ThreatFox IOCs for 2025-12-02
ThreatFox IOCs for 2025-12-02
AI Analysis
Technical Summary
The data describes a set of Indicators of Compromise (IOCs) from ThreatFox, a MISP feed source, dated December 2, 2025. The threat is classified as malware with emphasis on OSINT (Open Source Intelligence), payload delivery, and network activity categories. No specific affected software versions or products are listed, indicating this is a general intelligence feed rather than a vulnerability tied to a particular system. The absence of known exploits in the wild and lack of available patches suggest this is either emerging intelligence or a catalog of potential threats rather than an active exploit campaign. The technical details provide minimal insight, with a threat level of 2 (on an unspecified scale), analysis rating of 1, and distribution rating of 3, implying moderate dissemination but limited analysis depth. No concrete indicators such as IP addresses, hashes, or domains are included, which limits actionable detection capabilities. The medium severity rating aligns with the nature of the feed as a preparatory intelligence resource rather than an immediate threat. This type of threat intelligence is valuable for organizations to update detection rules, enhance situational awareness, and prepare defenses against potential malware payloads delivered via network vectors.
Potential Impact
For European organizations, the impact of this threat intelligence feed depends on how effectively it is integrated into security operations. If these IOCs correspond to emerging malware campaigns, failure to incorporate them into detection systems could result in delayed identification of payload delivery attempts or network intrusions. Potential impacts include unauthorized access, data exfiltration, or disruption of network services if malware payloads are successfully delivered. The lack of specific affected products or versions means the threat could be broad, affecting multiple sectors relying on network infrastructure and OSINT tools. Organizations with mature security monitoring and incident response capabilities can leverage this intelligence to reduce dwell time and mitigate attacks early. Conversely, entities lacking such capabilities may face increased risk of compromise. The medium severity suggests moderate risk, with potential confidentiality and availability impacts if exploited. The absence of known exploits in the wild currently limits immediate risk but does not preclude future escalation.
Mitigation Recommendations
1. Integrate ThreatFox IOCs into existing Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) systems to enhance detection capabilities. 2. Regularly update threat intelligence feeds and correlate with internal logs to identify suspicious network activity or payload delivery attempts. 3. Conduct network segmentation to limit lateral movement in case of malware infection. 4. Implement strict egress filtering and monitor outbound traffic for anomalies that may indicate data exfiltration. 5. Train security teams to analyze OSINT-based threat intelligence and adapt detection rules accordingly. 6. Perform regular threat hunting exercises using the latest IOCs to proactively identify potential compromises. 7. Maintain up-to-date backups and incident response plans to reduce impact in case of successful payload delivery. 8. Collaborate with national and European cybersecurity centers to share intelligence and receive timely alerts about emerging threats. 9. Employ multi-factor authentication and least privilege principles to reduce attack surface, even though this threat does not specify authentication requirements. 10. Monitor vendor advisories and update defenses promptly if new patches or mitigations become available.
Affected Countries
Germany, France, United Kingdom, Netherlands, Italy, Spain
Indicators of Compromise
- url: https://echo-pr.co.uk/
- file: 51.255.81.133
- hash: 2024
- file: 74.91.19.130
- hash: 2024
- file: 104.131.23.252
- hash: 39691
- domain: soft-dns.sejilod7488888.workers.dev
- domain: alexiac.cyou
- domain: ascetin.cyou
- domain: boflijo.cyou
- domain: entraiz.cyou
- domain: extirpo.cyou
- domain: leonhat.cyou
- domain: rotfqxu.cyou
- domain: truxaqn.cyou
- domain: simonts.cyou
- domain: souldey.cyou
- domain: townsex.cyou
- file: 119.29.112.57
- hash: 443
- file: 54.255.195.252
- hash: 22
- file: 109.230.231.29
- hash: 8888
- domain: crystal.cloudb1te.ru
- domain: g6vi.softgl1de.ru
- domain: 7qqa.softgl1de.ru
- domain: 92nr.softgl1de.ru
- domain: 19r6l.softgl1de.ru
- domain: gate.rivershad0w.ru
- domain: 5h.rivershad0w.ru
- domain: 7c.rivershad0w.ru
- domain: 8m.rivershad0w.ru
- domain: alpha.crystal0ak.ru
- domain: j1bn.crystal0ak.ru
- domain: trace.crystal0ak.ru
- domain: k9yn.crystal0ak.ru
- domain: soft.brightst0ne.ru
- domain: ydb7x.brightst0ne.ru
- domain: j8kd7.brightst0ne.ru
- domain: kd7u.mistyflare.ru
- domain: x40.mistyflare.ru
- domain: 368.mistyflare.ru
- file: 194.14.217.125
- hash: 443
- file: 194.14.217.125
- hash: 80
- file: 38.182.168.169
- hash: 80
- domain: forest.mistyflare.ru
- domain: 84m.stoneflare.ru
- domain: 6tal.stoneflare.ru
- domain: river.stoneflare.ru
- domain: jn.stoneflare.ru
- domain: pond.n1ghtbloom.ru
- domain: 6f.n1ghtbloom.ru
- file: 156.234.121.175
- hash: 6181
- file: 129.204.146.115
- hash: 8089
- file: 47.76.237.89
- hash: 8888
- file: 121.41.86.68
- hash: 60002
- file: 38.165.33.58
- hash: 80
- file: 8.137.171.139
- hash: 6666
- file: 158.94.208.145
- hash: 443
- file: 81.92.219.143
- hash: 443
- file: 172.193.170.213
- hash: 443
- file: 101.251.179.31
- hash: 8888
- file: 117.2.181.74
- hash: 8808
- file: 173.208.168.61
- hash: 8080
- file: 144.31.3.123
- hash: 9000
- file: 213.139.77.218
- hash: 9000
- file: 34.222.248.75
- hash: 7443
- file: 69.167.11.120
- hash: 443
- file: 84.154.176.63
- hash: 81
- domain: sbtua.n1ghtbloom.ru
- file: 196.75.32.180
- hash: 2222
- file: 103.177.47.214
- hash: 3790
- file: 119.53.187.40
- hash: 10001
- file: 144.2.114.83
- hash: 444
- file: 193.242.184.136
- hash: 1337
- domain: uw.n1ghtbloom.ru
- domain: flare.wildm1st.ru
- domain: mzu8.wildm1st.ru
- url: http://www.tsq-hk.com/rollers/rokow3/fre.php
- domain: p7l0.wildm1st.ru
- domain: a6u.wildm1st.ru
- domain: hl.w1ndcrest.ru
- domain: vnq.w1ndcrest.ru
- domain: h3m.w1ndcrest.ru
- url: http://77.221.154.164/unamwebpanel/unamwebpanel/pages/login.php
- domain: coast.w1ndcrest.ru
- domain: 00f.deepflash.ru
- domain: shadow.deepflash.ru
- domain: llbf.deepflash.ru
- domain: sf.deepflash.ru
- domain: needs-developed.gl.at.ply.gg
- domain: envio2777.mysynology.net
- domain: jun-suppliers.gl.at.ply.gg
- url: http://167.88.165.253
- domain: 5adm.windsh1ne.ru
- domain: 1qc.windsh1ne.ru
- domain: gold.windsh1ne.ru
- file: 193.111.78.83
- hash: 1604
- domain: xnaw.windsh1ne.ru
- domain: spark.silenth1ll.ru
- domain: 31x.silenth1ll.ru
- domain: e7.silenth1ll.ru
- url: http://23.132.228.234/panel.html
- url: https://butege075.xyz/
- domain: quick.silenth1ll.ru
- domain: bz.forestgl0w.ru
- domain: dl9e.forestgl0w.ru
- file: 87.121.84.117
- hash: 9772
- file: 213.209.143.33
- hash: 54128
- domain: efjgerws.galaxias.cc
- domain: night.forestgl0w.ru
- domain: light.forestgl0w.ru
- domain: silver.nightm1nt.ru
- domain: 3h2p.nightm1nt.ru
- domain: to-appreciation.gl.at.ply.gg
- domain: tovool123343123-42020.portmap.host
- domain: stone.nightm1nt.ru
- file: 108.165.154.164
- hash: 1122
- domain: work.nightm1nt.ru
- domain: public.dvrexpert.st
- file: 213.209.143.34
- hash: 9931
- domain: s1603.house-spirit.com
- domain: s1619.house-spirit.com
- domain: s1270.house-spirit.com
- domain: s1256.house-spirit.com
- domain: s1533.house-spirit.com
- domain: s1276.house-spirit.com
- domain: s1252.house-spirit.com
- domain: s1264.house-spirit.com
- domain: s1535.house-spirit.com
- domain: s1266.house-spirit.com
- domain: s1244.house-spirit.com
- domain: s1531.house-spirit.com
- domain: s1262.house-spirit.com
- domain: s1254.house-spirit.com
- domain: s1272.house-spirit.com
- domain: s1246.house-spirit.com
- domain: s1248.house-spirit.com
- domain: s1258.house-spirit.com
- domain: s1274.house-spirit.com
- domain: s1268.house-spirit.com
- domain: s1613.house-spirit.com
- domain: s1621.house-spirit.com
- domain: s1617.house-spirit.com
- domain: s1609.house-spirit.com
- domain: crest.f1recrest.ru
- url: https://serv-in.fr/
- file: 39.104.22.29
- hash: 80
- file: 117.72.57.11
- hash: 4433
- file: 101.33.225.32
- hash: 80
- file: 101.33.225.32
- hash: 443
- file: 119.45.240.254
- hash: 7777
- domain: glow.f1recrest.ru
- file: 103.109.22.6
- hash: 8000
- domain: group.f1recrest.ru
- domain: wild.f1recrest.ru
- domain: owl.stonef1eld.ru
- domain: b2x0.stonef1eld.ru
- domain: pew.stonef1eld.ru
- domain: jalz.stonef1eld.ru
- file: 120.55.65.66
- hash: 8443
- file: 194.87.68.115
- hash: 80
- url: https://exodus-wallets.io/exodus.exe
- domain: sunny.cloudp0nd.ru
- file: 42.230.33.199
- hash: 52825
- domain: fg.cloudp0nd.ru
- file: 116.204.169.9
- hash: 8089
- domain: wind.cloudp0nd.ru
- domain: lhv.cloudp0nd.ru
- domain: qau.c1earstone.ru
- domain: vuqov.c1earstone.ru
- domain: ld5f.c1earstone.ru
- domain: o3x5v.c1earstone.ru
- file: 1.161.117.174
- hash: 443
- file: 101.35.103.239
- hash: 2046
- domain: cpqps.wildc0ast.ru
- file: 185.107.74.247
- hash: 7705
- domain: 0zi.wildc0ast.ru
- domain: d038t.wildc0ast.ru
- domain: 73r.wildc0ast.ru
- file: 122.114.10.199
- hash: 8003
- domain: v9y32.m1stybird.ru
- domain: beta.m1stybird.ru
- file: 121.41.29.78
- hash: 8443
- file: 115.190.7.74
- hash: 8888
- file: 47.99.68.122
- hash: 80
- file: 47.108.86.99
- hash: 8888
- domain: z9l5.m1stybird.ru
- file: 157.245.46.190
- hash: 45678
- domain: qn.m1stybird.ru
- domain: kq.gr0upw0rk.ru
- domain: seris.gd
- domain: 7juhe.gr0upw0rk.ru
- file: 142.93.37.162
- hash: 8001
- file: 188.166.87.174
- hash: 8001
- file: 159.203.125.218
- hash: 8001
- domain: ohbro.krebstresser.st
- domain: gx0tr.gr0upw0rk.ru
- file: 165.227.229.167
- hash: 8001
- file: 159.65.194.245
- hash: 8001
- file: 134.122.116.135
- hash: 8001
- file: 178.62.42.170
- hash: 8001
- file: 68.183.12.122
- hash: 8001
- file: 167.71.252.109
- hash: 8001
- file: 178.128.4.89
- hash: 8001
- url: https://www.vanda.edu.kh/
- file: 47.122.118.104
- hash: 8888
- file: 5.255.105.92
- hash: 3333
- file: 142.93.163.227
- hash: 3333
- file: 84.8.40.99
- hash: 443
- file: 94.113.246.92
- hash: 443
- domain: delta.gr0upw0rk.ru
- domain: fjhk.snowtrace.ru
- domain: 68.snowtrace.ru
- domain: wne.snowtrace.ru
- domain: dcv.snowtrace.ru
- domain: decryn.decor1cry5t.ru
- domain: ocryl.decor1cry5t.ru
- domain: drift5.decor1cry5t.ru
- file: 45.138.50.124
- hash: 1277
- file: 103.82.132.67
- hash: 7000
- file: 178.155.74.173
- hash: 4114
- file: 192.210.227.187
- hash: 4444
- file: 212.11.64.228
- hash: 5555
- file: 196.75.102.207
- hash: 2222
- file: 199.101.108.153
- hash: 3790
- domain: unionserver.duckdns.org
- file: 138.197.40.0
- hash: 8001
- file: 161.35.59.1
- hash: 8001
- file: 104.248.223.110
- hash: 8001
- domain: youcool12334213213-43544.portmap.host
- domain: youcool12334213213-42391.portmap.host
- domain: youcool12334213213-62107.portmap.host
- domain: youcool12334213213-52394.portmap.hos
- domain: coolboy123123431-41087.portmap.host
- domain: velorn.decor1cry5t.ru
- domain: uuuucome.com
- file: 108.187.37.85
- hash: 8888
- file: 108.187.37.85
- hash: 6666
- file: 108.187.37.85
- hash: 80
- domain: talcry.decor1cry5t.ru
- domain: a23.nbdsnb2.top
- domain: bryuk.b2ptb1ryuk.ru
- url: https://www.cymage-media.com/
- domain: tapel1.b2ptb1ryuk.ru
- domain: ptarb.b2ptb1ryuk.ru
- url: http://vtubers.uwunekochan.com/panel.html
- url: http://185.190.250.43/a4b374f33e9c46af.php
- domain: rybuk7.b2ptb1ryuk.ru
- domain: nebpt.b2ptb1ryuk.ru
- file: 8.137.149.67
- hash: 8091
- domain: fulen.fu1lneve7.ru
- url: https://abqsales.com/6t6t.js
- domain: abqsales.com
- url: https://abqsales.com/js.php
- url: http://199.217.98.217/a
- domain: nevar.fu1lneve7.ru
- domain: lumen7.fu1lneve7.ru
- domain: flevin.fu1lneve7.ru
- domain: uvelf1.fu1lneve7.ru
- url: https://trs.jyhsolucion.ar/
- url: https://trs.whitehallalliance.co.uk/
- url: https://49.13.37.79/
- url: https://212.11.64.161/
- domain: trs.jyhsolucion.ar
- domain: trs.whitehallalliance.co.uk
- file: 49.13.37.79
- hash: 443
- file: 212.11.64.161
- hash: 443
- domain: sevray.seven5pr2y.ru
- domain: spryn.seven5pr2y.ru
- domain: pravy2.seven5pr2y.ru
- domain: venpry.seven5pr2y.ru
- domain: sevyn5.seven5pr2y.ru
- domain: befrin.be8ref7ain.ru
- domain: rainel.be8ref7ain.ru
- domain: billing.keywordmatters.com
- domain: breez5.be8ref7ain.ru
- domain: refayn.be8ref7ain.ru
- domain: benra8.be8ref7ain.ru
- domain: deepem.de5per5eem.ru
- file: 176.65.132.160
- hash: 2785
- file: 103.77.241.148
- hash: 12121
- domain: depra.de5per5eem.ru
- domain: peren5.de5per5eem.ru
- domain: demure.de5per5eem.ru
- domain: derv1n.de5per5eem.ru
- file: 38.162.112.141
- hash: 8088
- file: 107.173.180.173
- hash: 2096
- file: 194.14.217.216
- hash: 80
- file: 94.237.29.30
- hash: 4443
- domain: email.meta-email.online
- file: 158.247.242.116
- hash: 8888
- file: 43.153.40.135
- hash: 4444
- file: 18.207.124.163
- hash: 501
- file: 18.207.124.163
- hash: 5901
- file: 18.207.124.163
- hash: 8001
- domain: author.auth0r1etter.ru
- domain: lettyr.auth0r1etter.ru
- domain: rhet1c.auth0r1etter.ru
- domain: inkset.auth0r1etter.ru
- domain: quill5.auth0r1etter.ru
- domain: baryan.ba8ryanhe7d.ru
- domain: ranhed.ba8ryanhe7d.ru
- domain: bayen5.ba8ryanhe7d.ru
- domain: harbyn.ba8ryanhe7d.ru
- file: 194.87.68.115
- hash: 443
- domain: rya7nd.ba8ryanhe7d.ru
- file: 64.227.66.216
- hash: 8001
- file: 157.230.234.254
- hash: 8001
- file: 159.203.70.20
- hash: 8001
- domain: abstra.abstractm1s5.ru
- domain: stract.abstractm1s5.ru
- domain: m1stic.abstractm1s5.ru
- domain: film-gear.gl.at.ply.gg
- domain: chukwunwike.ydns.eu
- url: http://37.221.66.19
- domain: absray.abstractm1s5.ru
- domain: tram5s.abstractm1s5.ru
- domain: hubris.hubr1s5ajor.ru
- domain: sajor.hubr1s5ajor.ru
- domain: brume1.hubr1s5ajor.ru
- file: 120.233.83.48
- hash: 10250
- file: 191.112.4.221
- hash: 443
- file: 46.246.80.12
- hash: 4444
- file: 99.83.215.169
- hash: 8127
- domain: husaor.hubr1s5ajor.ru
- domain: majr5a.hubr1s5ajor.ru
- domain: cossak.cos5acklove1.ru
- domain: lovent.cos5acklove1.ru
- domain: co5hue.cos5acklove1.ru
- domain: saclor.cos5acklove1.ru
- domain: covel1.cos5acklove1.ru
- domain: quick.mes5yr0mp.ru
- file: 114.67.181.194
- hash: 80
- domain: eg.mes5yr0mp.ru
- file: 165.154.224.175
- hash: 2095
- file: 167.150.100.196
- hash: 80
- file: 171.80.1.116
- hash: 80
- file: 91.92.240.66
- hash: 443
- file: 124.198.131.245
- hash: 5000
- file: 104.248.197.155
- hash: 443
- file: 35.179.100.221
- hash: 443
- file: 67.205.190.217
- hash: 443
- file: 124.198.131.205
- hash: 6000
- file: 104.194.215.111
- hash: 443
- file: 20.3.232.86
- hash: 443
- file: 47.156.8.196
- hash: 80
- domain: silent.mes5yr0mp.ru
- domain: qjpc.mes5yr0mp.ru
- domain: 3zg.barg5t0get.ru
- domain: bird.barg5t0get.ru
- domain: 0ec.barg5t0get.ru
- domain: wind.barg5t0get.ru
- domain: zx8.a5pirbo0rda.ru
- domain: cloud.a5pirbo0rda.ru
- file: 23.177.185.48
- hash: 8001
- file: 23.177.185.62
- hash: 8001
- domain: x5.a5pirbo0rda.ru
- domain: dark.a5pirbo0rda.ru
- domain: crest.bana1ity8ed.ru
- domain: field.bana1ity8ed.ru
- domain: vn.bana1ity8ed.ru
- domain: y54.bana1ity8ed.ru
- domain: 11qb.deve1ins0le.ru
- domain: z6.deve1ins0le.ru
- domain: group.deve1ins0le.ru
- file: 138.124.70.108
- hash: 8001
- domain: spark.deve1ins0le.ru
- domain: la.c0ffee8rind.ru
- domain: tn7z.c0ffee8rind.ru
- domain: stone.c0ffee8rind.ru
- domain: 9gzt.c0ffee8rind.ru
- domain: 72.em1npe0ny.ru
- domain: night.em1npe0ny.ru
ThreatFox IOCs for 2025-12-02
Description
ThreatFox IOCs for 2025-12-02
AI-Powered Analysis
Technical Analysis
The data describes a set of Indicators of Compromise (IOCs) from ThreatFox, a MISP feed source, dated December 2, 2025. The threat is classified as malware with emphasis on OSINT (Open Source Intelligence), payload delivery, and network activity categories. No specific affected software versions or products are listed, indicating this is a general intelligence feed rather than a vulnerability tied to a particular system. The absence of known exploits in the wild and lack of available patches suggest this is either emerging intelligence or a catalog of potential threats rather than an active exploit campaign. The technical details provide minimal insight, with a threat level of 2 (on an unspecified scale), analysis rating of 1, and distribution rating of 3, implying moderate dissemination but limited analysis depth. No concrete indicators such as IP addresses, hashes, or domains are included, which limits actionable detection capabilities. The medium severity rating aligns with the nature of the feed as a preparatory intelligence resource rather than an immediate threat. This type of threat intelligence is valuable for organizations to update detection rules, enhance situational awareness, and prepare defenses against potential malware payloads delivered via network vectors.
Potential Impact
For European organizations, the impact of this threat intelligence feed depends on how effectively it is integrated into security operations. If these IOCs correspond to emerging malware campaigns, failure to incorporate them into detection systems could result in delayed identification of payload delivery attempts or network intrusions. Potential impacts include unauthorized access, data exfiltration, or disruption of network services if malware payloads are successfully delivered. The lack of specific affected products or versions means the threat could be broad, affecting multiple sectors relying on network infrastructure and OSINT tools. Organizations with mature security monitoring and incident response capabilities can leverage this intelligence to reduce dwell time and mitigate attacks early. Conversely, entities lacking such capabilities may face increased risk of compromise. The medium severity suggests moderate risk, with potential confidentiality and availability impacts if exploited. The absence of known exploits in the wild currently limits immediate risk but does not preclude future escalation.
Mitigation Recommendations
1. Integrate ThreatFox IOCs into existing Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) systems to enhance detection capabilities. 2. Regularly update threat intelligence feeds and correlate with internal logs to identify suspicious network activity or payload delivery attempts. 3. Conduct network segmentation to limit lateral movement in case of malware infection. 4. Implement strict egress filtering and monitor outbound traffic for anomalies that may indicate data exfiltration. 5. Train security teams to analyze OSINT-based threat intelligence and adapt detection rules accordingly. 6. Perform regular threat hunting exercises using the latest IOCs to proactively identify potential compromises. 7. Maintain up-to-date backups and incident response plans to reduce impact in case of successful payload delivery. 8. Collaborate with national and European cybersecurity centers to share intelligence and receive timely alerts about emerging threats. 9. Employ multi-factor authentication and least privilege principles to reduce attack surface, even though this threat does not specify authentication requirements. 10. Monitor vendor advisories and update defenses promptly if new patches or mitigations become available.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- a16ce364-7ef2-42b7-8314-2de9e78f0243
- Original Timestamp
- 1764720186
Indicators of Compromise
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://echo-pr.co.uk/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttp://www.tsq-hk.com/rollers/rokow3/fre.php | Loki Password Stealer (PWS) botnet C2 (confidence level: 100%) | |
urlhttp://77.221.154.164/unamwebpanel/unamwebpanel/pages/login.php | Unknown RAT botnet C2 (confidence level: 100%) | |
urlhttp://167.88.165.253 | Stealc botnet C2 (confidence level: 100%) | |
urlhttp://23.132.228.234/panel.html | Unknown malware botnet C2 (confidence level: 50%) | |
urlhttps://butege075.xyz/ | SpyNote botnet C2 (confidence level: 50%) | |
urlhttps://serv-in.fr/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://exodus-wallets.io/exodus.exe | Unknown RAT payload delivery URL (confidence level: 100%) | |
urlhttps://www.vanda.edu.kh/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://www.cymage-media.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttp://vtubers.uwunekochan.com/panel.html | Unknown malware botnet C2 (confidence level: 50%) | |
urlhttp://185.190.250.43/a4b374f33e9c46af.php | Stealc botnet C2 (confidence level: 50%) | |
urlhttps://abqsales.com/6t6t.js | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttps://abqsales.com/js.php | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttp://199.217.98.217/a | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttps://trs.jyhsolucion.ar/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://trs.whitehallalliance.co.uk/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://49.13.37.79/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://212.11.64.161/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttp://37.221.66.19 | Stealc botnet C2 (confidence level: 100%) |
File
| Value | Description | Copy |
|---|---|---|
file51.255.81.133 | Socks5 Systemz botnet C2 server (confidence level: 99%) | |
file74.91.19.130 | Socks5 Systemz botnet C2 server (confidence level: 99%) | |
file104.131.23.252 | Mirai botnet C2 server (confidence level: 100%) | |
file119.29.112.57 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file54.255.195.252 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file109.230.231.29 | MimiKatz botnet C2 server (confidence level: 100%) | |
file194.14.217.125 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file194.14.217.125 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file38.182.168.169 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file156.234.121.175 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file129.204.146.115 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file47.76.237.89 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file121.41.86.68 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file38.165.33.58 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file8.137.171.139 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file158.94.208.145 | Latrodectus botnet C2 server (confidence level: 100%) | |
file81.92.219.143 | Remcos botnet C2 server (confidence level: 100%) | |
file172.193.170.213 | Sliver botnet C2 server (confidence level: 100%) | |
file101.251.179.31 | Unknown malware botnet C2 server (confidence level: 100%) | |
file117.2.181.74 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file173.208.168.61 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file144.31.3.123 | SectopRAT botnet C2 server (confidence level: 100%) | |
file213.139.77.218 | SectopRAT botnet C2 server (confidence level: 100%) | |
file34.222.248.75 | Unknown malware botnet C2 server (confidence level: 100%) | |
file69.167.11.120 | DCRat botnet C2 server (confidence level: 100%) | |
file84.154.176.63 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file196.75.32.180 | Meterpreter botnet C2 server (confidence level: 100%) | |
file103.177.47.214 | Meterpreter botnet C2 server (confidence level: 100%) | |
file119.53.187.40 | Meterpreter botnet C2 server (confidence level: 100%) | |
file144.2.114.83 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file193.242.184.136 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file193.111.78.83 | Quasar RAT botnet C2 server (confidence level: 75%) | |
file87.121.84.117 | Mirai botnet C2 server (confidence level: 75%) | |
file213.209.143.33 | Mirai botnet C2 server (confidence level: 75%) | |
file108.165.154.164 | Remcos botnet C2 server (confidence level: 100%) | |
file213.209.143.34 | Mirai botnet C2 server (confidence level: 75%) | |
file39.104.22.29 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file117.72.57.11 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file101.33.225.32 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file101.33.225.32 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file119.45.240.254 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file103.109.22.6 | MimiKatz botnet C2 server (confidence level: 100%) | |
file120.55.65.66 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file194.87.68.115 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file42.230.33.199 | Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%) | |
file116.204.169.9 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file1.161.117.174 | QakBot botnet C2 server (confidence level: 75%) | |
file101.35.103.239 | Unknown malware botnet C2 server (confidence level: 75%) | |
file185.107.74.247 | PureLogs Stealer botnet C2 server (confidence level: 88%) | |
file122.114.10.199 | Sliver botnet C2 server (confidence level: 75%) | |
file121.41.29.78 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file115.190.7.74 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file47.99.68.122 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file47.108.86.99 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file157.245.46.190 | Sliver botnet C2 server (confidence level: 75%) | |
file142.93.37.162 | Aisuru botnet C2 server (confidence level: 75%) | |
file188.166.87.174 | Aisuru botnet C2 server (confidence level: 75%) | |
file159.203.125.218 | Aisuru botnet C2 server (confidence level: 75%) | |
file165.227.229.167 | Aisuru botnet C2 server (confidence level: 75%) | |
file159.65.194.245 | Aisuru botnet C2 server (confidence level: 75%) | |
file134.122.116.135 | Aisuru botnet C2 server (confidence level: 75%) | |
file178.62.42.170 | Aisuru botnet C2 server (confidence level: 75%) | |
file68.183.12.122 | Aisuru botnet C2 server (confidence level: 75%) | |
file167.71.252.109 | Aisuru botnet C2 server (confidence level: 75%) | |
file178.128.4.89 | Aisuru botnet C2 server (confidence level: 75%) | |
file47.122.118.104 | Unknown malware botnet C2 server (confidence level: 100%) | |
file5.255.105.92 | Unknown malware botnet C2 server (confidence level: 100%) | |
file142.93.163.227 | Unknown malware botnet C2 server (confidence level: 100%) | |
file84.8.40.99 | Unknown malware botnet C2 server (confidence level: 100%) | |
file94.113.246.92 | Unknown malware botnet C2 server (confidence level: 100%) | |
file45.138.50.124 | XWorm botnet C2 server (confidence level: 100%) | |
file103.82.132.67 | XWorm botnet C2 server (confidence level: 100%) | |
file178.155.74.173 | XWorm botnet C2 server (confidence level: 100%) | |
file192.210.227.187 | Venom RAT botnet C2 server (confidence level: 100%) | |
file212.11.64.228 | Unknown malware botnet C2 server (confidence level: 100%) | |
file196.75.102.207 | Meterpreter botnet C2 server (confidence level: 100%) | |
file199.101.108.153 | Meterpreter botnet C2 server (confidence level: 100%) | |
file138.197.40.0 | Aisuru botnet C2 server (confidence level: 75%) | |
file161.35.59.1 | Aisuru botnet C2 server (confidence level: 75%) | |
file104.248.223.110 | Aisuru botnet C2 server (confidence level: 75%) | |
file108.187.37.85 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file108.187.37.85 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file108.187.37.85 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file8.137.149.67 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file49.13.37.79 | Vidar botnet C2 server (confidence level: 100%) | |
file212.11.64.161 | Vidar botnet C2 server (confidence level: 100%) | |
file176.65.132.160 | Mirai botnet C2 server (confidence level: 75%) | |
file103.77.241.148 | Mirai botnet C2 server (confidence level: 75%) | |
file38.162.112.141 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file107.173.180.173 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file194.14.217.216 | Unknown RAT botnet C2 server (confidence level: 100%) | |
file94.237.29.30 | Sliver botnet C2 server (confidence level: 100%) | |
file158.247.242.116 | MimiKatz botnet C2 server (confidence level: 100%) | |
file43.153.40.135 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file18.207.124.163 | Meterpreter botnet C2 server (confidence level: 100%) | |
file18.207.124.163 | Meterpreter botnet C2 server (confidence level: 100%) | |
file18.207.124.163 | Meterpreter botnet C2 server (confidence level: 100%) | |
file194.87.68.115 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file64.227.66.216 | Aisuru botnet C2 server (confidence level: 75%) | |
file157.230.234.254 | Aisuru botnet C2 server (confidence level: 75%) | |
file159.203.70.20 | Aisuru botnet C2 server (confidence level: 75%) | |
file120.233.83.48 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file191.112.4.221 | QakBot botnet C2 server (confidence level: 75%) | |
file46.246.80.12 | DCRat botnet C2 server (confidence level: 75%) | |
file99.83.215.169 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file114.67.181.194 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file165.154.224.175 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file167.150.100.196 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file171.80.1.116 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file91.92.240.66 | Latrodectus botnet C2 server (confidence level: 100%) | |
file124.198.131.245 | Remcos botnet C2 server (confidence level: 100%) | |
file104.248.197.155 | Sliver botnet C2 server (confidence level: 100%) | |
file35.179.100.221 | Sliver botnet C2 server (confidence level: 100%) | |
file67.205.190.217 | Sliver botnet C2 server (confidence level: 100%) | |
file124.198.131.205 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file104.194.215.111 | Havoc botnet C2 server (confidence level: 100%) | |
file20.3.232.86 | Venom RAT botnet C2 server (confidence level: 100%) | |
file47.156.8.196 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file23.177.185.48 | Aisuru botnet C2 server (confidence level: 75%) | |
file23.177.185.62 | Aisuru botnet C2 server (confidence level: 75%) | |
file138.124.70.108 | Aisuru botnet C2 server (confidence level: 75%) |
Hash
| Value | Description | Copy |
|---|---|---|
hash2024 | Socks5 Systemz botnet C2 server (confidence level: 99%) | |
hash2024 | Socks5 Systemz botnet C2 server (confidence level: 99%) | |
hash39691 | Mirai botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash22 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash8888 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash6181 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8089 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash60002 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash6666 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Latrodectus botnet C2 server (confidence level: 100%) | |
hash443 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8080 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | DCRat botnet C2 server (confidence level: 100%) | |
hash81 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash2222 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash10001 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash444 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash1337 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash1604 | Quasar RAT botnet C2 server (confidence level: 75%) | |
hash9772 | Mirai botnet C2 server (confidence level: 75%) | |
hash54128 | Mirai botnet C2 server (confidence level: 75%) | |
hash1122 | Remcos botnet C2 server (confidence level: 100%) | |
hash9931 | Mirai botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash4433 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash7777 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash8000 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash8443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash52825 | Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%) | |
hash8089 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash443 | QakBot botnet C2 server (confidence level: 75%) | |
hash2046 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash7705 | PureLogs Stealer botnet C2 server (confidence level: 88%) | |
hash8003 | Sliver botnet C2 server (confidence level: 75%) | |
hash8443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash45678 | Sliver botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash1277 | XWorm botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash4114 | XWorm botnet C2 server (confidence level: 100%) | |
hash4444 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash5555 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash2222 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8888 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash6666 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash80 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash8091 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash443 | Vidar botnet C2 server (confidence level: 100%) | |
hash2785 | Mirai botnet C2 server (confidence level: 75%) | |
hash12121 | Mirai botnet C2 server (confidence level: 75%) | |
hash8088 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2096 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Unknown RAT botnet C2 server (confidence level: 100%) | |
hash4443 | Sliver botnet C2 server (confidence level: 100%) | |
hash8888 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash4444 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash501 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash5901 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash8001 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash10250 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | QakBot botnet C2 server (confidence level: 75%) | |
hash4444 | DCRat botnet C2 server (confidence level: 75%) | |
hash8127 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2095 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Latrodectus botnet C2 server (confidence level: 100%) | |
hash5000 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash6000 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash443 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash80 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) |
Domain
| Value | Description | Copy |
|---|---|---|
domainsoft-dns.sejilod7488888.workers.dev | SMOKEDHAM botnet C2 domain (confidence level: 100%) | |
domainalexiac.cyou | Lumma Stealer botnet C2 domain (confidence level: 75%) | |
domainascetin.cyou | Lumma Stealer botnet C2 domain (confidence level: 75%) | |
domainboflijo.cyou | Lumma Stealer botnet C2 domain (confidence level: 75%) | |
domainentraiz.cyou | Lumma Stealer botnet C2 domain (confidence level: 75%) | |
domainextirpo.cyou | Lumma Stealer botnet C2 domain (confidence level: 75%) | |
domainleonhat.cyou | Lumma Stealer botnet C2 domain (confidence level: 75%) | |
domainrotfqxu.cyou | Lumma Stealer botnet C2 domain (confidence level: 75%) | |
domaintruxaqn.cyou | Lumma Stealer botnet C2 domain (confidence level: 75%) | |
domainsimonts.cyou | Lumma Stealer botnet C2 domain (confidence level: 75%) | |
domainsouldey.cyou | Lumma Stealer botnet C2 domain (confidence level: 75%) | |
domaintownsex.cyou | Lumma Stealer botnet C2 domain (confidence level: 75%) | |
domaincrystal.cloudb1te.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaing6vi.softgl1de.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7qqa.softgl1de.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain92nr.softgl1de.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain19r6l.softgl1de.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingate.rivershad0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain5h.rivershad0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7c.rivershad0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain8m.rivershad0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainalpha.crystal0ak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainj1bn.crystal0ak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintrace.crystal0ak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaink9yn.crystal0ak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsoft.brightst0ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainydb7x.brightst0ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainj8kd7.brightst0ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkd7u.mistyflare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainx40.mistyflare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain368.mistyflare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainforest.mistyflare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain84m.stoneflare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain6tal.stoneflare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainriver.stoneflare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjn.stoneflare.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpond.n1ghtbloom.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain6f.n1ghtbloom.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsbtua.n1ghtbloom.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainuw.n1ghtbloom.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainflare.wildm1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmzu8.wildm1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainp7l0.wildm1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaina6u.wildm1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhl.w1ndcrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvnq.w1ndcrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainh3m.w1ndcrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincoast.w1ndcrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain00f.deepflash.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshadow.deepflash.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainllbf.deepflash.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsf.deepflash.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainneeds-developed.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainenvio2777.mysynology.net | XWorm botnet C2 domain (confidence level: 100%) | |
domainjun-suppliers.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domain5adm.windsh1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain1qc.windsh1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingold.windsh1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxnaw.windsh1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspark.silenth1ll.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain31x.silenth1ll.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaine7.silenth1ll.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainquick.silenth1ll.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbz.forestgl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindl9e.forestgl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainefjgerws.galaxias.cc | Mirai botnet C2 domain (confidence level: 100%) | |
domainnight.forestgl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlight.forestgl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsilver.nightm1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain3h2p.nightm1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainto-appreciation.gl.at.ply.gg | NjRAT botnet C2 domain (confidence level: 50%) | |
domaintovool123343123-42020.portmap.host | Quasar RAT botnet C2 domain (confidence level: 50%) | |
domainstone.nightm1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwork.nightm1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpublic.dvrexpert.st | Aisuru botnet C2 domain (confidence level: 100%) | |
domains1603.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1619.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1270.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1256.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1533.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1276.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1252.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1264.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1535.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1266.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1244.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1531.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1262.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1254.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1272.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1246.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1248.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1258.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1274.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1268.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1613.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1621.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1617.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domains1609.house-spirit.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domaincrest.f1recrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainglow.f1recrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingroup.f1recrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwild.f1recrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainowl.stonef1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainb2x0.stonef1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpew.stonef1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjalz.stonef1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsunny.cloudp0nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfg.cloudp0nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwind.cloudp0nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlhv.cloudp0nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqau.c1earstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvuqov.c1earstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainld5f.c1earstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaino3x5v.c1earstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincpqps.wildc0ast.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain0zi.wildc0ast.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaind038t.wildc0ast.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain73r.wildc0ast.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainv9y32.m1stybird.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbeta.m1stybird.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainz9l5.m1stybird.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqn.m1stybird.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkq.gr0upw0rk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainseris.gd | Mirai botnet C2 domain (confidence level: 100%) | |
domain7juhe.gr0upw0rk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainohbro.krebstresser.st | Aisuru botnet C2 domain (confidence level: 100%) | |
domaingx0tr.gr0upw0rk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindelta.gr0upw0rk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfjhk.snowtrace.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain68.snowtrace.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwne.snowtrace.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindcv.snowtrace.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindecryn.decor1cry5t.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainocryl.decor1cry5t.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindrift5.decor1cry5t.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainunionserver.duckdns.org | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainyoucool12334213213-43544.portmap.host | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainyoucool12334213213-42391.portmap.host | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainyoucool12334213213-62107.portmap.host | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainyoucool12334213213-52394.portmap.hos | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domaincoolboy123123431-41087.portmap.host | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainvelorn.decor1cry5t.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainuuuucome.com | ValleyRAT botnet C2 domain (confidence level: 100%) | |
domaintalcry.decor1cry5t.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaina23.nbdsnb2.top | FatalRat botnet C2 domain (confidence level: 100%) | |
domainbryuk.b2ptb1ryuk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintapel1.b2ptb1ryuk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainptarb.b2ptb1ryuk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrybuk7.b2ptb1ryuk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnebpt.b2ptb1ryuk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfulen.fu1lneve7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainabqsales.com | KongTuke payload delivery domain (confidence level: 100%) | |
domainnevar.fu1lneve7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlumen7.fu1lneve7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainflevin.fu1lneve7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainuvelf1.fu1lneve7.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintrs.jyhsolucion.ar | Vidar botnet C2 domain (confidence level: 100%) | |
domaintrs.whitehallalliance.co.uk | Vidar botnet C2 domain (confidence level: 100%) | |
domainsevray.seven5pr2y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspryn.seven5pr2y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpravy2.seven5pr2y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvenpry.seven5pr2y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsevyn5.seven5pr2y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbefrin.be8ref7ain.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrainel.be8ref7ain.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbilling.keywordmatters.com | FAKEUPDATES botnet C2 domain (confidence level: 100%) | |
domainbreez5.be8ref7ain.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrefayn.be8ref7ain.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbenra8.be8ref7ain.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindeepem.de5per5eem.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindepra.de5per5eem.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainperen5.de5per5eem.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindemure.de5per5eem.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainderv1n.de5per5eem.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainemail.meta-email.online | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainauthor.auth0r1etter.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlettyr.auth0r1etter.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrhet1c.auth0r1etter.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaininkset.auth0r1etter.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainquill5.auth0r1etter.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbaryan.ba8ryanhe7d.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainranhed.ba8ryanhe7d.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbayen5.ba8ryanhe7d.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainharbyn.ba8ryanhe7d.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrya7nd.ba8ryanhe7d.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainabstra.abstractm1s5.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstract.abstractm1s5.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainm1stic.abstractm1s5.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfilm-gear.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainchukwunwike.ydns.eu | Remcos botnet C2 domain (confidence level: 100%) | |
domainabsray.abstractm1s5.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintram5s.abstractm1s5.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhubris.hubr1s5ajor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsajor.hubr1s5ajor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrume1.hubr1s5ajor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhusaor.hubr1s5ajor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmajr5a.hubr1s5ajor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincossak.cos5acklove1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlovent.cos5acklove1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainco5hue.cos5acklove1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsaclor.cos5acklove1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincovel1.cos5acklove1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainquick.mes5yr0mp.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineg.mes5yr0mp.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsilent.mes5yr0mp.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqjpc.mes5yr0mp.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain3zg.barg5t0get.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbird.barg5t0get.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain0ec.barg5t0get.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwind.barg5t0get.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzx8.a5pirbo0rda.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincloud.a5pirbo0rda.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainx5.a5pirbo0rda.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindark.a5pirbo0rda.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincrest.bana1ity8ed.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfield.bana1ity8ed.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvn.bana1ity8ed.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainy54.bana1ity8ed.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain11qb.deve1ins0le.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainz6.deve1ins0le.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingroup.deve1ins0le.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspark.deve1ins0le.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainla.c0ffee8rind.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintn7z.c0ffee8rind.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstone.c0ffee8rind.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain9gzt.c0ffee8rind.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain72.em1npe0ny.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnight.em1npe0ny.ru | ClearFake payload delivery domain (confidence level: 100%) |
Threat ID: 692f8089619fec35b42a60bc
Added to database: 12/3/2025, 12:12:57 AM
Last enriched: 12/3/2025, 12:13:28 AM
Last updated: 12/5/2025, 1:07:56 AM
Views: 38
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
ThreatFox IOCs for 2025-12-04
MediumQilin Ransomware Claims Data Theft from Church of Scientology
MediumSilver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
MediumNew Android malware lets criminals control your phone and drain your bank account
MediumNewly Sold Albiriox Android Malware Targets Banks and Crypto Holders
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.