Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2025-12-05

0
Medium
Published: Fri Dec 05 2025 (12/05/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-12-05

AI-Powered Analysis

AILast updated: 12/06/2025, 00:30:19 UTC

Technical Analysis

The threat described is a set of Indicators of Compromise (IOCs) published by ThreatFox on 2025-12-05, related to malware activities involving OSINT (Open Source Intelligence), network activity, and payload delivery. The data lacks detailed technical indicators such as specific malware families, attack vectors, or affected software versions. There are no known exploits in the wild, no patches available, and no CVEs or CWEs associated with this threat. The threat level is rated as medium, with a threatLevel metric of 2 and distribution metric of 3, indicating moderate dissemination potential. The absence of detailed indicators and affected versions suggests this is an intelligence feed update rather than a newly discovered vulnerability or active exploit campaign. The focus on OSINT and network activity implies that the threat actors may be leveraging publicly available information to deliver payloads, possibly through phishing, watering hole attacks, or other network-based delivery methods. The lack of authentication or user interaction details limits the ability to assess exploitation complexity. Overall, this represents a moderate risk malware-related threat that organizations should monitor through threat intelligence platforms and network defenses.

Potential Impact

For European organizations, the impact of this threat is potentially moderate due to its classification as malware involving payload delivery via network activity. If exploited, it could lead to unauthorized access, data exfiltration, or disruption of services depending on the payload's nature. However, the lack of known exploits in the wild and absence of specific affected software versions reduce immediate risk. Organizations relying heavily on OSINT tools or those with extensive network exposure may face increased risk of targeted payload delivery attempts. The threat could impact confidentiality and integrity if successful payload delivery leads to malware execution. Availability impact appears limited based on current information. The medium severity suggests that while the threat is not critical, it warrants attention to prevent escalation or exploitation in the future. European sectors such as finance, government, and critical infrastructure, which are frequent targets of malware campaigns, should remain vigilant.

Mitigation Recommendations

1. Integrate ThreatFox and other OSINT-based threat intelligence feeds into Security Information and Event Management (SIEM) systems to detect and respond to emerging IOCs promptly. 2. Enhance network monitoring to identify unusual payload delivery attempts, including anomalous traffic patterns and suspicious connections. 3. Implement strict email and web filtering policies to reduce the risk of phishing or watering hole attacks that could deliver malware payloads. 4. Conduct regular threat hunting exercises focusing on network activity and payload delivery vectors to identify potential compromises early. 5. Maintain updated endpoint detection and response (EDR) solutions capable of detecting unknown or emerging malware behaviors. 6. Educate staff on recognizing social engineering tactics that may be used to facilitate payload delivery. 7. Employ network segmentation to limit lateral movement if a payload is successfully delivered. 8. Since no patches are available, focus on detection and containment strategies rather than remediation via updates. 9. Collaborate with national cybersecurity centers and information sharing organizations to stay informed about evolving threats and mitigation best practices.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
ce86af89-1ffa-48bd-a461-e2a35ba9a68c
Original Timestamp
1764979386

Indicators of Compromise

File

ValueDescriptionCopy
file195.2.70.190
AdaptixC2 botnet C2 server (confidence level: 99%)
file176.117.107.18
Remcos botnet C2 server (confidence level: 100%)
file162.243.28.13
AsyncRAT botnet C2 server (confidence level: 100%)
file134.122.200.237
DCRat botnet C2 server (confidence level: 100%)
file212.11.64.108
Unknown malware botnet C2 server (confidence level: 100%)
file93.113.180.31
AdaptixC2 botnet C2 server (confidence level: 100%)
file45.138.16.81
Mirai botnet C2 server (confidence level: 75%)
file194.26.192.195
Mirai botnet C2 server (confidence level: 75%)
file23.132.164.55
PureLogs Stealer botnet C2 server (confidence level: 100%)
file116.230.254.66
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.108.72.53
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.235.73.228
Cobalt Strike botnet C2 server (confidence level: 100%)
file79.110.52.181
Remcos botnet C2 server (confidence level: 100%)
file144.172.110.144
Remcos botnet C2 server (confidence level: 100%)
file101.99.75.185
Remcos botnet C2 server (confidence level: 100%)
file106.14.116.244
Unknown malware botnet C2 server (confidence level: 100%)
file45.141.86.16
Quasar RAT botnet C2 server (confidence level: 100%)
file94.154.32.99
Venom RAT botnet C2 server (confidence level: 100%)
file134.122.200.240
DCRat botnet C2 server (confidence level: 100%)
file134.122.200.244
DCRat botnet C2 server (confidence level: 100%)
file103.177.47.79
Meterpreter botnet C2 server (confidence level: 100%)
file85.120.229.147
Mirai botnet C2 server (confidence level: 80%)
file23.132.164.56
PureLogs Stealer botnet C2 server (confidence level: 100%)
file192.3.27.141
Remcos botnet C2 server (confidence level: 100%)
file38.181.23.21
ValleyRAT botnet C2 server (confidence level: 100%)
file38.181.23.21
ValleyRAT botnet C2 server (confidence level: 100%)
file38.181.23.21
ValleyRAT botnet C2 server (confidence level: 100%)
file8.134.131.92
Cobalt Strike botnet C2 server (confidence level: 100%)
file181.215.18.78
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.138.7.174
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.109.157.54
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.93.9.43
Cobalt Strike botnet C2 server (confidence level: 100%)
file87.120.254.220
Cobalt Strike botnet C2 server (confidence level: 100%)
file176.65.148.57
Mirai botnet C2 server (confidence level: 75%)
file119.29.236.125
Cobalt Strike botnet C2 server (confidence level: 100%)
file37.120.206.165
Remcos botnet C2 server (confidence level: 100%)
file194.26.192.197
Remcos botnet C2 server (confidence level: 100%)
file67.219.100.49
Unknown malware botnet C2 server (confidence level: 100%)
file103.177.47.246
Meterpreter botnet C2 server (confidence level: 100%)
file100.31.161.125
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.158
Meterpreter botnet C2 server (confidence level: 100%)
file54.234.147.68
Meterpreter botnet C2 server (confidence level: 100%)
file54.234.147.68
Meterpreter botnet C2 server (confidence level: 100%)
file54.234.147.68
Meterpreter botnet C2 server (confidence level: 100%)
file54.234.147.68
Meterpreter botnet C2 server (confidence level: 100%)
file54.234.147.68
Meterpreter botnet C2 server (confidence level: 100%)
file54.234.147.68
Meterpreter botnet C2 server (confidence level: 100%)
file182.254.146.29
Meterpreter botnet C2 server (confidence level: 100%)
file158.94.210.88
Mirai botnet C2 server (confidence level: 80%)
file148.178.33.50
DeimosC2 botnet C2 server (confidence level: 75%)
file161.35.64.250
Sliver botnet C2 server (confidence level: 75%)
file59.13.206.75
DeimosC2 botnet C2 server (confidence level: 75%)
file91.99.140.177
Brute Ratel C4 botnet C2 server (confidence level: 75%)
file46.62.240.212
Vidar botnet C2 server (confidence level: 100%)
file43.249.175.89
Cobalt Strike botnet C2 server (confidence level: 75%)
file156.234.121.183
Cobalt Strike botnet C2 server (confidence level: 75%)
file91.219.237.165
XWorm botnet C2 server (confidence level: 100%)
file31.44.184.52
Orcus RAT botnet C2 server (confidence level: 50%)
file194.67.71.113
Orcus RAT botnet C2 server (confidence level: 50%)
file185.53.179.136
Orcus RAT botnet C2 server (confidence level: 50%)
file158.160.193.205
Cobalt Strike botnet C2 server (confidence level: 75%)
file8.137.161.14
Cobalt Strike botnet C2 server (confidence level: 100%)
file185.196.8.109
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.55
Cobalt Strike botnet C2 server (confidence level: 100%)
file68.64.176.19
Cobalt Strike botnet C2 server (confidence level: 100%)
file195.20.17.237
Sliver botnet C2 server (confidence level: 90%)
file118.107.25.243
Unknown malware botnet C2 server (confidence level: 100%)
file15.207.27.164
Unknown malware botnet C2 server (confidence level: 100%)
file20.114.49.195
Unknown malware botnet C2 server (confidence level: 100%)
file51.195.223.85
Unknown malware botnet C2 server (confidence level: 100%)
file4.187.235.187
Unknown malware botnet C2 server (confidence level: 100%)
file52.233.86.40
Unknown malware botnet C2 server (confidence level: 100%)
file123.56.92.251
Unknown malware botnet C2 server (confidence level: 100%)
file45.141.27.233
XWorm botnet C2 server (confidence level: 100%)
file96.44.154.209
XWorm botnet C2 server (confidence level: 100%)
file194.164.33.16
Remcos botnet C2 server (confidence level: 100%)
file37.156.8.199
Meterpreter botnet C2 server (confidence level: 100%)
file156.226.183.249
Ghost RAT botnet C2 server (confidence level: 100%)
file49.232.40.212
Cobalt Strike botnet C2 server (confidence level: 75%)
file77.110.125.185
PureLogs Stealer botnet C2 server (confidence level: 100%)
file45.153.34.118
NjRAT botnet C2 server (confidence level: 100%)
file85.17.239.78
RedLine Stealer botnet C2 server (confidence level: 100%)
file43.160.202.246
Meterpreter botnet C2 server (confidence level: 75%)
file121.127.41.143
Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%)
file85.187.200.250
Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%)
file156.251.180.132
GhostSocks botnet C2 server (confidence level: 100%)
file36.140.162.173
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.94.133.100
Cobalt Strike botnet C2 server (confidence level: 100%)
file91.92.242.66
Latrodectus botnet C2 server (confidence level: 100%)
file86.106.85.179
Sliver botnet C2 server (confidence level: 100%)
file34.12.225.149
Unknown malware botnet C2 server (confidence level: 100%)
file23.227.196.62
AdaptixC2 botnet C2 server (confidence level: 100%)
file188.165.150.96
RedLine Stealer botnet C2 server (confidence level: 100%)
file162.216.243.228
Remcos botnet C2 server (confidence level: 100%)
file193.233.198.22
Vidar botnet C2 server (confidence level: 100%)
file185.196.10.54
Vidar botnet C2 server (confidence level: 100%)
file93.88.204.5
Mirai botnet C2 server (confidence level: 75%)
file79.250.141.94
XWorm botnet C2 server (confidence level: 100%)
file194.5.99.117
Remcos botnet C2 server (confidence level: 100%)
file185.177.59.178
AsyncRAT botnet C2 server (confidence level: 100%)
file185.177.59.178
AsyncRAT botnet C2 server (confidence level: 100%)
file185.177.59.178
Quasar RAT botnet C2 server (confidence level: 100%)
file108.61.127.94
pupy botnet C2 server (confidence level: 75%)
file159.198.66.244
BianLian botnet C2 server (confidence level: 75%)
file183.60.6.229
DeimosC2 botnet C2 server (confidence level: 75%)
file188.4.158.48
QakBot botnet C2 server (confidence level: 75%)
file195.201.5.23
DeimosC2 botnet C2 server (confidence level: 75%)
file20.205.162.42
Unknown malware botnet C2 server (confidence level: 75%)
file5.2.78.212
DeimosC2 botnet C2 server (confidence level: 75%)
file51.178.52.32
Sliver botnet C2 server (confidence level: 75%)
file156.234.145.43
Cobalt Strike botnet C2 server (confidence level: 100%)
file194.87.54.250
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.167
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.40
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.38
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.78
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.14
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.178
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.92
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.89
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.70
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.58
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.16
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.73
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.10
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.17
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.7
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.19
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.71
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.42
Cobalt Strike botnet C2 server (confidence level: 100%)
file154.12.90.150
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.47
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.6
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.87
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.216.163
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.82
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.85
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.74
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.79
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.69
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.20
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.188
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.30
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.15
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.5
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.94
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.168
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.61
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.24
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.90
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.44
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.18
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.72
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.23
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.181
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.62
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.49
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.45
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.35
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.91
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.67
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.162
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.59
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.66
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.75
Cobalt Strike botnet C2 server (confidence level: 100%)
file193.135.174.51
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.83
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.13
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.88
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.161
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.163
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.2
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.60
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.12
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.171
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.3
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.163.211
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.165
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.76
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.50
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.68
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.27
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.56
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.21
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.8
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.175
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.81
Cobalt Strike botnet C2 server (confidence level: 100%)
file138.226.236.42
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.77
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.180
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.176
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.173
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.39
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.170
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.37
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.9
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.11
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.65
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.169
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.25
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.166
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.57
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.184
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.177
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.48
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.190
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.29
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.4
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.34
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.183
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.1
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.26
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.41
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.22
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.54
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.138.7.174
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.179
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.86
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.80
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.164
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.84
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.174
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.28
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.93
Cobalt Strike botnet C2 server (confidence level: 100%)
file155.94.170.180
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.64.52.181
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.64.52.161
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.101.220.244
GobRAT botnet C2 server (confidence level: 100%)
file124.198.131.41
Remcos botnet C2 server (confidence level: 100%)
file45.141.215.25
Remcos botnet C2 server (confidence level: 100%)
file195.20.17.49
Sliver botnet C2 server (confidence level: 100%)
file85.113.70.180
Unknown malware botnet C2 server (confidence level: 100%)
file154.36.175.48
Unknown malware botnet C2 server (confidence level: 100%)
file113.45.28.96
Unknown malware botnet C2 server (confidence level: 100%)
file45.61.150.98
Unknown malware botnet C2 server (confidence level: 100%)
file8.148.211.238
Unknown malware botnet C2 server (confidence level: 100%)
file156.239.254.100
Unknown malware botnet C2 server (confidence level: 100%)
file38.60.203.146
Unknown malware botnet C2 server (confidence level: 100%)
file45.77.71.144
Unknown malware botnet C2 server (confidence level: 100%)
file146.103.126.229
SectopRAT botnet C2 server (confidence level: 100%)
file45.59.122.235
SectopRAT botnet C2 server (confidence level: 100%)
file18.194.57.25
Unknown malware botnet C2 server (confidence level: 100%)
file182.123.76.141
Quasar RAT botnet C2 server (confidence level: 100%)
file181.162.142.203
Quasar RAT botnet C2 server (confidence level: 100%)
file177.124.72.24
Havoc botnet C2 server (confidence level: 100%)
file54.166.235.66
Meterpreter botnet C2 server (confidence level: 100%)
file50.114.206.110
XWorm botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash443
AdaptixC2 botnet C2 server (confidence level: 99%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash5010
AsyncRAT botnet C2 server (confidence level: 100%)
hash65503
DCRat botnet C2 server (confidence level: 100%)
hash5555
Unknown malware botnet C2 server (confidence level: 100%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 100%)
hash8443
Mirai botnet C2 server (confidence level: 75%)
hash8443
Mirai botnet C2 server (confidence level: 75%)
hash5763
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash12949
Unknown malware botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Venom RAT botnet C2 server (confidence level: 100%)
hash65503
DCRat botnet C2 server (confidence level: 100%)
hash65503
DCRat botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash1024
Mirai botnet C2 server (confidence level: 80%)
hash6538
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash446
ValleyRAT botnet C2 server (confidence level: 100%)
hash448
ValleyRAT botnet C2 server (confidence level: 100%)
hash442
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash5000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash6969
Mirai botnet C2 server (confidence level: 75%)
hash31303
Cobalt Strike botnet C2 server (confidence level: 100%)
hash57742
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash20256
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash830
Meterpreter botnet C2 server (confidence level: 100%)
hash1080
Meterpreter botnet C2 server (confidence level: 100%)
hash3280
Meterpreter botnet C2 server (confidence level: 100%)
hash4730
Meterpreter botnet C2 server (confidence level: 100%)
hash8080
Meterpreter botnet C2 server (confidence level: 100%)
hash25930
Meterpreter botnet C2 server (confidence level: 100%)
hash8000
Meterpreter botnet C2 server (confidence level: 100%)
hash1312
Mirai botnet C2 server (confidence level: 80%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
Sliver botnet C2 server (confidence level: 75%)
hash9100
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
Brute Ratel C4 botnet C2 server (confidence level: 75%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash7777
Cobalt Strike botnet C2 server (confidence level: 75%)
hash7777
Cobalt Strike botnet C2 server (confidence level: 75%)
hash6262
XWorm botnet C2 server (confidence level: 100%)
hash50625
Orcus RAT botnet C2 server (confidence level: 50%)
hash50625
Orcus RAT botnet C2 server (confidence level: 50%)
hash50625
Orcus RAT botnet C2 server (confidence level: 50%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash33998
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2095
