Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2025-12-02

0
Medium
Published: Tue Dec 02 2025 (12/02/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-12-02

AI-Powered Analysis

AILast updated: 12/03/2025, 00:13:28 UTC

Technical Analysis

The data describes a set of Indicators of Compromise (IOCs) from ThreatFox, a MISP feed source, dated December 2, 2025. The threat is classified as malware with emphasis on OSINT (Open Source Intelligence), payload delivery, and network activity categories. No specific affected software versions or products are listed, indicating this is a general intelligence feed rather than a vulnerability tied to a particular system. The absence of known exploits in the wild and lack of available patches suggest this is either emerging intelligence or a catalog of potential threats rather than an active exploit campaign. The technical details provide minimal insight, with a threat level of 2 (on an unspecified scale), analysis rating of 1, and distribution rating of 3, implying moderate dissemination but limited analysis depth. No concrete indicators such as IP addresses, hashes, or domains are included, which limits actionable detection capabilities. The medium severity rating aligns with the nature of the feed as a preparatory intelligence resource rather than an immediate threat. This type of threat intelligence is valuable for organizations to update detection rules, enhance situational awareness, and prepare defenses against potential malware payloads delivered via network vectors.

Potential Impact

For European organizations, the impact of this threat intelligence feed depends on how effectively it is integrated into security operations. If these IOCs correspond to emerging malware campaigns, failure to incorporate them into detection systems could result in delayed identification of payload delivery attempts or network intrusions. Potential impacts include unauthorized access, data exfiltration, or disruption of network services if malware payloads are successfully delivered. The lack of specific affected products or versions means the threat could be broad, affecting multiple sectors relying on network infrastructure and OSINT tools. Organizations with mature security monitoring and incident response capabilities can leverage this intelligence to reduce dwell time and mitigate attacks early. Conversely, entities lacking such capabilities may face increased risk of compromise. The medium severity suggests moderate risk, with potential confidentiality and availability impacts if exploited. The absence of known exploits in the wild currently limits immediate risk but does not preclude future escalation.

Mitigation Recommendations

1. Integrate ThreatFox IOCs into existing Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) systems to enhance detection capabilities. 2. Regularly update threat intelligence feeds and correlate with internal logs to identify suspicious network activity or payload delivery attempts. 3. Conduct network segmentation to limit lateral movement in case of malware infection. 4. Implement strict egress filtering and monitor outbound traffic for anomalies that may indicate data exfiltration. 5. Train security teams to analyze OSINT-based threat intelligence and adapt detection rules accordingly. 6. Perform regular threat hunting exercises using the latest IOCs to proactively identify potential compromises. 7. Maintain up-to-date backups and incident response plans to reduce impact in case of successful payload delivery. 8. Collaborate with national and European cybersecurity centers to share intelligence and receive timely alerts about emerging threats. 9. Employ multi-factor authentication and least privilege principles to reduce attack surface, even though this threat does not specify authentication requirements. 10. Monitor vendor advisories and update defenses promptly if new patches or mitigations become available.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
a16ce364-7ef2-42b7-8314-2de9e78f0243
Original Timestamp
1764720186

Indicators of Compromise

Url

ValueDescriptionCopy
urlhttps://echo-pr.co.uk/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://www.tsq-hk.com/rollers/rokow3/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttp://77.221.154.164/unamwebpanel/unamwebpanel/pages/login.php
Unknown RAT botnet C2 (confidence level: 100%)
urlhttp://167.88.165.253
Stealc botnet C2 (confidence level: 100%)
urlhttp://23.132.228.234/panel.html
Unknown malware botnet C2 (confidence level: 50%)
urlhttps://butege075.xyz/
SpyNote botnet C2 (confidence level: 50%)
urlhttps://serv-in.fr/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://exodus-wallets.io/exodus.exe
Unknown RAT payload delivery URL (confidence level: 100%)
urlhttps://www.vanda.edu.kh/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.cymage-media.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://vtubers.uwunekochan.com/panel.html
Unknown malware botnet C2 (confidence level: 50%)
urlhttp://185.190.250.43/a4b374f33e9c46af.php
Stealc botnet C2 (confidence level: 50%)
urlhttps://abqsales.com/6t6t.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://abqsales.com/js.php
KongTuke payload delivery URL (confidence level: 100%)
urlhttp://199.217.98.217/a
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://trs.jyhsolucion.ar/
Vidar botnet C2 (confidence level: 100%)
urlhttps://trs.whitehallalliance.co.uk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://49.13.37.79/
Vidar botnet C2 (confidence level: 100%)
urlhttps://212.11.64.161/
Vidar botnet C2 (confidence level: 100%)
urlhttp://37.221.66.19
Stealc botnet C2 (confidence level: 100%)

File

ValueDescriptionCopy
file51.255.81.133
Socks5 Systemz botnet C2 server (confidence level: 99%)
file74.91.19.130
Socks5 Systemz botnet C2 server (confidence level: 99%)
file104.131.23.252
Mirai botnet C2 server (confidence level: 100%)
file119.29.112.57
Cobalt Strike botnet C2 server (confidence level: 100%)
file54.255.195.252
Quasar RAT botnet C2 server (confidence level: 100%)
file109.230.231.29
MimiKatz botnet C2 server (confidence level: 100%)
file194.14.217.125
Cobalt Strike botnet C2 server (confidence level: 75%)
file194.14.217.125
Cobalt Strike botnet C2 server (confidence level: 75%)
file38.182.168.169
Cobalt Strike botnet C2 server (confidence level: 75%)
file156.234.121.175
Cobalt Strike botnet C2 server (confidence level: 100%)
file129.204.146.115
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.76.237.89
Cobalt Strike botnet C2 server (confidence level: 100%)
file121.41.86.68
Cobalt Strike botnet C2 server (confidence level: 100%)
file38.165.33.58
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.137.171.139
Cobalt Strike botnet C2 server (confidence level: 100%)
file158.94.208.145
Latrodectus botnet C2 server (confidence level: 100%)
file81.92.219.143
Remcos botnet C2 server (confidence level: 100%)
file172.193.170.213
Sliver botnet C2 server (confidence level: 100%)
file101.251.179.31
Unknown malware botnet C2 server (confidence level: 100%)
file117.2.181.74
AsyncRAT botnet C2 server (confidence level: 100%)
file173.208.168.61
AsyncRAT botnet C2 server (confidence level: 100%)
file144.31.3.123
SectopRAT botnet C2 server (confidence level: 100%)
file213.139.77.218
SectopRAT botnet C2 server (confidence level: 100%)
file34.222.248.75
Unknown malware botnet C2 server (confidence level: 100%)
file69.167.11.120
DCRat botnet C2 server (confidence level: 100%)
file84.154.176.63
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file196.75.32.180
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.214
Meterpreter botnet C2 server (confidence level: 100%)
file119.53.187.40
Meterpreter botnet C2 server (confidence level: 100%)
file144.2.114.83
Empire Downloader botnet C2 server (confidence level: 100%)
file193.242.184.136
Empire Downloader botnet C2 server (confidence level: 100%)
file193.111.78.83
Quasar RAT botnet C2 server (confidence level: 75%)
file87.121.84.117
Mirai botnet C2 server (confidence level: 75%)
file213.209.143.33
Mirai botnet C2 server (confidence level: 75%)
file108.165.154.164
Remcos botnet C2 server (confidence level: 100%)
file213.209.143.34
Mirai botnet C2 server (confidence level: 75%)
file39.104.22.29
Cobalt Strike botnet C2 server (confidence level: 100%)
file117.72.57.11
Cobalt Strike botnet C2 server (confidence level: 100%)
file101.33.225.32
Cobalt Strike botnet C2 server (confidence level: 100%)
file101.33.225.32
Cobalt Strike botnet C2 server (confidence level: 100%)
file119.45.240.254
Ghost RAT botnet C2 server (confidence level: 100%)
file103.109.22.6
MimiKatz botnet C2 server (confidence level: 100%)
file120.55.65.66
Cobalt Strike botnet C2 server (confidence level: 75%)
file194.87.68.115
Cobalt Strike botnet C2 server (confidence level: 75%)
file42.230.33.199
Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%)
file116.204.169.9
ValleyRAT botnet C2 server (confidence level: 100%)
file1.161.117.174
QakBot botnet C2 server (confidence level: 75%)
file101.35.103.239
Unknown malware botnet C2 server (confidence level: 75%)
file185.107.74.247
PureLogs Stealer botnet C2 server (confidence level: 88%)
file122.114.10.199
Sliver botnet C2 server (confidence level: 75%)
file121.41.29.78
Cobalt Strike botnet C2 server (confidence level: 100%)
file115.190.7.74
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.99.68.122
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.108.86.99
Cobalt Strike botnet C2 server (confidence level: 100%)
file157.245.46.190
Sliver botnet C2 server (confidence level: 75%)
file142.93.37.162
Aisuru botnet C2 server (confidence level: 75%)
file188.166.87.174
Aisuru botnet C2 server (confidence level: 75%)
file159.203.125.218
Aisuru botnet C2 server (confidence level: 75%)
file165.227.229.167
Aisuru botnet C2 server (confidence level: 75%)
file159.65.194.245
Aisuru botnet C2 server (confidence level: 75%)
file134.122.116.135
Aisuru botnet C2 server (confidence level: 75%)
file178.62.42.170
Aisuru botnet C2 server (confidence level: 75%)
file68.183.12.122
Aisuru botnet C2 server (confidence level: 75%)
file167.71.252.109
Aisuru botnet C2 server (confidence level: 75%)
file178.128.4.89
Aisuru botnet C2 server (confidence level: 75%)
file47.122.118.104
Unknown malware botnet C2 server (confidence level: 100%)
file5.255.105.92
Unknown malware botnet C2 server (confidence level: 100%)
file142.93.163.227
Unknown malware botnet C2 server (confidence level: 100%)
file84.8.40.99
Unknown malware botnet C2 server (confidence level: 100%)
file94.113.246.92
Unknown malware botnet C2 server (confidence level: 100%)
file45.138.50.124
XWorm botnet C2 server (confidence level: 100%)
file103.82.132.67
XWorm botnet C2 server (confidence level: 100%)
file178.155.74.173
XWorm botnet C2 server (confidence level: 100%)
file192.210.227.187
Venom RAT botnet C2 server (confidence level: 100%)
file212.11.64.228
Unknown malware botnet C2 server (confidence level: 100%)
file196.75.102.207
Meterpreter botnet C2 server (confidence level: 100%)
file199.101.108.153
Meterpreter botnet C2 server (confidence level: 100%)
file138.197.40.0
Aisuru botnet C2 server (confidence level: 75%)
file161.35.59.1
Aisuru botnet C2 server (confidence level: 75%)
file104.248.223.110
Aisuru botnet C2 server (confidence level: 75%)
file108.187.37.85
ValleyRAT botnet C2 server (confidence level: 100%)
file108.187.37.85
ValleyRAT botnet C2 server (confidence level: 100%)
file108.187.37.85
ValleyRAT botnet C2 server (confidence level: 100%)
file8.137.149.67
Cobalt Strike botnet C2 server (confidence level: 75%)
file49.13.37.79
Vidar botnet C2 server (confidence level: 100%)
file212.11.64.161
Vidar botnet C2 server (confidence level: 100%)
file176.65.132.160
Mirai botnet C2 server (confidence level: 75%)
file103.77.241.148
Mirai botnet C2 server (confidence level: 75%)
file38.162.112.141
Cobalt Strike botnet C2 server (confidence level: 100%)
file107.173.180.173
Cobalt Strike botnet C2 server (confidence level: 100%)
file194.14.217.216
Unknown RAT botnet C2 server (confidence level: 100%)
file94.237.29.30
Sliver botnet C2 server (confidence level: 100%)
file158.247.242.116
MimiKatz botnet C2 server (confidence level: 100%)
file43.153.40.135
AdaptixC2 botnet C2 server (confidence level: 100%)
file18.207.124.163
Meterpreter botnet C2 server (confidence level: 100%)
file18.207.124.163
Meterpreter botnet C2 server (confidence level: 100%)
file18.207.124.163
Meterpreter botnet C2 server (confidence level: 100%)
file194.87.68.115
Cobalt Strike botnet C2 server (confidence level: 75%)
file64.227.66.216
Aisuru botnet C2 server (confidence level: 75%)
file157.230.234.254
Aisuru botnet C2 server (confidence level: 75%)
file159.203.70.20
Aisuru botnet C2 server (confidence level: 75%)
file120.233.83.48
DeimosC2 botnet C2 server (confidence level: 75%)
file191.112.4.221
QakBot botnet C2 server (confidence level: 75%)
file46.246.80.12
DCRat botnet C2 server (confidence level: 75%)
file99.83.215.169
DeimosC2 botnet C2 server (confidence level: 75%)
file114.67.181.194
Cobalt Strike botnet C2 server (confidence level: 100%)
file165.154.224.175
Cobalt Strike botnet C2 server (confidence level: 100%)
file167.150.100.196
Cobalt Strike botnet C2 server (confidence level: 100%)
file171.80.1.116
Cobalt Strike botnet C2 server (confidence level: 100%)
file91.92.240.66
Latrodectus botnet C2 server (confidence level: 100%)
file124.198.131.245
Remcos botnet C2 server (confidence level: 100%)
file104.248.197.155
Sliver botnet C2 server (confidence level: 100%)
file35.179.100.221
Sliver botnet C2 server (confidence level: 100%)
file67.205.190.217
Sliver botnet C2 server (confidence level: 100%)
file124.198.131.205
AsyncRAT botnet C2 server (confidence level: 100%)
file104.194.215.111
Havoc botnet C2 server (confidence level: 100%)
file20.3.232.86
Venom RAT botnet C2 server (confidence level: 100%)
file47.156.8.196
Empire Downloader botnet C2 server (confidence level: 100%)
file23.177.185.48
Aisuru botnet C2 server (confidence level: 75%)
file23.177.185.62
Aisuru botnet C2 server (confidence level: 75%)
file138.124.70.108
Aisuru botnet C2 server (confidence level: 75%)

Hash

ValueDescriptionCopy
hash2024
Socks5 Systemz botnet C2 server (confidence level: 99%)
hash2024
Socks5 Systemz botnet C2 server (confidence level: 99%)
hash39691
Mirai botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash22
Quasar RAT botnet C2 server (confidence level: 100%)
hash8888
MimiKatz botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash6181
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8089
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash60002
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash6666
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8080
AsyncRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
DCRat botnet C2 server (confidence level: 100%)
hash81
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash2222
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash10001
Meterpreter botnet C2 server (confidence level: 100%)
hash444
Empire Downloader botnet C2 server (confidence level: 100%)
hash1337
Empire Downloader botnet C2 server (confidence level: 100%)
hash1604
Quasar RAT botnet C2 server (confidence level: 75%)
hash9772
Mirai botnet C2 server (confidence level: 75%)
hash54128
Mirai botnet C2 server (confidence level: 75%)
hash1122
Remcos botnet C2 server (confidence level: 100%)
hash9931
Mirai botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4433
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7777
Ghost RAT botnet C2 server (confidence level: 100%)
hash8000
MimiKatz botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash52825
Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%)
hash8089
ValleyRAT botnet C2 server (confidence level: 100%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash2046
Unknown malware botnet C2 server (confidence level: 75%)
hash7705
PureLogs Stealer botnet C2 server (confidence level: 88%)
hash8003
Sliver botnet C2 server (confidence level: 75%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash45678
Sliver botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash1277
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash4114
XWorm botnet C2 server (confidence level: 100%)
hash4444
Venom RAT botnet C2 server (confidence level: 100%)
hash5555
Unknown malware botnet C2 server (confidence level: 100%)
hash2222
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8888
ValleyRAT botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
ValleyRAT botnet C2 server (confidence level: 100%)
hash8091
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash2785
Mirai botnet C2 server (confidence level: 75%)
hash12121
Mirai botnet C2 server (confidence level: 75%)
hash8088
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2096
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Unknown RAT botnet C2 server (confidence level: 100%)
hash4443
Sliver botnet C2 server (confidence level: 100%)
hash8888
MimiKatz botnet C2 server (confidence level: 100%)
hash4444
AdaptixC2 botnet C2 server (confidence level: 100%)
hash501
Meterpreter botnet C2 server (confidence level: 100%)
hash5901
Meterpreter botnet C2 server (confidence level: 100%)
hash8001
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash10250
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash4444
DCRat botnet C2 server (confidence level: 75%)
hash8127
DeimosC2 botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2095
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash5000
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash6000
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash443
Venom RAT botnet C2 server (confidence level: 100%)
hash80
Empire Downloader botnet C2 server (confidence level: 100%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)

Domain

ValueDescriptionCopy
domainsoft-dns.sejilod7488888.workers.dev
SMOKEDHAM botnet C2 domain (confidence level: 100%)
domainalexiac.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domainascetin.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domainboflijo.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domainentraiz.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domainextirpo.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domainleonhat.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domainrotfqxu.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domaintruxaqn.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domainsimonts.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domainsouldey.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domaintownsex.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domaincrystal.cloudb1te.ru
ClearFake payload delivery domain (confidence level: 100%)
domaing6vi.softgl1de.ru
ClearFake payload delivery domain (confidence level: 100%)
domain7qqa.softgl1de.ru
ClearFake payload delivery domain (confidence level: 100%)
domain92nr.softgl1de.ru
ClearFake payload delivery domain (confidence level: 100%)
domain19r6l.softgl1de.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingate.rivershad0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domain5h.rivershad0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domain7c.rivershad0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8m.rivershad0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domainalpha.crystal0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainj1bn.crystal0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintrace.crystal0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domaink9yn.crystal0ak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsoft.brightst0ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainydb7x.brightst0ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainj8kd7.brightst0ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkd7u.mistyflare.ru
ClearFake payload delivery domain (confidence level: 100%)
domainx40.mistyflare.ru
ClearFake payload delivery domain (confidence level: 100%)
domain368.mistyflare.ru
ClearFake payload delivery domain (confidence level: 100%)
domainforest.mistyflare.ru
ClearFake payload delivery domain (confidence level: 100%)
domain84m.stoneflare.ru
ClearFake payload delivery domain (confidence level: 100%)
domain6tal.stoneflare.ru
ClearFake payload delivery domain (confidence level: 100%)
domainriver.stoneflare.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjn.stoneflare.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpond.n1ghtbloom.ru
ClearFake payload delivery domain (confidence level: 100%)
domain6f.n1ghtbloom.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsbtua.n1ghtbloom.ru
ClearFake payload delivery domain (confidence level: 100%)
domainuw.n1ghtbloom.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflare.wildm1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmzu8.wildm1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainp7l0.wildm1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domaina6u.wildm1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhl.w1ndcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvnq.w1ndcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainh3m.w1ndcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincoast.w1ndcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domain00f.deepflash.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshadow.deepflash.ru
ClearFake payload delivery domain (confidence level: 100%)
domainllbf.deepflash.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsf.deepflash.ru
ClearFake payload delivery domain (confidence level: 100%)
domainneeds-developed.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainenvio2777.mysynology.net
XWorm botnet C2 domain (confidence level: 100%)
domainjun-suppliers.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domain5adm.windsh1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domain1qc.windsh1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingold.windsh1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxnaw.windsh1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspark.silenth1ll.ru
ClearFake payload delivery domain (confidence level: 100%)
domain31x.silenth1ll.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine7.silenth1ll.ru
ClearFake payload delivery domain (confidence level: 100%)
domainquick.silenth1ll.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbz.forestgl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindl9e.forestgl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domainefjgerws.galaxias.cc
Mirai botnet C2 domain (confidence level: 100%)
domainnight.forestgl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlight.forestgl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsilver.nightm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domain3h2p.nightm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainto-appreciation.gl.at.ply.gg
NjRAT botnet C2 domain (confidence level: 50%)
domaintovool123343123-42020.portmap.host
Quasar RAT botnet C2 domain (confidence level: 50%)
domainstone.nightm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwork.nightm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpublic.dvrexpert.st
Aisuru botnet C2 domain (confidence level: 100%)
domains1603.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1619.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1270.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1256.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1533.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1276.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1252.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1264.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1535.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1266.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1244.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1531.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1262.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1254.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1272.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1246.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1248.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1258.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1274.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1268.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1613.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1621.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1617.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domains1609.house-spirit.com
Unknown malware botnet C2 domain (confidence level: 100%)
domaincrest.f1recrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainglow.f1recrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingroup.f1recrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwild.f1recrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainowl.stonef1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domainb2x0.stonef1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpew.stonef1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjalz.stonef1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsunny.cloudp0nd.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfg.cloudp0nd.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwind.cloudp0nd.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlhv.cloudp0nd.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqau.c1earstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvuqov.c1earstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainld5f.c1earstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domaino3x5v.c1earstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincpqps.wildc0ast.ru
ClearFake payload delivery domain (confidence level: 100%)
domain0zi.wildc0ast.ru
ClearFake payload delivery domain (confidence level: 100%)
domaind038t.wildc0ast.ru
ClearFake payload delivery domain (confidence level: 100%)
domain73r.wildc0ast.ru
ClearFake payload delivery domain (confidence level: 100%)
domainv9y32.m1stybird.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbeta.m1stybird.ru
ClearFake payload delivery domain (confidence level: 100%)
domainz9l5.m1stybird.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqn.m1stybird.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkq.gr0upw0rk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainseris.gd
Mirai botnet C2 domain (confidence level: 100%)
domain7juhe.gr0upw0rk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainohbro.krebstresser.st
Aisuru botnet C2 domain (confidence level: 100%)
domaingx0tr.gr0upw0rk.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindelta.gr0upw0rk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfjhk.snowtrace.ru
ClearFake payload delivery domain (confidence level: 100%)
domain68.snowtrace.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwne.snowtrace.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindcv.snowtrace.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindecryn.decor1cry5t.ru
ClearFake payload delivery domain (confidence level: 100%)
domainocryl.decor1cry5t.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindrift5.decor1cry5t.ru
ClearFake payload delivery domain (confidence level: 100%)
domainunionserver.duckdns.org
AsyncRAT botnet C2 domain (confidence level: 100%)
domainyoucool12334213213-43544.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainyoucool12334213213-42391.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainyoucool12334213213-62107.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainyoucool12334213213-52394.portmap.hos
Quasar RAT botnet C2 domain (confidence level: 100%)
domaincoolboy123123431-41087.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainvelorn.decor1cry5t.ru
ClearFake payload delivery domain (confidence level: 100%)
domainuuuucome.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domaintalcry.decor1cry5t.ru
ClearFake payload delivery domain (confidence level: 100%)
domaina23.nbdsnb2.top
FatalRat botnet C2 domain (confidence level: 100%)
domainbryuk.b2ptb1ryuk.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintapel1.b2ptb1ryuk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainptarb.b2ptb1ryuk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrybuk7.b2ptb1ryuk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnebpt.b2ptb1ryuk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfulen.fu1lneve7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainabqsales.com
KongTuke payload delivery domain (confidence level: 100%)
domainnevar.fu1lneve7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlumen7.fu1lneve7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflevin.fu1lneve7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainuvelf1.fu1lneve7.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintrs.jyhsolucion.ar
Vidar botnet C2 domain (confidence level: 100%)
domaintrs.whitehallalliance.co.uk
Vidar botnet C2 domain (confidence level: 100%)
domainsevray.seven5pr2y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspryn.seven5pr2y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpravy2.seven5pr2y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvenpry.seven5pr2y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsevyn5.seven5pr2y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbefrin.be8ref7ain.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrainel.be8ref7ain.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbilling.keywordmatters.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainbreez5.be8ref7ain.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrefayn.be8ref7ain.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbenra8.be8ref7ain.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindeepem.de5per5eem.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindepra.de5per5eem.ru
ClearFake payload delivery domain (confidence level: 100%)
domainperen5.de5per5eem.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindemure.de5per5eem.ru
ClearFake payload delivery domain (confidence level: 100%)
domainderv1n.de5per5eem.ru
ClearFake payload delivery domain (confidence level: 100%)
domainemail.meta-email.online
Unknown malware botnet C2 domain (confidence level: 100%)
domainauthor.auth0r1etter.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlettyr.auth0r1etter.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrhet1c.auth0r1etter.ru
ClearFake payload delivery domain (confidence level: 100%)
domaininkset.auth0r1etter.ru
ClearFake payload delivery domain (confidence level: 100%)
domainquill5.auth0r1etter.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbaryan.ba8ryanhe7d.ru
ClearFake payload delivery domain (confidence level: 100%)
domainranhed.ba8ryanhe7d.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbayen5.ba8ryanhe7d.ru
ClearFake payload delivery domain (confidence level: 100%)
domainharbyn.ba8ryanhe7d.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrya7nd.ba8ryanhe7d.ru
ClearFake payload delivery domain (confidence level: 100%)
domainabstra.abstractm1s5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstract.abstractm1s5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainm1stic.abstractm1s5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfilm-gear.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainchukwunwike.ydns.eu
Remcos botnet C2 domain (confidence level: 100%)
domainabsray.abstractm1s5.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintram5s.abstractm1s5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhubris.hubr1s5ajor.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsajor.hubr1s5ajor.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbrume1.hubr1s5ajor.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhusaor.hubr1s5ajor.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmajr5a.hubr1s5ajor.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincossak.cos5acklove1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlovent.cos5acklove1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainco5hue.cos5acklove1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsaclor.cos5acklove1.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincovel1.cos5acklove1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainquick.mes5yr0mp.ru
ClearFake payload delivery domain (confidence level: 100%)
domaineg.mes5yr0mp.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsilent.mes5yr0mp.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqjpc.mes5yr0mp.ru
ClearFake payload delivery domain (confidence level: 100%)
domain3zg.barg5t0get.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbird.barg5t0get.ru
ClearFake payload delivery domain (confidence level: 100%)
domain0ec.barg5t0get.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwind.barg5t0get.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzx8.a5pirbo0rda.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincloud.a5pirbo0rda.ru
ClearFake payload delivery domain (confidence level: 100%)
domainx5.a5pirbo0rda.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindark.a5pirbo0rda.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincrest.bana1ity8ed.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfield.bana1ity8ed.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvn.bana1ity8ed.ru
ClearFake payload delivery domain (confidence level: 100%)
domainy54.bana1ity8ed.ru
ClearFake payload delivery domain (confidence level: 100%)
domain11qb.deve1ins0le.ru
ClearFake payload delivery domain (confidence level: 100%)
domainz6.deve1ins0le.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingroup.deve1ins0le.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspark.deve1ins0le.ru
ClearFake payload delivery domain (confidence level: 100%)
domainla.c0ffee8rind.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintn7z.c0ffee8rind.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstone.c0ffee8rind.ru
ClearFake payload delivery domain (confidence level: 100%)
domain9gzt.c0ffee8rind.ru
ClearFake payload delivery domain (confidence level: 100%)
domain72.em1npe0ny.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnight.em1npe0ny.ru
ClearFake payload delivery domain (confidence level: 100%)

Threat ID: 692f8089619fec35b42a60bc

Added to database: 12/3/2025, 12:12:57 AM

Last enriched: 12/3/2025, 12:13:28 AM

Last updated: 12/5/2025, 1:07:56 AM

Views: 38

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats