ThreatFox IOCs for 2025-11-14
ThreatFox IOCs for 2025-11-14
AI Analysis
Technical Summary
The threat information pertains to ThreatFox IOCs published on 2025-11-14, classified as malware with a medium severity level. The data originates from the ThreatFox MISP feed, focusing on OSINT-related network activity and payload delivery mechanisms. However, the report lacks specific affected products, versions, or detailed technical indicators, which limits the ability to perform a deep technical analysis. The absence of known exploits in the wild and no available patches suggest that this threat is either emerging or not yet actively exploited. The technical details indicate a low threat level (2 out of an unspecified scale), minimal analysis (1), and moderate distribution (3), implying limited current impact or spread. The lack of CWEs and indicators further restricts actionable insights. The threat likely involves the use of OSINT techniques to identify targets or deliver payloads via network vectors, which could be leveraged by attackers for reconnaissance or initial compromise stages. Without concrete payload or exploit details, the threat remains primarily informational but warrants monitoring due to its potential to facilitate subsequent attacks.
Potential Impact
For European organizations, the impact of this threat is currently moderate due to the lack of specific exploit details or known active campaigns. However, the focus on OSINT and network-based payload delivery suggests potential risks in reconnaissance and initial access phases of cyberattacks. Organizations heavily reliant on open-source intelligence or with extensive network exposure could face increased risk of targeted payload delivery attempts. The absence of patches or mitigations indicates that if exploitation occurs, it may be difficult to counteract without proactive detection. Potential impacts include unauthorized access, data exfiltration, or disruption if payloads are successfully delivered and executed. The medium severity rating reflects these possibilities but also the current limited evidence of active exploitation. European entities in critical infrastructure, finance, or government sectors should remain vigilant given their attractiveness as targets and the strategic value of OSINT in attack planning.
Mitigation Recommendations
Given the limited technical details, mitigation should focus on enhancing OSINT monitoring and network security posture. Organizations should integrate ThreatFox and similar OSINT feeds into their Security Information and Event Management (SIEM) systems to detect emerging indicators promptly. Network traffic analysis tools should be configured to identify unusual payload delivery patterns or suspicious communications. Employ strict network segmentation and enforce least privilege principles to limit payload propagation. Regularly update and patch all systems to reduce attack surface, even though no specific patches are available for this threat. Conduct employee training on recognizing phishing or social engineering attempts that may leverage OSINT-derived information. Collaborate with national Computer Security Incident Response Teams (CSIRTs) to share intelligence and receive timely alerts. Finally, implement robust endpoint detection and response (EDR) solutions to identify and contain payload execution attempts.
Affected Countries
Germany, France, United Kingdom, Netherlands, Italy
Indicators of Compromise
- url: http://154.219.123.95:8888/supershell/login/
- domain: catlover-pawpaw504.sbs
- domain: easternwhiskerholdings.sbs
- hash: f89aab69e01d21b2c8ce2b8ee9909d25
- hash: 42b9f136abd20cfe07cd08a9b1631ea8
- hash: e46f155df70c8a8c4506a2a42425c1a6
- file: 31.58.247.201
- hash: 3778
- domain: puffyclaw2008.shop
- domain: cpanel.fjfrey.com
- domain: nakaizu.com
- url: https://nakaizu.com/6h8h.js
- domain: fcontrols.pro
- url: https://fcontrols.pro/xhamster.html
- url: http://194.87.55.59/rex.odd
- url: http://192.177.26.210/saver.odd
- url: https://dcontrols.pro/xhamster.html
- url: https://dcontrols.pro/xxx.html
- domain: dcontrols.pro
- domain: infernolo.com
- url: https://infernolo.com/xxx.html
- url: https://infernolo.com/xhamster.html
- domain: hcontrol.pro
- url: https://hcontrol.pro/xxx.html
- url: https://hcontrol.pro/xhamster.html
- url: https://194.87.55.59/dxx.odd
- url: https://3accdomain3.ru/xhamster.html
- domain: 3accdomain3.ru
- url: https://clubdetiroelpicarcho.com/ourzz.wav
- domain: asdtvcvchcvhhhhh.com
- domain: xxclglglglklgkxlc.com
- url: https://xxclglglglklgkxlc.com/bxx.js
- url: https://talentforth.org/lalu.php
- domain: appasdmdamsdmasd.com
- url: https://appasdmdamsdmasd.com/das
- domain: ototaikfffkf.com
- url: https://ototaikfffkf.com/fffa.js
- url: https://wintars.com/lina.php
- url: http://151.243.18.246/bcvv.wav
- domain: updateday.info
- domain: rune.acornhollow.ru
- file: 102.205.170.10
- hash: 20473
- file: 102.205.170.10
- hash: 31975
- file: 102.205.170.10
- hash: 54096
- file: 102.205.170.10
- hash: 23
- file: 102.205.170.10
- hash: 28045
- file: 102.205.170.10
- hash: 5060
- file: 102.205.170.10
- hash: 1796
- file: 45.153.34.35
- hash: 8080
- domain: wald.rowanstead.ru
- domain: hafen.rowanstead.ru
- domain: nacht.yewhollow.ru
- domain: weiss.yewhollow.ru
- domain: pfad.yewhollow.ru
- domain: bal-rewards.xyz
- domain: rauch.ashriver.ru
- domain: fjord.ashriver.ru
- url: http://91.231.222.217/pages/login.php
- file: 139.59.23.248
- hash: 13000
- file: 193.161.193.99
- hash: 13000
- domain: korn.ashriver.ru
- domain: falke.thrushmere.ru
- domain: moos.thrushmere.ru
- domain: ufer.thrushmere.ru
- domain: stein.boulderfield.ru
- domain: licht.boulderfield.ru
- url: http://103.97.178.243:8888/supershell/login/
- domain: zorn.boulderfield.ru
- file: 213.255.209.93
- hash: 3778
- domain: wolke.thundergrove.ru
- domain: pfad.thundergrove.ru
- domain: moos.thundergrove.ru
- domain: stern.emberweide.ru
- domain: bach.emberweide.ru
- domain: 4gef4km41aysc.cfc-execute.bj.baidubce.com
- domain: glut.emberweide.ru
- domain: adler.quartzfuchs.ru
- domain: kamm.quartzfuchs.ru
- file: 104.168.115.89
- hash: 7889
- domain: nacht.quartzfuchs.ru
- domain: birch.cobaltspore.ru
- domain: tau.cobaltspore.ru
- domain: fels.cobaltspore.ru
- domain: gleis.neonkiefer.ru
- file: 146.56.216.116
- hash: 6666
- file: 123.207.20.187
- hash: 8080
- file: 91.92.243.167
- hash: 443
- file: 91.92.243.164
- hash: 443
- file: 47.104.11.241
- hash: 8888
- file: 180.93.227.136
- hash: 80
- file: 130.61.47.176
- hash: 443
- file: 155.138.162.86
- hash: 24321
- domain: moor.neonkiefer.ru
- domain: eiche.neonkiefer.ru
- domain: hafen.auricfluss.ru
- domain: wind.auricfluss.ru
- domain: rune.auricfluss.ru
- domain: licht.frostweald.ru
- domain: tal.frostweald.ru
- domain: krone.frostweald.ru
- domain: sturm.cedarberg.ru
- domain: pfote.cedarberg.ru
- domain: weiss.cedarberg.ru
- domain: klee.ravenquelle.ru
- domain: msi25.dynnamn.ru
- file: 46.224.4.226
- hash: 1912
- url: https://65.21.87.125/48a8a6cd726abeec.php
- domain: ufer.ravenquelle.ru
- url: http://ytbulten.web.tr/
- url: https://managecontrol.top
- url: https://one-experience-database-4qma.s3.ap-northeast-2.amazonaws.com/yno0tm0enn?id=m7uiimuo2kukkfz
- url: https://efficient-studio-2022.s3.us-east-1.amazonaws.com/hetneaev47?id=vkbyzhxs37ud
- url: https://one-experience-database-4qma.s3.ap-northeast-2.amazonaws.com/yno0tm0enn?id=pvhjxkys34anhlb
- url: https://signin-att.dynamic-iamlrr-controller.appname-success.att-com.printactive.top/
- url: https://enterprise-productivity-v2.s3.us-east-2.amazonaws.com/bbbf?id=lane
- url: https://ebd73a0e-d227-4e72-b385-2f28acd9f66f.server2.nisdably.com/
- url: https://api.telegram.org/bot8365730823:aag9wt_xut_pm0y7fkw1cytt2wd7ckk0woi/
- domain: brentwood-operatic.com
- domain: gatex.brentwood-operatic.com
- domain: gatex.otisgrand.com
- domain: shop.atrishop.xyz
- domain: xerrrload08.top
- url: http://hjjpoli13.top/index.php
- url: http://moraatwoo01.top/index.php
- url: http://xerrrload08.top/download.php?file=lm.exe
- domain: closeconection.duckdns.org
- domain: effects-animation.gl.at.ply.gg
- domain: rafaborre27.duckdns.org
- domain: v2.otisgrand.com
- domain: v3.otisgrand.com
- file: 5.79.102.209
- hash: 80
- domain: cybersecuritefrance.ddns.net
- domain: quantaservices.store
- domain: vr3b.ddns.net
- domain: rcdoncu1906.duckdns.org
- domain: remcos26.dynuddns.com
- file: 185.101.34.110
- hash: 3289
- file: 195.177.94.40
- hash: 1616
- domain: glanz.ravenquelle.ru
- domain: eis.obsidianpfad.ru
- domain: birch.obsidianpfad.ru
- domain: gleam.obsidianpfad.ru
- domain: anchor.mashrift.ru
- domain: hx.mashrift.ru
- url: https://digitline.ch/
- url: https://hx.mashrift.ru/67kf5nb9
- domain: lnk1man.pages.dev
- domain: 0iz7q.mashrift.ru
- file: 138.226.236.62
- hash: 8443
- file: 106.75.162.108
- hash: 81
- file: 119.91.37.94
- hash: 8888
- file: 47.119.178.247
- hash: 80
- file: 117.72.206.244
- hash: 443
- file: 123.56.16.123
- hash: 8088
- file: 111.228.3.39
- hash: 4433
- domain: trust007-44490.portmap.host
- domain: hover.st0bepress.ru
- domain: gleam.st0bepress.ru
- url: https://ter.vrolijkecreaties.nl/
- url: https://ter.hotelsinjacksonvillefl.com/
- domain: ter.vrolijkecreaties.nl
- domain: ter.hotelsinjacksonvillefl.com
- file: 91.98.151.0
- hash: 443
- domain: www.dwf1579.vip
- file: 156.234.207.194
- hash: 55550
- domain: zoo.st0bepress.ru
- domain: shanghai.googledns.io
- domain: 3z1s.oddkraken.ru
- file: 47.120.67.103
- hash: 443
- file: 91.92.243.166
- hash: 443
- file: 216.252.238.41
- hash: 8463
- file: 198.55.102.71
- hash: 2404
- file: 198.23.175.60
- hash: 2404
- file: 185.243.112.253
- hash: 443
- file: 94.103.0.190
- hash: 443
- file: 45.150.108.93
- hash: 31337
- file: 5.180.81.66
- hash: 80
- file: 181.162.150.252
- hash: 8080
- file: 84.154.188.167
- hash: 81
- file: 91.92.243.215
- hash: 1911
- file: 5.180.81.66
- hash: 8082
- domain: shift.oddkraken.ru
- domain: 0op3s.oddkraken.ru
- domain: 0315.protohush.ru
- url: https://95.217.25.212/
- url: https://49.13.35.2/
- url: https://5.75.220.143/
- url: https://91.98.239.99/
- file: 95.217.25.212
- hash: 443
- file: 49.13.35.2
- hash: 443
- file: 5.75.220.143
- hash: 443
- file: 91.98.239.99
- hash: 443
- domain: vdj3j.protohush.ru
- file: 151.242.20.91
- hash: 8888
- url: https://sd.r.banana.vu/
- url: https://ug.andreeamunteanu.com/
- domain: sd.r.banana.vu
- domain: ug.andreeamunteanu.com
- domain: 6zbr.protohush.ru
- file: 185.222.58.49
- hash: 2244
- domain: byte.syrupdock.ru
- domain: pulse8.syrupdock.ru
- file: 212.7.200.238
- hash: 2052
- file: 101.42.31.153
- hash: 80
- file: 120.24.61.117
- hash: 8443
- file: 146.56.194.84
- hash: 80
- domain: b53.syrupdock.ru
- file: 5.101.86.3
- hash: 48254
- domain: jarcovilokaserdrinok.com
- domain: maukateciklodasresm.com
- domain: ploykalofomarixcley.com
- domain: sparkle9.ma-shrift.ru
- domain: 2n62w.ma-shrift.ru
- domain: defupdater.dll
- domain: w1558.ma-shrift.ru
- domain: flux.flint-zoo.ru
- domain: whlox.flint-zoo.ru
- domain: ottobattleskaldthrenody.com
- file: 198.23.177.196
- hash: 1977
- domain: wave.flint-zoo.ru
- hash: 83ac4cb463bbbdab3c758f9fdfe0cc52c69364ec0ad9a21a8687dac28cd74c27
- domain: u6.quantmelt.ru
- file: 193.26.115.214
- hash: 32962
- domain: 6m.quantmelt.ru
- domain: vale.quantmelt.ru
- domain: z5.bl1nkswitch.ru
- domain: lmn.bl1nkswitch.ru
- domain: ceshioa.us.kg
- domain: kna.bl1nkswitch.ru
- file: 180.76.240.53
- hash: 443
- file: 47.79.34.160
- hash: 8080
- file: 212.80.213.212
- hash: 443
- url: http://2.58.15.233/index.php
- file: 103.103.21.230
- hash: 443
- file: 104.234.204.20
- hash: 8808
- domain: www.marmosfinancial.com
- file: 206.81.21.81
- hash: 7443
- file: 77.110.115.14
- hash: 8089
- file: 5.180.81.66
- hash: 8089
- file: 4.218.10.81
- hash: 80
- file: 183.90.150.110
- hash: 8443
- file: 44.223.143.23
- hash: 443
- file: 159.69.211.99
- hash: 443
- file: 159.69.211.99
- hash: 3333
- file: 143.110.187.42
- hash: 3333
- file: 149.3.170.50
- hash: 443
- file: 104.248.24.98
- hash: 8443
- file: 39.106.42.38
- hash: 3333
- file: 54.155.189.199
- hash: 443
- file: 202.151.176.128
- hash: 80
- file: 202.151.176.128
- hash: 443
- file: 159.65.48.193
- hash: 3333
- file: 51.77.192.147
- hash: 3333
- domain: yw7.v0xelmint.ru
- domain: uuf.v0xelmint.ru
- domain: omgtelecom.com
- url: https://omgtelecom.com/6e32s.js
- domain: sb.v0xelmint.ru
- domain: bkp.st-0-bepress.ru
- domain: nova.st-0-bepress.ru
- domain: cms0c.st-0-bepress.ru
- file: 95.81.76.77
- hash: 443
- domain: confrewdsfgfs.con-ip.com
- file: 91.92.243.134
- hash: 9861
- domain: mr24251.duckdns.org
- file: 79.241.110.210
- hash: 81
- file: 38.180.149.179
- hash: 8080
- domain: www.smssending.ns1.name
- file: 202.128.127.94
- hash: 4444
- domain: 1b8.flintzoo.ru
- domain: echo.flintzoo.ru
- domain: trail.flintzoo.ru
- domain: q40eo.quant-melt.ru
- domain: blink.quant-melt.ru
- domain: flux0.quant-melt.ru
- domain: e8.gleamspan.ru
- file: 173.212.239.206
- hash: 443
- file: 3.133.102.58
- hash: 443
- domain: amigor.qpon
- domain: audioux.qpon
- domain: ml.gleamspan.ru
- domain: mockerl.qpon
- domain: shutsra.qpon
- domain: poochse.qpon
- domain: oleaceg.qpon
- domain: notionz.qpon
- domain: evasivr.qpon
- domain: qkund.gleamspan.ru
- domain: 01efv.odd-kraken.ru
- domain: vibesyncvr.com
- domain: kruipro.com
- domain: root.kruipro.com
- domain: dock.odd-kraken.ru
- domain: orbit.odd-kraken.ru
- domain: sdh3a.knotberry.ru
- domain: qg3q2.knotberry.ru
- domain: 053.knotberry.ru
- url: https://srimedhasoft.com/xss/buf.js
- domain: srimedhasoft.com
- url: https://srimedhasoft.com/xss/index.php
- url: https://srimedhasoft.com/xss/bof.js
- url: https://twentyfournow.com/verify
- url: https://www.iconconsultants.com/lopayt.zip
- file: 5.252.178.35
- hash: 443
- domain: tla.gr1tmodule.ru
- domain: siq.gr1tmodule.ru
- domain: px.gr1tmodule.ru
- domain: qvm.z1ncspike.ru
- url: tftp://36.93.2.29/.i
- domain: o5.z1ncspike.ru
- domain: anchor.z1ncspike.ru
- domain: u3z.pr0wldrop.ru
- domain: yf.pr0wldrop.ru
- domain: quark.pr0wldrop.ru
- url: https://xxx.vrolijkecreaties.nl/
- url: https://xxx.hotelsinnewjerseyatlanticcity.com/
- domain: xxx.vrolijkecreaties.nl
- domain: xxx.hotelsinnewjerseyatlanticcity.com
- file: 5.75.217.93
- hash: 443
- domain: vpcp.clipmorrow.ru
- domain: getinstallclient32.live
- domain: verificationsbycapcha.center
- domain: hrtf3.clipmorrow.ru
- file: 123.11.255.35
- hash: 5873
- file: 124.222.182.210
- hash: 8888
- file: 80.211.238.184
- hash: 1312
- file: 137.220.156.69
- hash: 8088
- file: 16.52.72.37
- hash: 16446
- domain: 28xr3.clipmorrow.ru
- file: 80.253.249.102
- hash: 4444
- domain: 1wd.viberspan.ru
- domain: magicupdate.cfd
- domain: searchagent.cfd
- domain: module7.viberspan.ru
- url: http://185.233.164.123/archer.exe
- domain: 7u.viberspan.ru
- domain: 5lw6.lumentwist.ru
- domain: mail.outlook365.vip
- file: 149.28.148.209
- hash: 53
- file: 27.124.19.123
- hash: 53
- domain: 5z.lumentwist.ru
- domain: 2v1.lumentwist.ru
- domain: drop7.st1rlingpad.ru
- domain: 11v.st1rlingpad.ru
- domain: knot.st1rlingpad.ru
- domain: g0pv.saffronjet.ru
- domain: 1665s.saffronjet.ru
- url: https://afonoditrixdxcomplany.com/work/
- url: https://bistroilonalkidimosds.com/work/
- domain: core.saffronjet.ru
- domain: fdsgofgjoefjiooe.con-ip.com
- domain: enivomarzo12.dynuddns.com
- url: http://86.54.24.139
- domain: byte8.hazebinder.ru
- domain: nova8.hazebinder.ru
- domain: ctr.hazebinder.ru
- domain: moos.flintquelle.ru
- file: 15.197.91.241
- hash: 443
- domain: rune.flintquelle.ru
- domain: dampf.flintquelle.ru
- file: 91.92.241.119
- hash: 8888
- domain: ufer.ravensteg.ru
- domain: glut.ravensteg.ru
- domain: hain.ravensteg.ru
- domain: tau.ironweide.ru
- domain: schirm.ironweide.ru
- domain: klee.ironweide.ru
- file: 8.140.200.78
- hash: 80
- file: 43.139.88.57
- hash: 8888
- file: 149.88.81.215
- hash: 18443
- file: 203.91.76.119
- hash: 8080
- file: 45.83.31.50
- hash: 8000
- file: 192.236.147.59
- hash: 2404
- file: 204.10.160.183
- hash: 443
- file: 8.136.241.242
- hash: 8443
- file: 8.136.241.170
- hash: 8443
- file: 8.136.240.81
- hash: 8443
- file: 45.152.243.178
- hash: 443
- file: 64.7.199.71
- hash: 8090
- file: 56.228.6.115
- hash: 35946
- file: 45.156.87.43
- hash: 1911
- file: 5.129.218.245
- hash: 80
- file: 107.170.38.154
- hash: 4443
- file: 3.85.201.51
- hash: 21969
- file: 3.85.201.51
- hash: 44819
- domain: dorn.silverbirke.ru
- domain: wolke.silverbirke.ru
- file: 111.92.240.204
- hash: 5539
- domain: glanz.silverbirke.ru
- file: 45.156.87.43
- hash: 1912
- domain: fjord.wolkenhof.ru
- domain: stern.wolkenhof.ru
- domain: justamap.com
- file: 103.74.194.97
- hash: 443
- domain: eiche.wolkenhof.ru
- file: 5.182.204.156
- hash: 443
- file: 5.182.204.156
- hash: 80
- domain: rauch.neonbuche.ru
- file: 62.210.195.179
- hash: 8180
- domain: korn.neonbuche.ru
- domain: gleis.neonbuche.ru
- domain: bach.cobaltquelle.ru
- domain: tal.cobaltquelle.ru
- domain: weald.cobaltquelle.ru
- domain: sturm.obsidianufer.ru
- domain: pfote.obsidianufer.ru
- domain: licht.obsidianufer.ru
- domain: eis.solarpfad.ru
- domain: kamm.solarpfad.ru
- domain: weiss.solarpfad.ru
- domain: moor.willowgrat.ru
- domain: falke.willowgrat.ru
- domain: rinde.willowgrat.ru
- domain: wolke.thunderkiesel.ru
- domain: bach.thunderkiesel.ru
- domain: grat.thunderkiesel.ru
- domain: nebel.thunderkiesel.ru
- file: 124.198.132.30
- hash: 2107
- domain: funke.thunderkiesel.ru
ThreatFox IOCs for 2025-11-14
Description
ThreatFox IOCs for 2025-11-14
AI-Powered Analysis
Technical Analysis
The threat information pertains to ThreatFox IOCs published on 2025-11-14, classified as malware with a medium severity level. The data originates from the ThreatFox MISP feed, focusing on OSINT-related network activity and payload delivery mechanisms. However, the report lacks specific affected products, versions, or detailed technical indicators, which limits the ability to perform a deep technical analysis. The absence of known exploits in the wild and no available patches suggest that this threat is either emerging or not yet actively exploited. The technical details indicate a low threat level (2 out of an unspecified scale), minimal analysis (1), and moderate distribution (3), implying limited current impact or spread. The lack of CWEs and indicators further restricts actionable insights. The threat likely involves the use of OSINT techniques to identify targets or deliver payloads via network vectors, which could be leveraged by attackers for reconnaissance or initial compromise stages. Without concrete payload or exploit details, the threat remains primarily informational but warrants monitoring due to its potential to facilitate subsequent attacks.
Potential Impact
For European organizations, the impact of this threat is currently moderate due to the lack of specific exploit details or known active campaigns. However, the focus on OSINT and network-based payload delivery suggests potential risks in reconnaissance and initial access phases of cyberattacks. Organizations heavily reliant on open-source intelligence or with extensive network exposure could face increased risk of targeted payload delivery attempts. The absence of patches or mitigations indicates that if exploitation occurs, it may be difficult to counteract without proactive detection. Potential impacts include unauthorized access, data exfiltration, or disruption if payloads are successfully delivered and executed. The medium severity rating reflects these possibilities but also the current limited evidence of active exploitation. European entities in critical infrastructure, finance, or government sectors should remain vigilant given their attractiveness as targets and the strategic value of OSINT in attack planning.
Mitigation Recommendations
Given the limited technical details, mitigation should focus on enhancing OSINT monitoring and network security posture. Organizations should integrate ThreatFox and similar OSINT feeds into their Security Information and Event Management (SIEM) systems to detect emerging indicators promptly. Network traffic analysis tools should be configured to identify unusual payload delivery patterns or suspicious communications. Employ strict network segmentation and enforce least privilege principles to limit payload propagation. Regularly update and patch all systems to reduce attack surface, even though no specific patches are available for this threat. Conduct employee training on recognizing phishing or social engineering attempts that may leverage OSINT-derived information. Collaborate with national Computer Security Incident Response Teams (CSIRTs) to share intelligence and receive timely alerts. Finally, implement robust endpoint detection and response (EDR) solutions to identify and contain payload execution attempts.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- 0190cb35-66a9-47ba-828f-31fc2f6d780f
- Original Timestamp
- 1763164986
Indicators of Compromise
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://154.219.123.95:8888/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://nakaizu.com/6h8h.js | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttps://fcontrols.pro/xhamster.html | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://194.87.55.59/rex.odd | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://192.177.26.210/saver.odd | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dcontrols.pro/xhamster.html | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dcontrols.pro/xxx.html | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://infernolo.com/xxx.html | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://infernolo.com/xhamster.html | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://hcontrol.pro/xxx.html | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://hcontrol.pro/xhamster.html | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://194.87.55.59/dxx.odd | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://3accdomain3.ru/xhamster.html | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://clubdetiroelpicarcho.com/ourzz.wav | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://xxclglglglklgkxlc.com/bxx.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://talentforth.org/lalu.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://appasdmdamsdmasd.com/das | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://ototaikfffkf.com/fffa.js | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://wintars.com/lina.php | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://151.243.18.246/bcvv.wav | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://91.231.222.217/pages/login.php | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttp://103.97.178.243:8888/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://65.21.87.125/48a8a6cd726abeec.php | Stealc botnet C2 (confidence level: 50%) | |
urlhttp://ytbulten.web.tr/ | Hook botnet C2 (confidence level: 50%) | |
urlhttps://managecontrol.top | XWorm payload delivery URL (confidence level: 50%) | |
urlhttps://one-experience-database-4qma.s3.ap-northeast-2.amazonaws.com/yno0tm0enn?id=m7uiimuo2kukkfz | XWorm payload delivery URL (confidence level: 50%) | |
urlhttps://efficient-studio-2022.s3.us-east-1.amazonaws.com/hetneaev47?id=vkbyzhxs37ud | XWorm payload delivery URL (confidence level: 50%) | |
urlhttps://one-experience-database-4qma.s3.ap-northeast-2.amazonaws.com/yno0tm0enn?id=pvhjxkys34anhlb | XWorm payload delivery URL (confidence level: 50%) | |
urlhttps://signin-att.dynamic-iamlrr-controller.appname-success.att-com.printactive.top/ | XWorm payload delivery URL (confidence level: 50%) | |
urlhttps://enterprise-productivity-v2.s3.us-east-2.amazonaws.com/bbbf?id=lane | XWorm payload delivery URL (confidence level: 50%) | |
urlhttps://ebd73a0e-d227-4e72-b385-2f28acd9f66f.server2.nisdably.com/ | Glupteba botnet C2 (confidence level: 50%) | |
urlhttps://api.telegram.org/bot8365730823:aag9wt_xut_pm0y7fkw1cytt2wd7ckk0woi/ | Agent Tesla botnet C2 (confidence level: 50%) | |
urlhttp://hjjpoli13.top/index.php | CryptBot botnet C2 (confidence level: 50%) | |
urlhttp://moraatwoo01.top/index.php | CryptBot botnet C2 (confidence level: 50%) | |
urlhttp://xerrrload08.top/download.php?file=lm.exe | CryptBot botnet C2 (confidence level: 50%) | |
urlhttps://digitline.ch/ | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://hx.mashrift.ru/67kf5nb9 | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://ter.vrolijkecreaties.nl/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://ter.hotelsinjacksonvillefl.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://95.217.25.212/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://49.13.35.2/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://5.75.220.143/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://91.98.239.99/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://sd.r.banana.vu/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://ug.andreeamunteanu.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttp://2.58.15.233/index.php | Koi Loader botnet C2 (confidence level: 100%) | |
urlhttps://omgtelecom.com/6e32s.js | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttps://srimedhasoft.com/xss/buf.js | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://srimedhasoft.com/xss/index.php | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://srimedhasoft.com/xss/bof.js | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://twentyfournow.com/verify | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://www.iconconsultants.com/lopayt.zip | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urltftp://36.93.2.29/.i | Unknown malware payload delivery URL (confidence level: 75%) | |
urlhttps://xxx.vrolijkecreaties.nl/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://xxx.hotelsinnewjerseyatlanticcity.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttp://185.233.164.123/archer.exe | Quasar RAT payload delivery URL (confidence level: 100%) | |
urlhttps://afonoditrixdxcomplany.com/work/ | Latrodectus botnet C2 (confidence level: 75%) | |
urlhttps://bistroilonalkidimosds.com/work/ | Latrodectus botnet C2 (confidence level: 75%) | |
urlhttp://86.54.24.139 | Stealc botnet C2 (confidence level: 100%) |
Domain
| Value | Description | Copy |
|---|---|---|
domaincatlover-pawpaw504.sbs | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domaineasternwhiskerholdings.sbs | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainpuffyclaw2008.shop | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domaincpanel.fjfrey.com | FAKEUPDATES botnet C2 domain (confidence level: 100%) | |
domainnakaizu.com | KongTuke payload delivery domain (confidence level: 100%) | |
domainfcontrols.pro | Unknown malware payload delivery domain (confidence level: 100%) | |
domaindcontrols.pro | Unknown malware payload delivery domain (confidence level: 100%) | |
domaininfernolo.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainhcontrol.pro | Unknown malware payload delivery domain (confidence level: 100%) | |
domain3accdomain3.ru | Unknown malware payload delivery domain (confidence level: 100%) | |
domainasdtvcvchcvhhhhh.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainxxclglglglklgkxlc.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainappasdmdamsdmasd.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainototaikfffkf.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainupdateday.info | Unknown malware payload delivery domain (confidence level: 100%) | |
domainrune.acornhollow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwald.rowanstead.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhafen.rowanstead.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnacht.yewhollow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainweiss.yewhollow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpfad.yewhollow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbal-rewards.xyz | Quasar RAT payload delivery domain (confidence level: 100%) | |
domainrauch.ashriver.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfjord.ashriver.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkorn.ashriver.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfalke.thrushmere.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoos.thrushmere.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainufer.thrushmere.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstein.boulderfield.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlicht.boulderfield.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzorn.boulderfield.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolke.thundergrove.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpfad.thundergrove.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoos.thundergrove.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstern.emberweide.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbach.emberweide.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain4gef4km41aysc.cfc-execute.bj.baidubce.com | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainglut.emberweide.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainadler.quartzfuchs.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkamm.quartzfuchs.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnacht.quartzfuchs.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbirch.cobaltspore.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintau.cobaltspore.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfels.cobaltspore.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingleis.neonkiefer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoor.neonkiefer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineiche.neonkiefer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhafen.auricfluss.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwind.auricfluss.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrune.auricfluss.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlicht.frostweald.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintal.frostweald.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkrone.frostweald.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsturm.cedarberg.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpfote.cedarberg.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainweiss.cedarberg.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainklee.ravenquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmsi25.dynnamn.ru | Remcos botnet C2 domain (confidence level: 100%) | |
domainufer.ravenquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrentwood-operatic.com | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domaingatex.brentwood-operatic.com | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domaingatex.otisgrand.com | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainshop.atrishop.xyz | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainxerrrload08.top | CryptBot botnet C2 domain (confidence level: 50%) | |
domaincloseconection.duckdns.org | DCRat botnet C2 domain (confidence level: 50%) | |
domaineffects-animation.gl.at.ply.gg | DCRat botnet C2 domain (confidence level: 50%) | |
domainrafaborre27.duckdns.org | DCRat botnet C2 domain (confidence level: 50%) | |
domainv2.otisgrand.com | DCRat botnet C2 domain (confidence level: 50%) | |
domainv3.otisgrand.com | DCRat botnet C2 domain (confidence level: 50%) | |
domaincybersecuritefrance.ddns.net | Mirai botnet C2 domain (confidence level: 50%) | |
domainquantaservices.store | Mirai botnet C2 domain (confidence level: 50%) | |
domainvr3b.ddns.net | Mirai botnet C2 domain (confidence level: 50%) | |
domainrcdoncu1906.duckdns.org | Remcos botnet C2 domain (confidence level: 50%) | |
domainremcos26.dynuddns.com | Remcos botnet C2 domain (confidence level: 50%) | |
domainglanz.ravenquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineis.obsidianpfad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbirch.obsidianpfad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingleam.obsidianpfad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainanchor.mashrift.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhx.mashrift.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlnk1man.pages.dev | Unknown malware payload delivery domain (confidence level: 50%) | |
domain0iz7q.mashrift.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintrust007-44490.portmap.host | Unknown RAT botnet C2 domain (confidence level: 50%) | |
domainhover.st0bepress.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingleam.st0bepress.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainter.vrolijkecreaties.nl | Vidar botnet C2 domain (confidence level: 100%) | |
domainter.hotelsinjacksonvillefl.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainwww.dwf1579.vip | PumaBot botnet C2 domain (confidence level: 100%) | |
domainzoo.st0bepress.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshanghai.googledns.io | AhMyth payload delivery domain (confidence level: 50%) | |
domain3z1s.oddkraken.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshift.oddkraken.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain0op3s.oddkraken.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain0315.protohush.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvdj3j.protohush.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsd.r.banana.vu | Vidar botnet C2 domain (confidence level: 100%) | |
domainug.andreeamunteanu.com | Vidar botnet C2 domain (confidence level: 100%) | |
domain6zbr.protohush.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbyte.syrupdock.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpulse8.syrupdock.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainb53.syrupdock.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjarcovilokaserdrinok.com | Latrodectus botnet C2 domain (confidence level: 100%) | |
domainmaukateciklodasresm.com | Latrodectus botnet C2 domain (confidence level: 100%) | |
domainploykalofomarixcley.com | Latrodectus botnet C2 domain (confidence level: 100%) | |
domainsparkle9.ma-shrift.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain2n62w.ma-shrift.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindefupdater.dll | Alien payload delivery domain (confidence level: 75%) | |
domainw1558.ma-shrift.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainflux.flint-zoo.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwhlox.flint-zoo.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainottobattleskaldthrenody.com | donut_injector botnet C2 domain (confidence level: 100%) | |
domainwave.flint-zoo.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainu6.quantmelt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain6m.quantmelt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvale.quantmelt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainz5.bl1nkswitch.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlmn.bl1nkswitch.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainceshioa.us.kg | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainkna.bl1nkswitch.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwww.marmosfinancial.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainyw7.v0xelmint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainuuf.v0xelmint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainomgtelecom.com | KongTuke payload delivery domain (confidence level: 100%) | |
domainsb.v0xelmint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbkp.st-0-bepress.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnova.st-0-bepress.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincms0c.st-0-bepress.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainconfrewdsfgfs.con-ip.com | Remcos botnet C2 domain (confidence level: 100%) | |
domainmr24251.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domainwww.smssending.ns1.name | MimiKatz botnet C2 domain (confidence level: 100%) | |
domain1b8.flintzoo.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainecho.flintzoo.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintrail.flintzoo.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainq40eo.quant-melt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainblink.quant-melt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainflux0.quant-melt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaine8.gleamspan.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainamigor.qpon | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainaudioux.qpon | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainml.gleamspan.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmockerl.qpon | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainshutsra.qpon | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainpoochse.qpon | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainoleaceg.qpon | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainnotionz.qpon | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainevasivr.qpon | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainqkund.gleamspan.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain01efv.odd-kraken.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvibesyncvr.com | Unknown Stealer payload delivery domain (confidence level: 100%) | |
domainkruipro.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainroot.kruipro.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domaindock.odd-kraken.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainorbit.odd-kraken.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsdh3a.knotberry.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqg3q2.knotberry.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain053.knotberry.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsrimedhasoft.com | NetSupportManager RAT payload delivery domain (confidence level: 100%) | |
domaintla.gr1tmodule.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsiq.gr1tmodule.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpx.gr1tmodule.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqvm.z1ncspike.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaino5.z1ncspike.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainanchor.z1ncspike.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainu3z.pr0wldrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainyf.pr0wldrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainquark.pr0wldrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxxx.vrolijkecreaties.nl | Vidar botnet C2 domain (confidence level: 100%) | |
domainxxx.hotelsinnewjerseyatlanticcity.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainvpcp.clipmorrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingetinstallclient32.live | Unknown malware payload delivery domain (confidence level: 100%) | |
domainverificationsbycapcha.center | Unknown malware payload delivery domain (confidence level: 100%) | |
domainhrtf3.clipmorrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain28xr3.clipmorrow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain1wd.viberspan.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmagicupdate.cfd | Aura Stealer botnet C2 domain (confidence level: 100%) | |
domainsearchagent.cfd | Aura Stealer botnet C2 domain (confidence level: 100%) | |
domainmodule7.viberspan.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7u.viberspan.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain5lw6.lumentwist.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmail.outlook365.vip | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domain5z.lumentwist.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain2v1.lumentwist.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindrop7.st1rlingpad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain11v.st1rlingpad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainknot.st1rlingpad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaing0pv.saffronjet.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain1665s.saffronjet.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincore.saffronjet.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfdsgofgjoefjiooe.con-ip.com | Remcos botnet C2 domain (confidence level: 100%) | |
domainenivomarzo12.dynuddns.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainbyte8.hazebinder.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnova8.hazebinder.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainctr.hazebinder.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoos.flintquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrune.flintquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindampf.flintquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainufer.ravensteg.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglut.ravensteg.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhain.ravensteg.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintau.ironweide.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainschirm.ironweide.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainklee.ironweide.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindorn.silverbirke.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolke.silverbirke.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglanz.silverbirke.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfjord.wolkenhof.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstern.wolkenhof.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjustamap.com | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domaineiche.wolkenhof.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrauch.neonbuche.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkorn.neonbuche.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingleis.neonbuche.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbach.cobaltquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintal.cobaltquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainweald.cobaltquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsturm.obsidianufer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpfote.obsidianufer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlicht.obsidianufer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineis.solarpfad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkamm.solarpfad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainweiss.solarpfad.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoor.willowgrat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfalke.willowgrat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrinde.willowgrat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolke.thunderkiesel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbach.thunderkiesel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingrat.thunderkiesel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnebel.thunderkiesel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfunke.thunderkiesel.ru | ClearFake payload delivery domain (confidence level: 100%) |
Hash
| Value | Description | Copy |
|---|---|---|
hashf89aab69e01d21b2c8ce2b8ee9909d25 | Unknown malware payload (confidence level: 100%) | |
hash42b9f136abd20cfe07cd08a9b1631ea8 | Unknown malware payload (confidence level: 100%) | |
hashe46f155df70c8a8c4506a2a42425c1a6 | Unknown malware payload (confidence level: 100%) | |
hash3778 | Mirai botnet C2 server (confidence level: 80%) | |
hash20473 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash31975 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash54096 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash23 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash28045 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash5060 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash1796 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash8080 | Bashlite botnet C2 server (confidence level: 100%) | |
hash13000 | Quasar RAT botnet C2 server (confidence level: 75%) | |
hash13000 | Quasar RAT botnet C2 server (confidence level: 75%) | |
hash3778 | Mirai botnet C2 server (confidence level: 80%) | |
hash7889 | PureLogs Stealer botnet C2 server (confidence level: 100%) | |
hash6666 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Latrodectus botnet C2 server (confidence level: 100%) | |
hash443 | Latrodectus botnet C2 server (confidence level: 100%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash24321 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash1912 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
hash80 | Ficker Stealer botnet C2 server (confidence level: 50%) | |
hash3289 | Remcos botnet C2 server (confidence level: 50%) | |
hash1616 | Remcos botnet C2 server (confidence level: 50%) | |
hash8443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash81 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8088 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash4433 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash55550 | PumaBot botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Latrodectus botnet C2 server (confidence level: 100%) | |
hash8463 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Unknown RAT botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash31337 | Sliver botnet C2 server (confidence level: 100%) | |
hash80 | Hook botnet C2 server (confidence level: 100%) | |
hash8080 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash81 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash1911 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
hash8082 | ERMAC botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash8888 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash2244 | XWorm botnet C2 server (confidence level: 75%) | |
hash2052 | Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash8443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash48254 | Remcos botnet C2 server (confidence level: 100%) | |
hash1977 | Remcos botnet C2 server (confidence level: 100%) | |
hash83ac4cb463bbbdab3c758f9fdfe0cc52c69364ec0ad9a21a8687dac28cd74c27 | BKA Trojaner payload (confidence level: 100%) | |
hash32962 | Mirai botnet C2 server (confidence level: 80%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 90%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8089 | Hook botnet C2 server (confidence level: 100%) | |
hash8089 | Hook botnet C2 server (confidence level: 100%) | |
hash80 | Havoc botnet C2 server (confidence level: 100%) | |
hash8443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | XWorm botnet C2 server (confidence level: 100%) | |
hash9861 | Remcos botnet C2 server (confidence level: 100%) | |
hash81 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash8080 | ERMAC botnet C2 server (confidence level: 100%) | |
hash4444 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash443 | Meterpreter botnet C2 server (confidence level: 75%) | |
hash443 | Meterpreter botnet C2 server (confidence level: 75%) | |
hash443 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash5873 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash1312 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash8088 | DCRat botnet C2 server (confidence level: 100%) | |
hash16446 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash4444 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash53 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash53 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash8888 | Sliver botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash18443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8000 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Remcos botnet C2 server (confidence level: 100%) | |
hash8443 | Sliver botnet C2 server (confidence level: 100%) | |
hash8443 | Sliver botnet C2 server (confidence level: 100%) | |
hash8443 | Sliver botnet C2 server (confidence level: 100%) | |
hash443 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8090 | DCRat botnet C2 server (confidence level: 100%) | |
hash35946 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash1911 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
hash80 | Chaos botnet C2 server (confidence level: 100%) | |
hash4443 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash21969 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash44819 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash5539 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash1912 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash8180 | Cobalt Strike botnet C2 server (confidence level: 90%) | |
hash2107 | AsyncRAT botnet C2 server (confidence level: 100%) |
File
| Value | Description | Copy |
|---|---|---|
file31.58.247.201 | Mirai botnet C2 server (confidence level: 80%) | |
file102.205.170.10 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file102.205.170.10 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file102.205.170.10 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file102.205.170.10 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file102.205.170.10 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file102.205.170.10 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file102.205.170.10 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file45.153.34.35 | Bashlite botnet C2 server (confidence level: 100%) | |
file139.59.23.248 | Quasar RAT botnet C2 server (confidence level: 75%) | |
file193.161.193.99 | Quasar RAT botnet C2 server (confidence level: 75%) | |
file213.255.209.93 | Mirai botnet C2 server (confidence level: 80%) | |
file104.168.115.89 | PureLogs Stealer botnet C2 server (confidence level: 100%) | |
file146.56.216.116 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file123.207.20.187 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file91.92.243.167 | Latrodectus botnet C2 server (confidence level: 100%) | |
file91.92.243.164 | Latrodectus botnet C2 server (confidence level: 100%) | |
file47.104.11.241 | Unknown malware botnet C2 server (confidence level: 100%) | |
file180.93.227.136 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file130.61.47.176 | Havoc botnet C2 server (confidence level: 100%) | |
file155.138.162.86 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file46.224.4.226 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
file5.79.102.209 | Ficker Stealer botnet C2 server (confidence level: 50%) | |
file185.101.34.110 | Remcos botnet C2 server (confidence level: 50%) | |
file195.177.94.40 | Remcos botnet C2 server (confidence level: 50%) | |
file138.226.236.62 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file106.75.162.108 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file119.91.37.94 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file47.119.178.247 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file117.72.206.244 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file123.56.16.123 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file111.228.3.39 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file91.98.151.0 | Vidar botnet C2 server (confidence level: 100%) | |
file156.234.207.194 | PumaBot botnet C2 server (confidence level: 75%) | |
file47.120.67.103 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file91.92.243.166 | Latrodectus botnet C2 server (confidence level: 100%) | |
file216.252.238.41 | Remcos botnet C2 server (confidence level: 100%) | |
file198.55.102.71 | Remcos botnet C2 server (confidence level: 100%) | |
file198.23.175.60 | Remcos botnet C2 server (confidence level: 100%) | |
file185.243.112.253 | Unknown RAT botnet C2 server (confidence level: 100%) | |
file94.103.0.190 | Sliver botnet C2 server (confidence level: 100%) | |
file45.150.108.93 | Sliver botnet C2 server (confidence level: 100%) | |
file5.180.81.66 | Hook botnet C2 server (confidence level: 100%) | |
file181.162.150.252 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file84.154.188.167 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file91.92.243.215 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
file5.180.81.66 | ERMAC botnet C2 server (confidence level: 100%) | |
file95.217.25.212 | Vidar botnet C2 server (confidence level: 100%) | |
file49.13.35.2 | Vidar botnet C2 server (confidence level: 100%) | |
file5.75.220.143 | Vidar botnet C2 server (confidence level: 100%) | |
file91.98.239.99 | Vidar botnet C2 server (confidence level: 100%) | |
file151.242.20.91 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file185.222.58.49 | XWorm botnet C2 server (confidence level: 75%) | |
file212.7.200.238 | Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%) | |
file101.42.31.153 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file120.24.61.117 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file146.56.194.84 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file5.101.86.3 | Remcos botnet C2 server (confidence level: 100%) | |
file198.23.177.196 | Remcos botnet C2 server (confidence level: 100%) | |
file193.26.115.214 | Mirai botnet C2 server (confidence level: 80%) | |
file180.76.240.53 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file47.79.34.160 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file212.80.213.212 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file103.103.21.230 | Sliver botnet C2 server (confidence level: 90%) | |
file104.234.204.20 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file206.81.21.81 | Unknown malware botnet C2 server (confidence level: 100%) | |
file77.110.115.14 | Hook botnet C2 server (confidence level: 100%) | |
file5.180.81.66 | Hook botnet C2 server (confidence level: 100%) | |
file4.218.10.81 | Havoc botnet C2 server (confidence level: 100%) | |
file183.90.150.110 | Unknown malware botnet C2 server (confidence level: 100%) | |
file44.223.143.23 | Unknown malware botnet C2 server (confidence level: 100%) | |
file159.69.211.99 | Unknown malware botnet C2 server (confidence level: 100%) | |
file159.69.211.99 | Unknown malware botnet C2 server (confidence level: 100%) | |
file143.110.187.42 | Unknown malware botnet C2 server (confidence level: 100%) | |
file149.3.170.50 | Unknown malware botnet C2 server (confidence level: 100%) | |
file104.248.24.98 | Unknown malware botnet C2 server (confidence level: 100%) | |
file39.106.42.38 | Unknown malware botnet C2 server (confidence level: 100%) | |
file54.155.189.199 | Unknown malware botnet C2 server (confidence level: 100%) | |
file202.151.176.128 | Unknown malware botnet C2 server (confidence level: 100%) | |
file202.151.176.128 | Unknown malware botnet C2 server (confidence level: 100%) | |
file159.65.48.193 | Unknown malware botnet C2 server (confidence level: 100%) | |
file51.77.192.147 | Unknown malware botnet C2 server (confidence level: 100%) | |
file95.81.76.77 | XWorm botnet C2 server (confidence level: 100%) | |
file91.92.243.134 | Remcos botnet C2 server (confidence level: 100%) | |
file79.241.110.210 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file38.180.149.179 | ERMAC botnet C2 server (confidence level: 100%) | |
file202.128.127.94 | Meterpreter botnet C2 server (confidence level: 100%) | |
file173.212.239.206 | Meterpreter botnet C2 server (confidence level: 75%) | |
file3.133.102.58 | Meterpreter botnet C2 server (confidence level: 75%) | |
file5.252.178.35 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file5.75.217.93 | Vidar botnet C2 server (confidence level: 100%) | |
file123.11.255.35 | Unknown malware botnet C2 server (confidence level: 100%) | |
file124.222.182.210 | Unknown malware botnet C2 server (confidence level: 100%) | |
file80.211.238.184 | Venom RAT botnet C2 server (confidence level: 100%) | |
file137.220.156.69 | DCRat botnet C2 server (confidence level: 100%) | |
file16.52.72.37 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file80.253.249.102 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file149.28.148.209 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file27.124.19.123 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file15.197.91.241 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file91.92.241.119 | Sliver botnet C2 server (confidence level: 75%) | |
file8.140.200.78 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file43.139.88.57 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file149.88.81.215 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file203.91.76.119 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file45.83.31.50 | Remcos botnet C2 server (confidence level: 100%) | |
file192.236.147.59 | Remcos botnet C2 server (confidence level: 100%) | |
file204.10.160.183 | Remcos botnet C2 server (confidence level: 100%) | |
file8.136.241.242 | Sliver botnet C2 server (confidence level: 100%) | |
file8.136.241.170 | Sliver botnet C2 server (confidence level: 100%) | |
file8.136.240.81 | Sliver botnet C2 server (confidence level: 100%) | |
file45.152.243.178 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file64.7.199.71 | DCRat botnet C2 server (confidence level: 100%) | |
file56.228.6.115 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file45.156.87.43 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
file5.129.218.245 | Chaos botnet C2 server (confidence level: 100%) | |
file107.170.38.154 | Meterpreter botnet C2 server (confidence level: 100%) | |
file3.85.201.51 | Meterpreter botnet C2 server (confidence level: 100%) | |
file3.85.201.51 | Meterpreter botnet C2 server (confidence level: 100%) | |
file111.92.240.204 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file45.156.87.43 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
file103.74.194.97 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file5.182.204.156 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file5.182.204.156 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file62.210.195.179 | Cobalt Strike botnet C2 server (confidence level: 90%) | |
file124.198.132.30 | AsyncRAT botnet C2 server (confidence level: 100%) |
Threat ID: 6917c3f5ed594783724dd8d8
Added to database: 11/15/2025, 12:06:13 AM
Last enriched: 11/15/2025, 12:06:59 AM
Last updated: 11/16/2025, 4:13:53 AM
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
ThreatFox IOCs for 2025-11-15
MediumNew Security Tools Target Growing macOS Threats
MediumOperation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown
MediumNorth Korean Hackers Turn JSON Services into Covert Malware Delivery Channels
MediumNovaStealer - Apple Intelligence is leaving a plist.. it is legit, right?
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.