Cobalt Strike botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 90%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash4443
Unknown malware botnet C2 server (confidence level: 100%)
hash4433
Unknown malware botnet C2 server (confidence level: 100%)
hash6000
XWorm botnet C2 server (confidence level: 100%)
hash51994
XWorm botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash9927
Meterpreter botnet C2 server (confidence level: 100%)
hash6000
Ghost RAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash22100
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash9878
NjRAT botnet C2 server (confidence level: 100%)
hash55615
RedLine Stealer botnet C2 server (confidence level: 100%)
hash80
Meterpreter botnet C2 server (confidence level: 75%)
hash25461
Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%)
hash4807
Loki Password Stealer (PWS) botnet C2 server (confidence level: 75%)
hash10000
GhostSocks botnet C2 server (confidence level: 100%)
hash8088
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8081
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash42415
AdaptixC2 botnet C2 server (confidence level: 100%)
hash1912
RedLine Stealer botnet C2 server (confidence level: 100%)
hash1804
Remcos botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash3785
Mirai botnet C2 server (confidence level: 75%)
hash55667
XWorm botnet C2 server (confidence level: 100%)
hash6790
Remcos botnet C2 server (confidence level: 100%)
hash43520
AsyncRAT botnet C2 server (confidence level: 100%)
hash51820
AsyncRAT botnet C2 server (confidence level: 100%)
hash4444
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
pupy botnet C2 server (confidence level: 75%)
hash443
BianLian botnet C2 server (confidence level: 75%)
hash10250
DeimosC2 botnet C2 server (confidence level: 75%)
hash995
QakBot botnet C2 server (confidence level: 75%)
hash8384
DeimosC2 botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash8384
DeimosC2 botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash20911
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8978
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4434
GobRAT botnet C2 server (confidence level: 100%)
hash5000
Remcos botnet C2 server (confidence level: 100%)
hash4040
Remcos botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Quasar RAT botnet C2 server (confidence level: 100%)
hash8080
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash1911
Meterpreter botnet C2 server (confidence level: 100%)
hash7031
XWorm botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://theharadamethod.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://lcontrols6.ru/videos.html
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://coinmarketsap.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://giooga.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://eso.fwf.temporary.site/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://mail.heartofthepiedmont.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://bn.automanpk.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://bn.btreena.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://www.vyaparionline.org/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://tcsecurity.top/
SpyNote botnet C2 (confidence level: 50%)
urlhttps://111.253.220.24/
SpyNote botnet C2 (confidence level: 50%)
urlhttps://fact-2012.jp/shopdetail/authentic/f10273645
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://www.socalvc.com/featured-builds/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://trendgenicssports.com
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://teluguboxoffice.com
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://hxingsoft.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://vk.automanpk.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://vk.btreena.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://193.233.198.22/
Vidar botnet C2 (confidence level: 100%)
urlhttps://185.196.10.54/
Vidar botnet C2 (confidence level: 100%)
urlhttps://sessionsverificatise.live
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://sessionsverificatse.live
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://195.133.9.111/swear.odd
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols1.ru/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols2.ru/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols3.ru/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols4.ru/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://content-distribution-v2.pro
Stealc botnet C2 (confidence level: 100%)
urlhttps://lcontrols5.ru/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols7.ru/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols8.ru/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols9.ru/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols10.ru/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://hotelmegestore.com/carp/zeez/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttp://weibilt.com/ruinli/futurema98/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttp://sigiindserv.com/loip89o/kuo988llk/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttp://198.50.187.116/done/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttp://buckpull.ru/fiv/jays/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttp://xandrae.ml/rave/jake/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttps://lcontrol-1.online/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols9.online/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols8.online/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols7.online/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols6.online/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols5.online/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols4.online/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols3.online/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttps://lcontrols2.online/videos.html
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://193.37.69.43:95/suof
Cobalt Strike botnet C2 (confidence level: 75%)
urlhttp://dll32s.lat/ms/index.php
Amadey botnet C2 (confidence level: 100%)

Domain

ValueDescriptionCopy
domainnova.brightf1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domainx5ust.windshift.ru
ClearFake payload delivery domain (confidence level: 100%)
domainma.windshift.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfrost.windshift.ru
ClearFake payload delivery domain (confidence level: 100%)
domaini2.windshift.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmist.riverl1ght.ru
ClearFake payload delivery domain (confidence level: 100%)
domainox.riverl1ght.ru
ClearFake payload delivery domain (confidence level: 100%)
domainb0.riverl1ght.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincrest.riverl1ght.ru
ClearFake payload delivery domain (confidence level: 100%)
domainss7e.softr1ver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkbbet777.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainmalware.kbbet777.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainphishing.kbbet777.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainhouse.softr1ver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlight.softr1ver.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintrail.softr1ver.ru
ClearFake payload delivery domain (confidence level: 100%)
domaing5wyk.s0ftbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsecretcryptos.com
Unknown malware payload delivery domain (confidence level: 100%)
domain4vc.s0ftbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspark.s0ftbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainleaf.s0ftbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwww.vxucqb.dpdns.org
Cobalt Strike botnet C2 domain (confidence level: 75%)
domaincloud.silverh1ll.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8q1qk.silverh1ll.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrequest.affiliatesalesagent.com
FAKEUPDATES botnet C2 domain (confidence level: 100%)
domainfqz.silverh1ll.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwind.silverh1ll.ru
ClearFake payload delivery domain (confidence level: 100%)
domain4zt.n1ghtstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainocean.n1ghtstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsoft.n1ghtstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindrv.n1ghtstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflame.softcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsun.softcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domain1u.softcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincloud.softcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbright.m1stysun.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyoeo7.m1stysun.ru
ClearFake payload delivery domain (confidence level: 100%)
domainidsb.m1stysun.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhuh7f.m1stysun.ru
ClearFake payload delivery domain (confidence level: 100%)
domain7zos4.rainb1te.ru
ClearFake payload delivery domain (confidence level: 100%)
domainriver.rainb1te.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbridge.rainb1te.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmonbondns.duckdns.org
CyberGate botnet C2 domain (confidence level: 100%)
domainclients.enigmasolutions.xyz
NetWire RC botnet C2 domain (confidence level: 100%)
domainwild.rainb1te.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingamma.st0neforest.ru
ClearFake payload delivery domain (confidence level: 100%)
domain738n.st0neforest.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindelta.st0neforest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnight.st0neforest.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincrystal.f1rebyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmm.f1rebyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrange.f1rebyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainw2z.f1rebyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwomp.datasurge.vip
Mirai botnet C2 domain (confidence level: 100%)
domaingatw7.cloudm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainc1m.cloudm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsilent.cloudm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnimeshpatel.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainmalware.nimeshpatel.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domain6mfff.cloudm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkla.deepc1iff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmint.deepc1iff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshadow.deepc1iff.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindjv.deepc1iff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbn.automanpk.com
Vidar botnet C2 domain (confidence level: 100%)
domainbn.btreena.com
Vidar botnet C2 domain (confidence level: 100%)
domainhdzr.wildrange.ru
ClearFake payload delivery domain (confidence level: 100%)
domain6p.wildrange.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstone.wildrange.ru
ClearFake payload delivery domain (confidence level: 100%)
domainb9j.wildrange.ru
ClearFake payload delivery domain (confidence level: 100%)
domainm0tad.crystalwind.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintv.crystalwind.ru
ClearFake payload delivery domain (confidence level: 100%)
domain7h7gd.crystalwind.ru
ClearFake payload delivery domain (confidence level: 100%)
domainomega.crystalwind.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbrownandgraymusic.com
AsyncRAT botnet C2 domain (confidence level: 50%)
domaingatex.brownandgraymusic.com
AsyncRAT botnet C2 domain (confidence level: 50%)
domainmyfile.mywire.org
AsyncRAT botnet C2 domain (confidence level: 50%)
domaintelechea123.dynuddns.com
DCRat botnet C2 domain (confidence level: 50%)
domaindraft22.redirectme.net
Mirai botnet C2 domain (confidence level: 50%)
domain50625.client.sudorat.ru
Orcus RAT botnet C2 domain (confidence level: 50%)
domain50625.client.sudorat.top
Orcus RAT botnet C2 domain (confidence level: 50%)
domainelastolutdoc.duckdns.org
Remcos botnet C2 domain (confidence level: 50%)
domaineltesoro000.dynuddns.com
Remcos botnet C2 domain (confidence level: 50%)
domain56p3d.darkc0re.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhobmjoi.click
Lumma Stealer botnet C2 domain (confidence level: 50%)
domainnmj.darkc0re.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbeta.darkc0re.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhcinz.darkc0re.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlk.cl0udwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainar0r8.cl0udwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvk.automanpk.com
Vidar botnet C2 domain (confidence level: 100%)
domainvk.btreena.com
Vidar botnet C2 domain (confidence level: 100%)
domainzkc.cl0udwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainr8uw.cl0udwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainps31j.r1verstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintd.r1verstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine2cw.r1verstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmedloqservices.com
XWorm botnet C2 domain (confidence level: 100%)
domainledivineenfant-60344.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainsky.r1verstone.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflare.shadowstream.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsbh.shadowstream.ru
ClearFake payload delivery domain (confidence level: 100%)
domain0up.shadowstream.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstorm.shadowstream.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfrost.m1ntbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhill.m1ntbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domainm3.m1ntbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingsj.m1ntbyte.ru
ClearFake payload delivery domain (confidence level: 100%)
domain326.softw1nd.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincp.softw1nd.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvla6j.softw1nd.ru
ClearFake payload delivery domain (confidence level: 100%)
domain0vp7.softw1nd.ru
ClearFake payload delivery domain (confidence level: 100%)
domainib.nightc0de.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhz7en.nightc0de.ru
ClearFake payload delivery domain (confidence level: 100%)
domainz38u.nightc0de.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindc.nightc0de.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyt6sz.windbr1dge.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsvqwb.windbr1dge.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwave.windbr1dge.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfd.windbr1dge.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnova.darkh1ll.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxd.darkh1ll.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqualitia.testingweblink.com
Havoc botnet C2 domain (confidence level: 100%)
domainconquestcourier.testingweblink.com
Havoc botnet C2 domain (confidence level: 100%)
domainbuzzglobal.testingweblink.com
Havoc botnet C2 domain (confidence level: 100%)
domainsci.fern-estates.com
Unknown malware botnet C2 domain (confidence level: 100%)
domaingraph.fern-estates.com
Unknown malware botnet C2 domain (confidence level: 100%)
domaino.fern-estates.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainsso.fern-estates.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainpas.fern-estates.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainoutk.fern-estates.com
Unknown malware botnet C2 domain (confidence level: 100%)
domaindods.fern-estates.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainiqurf.darkh1ll.ru
ClearFake payload delivery domain (confidence level: 100%)
domainh3.darkh1ll.ru
ClearFake payload delivery domain (confidence level: 100%)
domainforest.firecrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrzv.firecrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwju.firecrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindxtt.firecrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domain39.silentm1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvt.silentm1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domain69.silentm1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domain33wk.silentm1st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainua7.st0rmwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainreduction-atlas-services-mechanisms.trycloudflare.com
Unknown malware payload delivery domain (confidence level: 100%)
domainsessionsverificatise.live
Unknown malware payload delivery domain (confidence level: 100%)
domainsessionsverificatse.live
Unknown malware payload delivery domain (confidence level: 100%)
domaineg1.st0rmwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domain100testtt.duckdns.org
XWorm botnet C2 domain (confidence level: 100%)
domainwrufkhnwc.localto.net
XWorm botnet C2 domain (confidence level: 100%)
domainprivatedns.b3tter.online
XWorm botnet C2 domain (confidence level: 100%)
domainmike-dozens.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainhppro1.hpnu.cn
Quasar RAT botnet C2 domain (confidence level: 100%)
domainlcontrols10.ru
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrols9.ru
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrols8.ru
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrols7.ru
Unknown malware payload delivery domain (confidence level: 100%)
domainlinhxasro.com
Mirai botnet C2 domain (confidence level: 100%)
domainlcontrols6.ru
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrols5.ru
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrols4.ru
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrol-1.online
Unknown malware payload delivery domain (confidence level: 100%)
domain2ro.st0rmwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlcontrols9.online
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrols8.online
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrols7.online
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrols6.online
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrols5.online
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrols4.online
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrols3.online
Unknown malware payload delivery domain (confidence level: 100%)
domainlcontrols2.online
Unknown malware payload delivery domain (confidence level: 100%)
domainr1.st0rmwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domaind10.oceanflare.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingrqd.oceanflare.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2m42p.oceanflare.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxt5t8.oceanflare.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhill.bi2sedm0uth.ru
ClearFake payload delivery domain (confidence level: 100%)
domainry.bi2sedm0uth.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintg.bi2sedm0uth.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlight.bi2sedm0uth.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintur.agr0chem1nter.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspark.agr0chem1nter.ru
ClearFake payload delivery domain (confidence level: 100%)
domainalpha.agr0chem1nter.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbright.agr0chem1nter.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfrost.ei8htyern1k.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8r3y.ei8htyern1k.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwild.ei8htyern1k.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpb4.ei8htyern1k.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstone.buddco1lect0r.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine37.buddco1lect0r.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindark.buddco1lect0r.ru
ClearFake payload delivery domain (confidence level: 100%)
domainclear.buddco1lect0r.ru
ClearFake payload delivery domain (confidence level: 100%)
domain9wf.re1iabteady.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflame.re1iabteady.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzmj0.re1iabteady.ru
ClearFake payload delivery domain (confidence level: 100%)
domain6cm1.re1iabteady.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbridge.st2rudmu7t.ru
ClearFake payload delivery domain (confidence level: 100%)
domainocean.st2rudmu7t.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwave.st2rudmu7t.ru
ClearFake payload delivery domain (confidence level: 100%)
domain0m95l.st2rudmu7t.ru
ClearFake payload delivery domain (confidence level: 100%)
domain0icfl.getr18ht.ru
ClearFake payload delivery domain (confidence level: 100%)
domainat0.getr18ht.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8s.getr18ht.ru
ClearFake payload delivery domain (confidence level: 100%)
domainguard.getr18ht.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincwtw5.f2rcegro0m.ru
ClearFake payload delivery domain (confidence level: 100%)

Threat ID: 69337586f88dbe026c314958

Added to database: 12/6/2025, 12:15:02 AM

Last enriched: 12/6/2025, 12:30:19 AM

Last updated: 12/6/2025, 4:28:25 AM

Views: 13

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats