Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2025-12-12

0
Medium
Published: Fri Dec 12 2025 (12/12/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-12-12

AI-Powered Analysis

AILast updated: 12/13/2025, 00:04:19 UTC

Technical Analysis

This threat report from the ThreatFox MISP feed provides a collection of Indicators of Compromise (IOCs) related to malware activities observed or predicted for the date 2025-12-12. The threat is categorized under OSINT (Open Source Intelligence), network activity, and payload delivery, indicating that it involves the monitoring of network traffic and potentially malicious payload transmissions. However, the report lacks specific details such as affected software versions, concrete technical indicators, or exploit mechanisms. No patches or mitigations are currently available, and there are no known active exploits in the wild. The threat level is assessed as medium, reflecting a moderate risk based on the available intelligence. The absence of CWEs and detailed technical indicators suggests this is an intelligence feed update rather than a new vulnerability or exploit. The data is tagged with TLP:WHITE, indicating it is intended for broad distribution and use in defensive measures. Overall, this information serves as a situational awareness tool for security teams to enhance detection capabilities and prepare for potential malware-related network threats.

Potential Impact

For European organizations, the impact of this threat is currently limited due to the lack of active exploits and specific affected products or versions. However, the presence of IOCs related to network activity and payload delivery means that organizations could face risks from malware infections if these indicators correspond to emerging or ongoing campaigns. The medium severity suggests a moderate potential for disruption, data compromise, or network intrusion if the threat evolves. Organizations relying heavily on OSINT tools or those with extensive network exposure might be more susceptible to related attacks. Since no patches or direct mitigations are available, the impact is primarily on detection and response capabilities. Failure to incorporate these IOCs into monitoring systems could delay identification of malicious activity, increasing the risk of successful intrusions or data breaches.

Mitigation Recommendations

European organizations should integrate the provided IOCs into their existing security monitoring and threat intelligence platforms to enhance detection of related malware activity. Network traffic should be closely monitored for anomalies matching the threat indicators, and endpoint detection and response (EDR) tools should be updated with the latest intelligence feeds. Organizations should conduct regular threat hunting exercises focusing on payload delivery mechanisms and suspicious network behaviors. Since no patches are available, emphasis should be placed on proactive detection, segmentation of critical networks, and strict access controls to limit lateral movement in case of compromise. Collaboration with national and European cybersecurity centers to share and receive updated intelligence is recommended. Additionally, organizations should review and update incident response plans to address potential malware infections indicated by these IOCs.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
86ad6f8d-d434-4c84-a991-498f692890df
Original Timestamp
1765584186

Indicators of Compromise

Domain

ValueDescriptionCopy
domaingov.hanel.work
Vidar botnet C2 domain (confidence level: 100%)
domainmicroservice-update-s1-bucket.cc
Amatera payload delivery domain (confidence level: 100%)
domainmicroservice-update-s2-bucket.cc
Amatera payload delivery domain (confidence level: 100%)
domainapi-w11c.onrender.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainqwg6.orbshackle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshackle.twig-mantle.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindlnd.twig-mantle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbf1.twig-mantle.ru
ClearFake payload delivery domain (confidence level: 100%)
domaini4o3.twig-mantle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqmolq.saffrondent.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpq.saffrondent.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsn7.saffrondent.ru
ClearFake payload delivery domain (confidence level: 100%)
domaind8iw.saffrondent.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2njv.saffron-dent.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincobble.saffron-dent.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjitter.saffron-dent.ru
ClearFake payload delivery domain (confidence level: 100%)
domainukd0.saffron-dent.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqk8q.cloudpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbright.cloudpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domain7iwp.cloudpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domain4b.cloudpeak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsnow.br1ghtstorm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainc2.tiktok-js.top
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainup.mcprotocol.cn
Cobalt Strike botnet C2 domain (confidence level: 75%)
domaina72o.br1ghtstorm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnkpoor.sa.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindownload.nkpoor.sa.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaink1v5q.br1ghtstorm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbreeze.br1ghtstorm.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintur.stonec0re.ru
ClearFake payload delivery domain (confidence level: 100%)
domainocean.stonec0re.ru
ClearFake payload delivery domain (confidence level: 100%)
domain69z.stonec0re.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincwscj.stonec0re.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintestcuncr.testingweblink.com
Havoc botnet C2 domain (confidence level: 100%)
domainhill.s0ftcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindh28.s0ftcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstorm.s0ftcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsun.s0ftcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainp1fb9.l1ghtshore.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincr.l1ghtshore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainomega.l1ghtshore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainr8x.l1ghtshore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbeta.skyf1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domain6rpmj.skyf1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domainx93.skyf1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwave.skyf1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxew2z.dr1ftshade.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhalahtyb-45632.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainhalahtyb-41206.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainmariajose12.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainmedcom.it.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainmalware.medcom.it.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainquality.it.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainmalware.quality.it.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainrange.dr1ftshade.ru
ClearFake payload delivery domain (confidence level: 100%)
domainebsk.dr1ftshade.ru
ClearFake payload delivery domain (confidence level: 100%)
domaineia.dr1ftshade.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindamysa10.top
CryptBot botnet C2 domain (confidence level: 50%)
domainsarefy07.top
CryptBot botnet C2 domain (confidence level: 50%)
domainsarjeb09.top
CryptBot botnet C2 domain (confidence level: 50%)
domaingoogle.motchilltv.red
DCRat botnet C2 domain (confidence level: 50%)
domaingugugulol.kenkejai.com
Mirai botnet C2 domain (confidence level: 50%)
domaincountry-tex.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 50%)
domainwwexp.com
FAKEUPDATES payload delivery domain (confidence level: 50%)
domaintotalservices.info
Unknown malware botnet C2 domain (confidence level: 50%)
domainbroughservice.info
Unknown malware botnet C2 domain (confidence level: 50%)
domaintheoyservices.info
Unknown malware botnet C2 domain (confidence level: 50%)
domainexcesswintex.info
Unknown malware botnet C2 domain (confidence level: 50%)
domainbrityservice.info
Unknown malware botnet C2 domain (confidence level: 50%)
domainbijoyshare.buzz
Unknown malware botnet C2 domain (confidence level: 50%)
domainsharetobijoy.buzz
Unknown malware botnet C2 domain (confidence level: 50%)
domainapi.htscefh.com
Unknown Loader botnet C2 domain (confidence level: 50%)
domainapp.enzirt.com
Unknown Loader botnet C2 domain (confidence level: 50%)
domainapi.qtss.cc
Unknown malware botnet C2 domain (confidence level: 50%)
domainvps-zap812595-1.zap-srv.com
Unknown malware botnet C2 domain (confidence level: 50%)
domainhelp.093214.xyz
Unknown malware botnet C2 domain (confidence level: 50%)
domainkeep.camdvr.org
Unknown malware botnet C2 domain (confidence level: 50%)
domainbrands.khaitara.com
Unknown malware botnet C2 domain (confidence level: 50%)
domainbridge.cleardawn.ru
ClearFake payload delivery domain (confidence level: 100%)
domain60sek.cleardawn.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine5w.cleardawn.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbamboopaw2021.sbs
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainnova.cleardawn.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsky.frostbranch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainffmg.frostbranch.ru
ClearFake payload delivery domain (confidence level: 100%)
domaind5.frostbranch.ru
ClearFake payload delivery domain (confidence level: 100%)
domain0s.frostbranch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyljy.m1stleaf.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqo1u.m1stleaf.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincwt.m1stleaf.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincrest.m1stleaf.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8l8gr.clearh0st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainriver.clearh0st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmint.clearh0st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainforest.clearh0st.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkp3uw.f0xwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domain554r5.f0xwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmist.f0xwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjjt.f0xwave.ru
ClearFake payload delivery domain (confidence level: 100%)
domain3gky.forestcl0ud.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhost.forestcl0ud.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine08z3.forestcl0ud.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzgeg.forestcl0ud.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindrift.clears0ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domain3e.clears0ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjt77.clears0ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfox.clears0ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshore.mistyshore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainue.mistyshore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbaritale.com
Matanbuchus botnet C2 domain (confidence level: 75%)
domainq71t.mistyshore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainz24rf.mistyshore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfield.deepbreez3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstone.deepbreez3.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8wp1.deepbreez3.ru
ClearFake payload delivery domain (confidence level: 100%)
domaink38.deepbreez3.ru
ClearFake payload delivery domain (confidence level: 100%)
domainregister.spc.jp.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domains9i01.mounta1npath.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincore.mounta1npath.ru
ClearFake payload delivery domain (confidence level: 100%)
domainneurolattice.com
Matanbuchus botnet C2 domain (confidence level: 100%)
domainasirojointofucks.com
Latrodectus botnet C2 domain (confidence level: 100%)
domainnh60c.mounta1npath.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwind.mounta1npath.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnight.snowcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainraisinc.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaingenustt.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainservilg.click
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainfixedwr.click
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaindhulhxu.click
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincacodsq.click
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainvz.snowcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzwo.snowcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkevincheat.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domain7yyu6.snowcrest.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingamma.oceandrift.ru
ClearFake payload delivery domain (confidence level: 100%)
domainburadakimvar.xyz
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaingsv54.oceandrift.ru
ClearFake payload delivery domain (confidence level: 100%)
domainic7y.oceandrift.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincwci.oceandrift.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintp.cloudreach.ru
ClearFake payload delivery domain (confidence level: 100%)
domains9ps.cloudreach.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingastroikoliojauiol.com
Latrodectus botnet C2 domain (confidence level: 100%)
domainjiontrusdergaseol.com
Latrodectus botnet C2 domain (confidence level: 100%)
domainaniradodokloiure.com
Latrodectus botnet C2 domain (confidence level: 100%)
domainihokolkasdiemh.com
Latrodectus botnet C2 domain (confidence level: 100%)
domainhcg.cloudreach.ru
ClearFake payload delivery domain (confidence level: 100%)
domainoput.brightgate.ru
ClearFake payload delivery domain (confidence level: 100%)
domaini3o.brightgate.ru
ClearFake payload delivery domain (confidence level: 100%)
domaint84g.brightgate.ru
ClearFake payload delivery domain (confidence level: 100%)
domainintercttp.xyz
Unknown malware botnet C2 domain (confidence level: 100%)
domainclear.brightgate.ru
ClearFake payload delivery domain (confidence level: 100%)
domainuqdz.nightl1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainitaly-divine.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domainbranch.nightl1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzj3m0.nightl1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincontent-v2-verisoiu.icu
Stealc botnet C2 domain (confidence level: 100%)
domainjoyeriatauro.com
Stealc botnet C2 domain (confidence level: 100%)
domainpeak.nightl1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainz9s.starl1tewave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainalpha.starl1tewave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmouc.starl1tewave.ru
ClearFake payload delivery domain (confidence level: 100%)
domain1tza.starl1tewave.ru
ClearFake payload delivery domain (confidence level: 100%)
domaini6.co0perport5.ru
ClearFake payload delivery domain (confidence level: 100%)
domain9vq0tzgx64793.cfc-execute.bj.baidubce.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domain8cu.co0perport5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainleqdger.click
ClearFake payload delivery domain (confidence level: 100%)
domainwind.co0perport5.ru
ClearFake payload delivery domain (confidence level: 100%)
domaininter.co0perport5.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2vv6.adm1rep1ay.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsdsu.adm1rep1ay.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhdbg.adm1rep1ay.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxk8.adm1rep1ay.ru
ClearFake payload delivery domain (confidence level: 100%)
domainentire-so.gl.at.ply.gg
XWorm botnet C2 domain (confidence level: 100%)
domaindad9idois-44752.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domain8.tcp.clar.top
XWorm botnet C2 domain (confidence level: 100%)
domain1.tcp.clar.io
XWorm botnet C2 domain (confidence level: 100%)
domainsodendick-39162.portmap.host
Quasar RAT botnet C2 domain (confidence level: 100%)
domainau.1nju5tred.ru
ClearFake payload delivery domain (confidence level: 100%)
domainriver.1nju5tred.ru
ClearFake payload delivery domain (confidence level: 100%)
domain6t5.1nju5tred.ru
ClearFake payload delivery domain (confidence level: 100%)
domainomega.1nju5tred.ru
ClearFake payload delivery domain (confidence level: 100%)
domaink5i.pr2ctsu7v.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbeta.pr2ctsu7v.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflame.pr2ctsu7v.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindur71.pr2ctsu7v.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhill.n0uvpu7itan.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfdvfr.n0uvpu7itan.ru
ClearFake payload delivery domain (confidence level: 100%)
domain6xy2.n0uvpu7itan.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshort.n0uvpu7itan.ru
ClearFake payload delivery domain (confidence level: 100%)
domainarabsea.testingweblink.com
Havoc botnet C2 domain (confidence level: 100%)
domainadfs.abdullah-sharif.com
Havoc botnet C2 domain (confidence level: 100%)
domainfpt.dfp.abdullah-sharif.com
Havoc botnet C2 domain (confidence level: 100%)
domainyl90o.sh0rtwe5ter.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlq.sh0rtwe5ter.ru
ClearFake payload delivery domain (confidence level: 100%)
domainz4l.sh0rtwe5ter.ru
ClearFake payload delivery domain (confidence level: 100%)
domain3w.sh0rtwe5ter.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincore.interk2ts2v.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvdf.interk2ts2v.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindndhub.xyz
ClearFake payload delivery domain (confidence level: 100%)
domainbbpa.interk2ts2v.ru
ClearFake payload delivery domain (confidence level: 100%)
domainq1.interk2ts2v.ru
ClearFake payload delivery domain (confidence level: 100%)
domainm9dbmhskb.localto.net
XWorm botnet C2 domain (confidence level: 75%)
domainfield.b1o0dmanneq.ru
ClearFake payload delivery domain (confidence level: 100%)
domainp8.b1o0dmanneq.ru
ClearFake payload delivery domain (confidence level: 100%)
domainepfe.b1o0dmanneq.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsabr6.b1o0dmanneq.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmint.b0okca7niv.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzeq3.b0okca7niv.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbyte.b0okca7niv.ru
ClearFake payload delivery domain (confidence level: 100%)
domainneuro.b0okca7niv.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2ic.f1fthudde7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainember.f1fthudde7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjtp4r.f1fthudde7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspark.f1fthudde7.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintrace.c0nju8maraf.ru
ClearFake payload delivery domain (confidence level: 100%)
domainguard.c0nju8maraf.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwild.c0nju8maraf.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstorm.c0nju8maraf.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyzmbi.neur0l5uptn.ru
ClearFake payload delivery domain (confidence level: 100%)

File

ValueDescriptionCopy
file157.180.22.193
Vidar botnet C2 server (confidence level: 100%)
file158.94.210.44
Mirai botnet C2 server (confidence level: 80%)
file95.182.101.109
Stealc botnet C2 server (confidence level: 100%)
file213.176.16.165
Amatera botnet C2 server (confidence level: 100%)
file94.183.183.52
Amatera botnet C2 server (confidence level: 100%)
file206.206.127.137
Unknown RAT botnet C2 server (confidence level: 100%)
file172.111.150.202
Remcos botnet C2 server (confidence level: 100%)
file23.17.234.198
Unknown malware botnet C2 server (confidence level: 100%)
file80.69.88.61
Unknown malware botnet C2 server (confidence level: 100%)
file193.233.87.70
Mirai botnet C2 server (confidence level: 75%)
file142.252.220.135
Mirai botnet C2 server (confidence level: 75%)
file156.234.216.187
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.97.113.42
Cobalt Strike botnet C2 server (confidence level: 75%)
file67.219.102.244
Cobalt Strike botnet C2 server (confidence level: 75%)
file84.200.17.174
XWorm botnet C2 server (confidence level: 75%)
file198.251.84.61
Stealc botnet C2 server (confidence level: 100%)
file23.226.48.206
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.248.214.10
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.37
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.138.159.121
Cobalt Strike botnet C2 server (confidence level: 100%)
file119.45.250.8
Cobalt Strike botnet C2 server (confidence level: 100%)
file80.78.30.76
Sliver botnet C2 server (confidence level: 100%)
file34.239.178.12
Sliver botnet C2 server (confidence level: 100%)
file107.172.31.102
AsyncRAT botnet C2 server (confidence level: 100%)
file62.164.177.31
SectopRAT botnet C2 server (confidence level: 100%)
file62.164.177.31
SectopRAT botnet C2 server (confidence level: 100%)
file102.117.170.95
Unknown malware botnet C2 server (confidence level: 100%)
file91.204.74.131
Havoc botnet C2 server (confidence level: 100%)
file103.245.231.83
AdaptixC2 botnet C2 server (confidence level: 100%)
file107.149.142.169
AdaptixC2 botnet C2 server (confidence level: 100%)
file168.245.200.34
Meterpreter botnet C2 server (confidence level: 100%)
file13.238.96.31
Empire Downloader botnet C2 server (confidence level: 100%)
file37.77.107.49
Unknown malware botnet C2 server (confidence level: 100%)
file91.202.233.215
Remcos botnet C2 server (confidence level: 100%)
file195.85.207.132
DCRat botnet C2 server (confidence level: 50%)
file116.103.90.20
XWorm botnet C2 server (confidence level: 50%)
file193.27.90.80
Unknown malware botnet C2 server (confidence level: 75%)
file213.209.143.34
Mirai botnet C2 server (confidence level: 80%)
file144.202.27.199
Sliver botnet C2 server (confidence level: 50%)
file15.204.59.20
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.207.208.83
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.148.211.47
Cobalt Strike botnet C2 server (confidence level: 100%)
file36.253.9.57
Cobalt Strike botnet C2 server (confidence level: 100%)
file216.126.239.157
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.192.248.45
Cobalt Strike botnet C2 server (confidence level: 100%)
file195.177.94.107
Unknown malware botnet C2 server (confidence level: 75%)
file192.210.215.210
Cobalt Strike botnet C2 server (confidence level: 100%)
file121.43.230.164
Cobalt Strike botnet C2 server (confidence level: 100%)
file38.54.88.89
Cobalt Strike botnet C2 server (confidence level: 100%)
file178.16.53.165
Latrodectus botnet C2 server (confidence level: 100%)
file178.16.53.175
Latrodectus botnet C2 server (confidence level: 100%)
file44.200.209.5
Sliver botnet C2 server (confidence level: 100%)
file137.131.241.10
Sliver botnet C2 server (confidence level: 100%)
file44.200.209.5
Sliver botnet C2 server (confidence level: 100%)
file178.16.53.119
AsyncRAT botnet C2 server (confidence level: 100%)
file89.125.209.173
Unknown malware botnet C2 server (confidence level: 100%)
file45.156.27.23
Unknown malware botnet C2 server (confidence level: 100%)
file3.85.126.181
Meterpreter botnet C2 server (confidence level: 100%)
file3.85.126.181
Meterpreter botnet C2 server (confidence level: 100%)
file89.111.149.164
Unknown malware botnet C2 server (confidence level: 100%)
file77.83.240.196
Aisuru botnet C2 server (confidence level: 75%)
file45.92.218.126
Aisuru botnet C2 server (confidence level: 75%)
file77.83.240.194
Aisuru botnet C2 server (confidence level: 75%)
file77.83.240.193
Aisuru botnet C2 server (confidence level: 75%)
file137.131.241.10
Sliver botnet C2 server (confidence level: 75%)
file64.111.92.248
Sliver botnet C2 server (confidence level: 75%)
file208.87.205.54
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.92.196.59
Cobalt Strike botnet C2 server (confidence level: 100%)
file117.72.99.21
Cobalt Strike botnet C2 server (confidence level: 100%)
file208.69.78.184
Sliver botnet C2 server (confidence level: 90%)
file167.71.90.208
Unknown malware botnet C2 server (confidence level: 100%)
file45.130.166.85
Unknown malware botnet C2 server (confidence level: 100%)
file144.172.114.13
Unknown malware botnet C2 server (confidence level: 100%)
file202.189.12.194
Quasar RAT botnet C2 server (confidence level: 100%)
file125.168.249.139
Unknown malware botnet C2 server (confidence level: 100%)
file75.133.120.54
Unknown malware botnet C2 server (confidence level: 100%)
file75.66.72.160
Unknown malware botnet C2 server (confidence level: 100%)
file24.235.137.164
Unknown malware botnet C2 server (confidence level: 100%)
file91.158.199.43
Unknown malware botnet C2 server (confidence level: 100%)
file67.254.169.34
Unknown malware botnet C2 server (confidence level: 100%)
file78.27.85.26
Unknown malware botnet C2 server (confidence level: 100%)
file107.179.200.87
Unknown malware botnet C2 server (confidence level: 100%)
file46.162.105.194
Unknown malware botnet C2 server (confidence level: 100%)
file136.24.74.5
Unknown malware botnet C2 server (confidence level: 100%)
file175.182.177.198
Unknown malware botnet C2 server (confidence level: 100%)
file24.47.51.37
Unknown malware botnet C2 server (confidence level: 100%)
file125.224.153.221
Unknown malware botnet C2 server (confidence level: 100%)
file220.246.204.92
Unknown malware botnet C2 server (confidence level: 100%)
file66.190.34.226
Unknown malware botnet C2 server (confidence level: 100%)
file47.239.201.21
Unknown malware botnet C2 server (confidence level: 100%)
file206.189.160.102
Unknown malware botnet C2 server (confidence level: 100%)
file195.88.24.103
Unknown malware botnet C2 server (confidence level: 100%)
file165.227.48.115
Unknown malware botnet C2 server (confidence level: 100%)
file82.156.210.64
Unknown malware botnet C2 server (confidence level: 100%)
file167.99.26.105
Unknown malware botnet C2 server (confidence level: 100%)
file3.148.221.7
Unknown malware botnet C2 server (confidence level: 100%)
file111.230.103.245
Unknown malware botnet C2 server (confidence level: 100%)
file156.234.216.182
Cobalt Strike botnet C2 server (confidence level: 100%)
file89.149.243.170
Remcos botnet C2 server (confidence level: 100%)
file81.92.219.143
Remcos botnet C2 server (confidence level: 100%)
file190.255.86.132
Remcos botnet C2 server (confidence level: 100%)
file45.156.87.240
AsyncRAT botnet C2 server (confidence level: 100%)
file213.176.79.226
SectopRAT botnet C2 server (confidence level: 100%)
file217.60.249.161
SectopRAT botnet C2 server (confidence level: 100%)
file185.208.156.159
Unknown malware botnet C2 server (confidence level: 100%)
file34.227.242.206
Meterpreter botnet C2 server (confidence level: 100%)
file213.35.114.163
Meterpreter botnet C2 server (confidence level: 100%)
file162.215.130.152
Unknown malware botnet C2 server (confidence level: 100%)
file45.141.26.243
XWorm botnet C2 server (confidence level: 100%)
file162.251.123.238
XWorm botnet C2 server (confidence level: 100%)
file166.88.185.88
XWorm botnet C2 server (confidence level: 100%)
file177.136.203.81
XWorm botnet C2 server (confidence level: 100%)
file208.91.189.160
XWorm botnet C2 server (confidence level: 100%)
file151.241.100.116
AsyncRAT botnet C2 server (confidence level: 100%)
file138.226.236.29
Vidar botnet C2 server (confidence level: 100%)
file38.49.210.241
PureLogs Stealer botnet C2 server (confidence level: 100%)
file165.22.117.74
Aisuru botnet C2 server (confidence level: 75%)
file68.183.155.83
Aisuru botnet C2 server (confidence level: 75%)
file161.35.152.74
Aisuru botnet C2 server (confidence level: 75%)
file165.227.65.246
Aisuru botnet C2 server (confidence level: 75%)
file143.110.132.186
Aisuru botnet C2 server (confidence level: 75%)
file165.227.28.253
Aisuru botnet C2 server (confidence level: 75%)
file157.245.123.120
Aisuru botnet C2 server (confidence level: 75%)
file134.209.91.203
Aisuru botnet C2 server (confidence level: 75%)
file178.62.204.148
Aisuru botnet C2 server (confidence level: 75%)
file134.209.204.135
Aisuru botnet C2 server (confidence level: 75%)
file165.22.47.134
Aisuru botnet C2 server (confidence level: 75%)
file167.172.60.110
Aisuru botnet C2 server (confidence level: 75%)
file104.131.168.18
Aisuru botnet C2 server (confidence level: 75%)
file147.182.216.151
Aisuru botnet C2 server (confidence level: 75%)
file188.166.23.66
Aisuru botnet C2 server (confidence level: 75%)
file159.65.85.62
Aisuru botnet C2 server (confidence level: 75%)
file64.227.93.213
Aisuru botnet C2 server (confidence level: 75%)
file206.189.5.192
Aisuru botnet C2 server (confidence level: 75%)
file142.93.254.14
Aisuru botnet C2 server (confidence level: 75%)
file174.138.7.252
Aisuru botnet C2 server (confidence level: 75%)
file45.141.215.133
XenoRAT botnet C2 server (confidence level: 100%)
file147.185.221.31
XWorm botnet C2 server (confidence level: 100%)
file185.91.127.175
XWorm botnet C2 server (confidence level: 100%)
file157.245.180.129
Aisuru botnet C2 server (confidence level: 75%)
file134.209.27.68
Aisuru botnet C2 server (confidence level: 75%)
file167.172.205.144
Aisuru botnet C2 server (confidence level: 75%)
file68.183.6.51
Aisuru botnet C2 server (confidence level: 75%)
file159.65.205.44
Aisuru botnet C2 server (confidence level: 75%)
file142.93.135.82
Aisuru botnet C2 server (confidence level: 75%)
file206.189.198.144
Aisuru botnet C2 server (confidence level: 75%)
file165.22.136.66
Aisuru botnet C2 server (confidence level: 75%)
file178.128.2.44
Aisuru botnet C2 server (confidence level: 75%)
file134.209.89.14
Aisuru botnet C2 server (confidence level: 75%)
file8.134.55.194
Cobalt Strike botnet C2 server (confidence level: 100%)
file204.77.130.20
Cobalt Strike botnet C2 server (confidence level: 100%)
file212.64.215.198
DarkComet botnet C2 server (confidence level: 100%)
file62.60.135.119
SectopRAT botnet C2 server (confidence level: 100%)
file199.101.111.96
Meterpreter botnet C2 server (confidence level: 100%)
file52.91.221.78
Meterpreter botnet C2 server (confidence level: 100%)
file52.91.221.78
Meterpreter botnet C2 server (confidence level: 100%)
file100.31.160.236
Meterpreter botnet C2 server (confidence level: 100%)
file98.93.225.126
Meterpreter botnet C2 server (confidence level: 100%)
file144.22.251.16
Unknown malware botnet C2 server (confidence level: 100%)
file18.140.146.3
Unknown malware botnet C2 server (confidence level: 100%)
file208.123.119.198
Mirai botnet C2 server (confidence level: 75%)
file208.123.119.236
Mirai botnet C2 server (confidence level: 75%)
file216.189.145.14
Mirai botnet C2 server (confidence level: 75%)
file208.123.119.235
Mirai botnet C2 server (confidence level: 75%)
file68.183.176.122
Aisuru botnet C2 server (confidence level: 75%)
file206.189.127.228
Aisuru botnet C2 server (confidence level: 75%)
file139.59.39.130
Aisuru botnet C2 server (confidence level: 75%)
file157.245.146.209
Aisuru botnet C2 server (confidence level: 75%)
file143.110.188.80
Aisuru botnet C2 server (confidence level: 75%)
file139.59.125.228
Aisuru botnet C2 server (confidence level: 75%)
file209.97.182.186
Aisuru botnet C2 server (confidence level: 75%)
file139.59.78.96
Aisuru botnet C2 server (confidence level: 75%)
file188.166.181.135
Aisuru botnet C2 server (confidence level: 75%)
file164.90.203.98
Aisuru botnet C2 server (confidence level: 75%)
file91.92.243.254
Loki Password Stealer (PWS) botnet C2 server (confidence level: 50%)
file138.68.136.84
Aisuru botnet C2 server (confidence level: 75%)
file124.220.231.155
Cobalt Strike botnet C2 server (confidence level: 75%)
file2.56.165.27
XWorm botnet C2 server (confidence level: 100%)
file80.211.137.34
XWorm botnet C2 server (confidence level: 100%)
file165.227.234.4
Aisuru botnet C2 server (confidence level: 75%)
file109.145.252.9
QakBot botnet C2 server (confidence level: 75%)
file136.0.157.158
AsyncRAT botnet C2 server (confidence level: 75%)
file184.174.32.240
Unknown malware botnet C2 server (confidence level: 75%)
file31.220.89.71
DeimosC2 botnet C2 server (confidence level: 75%)
file64.227.55.187
Aisuru botnet C2 server (confidence level: 75%)
file206.189.66.166
Aisuru botnet C2 server (confidence level: 75%)
file147.182.138.189
Aisuru botnet C2 server (confidence level: 75%)
file192.241.141.249
Aisuru botnet C2 server (confidence level: 75%)
file143.110.168.110
Aisuru botnet C2 server (confidence level: 75%)
file165.22.156.232
Aisuru botnet C2 server (confidence level: 75%)
file167.99.207.16
Aisuru botnet C2 server (confidence level: 75%)
file157.230.131.89
Aisuru botnet C2 server (confidence level: 75%)
file167.172.56.254
Aisuru botnet C2 server (confidence level: 75%)
file195.177.94.233
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.45
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.35
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.66
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.101.173
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.145.34
Cobalt Strike botnet C2 server (confidence level: 100%)
file119.91.141.52
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.216.171
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.252.86
Cobalt Strike botnet C2 server (confidence level: 100%)
file39.104.81.39
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.92.196.59
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.255.30.4
Cobalt Strike botnet C2 server (confidence level: 100%)
file38.246.245.82
Cobalt Strike botnet C2 server (confidence level: 100%)
file31.97.76.25
Remcos botnet C2 server (confidence level: 100%)
file186.169.56.216
Remcos botnet C2 server (confidence level: 100%)
file158.94.210.63
Remcos botnet C2 server (confidence level: 100%)
file83.136.254.247
Sliver botnet C2 server (confidence level: 100%)
file1.52.28.182
Quasar RAT botnet C2 server (confidence level: 100%)
file89.58.41.159
MimiKatz botnet C2 server (confidence level: 100%)
file89.58.41.159
MimiKatz botnet C2 server (confidence level: 100%)
file199.101.111.205
Meterpreter botnet C2 server (confidence level: 100%)
file34.238.116.93
Meterpreter botnet C2 server (confidence level: 100%)
file199.101.111.188
Meterpreter botnet C2 server (confidence level: 100%)
file54.82.226.86
Meterpreter botnet C2 server (confidence level: 100%)
file54.82.226.86
Meterpreter botnet C2 server (confidence level: 100%)
file54.82.226.86
Meterpreter botnet C2 server (confidence level: 100%)
file72.62.60.228
Empire Downloader botnet C2 server (confidence level: 100%)
file162.215.130.152
Unknown malware botnet C2 server (confidence level: 100%)
file80.211.137.34
XWorm botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash443
Vidar botnet C2 server (confidence level: 100%)
hash1312
Mirai botnet C2 server (confidence level: 80%)
hash22804099ed114502613561e19c39b08d85532366de6aa7dc7b648da51d4a7515
Quasar RAT payload (confidence level: 100%)
hashca49f69a007de870c0ae4c9cabaa4707ad73c9735d643c7bfcdc2a4cf2ba9765
Quasar RAT payload (confidence level: 100%)
hashde5fcb3128ab96a7c5e45d93ed01498102aacde90552b9bffc581fa94d5c8e6a
Coinminer payload (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash443
Amatera botnet C2 server (confidence level: 100%)
hash443
Amatera botnet C2 server (confidence level: 100%)
hash8041
Unknown RAT botnet C2 server (confidence level: 100%)
hash3872
Remcos botnet C2 server (confidence level: 100%)
hash3000
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Mirai botnet C2 server (confidence level: 75%)
hash8443
Mirai botnet C2 server (confidence level: 75%)
hash43131
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash53
Cobalt Strike botnet C2 server (confidence level: 75%)
hash6000
XWorm botnet C2 server (confidence level: 75%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash43131
Cobalt Strike botnet C2 server (confidence level: 100%)
hash43131
Cobalt Strike botnet C2 server (confidence level: 100%)
hash43131
Cobalt Strike botnet C2 server (confidence level: 100%)
hash88
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash8080
Sliver botnet C2 server (confidence level: 100%)
hash80
AsyncRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash15647
SectopRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash4321
AdaptixC2 botnet C2 server (confidence level: 100%)
hash4444
AdaptixC2 botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash88
Empire Downloader botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash1337
DCRat botnet C2 server (confidence level: 50%)
hash4411
XWorm botnet C2 server (confidence level: 50%)
hash5010
Unknown malware botnet C2 server (confidence level: 75%)
hash59666
Mirai botnet C2 server (confidence level: 80%)
hash31337
Sliver botnet C2 server (confidence level: 50%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9999
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8081
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8088
Cobalt Strike botnet C2 server (confidence level: 100%)
hash56238
Unknown malware botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash443
Latrodectus botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash8080
Sliver botnet C2 server (confidence level: 100%)
hash4444
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash1913
Meterpreter botnet C2 server (confidence level: 100%)
hash1963
Meterpreter botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8443
Sliver botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash81
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9999
Cobalt Strike botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 90%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash5566
Quasar RAT botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8033
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash10813
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash8085
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash8712
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Remcos botnet C2 server (confidence level: 100%)
hash60000
Remcos botnet C2 server (confidence level: 100%)
hash5060
Remcos botnet C2 server (confidence level: 100%)
hash777
AsyncRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash5555
Unknown malware botnet C2 server (confidence level: 100%)
hash33070
Meterpreter botnet C2 server (confidence level: 100%)
hash8888
Meterpreter botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash6000
XWorm botnet C2 server (confidence level: 100%)
hash5353
XWorm botnet C2 server (confidence level: 100%)
hash8000
XWorm botnet C2 server (confidence level: 100%)
hash7050
XWorm botnet C2 server (confidence level: 100%)
hash6922
XWorm botnet C2 server (confidence level: 100%)
hash2700
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash22100
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash4444
XenoRAT botnet C2 server (confidence level: 100%)
hash63171
XWorm botnet C2 server (confidence level: 100%)
hash1330
XWorm botnet C2 server (confidence level: 100%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4444
DarkComet botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash21
Meterpreter botnet C2 server (confidence level: 100%)
hash771
Meterpreter botnet C2 server (confidence level: 100%)
hash53695
Meterpreter botnet C2 server (confidence level: 100%)
hash20547
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Mirai botnet C2 server (confidence level: 75%)
hash8443
Mirai botnet C2 server (confidence level: 75%)
hash8443
Mirai botnet C2 server (confidence level: 75%)
hash8443
Mirai botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash80
Loki Password Stealer (PWS) botnet C2 server (confidence level: 50%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash9111
XWorm botnet C2 server (confidence level: 100%)
hash3413
XWorm botnet C2 server (confidence level: 100%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash2222
QakBot botnet C2 server (confidence level: 75%)
hash7707
AsyncRAT botnet C2 server (confidence level: 75%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash8080
DeimosC2 botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8712
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8712
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8712
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8712
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8712
Cobalt Strike botnet C2 server (confidence level: 100%)
hash31303
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8712
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8712
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash30303
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash9090
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash443
Quasar RAT botnet C2 server (confidence level: 100%)
hash80
MimiKatz botnet C2 server (confidence level: 100%)
hash443
MimiKatz botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash1317
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash80
Meterpreter botnet C2 server (confidence level: 100%)
hash2380
Meterpreter botnet C2 server (confidence level: 100%)
hash8880
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Empire Downloader botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash4230
XWorm botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://lingering-my-verify-clouds-1.pages.dev/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://microservice-update-s1-bucket.cc/hollypriest.docx
Amatera payload delivery URL (confidence level: 100%)
urlhttps://api-w11c.onrender.com/api/send
Unknown Stealer botnet C2 (confidence level: 50%)
urlhttp://47.243.211.91:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://154.61.77.105:8082/
Unknown malware botnet C2 (confidence level: 50%)
urlhttp://damysa10.top/download.php?file=lv.exe
CryptBot payload delivery URL (confidence level: 50%)
urlhttp://sarefy07.top/download.php?file=lv.exe
CryptBot payload delivery URL (confidence level: 50%)
urlhttp://sarjeb09.top/download.php?file=lv.exe
CryptBot payload delivery URL (confidence level: 50%)
urlhttp://knumfl68.top/index.php
CryptBot botnet C2 (confidence level: 50%)
urlhttp://knuywu58.top/index.php
CryptBot botnet C2 (confidence level: 50%)
urlhttp://lysuht78.top/index.php
CryptBot botnet C2 (confidence level: 50%)
urlhttp://morisc07.top/index.php
CryptBot botnet C2 (confidence level: 50%)
urlhttp://morjeo05.top/index.php
CryptBot botnet C2 (confidence level: 50%)
urlhttp://morwye06.top/index.php
CryptBot botnet C2 (confidence level: 50%)
urlhttp://telegatt.top/oh12manymarty
Raccoon botnet C2 (confidence level: 50%)
urlhttp://telegin.top/oh12manymarty
Raccoon botnet C2 (confidence level: 50%)
urlhttp://telegka.top/oh12manymarty
Raccoon botnet C2 (confidence level: 50%)
urlhttps://t.me/borderxra
Raccoon botnet C2 (confidence level: 50%)
urlhttps://t.me/jredmankun
Raccoon botnet C2 (confidence level: 50%)
urlhttps://t.me/masseffectus2
Raccoon botnet C2 (confidence level: 50%)
urlhttps://t.me/oh12manymarty
Raccoon botnet C2 (confidence level: 50%)
urlhttps://t.me/takecareandkeepitup
Raccoon botnet C2 (confidence level: 50%)
urlhttps://raw.githubusercontent.com/locsucc/cac/refs/heads/master/c
XWorm botnet C2 (confidence level: 50%)
urlhttp://bamboopaw2021.sbs/b5a52ebb310b65f06dd10cfe69f72363/
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttps://roku.jnishop.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://rummagewi.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://sageproductions.tv/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://schluesselringe.de/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://red-eyesecurity.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://rummagewi.drcs-solutions.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://qka.poy.temporary.site/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://roumanie.sandierrot.fr/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://portaldesigngrafico.com.br.agenciadelivearte.com.br/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://psicologowil.com.br/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://quabala-quabala.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://shop.net-gazet.ru/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://singlevendor.ninetysix.in/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://sebastiancafe.kbral.com.br/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://teresina.oligoflora.com.br/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://syuchan.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://tanakazu1977.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://supvitalfree.verslo.io/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://stazio54.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://staging.trytebox.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://suzuya-basketball-dog-house.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://stavby.sk/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://vendamaiscomthiago.ads360imob.com.br/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://webmail.mega77b.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://webmail.giracoin.io/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://urbiagua.pt/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://teenpattijawaan.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://tes-totaleng.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://study.bisabarengoby.id/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://vegasvalleycommercial.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://wordt-ontwikkeldbe.site.tb-hosting.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://vitaricca-1.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://yellowbird.siulyn.fr/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://webdisk.kasatnews.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://whm.tamiltotamil.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://whm.umeedshiksharath.org/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://ysetechnologies.com.appniacs.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://watabaran.se/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://tlcmaui.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://quamecheng.co.zm/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://123.56.48.58:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://wooddecor.com.br.kbral.com.br/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://evanderupdate.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://code.hybclient.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://178.17.59.88/api/ntesn2qsn2usntgsnwisnjasnjisnjcsyyw3osw=
SmartLoader botnet C2 (confidence level: 75%)
urlhttps://138.226.236.29/
Vidar botnet C2 (confidence level: 100%)
urlhttps://zoomteammeeting.im/windows/invite.php
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://teaminvitemeeting.im/windows/invite.php
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://2z1alloom2.click/zoom/windows/invite.php
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://zoommeetingsetup.vip/webzu0sju/windows/invite.php
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://chandhandicrafts.com/microsoftteam/teamsfinal/teams/windows/invite.php
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://institutoalfrednobel.edu.mx/meet/567/windows/invite.php
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://ucd.ru.com/msteamss/teams/windows/invite.php
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://blvas.online/zoooom/windows/invite.php
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://prominencecleaners.com/excell/windows/invite.php
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://com-a2gamepromotwo-eg--112a2-com---ad.pages.dev/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://mart.delipack.shop/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://18plus.tiktok.market.google.cuocsong.store/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://poidx.777md.xyz/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://18plus.tiktok.market.google.2049uu.top/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://18plus.tiktok.market.google.totti911-aakk04.store/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://18plus.tiktok.market.google.976uu9.top/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://googleplaycr.pages.dev/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://play-app.huami123.online/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://18plus.tiktok.market.google.luxelockssalon.shop/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://18plus.tiktok.market.google.b44brha.top/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://18plus.tiktok.market.google.101uu6.top/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttps://18plus.tiktok.market.google.pinklotusfoundation.online/
Unknown malware payload delivery URL (confidence level: 50%)
urlhttp://91.92.243.254/kelly/five/fre.php
Loki Password Stealer (PWS) botnet C2 (confidence level: 100%)
urlhttp://77.105.161.133
Stealc botnet C2 (confidence level: 100%)
urlhttp://towerbingobongoboom.com:8080/updater?for=81d1b730207b50bc16231686b723b33f
Unknown malware botnet C2 (confidence level: 100%)

Threat ID: 693cad76b3e344112f4b8ac0

Added to database: 12/13/2025, 12:04:06 AM

Last enriched: 12/13/2025, 12:04:19 AM

Last updated: 12/14/2025, 6:57:01 PM

Views: 26

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats