ThreatFox IOCs for 2025-11-21
ThreatFox IOCs for 2025-11-21
AI Analysis
Technical Summary
The ThreatFox IOCs for 2025-11-21 represent a set of Indicators of Compromise disseminated through the ThreatFox MISP feed, which is an open-source threat intelligence platform. These IOCs are categorized under malware, specifically focusing on OSINT (Open Source Intelligence), network activity, and payload delivery mechanisms. The data does not specify any particular affected software versions or products, indicating that the IOCs may be generic or broadly applicable rather than tied to a specific vulnerability or exploit. No patches or fixes are available, and there are no known active exploits in the wild, suggesting this is an intelligence update rather than an active threat campaign. The technical details provided include a threat level of 2 (on an unspecified scale), an analysis rating of 1, and a distribution rating of 3, which may imply moderate dissemination but limited analysis depth. The absence of concrete indicators or CWEs (Common Weakness Enumerations) limits the ability to perform a detailed technical dissection. The primary value of this information lies in its use for enhancing situational awareness and improving detection capabilities through integration into security monitoring tools. The categorization under network activity and payload delivery highlights the potential for these IOCs to be associated with malware delivery via network vectors, which is a common attack vector in contemporary cyber threats.
Potential Impact
For European organizations, the impact of these IOCs depends largely on their ability to integrate and act upon threat intelligence feeds. Since no specific exploits or vulnerabilities are identified, the immediate risk is low to medium. However, the presence of network activity and payload delivery indicators suggests a potential for malware infections if these IOCs correspond to active or emerging threats. Organizations with extensive network infrastructure and critical services could face disruptions or data breaches if such payloads are successfully delivered and executed. The lack of patches or fixes means that prevention relies heavily on detection and response capabilities. Failure to incorporate these IOCs into security monitoring could result in delayed detection of malware campaigns, increasing the risk of compromise. Additionally, the medium severity rating indicates that while the threat is not critical, it should not be ignored, especially in sectors with high-value data or critical infrastructure. The impact is also influenced by the organization's maturity in threat intelligence consumption and network security posture.
Mitigation Recommendations
To mitigate risks associated with these ThreatFox IOCs, European organizations should: 1) Integrate the ThreatFox MISP feed and similar OSINT sources into their Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) systems to enable real-time detection of related indicators. 2) Enhance network monitoring to identify unusual or suspicious payload delivery attempts, focusing on traffic patterns that match the characteristics of the shared IOCs. 3) Conduct regular threat hunting exercises using the updated IOCs to proactively identify potential compromises. 4) Implement strict network segmentation and access controls to limit the spread of malware if payload delivery occurs. 5) Educate security teams on interpreting and operationalizing OSINT feeds to improve response times. 6) Maintain up-to-date backups and incident response plans to minimize impact in case of infection. 7) Collaborate with national and European cybersecurity centers to share intelligence and receive timely alerts about emerging threats. These steps go beyond generic advice by emphasizing the operational integration of threat intelligence and proactive network defense tailored to the nature of the IOCs.
Affected Countries
Germany, France, United Kingdom, Netherlands, Italy
Indicators of Compromise
- file: 31.129.54.227
- hash: 443
- hash: 59d3a806684dfc3e0d6a9fac5f349e0a08a628e9307acbc29b14012f8dd9c48c
- hash: 80ea6b70823ebc4f76d9af3e72c268862c5a1deeacc09066e1c87636a46c0866
- hash: a6dfdfa0dda4c9b2d3767ed44b49f858c2df2f049b8606f85c0219076ad91111
- hash: e33e882a1bf4ef13b23f33e76575fac5e48b265b316727e462109fb8bd0d9a35
- hash: f42b4366500178d40380d21433efea12cdc5aa66eebb74ec6820adf00a29ae6b
- hash: 2178a927cb1486293bb77fc394dc53d7dd7b1b3c1a97b4f84591616d4c921edd
- hash: 68bd4f1a56632380307f892f32e59e481269caabd1d076abf6a824ace474d82e
- hash: b250ef40ab3cc5cae98cab7da42245f1b30021b52082d8fa83f5b550c8997478
- hash: c42fccdf608e98be7739915a086f49c3bb7328ae3fc3662b1abc2894a9792570
- hash: d1ec6b46ad22793485504e969661c9e79c5a3f8b84a5e76538955a6c684300b1
- hash: da9551fc5564a6958b3aa72edc88b71d00d12ddc5cdb9f6038c07512bd56e502
- domain: gog.nigeriaafricatime.com
- domain: tgk.clashofmaps.vip
- url: https://31.129.54.227/
- file: 193.233.245.114
- hash: 38990
- domain: api.cpibot.com
- domain: portabalbufe.com
- url: http://91.92.243.129/0gjsy4hf3/login.php
- url: https://seiho-ouyou.com/
- url: https://bongoshare.bishtelecom.com/
- url: https://xerovent.org/
- url: https://lcontrols4.ru/xhamster.html
- url: https://workcrms.abesecom.co.in/
- file: 123.58.64.57
- hash: 34567
- file: 91.231.222.184
- hash: 5000
- file: 104.168.5.56
- hash: 5000
- file: 77.90.185.239
- hash: 9000
- file: 95.111.217.209
- hash: 443
- file: 165.232.126.106
- hash: 4321
- file: 175.17.182.112
- hash: 10001
- domain: kamm.m1ntcioud.ru
- domain: glanz7.m1ntcioud.ru
- domain: weiss.m1ntcioud.ru
- domain: bach.stormpeak.ru
- domain: tal.stormpeak.ru
- domain: grat.stormpeak.ru
- domain: wolke2.stormpeak.ru
- domain: wolke.kab1spr0tect.ru
- domain: glade.kab1spr0tect.ru
- domain: tau3.kab1spr0tect.ru
- domain: korn.kab1spr0tect.ru
- file: 193.161.193.99
- hash: 31009
- domain: moor.inha4itmu1ti.ru
- domain: ufer1.inha4itmu1ti.ru
- domain: pfad.inha4itmu1ti.ru
- domain: geist.dis-5-h-7-gien.ru
- domain: eiche.dis-5-h-7-gien.ru
- domain: falke.dis-5-h-7-gien.ru
- domain: wind2.dis-5-h-7-gien.ru
- domain: bach.dis-5-h-7-gien.ru
- url: http://cd672412.tw1.ru/d8123622.php
- domain: wolfe.kab-1-spr-0-tect.ru
- domain: stern.kab-1-spr-0-tect.ru
- domain: rune4.kab-1-spr-0-tect.ru
- domain: klee.kab-1-spr-0-tect.ru
- domain: licht.dinfectt-0-rs-0.ru
- url: http://156.252.63.98:8888/supershell/login/
- file: 175.178.149.35
- hash: 8088
- file: 38.55.192.138
- hash: 443
- file: 147.124.221.176
- hash: 2404
- file: 46.151.24.12
- hash: 80
- file: 208.69.78.192
- hash: 31337
- file: 164.92.191.215
- hash: 4443
- file: 156.252.63.101
- hash: 8888
- file: 66.94.103.70
- hash: 8808
- file: 34.172.85.181
- hash: 3000
- file: 81.169.170.55
- hash: 9443
- file: 102.98.82.32
- hash: 443
- file: 141.98.6.51
- hash: 80
- file: 168.245.201.250
- hash: 3790
- domain: tal.dinfectt-0-rs-0.ru
- domain: grat.dinfectt-0-rs-0.ru
- domain: hafen2.dinfectt-0-rs-0.ru
- domain: weald.kick-5-ubs-4-ance.ru
- domain: brise5.kick-5-ubs-4-ance.ru
- domain: moor.kick-5-ubs-4-ance.ru
- domain: adler.gu5hnatr3mb.ru
- domain: wolke.gu5hnatr3mb.ru
- domain: dune.gu5hnatr3mb.ru
- domain: gleis.gu5hnatr3mb.ru
- domain: nest1.gu5hnatr3mb.ru
- domain: sturm.in-ha-4-it-mu-1-ti.ru
- file: 158.94.209.169
- hash: 6077
- domain: cut-cash.gl.at.ply.gg
- file: 91.231.222.180
- hash: 2404
- domain: josesi4418-31009.portmap.host
- url: http://158.94.208.130
- url: http://91.212.150.45
- domain: xyk33.cyou
- file: 213.152.162.110
- hash: 39439
- domain: appremiumoilfield.duckdns.org
- domain: linmaco001.abrdns.com
- domain: wald.in-ha-4-it-mu-1-ti.ru
- domain: fjord3.in-ha-4-it-mu-1-ti.ru
- domain: kamm.in-ha-4-it-mu-1-ti.ru
- domain: rauch.dis5h7gien.ru
- domain: wolke2.dis5h7gien.ru
- domain: pfad.dis5h7gien.ru
- domain: glanz.kick5ubs4ance.ru
- domain: ufer.kick5ubs4ance.ru
- domain: mircd.hokkien.my.id
- domain: mircd.xiao.my.id
- domain: krone.kick5ubs4ance.ru
- domain: tau1.kick5ubs4ance.ru
- domain: klee.dinfectt0rs0.ru
- domain: birch.dinfectt0rs0.ru
- url: https://fvd.wallyapp.xyz/
- url: https://fvd.noisolation.org.uk/
- url: https://94.130.189.15/
- url: https://delivery.parsflowers.com/
- domain: fvd.wallyapp.xyz
- domain: fvd.noisolation.org.uk
- domain: delivery.parsflowers.com
- file: 78.47.161.107
- hash: 443
- file: 116.203.4.84
- hash: 443
- file: 94.130.189.15
- hash: 443
- file: 60.204.139.145
- hash: 5555
- file: 123.60.60.119
- hash: 801
- file: 39.97.47.45
- hash: 5555
- url: https://hiddenpoly.markets/
- url: https://45.88.76.238/3b55d279dd60140c.php
- url: https://lbaiawugmhxp7t6pczm3.bianco.com.mx/
- url: https://aa.fahrenheitacfl.com/
- url: https://aa.consultoriapericial.com/
- url: https://a.kehribarinsaat.com/
- domain: moor4.dinfectt0rs0.ru
- url: http://mngrblgvopedwfeongv6xbf8ukd7qz.testerta.pwtruckwright.cfd/
- url: https://servlcenow.com/
- url: https://www.aa.fahrenheitacfl.com/
- domain: csam.www.moroccancam.com
- domain: serviciospkkm.duckdns.org
- domain: child-porn.womensoundoff.com
- domain: freeporn.womensoundoff.com
- domain: sex-child.womensoundoff.com
- file: 156.247.41.70
- hash: 8848
- domain: play.mclighthouse.ir
- domain: julio31.con-ip.com
- domain: zuwkanuikekauwawebarugibikonemwehnhumdon.duckdns.org
- file: 80.85.154.41
- hash: 7777
- file: 43.249.175.93
- hash: 5423
- file: 175.178.149.35
- hash: 443
- file: 46.151.24.12
- hash: 443
- file: 104.168.5.56
- hash: 2404
- file: 64.176.17.3
- hash: 443
- file: 89.116.164.107
- hash: 8808
- file: 193.29.13.67
- hash: 15647
- domain: wolfe.gu-5-hnatr-3-mb.ru
- domain: blitz.gu-5-hnatr-3-mb.ru
- domain: weiss.gu-5-hnatr-3-mb.ru
- hash: 3ca4cb5499ac164a6af42f3e852d4d804d0bd440739746567364c922d3be7b36
- hash: a8cf98b8e71e4800662e5fa1f73e8f730d51989379f7080e89eb439de1aee238
- hash: 94d887bd9e17ef1d032b1ade397c8cdb06ad5bee97ee2acbea986815812e7833
- hash: 3dfeaec000f3ed10fcc5e73e4511c8fae039625abb7c3ad78bd0494b9e806248
- hash: 8ace4e3efde30f300d3c116b03ddf62b3ed8b289363f6cb97f441229b9765786
- hash: 1a7cc94fc56632039953e36a6c1deb26451416d9315e00ec0a930417fd443c2a
- hash: 86623fea2bd4b84059577d1af23790421a9a054f8021c3628f5f4e45feb292ef
- hash: 1382e61009a959a78baad1ed49599c84509e99aad0f2b8aaf8aa34fecff6e61f
- domain: rune.gu-5-hnatr-3-mb.ru
- url: http://160.250.247.152/arc
- url: http://160.250.247.152/arm
- url: http://160.250.247.152/arm5
- url: http://160.250.247.152/arm7
- url: http://160.250.247.152/mips
- url: http://160.250.247.152/mpsl
- url: http://160.250.247.152/ppc
- url: http://160.250.247.152/sh4
- file: 104.140.154.147
- hash: 30125
- file: 104.140.154.187
- hash: 30251
- file: 139.84.208.222
- hash: 443
- file: 189.140.37.235
- hash: 443
- domain: bach2.gu-5-hnatr-3-mb.ru
- domain: yyb0w.shad0wmist.ru
- file: 196.251.100.20
- hash: 55008
- file: 54.166.128.216
- hash: 443
- file: 37.59.112.22
- hash: 8000
- file: 52.156.27.122
- hash: 443
- file: 94.156.119.170
- hash: 443
- file: 115.120.248.106
- hash: 443
- file: 47.79.88.143
- hash: 8443
- file: 62.234.150.115
- hash: 8099
- file: 4.201.220.7
- hash: 80
- file: 40.67.149.122
- hash: 443
- file: 156.234.101.186
- hash: 7634
- file: 23.248.214.6
- hash: 7634
- file: 23.235.187.69
- hash: 7634
- file: 217.154.162.45
- hash: 5566
- domain: nf0g.shad0wmist.ru
- file: 118.107.46.74
- hash: 6666
- domain: bj1s.shad0wmist.ru
- domain: crest5.shad0wmist.ru
- domain: drift.rapidst0ne.ru
- domain: mist8.rapidst0ne.ru
- domain: ridge.rapidst0ne.ru
- domain: kj.rapidst0ne.ru
- domain: stone.skybl1ss.ru
- domain: crest3.skybl1ss.ru
- domain: wild6.skybl1ss.ru
- domain: drift8.skybl1ss.ru
- domain: nova.m1ntflare.ru
- file: 159.89.26.251
- hash: 3696
- url: http://23.94.126.153:1133/check_version
- url: http://23.94.126.153:1133/send_file
- domain: 61.m1ntflare.ru
- file: 1.13.247.208
- hash: 80
- domain: blue.m1ntflare.ru
- domain: sky.m1ntflare.ru
- file: 107.173.180.173
- hash: 2053
- file: 23.235.172.18
- hash: 5423
- file: 156.234.94.217
- hash: 6671
- file: 15.237.184.174
- hash: 443
- file: 144.126.149.104
- hash: 20400
- file: 89.116.164.107
- hash: 5555
- file: 217.60.38.11
- hash: 8082
- file: 4.213.225.251
- hash: 3333
- file: 59.124.9.77
- hash: 443
- file: 195.143.125.120
- hash: 3333
- file: 41.231.122.52
- hash: 8443
- file: 115.190.92.164
- hash: 3333
- file: 190.110.41.114
- hash: 3333
- domain: 731.b1uespark.ru
- domain: sun.b1uespark.ru
- domain: tw80g.b1uespark.ru
- domain: spark5.b1uespark.ru
- domain: flare.suncrest0n.ru
- file: 91.92.242.140
- hash: 5009
- domain: 6xnq.suncrest0n.ru
- domain: shadow.suncrest0n.ru
- file: 38.55.192.138
- hash: 8080
- domain: 6menpanelgrace99.duckdns.org
- domain: cucuketeee.dynuddns.com
- domain: goloe2.duckdns.org
- file: 107.173.47.136
- hash: 2404
- file: 91.231.222.184
- hash: 2404
- file: 45.9.148.22
- hash: 8080
- file: 118.107.46.74
- hash: 8888
- file: 103.86.44.167
- hash: 69
- file: 103.86.44.167
- hash: 73
- file: 103.86.44.167
- hash: 288
- file: 38.162.117.58
- hash: 3322
- file: 103.119.15.173
- hash: 3322
- domain: 0i4.suncrest0n.ru
- file: 196.251.100.20
- hash: 5542
- file: 192.229.115.159
- hash: 7881
- file: 192.229.115.159
- hash: 7880
- domain: ee2x.w1ldforge.ru
- domain: vale4.w1ldforge.ru
- domain: pulse1.w1ldforge.ru
- domain: d17.w1ldforge.ru
- file: 23.94.126.153
- hash: 1133
- domain: 1e8.stonecl0ud.ru
- domain: wild0.stonecl0ud.ru
- domain: qm.stonecl0ud.ru
- url: https://medinflow.com/5t5t.js
- domain: medinflow.com
- url: https://medinflow.com/js.php
- url: http://199.217.99.96:6655/alph
- domain: lr.stonecl0ud.ru
- domain: 3y.brightridge.ru
- domain: rapid.brightridge.ru
- url: https://efcst.org/help/scholarships/?utm_source=chatgpt.com
- domain: 96btv.brightridge.ru
- domain: 7l.brightridge.ru
- url: https://hop.wallyapp.xyz/
- url: https://hop.noisolation.org.uk/
- file: 205.209.99.112
- hash: 8990
- domain: hop.wallyapp.xyz
- domain: hop.noisolation.org.uk
- domain: bv.fro5tlane.ru
- domain: xcx.fro5tlane.ru
- domain: silver9.fro5tlane.ru
- domain: vale3.fro5tlane.ru
- domain: pulse.mintforge.ru
- domain: 35y.mintforge.ru
- domain: 5i.mintforge.ru
- domain: uy3hc.mintforge.ru
- domain: sage8.cioudnest.ru
- domain: vale.cioudnest.ru
- domain: nsi.cioudnest.ru
- domain: feedback.rightontheroad.com
- domain: silver.cioudnest.ru
- domain: u3i3y.st0nefield.ru
- domain: lpx.st0nefield.ru
- domain: cloud8.st0nefield.ru
- domain: mint.st0nefield.ru
- domain: nest5.windfiare.ru
- domain: cloud4.windfiare.ru
- file: 111.228.35.33
- hash: 7878
- file: 175.27.227.41
- hash: 19999
- file: 124.198.132.99
- hash: 5000
- file: 80.76.49.172
- hash: 443
- file: 216.250.252.233
- hash: 443
- file: 93.113.214.168
- hash: 80
- file: 165.227.129.255
- hash: 443
- file: 165.227.129.255
- hash: 7443
- file: 185.72.199.83
- hash: 8080
- file: 185.196.9.213
- hash: 8000
- file: 46.62.246.163
- hash: 9090
- domain: cloud.windfiare.ru
- domain: lbs.windfiare.ru
- domain: nova4.silverr0ot.ru
- domain: mint3.silverr0ot.ru
- domain: storm.silverr0ot.ru
- domain: frost8.silverr0ot.ru
- domain: hello.tgllsy.bar
- domain: v9.brightsage.ru
- domain: q6.brightsage.ru
- url: https://leojbl.xin/qiue
- domain: 5obr8.brightsage.ru
- domain: bpk.brightsage.ru
- domain: bloom.stormbioom.ru
- domain: 6tpmi.stormbioom.ru
- domain: lake.stormbioom.ru
- domain: qsa1.stormbioom.ru
- file: 202.73.4.100
- hash: 6666
- domain: said-letter.gl.at.ply.gg
- file: 198.135.54.36
- hash: 40164
- domain: nas064gjgfebvbutebbtakethisasitisbhfdnmn.duckdns.org
- url: http://80.97.160.198
- domain: tickets-somewhat.gl.at.ply.gg
- domain: 2h6.mistfaii.ru
- domain: s2awscloudupdates.com
- domain: cloud2.mistfaii.ru
- domain: cr.mistfaii.ru
- domain: 383cc.mistfaii.ru
- file: 124.198.132.68
- hash: 8080
- file: 18.102.94.254
- hash: 443
- file: 186.105.109.59
- hash: 443
- file: 186.105.118.255
- hash: 443
- file: 65.20.108.228
- hash: 3000
- domain: fkk4m.iunarpeak.ru
- domain: lwch.iunarpeak.ru
- domain: flare.iunarpeak.ru
- domain: ngytp.iunarpeak.ru
- domain: lane7.emberiake.ru
- domain: sage.emberiake.ru
- domain: vsieh.emberiake.ru
- domain: vh.emberiake.ru
- file: 123.53.36.199
- hash: 54002
- file: 108.174.56.152
- hash: 2404
- file: 89.116.164.107
- hash: 2003
- file: 151.243.18.201
- hash: 9000
- file: 45.9.148.22
- hash: 7443
- file: 217.60.38.40
- hash: 8089
- file: 178.16.52.64
- hash: 8082
- file: 217.156.8.145
- hash: 443
- domain: wolke.brightf0rge.ru
- file: 37.114.37.213
- hash: 80
- file: 31.172.87.151
- hash: 80
- file: 194.87.55.166
- hash: 4321
- domain: pfad2.brightf0rge.ru
- domain: eiche.brightf0rge.ru
- domain: rune.brightf0rge.ru
- domain: taiga.iunarblend.ru
- domain: glade.iunarblend.ru
- domain: kamm1.iunarblend.ru
- domain: fjord.wiidharbor.ru
- domain: ufer.wiidharbor.ru
- domain: moos.wiidharbor.ru
- domain: brise4.wiidharbor.ru
- domain: korn.wiidharbor.ru
- file: 167.148.195.154
- hash: 55508
- domain: wolfe.deepstream.ru
- domain: bach.deepstream.ru
- domain: tal2.deepstream.ru
- domain: gleam.starcresting.ru
- domain: nebel.starcresting.ru
- domain: falke1.starcresting.ru
- file: 158.51.125.27
- hash: 3114
- domain: jsbot.dzbot.top
- domain: pfote.starcresting.ru
- domain: birch.m1styvaive.ru
- domain: weald.m1styvaive.ru
- domain: glow2.m1styvaive.ru
- domain: rill.m1styvaive.ru
- domain: shady.m1styvaive.ru
- domain: rauch.mintstone.ru
- domain: klee.mintstone.ru
ThreatFox IOCs for 2025-11-21
Description
ThreatFox IOCs for 2025-11-21
AI-Powered Analysis
Technical Analysis
The ThreatFox IOCs for 2025-11-21 represent a set of Indicators of Compromise disseminated through the ThreatFox MISP feed, which is an open-source threat intelligence platform. These IOCs are categorized under malware, specifically focusing on OSINT (Open Source Intelligence), network activity, and payload delivery mechanisms. The data does not specify any particular affected software versions or products, indicating that the IOCs may be generic or broadly applicable rather than tied to a specific vulnerability or exploit. No patches or fixes are available, and there are no known active exploits in the wild, suggesting this is an intelligence update rather than an active threat campaign. The technical details provided include a threat level of 2 (on an unspecified scale), an analysis rating of 1, and a distribution rating of 3, which may imply moderate dissemination but limited analysis depth. The absence of concrete indicators or CWEs (Common Weakness Enumerations) limits the ability to perform a detailed technical dissection. The primary value of this information lies in its use for enhancing situational awareness and improving detection capabilities through integration into security monitoring tools. The categorization under network activity and payload delivery highlights the potential for these IOCs to be associated with malware delivery via network vectors, which is a common attack vector in contemporary cyber threats.
Potential Impact
For European organizations, the impact of these IOCs depends largely on their ability to integrate and act upon threat intelligence feeds. Since no specific exploits or vulnerabilities are identified, the immediate risk is low to medium. However, the presence of network activity and payload delivery indicators suggests a potential for malware infections if these IOCs correspond to active or emerging threats. Organizations with extensive network infrastructure and critical services could face disruptions or data breaches if such payloads are successfully delivered and executed. The lack of patches or fixes means that prevention relies heavily on detection and response capabilities. Failure to incorporate these IOCs into security monitoring could result in delayed detection of malware campaigns, increasing the risk of compromise. Additionally, the medium severity rating indicates that while the threat is not critical, it should not be ignored, especially in sectors with high-value data or critical infrastructure. The impact is also influenced by the organization's maturity in threat intelligence consumption and network security posture.
Mitigation Recommendations
To mitigate risks associated with these ThreatFox IOCs, European organizations should: 1) Integrate the ThreatFox MISP feed and similar OSINT sources into their Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) systems to enable real-time detection of related indicators. 2) Enhance network monitoring to identify unusual or suspicious payload delivery attempts, focusing on traffic patterns that match the characteristics of the shared IOCs. 3) Conduct regular threat hunting exercises using the updated IOCs to proactively identify potential compromises. 4) Implement strict network segmentation and access controls to limit the spread of malware if payload delivery occurs. 5) Educate security teams on interpreting and operationalizing OSINT feeds to improve response times. 6) Maintain up-to-date backups and incident response plans to minimize impact in case of infection. 7) Collaborate with national and European cybersecurity centers to share intelligence and receive timely alerts about emerging threats. These steps go beyond generic advice by emphasizing the operational integration of threat intelligence and proactive network defense tailored to the nature of the IOCs.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- 4fc338d9-12d7-4d48-bfd6-6d854a51510c
- Original Timestamp
- 1763769786
Indicators of Compromise
File
| Value | Description | Copy |
|---|---|---|
file31.129.54.227 | Vidar botnet C2 server (confidence level: 75%) | |
file193.233.245.114 | Pink botnet C2 server (confidence level: 100%) | |
file123.58.64.57 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file91.231.222.184 | Remcos botnet C2 server (confidence level: 100%) | |
file104.168.5.56 | Remcos botnet C2 server (confidence level: 100%) | |
file77.90.185.239 | SectopRAT botnet C2 server (confidence level: 100%) | |
file95.111.217.209 | MimiKatz botnet C2 server (confidence level: 100%) | |
file165.232.126.106 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file175.17.182.112 | Meterpreter botnet C2 server (confidence level: 100%) | |
file193.161.193.99 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file175.178.149.35 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file38.55.192.138 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file147.124.221.176 | Remcos botnet C2 server (confidence level: 100%) | |
file46.151.24.12 | Remcos botnet C2 server (confidence level: 100%) | |
file208.69.78.192 | Sliver botnet C2 server (confidence level: 100%) | |
file164.92.191.215 | Sliver botnet C2 server (confidence level: 100%) | |
file156.252.63.101 | Unknown malware botnet C2 server (confidence level: 100%) | |
file66.94.103.70 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file34.172.85.181 | Unknown malware botnet C2 server (confidence level: 100%) | |
file81.169.170.55 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file102.98.82.32 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file141.98.6.51 | Bashlite botnet C2 server (confidence level: 100%) | |
file168.245.201.250 | Meterpreter botnet C2 server (confidence level: 100%) | |
file158.94.209.169 | XWorm botnet C2 server (confidence level: 100%) | |
file91.231.222.180 | Remcos botnet C2 server (confidence level: 100%) | |
file213.152.162.110 | Nanocore RAT botnet C2 server (confidence level: 100%) | |
file78.47.161.107 | Vidar botnet C2 server (confidence level: 100%) | |
file116.203.4.84 | Vidar botnet C2 server (confidence level: 100%) | |
file94.130.189.15 | Vidar botnet C2 server (confidence level: 100%) | |
file60.204.139.145 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file123.60.60.119 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file39.97.47.45 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file156.247.41.70 | DCRat botnet C2 server (confidence level: 50%) | |
file80.85.154.41 | Remcos botnet C2 server (confidence level: 50%) | |
file43.249.175.93 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file175.178.149.35 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file46.151.24.12 | Remcos botnet C2 server (confidence level: 100%) | |
file104.168.5.56 | Remcos botnet C2 server (confidence level: 100%) | |
file64.176.17.3 | Sliver botnet C2 server (confidence level: 100%) | |
file89.116.164.107 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file193.29.13.67 | SectopRAT botnet C2 server (confidence level: 100%) | |
file104.140.154.147 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file104.140.154.187 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file139.84.208.222 | Havoc botnet C2 server (confidence level: 75%) | |
file189.140.37.235 | QakBot botnet C2 server (confidence level: 75%) | |
file196.251.100.20 | Nanocore RAT botnet C2 server (confidence level: 75%) | |
file54.166.128.216 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file37.59.112.22 | Havoc botnet C2 server (confidence level: 75%) | |
file52.156.27.122 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file94.156.119.170 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file115.120.248.106 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.79.88.143 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file62.234.150.115 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file4.201.220.7 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file40.67.149.122 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file156.234.101.186 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file23.248.214.6 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file23.235.187.69 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file217.154.162.45 | Havoc botnet C2 server (confidence level: 75%) | |
file118.107.46.74 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file159.89.26.251 | Mirai botnet C2 server (confidence level: 50%) | |
file1.13.247.208 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file107.173.180.173 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file23.235.172.18 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file156.234.94.217 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file15.237.184.174 | Sliver botnet C2 server (confidence level: 90%) | |
file144.126.149.104 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file89.116.164.107 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file217.60.38.11 | Hook botnet C2 server (confidence level: 100%) | |
file4.213.225.251 | Unknown malware botnet C2 server (confidence level: 100%) | |
file59.124.9.77 | Unknown malware botnet C2 server (confidence level: 100%) | |
file195.143.125.120 | Unknown malware botnet C2 server (confidence level: 100%) | |
file41.231.122.52 | Unknown malware botnet C2 server (confidence level: 100%) | |
file115.190.92.164 | Unknown malware botnet C2 server (confidence level: 100%) | |
file190.110.41.114 | Unknown malware botnet C2 server (confidence level: 100%) | |
file91.92.242.140 | XWorm botnet C2 server (confidence level: 75%) | |
file38.55.192.138 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file107.173.47.136 | Remcos botnet C2 server (confidence level: 100%) | |
file91.231.222.184 | Remcos botnet C2 server (confidence level: 100%) | |
file45.9.148.22 | Havoc botnet C2 server (confidence level: 100%) | |
file118.107.46.74 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file103.86.44.167 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file103.86.44.167 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file103.86.44.167 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file38.162.117.58 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file103.119.15.173 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file196.251.100.20 | Remcos botnet C2 server (confidence level: 100%) | |
file192.229.115.159 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file192.229.115.159 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file23.94.126.153 | Unknown Stealer botnet C2 server (confidence level: 75%) | |
file205.209.99.112 | Quasar RAT botnet C2 server (confidence level: 75%) | |
file111.228.35.33 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file175.27.227.41 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file124.198.132.99 | Remcos botnet C2 server (confidence level: 100%) | |
file80.76.49.172 | Remcos botnet C2 server (confidence level: 100%) | |
file216.250.252.233 | Remcos botnet C2 server (confidence level: 100%) | |
file93.113.214.168 | Unknown RAT botnet C2 server (confidence level: 100%) | |
file165.227.129.255 | Unknown malware botnet C2 server (confidence level: 100%) | |
file165.227.129.255 | Unknown malware botnet C2 server (confidence level: 100%) | |
file185.72.199.83 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file185.196.9.213 | MimiKatz botnet C2 server (confidence level: 100%) | |
file46.62.246.163 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file202.73.4.100 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file198.135.54.36 | Remcos botnet C2 server (confidence level: 100%) | |
file124.198.132.68 | AsyncRAT botnet C2 server (confidence level: 75%) | |
file18.102.94.254 | Eye Pyramid botnet C2 server (confidence level: 75%) | |
file186.105.109.59 | QakBot botnet C2 server (confidence level: 75%) | |
file186.105.118.255 | QakBot botnet C2 server (confidence level: 75%) | |
file65.20.108.228 | Unknown malware botnet C2 server (confidence level: 75%) | |
file123.53.36.199 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file108.174.56.152 | Remcos botnet C2 server (confidence level: 100%) | |
file89.116.164.107 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file151.243.18.201 | SectopRAT botnet C2 server (confidence level: 100%) | |
file45.9.148.22 | Unknown malware botnet C2 server (confidence level: 100%) | |
file217.60.38.40 | Hook botnet C2 server (confidence level: 100%) | |
file178.16.52.64 | Hook botnet C2 server (confidence level: 100%) | |
file217.156.8.145 | Havoc botnet C2 server (confidence level: 100%) | |
file37.114.37.213 | MooBot botnet C2 server (confidence level: 100%) | |
file31.172.87.151 | Bashlite botnet C2 server (confidence level: 100%) | |
file194.87.55.166 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file167.148.195.154 | PureLogs Stealer botnet C2 server (confidence level: 100%) | |
file158.51.125.27 | Mirai botnet C2 server (confidence level: 100%) |
Hash
| Value | Description | Copy |
|---|---|---|
hash443 | Vidar botnet C2 server (confidence level: 75%) | |
hash59d3a806684dfc3e0d6a9fac5f349e0a08a628e9307acbc29b14012f8dd9c48c | Vidar payload (confidence level: 100%) | |
hash80ea6b70823ebc4f76d9af3e72c268862c5a1deeacc09066e1c87636a46c0866 | Vidar payload (confidence level: 100%) | |
hasha6dfdfa0dda4c9b2d3767ed44b49f858c2df2f049b8606f85c0219076ad91111 | Vidar payload (confidence level: 100%) | |
hashe33e882a1bf4ef13b23f33e76575fac5e48b265b316727e462109fb8bd0d9a35 | Vidar payload (confidence level: 100%) | |
hashf42b4366500178d40380d21433efea12cdc5aa66eebb74ec6820adf00a29ae6b | Vidar payload (confidence level: 100%) | |
hash2178a927cb1486293bb77fc394dc53d7dd7b1b3c1a97b4f84591616d4c921edd | Vidar payload (confidence level: 100%) | |
hash68bd4f1a56632380307f892f32e59e481269caabd1d076abf6a824ace474d82e | Vidar payload (confidence level: 100%) | |
hashb250ef40ab3cc5cae98cab7da42245f1b30021b52082d8fa83f5b550c8997478 | Vidar payload (confidence level: 100%) | |
hashc42fccdf608e98be7739915a086f49c3bb7328ae3fc3662b1abc2894a9792570 | Vidar payload (confidence level: 100%) | |
hashd1ec6b46ad22793485504e969661c9e79c5a3f8b84a5e76538955a6c684300b1 | Vidar payload (confidence level: 100%) | |
hashda9551fc5564a6958b3aa72edc88b71d00d12ddc5cdb9f6038c07512bd56e502 | Vidar payload (confidence level: 100%) | |
hash38990 | Pink botnet C2 server (confidence level: 100%) | |
hash34567 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash5000 | Remcos botnet C2 server (confidence level: 100%) | |
hash5000 | Remcos botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash443 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash4321 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash10001 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash31009 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash8088 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash80 | Remcos botnet C2 server (confidence level: 100%) | |
hash31337 | Sliver botnet C2 server (confidence level: 100%) | |
hash4443 | Sliver botnet C2 server (confidence level: 100%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash3000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash9443 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash443 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash80 | Bashlite botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash6077 | XWorm botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash39439 | Nanocore RAT botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash5555 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash801 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash5555 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8848 | DCRat botnet C2 server (confidence level: 50%) | |
hash7777 | Remcos botnet C2 server (confidence level: 50%) | |
hash5423 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash15647 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash3ca4cb5499ac164a6af42f3e852d4d804d0bd440739746567364c922d3be7b36 | Mirai payload (confidence level: 100%) | |
hasha8cf98b8e71e4800662e5fa1f73e8f730d51989379f7080e89eb439de1aee238 | Mirai payload (confidence level: 100%) | |
hash94d887bd9e17ef1d032b1ade397c8cdb06ad5bee97ee2acbea986815812e7833 | Mirai payload (confidence level: 100%) | |
hash3dfeaec000f3ed10fcc5e73e4511c8fae039625abb7c3ad78bd0494b9e806248 | Mirai payload (confidence level: 100%) | |
hash8ace4e3efde30f300d3c116b03ddf62b3ed8b289363f6cb97f441229b9765786 | Mirai payload (confidence level: 100%) | |
hash1a7cc94fc56632039953e36a6c1deb26451416d9315e00ec0a930417fd443c2a | Mirai payload (confidence level: 100%) | |
hash86623fea2bd4b84059577d1af23790421a9a054f8021c3628f5f4e45feb292ef | Mirai payload (confidence level: 100%) | |
hash1382e61009a959a78baad1ed49599c84509e99aad0f2b8aaf8aa34fecff6e61f | Mirai payload (confidence level: 100%) | |
hash30125 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash30251 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | Havoc botnet C2 server (confidence level: 75%) | |
hash443 | QakBot botnet C2 server (confidence level: 75%) | |
hash55008 | Nanocore RAT botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash8000 | Havoc botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash8443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash8099 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash7634 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash7634 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash7634 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash5566 | Havoc botnet C2 server (confidence level: 75%) | |
hash6666 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash3696 | Mirai botnet C2 server (confidence level: 50%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash2053 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash5423 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash6671 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 90%) | |
hash20400 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash5555 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8082 | Hook botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash5009 | XWorm botnet C2 server (confidence level: 75%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash8080 | Havoc botnet C2 server (confidence level: 100%) | |
hash8888 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash69 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash73 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash288 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash3322 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash3322 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash5542 | Remcos botnet C2 server (confidence level: 100%) | |
hash7881 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash7880 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash1133 | Unknown Stealer botnet C2 server (confidence level: 75%) | |
hash8990 | Quasar RAT botnet C2 server (confidence level: 75%) | |
hash7878 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash19999 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash5000 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Remcos botnet C2 server (confidence level: 100%) | |
hash80 | Unknown RAT botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8080 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash8000 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash9090 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash6666 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash40164 | Remcos botnet C2 server (confidence level: 100%) | |
hash8080 | AsyncRAT botnet C2 server (confidence level: 75%) | |
hash443 | Eye Pyramid botnet C2 server (confidence level: 75%) | |
hash443 | QakBot botnet C2 server (confidence level: 75%) | |
hash443 | QakBot botnet C2 server (confidence level: 75%) | |
hash3000 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash54002 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash2003 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8089 | Hook botnet C2 server (confidence level: 100%) | |
hash8082 | Hook botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hash80 | Bashlite botnet C2 server (confidence level: 100%) | |
hash4321 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash55508 | PureLogs Stealer botnet C2 server (confidence level: 100%) | |
hash3114 | Mirai botnet C2 server (confidence level: 100%) |
Domain
| Value | Description | Copy |
|---|---|---|
domaingog.nigeriaafricatime.com | Vidar botnet C2 domain (confidence level: 100%) | |
domaintgk.clashofmaps.vip | Vidar botnet C2 domain (confidence level: 100%) | |
domainapi.cpibot.com | Unknown Loader payload delivery domain (confidence level: 90%) | |
domainportabalbufe.com | Unknown malware botnet C2 domain (confidence level: 50%) | |
domainkamm.m1ntcioud.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglanz7.m1ntcioud.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainweiss.m1ntcioud.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbach.stormpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintal.stormpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingrat.stormpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolke2.stormpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolke.kab1spr0tect.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglade.kab1spr0tect.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintau3.kab1spr0tect.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkorn.kab1spr0tect.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoor.inha4itmu1ti.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainufer1.inha4itmu1ti.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpfad.inha4itmu1ti.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingeist.dis-5-h-7-gien.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineiche.dis-5-h-7-gien.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfalke.dis-5-h-7-gien.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwind2.dis-5-h-7-gien.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbach.dis-5-h-7-gien.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolfe.kab-1-spr-0-tect.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstern.kab-1-spr-0-tect.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrune4.kab-1-spr-0-tect.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainklee.kab-1-spr-0-tect.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlicht.dinfectt-0-rs-0.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintal.dinfectt-0-rs-0.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingrat.dinfectt-0-rs-0.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhafen2.dinfectt-0-rs-0.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainweald.kick-5-ubs-4-ance.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrise5.kick-5-ubs-4-ance.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoor.kick-5-ubs-4-ance.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainadler.gu5hnatr3mb.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolke.gu5hnatr3mb.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindune.gu5hnatr3mb.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingleis.gu5hnatr3mb.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnest1.gu5hnatr3mb.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsturm.in-ha-4-it-mu-1-ti.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincut-cash.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainjosesi4418-31009.portmap.host | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainxyk33.cyou | ValleyRAT botnet C2 domain (confidence level: 100%) | |
domainappremiumoilfield.duckdns.org | Nanocore RAT botnet C2 domain (confidence level: 100%) | |
domainlinmaco001.abrdns.com | Nanocore RAT botnet C2 domain (confidence level: 100%) | |
domainwald.in-ha-4-it-mu-1-ti.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfjord3.in-ha-4-it-mu-1-ti.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkamm.in-ha-4-it-mu-1-ti.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrauch.dis5h7gien.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolke2.dis5h7gien.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpfad.dis5h7gien.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglanz.kick5ubs4ance.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainufer.kick5ubs4ance.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmircd.hokkien.my.id | Tsunami botnet C2 domain (confidence level: 100%) | |
domainmircd.xiao.my.id | Tsunami botnet C2 domain (confidence level: 100%) | |
domainkrone.kick5ubs4ance.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintau1.kick5ubs4ance.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainklee.dinfectt0rs0.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbirch.dinfectt0rs0.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfvd.wallyapp.xyz | Vidar botnet C2 domain (confidence level: 100%) | |
domainfvd.noisolation.org.uk | Vidar botnet C2 domain (confidence level: 100%) | |
domaindelivery.parsflowers.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainmoor4.dinfectt0rs0.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincsam.www.moroccancam.com | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainserviciospkkm.duckdns.org | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainchild-porn.womensoundoff.com | DCRat botnet C2 domain (confidence level: 50%) | |
domainfreeporn.womensoundoff.com | DCRat botnet C2 domain (confidence level: 50%) | |
domainsex-child.womensoundoff.com | DCRat botnet C2 domain (confidence level: 50%) | |
domainplay.mclighthouse.ir | Mirai botnet C2 domain (confidence level: 50%) | |
domainjulio31.con-ip.com | Remcos botnet C2 domain (confidence level: 50%) | |
domainzuwkanuikekauwawebarugibikonemwehnhumdon.duckdns.org | Remcos botnet C2 domain (confidence level: 50%) | |
domainwolfe.gu-5-hnatr-3-mb.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainblitz.gu-5-hnatr-3-mb.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainweiss.gu-5-hnatr-3-mb.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrune.gu-5-hnatr-3-mb.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbach2.gu-5-hnatr-3-mb.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainyyb0w.shad0wmist.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnf0g.shad0wmist.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbj1s.shad0wmist.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincrest5.shad0wmist.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindrift.rapidst0ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmist8.rapidst0ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainridge.rapidst0ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkj.rapidst0ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstone.skybl1ss.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincrest3.skybl1ss.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwild6.skybl1ss.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindrift8.skybl1ss.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnova.m1ntflare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain61.m1ntflare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainblue.m1ntflare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsky.m1ntflare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain731.b1uespark.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsun.b1uespark.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintw80g.b1uespark.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspark5.b1uespark.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainflare.suncrest0n.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain6xnq.suncrest0n.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshadow.suncrest0n.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain6menpanelgrace99.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domaincucuketeee.dynuddns.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaingoloe2.duckdns.org | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domain0i4.suncrest0n.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainee2x.w1ldforge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvale4.w1ldforge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpulse1.w1ldforge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaind17.w1ldforge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain1e8.stonecl0ud.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwild0.stonecl0ud.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqm.stonecl0ud.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmedinflow.com | KongTuke payload delivery domain (confidence level: 100%) | |
domainlr.stonecl0ud.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain3y.brightridge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrapid.brightridge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain96btv.brightridge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7l.brightridge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhop.wallyapp.xyz | Vidar botnet C2 domain (confidence level: 100%) | |
domainhop.noisolation.org.uk | Vidar botnet C2 domain (confidence level: 100%) | |
domainbv.fro5tlane.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxcx.fro5tlane.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsilver9.fro5tlane.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvale3.fro5tlane.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpulse.mintforge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain35y.mintforge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain5i.mintforge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainuy3hc.mintforge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsage8.cioudnest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvale.cioudnest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnsi.cioudnest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfeedback.rightontheroad.com | FAKEUPDATES botnet C2 domain (confidence level: 100%) | |
domainsilver.cioudnest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainu3i3y.st0nefield.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlpx.st0nefield.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincloud8.st0nefield.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmint.st0nefield.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnest5.windfiare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincloud4.windfiare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincloud.windfiare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlbs.windfiare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnova4.silverr0ot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmint3.silverr0ot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstorm.silverr0ot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfrost8.silverr0ot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhello.tgllsy.bar | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainv9.brightsage.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainq6.brightsage.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain5obr8.brightsage.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbpk.brightsage.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbloom.stormbioom.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain6tpmi.stormbioom.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlake.stormbioom.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqsa1.stormbioom.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsaid-letter.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainnas064gjgfebvbutebbtakethisasitisbhfdnmn.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domaintickets-somewhat.gl.at.ply.gg | NjRAT botnet C2 domain (confidence level: 100%) | |
domain2h6.mistfaii.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domains2awscloudupdates.com | NetWire RC botnet C2 domain (confidence level: 100%) | |
domaincloud2.mistfaii.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincr.mistfaii.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain383cc.mistfaii.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfkk4m.iunarpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlwch.iunarpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainflare.iunarpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainngytp.iunarpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlane7.emberiake.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsage.emberiake.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvsieh.emberiake.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvh.emberiake.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolke.brightf0rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpfad2.brightf0rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineiche.brightf0rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrune.brightf0rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintaiga.iunarblend.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglade.iunarblend.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkamm1.iunarblend.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfjord.wiidharbor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainufer.wiidharbor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoos.wiidharbor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrise4.wiidharbor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkorn.wiidharbor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwolfe.deepstream.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbach.deepstream.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintal2.deepstream.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingleam.starcresting.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnebel.starcresting.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfalke1.starcresting.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjsbot.dzbot.top | Mirai botnet C2 domain (confidence level: 100%) | |
domainpfote.starcresting.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbirch.m1styvaive.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainweald.m1styvaive.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglow2.m1styvaive.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrill.m1styvaive.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshady.m1styvaive.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrauch.mintstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainklee.mintstone.ru | ClearFake payload delivery domain (confidence level: 100%) |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://31.129.54.227/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttp://91.92.243.129/0gjsy4hf3/login.php | Amadey botnet C2 (confidence level: 100%) | |
urlhttps://seiho-ouyou.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://bongoshare.bishtelecom.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://xerovent.org/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://lcontrols4.ru/xhamster.html | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://workcrms.abesecom.co.in/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttp://cd672412.tw1.ru/d8123622.php | DCRat botnet C2 (confidence level: 100%) | |
urlhttp://156.252.63.98:8888/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttp://158.94.208.130 | Stealc botnet C2 (confidence level: 100%) | |
urlhttp://91.212.150.45 | Stealc botnet C2 (confidence level: 100%) | |
urlhttps://fvd.wallyapp.xyz/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://fvd.noisolation.org.uk/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://94.130.189.15/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://delivery.parsflowers.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://hiddenpoly.markets/ | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://45.88.76.238/3b55d279dd60140c.php | Stealc botnet C2 (confidence level: 50%) | |
urlhttps://lbaiawugmhxp7t6pczm3.bianco.com.mx/ | Unknown malware botnet C2 (confidence level: 50%) | |
urlhttps://aa.fahrenheitacfl.com/ | Unknown malware botnet C2 (confidence level: 50%) | |
urlhttps://aa.consultoriapericial.com/ | Unknown malware botnet C2 (confidence level: 50%) | |
urlhttps://a.kehribarinsaat.com/ | Unknown malware botnet C2 (confidence level: 50%) | |
urlhttp://mngrblgvopedwfeongv6xbf8ukd7qz.testerta.pwtruckwright.cfd/ | Unknown malware botnet C2 (confidence level: 50%) | |
urlhttps://servlcenow.com/ | Unknown malware botnet C2 (confidence level: 50%) | |
urlhttps://www.aa.fahrenheitacfl.com/ | Unknown malware botnet C2 (confidence level: 50%) | |
urlhttp://160.250.247.152/arc | Mirai payload delivery URL (confidence level: 100%) | |
urlhttp://160.250.247.152/arm | Mirai payload delivery URL (confidence level: 100%) | |
urlhttp://160.250.247.152/arm5 | Mirai payload delivery URL (confidence level: 100%) | |
urlhttp://160.250.247.152/arm7 | Mirai payload delivery URL (confidence level: 100%) | |
urlhttp://160.250.247.152/mips | Mirai payload delivery URL (confidence level: 100%) | |
urlhttp://160.250.247.152/mpsl | Mirai payload delivery URL (confidence level: 100%) | |
urlhttp://160.250.247.152/ppc | Mirai payload delivery URL (confidence level: 100%) | |
urlhttp://160.250.247.152/sh4 | Mirai payload delivery URL (confidence level: 100%) | |
urlhttp://23.94.126.153:1133/check_version | KillDisk (Lazarus) botnet C2 (confidence level: 50%) | |
urlhttp://23.94.126.153:1133/send_file | KillDisk (Lazarus) botnet C2 (confidence level: 50%) | |
urlhttps://medinflow.com/5t5t.js | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttps://medinflow.com/js.php | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttp://199.217.99.96:6655/alph | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttps://efcst.org/help/scholarships/?utm_source=chatgpt.com | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://hop.wallyapp.xyz/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://hop.noisolation.org.uk/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://leojbl.xin/qiue | Lumma Stealer botnet C2 (confidence level: 75%) | |
urlhttp://80.97.160.198 | Stealc botnet C2 (confidence level: 100%) |
Threat ID: 6920fe842cd4adea235208d7
Added to database: 11/22/2025, 12:06:28 AM
Last enriched: 11/22/2025, 12:06:40 AM
Last updated: 11/22/2025, 10:19:45 AM
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
APT24 Deploys BADAUDIO in Years-Long Espionage Hitting Taiwan and 1,000+ Domains
MediumSyncro + Lovable: RAT delivery via AI-generated websites | Kaspersky official blog
MediumNew Sturnus Android Malware Reads WhatsApp, Telegram, Signal Chats via Accessibility Abuse
MediumChinese Cyberspies Deploy ‘BadAudio’ Malware via Supply Chain Attacks
MediumThe Tsundere botnet uses the Ethereum blockchain to infect its targets
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.