ThreatFox IOCs for 2025-11-27
ThreatFox IOCs for 2025-11-27
AI Analysis
Technical Summary
The entry titled 'ThreatFox IOCs for 2025-11-27' is a report from the ThreatFox MISP feed, focusing on OSINT-derived Indicators of Compromise related to malware and network activity associated with payload delivery. The report does not specify particular malware families, affected software versions, or detailed attack vectors. It is primarily a collection of threat intelligence data intended to support detection and investigation efforts. The threat level is medium, with no known exploits currently active in the wild and no patches available, indicating that this is not a newly discovered vulnerability but rather intelligence on existing or potential threats. The technical details include a threat level rating of 2 and distribution rating of 3, suggesting moderate prevalence or dissemination of the associated IOCs. The absence of CWEs and exploit details implies that this is not a direct vulnerability but a set of indicators to aid in identifying malicious activity. The information is tagged as TLP:WHITE, meaning it is intended for wide distribution and sharing. This type of intelligence is valuable for security teams to improve situational awareness and enhance network monitoring and incident response capabilities. However, without specific actionable exploit or vulnerability data, it does not represent an immediate or direct threat to systems.
Potential Impact
For European organizations, the impact of this threat intelligence is primarily in the realm of improved detection and response rather than direct compromise. The availability of these IOCs can help security teams identify malicious network activity or payload delivery attempts that align with the reported indicators. This can reduce dwell time of attackers and limit potential damage from malware infections. However, since no specific vulnerabilities or exploits are detailed, there is no immediate risk of exploitation or system compromise. The medium severity rating suggests that while the threat intelligence is useful, it does not indicate a critical or widespread active threat. Organizations with mature security operations centers (SOCs) and threat intelligence capabilities will benefit most by integrating these IOCs into their monitoring tools. Conversely, organizations lacking such capabilities may find limited immediate benefit. The lack of patches or exploit activity means no urgent remediation is required, but vigilance in monitoring is advised. Overall, the impact is moderate and focused on enhancing defensive posture rather than responding to an active attack.
Mitigation Recommendations
To effectively leverage this threat intelligence, European organizations should integrate the provided IOCs into their security information and event management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS), and endpoint detection and response (EDR) tools. Regularly updating threat intelligence feeds and correlating these IOCs with internal logs can improve detection of suspicious network activity and payload delivery attempts. Security teams should conduct threat hunting exercises using these indicators to proactively identify potential compromises. Additionally, organizations should ensure robust network segmentation and implement strict access controls to limit the impact of any detected malware activity. Employee awareness training on phishing and social engineering remains important, as payload delivery often exploits human factors. Since no patches are available, maintaining up-to-date software and applying security best practices reduces the attack surface. Collaboration with national and European cybersecurity agencies can enhance situational awareness and response coordination. Finally, documenting and sharing any findings related to these IOCs within trusted communities can improve collective defense.
Affected Countries
Germany, France, United Kingdom, Netherlands, Italy, Spain, Poland
Indicators of Compromise
- url: http://47.236.194.231:8888/supershell/login/
- file: 47.236.194.231
- hash: 8888
- domain: control.myaffiliateincome.com
- url: http://185.163.204.237/google.json
- url: https://cryptoinfa.com
- domain: cryptoinfa.com
- url: https://dmmediacamp.com/
- file: 104.168.142.88
- hash: 5050
- file: 158.94.210.133
- hash: 443
- file: 91.214.78.123
- hash: 443
- file: 139.59.141.55
- hash: 443
- file: 78.47.226.37
- hash: 8082
- file: 197.44.116.226
- hash: 80
- file: 104.198.157.155
- hash: 4444
- domain: braun5.copperweide8.ru
- domain: yoxel2.copperweide8.ru
- domain: rava7n.ravenstein.ru
- domain: eis3en.ravenstein.ru
- domain: korvo5.ravenstein.ru
- domain: steyn4.ravenstein.ru
- domain: noxil7.ravenstein.ru
- domain: mapl3e.maplekueste.ru
- url: https://trd.vn/
- domain: fjord6.maplekueste.ru
- domain: kuest5.maplekueste.ru
- domain: ahorn7.maplekueste.ru
- domain: bryz4a.maplekueste.ru
- domain: gl1mra.glimmerkranz.ru
- domain: kran7z.glimmerkranz.ru
- domain: funke5.glimmerkranz.ru
- domain: scher4.glimmerkranz.ru
- domain: bl3nda.glimmerkranz.ru
- domain: silb3r.silberquarz4.ru
- domain: 1310445127-bo78zajqf2.ap-shanghai.tencentscf.com
- domain: static-mtpjoriqkv.cn-beijing.fcapp.run
- domain: www.beihu-jlbank.com
- file: 43.155.252.158
- hash: 443
- domain: qartz7.silberquarz4.ru
- domain: glanz5.silberquarz4.ru
- domain: rauch4.silberquarz4.ru
- domain: beryl6.silberquarz4.ru
- domain: will7o.willowgase.ru
- domain: gas3en.willowgase.ru
- domain: nebl4e.willowgase.ru
- domain: haust5.willowgase.ru
- domain: zerfa2.willowgase.ru
- domain: nebe7l.nebeltal.ru
- domain: tau3ig.nebeltal.ru
- domain: grau5e.nebeltal.ru
- domain: talon4.nebeltal.ru
- file: 137.220.194.49
- hash: 443
- file: 46.247.108.140
- hash: 2404
- file: 47.110.66.48
- hash: 8443
- file: 80.78.25.70
- hash: 8444
- file: 162.243.28.13
- hash: 8000
- file: 144.124.246.133
- hash: 9000
- file: 91.84.125.113
- hash: 9000
- file: 3.222.9.169
- hash: 443
- file: 171.232.1.88
- hash: 5000
- file: 171.232.1.88
- hash: 5001
- file: 171.232.1.88
- hash: 6000
- file: 168.245.201.145
- hash: 3790
- file: 168.245.201.158
- hash: 3790
- file: 168.245.201.153
- hash: 3790
- file: 168.245.201.136
- hash: 3790
- file: 168.245.201.142
- hash: 3790
- domain: fluss8.nebeltal.ru
- file: 89.110.93.218
- hash: 8443
- domain: spruc5.sprucewinkel.ru
- domain: wink3l.sprucewinkel.ru
- domain: harz7a.sprucewinkel.ru
- domain: ficht4.sprucewinkel.ru
- url: https://mail.perthspeechpathology.com.au/
- hash: f68872773a88652541bd8d6ca9bda058
- domain: schne8.sprucewinkel.ru
- domain: onyx5a.onyxquelle.ru
- domain: brun4n.onyxquelle.ru
- domain: quel7e.onyxquelle.ru
- url: http://45.144.53.58/949ea21567eb4db7.php
- domain: sourc3.onyxquelle.ru
- domain: grot8o.onyxquelle.ru
- domain: ember5.emberklamm.ru
- domain: kalm3m.emberklamm.ru
- domain: schlu7.emberklamm.ru
- domain: flar4e.emberklamm.ru
- file: 64.95.13.26
- hash: 80
- file: 180.76.174.250
- hash: 8888
- file: 111.228.40.26
- hash: 9090
- file: 130.49.176.86
- hash: 85
- domain: brand8.emberklamm.ru
- domain: borass.ddns.net
- domain: uzlehalo134.duckdns.org
- url: https://ggh5e4h54.cc
- domain: vex7in.st0rmshade.ru
- domain: buyaofengwoa.com
- domain: strm9a.st0rmshade.ru
- domain: silverpath.shadowstresser.info
- domain: halox5.st0rmshade.ru
- url: https://seiho-ippankatei.com/
- domain: yolwkl.org
- url: https://yolwkl.org/captcha.html
- domain: driff7.st0rmshade.ru
- file: 206.189.0.80
- hash: 39691
- domain: slursbeback.ru
- domain: nubil3.st0rmshade.ru
- domain: crys7a.crystalv1be.ru
- url: https://cryptoportalhub.com
- domain: cryptoportalhub.com
- url: https://99sbobet.net
- domain: 99sbobet.net
- domain: aimania2024.com
- url: https://aimania2024.com
- domain: ami-thai.com
- url: https://ami-thai.com
- url: https://arnaelevators.com
- domain: aceawarewales.com
- domain: gatex.aceawarewales.com
- domain: gatex.www.50thirdand3rd.com
- domain: kitchen-bet.gl.at.ply.gg
- domain: www.canwoodgallery.com
- domain: www.fondazionesabattini.it
- domain: vib3ro.crystalv1be.ru
- domain: arnaelevators.com
- file: 45.61.161.169
- hash: 6606
- file: 45.61.161.169
- hash: 7707
- file: 45.61.161.169
- hash: 8808
- domain: v2.aceawarewales.com
- domain: v2.homoclimbtastic.com
- domain: v2.socolive6.ac
- domain: v2.www.50thirdand3rd.com
- domain: v2.www.allaboutbasketball.us
- domain: v2.www.istas22.org
- domain: v2.www.outsideprague.com
- domain: v3.aceawarewales.com
- domain: v3.homoclimbtastic.com
- domain: v3.socolive6.ac
- domain: v3.www.50thirdand3rd.com
- domain: v3.www.allaboutbasketball.us
- domain: v3.www.istas22.org
- domain: v3.www.outsideprague.com
- domain: science-tight.gl.at.ply.gg
- file: 172.94.15.100
- hash: 6075
- domain: does-58376.portmap.host
- domain: most-inbox.gl.at.ply.gg
- url: http://118.107.21.101:8888/supershell/login/
- domain: bongoshare.bishtelecom.com
- domain: gotokenta.com
- url: https://gotokenta.com
- url: https://homeexplore.novacrm.ca
- domain: homeexplore.novacrm.ca
- url: https://lorriedeenacaplan.com
- domain: lorriedeenacaplan.com
- url: https://padelsportacademy.app
- domain: padelsportacademy.app
- url: https://sparklehomecleaningcompany.com
- domain: sparklehomecleaningcompany.com
- domain: lumyx6.crystalv1be.ru
- url: https://nutritionadvicehub.com
- domain: nutritionadvicehub.com
- url: https://ridethecape.co.za
- domain: ridethecape.co.za
- domain: mmoo.vet
- url: https://www.mmoo.vet
- domain: glint5.crystalv1be.ru
- url: https://nithani.co.uk
- domain: nithani.co.uk
- url: http://194.87.55.59/dxx.odd
- url: https://thewrightgiftstore.com
- domain: thewrightgiftstore.com
- domain: training-uat.rapidascent.com
- url: https://training-uat.rapidascent.com
- domain: frakt8.crystalv1be.ru
- url: https://baby-mine0821.com
- domain: baby-mine0821.com
- domain: keyframe.com.co
- url: https://keyframe.com.co
- url: https://myfandollars.com
- domain: myfandollars.com
- url: https://nisourcetech.com
- domain: nisourcetech.com
- url: https://peppersghost.org
- domain: peppersghost.org
- domain: gale7x.windstack.ru
- url: https://23wincom.agency
- domain: 23wincom.agency
- url: https://africanalphacc.com
- domain: africanalphacc.com
- url: https://uniquedreambuilders.in/wps/index.html
- domain: vindex5.windstack.ru
- domain: aeri4s.windstack.ru
- domain: squall6.windstack.ru
- url: https://pec.itermed.ar/
- url: https://pec.thesmarthustle.info/
- url: https://116.203.11.101/
- url: https://49.13.217.28/
- url: https://49.13.39.130/
- url: https://91.244.71.62/
- url: https://49.13.38.235/
- domain: pec.itermed.ar
- domain: pec.thesmarthustle.info
- file: 78.46.214.104
- hash: 443
- file: 116.203.11.101
- hash: 443
- file: 49.13.217.28
- hash: 443
- file: 49.13.39.130
- hash: 443
- file: 91.244.71.62
- hash: 443
- file: 49.13.38.235
- hash: 443
- domain: w1ndo.windstack.ru
- url: https://www.peppersghost.org/
- url: https://mmoo.vet/
- file: 38.47.239.72
- hash: 80
- file: 43.159.53.42
- hash: 80
- file: 157.20.182.28
- hash: 9992
- file: 172.94.92.38
- hash: 1000
- file: 41.251.41.218
- hash: 443
- file: 197.44.116.226
- hash: 443
- file: 110.40.186.230
- hash: 12564
- file: 69.5.189.149
- hash: 5985
- file: 196.75.72.57
- hash: 2222
- domain: st0ne.stoneburst.ru
- domain: fdlkewebsite.icu
- url: https://fdlkewebsite.icu
- domain: brecc8.stoneburst.ru
- domain: shard7.stoneburst.ru
- domain: rumbl5.stoneburst.ru
- domain: quak3r.stoneburst.ru
- domain: slush5.sn0wtrail.ru
- domain: sn0wy7.sn0wtrail.ru
- domain: trac3r.sn0wtrail.ru
- domain: flurr6.sn0wtrail.ru
- file: 218.255.179.148
- hash: 47156
- file: 31.7.77.230
- hash: 18080
- domain: skid9x.sn0wtrail.ru
- domain: azure5.bluem1st.ru
- domain: mist7y.bluem1st.ru
- domain: cyan9x.bluem1st.ru
- domain: bleue4.bluem1st.ru
- domain: foggy6.bluem1st.ru
- domain: riv3t.r1verdrop.ru
- domain: dropl7.r1verdrop.ru
- domain: creek5.r1verdrop.ru
- domain: splash8.r1verdrop.ru
- domain: delta6.r1verdrop.ru
- domain: softe5.soft0cean.ru
- domain: tid4l.soft0cean.ru
- domain: wave7x.soft0cean.ru
- domain: surf9a.soft0cean.ru
- url: https://alpeoqa.cyou/api
- domain: mar3na.soft0cean.ru
- domain: clov3r.cl0vermint.ru
- domain: minty7.cl0vermint.ru
- domain: herb6x.cl0vermint.ru
- url: https://bop.itermed.ar/
- url: https://bop.thesmarthustle.info/
- domain: bop.itermed.ar
- domain: bop.thesmarthustle.info
- domain: shamr4.cl0vermint.ru
- file: 41.216.189.185
- hash: 12121
- domain: fr3sha.cl0vermint.ru
- domain: herb5x.mintpeak.ru
- domain: mnt3ak.mintpeak.ru
- domain: zefyr7.mintpeak.ru
- domain: clov8r.mintpeak.ru
- domain: dew4ly.mintpeak.ru
- file: 198.23.196.130
- hash: 443
- file: 188.166.185.215
- hash: 80
- file: 191.96.207.153
- hash: 8808
- file: 157.250.206.75
- hash: 7008
- file: 47.243.77.121
- hash: 48396
- file: 2.57.19.230
- hash: 4449
- file: 196.251.100.51
- hash: 80
- file: 196.251.100.51
- hash: 443
- file: 8.210.253.131
- hash: 60000
- file: 213.200.185.124
- hash: 3333
- file: 119.91.55.16
- hash: 3333
- file: 173.249.42.51
- hash: 3333
- file: 47.102.197.153
- hash: 7777
- file: 69.169.108.238
- hash: 8080
- file: 124.156.205.244
- hash: 3333
- file: 98.91.214.147
- hash: 443
- file: 62.84.190.38
- hash: 443
- file: 35.201.254.128
- hash: 443
- domain: fr0stx.frostdrop.ru
- domain: drip7y.frostdrop.ru
- domain: icell3.frostdrop.ru
- domain: shivr5.frostdrop.ru
- domain: flak8e.frostdrop.ru
- domain: du5tly.dustpeak.ru
- domain: peak7r.dustpeak.ru
- domain: silt9x.dustpeak.ru
- domain: haz3lo.dustpeak.ru
- domain: mote5r.dustpeak.ru
- domain: flash7.fastspark.ru
- domain: sp4rkx.fastspark.ru
- file: 151.243.218.164
- hash: 7007
- file: 172.111.137.164
- hash: 3384
- file: 209.54.101.170
- hash: 8085
- file: 95.164.5.245
- hash: 31337
- file: 124.158.5.149
- hash: 8443
- file: 111.119.203.52
- hash: 8080
- file: 45.151.142.251
- hash: 2222
- url: http://85.121.148.35
- file: 2.56.214.177
- hash: 1080
- domain: b1.yydscd1.top
- domain: b1.yydscd3.top
- domain: qu1ckr.fastspark.ru
- domain: bolt9a.fastspark.ru
- domain: racy5n.fastspark.ru
- domain: doz3er.lazywind.ru
- domain: laz7ee.lazywind.ru
- domain: breez5.lazywind.ru
- domain: yawn9x.lazywind.ru
- domain: calm4y.lazywind.ru
- file: 114.55.34.71
- hash: 8443
- file: 213.165.42.46
- hash: 8080
- domain: st0rmx.stormling.ru
- file: 185.186.26.202
- hash: 1312
- domain: ling7o.stormling.ru
- domain: gust5y.stormling.ru
- domain: rumbl3.stormling.ru
- domain: clap9t.stormling.ru
- domain: glaci5.iceglow.ru
- domain: froz7y.iceglow.ru
- domain: icey4x.iceglow.ru
- url: https://commonloamprojects.com/k3ts3rhrrkh6rop0lltc44dr64xezms-m3qtzdli
- domain: lum3na.iceglow.ru
- url: http://8.130.89.132:8888/supershell/login/
- url: http://47.105.117.209:8888/supershell/login/
- domain: halo9r.iceglow.ru
- domain: leaf7y.leafbyte.ru
- domain: byt3rx.leafbyte.ru
- domain: spr1gg.leafbyte.ru
- domain: bud4le.leafbyte.ru
- domain: twig9x.leafbyte.ru
- domain: rain7x.rainbyte.ru
- domain: drop5y.rainbyte.ru
- domain: cl0udy.rainbyte.ru
- domain: patt3r.rainbyte.ru
- domain: splo8s.rainbyte.ru
- url: https://thu.itermed.ar/
- url: https://thu.thesmarthustle.info/
- domain: thu.itermed.ar
- domain: thu.thesmarthustle.info
- file: 5.75.216.89
- hash: 443
- domain: snow7y.snowroot.ru
- domain: root4x.snowroot.ru
- domain: sl3etx.snowroot.ru
- domain: thaw9r.snowroot.ru
- file: 46.62.225.51
- hash: 8008
- file: 46.62.205.38
- hash: 8008
- domain: firn5a.snowroot.ru
- domain: r767b.stormmint.ru
- domain: 9t.stormmint.ru
- file: 119.29.183.182
- hash: 80
- file: 107.173.180.173
- hash: 2052
- file: 103.12.148.42
- hash: 443
- file: 139.162.137.67
- hash: 443
- file: 72.61.194.81
- hash: 7443
- file: 81.68.238.97
- hash: 4433
- file: 134.33.194.214
- hash: 8443
- file: 94.237.59.231
- hash: 9999
- domain: 137f.stormmint.ru
- file: 72.61.141.82
- hash: 1337
- domain: n2ag.stormmint.ru
- domain: ds.c0deroot.ru
- domain: 58k2.c0deroot.ru
- domain: fy.c0deroot.ru
- domain: spark2.c0deroot.ru
- domain: q8s9.fl0wstone.ru
- domain: rise.fl0wstone.ru
- domain: 87kd.fl0wstone.ru
- domain: fst.fl0wstone.ru
- domain: 0g7o3.redm0on.ru
- domain: pulse1.redm0on.ru
- domain: t7q2.redm0on.ru
- domain: fkl7.redm0on.ru
- domain: os2rz.br1ghtwave.ru
- domain: data.br1ghtwave.ru
- domain: q54.br1ghtwave.ru
- domain: bcts.br1ghtwave.ru
- domain: copyright-cnn.gl.at.ply.gg
- domain: tiw6q.cioudriver.ru
- url: http://45.149.154.97
- domain: w4.cioudriver.ru
- domain: fut.cioudriver.ru
- file: 185.254.96.150
- hash: 4123
- domain: f15yw.cioudriver.ru
- domain: qyvu.cl1ffwood.ru
- domain: bright6.cl1ffwood.ru
- domain: bright.cl1ffwood.ru
- file: 111.119.203.52
- hash: 443
- file: 188.130.207.22
- hash: 8443
- file: 188.166.156.56
- hash: 443
- file: 190.225.32.131
- hash: 443
- file: 216.126.237.61
- hash: 7443
- file: 47.103.143.60
- hash: 60000
- file: 69.5.189.243
- hash: 2374
- file: 89.110.77.192
- hash: 443
- domain: wq.cl1ffwood.ru
- domain: a2.snowr1se.ru
- domain: lake.snowr1se.ru
- domain: 52i.snowr1se.ru
- domain: echo9.snowr1se.ru
- domain: spark8.stonem1nt.ru
- domain: note7.stonem1nt.ru
- file: 154.219.104.36
- hash: 80
- file: 39.105.136.189
- hash: 80
- file: 103.12.148.33
- hash: 443
- file: 91.92.241.247
- hash: 443
- file: 3.39.253.174
- hash: 8888
- file: 158.94.210.136
- hash: 443
- file: 5.182.211.16
- hash: 8080
- file: 167.71.255.8
- hash: 8808
- file: 162.243.28.13
- hash: 8088
- file: 52.77.62.221
- hash: 22
- domain: www.microsofrtonline.com
- domain: tmsawards.testingweblink.com
- domain: smartlegal.testingweblink.com
- file: 188.130.207.22
- hash: 443
- file: 172.105.183.234
- hash: 443
- file: 171.232.1.88
- hash: 9999
- file: 95.111.204.23
- hash: 26477
- file: 23.227.202.163
- hash: 8000
- file: 86.125.227.77
- hash: 80
- file: 107.189.17.247
- hash: 1080
- file: 160.178.223.144
- hash: 2222
- file: 106.13.86.178
- hash: 8080
- file: 193.242.184.136
- hash: 80
- domain: p81s.stonem1nt.ru
- domain: gty6.stonem1nt.ru
- domain: spark7.mistlake.ru
- domain: lake5.mistlake.ru
- domain: red9.mistlake.ru
- domain: pz8ux.mistlake.ru
- domain: z1w.st0y70renka.ru
- domain: bright7.st0y70renka.ru
- domain: 0a5f.st0y70renka.ru
- domain: frost7.st0y70renka.ru
- domain: p5.manual1sa1yz.ru
- domain: 4u29.manual1sa1yz.ru
- domain: oxiw.manual1sa1yz.ru
- domain: wzs.manual1sa1yz.ru
- domain: ugmbe.a-5-t-1-gstudy.ru
- domain: wood.a-5-t-1-gstudy.ru
- domain: ei.a-5-t-1-gstudy.ru
- domain: 5r.a-5-t-1-gstudy.ru
- domain: 8lwyc.dunn-0-en-7-el.ru
- domain: tvaz.dunn-0-en-7-el.ru
- domain: 2ql.dunn-0-en-7-el.ru
- domain: 2fq4.dunn-0-en-7-el.ru
- domain: 53.ede-1-g-0-rge.ru
- domain: b2.ede-1-g-0-rge.ru
- domain: td.ede-1-g-0-rge.ru
- domain: dperw.ede-1-g-0-rge.ru
- domain: 7ol4i.a5t1gstudy.ru
- domain: lake2.a5t1gstudy.ru
- domain: storm.a5t1gstudy.ru
- domain: red7.a5t1gstudy.ru
- domain: root7.ju-4-en-pare-1.ru
- domain: dk2fp.ju-4-en-pare-1.ru
ThreatFox IOCs for 2025-11-27
Description
ThreatFox IOCs for 2025-11-27
AI-Powered Analysis
Technical Analysis
The entry titled 'ThreatFox IOCs for 2025-11-27' is a report from the ThreatFox MISP feed, focusing on OSINT-derived Indicators of Compromise related to malware and network activity associated with payload delivery. The report does not specify particular malware families, affected software versions, or detailed attack vectors. It is primarily a collection of threat intelligence data intended to support detection and investigation efforts. The threat level is medium, with no known exploits currently active in the wild and no patches available, indicating that this is not a newly discovered vulnerability but rather intelligence on existing or potential threats. The technical details include a threat level rating of 2 and distribution rating of 3, suggesting moderate prevalence or dissemination of the associated IOCs. The absence of CWEs and exploit details implies that this is not a direct vulnerability but a set of indicators to aid in identifying malicious activity. The information is tagged as TLP:WHITE, meaning it is intended for wide distribution and sharing. This type of intelligence is valuable for security teams to improve situational awareness and enhance network monitoring and incident response capabilities. However, without specific actionable exploit or vulnerability data, it does not represent an immediate or direct threat to systems.
Potential Impact
For European organizations, the impact of this threat intelligence is primarily in the realm of improved detection and response rather than direct compromise. The availability of these IOCs can help security teams identify malicious network activity or payload delivery attempts that align with the reported indicators. This can reduce dwell time of attackers and limit potential damage from malware infections. However, since no specific vulnerabilities or exploits are detailed, there is no immediate risk of exploitation or system compromise. The medium severity rating suggests that while the threat intelligence is useful, it does not indicate a critical or widespread active threat. Organizations with mature security operations centers (SOCs) and threat intelligence capabilities will benefit most by integrating these IOCs into their monitoring tools. Conversely, organizations lacking such capabilities may find limited immediate benefit. The lack of patches or exploit activity means no urgent remediation is required, but vigilance in monitoring is advised. Overall, the impact is moderate and focused on enhancing defensive posture rather than responding to an active attack.
Mitigation Recommendations
To effectively leverage this threat intelligence, European organizations should integrate the provided IOCs into their security information and event management (SIEM) systems, intrusion detection/prevention systems (IDS/IPS), and endpoint detection and response (EDR) tools. Regularly updating threat intelligence feeds and correlating these IOCs with internal logs can improve detection of suspicious network activity and payload delivery attempts. Security teams should conduct threat hunting exercises using these indicators to proactively identify potential compromises. Additionally, organizations should ensure robust network segmentation and implement strict access controls to limit the impact of any detected malware activity. Employee awareness training on phishing and social engineering remains important, as payload delivery often exploits human factors. Since no patches are available, maintaining up-to-date software and applying security best practices reduces the attack surface. Collaboration with national and European cybersecurity agencies can enhance situational awareness and response coordination. Finally, documenting and sharing any findings related to these IOCs within trusted communities can improve collective defense.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- 2c81e393-628f-4869-a7b4-23ea4d0c07a3
- Original Timestamp
- 1764288186
Indicators of Compromise
Url
| Value | Description | Copy |
|---|---|---|
urlhttp://47.236.194.231:8888/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttp://185.163.204.237/google.json | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://cryptoinfa.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://dmmediacamp.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://trd.vn/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://mail.perthspeechpathology.com.au/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttp://45.144.53.58/949ea21567eb4db7.php | Stealc botnet C2 (confidence level: 100%) | |
urlhttps://ggh5e4h54.cc | Stealc botnet C2 (confidence level: 100%) | |
urlhttps://seiho-ippankatei.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://yolwkl.org/captcha.html | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://cryptoportalhub.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://99sbobet.net | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://aimania2024.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://ami-thai.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://arnaelevators.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://118.107.21.101:8888/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://gotokenta.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://homeexplore.novacrm.ca | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://lorriedeenacaplan.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://padelsportacademy.app | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://sparklehomecleaningcompany.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://nutritionadvicehub.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://ridethecape.co.za | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://www.mmoo.vet | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://nithani.co.uk | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://194.87.55.59/dxx.odd | Unknown malware payload delivery URL (confidence level: 50%) | |
urlhttps://thewrightgiftstore.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://training-uat.rapidascent.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://baby-mine0821.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://keyframe.com.co | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://myfandollars.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://nisourcetech.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://peppersghost.org | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://23wincom.agency | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://africanalphacc.com | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://uniquedreambuilders.in/wps/index.html | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://pec.itermed.ar/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://pec.thesmarthustle.info/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://116.203.11.101/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://49.13.217.28/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://49.13.39.130/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://91.244.71.62/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://49.13.38.235/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://www.peppersghost.org/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://mmoo.vet/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://fdlkewebsite.icu | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttps://alpeoqa.cyou/api | Lumma Stealer botnet C2 (confidence level: 75%) | |
urlhttps://bop.itermed.ar/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://bop.thesmarthustle.info/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttp://85.121.148.35 | Stealc botnet C2 (confidence level: 100%) | |
urlhttps://commonloamprojects.com/k3ts3rhrrkh6rop0lltc44dr64xezms-m3qtzdli | FAKEUPDATES payload delivery URL (confidence level: 100%) | |
urlhttp://8.130.89.132:8888/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttp://47.105.117.209:8888/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://thu.itermed.ar/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://thu.thesmarthustle.info/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttp://45.149.154.97 | Stealc botnet C2 (confidence level: 100%) |
File
| Value | Description | Copy |
|---|---|---|
file47.236.194.231 | Unknown malware botnet C2 server (confidence level: 100%) | |
file104.168.142.88 | STRRAT botnet C2 server (confidence level: 100%) | |
file158.94.210.133 | Latrodectus botnet C2 server (confidence level: 100%) | |
file91.214.78.123 | Remcos botnet C2 server (confidence level: 100%) | |
file139.59.141.55 | Unknown malware botnet C2 server (confidence level: 100%) | |
file78.47.226.37 | Hook botnet C2 server (confidence level: 100%) | |
file197.44.116.226 | Unknown malware botnet C2 server (confidence level: 100%) | |
file104.198.157.155 | Meterpreter botnet C2 server (confidence level: 100%) | |
file43.155.252.158 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file137.220.194.49 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file46.247.108.140 | Remcos botnet C2 server (confidence level: 100%) | |
file47.110.66.48 | Sliver botnet C2 server (confidence level: 100%) | |
file80.78.25.70 | Sliver botnet C2 server (confidence level: 100%) | |
file162.243.28.13 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file144.124.246.133 | SectopRAT botnet C2 server (confidence level: 100%) | |
file91.84.125.113 | SectopRAT botnet C2 server (confidence level: 100%) | |
file3.222.9.169 | Unknown malware botnet C2 server (confidence level: 100%) | |
file171.232.1.88 | Venom RAT botnet C2 server (confidence level: 100%) | |
file171.232.1.88 | Venom RAT botnet C2 server (confidence level: 100%) | |
file171.232.1.88 | Venom RAT botnet C2 server (confidence level: 100%) | |
file168.245.201.145 | Meterpreter botnet C2 server (confidence level: 100%) | |
file168.245.201.158 | Meterpreter botnet C2 server (confidence level: 100%) | |
file168.245.201.153 | Meterpreter botnet C2 server (confidence level: 100%) | |
file168.245.201.136 | Meterpreter botnet C2 server (confidence level: 100%) | |
file168.245.201.142 | Meterpreter botnet C2 server (confidence level: 100%) | |
file89.110.93.218 | BianLian botnet C2 server (confidence level: 100%) | |
file64.95.13.26 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file180.76.174.250 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file111.228.40.26 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file130.49.176.86 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file206.189.0.80 | Mirai botnet C2 server (confidence level: 75%) | |
file45.61.161.169 | AsyncRAT botnet C2 server (confidence level: 50%) | |
file45.61.161.169 | AsyncRAT botnet C2 server (confidence level: 50%) | |
file45.61.161.169 | AsyncRAT botnet C2 server (confidence level: 50%) | |
file172.94.15.100 | Remcos botnet C2 server (confidence level: 50%) | |
file78.46.214.104 | Vidar botnet C2 server (confidence level: 100%) | |
file116.203.11.101 | Vidar botnet C2 server (confidence level: 100%) | |
file49.13.217.28 | Vidar botnet C2 server (confidence level: 100%) | |
file49.13.39.130 | Vidar botnet C2 server (confidence level: 100%) | |
file91.244.71.62 | Vidar botnet C2 server (confidence level: 100%) | |
file49.13.38.235 | Vidar botnet C2 server (confidence level: 100%) | |
file38.47.239.72 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file43.159.53.42 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file157.20.182.28 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file172.94.92.38 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file41.251.41.218 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file197.44.116.226 | Unknown malware botnet C2 server (confidence level: 100%) | |
file110.40.186.230 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file69.5.189.149 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file196.75.72.57 | Meterpreter botnet C2 server (confidence level: 100%) | |
file218.255.179.148 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file31.7.77.230 | Eye Pyramid botnet C2 server (confidence level: 75%) | |
file41.216.189.185 | Mirai botnet C2 server (confidence level: 75%) | |
file198.23.196.130 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file188.166.185.215 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file191.96.207.153 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file157.250.206.75 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file47.243.77.121 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file2.57.19.230 | Venom RAT botnet C2 server (confidence level: 100%) | |
file196.251.100.51 | BlackNET RAT botnet C2 server (confidence level: 100%) | |
file196.251.100.51 | BlackNET RAT botnet C2 server (confidence level: 100%) | |
file8.210.253.131 | Unknown malware botnet C2 server (confidence level: 100%) | |
file213.200.185.124 | Unknown malware botnet C2 server (confidence level: 100%) | |
file119.91.55.16 | Unknown malware botnet C2 server (confidence level: 100%) | |
file173.249.42.51 | Unknown malware botnet C2 server (confidence level: 100%) | |
file47.102.197.153 | Unknown malware botnet C2 server (confidence level: 100%) | |
file69.169.108.238 | Unknown malware botnet C2 server (confidence level: 100%) | |
file124.156.205.244 | Unknown malware botnet C2 server (confidence level: 100%) | |
file98.91.214.147 | Unknown malware botnet C2 server (confidence level: 100%) | |
file62.84.190.38 | Unknown malware botnet C2 server (confidence level: 100%) | |
file35.201.254.128 | Unknown malware botnet C2 server (confidence level: 100%) | |
file151.243.218.164 | XWorm botnet C2 server (confidence level: 100%) | |
file172.111.137.164 | Remcos botnet C2 server (confidence level: 100%) | |
file209.54.101.170 | Remcos botnet C2 server (confidence level: 100%) | |
file95.164.5.245 | Sliver botnet C2 server (confidence level: 100%) | |
file124.158.5.149 | Sliver botnet C2 server (confidence level: 100%) | |
file111.119.203.52 | Sliver botnet C2 server (confidence level: 100%) | |
file45.151.142.251 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file2.56.214.177 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file114.55.34.71 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file213.165.42.46 | Meterpreter botnet C2 server (confidence level: 75%) | |
file185.186.26.202 | Mirai botnet C2 server (confidence level: 100%) | |
file5.75.216.89 | Vidar botnet C2 server (confidence level: 100%) | |
file46.62.225.51 | Unknown malware botnet C2 server (confidence level: 75%) | |
file46.62.205.38 | Unknown malware botnet C2 server (confidence level: 75%) | |
file119.29.183.182 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file107.173.180.173 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file103.12.148.42 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file139.162.137.67 | Sliver botnet C2 server (confidence level: 100%) | |
file72.61.194.81 | Unknown malware botnet C2 server (confidence level: 100%) | |
file81.68.238.97 | Havoc botnet C2 server (confidence level: 100%) | |
file134.33.194.214 | Unknown malware botnet C2 server (confidence level: 100%) | |
file94.237.59.231 | MimiKatz botnet C2 server (confidence level: 100%) | |
file72.61.141.82 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file185.254.96.150 | Mirai botnet C2 server (confidence level: 100%) | |
file111.119.203.52 | Sliver botnet C2 server (confidence level: 75%) | |
file188.130.207.22 | Havoc botnet C2 server (confidence level: 75%) | |
file188.166.156.56 | Havoc botnet C2 server (confidence level: 75%) | |
file190.225.32.131 | QakBot botnet C2 server (confidence level: 75%) | |
file216.126.237.61 | Unknown malware botnet C2 server (confidence level: 75%) | |
file47.103.143.60 | Unknown malware botnet C2 server (confidence level: 75%) | |
file69.5.189.243 | AdaptixC2 botnet C2 server (confidence level: 75%) | |
file89.110.77.192 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file154.219.104.36 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file39.105.136.189 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file103.12.148.33 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file91.92.241.247 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file3.39.253.174 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file158.94.210.136 | Latrodectus botnet C2 server (confidence level: 100%) | |
file5.182.211.16 | Unknown malware botnet C2 server (confidence level: 100%) | |
file167.71.255.8 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file162.243.28.13 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file52.77.62.221 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file188.130.207.22 | Havoc botnet C2 server (confidence level: 100%) | |
file172.105.183.234 | Havoc botnet C2 server (confidence level: 100%) | |
file171.232.1.88 | Venom RAT botnet C2 server (confidence level: 100%) | |
file95.111.204.23 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file23.227.202.163 | MimiKatz botnet C2 server (confidence level: 100%) | |
file86.125.227.77 | MimiKatz botnet C2 server (confidence level: 100%) | |
file107.189.17.247 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file160.178.223.144 | Meterpreter botnet C2 server (confidence level: 100%) | |
file106.13.86.178 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file193.242.184.136 | Empire Downloader botnet C2 server (confidence level: 100%) |
Hash
| Value | Description | Copy |
|---|---|---|
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash5050 | STRRAT botnet C2 server (confidence level: 100%) | |
hash443 | Latrodectus botnet C2 server (confidence level: 100%) | |
hash443 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8082 | Hook botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash4444 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash8443 | Sliver botnet C2 server (confidence level: 100%) | |
hash8444 | Sliver botnet C2 server (confidence level: 100%) | |
hash8000 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash5000 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash5001 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash6000 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash8443 | BianLian botnet C2 server (confidence level: 100%) | |
hashf68872773a88652541bd8d6ca9bda058 | WORMHOLE payload (confidence level: 50%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash9090 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash85 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash39691 | Mirai botnet C2 server (confidence level: 75%) | |
hash6606 | AsyncRAT botnet C2 server (confidence level: 50%) | |
hash7707 | AsyncRAT botnet C2 server (confidence level: 50%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 50%) | |
hash6075 | Remcos botnet C2 server (confidence level: 50%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash9992 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash1000 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash443 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash12564 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash5985 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash2222 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash47156 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash18080 | Eye Pyramid botnet C2 server (confidence level: 75%) | |
hash12121 | Mirai botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash7008 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash48396 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash4449 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash80 | BlackNET RAT botnet C2 server (confidence level: 100%) | |
hash443 | BlackNET RAT botnet C2 server (confidence level: 100%) | |
hash60000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash7777 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8080 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash7007 | XWorm botnet C2 server (confidence level: 100%) | |
hash3384 | Remcos botnet C2 server (confidence level: 100%) | |
hash8085 | Remcos botnet C2 server (confidence level: 100%) | |
hash31337 | Sliver botnet C2 server (confidence level: 100%) | |
hash8443 | Sliver botnet C2 server (confidence level: 100%) | |
hash8080 | Sliver botnet C2 server (confidence level: 100%) | |
hash2222 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash1080 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash8443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash8080 | Meterpreter botnet C2 server (confidence level: 75%) | |
hash1312 | Mirai botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash8008 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash8008 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2052 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash4433 | Havoc botnet C2 server (confidence level: 100%) | |
hash8443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash9999 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash1337 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash4123 | Mirai botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 75%) | |
hash8443 | Havoc botnet C2 server (confidence level: 75%) | |
hash443 | Havoc botnet C2 server (confidence level: 75%) | |
hash443 | QakBot botnet C2 server (confidence level: 75%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash60000 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash2374 | AdaptixC2 botnet C2 server (confidence level: 75%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Latrodectus botnet C2 server (confidence level: 100%) | |
hash8080 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8088 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash22 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash9999 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash26477 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash8000 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash80 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash1080 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash2222 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Empire Downloader botnet C2 server (confidence level: 100%) |
Domain
| Value | Description | Copy |
|---|---|---|
domaincontrol.myaffiliateincome.com | FAKEUPDATES botnet C2 domain (confidence level: 100%) | |
domaincryptoinfa.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainbraun5.copperweide8.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainyoxel2.copperweide8.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrava7n.ravenstein.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineis3en.ravenstein.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkorvo5.ravenstein.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsteyn4.ravenstein.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnoxil7.ravenstein.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmapl3e.maplekueste.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfjord6.maplekueste.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkuest5.maplekueste.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainahorn7.maplekueste.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbryz4a.maplekueste.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingl1mra.glimmerkranz.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkran7z.glimmerkranz.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfunke5.glimmerkranz.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainscher4.glimmerkranz.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbl3nda.glimmerkranz.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsilb3r.silberquarz4.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain1310445127-bo78zajqf2.ap-shanghai.tencentscf.com | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainstatic-mtpjoriqkv.cn-beijing.fcapp.run | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainwww.beihu-jlbank.com | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainqartz7.silberquarz4.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglanz5.silberquarz4.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrauch4.silberquarz4.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainberyl6.silberquarz4.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwill7o.willowgase.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingas3en.willowgase.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnebl4e.willowgase.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhaust5.willowgase.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzerfa2.willowgase.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnebe7l.nebeltal.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintau3ig.nebeltal.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingrau5e.nebeltal.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintalon4.nebeltal.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfluss8.nebeltal.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspruc5.sprucewinkel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwink3l.sprucewinkel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainharz7a.sprucewinkel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainficht4.sprucewinkel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainschne8.sprucewinkel.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainonyx5a.onyxquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrun4n.onyxquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainquel7e.onyxquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsourc3.onyxquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingrot8o.onyxquelle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainember5.emberklamm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkalm3m.emberklamm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainschlu7.emberklamm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainflar4e.emberklamm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrand8.emberklamm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainborass.ddns.net | XWorm botnet C2 domain (confidence level: 100%) | |
domainuzlehalo134.duckdns.org | XWorm botnet C2 domain (confidence level: 100%) | |
domainvex7in.st0rmshade.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbuyaofengwoa.com | ValleyRAT botnet C2 domain (confidence level: 100%) | |
domainstrm9a.st0rmshade.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsilverpath.shadowstresser.info | Mirai botnet C2 domain (confidence level: 100%) | |
domainhalox5.st0rmshade.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainyolwkl.org | Unknown malware payload delivery domain (confidence level: 100%) | |
domaindriff7.st0rmshade.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainslursbeback.ru | Mirai botnet C2 domain (confidence level: 100%) | |
domainnubil3.st0rmshade.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincrys7a.crystalv1be.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincryptoportalhub.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domain99sbobet.net | Unknown malware payload delivery domain (confidence level: 100%) | |
domainaimania2024.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainami-thai.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainaceawarewales.com | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domaingatex.aceawarewales.com | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domaingatex.www.50thirdand3rd.com | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainkitchen-bet.gl.at.ply.gg | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainwww.canwoodgallery.com | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainwww.fondazionesabattini.it | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainvib3ro.crystalv1be.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainarnaelevators.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainv2.aceawarewales.com | DCRat botnet C2 domain (confidence level: 50%) | |
domainv2.homoclimbtastic.com | DCRat botnet C2 domain (confidence level: 50%) | |
domainv2.socolive6.ac | DCRat botnet C2 domain (confidence level: 50%) | |
domainv2.www.50thirdand3rd.com | DCRat botnet C2 domain (confidence level: 50%) | |
domainv2.www.allaboutbasketball.us | DCRat botnet C2 domain (confidence level: 50%) | |
domainv2.www.istas22.org | DCRat botnet C2 domain (confidence level: 50%) | |
domainv2.www.outsideprague.com | DCRat botnet C2 domain (confidence level: 50%) | |
domainv3.aceawarewales.com | DCRat botnet C2 domain (confidence level: 50%) | |
domainv3.homoclimbtastic.com | DCRat botnet C2 domain (confidence level: 50%) | |
domainv3.socolive6.ac | DCRat botnet C2 domain (confidence level: 50%) | |
domainv3.www.50thirdand3rd.com | DCRat botnet C2 domain (confidence level: 50%) | |
domainv3.www.allaboutbasketball.us | DCRat botnet C2 domain (confidence level: 50%) | |
domainv3.www.istas22.org | DCRat botnet C2 domain (confidence level: 50%) | |
domainv3.www.outsideprague.com | DCRat botnet C2 domain (confidence level: 50%) | |
domainscience-tight.gl.at.ply.gg | NjRAT botnet C2 domain (confidence level: 50%) | |
domaindoes-58376.portmap.host | XWorm botnet C2 domain (confidence level: 50%) | |
domainmost-inbox.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 50%) | |
domainbongoshare.bishtelecom.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domaingotokenta.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainhomeexplore.novacrm.ca | Unknown malware payload delivery domain (confidence level: 100%) | |
domainlorriedeenacaplan.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainpadelsportacademy.app | Unknown malware payload delivery domain (confidence level: 100%) | |
domainsparklehomecleaningcompany.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainlumyx6.crystalv1be.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnutritionadvicehub.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainridethecape.co.za | Unknown malware payload delivery domain (confidence level: 100%) | |
domainmmoo.vet | Unknown malware payload delivery domain (confidence level: 100%) | |
domainglint5.crystalv1be.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnithani.co.uk | Unknown malware payload delivery domain (confidence level: 100%) | |
domainthewrightgiftstore.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domaintraining-uat.rapidascent.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainfrakt8.crystalv1be.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbaby-mine0821.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainkeyframe.com.co | Unknown malware payload delivery domain (confidence level: 100%) | |
domainmyfandollars.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainnisourcetech.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainpeppersghost.org | Unknown malware payload delivery domain (confidence level: 100%) | |
domaingale7x.windstack.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain23wincom.agency | Unknown malware payload delivery domain (confidence level: 100%) | |
domainafricanalphacc.com | Unknown malware payload delivery domain (confidence level: 100%) | |
domainvindex5.windstack.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainaeri4s.windstack.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsquall6.windstack.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpec.itermed.ar | Vidar botnet C2 domain (confidence level: 100%) | |
domainpec.thesmarthustle.info | Vidar botnet C2 domain (confidence level: 100%) | |
domainw1ndo.windstack.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainst0ne.stoneburst.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfdlkewebsite.icu | Unknown malware payload delivery domain (confidence level: 100%) | |
domainbrecc8.stoneburst.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshard7.stoneburst.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrumbl5.stoneburst.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainquak3r.stoneburst.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainslush5.sn0wtrail.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsn0wy7.sn0wtrail.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintrac3r.sn0wtrail.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainflurr6.sn0wtrail.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainskid9x.sn0wtrail.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainazure5.bluem1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmist7y.bluem1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincyan9x.bluem1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbleue4.bluem1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfoggy6.bluem1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainriv3t.r1verdrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindropl7.r1verdrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincreek5.r1verdrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsplash8.r1verdrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindelta6.r1verdrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsofte5.soft0cean.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintid4l.soft0cean.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwave7x.soft0cean.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsurf9a.soft0cean.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmar3na.soft0cean.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainclov3r.cl0vermint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainminty7.cl0vermint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainherb6x.cl0vermint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbop.itermed.ar | Vidar botnet C2 domain (confidence level: 100%) | |
domainbop.thesmarthustle.info | Vidar botnet C2 domain (confidence level: 100%) | |
domainshamr4.cl0vermint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfr3sha.cl0vermint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainherb5x.mintpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmnt3ak.mintpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzefyr7.mintpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainclov8r.mintpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindew4ly.mintpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfr0stx.frostdrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindrip7y.frostdrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainicell3.frostdrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshivr5.frostdrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainflak8e.frostdrop.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindu5tly.dustpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpeak7r.dustpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsilt9x.dustpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhaz3lo.dustpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmote5r.dustpeak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainflash7.fastspark.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsp4rkx.fastspark.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainb1.yydscd1.top | ValleyRAT botnet C2 domain (confidence level: 100%) | |
domainb1.yydscd3.top | ValleyRAT botnet C2 domain (confidence level: 100%) | |
domainqu1ckr.fastspark.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbolt9a.fastspark.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainracy5n.fastspark.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindoz3er.lazywind.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlaz7ee.lazywind.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbreez5.lazywind.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainyawn9x.lazywind.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincalm4y.lazywind.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainst0rmx.stormling.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainling7o.stormling.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingust5y.stormling.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrumbl3.stormling.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainclap9t.stormling.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglaci5.iceglow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfroz7y.iceglow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainicey4x.iceglow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlum3na.iceglow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhalo9r.iceglow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainleaf7y.leafbyte.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbyt3rx.leafbyte.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspr1gg.leafbyte.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbud4le.leafbyte.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintwig9x.leafbyte.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrain7x.rainbyte.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindrop5y.rainbyte.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincl0udy.rainbyte.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpatt3r.rainbyte.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsplo8s.rainbyte.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainthu.itermed.ar | Vidar botnet C2 domain (confidence level: 100%) | |
domainthu.thesmarthustle.info | Vidar botnet C2 domain (confidence level: 100%) | |
domainsnow7y.snowroot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainroot4x.snowroot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsl3etx.snowroot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainthaw9r.snowroot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfirn5a.snowroot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainr767b.stormmint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain9t.stormmint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain137f.stormmint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainn2ag.stormmint.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainds.c0deroot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain58k2.c0deroot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfy.c0deroot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspark2.c0deroot.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainq8s9.fl0wstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrise.fl0wstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain87kd.fl0wstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfst.fl0wstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain0g7o3.redm0on.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpulse1.redm0on.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaint7q2.redm0on.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfkl7.redm0on.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainos2rz.br1ghtwave.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindata.br1ghtwave.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainq54.br1ghtwave.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbcts.br1ghtwave.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincopyright-cnn.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domaintiw6q.cioudriver.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainw4.cioudriver.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfut.cioudriver.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainf15yw.cioudriver.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqyvu.cl1ffwood.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbright6.cl1ffwood.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbright.cl1ffwood.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwq.cl1ffwood.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaina2.snowr1se.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlake.snowr1se.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain52i.snowr1se.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainecho9.snowr1se.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspark8.stonem1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnote7.stonem1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwww.microsofrtonline.com | Havoc botnet C2 domain (confidence level: 100%) | |
domaintmsawards.testingweblink.com | Havoc botnet C2 domain (confidence level: 100%) | |
domainsmartlegal.testingweblink.com | Havoc botnet C2 domain (confidence level: 100%) | |
domainp81s.stonem1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingty6.stonem1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspark7.mistlake.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlake5.mistlake.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainred9.mistlake.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpz8ux.mistlake.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainz1w.st0y70renka.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbright7.st0y70renka.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain0a5f.st0y70renka.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfrost7.st0y70renka.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainp5.manual1sa1yz.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain4u29.manual1sa1yz.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainoxiw.manual1sa1yz.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwzs.manual1sa1yz.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainugmbe.a-5-t-1-gstudy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwood.a-5-t-1-gstudy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainei.a-5-t-1-gstudy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain5r.a-5-t-1-gstudy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain8lwyc.dunn-0-en-7-el.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintvaz.dunn-0-en-7-el.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain2ql.dunn-0-en-7-el.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain2fq4.dunn-0-en-7-el.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain53.ede-1-g-0-rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainb2.ede-1-g-0-rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintd.ede-1-g-0-rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindperw.ede-1-g-0-rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7ol4i.a5t1gstudy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlake2.a5t1gstudy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstorm.a5t1gstudy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainred7.a5t1gstudy.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainroot7.ju-4-en-pare-1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindk2fp.ju-4-en-pare-1.ru | ClearFake payload delivery domain (confidence level: 100%) |
Threat ID: 6928e9f7ce4290e3e3801337
Added to database: 11/28/2025, 12:16:55 AM
Last enriched: 11/28/2025, 12:32:12 AM
Last updated: 12/1/2025, 11:12:19 PM
Views: 29
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
New Albiriox Android Malware Developed by Russian Cybercriminals
MediumWebinar: The "Agentic" Trojan Horse: Why the New AI Browsers War is a Nightmare for Security Teams
MediumNew Albiriox MaaS Malware Targets 400+ Apps for On-Device Fraud and Screen Control
MediumThreatFox IOCs for 2025-11-30
MediumThreatFox IOCs for 2025-11-29
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.