server (confidence level: 100%)
file95.81.76.77
XWorm botnet C2 server (confidence level: 100%)
file91.92.243.134
Remcos botnet C2 server (confidence level: 100%)
file79.241.110.210
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file38.180.149.179
ERMAC botnet C2 server (confidence level: 100%)
file202.128.127.94
Meterpreter botnet C2 server (confidence level: 100%)
file173.212.239.206
Meterpreter botnet C2 server (confidence level: 75%)
file3.133.102.58
Meterpreter botnet C2 server (confidence level: 75%)
file5.252.178.35
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file5.75.217.93
Vidar botnet C2 server (confidence level: 100%)
file123.11.255.35
Unknown malware botnet C2 server (confidence level: 100%)
file124.222.182.210
Unknown malware botnet C2 server (confidence level: 100%)
file80.211.238.184
Venom RAT botnet C2 server (confidence level: 100%)
file137.220.156.69
DCRat botnet C2 server (confidence level: 100%)
file16.52.72.37
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file80.253.249.102
AdaptixC2 botnet C2 server (confidence level: 100%)
file149.28.148.209
Cobalt Strike botnet C2 server (confidence level: 75%)
file27.124.19.123
Cobalt Strike botnet C2 server (confidence level: 75%)
file15.197.91.241
DeimosC2 botnet C2 server (confidence level: 75%)
file91.92.241.119
Sliver botnet C2 server (confidence level: 75%)
file8.140.200.78
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.139.88.57
Cobalt Strike botnet C2 server (confidence level: 100%)
file149.88.81.215
Cobalt Strike botnet C2 server (confidence level: 100%)
file203.91.76.119
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.83.31.50
Remcos botnet C2 server (confidence level: 100%)
file192.236.147.59
Remcos botnet C2 server (confidence level: 100%)
file204.10.160.183
Remcos botnet C2 server (confidence level: 100%)
file8.136.241.242
Sliver botnet C2 server (confidence level: 100%)
file8.136.241.170
Sliver botnet C2 server (confidence level: 100%)
file8.136.240.81
Sliver botnet C2 server (confidence level: 100%)
file45.152.243.178
AsyncRAT botnet C2 server (confidence level: 100%)
file64.7.199.71
DCRat botnet C2 server (confidence level: 100%)
file56.228.6.115
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file45.156.87.43
RedLine Stealer botnet C2 server (confidence level: 100%)
file5.129.218.245
Chaos botnet C2 server (confidence level: 100%)
file107.170.38.154
Meterpreter botnet C2 server (confidence level: 100%)
file3.85.201.51
Meterpreter botnet C2 server (confidence level: 100%)
file3.85.201.51
Meterpreter botnet C2 server (confidence level: 100%)
file111.92.240.204
ValleyRAT botnet C2 server (confidence level: 100%)
file45.156.87.43
RedLine Stealer botnet C2 server (confidence level: 100%)
file103.74.194.97
Cobalt Strike botnet C2 server (confidence level: 75%)
file5.182.204.156
Cobalt Strike botnet C2 server (confidence level: 75%)
file5.182.204.156
Cobalt Strike botnet C2 server (confidence level: 75%)
file62.210.195.179
Cobalt Strike botnet C2 server (confidence level: 90%)
file124.198.132.30
AsyncRAT botnet C2 server (confidence level: 100%)

Threat ID: 6917c3f5ed594783724dd8d8

Added to database: 11/15/2025, 12:06:13 AM

Last enriched: 11/15/2025, 12:06:59 AM

Last updated: 11/16/2025, 4:13:53 AM

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats