Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2025-11-25

0
Medium
Published: Tue Nov 25 2025 (11/25/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-11-25

AI-Powered Analysis

AILast updated: 11/26/2025, 00:16:20 UTC

Technical Analysis

This threat entry describes a set of Indicators of Compromise (IOCs) published by ThreatFox on 2025-11-25, categorized under malware with a focus on OSINT (Open Source Intelligence), network activity, and payload delivery. The data lacks specific affected software versions or detailed technical indicators, suggesting it is a general intelligence feed rather than a detailed vulnerability report. The absence of known exploits in the wild and no available patches indicates that this is likely an intelligence update to help organizations detect and respond to emerging threats rather than a newly discovered vulnerability or active exploit. The threat level and analysis scores are low to moderate, with distribution rated higher, implying that these IOCs may be widely disseminated for detection purposes. The lack of CWEs and technical details limits the ability to pinpoint exact attack vectors, but the focus on network activity and payload delivery suggests malware campaigns that rely on network-based infection or communication. The threat intelligence feed is tagged as TLP:WHITE, indicating it is intended for broad sharing without restrictions. Overall, this entry serves as a situational awareness tool for security teams to update their detection capabilities against emerging malware threats identified through OSINT methods.

Potential Impact

For European organizations, the impact of this threat is primarily related to the potential detection and mitigation of malware campaigns that use the provided IOCs for network activity and payload delivery. While no direct exploitation or active attacks are reported, failure to incorporate these IOCs into security monitoring could result in missed detections of malware infections or command-and-control communications. This could lead to unauthorized data access, disruption of services, or lateral movement within networks. Sectors that heavily rely on OSINT tools or have extensive network infrastructures, such as finance, telecommunications, and government, may face increased risks. The medium severity rating suggests moderate potential impact on confidentiality and availability if malware leveraging these indicators is successfully deployed. However, the lack of patches or known exploits reduces the immediacy of the threat. Overall, the impact is contingent on the organization's ability to utilize the intelligence effectively to prevent or detect malware activity.

Mitigation Recommendations

1. Integrate the ThreatFox IOCs into existing Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) systems to enhance detection capabilities. 2. Employ network traffic analysis tools to monitor for suspicious payload delivery patterns and anomalous communications matching the IOCs. 3. Conduct regular threat hunting exercises using the updated IOCs to identify potential infections early. 4. Enhance employee awareness and training on recognizing phishing or social engineering attempts that could deliver malware payloads. 5. Implement strict network segmentation to limit lateral movement if malware is detected. 6. Maintain up-to-date backups and incident response plans tailored to malware infection scenarios. 7. Collaborate with national and European cybersecurity centers to share intelligence and receive timely updates on evolving threats. 8. Avoid reliance solely on signature-based detection; incorporate behavioral analytics to identify novel or obfuscated malware activity related to these IOCs.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
91c0d217-14ee-42f3-a046-c42065612747
Original Timestamp
1764115386

Indicators of Compromise

File

ValueDescriptionCopy
file45.88.186.116
XWorm botnet C2 server (confidence level: 77%)
file158.94.210.84
Latrodectus botnet C2 server (confidence level: 100%)
file192.159.99.75
Remcos botnet C2 server (confidence level: 100%)
file185.113.10.171
Sliver botnet C2 server (confidence level: 100%)
file216.245.184.84
SectopRAT botnet C2 server (confidence level: 100%)
file46.250.233.154
AdaptixC2 botnet C2 server (confidence level: 100%)
file79.30.15.144
Meterpreter botnet C2 server (confidence level: 100%)
file18.212.114.81
Meterpreter botnet C2 server (confidence level: 100%)
file208.83.1.231
Empire Downloader botnet C2 server (confidence level: 100%)
file88.214.50.35
SectopRAT botnet C2 server (confidence level: 100%)
file106.53.208.183
Cobalt Strike botnet C2 server (confidence level: 75%)
file156.234.252.68
Cobalt Strike botnet C2 server (confidence level: 75%)
file101.43.156.141
Ghost RAT botnet C2 server (confidence level: 100%)
file23.226.48.201
Cobalt Strike botnet C2 server (confidence level: 100%)
file95.179.137.169
Remcos botnet C2 server (confidence level: 100%)
file194.163.145.76
Remcos botnet C2 server (confidence level: 100%)
file108.181.121.140
Remcos botnet C2 server (confidence level: 100%)
file108.181.121.140
Remcos botnet C2 server (confidence level: 100%)
file64.52.80.227
SectopRAT botnet C2 server (confidence level: 100%)
file102.117.167.54
Unknown malware botnet C2 server (confidence level: 100%)
file175.17.181.237
Meterpreter botnet C2 server (confidence level: 100%)
file168.245.200.201
Meterpreter botnet C2 server (confidence level: 100%)
file168.245.200.192
Meterpreter botnet C2 server (confidence level: 100%)
file168.245.200.181
Meterpreter botnet C2 server (confidence level: 100%)
file168.245.200.174
Meterpreter botnet C2 server (confidence level: 100%)
file168.245.200.184
Meterpreter botnet C2 server (confidence level: 100%)
file34.226.217.10
Meterpreter botnet C2 server (confidence level: 100%)
file165.140.158.128
PureLogs Stealer botnet C2 server (confidence level: 100%)
file115.202.102.174
Ghost RAT botnet C2 server (confidence level: 100%)
file154.12.226.43
Quasar RAT botnet C2 server (confidence level: 100%)
file103.77.246.136
Mirai botnet C2 server (confidence level: 100%)
file176.117.107.18
Remcos botnet C2 server (confidence level: 50%)
file144.31.30.102
SystemBC botnet C2 server (confidence level: 100%)
file137.220.194.49
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.249.175.78
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.227.203.207
Remcos botnet C2 server (confidence level: 100%)
file107.175.88.100
Remcos botnet C2 server (confidence level: 100%)
file91.92.242.170
Remcos botnet C2 server (confidence level: 100%)
file8.209.221.211
Remcos botnet C2 server (confidence level: 100%)
file185.113.10.171
Sliver botnet C2 server (confidence level: 100%)
file185.113.10.170
Sliver botnet C2 server (confidence level: 100%)
file64.94.85.26
SectopRAT botnet C2 server (confidence level: 100%)
file88.192.127.87
Quasar RAT botnet C2 server (confidence level: 100%)
file103.20.102.151
Quasar RAT botnet C2 server (confidence level: 100%)
file206.189.154.77
Havoc botnet C2 server (confidence level: 100%)
file191.93.113.160
DCRat botnet C2 server (confidence level: 100%)
file85.9.214.193
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file168.245.200.207
Meterpreter botnet C2 server (confidence level: 100%)
file168.245.200.224
Meterpreter botnet C2 server (confidence level: 100%)
file52.90.223.183
Meterpreter botnet C2 server (confidence level: 100%)
file49.12.112.206
Vidar botnet C2 server (confidence level: 100%)
file116.202.178.198
Vidar botnet C2 server (confidence level: 100%)
file116.203.3.179
Vidar botnet C2 server (confidence level: 100%)
file195.201.255.10
Vidar botnet C2 server (confidence level: 100%)
file49.13.38.254
Vidar botnet C2 server (confidence level: 100%)
file116.202.182.165
Vidar botnet C2 server (confidence level: 100%)
file185.196.11.132
Vidar botnet C2 server (confidence level: 100%)
file158.94.210.88
Mirai botnet C2 server (confidence level: 80%)
file162.251.122.82
STRRAT botnet C2 server (confidence level: 100%)
file31.57.228.141
DeimosC2 botnet C2 server (confidence level: 75%)
file34.171.254.190
DanaBot botnet C2 server (confidence level: 75%)
file47.207.38.75
DeimosC2 botnet C2 server (confidence level: 75%)
file75.2.11.125
DeimosC2 botnet C2 server (confidence level: 75%)
file192.229.115.159
ValleyRAT botnet C2 server (confidence level: 100%)
file192.229.115.159
ValleyRAT botnet C2 server (confidence level: 100%)
file110.42.232.120
Cobalt Strike botnet C2 server (confidence level: 75%)
file121.41.116.254
Cobalt Strike botnet C2 server (confidence level: 75%)
file156.245.248.173
Cobalt Strike botnet C2 server (confidence level: 75%)
file150.158.120.73
Cobalt Strike botnet C2 server (confidence level: 100%)
file160.25.72.92
Remcos botnet C2 server (confidence level: 100%)
file207.166.166.21
Unknown malware botnet C2 server (confidence level: 100%)
file155.138.151.232
Unknown malware botnet C2 server (confidence level: 100%)
file158.94.210.76
Unknown RAT botnet C2 server (confidence level: 100%)
file178.16.55.109
Unknown RAT botnet C2 server (confidence level: 100%)
file51.38.250.193
Unknown RAT botnet C2 server (confidence level: 100%)
file158.94.210.52
Unknown RAT botnet C2 server (confidence level: 100%)
file168.245.200.227
Meterpreter botnet C2 server (confidence level: 100%)
file41.216.189.249
Unknown malware botnet C2 server (confidence level: 100%)
file43.143.214.45
Unknown malware botnet C2 server (confidence level: 100%)
file211.72.168.134
Unknown malware botnet C2 server (confidence level: 100%)
file211.72.168.134
Unknown malware botnet C2 server (confidence level: 100%)
file108.181.221.165
Unknown malware botnet C2 server (confidence level: 100%)
file38.56.209.142
Unknown malware botnet C2 server (confidence level: 100%)
file121.40.188.18
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.136.91.76
Cobalt Strike botnet C2 server (confidence level: 100%)
file119.27.178.41
Cobalt Strike botnet C2 server (confidence level: 100%)
file143.198.52.197
Cobalt Strike botnet C2 server (confidence level: 100%)
file143.92.56.92
ValleyRAT botnet C2 server (confidence level: 100%)
file143.92.61.62
ValleyRAT botnet C2 server (confidence level: 100%)
file143.92.61.62
ValleyRAT botnet C2 server (confidence level: 100%)
file47.77.203.33
Meterpreter botnet C2 server (confidence level: 75%)
file185.193.51.137
Remcos botnet C2 server (confidence level: 75%)
file172.245.106.56
XWorm botnet C2 server (confidence level: 75%)
file38.162.117.244
Cobalt Strike botnet C2 server (confidence level: 75%)
file198.55.102.84
Remcos botnet C2 server (confidence level: 75%)
file47.116.206.20
Cobalt Strike botnet C2 server (confidence level: 100%)
file158.94.210.82
Latrodectus botnet C2 server (confidence level: 100%)
file176.57.184.244
Remcos botnet C2 server (confidence level: 100%)
file89.45.6.220
Remcos botnet C2 server (confidence level: 100%)
file208.64.33.64
Remcos botnet C2 server (confidence level: 100%)
file181.162.151.54
Quasar RAT botnet C2 server (confidence level: 100%)
file109.74.144.151
Unknown malware botnet C2 server (confidence level: 100%)
file121.22.248.54
DCRat botnet C2 server (confidence level: 50%)
file91.231.222.29
Remcos botnet C2 server (confidence level: 50%)
file147.185.221.224
XWorm botnet C2 server (confidence level: 100%)
file5.252.178.90
Remcos botnet C2 server (confidence level: 100%)
file147.185.221.223
NjRAT botnet C2 server (confidence level: 100%)
file104.168.38.153
Unknown malware botnet C2 server (confidence level: 75%)
file165.101.92.54
AsyncRAT botnet C2 server (confidence level: 75%)
file217.154.162.45
Havoc botnet C2 server (confidence level: 75%)
file5.181.2.14
DeimosC2 botnet C2 server (confidence level: 75%)
file52.230.188.243
DanaBot botnet C2 server (confidence level: 75%)
file66.228.62.180
Cobalt Strike botnet C2 server (confidence level: 100%)
file195.2.85.72
Cobalt Strike botnet C2 server (confidence level: 100%)
file152.32.169.68
Cobalt Strike botnet C2 server (confidence level: 100%)
file118.25.141.108
Cobalt Strike botnet C2 server (confidence level: 100%)
file144.172.105.244
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.139.88.57
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.153.150.122
Cobalt Strike botnet C2 server (confidence level: 100%)
file143.198.52.197
Cobalt Strike botnet C2 server (confidence level: 100%)
file158.94.210.85
Latrodectus botnet C2 server (confidence level: 100%)
file208.64.33.111
Remcos botnet C2 server (confidence level: 100%)
file43.160.197.177
Unknown malware botnet C2 server (confidence level: 100%)
file89.116.164.107
AsyncRAT botnet C2 server (confidence level: 100%)
file78.47.226.37
Hook botnet C2 server (confidence level: 100%)
file159.65.14.178
Havoc botnet C2 server (confidence level: 100%)
file103.8.28.200
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.10
Meterpreter botnet C2 server (confidence level: 100%)
file87.21.25.132
Meterpreter botnet C2 server (confidence level: 100%)
file77.83.246.84
Sliver botnet C2 server (confidence level: 50%)
file121.127.233.111
ValleyRAT botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash2929
XWorm botnet C2 server (confidence level: 77%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash5000
Remcos botnet C2 server (confidence level: 100%)
hash82
Sliver botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 100%)
hash4444
Meterpreter botnet C2 server (confidence level: 100%)
hash20548
Meterpreter botnet C2 server (confidence level: 100%)
hash1337
Empire Downloader botnet C2 server (confidence level: 100%)
hash15647
SectopRAT botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash7841
Cobalt Strike botnet C2 server (confidence level: 75%)
hash6000
Ghost RAT botnet C2 server (confidence level: 100%)
hash7841
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash4444
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash10001
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash30005
Meterpreter botnet C2 server (confidence level: 100%)
hash13899
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash5252
Ghost RAT botnet C2 server (confidence level: 100%)
hash5
Quasar RAT botnet C2 server (confidence level: 100%)
hash6738
Mirai botnet C2 server (confidence level: 100%)
hash1518
Remcos botnet C2 server (confidence level: 50%)
hash4001
SystemBC botnet C2 server (confidence level: 100%)
hash2222
Cobalt Strike botnet C2 server (confidence level: 100%)
hash23619
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash9090
Remcos botnet C2 server (confidence level: 100%)
hash9337
Remcos botnet C2 server (confidence level: 100%)
hash6328
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash4444
Quasar RAT botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash8848
DCRat botnet C2 server (confidence level: 100%)
hash29870
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash2404
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash56999
Mirai botnet C2 server (confidence level: 80%)
hash3608
STRRAT botnet C2 server (confidence level: 100%)
hash990
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DanaBot botnet C2 server (confidence level: 75%)
hash631
DeimosC2 botnet C2 server (confidence level: 75%)
hash8112
DeimosC2 botnet C2 server (confidence level: 75%)
hash7883
ValleyRAT botnet C2 server (confidence level: 100%)
hash7882
ValleyRAT botnet C2 server (confidence level: 100%)
hash9191
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8083
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2403
Remcos botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8000
Unknown RAT botnet C2 server (confidence level: 100%)
hash8000
Unknown RAT botnet C2 server (confidence level: 100%)
hash8000
Unknown RAT botnet C2 server (confidence level: 100%)
hash8000
Unknown RAT botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash4444
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash389
Unknown malware botnet C2 server (confidence level: 100%)
hash55199
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8090
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8081
ValleyRAT botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash8888
ValleyRAT botnet C2 server (confidence level: 100%)
hash443
Meterpreter botnet C2 server (confidence level: 75%)
hash3033
Remcos botnet C2 server (confidence level: 75%)
hash2214
XWorm botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash1616
Remcos botnet C2 server (confidence level: 75%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash2409
Remcos botnet C2 server (confidence level: 100%)
hash2919
Remcos botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash8080
Quasar RAT botnet C2 server (confidence level: 100%)
hash3334
Unknown malware botnet C2 server (confidence level: 100%)
hash65503
DCRat botnet C2 server (confidence level: 50%)
hash2023
Remcos botnet C2 server (confidence level: 50%)
hash25126
XWorm botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash44804
NjRAT botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 75%)
hash8443
AsyncRAT botnet C2 server (confidence level: 75%)
hash443
Havoc botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DanaBot botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8880
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
AsyncRAT botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash8080
Havoc botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash4444
Meterpreter botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash7880
ValleyRAT botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttp://213.5.130.84
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://213.5.130.96
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://213.5.130.98
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://213.5.130.160
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://213.5.130.94
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://185.206.149.217
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://217.156.8.58
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://185.206.149.215
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://217.156.8.59
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://85.208.84.242/auth/login/
Matanbuchus botnet C2 (confidence level: 100%)
urlhttps://planb.ph/uploads/topics/updates/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://rovo.sa/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://oeluu.de/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://pmbtar.ae/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://go237.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://edex.dev/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://kubet.boo/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://a8a8a.net/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://kevius.se/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://buyqualityfirst.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://epilepsygolf.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://cryptolaughs.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://85.209.129.159
Stealc botnet C2 (confidence level: 100%)
urlhttps://chocola.ru.com/admin.php
DCRat botnet C2 (confidence level: 50%)
urlhttps://chocola.ru.com/result
DCRat botnet C2 (confidence level: 50%)
urlhttps://giw.wallyapp.xyz/
Vidar botnet C2 (confidence level: 100%)
urlhttps://giw.shortletsinaberdeen.co.uk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://wp2.unairdedemo.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://trp.wallyapp.xyz/
Vidar botnet C2 (confidence level: 100%)
urlhttps://trp.shortletsinaberdeen.co.uk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://we.flourish.biz/wp-includes/sitemaps/mqylibj/eta/vmp.html.
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://getfix.win
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://getfix.win/jsrepo
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://cptchic.icu
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://cptchic.icu/captcha.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://grunbcv.cyou/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://dasktiitititit.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://alsokdalsdkals.com/oraaa.js
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dasktiitititit.com/oraaa
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://www.webentangled.com/our.php
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://rodrigobarroxx.com/oink.json
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://adtrucking.org
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://185.163.204.237/2euesell.wav
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://pharmacygletsos.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://avciauto.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://keonhacai.cheap
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://columbusveteransfc.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://tiltdesigns.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://cardloan-bank.net
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://all-life-flower.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://3squaredapps.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://creators--cloud.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://shutter.myaccessio.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://tech247.com.vn
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://clwrealestate.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://fiqueforadacaixa.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://wadainomori.net
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://landman.africa
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://hifoison.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://onlysix.com.br
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://shienkenkyu.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://daimakkk.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://buke-monogatari.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://allsportsandwellness.ca
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://zarkons.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://kolbexenterprise.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://atmasolucoes.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://bulk-url-opener.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://bbc-themes.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://saaratechnepal.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://builder.cannazipbags.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://bx.digitech.ru
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://rajstonex.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://shiga-hagukumikai.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://encoderunlimited.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://zamek.ilza.pl
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://hijabbandung.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://upperdecklakes.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://syedamahnoorjaffery.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://manshinseyaku.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://la1.lybh66.top/
SpyNote botnet C2 (confidence level: 50%)
urlhttps://3accnet.sbs/
SpyNote botnet C2 (confidence level: 50%)
urlhttp://192.169.7.221:5000/
Unknown Stealer botnet C2 (confidence level: 50%)
urlhttp://168.222.253.97/video
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://jyoushin-solar.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://tea-garden.net
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dise-global.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://freqbitsolutions.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://einfach-sup.de
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://bekaskantor.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://naglisgym.lt
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://wordpress-theme-collection.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://powerforward.llc
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://trendsgh.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://enor.cloud
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://nardoweb.it
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://bestincestsexgames.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://diabezill.com.br
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://grrrowth.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://hoigiong.net
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://moneypond.in
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://palaghiacciocatania.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://saikicleaning.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dynamicedge-llc.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://candourtankers.ae
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://drohobycz-boryslaw.org
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://indianafoodpantry.org
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://marinabrizzibraus.it
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://optics.oxyappscr.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://matrimoniosconproposito.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://utama777.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://euromoc.co.mz
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://injuryarbitration.drdatasaver.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://profissionaisdevendas.com.br
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://frozensexgames.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://flightplanoriginal.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://sophiaev.de
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://takublog2020.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://uscentacademy.org
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://wealthruproperty.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://celebrityinfograph.info
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://autonom.com.pl
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lawwizafrica.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://blog.cementah.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://coctrecongtrinh.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://www.webentangled.com/our.php?page=
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://guild.0gfoundation.zone/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://guild.0gfoundation.zone/auth?xc=162692
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://artwix.ca/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://www.shaktibiotech.in/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://aslidomino.info/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://zoomwebinviteinfo.us/zoom/windows/invite.php
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://2oomiinvittee.com/windows/invite.php
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://store-na-phx-1.gofile.io/download/direct/04a0efd4-0fbc-4442-959b-9fee4e277669/zoomworkspace.vbs
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://2oomiinvittee.com/windows/download.php
Unknown malware payload delivery URL (confidence level: 50%)

Domain

ValueDescriptionCopy
domainfunnel.weightlosstonight.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainwww.cybermac.co.tz
ERMAC botnet C2 domain (confidence level: 100%)
domainwolke.sunb1aze.ru
ClearFake payload delivery domain (confidence level: 100%)
domainglade2.sunb1aze.ru
ClearFake payload delivery domain (confidence level: 100%)
domainreef.sunb1aze.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincrest.sunb1aze.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine2h.s0ftmint.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincrest.st0nepeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainblink.st0nepeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainscg7.st0nepeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshadow6.st0nepeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainli90.b1tzdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsilver0.b1tzdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domain5rn.b1tzdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainr91.b1tzdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpeak.stormblink.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine31.stormblink.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2wa.stormblink.ru
ClearFake payload delivery domain (confidence level: 100%)
domain4d.stormblink.ru
ClearFake payload delivery domain (confidence level: 100%)
domain1318289497-b40xhuifyy.ap-beijing.tencentscf.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domaincloud.cl0udmark.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsoft.cl0udmark.ru
ClearFake payload delivery domain (confidence level: 100%)
domain4sv.cl0udmark.ru
ClearFake payload delivery domain (confidence level: 100%)
domainem.cl0udmark.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmoor.deep5tone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainufer.deep5tone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainklee3.deep5tone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbirch.mount0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfjord.mount0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainweald.mount0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindune4.mount0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintal.mount0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnacht.night0ra.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpfad.night0ra.ru
ClearFake payload delivery domain (confidence level: 100%)
domainglow1.night0ra.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwind.c1earwind.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwolke.c1earwind.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlicht2.c1earwind.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhaze.c1earwind.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkorn.m1stwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspray.m1stwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainreef2.m1stwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshore.m1stwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincrest.m1stwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshadowb1t.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwww.xoilac86e.tv
AsyncRAT botnet C2 domain (confidence level: 50%)
domainstern.starl1nq.ru
ClearFake payload delivery domain (confidence level: 100%)
domainchocola.ru.com
DCRat botnet C2 domain (confidence level: 50%)
domainmaintenance-behavior.gl.at.ply.gg
DCRat botnet C2 domain (confidence level: 50%)
domainsocolive105.ac
DCRat botnet C2 domain (confidence level: 50%)
domainv2.socolive105.ac
DCRat botnet C2 domain (confidence level: 50%)
domainv3.socolive105.ac
DCRat botnet C2 domain (confidence level: 50%)
domainupdate.especificotks.site
Remcos botnet C2 domain (confidence level: 50%)
domaincall-sin.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domaingleis2.starl1nq.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwolke.starl1nq.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmicrosoft.ms-drivers.cam
Sliver botnet C2 domain (confidence level: 50%)
domainmilauth-mygovin.serveftp.com
Sliver botnet C2 domain (confidence level: 50%)
domaintal.starl1nq.ru
ClearFake payload delivery domain (confidence level: 100%)
domainreef.0ceanleaf.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintau.0ceanleaf.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingiw.wallyapp.xyz
Vidar botnet C2 domain (confidence level: 100%)
domaingiw.shortletsinaberdeen.co.uk
Vidar botnet C2 domain (confidence level: 100%)
domaindune4.0ceanleaf.ru
ClearFake payload delivery domain (confidence level: 100%)
domainweiss.bluer1ver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainufer.bluer1ver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstrom2.bluer1ver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwald.bluer1ver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainglanz.bluer1ver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwolke.st0necloud.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbach.st0necloud.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkamm2.st0necloud.ru
ClearFake payload delivery domain (confidence level: 100%)
domainglade.st0necloud.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintau.softl1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainweald.softl1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindune3.softl1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpfad.stormseed.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwp2.unairdedemo.com
Unknown malware payload delivery domain (confidence level: 100%)
domainlicht.stormseed.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwolfe2.stormseed.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmoor.stormseed.ru
ClearFake payload delivery domain (confidence level: 100%)
domainklee.stormseed.ru
ClearFake payload delivery domain (confidence level: 100%)
domainreef.sunm0tion.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintrp.wallyapp.xyz
Vidar botnet C2 domain (confidence level: 100%)
domaintrp.shortletsinaberdeen.co.uk
Vidar botnet C2 domain (confidence level: 100%)
domainglow1.sunm0tion.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincrest.sunm0tion.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwasimoc.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincrpavdsg.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainlacuobl.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainsenszlz.cfd
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainrealad.bond
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainshore.sunm0tion.ru
ClearFake payload delivery domain (confidence level: 100%)
domain1pc1wdstwjv4p.cfc-execute.gz.baidubce.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainglanz.fl0wbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainufer2.fl0wbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrill.fl0wbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnacht.midn1ghtdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfalke.midn1ghtdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkorn3.midn1ghtdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainweiss.midn1ghtdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingleis.midn1ghtdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainadler.w1ldgate.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintal.w1ldgate.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhain2.w1ldgate.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwolke.clearpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwind.clearpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbirch.clearpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainglade4.clearpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhafen.breezef0x.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzorn.breezef0x.ru
ClearFake payload delivery domain (confidence level: 100%)
domainweald3.breezef0x.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlicht.breezef0x.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmizu.deep5tone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvento.deep5tone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainselva.deep5tone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlago.deep5tone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsora.deep5tone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainaurora.sunb1aze.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincptchic.icu
Unknown malware payload delivery domain (confidence level: 100%)
domainflare.sunb1aze.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsolis.sunb1aze.ru
ClearFake payload delivery domain (confidence level: 100%)
domainardor.sunb1aze.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbrillar.sunb1aze.ru
ClearFake payload delivery domain (confidence level: 100%)
domainox1i.mintforest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfire2.mintforest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwave.mintforest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainneon.mintforest.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincn8y.wildr0sehub.ru
ClearFake payload delivery domain (confidence level: 100%)
domainulv.wildr0sehub.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvale.wildr0sehub.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingrunbcv.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaingrobpa.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaindasktiitititit.com
Unknown malware payload delivery domain (confidence level: 100%)
domain9gu.wildr0sehub.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqpiy0.skybr1dge.ru
ClearFake payload delivery domain (confidence level: 100%)
domainalsokdalsdkals.com
Unknown malware payload delivery domain (confidence level: 100%)
domainlp.skybr1dge.ru
ClearFake payload delivery domain (confidence level: 100%)
domainz3t.skybr1dge.ru
ClearFake payload delivery domain (confidence level: 100%)
domainr0f.skybr1dge.ru
ClearFake payload delivery domain (confidence level: 100%)
domain55a07.neoniake.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbloom.neoniake.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine2.neoniake.ru
ClearFake payload delivery domain (confidence level: 100%)
domain6ho.neoniake.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwave1.cieardrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domain7wa.cieardrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindrop.cieardrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhkz.cieardrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmint.cioudpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhb.cioudpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindrift.cioudpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspark0.cioudpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainadtrucking.org
Unknown malware payload delivery domain (confidence level: 100%)
domainpharmacygletsos.com
Unknown malware payload delivery domain (confidence level: 100%)
domainsky3.softm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine8rgy.softm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainavciauto.com
Unknown malware payload delivery domain (confidence level: 100%)
domainkeonhacai.cheap
Unknown malware payload delivery domain (confidence level: 100%)
domaincolumbusveteransfc.com
Unknown malware payload delivery domain (confidence level: 100%)
domaintiltdesigns.com
Unknown malware payload delivery domain (confidence level: 100%)
domaincardloan-bank.net
Unknown malware payload delivery domain (confidence level: 100%)
domainall-life-flower.com
Unknown malware payload delivery domain (confidence level: 100%)
domainhollow.softm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domain3squaredapps.com
Unknown malware payload delivery domain (confidence level: 100%)
domaincreators--cloud.com
Unknown malware payload delivery domain (confidence level: 100%)
domainshutter.myaccessio.com
Unknown malware payload delivery domain (confidence level: 100%)
domaintech247.com.vn
Unknown malware payload delivery domain (confidence level: 100%)
domainclwrealestate.com
Unknown malware payload delivery domain (confidence level: 100%)
domainsky.softm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfiqueforadacaixa.com
Unknown malware payload delivery domain (confidence level: 100%)
domainwadainomori.net
Unknown malware payload delivery domain (confidence level: 100%)
domaintj.waveb0x.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlandman.africa
Unknown malware payload delivery domain (confidence level: 100%)
domainhifoison.com
Unknown malware payload delivery domain (confidence level: 100%)
domainonlysix.com.br
Unknown malware payload delivery domain (confidence level: 100%)
domain2yv.waveb0x.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshienkenkyu.com
Unknown malware payload delivery domain (confidence level: 100%)
domaindaimakkk.com
Unknown malware payload delivery domain (confidence level: 100%)
domainbuke-monogatari.com
Unknown malware payload delivery domain (confidence level: 100%)
domainforest2.waveb0x.ru
ClearFake payload delivery domain (confidence level: 100%)
domainallsportsandwellness.ca
Unknown malware payload delivery domain (confidence level: 100%)
domainzarkons.com
Unknown malware payload delivery domain (confidence level: 100%)
domainkolbexenterprise.com
Unknown malware payload delivery domain (confidence level: 100%)
domainvaruna.uk
Unknown malware payload delivery domain (confidence level: 100%)
domainatmasolucoes.com
Unknown malware payload delivery domain (confidence level: 100%)
domainforest1.waveb0x.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbulk-url-opener.com
Unknown malware payload delivery domain (confidence level: 100%)
domainbbc-themes.com
Unknown malware payload delivery domain (confidence level: 100%)
domainsaaratechnepal.com
Unknown malware payload delivery domain (confidence level: 100%)
domainbridge.fireciiff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbuilder.cannazipbags.com
Unknown malware payload delivery domain (confidence level: 100%)
domaintrd.vn
Unknown malware payload delivery domain (confidence level: 100%)
domainbx.digitech.ru
Unknown malware payload delivery domain (confidence level: 100%)
domainrajstonex.com
Unknown malware payload delivery domain (confidence level: 100%)
domainfkk.fireciiff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshiga-hagukumikai.com
Unknown malware payload delivery domain (confidence level: 100%)
domainencoderunlimited.com
Unknown malware payload delivery domain (confidence level: 100%)
domainzamek.ilza.pl
Unknown malware payload delivery domain (confidence level: 100%)
domainlx88w.fireciiff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhijabbandung.com
Unknown malware payload delivery domain (confidence level: 100%)
domainupperdecklakes.com
Unknown malware payload delivery domain (confidence level: 100%)
domainsyedamahnoorjaffery.com
Unknown malware payload delivery domain (confidence level: 100%)
domainldx.fireciiff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmanshinseyaku.com
Unknown malware payload delivery domain (confidence level: 100%)
domainjyoushin-solar.com
Unknown malware payload delivery domain (confidence level: 100%)
domaintea-garden.net
Unknown malware payload delivery domain (confidence level: 100%)
domaincliff.stormbiend.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindise-global.com
Unknown malware payload delivery domain (confidence level: 100%)
domainfreqbitsolutions.com
Unknown malware payload delivery domain (confidence level: 100%)
domaineinfach-sup.de
Unknown malware payload delivery domain (confidence level: 100%)
domainsoft.stormbiend.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbekaskantor.com
Unknown malware payload delivery domain (confidence level: 100%)
domainnaglisgym.lt
Unknown malware payload delivery domain (confidence level: 100%)
domainwordpress-theme-collection.com
Unknown malware payload delivery domain (confidence level: 100%)
domainpowerforward.llc
Unknown malware payload delivery domain (confidence level: 100%)
domainforest.stormbiend.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintrendsgh.com
Unknown malware payload delivery domain (confidence level: 100%)
domainenor.cloud
Unknown malware payload delivery domain (confidence level: 100%)
domainnardoweb.it
Unknown malware payload delivery domain (confidence level: 100%)
domainpeak.stormbiend.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbestincestsexgames.com
Unknown malware payload delivery domain (confidence level: 100%)
domaindiabezill.com.br
Unknown malware payload delivery domain (confidence level: 100%)
domaingrrrowth.com
Unknown malware payload delivery domain (confidence level: 100%)
domainhoigiong.net
Unknown malware payload delivery domain (confidence level: 100%)
domainbrut.ydns.eu
Remcos botnet C2 domain (confidence level: 100%)
domainsoftx.duckdns.org
Quasar RAT botnet C2 domain (confidence level: 100%)
domainmoneypond.in
Unknown malware payload delivery domain (confidence level: 100%)
domainpalaghiacciocatania.com
Unknown malware payload delivery domain (confidence level: 100%)
domainsaikicleaning.com
Unknown malware payload delivery domain (confidence level: 100%)
domaindynamicedge-llc.com
Unknown malware payload delivery domain (confidence level: 100%)
domainrg.frostlake.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincandourtankers.ae
Unknown malware payload delivery domain (confidence level: 100%)
domaindrohobycz-boryslaw.org
Unknown malware payload delivery domain (confidence level: 100%)
domainindianafoodpantry.org
Unknown malware payload delivery domain (confidence level: 100%)
domainmarinabrizzibraus.it
Unknown malware payload delivery domain (confidence level: 100%)
domainpath.frostlake.ru
ClearFake payload delivery domain (confidence level: 100%)
domainoptics.oxyappscr.com
Unknown malware payload delivery domain (confidence level: 100%)
domainmatrimoniosconproposito.com
Unknown malware payload delivery domain (confidence level: 100%)
domaini987.frostlake.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8w.frostlake.ru
ClearFake payload delivery domain (confidence level: 100%)
domainutama777.com
Unknown malware payload delivery domain (confidence level: 100%)
domaineuromoc.co.mz
Unknown malware payload delivery domain (confidence level: 100%)
domaininjuryarbitration.drdatasaver.com
Unknown malware payload delivery domain (confidence level: 100%)
domainprofissionaisdevendas.com.br
Unknown malware payload delivery domain (confidence level: 100%)
domainmist.st0rmleaf.ru
ClearFake payload delivery domain (confidence level: 100%)
domainldm.jp
Unknown malware payload delivery domain (confidence level: 100%)
domainfrozensexgames.com
Unknown malware payload delivery domain (confidence level: 100%)
domainflightplanoriginal.com
Unknown malware payload delivery domain (confidence level: 100%)
domainsophiaev.de
Unknown malware payload delivery domain (confidence level: 100%)
domainlj.st0rmleaf.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintakublog2020.com
Unknown malware payload delivery domain (confidence level: 100%)
domainuscentacademy.org
Unknown malware payload delivery domain (confidence level: 100%)
domainwealthruproperty.com
Unknown malware payload delivery domain (confidence level: 100%)
domaincelebrityinfograph.info
Unknown malware payload delivery domain (confidence level: 100%)
domainautonom.com.pl
Unknown malware payload delivery domain (confidence level: 100%)
domainstorm.st0rmleaf.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlawwizafrica.com
Unknown malware payload delivery domain (confidence level: 100%)
domainblog.cementah.com
Unknown malware payload delivery domain (confidence level: 100%)
domaincoctrecongtrinh.com
Unknown malware payload delivery domain (confidence level: 100%)
domain4z.st0rmleaf.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsun.silverpath.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfa.silverpath.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpulse.silverpath.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyt.silverpath.ru
ClearFake payload delivery domain (confidence level: 100%)
domainoak2.br1ghtwood.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspark1.br1ghtwood.ru
ClearFake payload delivery domain (confidence level: 100%)
domainorbit.br1ghtwood.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsilver.br1ghtwood.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhrhzf.miststone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlake8.miststone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzyy93.miststone.ru
ClearFake payload delivery domain (confidence level: 100%)
domaind458f.miststone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainseed.wild0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspark.wild0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvale8.wild0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpulse1.wild0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8y.cloud5eed.ru
ClearFake payload delivery domain (confidence level: 100%)
domain46.cloud5eed.ru
ClearFake payload delivery domain (confidence level: 100%)
domainh8jc.cloud5eed.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwood4.cloud5eed.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrj8h.m1stbird.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbmr74.m1stbird.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwild.m1stbird.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstone.m1stbird.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkji.sun0rbit.ru
ClearFake payload delivery domain (confidence level: 100%)
domainue.sun0rbit.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsun2.sun0rbit.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwood.sun0rbit.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvento5.skyf1ame.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsol1.skyf1ame.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnebu7la.skyf1ame.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflare9.skyf1ame.ru
ClearFake payload delivery domain (confidence level: 100%)
domainastra3.skyf1ame.ru
ClearFake payload delivery domain (confidence level: 100%)
domainumbra8.darksun5et.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindusk1.darksun5et.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnoir4.darksun5et.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrock3.st0nebird.ru
ClearFake payload delivery domain (confidence level: 100%)
domainavian2.st0nebird.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincliff7.st0nebird.ru
ClearFake payload delivery domain (confidence level: 100%)

Threat ID: 692646c25765e822ee01c625

Added to database: 11/26/2025, 12:16:02 AM

Last enriched: 11/26/2025, 12:16:20 AM

Last updated: 12/5/2025, 1:22:34 AM

Views: 61

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats