Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2025-11-27

0
Medium
Published: Thu Nov 27 2025 (11/27/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-11-27

AI-Powered Analysis

AILast updated: 11/28/2025, 00:32:12 UTC

Technical Analysis

The entry titled 'ThreatFox IOCs for 2025-11-27' is a report from the ThreatFox MISP feed, focusing on OSINT-derived Indicators of Compromise related to malware and network activity associated with payload delivery. The report does not specify particular malware families, affected software versions, or detailed attack vectors. It is primarily a collection of threat intelligence data intended to support detection and investigation efforts. The threat level is medium, with no known exploits currently active in the wild and no patches available, indicating that this is not a newly discovered vulnerability but rather intelligence on existing or potential threats. The technical details include a threat level rating of 2 and distribution rating of 3, suggesting moderate prevalence or dissemination of the associated IOCs. The absence of CWEs and exploit details implies that this is not a direct vulnerability but a set of indicators to aid in identifying malicious activity. The information is tagged as TLP:WHITE, meaning it is intended for wide distribution and sharing. This type of intelligence is valuable for security teams to improve situational awareness and enhance network monitoring and incident response capabilities. However, without specific actionable exploit or vulnerability data, it does not represent an immediate or direct threat to systems.

Potential Impact

For European organizations, the impact of this threat intelligence is primarily in the realm of improved detection and response rather than direct compromise. The availability of these IOCs can help security teams identify malicious network activity or payload delivery attempts that align with the reported indicators. This can reduce dwell time of attackers and limit potential damage from malware infections. However, since no specific vulnerabilities or exploits are detailed, there is no immediate risk of exploitation or system compromise. The medium severity rating suggests that while the threat intelligence is useful, it does not indicate a critical or widespread active threat. Organizations with mature security operations centers (SOCs) and threat intelligence capabilities will benefit most by integrating these IOCs into their monitoring tools. Conversely, organizations lacking such capabilities may find limited immediate benefit. The lack of patches or exploit activity means no urgent remediation is required, but vigilance in monitoring is advised. Overall, the impact is moderate and focused on enhancing defensive posture rather than responding to an active attack.

Mitigation Recommendations

To effectively leverage this threat intelligence, European organizations should integrate the provided IOCs into their security information and event management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS), and endpoint detection and response (EDR) tools. Regularly updating threat intelligence feeds and correlating these IOCs with internal logs can improve detection of suspicious network activity and payload delivery attempts. Security teams should conduct threat hunting exercises using these indicators to proactively identify potential compromises. Additionally, organizations should ensure robust network segmentation and implement strict access controls to limit the impact of any detected malware activity. Employee awareness training on phishing and social engineering remains important, as payload delivery often exploits human factors. Since no patches are available, maintaining up-to-date software and applying security best practices reduces the attack surface. Collaboration with national and European cybersecurity agencies can enhance situational awareness and response coordination. Finally, documenting and sharing any findings related to these IOCs within trusted communities can improve collective defense.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
2c81e393-628f-4869-a7b4-23ea4d0c07a3
Original Timestamp
1764288186

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttp://47.236.194.231:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://185.163.204.237/google.json
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://cryptoinfa.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://dmmediacamp.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://trd.vn/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://mail.perthspeechpathology.com.au/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://45.144.53.58/949ea21567eb4db7.php
Stealc botnet C2 (confidence level: 100%)
urlhttps://ggh5e4h54.cc
Stealc botnet C2 (confidence level: 100%)
urlhttps://seiho-ippankatei.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://yolwkl.org/captcha.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://cryptoportalhub.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://99sbobet.net
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://aimania2024.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://ami-thai.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://arnaelevators.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://118.107.21.101:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://gotokenta.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://homeexplore.novacrm.ca
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lorriedeenacaplan.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://padelsportacademy.app
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://sparklehomecleaningcompany.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://nutritionadvicehub.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://ridethecape.co.za
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://www.mmoo.vet
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://nithani.co.uk
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://194.87.55.59/dxx.odd
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://thewrightgiftstore.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://training-uat.rapidascent.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://baby-mine0821.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://keyframe.com.co
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://myfandollars.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://nisourcetech.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://peppersghost.org
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://23wincom.agency
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://africanalphacc.com
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://uniquedreambuilders.in/wps/index.html
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://pec.itermed.ar/
Vidar botnet C2 (confidence level: 100%)
urlhttps://pec.thesmarthustle.info/
Vidar botnet C2 (confidence level: 100%)
urlhttps://116.203.11.101/
Vidar botnet C2 (confidence level: 100%)
urlhttps://49.13.217.28/
Vidar botnet C2 (confidence level: 100%)
urlhttps://49.13.39.130/
Vidar botnet C2 (confidence level: 100%)
urlhttps://91.244.71.62/
Vidar botnet C2 (confidence level: 100%)
urlhttps://49.13.38.235/
Vidar botnet C2 (confidence level: 100%)
urlhttps://www.peppersghost.org/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://mmoo.vet/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://fdlkewebsite.icu
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://alpeoqa.cyou/api
Lumma Stealer botnet C2 (confidence level: 75%)
urlhttps://bop.itermed.ar/
Vidar botnet C2 (confidence level: 100%)
urlhttps://bop.thesmarthustle.info/
Vidar botnet C2 (confidence level: 100%)
urlhttp://85.121.148.35
Stealc botnet C2 (confidence level: 100%)
urlhttps://commonloamprojects.com/k3ts3rhrrkh6rop0lltc44dr64xezms-m3qtzdli
FAKEUPDATES payload delivery URL (confidence level: 100%)
urlhttp://8.130.89.132:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://47.105.117.209:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://thu.itermed.ar/
Vidar botnet C2 (confidence level: 100%)
urlhttps://thu.thesmarthustle.info/
Vidar botnet C2 (confidence level: 100%)
urlhttp://45.149.154.97
Stealc botnet C2 (confidence level: 100%)

File

ValueDescriptionCopy
file47.236.194.231
Unknown malware botnet C2 server (confidence level: 100%)
file104.168.142.88
STRRAT botnet C2 server (confidence level: 100%)
file158.94.210.133
Latrodectus botnet C2 server (confidence level: 100%)
file91.214.78.123
Remcos botnet C2 server (confidence level: 100%)
file139.59.141.55
Unknown malware botnet C2 server (confidence level: 100%)
file78.47.226.37
Hook botnet C2 server (confidence level: 100%)
file197.44.116.226
Unknown malware botnet C2 server (confidence level: 100%)
file104.198.157.155
Meterpreter botnet C2 server (confidence level: 100%)
file43.155.252.158
Cobalt Strike botnet C2 server (confidence level: 75%)
file137.220.194.49
Cobalt Strike botnet C2 server (confidence level: 100%)
file46.247.108.140
Remcos botnet C2 server (confidence level: 100%)
file47.110.66.48
Sliver botnet C2 server (confidence level: 100%)
file80.78.25.70
Sliver botnet C2 server (confidence level: 100%)
file162.243.28.13
AsyncRAT botnet C2 server (confidence level: 100%)
file144.124.246.133
SectopRAT botnet C2 server (confidence level: 100%)
file91.84.125.113
SectopRAT botnet C2 server (confidence level: 100%)
file3.222.9.169
Unknown malware botnet C2 server (confidence level: 100%)
file171.232.1.88
Venom RAT botnet C2 server (confidence level: 100%)
file171.232.1.88
Venom RAT botnet C2 server (confidence level: 100%)
file171.232.1.88
Venom RAT botnet C2 server (confidence level: 100%)
file168.245.201.145
Meterpreter botnet C2 server (confidence level: 100%)
file168.245.201.158
Meterpreter botnet C2 server (confidence level: 100%)
file168.245.201.153
Meterpreter botnet C2 server (confidence level: 100%)
file168.245.201.136
Meterpreter botnet C2 server (confidence level: 100%)
file168.245.201.142
Meterpreter botnet C2 server (confidence level: 100%)
file89.110.93.218
BianLian botnet C2 server (confidence level: 100%)
file64.95.13.26
Cobalt Strike botnet C2 server (confidence level: 100%)
file180.76.174.250
Cobalt Strike botnet C2 server (confidence level: 100%)
file111.228.40.26
Cobalt Strike botnet C2 server (confidence level: 100%)
file130.49.176.86
Cobalt Strike botnet C2 server (confidence level: 100%)
file206.189.0.80
Mirai botnet C2 server (confidence level: 75%)
file45.61.161.169
AsyncRAT botnet C2 server (confidence level: 50%)
file45.61.161.169
AsyncRAT botnet C2 server (confidence level: 50%)
file45.61.161.169
AsyncRAT botnet C2 server (confidence level: 50%)
file172.94.15.100
Remcos botnet C2 server (confidence level: 50%)
file78.46.214.104
Vidar botnet C2 server (confidence level: 100%)
file116.203.11.101
Vidar botnet C2 server (confidence level: 100%)
file49.13.217.28
Vidar botnet C2 server (confidence level: 100%)
file49.13.39.130
Vidar botnet C2 server (confidence level: 100%)
file91.244.71.62
Vidar botnet C2 server (confidence level: 100%)
file49.13.38.235
Vidar botnet C2 server (confidence level: 100%)
file38.47.239.72
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.159.53.42
Cobalt Strike botnet C2 server (confidence level: 100%)
file157.20.182.28
AsyncRAT botnet C2 server (confidence level: 100%)
file172.94.92.38
Quasar RAT botnet C2 server (confidence level: 100%)
file41.251.41.218
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file197.44.116.226
Unknown malware botnet C2 server (confidence level: 100%)
file110.40.186.230
AdaptixC2 botnet C2 server (confidence level: 100%)
file69.5.189.149
AdaptixC2 botnet C2 server (confidence level: 100%)
file196.75.72.57
Meterpreter botnet C2 server (confidence level: 100%)
file218.255.179.148
DeimosC2 botnet C2 server (confidence level: 75%)
file31.7.77.230
Eye Pyramid botnet C2 server (confidence level: 75%)
file41.216.189.185
Mirai botnet C2 server (confidence level: 75%)
file198.23.196.130
Cobalt Strike botnet C2 server (confidence level: 100%)
file188.166.185.215
Cobalt Strike botnet C2 server (confidence level: 100%)
file191.96.207.153
AsyncRAT botnet C2 server (confidence level: 100%)
file157.250.206.75
AsyncRAT botnet C2 server (confidence level: 100%)
file47.243.77.121
Quasar RAT botnet C2 server (confidence level: 100%)
file2.57.19.230
Venom RAT botnet C2 server (confidence level: 100%)
file196.251.100.51
BlackNET RAT botnet C2 server (confidence level: 100%)
file196.251.100.51
BlackNET RAT botnet C2 server (confidence level: 100%)
file8.210.253.131
Unknown malware botnet C2 server (confidence level: 100%)
file213.200.185.124
Unknown malware botnet C2 server (confidence level: 100%)
file119.91.55.16
Unknown malware botnet C2 server (confidence level: 100%)
file173.249.42.51
Unknown malware botnet C2 server (confidence level: 100%)
file47.102.197.153
Unknown malware botnet C2 server (confidence level: 100%)
file69.169.108.238
Unknown malware botnet C2 server (confidence level: 100%)
file124.156.205.244
Unknown malware botnet C2 server (confidence level: 100%)
file98.91.214.147
Unknown malware botnet C2 server (confidence level: 100%)
file62.84.190.38
Unknown malware botnet C2 server (confidence level: 100%)
file35.201.254.128
Unknown malware botnet C2 server (confidence level: 100%)
file151.243.218.164
XWorm botnet C2 server (confidence level: 100%)
file172.111.137.164
Remcos botnet C2 server (confidence level: 100%)
file209.54.101.170
Remcos botnet C2 server (confidence level: 100%)
file95.164.5.245
Sliver botnet C2 server (confidence level: 100%)
file124.158.5.149
Sliver botnet C2 server (confidence level: 100%)
file111.119.203.52
Sliver botnet C2 server (confidence level: 100%)
file45.151.142.251
AsyncRAT botnet C2 server (confidence level: 100%)
file2.56.214.177
AdaptixC2 botnet C2 server (confidence level: 100%)
file114.55.34.71
Cobalt Strike botnet C2 server (confidence level: 75%)
file213.165.42.46
Meterpreter botnet C2 server (confidence level: 75%)
file185.186.26.202
Mirai botnet C2 server (confidence level: 100%)
file5.75.216.89
Vidar botnet C2 server (confidence level: 100%)
file46.62.225.51
Unknown malware botnet C2 server (confidence level: 75%)
file46.62.205.38
Unknown malware botnet C2 server (confidence level: 75%)
file119.29.183.182
Cobalt Strike botnet C2 server (confidence level: 100%)
file107.173.180.173
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.12.148.42
Cobalt Strike botnet C2 server (confidence level: 100%)
file139.162.137.67
Sliver botnet C2 server (confidence level: 100%)
file72.61.194.81
Unknown malware botnet C2 server (confidence level: 100%)
file81.68.238.97
Havoc botnet C2 server (confidence level: 100%)
file134.33.194.214
Unknown malware botnet C2 server (confidence level: 100%)
file94.237.59.231
MimiKatz botnet C2 server (confidence level: 100%)
file72.61.141.82
Empire Downloader botnet C2 server (confidence level: 100%)
file185.254.96.150
Mirai botnet C2 server (confidence level: 100%)
file111.119.203.52
Sliver botnet C2 server (confidence level: 75%)
file188.130.207.22
Havoc botnet C2 server (confidence level: 75%)
file188.166.156.56
Havoc botnet C2 server (confidence level: 75%)
file190.225.32.131
QakBot botnet C2 server (confidence level: 75%)
file216.126.237.61
Unknown malware botnet C2 server (confidence level: 75%)
file47.103.143.60
Unknown malware botnet C2 server (confidence level: 75%)
file69.5.189.243
AdaptixC2 botnet C2 server (confidence level: 75%)
file89.110.77.192
DeimosC2 botnet C2 server (confidence level: 75%)
file154.219.104.36
Cobalt Strike botnet C2 server (confidence level: 100%)
file39.105.136.189
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.12.148.33
Cobalt Strike botnet C2 server (confidence level: 100%)
file91.92.241.247
Cobalt Strike botnet C2 server (confidence level: 100%)
file3.39.253.174
Cobalt Strike botnet C2 server (confidence level: 100%)
file158.94.210.136
Latrodectus botnet C2 server (confidence level: 100%)
file5.182.211.16
Unknown malware botnet C2 server (confidence level: 100%)
file167.71.255.8
AsyncRAT botnet C2 server (confidence level: 100%)
file162.243.28.13
AsyncRAT botnet C2 server (confidence level: 100%)
file52.77.62.221
Quasar RAT botnet C2 server (confidence level: 100%)
file188.130.207.22
Havoc botnet C2 server (confidence level: 100%)
file172.105.183.234
Havoc botnet C2 server (confidence level: 100%)
file171.232.1.88
Venom RAT botnet C2 server (confidence level: 100%)
file95.111.204.23
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file23.227.202.163
MimiKatz botnet C2 server (confidence level: 100%)
file86.125.227.77
MimiKatz botnet C2 server (confidence level: 100%)
file107.189.17.247
AdaptixC2 botnet C2 server (confidence level: 100%)
file160.178.223.144
Meterpreter botnet C2 server (confidence level: 100%)
file106.13.86.178
Cobalt Strike botnet C2 server (confidence level: 100%)
file193.242.184.136
Empire Downloader botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash5050
STRRAT botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8082
Hook botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash4444
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash8443
Sliver botnet C2 server (confidence level: 100%)
hash8444
Sliver botnet C2 server (confidence level: 100%)
hash8000
AsyncRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash5000
Venom RAT botnet C2 server (confidence level: 100%)
hash5001
Venom RAT botnet C2 server (confidence level: 100%)
hash6000
Venom RAT botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash8443
BianLian botnet C2 server (confidence level: 100%)
hashf68872773a88652541bd8d6ca9bda058
WORMHOLE payload (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9090
Cobalt Strike botnet C2 server (confidence level: 100%)
hash85
Cobalt Strike botnet C2 server (confidence level: 100%)
hash39691
Mirai botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 50%)
hash7707
AsyncRAT botnet C2 server (confidence level: 50%)
hash8808
AsyncRAT botnet C2 server (confidence level: 50%)
hash6075
Remcos botnet C2 server (confidence level: 50%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9992
AsyncRAT botnet C2 server (confidence level: 100%)
hash1000
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash12564
AdaptixC2 botnet C2 server (confidence level: 100%)
hash5985
AdaptixC2 botnet C2 server (confidence level: 100%)
hash2222
Meterpreter botnet C2 server (confidence level: 100%)
hash47156
DeimosC2 botnet C2 server (confidence level: 75%)
hash18080
Eye Pyramid botnet C2 server (confidence level: 75%)
hash12121
Mirai botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash7008
AsyncRAT botnet C2 server (confidence level: 100%)
hash48396
Quasar RAT botnet C2 server (confidence level: 100%)
hash4449
Venom RAT botnet C2 server (confidence level: 100%)
hash80
BlackNET RAT botnet C2 server (confidence level: 100%)
hash443
BlackNET RAT botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash7777
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash7007
XWorm botnet C2 server (confidence level: 100%)
hash3384
Remcos botnet C2 server (confidence level: 100%)
hash8085
Remcos botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash8443
Sliver botnet C2 server (confidence level: 100%)
hash8080
Sliver botnet C2 server (confidence level: 100%)
hash2222
AsyncRAT botnet C2 server (confidence level: 100%)
hash1080
AdaptixC2 botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Meterpreter botnet C2 server (confidence level: 75%)
hash1312
Mirai botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash8008
Unknown malware botnet C2 server (confidence level: 75%)
hash8008
Unknown malware botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2052
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash4433
Havoc botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash9999
MimiKatz botnet C2 server (confidence level: 100%)
hash1337
Empire Downloader botnet C2 server (confidence level: 100%)
hash4123
Mirai botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 75%)
hash8443
Havoc botnet C2 server (confidence level: 75%)
hash443
Havoc botnet C2 server (confidence level: 75%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash60000
Unknown malware botnet C2 server (confidence level: 75%)
hash2374
AdaptixC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8088
AsyncRAT botnet C2 server (confidence level: 100%)
hash22
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash9999
Venom RAT botnet C2 server (confidence level: 100%)
hash26477
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash8000
MimiKatz botnet C2 server (confidence level: 100%)
hash80
MimiKatz botnet C2 server (confidence level: 100%)
hash1080
AdaptixC2 botnet C2 server (confidence level: 100%)
hash2222
Meterpreter botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Empire Downloader botnet C2 server (confidence level: 100%)

Domain

ValueDescriptionCopy
domaincontrol.myaffiliateincome.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domaincryptoinfa.com
Unknown malware payload delivery domain (confidence level: 100%)
domainbraun5.copperweide8.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyoxel2.copperweide8.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrava7n.ravenstein.ru
ClearFake payload delivery domain (confidence level: 100%)
domaineis3en.ravenstein.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkorvo5.ravenstein.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsteyn4.ravenstein.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnoxil7.ravenstein.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmapl3e.maplekueste.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfjord6.maplekueste.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkuest5.maplekueste.ru
ClearFake payload delivery domain (confidence level: 100%)
domainahorn7.maplekueste.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbryz4a.maplekueste.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingl1mra.glimmerkranz.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkran7z.glimmerkranz.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfunke5.glimmerkranz.ru
ClearFake payload delivery domain (confidence level: 100%)
domainscher4.glimmerkranz.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbl3nda.glimmerkranz.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsilb3r.silberquarz4.ru
ClearFake payload delivery domain (confidence level: 100%)
domain1310445127-bo78zajqf2.ap-shanghai.tencentscf.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainstatic-mtpjoriqkv.cn-beijing.fcapp.run
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainwww.beihu-jlbank.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainqartz7.silberquarz4.ru
ClearFake payload delivery domain (confidence level: 100%)
domainglanz5.silberquarz4.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrauch4.silberquarz4.ru
ClearFake payload delivery domain (confidence level: 100%)
domainberyl6.silberquarz4.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwill7o.willowgase.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingas3en.willowgase.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnebl4e.willowgase.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhaust5.willowgase.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzerfa2.willowgase.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnebe7l.nebeltal.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintau3ig.nebeltal.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingrau5e.nebeltal.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintalon4.nebeltal.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfluss8.nebeltal.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspruc5.sprucewinkel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwink3l.sprucewinkel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainharz7a.sprucewinkel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainficht4.sprucewinkel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainschne8.sprucewinkel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainonyx5a.onyxquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbrun4n.onyxquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainquel7e.onyxquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsourc3.onyxquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingrot8o.onyxquelle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainember5.emberklamm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkalm3m.emberklamm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainschlu7.emberklamm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflar4e.emberklamm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbrand8.emberklamm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainborass.ddns.net
XWorm botnet C2 domain (confidence level: 100%)
domainuzlehalo134.duckdns.org
XWorm botnet C2 domain (confidence level: 100%)
domainvex7in.st0rmshade.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbuyaofengwoa.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domainstrm9a.st0rmshade.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsilverpath.shadowstresser.info
Mirai botnet C2 domain (confidence level: 100%)
domainhalox5.st0rmshade.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyolwkl.org
Unknown malware payload delivery domain (confidence level: 100%)
domaindriff7.st0rmshade.ru
ClearFake payload delivery domain (confidence level: 100%)
domainslursbeback.ru
Mirai botnet C2 domain (confidence level: 100%)
domainnubil3.st0rmshade.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincrys7a.crystalv1be.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincryptoportalhub.com
Unknown malware payload delivery domain (confidence level: 100%)
domain99sbobet.net
Unknown malware payload delivery domain (confidence level: 100%)
domainaimania2024.com
Unknown malware payload delivery domain (confidence level: 100%)
domainami-thai.com
Unknown malware payload delivery domain (confidence level: 100%)
domainaceawarewales.com
AsyncRAT botnet C2 domain (confidence level: 50%)
domaingatex.aceawarewales.com
AsyncRAT botnet C2 domain (confidence level: 50%)
domaingatex.www.50thirdand3rd.com
AsyncRAT botnet C2 domain (confidence level: 50%)
domainkitchen-bet.gl.at.ply.gg
AsyncRAT botnet C2 domain (confidence level: 50%)
domainwww.canwoodgallery.com
AsyncRAT botnet C2 domain (confidence level: 50%)
domainwww.fondazionesabattini.it
AsyncRAT botnet C2 domain (confidence level: 50%)
domainvib3ro.crystalv1be.ru
ClearFake payload delivery domain (confidence level: 100%)
domainarnaelevators.com
Unknown malware payload delivery domain (confidence level: 100%)
domainv2.aceawarewales.com
DCRat botnet C2 domain (confidence level: 50%)
domainv2.homoclimbtastic.com
DCRat botnet C2 domain (confidence level: 50%)
domainv2.socolive6.ac
DCRat botnet C2 domain (confidence level: 50%)
domainv2.www.50thirdand3rd.com
DCRat botnet C2 domain (confidence level: 50%)
domainv2.www.allaboutbasketball.us
DCRat botnet C2 domain (confidence level: 50%)
domainv2.www.istas22.org
DCRat botnet C2 domain (confidence level: 50%)
domainv2.www.outsideprague.com
DCRat botnet C2 domain (confidence level: 50%)
domainv3.aceawarewales.com
DCRat botnet C2 domain (confidence level: 50%)
domainv3.homoclimbtastic.com
DCRat botnet C2 domain (confidence level: 50%)
domainv3.socolive6.ac
DCRat botnet C2 domain (confidence level: 50%)
domainv3.www.50thirdand3rd.com
DCRat botnet C2 domain (confidence level: 50%)
domainv3.www.allaboutbasketball.us
DCRat botnet C2 domain (confidence level: 50%)
domainv3.www.istas22.org
DCRat botnet C2 domain (confidence level: 50%)
domainv3.www.outsideprague.com
DCRat botnet C2 domain (confidence level: 50%)
domainscience-tight.gl.at.ply.gg
NjRAT botnet C2 domain (confidence level: 50%)
domaindoes-58376.portmap.host
XWorm botnet C2 domain (confidence level: 50%)
domainmost-inbox.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domainbongoshare.bishtelecom.com
Unknown malware payload delivery domain (confidence level: 100%)
domaingotokenta.com
Unknown malware payload delivery domain (confidence level: 100%)
domainhomeexplore.novacrm.ca
Unknown malware payload delivery domain (confidence level: 100%)
domainlorriedeenacaplan.com
Unknown malware payload delivery domain (confidence level: 100%)
domainpadelsportacademy.app
Unknown malware payload delivery domain (confidence level: 100%)
domainsparklehomecleaningcompany.com
Unknown malware payload delivery domain (confidence level: 100%)
domainlumyx6.crystalv1be.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnutritionadvicehub.com
Unknown malware payload delivery domain (confidence level: 100%)
domainridethecape.co.za
Unknown malware payload delivery domain (confidence level: 100%)
domainmmoo.vet
Unknown malware payload delivery domain (confidence level: 100%)
domainglint5.crystalv1be.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnithani.co.uk
Unknown malware payload delivery domain (confidence level: 100%)
domainthewrightgiftstore.com
Unknown malware payload delivery domain (confidence level: 100%)
domaintraining-uat.rapidascent.com
Unknown malware payload delivery domain (confidence level: 100%)
domainfrakt8.crystalv1be.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbaby-mine0821.com
Unknown malware payload delivery domain (confidence level: 100%)
domainkeyframe.com.co
Unknown malware payload delivery domain (confidence level: 100%)
domainmyfandollars.com
Unknown malware payload delivery domain (confidence level: 100%)
domainnisourcetech.com
Unknown malware payload delivery domain (confidence level: 100%)
domainpeppersghost.org
Unknown malware payload delivery domain (confidence level: 100%)
domaingale7x.windstack.ru
ClearFake payload delivery domain (confidence level: 100%)
domain23wincom.agency
Unknown malware payload delivery domain (confidence level: 100%)
domainafricanalphacc.com
Unknown malware payload delivery domain (confidence level: 100%)
domainvindex5.windstack.ru
ClearFake payload delivery domain (confidence level: 100%)
domainaeri4s.windstack.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsquall6.windstack.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpec.itermed.ar
Vidar botnet C2 domain (confidence level: 100%)
domainpec.thesmarthustle.info
Vidar botnet C2 domain (confidence level: 100%)
domainw1ndo.windstack.ru
ClearFake payload delivery domain (confidence level: 100%)
domainst0ne.stoneburst.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfdlkewebsite.icu
Unknown malware payload delivery domain (confidence level: 100%)
domainbrecc8.stoneburst.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshard7.stoneburst.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrumbl5.stoneburst.ru
ClearFake payload delivery domain (confidence level: 100%)
domainquak3r.stoneburst.ru
ClearFake payload delivery domain (confidence level: 100%)
domainslush5.sn0wtrail.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsn0wy7.sn0wtrail.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintrac3r.sn0wtrail.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflurr6.sn0wtrail.ru
ClearFake payload delivery domain (confidence level: 100%)
domainskid9x.sn0wtrail.ru
ClearFake payload delivery domain (confidence level: 100%)
domainazure5.bluem1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmist7y.bluem1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincyan9x.bluem1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbleue4.bluem1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfoggy6.bluem1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainriv3t.r1verdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindropl7.r1verdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincreek5.r1verdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsplash8.r1verdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindelta6.r1verdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsofte5.soft0cean.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintid4l.soft0cean.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwave7x.soft0cean.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsurf9a.soft0cean.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmar3na.soft0cean.ru
ClearFake payload delivery domain (confidence level: 100%)
domainclov3r.cl0vermint.ru
ClearFake payload delivery domain (confidence level: 100%)
domainminty7.cl0vermint.ru
ClearFake payload delivery domain (confidence level: 100%)
domainherb6x.cl0vermint.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbop.itermed.ar
Vidar botnet C2 domain (confidence level: 100%)
domainbop.thesmarthustle.info
Vidar botnet C2 domain (confidence level: 100%)
domainshamr4.cl0vermint.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfr3sha.cl0vermint.ru
ClearFake payload delivery domain (confidence level: 100%)
domainherb5x.mintpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmnt3ak.mintpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzefyr7.mintpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainclov8r.mintpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindew4ly.mintpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfr0stx.frostdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindrip7y.frostdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainicell3.frostdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshivr5.frostdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflak8e.frostdrop.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindu5tly.dustpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpeak7r.dustpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsilt9x.dustpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhaz3lo.dustpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmote5r.dustpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflash7.fastspark.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsp4rkx.fastspark.ru
ClearFake payload delivery domain (confidence level: 100%)
domainb1.yydscd1.top
ValleyRAT botnet C2 domain (confidence level: 100%)
domainb1.yydscd3.top
ValleyRAT botnet C2 domain (confidence level: 100%)
domainqu1ckr.fastspark.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbolt9a.fastspark.ru
ClearFake payload delivery domain (confidence level: 100%)
domainracy5n.fastspark.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindoz3er.lazywind.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlaz7ee.lazywind.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbreez5.lazywind.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyawn9x.lazywind.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincalm4y.lazywind.ru
ClearFake payload delivery domain (confidence level: 100%)
domainst0rmx.stormling.ru
ClearFake payload delivery domain (confidence level: 100%)
domainling7o.stormling.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingust5y.stormling.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrumbl3.stormling.ru
ClearFake payload delivery domain (confidence level: 100%)
domainclap9t.stormling.ru
ClearFake payload delivery domain (confidence level: 100%)
domainglaci5.iceglow.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfroz7y.iceglow.ru
ClearFake payload delivery domain (confidence level: 100%)
domainicey4x.iceglow.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlum3na.iceglow.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhalo9r.iceglow.ru
ClearFake payload delivery domain (confidence level: 100%)
domainleaf7y.leafbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbyt3rx.leafbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspr1gg.leafbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbud4le.leafbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintwig9x.leafbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrain7x.rainbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindrop5y.rainbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincl0udy.rainbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpatt3r.rainbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsplo8s.rainbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainthu.itermed.ar
Vidar botnet C2 domain (confidence level: 100%)
domainthu.thesmarthustle.info
Vidar botnet C2 domain (confidence level: 100%)
domainsnow7y.snowroot.ru
ClearFake payload delivery domain (confidence level: 100%)
domainroot4x.snowroot.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsl3etx.snowroot.ru
ClearFake payload delivery domain (confidence level: 100%)
domainthaw9r.snowroot.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfirn5a.snowroot.ru
ClearFake payload delivery domain (confidence level: 100%)
domainr767b.stormmint.ru
ClearFake payload delivery domain (confidence level: 100%)
domain9t.stormmint.ru
ClearFake payload delivery domain (confidence level: 100%)
domain137f.stormmint.ru
ClearFake payload delivery domain (confidence level: 100%)
domainn2ag.stormmint.ru
ClearFake payload delivery domain (confidence level: 100%)
domainds.c0deroot.ru
ClearFake payload delivery domain (confidence level: 100%)
domain58k2.c0deroot.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfy.c0deroot.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspark2.c0deroot.ru
ClearFake payload delivery domain (confidence level: 100%)
domainq8s9.fl0wstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrise.fl0wstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domain87kd.fl0wstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfst.fl0wstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domain0g7o3.redm0on.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpulse1.redm0on.ru
ClearFake payload delivery domain (confidence level: 100%)
domaint7q2.redm0on.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfkl7.redm0on.ru
ClearFake payload delivery domain (confidence level: 100%)
domainos2rz.br1ghtwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindata.br1ghtwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainq54.br1ghtwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbcts.br1ghtwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincopyright-cnn.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domaintiw6q.cioudriver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainw4.cioudriver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfut.cioudriver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainf15yw.cioudriver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqyvu.cl1ffwood.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbright6.cl1ffwood.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbright.cl1ffwood.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwq.cl1ffwood.ru
ClearFake payload delivery domain (confidence level: 100%)
domaina2.snowr1se.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlake.snowr1se.ru
ClearFake payload delivery domain (confidence level: 100%)
domain52i.snowr1se.ru
ClearFake payload delivery domain (confidence level: 100%)
domainecho9.snowr1se.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspark8.stonem1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnote7.stonem1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwww.microsofrtonline.com
Havoc botnet C2 domain (confidence level: 100%)
domaintmsawards.testingweblink.com
Havoc botnet C2 domain (confidence level: 100%)
domainsmartlegal.testingweblink.com
Havoc botnet C2 domain (confidence level: 100%)
domainp81s.stonem1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingty6.stonem1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspark7.mistlake.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlake5.mistlake.ru
ClearFake payload delivery domain (confidence level: 100%)
domainred9.mistlake.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpz8ux.mistlake.ru
ClearFake payload delivery domain (confidence level: 100%)
domainz1w.st0y70renka.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbright7.st0y70renka.ru
ClearFake payload delivery domain (confidence level: 100%)
domain0a5f.st0y70renka.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfrost7.st0y70renka.ru
ClearFake payload delivery domain (confidence level: 100%)
domainp5.manual1sa1yz.ru
ClearFake payload delivery domain (confidence level: 100%)
domain4u29.manual1sa1yz.ru
ClearFake payload delivery domain (confidence level: 100%)
domainoxiw.manual1sa1yz.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwzs.manual1sa1yz.ru
ClearFake payload delivery domain (confidence level: 100%)
domainugmbe.a-5-t-1-gstudy.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwood.a-5-t-1-gstudy.ru
ClearFake payload delivery domain (confidence level: 100%)
domainei.a-5-t-1-gstudy.ru
ClearFake payload delivery domain (confidence level: 100%)
domain5r.a-5-t-1-gstudy.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8lwyc.dunn-0-en-7-el.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintvaz.dunn-0-en-7-el.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2ql.dunn-0-en-7-el.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2fq4.dunn-0-en-7-el.ru
ClearFake payload delivery domain (confidence level: 100%)
domain53.ede-1-g-0-rge.ru
ClearFake payload delivery domain (confidence level: 100%)
domainb2.ede-1-g-0-rge.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintd.ede-1-g-0-rge.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindperw.ede-1-g-0-rge.ru
ClearFake payload delivery domain (confidence level: 100%)
domain7ol4i.a5t1gstudy.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlake2.a5t1gstudy.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstorm.a5t1gstudy.ru
ClearFake payload delivery domain (confidence level: 100%)
domainred7.a5t1gstudy.ru
ClearFake payload delivery domain (confidence level: 100%)
domainroot7.ju-4-en-pare-1.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindk2fp.ju-4-en-pare-1.ru
ClearFake payload delivery domain (confidence level: 100%)

Threat ID: 6928e9f7ce4290e3e3801337

Added to database: 11/28/2025, 12:16:55 AM

Last enriched: 11/28/2025, 12:32:12 AM

Last updated: 12/1/2025, 11:12:19 PM

Views: 29

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats