Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2025-12-18

0
Medium
Published: Thu Dec 18 2025 (12/18/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-12-18

AI-Powered Analysis

AILast updated: 12/19/2025, 00:11:21 UTC

Technical Analysis

The provided information pertains to a set of ThreatFox Indicators of Compromise (IOCs) published on 2025-12-18, categorized under malware with a focus on OSINT and network activity related to payload delivery. ThreatFox is a platform that aggregates threat intelligence, including IOCs, to aid in identifying malicious activity. This particular entry lacks detailed technical specifics such as affected software versions, CVEs, or concrete exploit mechanisms. The threat is tagged as OSINT and network activity, suggesting that the threat actors may be leveraging open source intelligence techniques to identify targets or deliver payloads via network channels. The absence of known exploits in the wild and patch availability indicates that this is likely an emerging or low-confidence threat rather than an active widespread campaign. The technical details provided are minimal, with a threat level of 2 (on an unspecified scale), analysis level 1, and distribution level 3, which may imply moderate distribution but limited analysis depth. No indicators are listed, which limits actionable detection capabilities. Overall, this appears to be an intelligence update rather than a detailed vulnerability or exploit report, highlighting potential malware activity involving OSINT and network-based payload delivery methods.

Potential Impact

For European organizations, the impact of this threat is currently moderate due to the lack of specific exploit details or confirmed active campaigns. However, organizations that utilize OSINT tools or rely heavily on network-based payload delivery mechanisms could be at risk of targeted malware infections if threat actors successfully leverage these IOCs. Potential impacts include unauthorized access, data exfiltration, or disruption of network services if payload delivery leads to successful compromise. The absence of patches or known exploits suggests that mitigation relies on detection and prevention rather than remediation. European critical infrastructure, government agencies, and enterprises with significant network exposure or OSINT operations should consider this threat as a cautionary indicator to enhance monitoring and incident response capabilities. The medium severity reflects the potential for impact without current evidence of widespread exploitation.

Mitigation Recommendations

1. Integrate ThreatFox and other threat intelligence feeds into Security Information and Event Management (SIEM) systems to improve detection of related IOCs. 2. Enhance network traffic monitoring and anomaly detection to identify unusual payload delivery attempts, especially those leveraging OSINT-derived targeting. 3. Conduct regular threat hunting exercises focusing on network activity and payload delivery vectors. 4. Implement strict network segmentation and access controls to limit the spread of potential malware infections. 5. Train security teams on emerging OSINT-related threats and encourage sharing of intelligence within trusted communities. 6. Maintain up-to-date endpoint detection and response (EDR) solutions capable of identifying suspicious payload execution. 7. Develop and test incident response plans that include scenarios involving OSINT-driven malware delivery. 8. Collaborate with national cybersecurity centers and CERTs to receive timely updates and guidance on evolving threats.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
1ef0ad29-2689-4274-b15b-74b1ae93ca05
Original Timestamp
1766102588

Indicators of Compromise

File

ValueDescriptionCopy
file138.226.237.34
Vidar botnet C2 server (confidence level: 100%)
file5.59.248.136
Mirai botnet C2 server (confidence level: 80%)
file138.226.236.31
Vidar botnet C2 server (confidence level: 100%)
file107.189.20.32
SectopRAT botnet C2 server (confidence level: 100%)
file62.60.135.76
SectopRAT botnet C2 server (confidence level: 100%)
file185.39.19.89
SectopRAT botnet C2 server (confidence level: 100%)
file62.204.41.230
SectopRAT botnet C2 server (confidence level: 100%)
file62.164.177.110
SectopRAT botnet C2 server (confidence level: 100%)
file62.234.98.218
Quasar RAT botnet C2 server (confidence level: 100%)
file144.86.4.160
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file176.117.107.175
Brute Ratel C4 botnet C2 server (confidence level: 100%)
file3.10.182.215
MimiKatz botnet C2 server (confidence level: 100%)
file103.177.47.116
Meterpreter botnet C2 server (confidence level: 100%)
file3.90.3.150
Meterpreter botnet C2 server (confidence level: 100%)
file34.203.212.52
Meterpreter botnet C2 server (confidence level: 100%)
file157.230.254.1
Unknown malware botnet C2 server (confidence level: 100%)
file88.198.19.78
Unknown malware botnet C2 server (confidence level: 100%)
file45.74.9.54
AsyncRAT botnet C2 server (confidence level: 100%)
file104.37.174.77
PureLogs Stealer botnet C2 server (confidence level: 100%)
file114.66.38.114
Cobalt Strike botnet C2 server (confidence level: 75%)
file119.91.141.52
Cobalt Strike botnet C2 server (confidence level: 75%)
file110.40.137.221
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.152.211.222
Cobalt Strike botnet C2 server (confidence level: 100%)
file64.176.65.222
ShadowPad botnet C2 server (confidence level: 90%)
file54.232.144.183
Unknown malware botnet C2 server (confidence level: 100%)
file49.13.20.35
Unknown malware botnet C2 server (confidence level: 100%)
file16.171.15.200
Unknown malware botnet C2 server (confidence level: 100%)
file77.110.122.76
Hook botnet C2 server (confidence level: 100%)
file162.19.211.151
Quasar RAT botnet C2 server (confidence level: 100%)
file5.182.33.151
Havoc botnet C2 server (confidence level: 100%)
file41.141.125.97
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file8.139.6.149
AdaptixC2 botnet C2 server (confidence level: 100%)
file199.101.111.201
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.123
Meterpreter botnet C2 server (confidence level: 100%)
file199.101.111.24
Meterpreter botnet C2 server (confidence level: 100%)
file199.101.111.230
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.136
Meterpreter botnet C2 server (confidence level: 100%)
file199.101.109.34
Meterpreter botnet C2 server (confidence level: 100%)
file199.101.111.204
Meterpreter botnet C2 server (confidence level: 100%)
file199.101.111.184
Meterpreter botnet C2 server (confidence level: 100%)
file199.101.111.191
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.124
Meterpreter botnet C2 server (confidence level: 100%)
file100.42.180.19
Unknown malware botnet C2 server (confidence level: 100%)
file89.32.41.172
Mirai botnet C2 server (confidence level: 75%)
file212.108.107.132
AsyncRAT botnet C2 server (confidence level: 75%)
file212.108.107.132
AsyncRAT botnet C2 server (confidence level: 75%)
file212.108.107.132
AsyncRAT botnet C2 server (confidence level: 75%)
file91.198.166.165
Cobalt Strike botnet C2 server (confidence level: 100%)
file62.235.6.231
Cobalt Strike botnet C2 server (confidence level: 100%)
file124.223.107.73
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.41.6.36
Cobalt Strike botnet C2 server (confidence level: 100%)
file39.99.33.10
Cobalt Strike botnet C2 server (confidence level: 100%)
file95.179.244.14
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.182.125
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.109.197.75
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.41.6.34
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.41.6.39
Cobalt Strike botnet C2 server (confidence level: 100%)
file27.102.127.137
Remcos botnet C2 server (confidence level: 100%)
file80.66.72.66
Sliver botnet C2 server (confidence level: 100%)
file18.141.182.223
Sliver botnet C2 server (confidence level: 100%)
file147.28.223.190
Sliver botnet C2 server (confidence level: 100%)
file62.204.41.231
SectopRAT botnet C2 server (confidence level: 100%)
file193.233.113.157
Unknown malware botnet C2 server (confidence level: 100%)
file156.252.60.227
Unknown RAT botnet C2 server (confidence level: 100%)
file156.252.60.226
Unknown RAT botnet C2 server (confidence level: 100%)
file31.220.60.75
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.161
Meterpreter botnet C2 server (confidence level: 100%)
file3.91.39.89
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.209
Meterpreter botnet C2 server (confidence level: 100%)
file54.172.19.197
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.169
Meterpreter botnet C2 server (confidence level: 100%)
file54.235.232.174
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.108
Meterpreter botnet C2 server (confidence level: 100%)
file152.32.231.79
Empire Downloader botnet C2 server (confidence level: 100%)
file104.219.248.200
Unknown malware botnet C2 server (confidence level: 100%)
file45.66.9.193
Unknown malware botnet C2 server (confidence level: 100%)
file198.144.189.90
Mirai botnet C2 server (confidence level: 80%)
file77.42.43.16
Vidar botnet C2 server (confidence level: 100%)
file95.217.25.136
Vidar botnet C2 server (confidence level: 100%)
file80.253.249.252
Unknown malware botnet C2 server (confidence level: 75%)
file1.161.65.90
QakBot botnet C2 server (confidence level: 75%)
file107.172.67.68
Sliver botnet C2 server (confidence level: 75%)
file138.197.194.86
Eye Pyramid botnet C2 server (confidence level: 75%)
file158.94.209.119
Sliver botnet C2 server (confidence level: 75%)
file185.237.166.132
Sliver botnet C2 server (confidence level: 75%)
file2.56.178.170
DeimosC2 botnet C2 server (confidence level: 75%)
file23.227.203.12
Sliver botnet C2 server (confidence level: 75%)
file35.172.60.6
DeimosC2 botnet C2 server (confidence level: 75%)
file43.163.26.181
Sliver botnet C2 server (confidence level: 75%)
file198.135.48.127
PureLogs Stealer botnet C2 server (confidence level: 100%)
file31.56.39.76
Mirai botnet C2 server (confidence level: 75%)
file31.57.38.119
Unknown Stealer botnet C2 server (confidence level: 75%)
file31.57.38.244
Unknown Stealer botnet C2 server (confidence level: 75%)
file80.76.49.114
Unknown Stealer botnet C2 server (confidence level: 75%)
file193.26.115.116
Unknown RAT botnet C2 server (confidence level: 75%)
file5.252.153.115
Unknown malware botnet C2 server (confidence level: 75%)
file5.252.153.115
Unknown malware botnet C2 server (confidence level: 75%)
file156.234.152.173
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.152.175
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.109.105.42
Cobalt Strike botnet C2 server (confidence level: 100%)
file162.243.28.13
AsyncRAT botnet C2 server (confidence level: 100%)
file193.233.113.157
Unknown malware botnet C2 server (confidence level: 100%)
file154.61.69.121
Hook botnet C2 server (confidence level: 100%)
file3.239.18.126
Havoc botnet C2 server (confidence level: 100%)
file13.200.214.164
Havoc botnet C2 server (confidence level: 100%)
file209.38.198.46
Unknown malware botnet C2 server (confidence level: 100%)
file162.240.171.175
Unknown malware botnet C2 server (confidence level: 100%)
file172.174.58.179
Unknown malware botnet C2 server (confidence level: 100%)
file47.87.131.65
Unknown malware botnet C2 server (confidence level: 100%)
file103.144.241.101
Unknown malware botnet C2 server (confidence level: 100%)
file158.220.97.82
Unknown malware botnet C2 server (confidence level: 100%)
file138.124.67.134
Unknown malware botnet C2 server (confidence level: 100%)
file3.137.208.23
Unknown malware botnet C2 server (confidence level: 100%)
file34.180.113.8
Unknown malware botnet C2 server (confidence level: 100%)
file15.229.250.40
Unknown malware botnet C2 server (confidence level: 100%)
file52.28.83.178
Unknown malware botnet C2 server (confidence level: 100%)
file52.28.83.178
Unknown malware botnet C2 server (confidence level: 100%)
file38.55.106.173
AdaptixC2 botnet C2 server (confidence level: 75%)
file212.11.64.229
Vidar botnet C2 server (confidence level: 100%)
file138.226.237.36
Vidar botnet C2 server (confidence level: 100%)
file43.240.239.228
Cobalt Strike botnet C2 server (confidence level: 100%)
file208.91.189.89
XWorm botnet C2 server (confidence level: 100%)
file79.110.49.136
XWorm botnet C2 server (confidence level: 100%)
file208.64.33.64
Remcos botnet C2 server (confidence level: 100%)
file64.176.36.191
Sliver botnet C2 server (confidence level: 100%)
file156.252.60.230
Unknown RAT botnet C2 server (confidence level: 100%)
file103.117.149.46
Quasar RAT botnet C2 server (confidence level: 100%)
file13.220.103.98
Meterpreter botnet C2 server (confidence level: 100%)
file13.220.103.98
Meterpreter botnet C2 server (confidence level: 100%)
file176.57.70.199
Unknown malware botnet C2 server (confidence level: 100%)
file178.128.71.26
Unknown malware botnet C2 server (confidence level: 100%)
file165.73.81.241
Unknown malware botnet C2 server (confidence level: 100%)
file46.62.249.23
Unknown malware botnet C2 server (confidence level: 100%)
file159.223.160.166
Unknown malware botnet C2 server (confidence level: 100%)
file144.31.30.235
SpyNote botnet C2 server (confidence level: 100%)
file144.31.30.235
SpyNote botnet C2 server (confidence level: 100%)
file138.226.236.68
Vidar botnet C2 server (confidence level: 100%)
file77.83.39.41
RedLine Stealer botnet C2 server (confidence level: 100%)
file124.156.113.135
Cobalt Strike botnet C2 server (confidence level: 75%)
file155.102.175.145
Cobalt Strike botnet C2 server (confidence level: 75%)
file155.102.181.183
Cobalt Strike botnet C2 server (confidence level: 75%)
file155.102.4.22
Cobalt Strike botnet C2 server (confidence level: 75%)
file163.181.228.148
Cobalt Strike botnet C2 server (confidence level: 75%)
file163.181.35.203
Cobalt Strike botnet C2 server (confidence level: 75%)
file159.223.6.254
Aisuru botnet C2 server (confidence level: 75%)
file91.215.85.42
Unknown malware botnet C2 server (confidence level: 100%)
file43.240.239.251
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.64.113.151
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.93.216.2
Cobalt Strike botnet C2 server (confidence level: 100%)
file5.182.210.126
Cobalt Strike botnet C2 server (confidence level: 100%)
file110.172.104.140
Remcos botnet C2 server (confidence level: 100%)
file80.97.160.110
SectopRAT botnet C2 server (confidence level: 100%)
file176.117.107.187
Unknown malware botnet C2 server (confidence level: 100%)
file66.78.40.70
Unknown malware botnet C2 server (confidence level: 100%)
file77.93.154.243
Hook botnet C2 server (confidence level: 100%)
file151.242.152.89
Venom RAT botnet C2 server (confidence level: 100%)
file89.47.249.228
XWorm botnet C2 server (confidence level: 100%)
file3.95.198.138
Meterpreter botnet C2 server (confidence level: 100%)
file3.95.198.138
Meterpreter botnet C2 server (confidence level: 100%)
file3.95.198.138
Meterpreter botnet C2 server (confidence level: 100%)
file74.243.232.240
Cobalt Strike botnet C2 server (confidence level: 100%)
file152.32.231.79
Empire Downloader botnet C2 server (confidence level: 100%)
file213.55.93.153
Unknown malware botnet C2 server (confidence level: 100%)
file176.57.70.199
Unknown malware botnet C2 server (confidence level: 100%)
file45.66.9.193
Unknown malware botnet C2 server (confidence level: 100%)
file178.128.71.26
Unknown malware botnet C2 server (confidence level: 100%)
file213.21.229.201
Mirai botnet C2 server (confidence level: 80%)
file94.156.114.203
Unknown Stealer botnet C2 server (confidence level: 100%)
file193.233.198.221
Vidar botnet C2 server (confidence level: 100%)
file104.140.154.119
DeimosC2 botnet C2 server (confidence level: 75%)
file104.140.154.120
DeimosC2 botnet C2 server (confidence level: 75%)
file104.140.154.171
DeimosC2 botnet C2 server (confidence level: 75%)
file104.140.154.177
DeimosC2 botnet C2 server (confidence level: 75%)
file120.240.156.51
DeimosC2 botnet C2 server (confidence level: 75%)
file155.102.133.61
DeimosC2 botnet C2 server (confidence level: 75%)
file163.5.149.126
Remcos botnet C2 server (confidence level: 75%)
file45.83.31.115
Remcos botnet C2 server (confidence level: 75%)
file23.235.188.174
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.167
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.164
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.234.209.102
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.48.135.207
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.48.135.193
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.187
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.226.59.230
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.138.188.193
Cobalt Strike botnet C2 server (confidence level: 100%)
file23.235.188.190
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.48.135.220
Cobalt Strike botnet C2 server (confidence level: 100%)
file172.65.211.41
Remcos botnet C2 server (confidence level: 100%)
file23.227.202.159
Sliver botnet C2 server (confidence level: 100%)
file23.227.202.200
Sliver botnet C2 server (confidence level: 100%)
file138.197.194.86
Sliver botnet C2 server (confidence level: 100%)
file38.12.32.243
Unknown malware botnet C2 server (confidence level: 100%)
file154.61.69.121
Hook botnet C2 server (confidence level: 100%)
file74.243.232.240
Havoc botnet C2 server (confidence level: 100%)
file104.194.154.98
DCRat botnet C2 server (confidence level: 100%)
file144.172.114.205
DCRat botnet C2 server (confidence level: 100%)
file45.59.122.15
PoshC2 botnet C2 server (confidence level: 100%)
file178.200.40.30
Meterpreter botnet C2 server (confidence level: 100%)
file60.191.208.227
Meterpreter botnet C2 server (confidence level: 100%)
file147.135.254.49
Unknown malware botnet C2 server (confidence level: 100%)
file176.57.70.199
Unknown malware botnet C2 server (confidence level: 100%)
file92.60.78.221
NjRAT botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash443
Vidar botnet C2 server (confidence level: 100%)
hash3778
Mirai botnet C2 server (confidence level: 80%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash443
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash8443
Brute Ratel C4 botnet C2 server (confidence level: 100%)
hash8888
MimiKatz botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash4840
Meterpreter botnet C2 server (confidence level: 100%)
hash831
Meterpreter botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3606
AsyncRAT botnet C2 server (confidence level: 100%)
hash62520
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash88
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash30003
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
ShadowPad botnet C2 server (confidence level: 90%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8082
Hook botnet C2 server (confidence level: 100%)
hash8000
Quasar RAT botnet C2 server (confidence level: 100%)
hash80
Havoc botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash8888
AdaptixC2 botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash32465
Mirai botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 75%)
hash7707
AsyncRAT botnet C2 server (confidence level: 75%)
hash7777
AsyncRAT botnet C2 server (confidence level: 75%)
hash887747dc1687953902488489b805d965
Mirai payload (confidence level: 100%)
hashb688c22aabcd83138bba4afb9b3ef4fc
Mirai payload (confidence level: 100%)
hash2fd5481e9d20dad6d27e320d5464f71e
Mirai payload (confidence level: 100%)
hash5f4ed952e69abb337f9405352cb5cc05
Mirai payload (confidence level: 100%)
hash4cd750f32ee5d4f9e335751ae992ce64
Mirai payload (confidence level: 100%)
hash8011ed1d1851c6ae31274c2ac8edfc06
Mirai payload (confidence level: 100%)
hash95efbc9fdc5c7bcbf469de3a0cc35699
Mirai payload (confidence level: 100%)
hashbda398fcd6da2ddd4c756e7e7c47f8d8
Mirai payload (confidence level: 100%)
hashea7e4930b7506c1a5ca7fee10547ef6b
Mirai payload (confidence level: 100%)
hashdfe8d1f591d53259e573b98acb178e84
Mirai payload (confidence level: 100%)
hash3a172e3a2d330c49d7baa42ead3b6539
Mirai payload (confidence level: 100%)
hash726557aaebee929541f9c60ec86d356e
Mirai payload (confidence level: 100%)
hashbf06011784990b3cca02fe997ff9b33d
Mirai payload (confidence level: 100%)
hashd086086b35d6c2ecf60b405e79f36d05
Mirai payload (confidence level: 100%)
hash2078af54891b32ea0b1d1bf08b552fe8
Mirai payload (confidence level: 100%)
hashb89ee1304b94f0951af31433dac9a1bd
Mirai payload (confidence level: 100%)
hash34dfa5bc38b8c6108406b1e4da9a21e4
Mirai payload (confidence level: 100%)
hash51cfe61eac636aae33a88aa5f95e5185
Mirai payload (confidence level: 100%)
hash1c03d82026b6bcf5acd8fc4bcf48ed00
Mirai payload (confidence level: 100%)
hashe96073b7ed4a8eb40bed6980a287bc9f
Mirai payload (confidence level: 100%)
hashf8a70ca813a6f5123c3869d418f00fe5
Mirai payload (confidence level: 100%)
hash33435ec640fbd3451f5316c9e45d46e8
Mirai payload (confidence level: 100%)
hash9053cef2ea429339b64f3df88cad8e3f
Mirai payload (confidence level: 100%)
hash85ba20e982ed8088bb1ba7ed23b0c497
Mirai payload (confidence level: 100%)
hash9b37f3bf3b91aa4f135a6c64aba643bd
Mirai payload (confidence level: 100%)
hashb1d4739d692d70c3e715f742ac329b05
Mirai payload (confidence level: 100%)
hash5490fb81cf24a2defa87ea251f553d11
Mirai payload (confidence level: 100%)
hashcf7960034540cd25840d619702c73a26
Mirai payload (confidence level: 100%)
hashe4be95de21627b8f988ba9b55c34380c
Mirai payload (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8088
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4109
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2406
Remcos botnet C2 server (confidence level: 100%)
hash59401
Sliver botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash8080
Sliver botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash444
Unknown RAT botnet C2 server (confidence level: 100%)
hash444
Unknown RAT botnet C2 server (confidence level: 100%)
hash4444
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash1000
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash33389
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash6008
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Empire Downloader botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash37212
Mirai botnet C2 server (confidence level: 80%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash5000
Unknown malware botnet C2 server (confidence level: 75%)
hash443
QakBot botnet C2 server (confidence level: 75%)
hash443
Sliver botnet C2 server (confidence level: 75%)
hash443
Eye Pyramid botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash443
Sliver botnet C2 server (confidence level: 75%)
hash8443
DeimosC2 botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash7705
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash6969
Mirai botnet C2 server (confidence level: 75%)
hash122789db14d04b78b14c224259ab48f0489e98aa5255fd5bd6dff5c0be241b2f
Cobalt Strike payload (confidence level: 100%)
hash378afc8d85ca9a0e482c422fc63c11bbdf07f20a8f0d2a93bcf13baabb021d48
Cobalt Strike payload (confidence level: 100%)
hash7c66cbdaa10b3a0a0d7d200d2336d08fd18ec0b114e665bfb18f673b9469bdf8
Cobalt Strike payload (confidence level: 100%)
hash6767
Unknown Stealer botnet C2 server (confidence level: 75%)
hash6767
Unknown Stealer botnet C2 server (confidence level: 75%)
hash6767
Unknown Stealer botnet C2 server (confidence level: 75%)
hash8041
Unknown RAT botnet C2 server (confidence level: 75%)
hash8510
Unknown malware botnet C2 server (confidence level: 75%)
hash3058
Unknown malware botnet C2 server (confidence level: 75%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7777
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash8443
Havoc botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash18443
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash4434
AdaptixC2 botnet C2 server (confidence level: 75%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash6000
XWorm botnet C2 server (confidence level: 100%)
hash6967
XWorm botnet C2 server (confidence level: 100%)
hash2591
Remcos botnet C2 server (confidence level: 100%)
hash8000
Sliver botnet C2 server (confidence level: 100%)
hash444
Unknown RAT botnet C2 server (confidence level: 100%)
hash8085
Quasar RAT botnet C2 server (confidence level: 100%)
hash5095
Meterpreter botnet C2 server (confidence level: 100%)
hash18245
Meterpreter botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash9808
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash9898
SpyNote botnet C2 server (confidence level: 100%)
hash5214
SpyNote botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash1912
RedLine Stealer botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash3003
Unknown malware botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8099
Cobalt Strike botnet C2 server (confidence level: 100%)
hash10443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2405
Remcos botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash443
Venom RAT botnet C2 server (confidence level: 100%)
hash80
XWorm botnet C2 server (confidence level: 100%)
hash465
Meterpreter botnet C2 server (confidence level: 100%)
hash7557
Meterpreter botnet C2 server (confidence level: 100%)
hash37215
Meterpreter botnet C2 server (confidence level: 100%)
hash8000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Empire Downloader botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash1337
Mirai botnet C2 server (confidence level: 80%)
hash5000
Unknown Stealer botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash30107
DeimosC2 botnet C2 server (confidence level: 75%)
hash30107
DeimosC2 botnet C2 server (confidence level: 75%)
hash30136
DeimosC2 botnet C2 server (confidence level: 75%)
hash30133
DeimosC2 botnet C2 server (confidence level: 75%)
hash10250
DeimosC2 botnet C2 server (confidence level: 75%)
hash4506
DeimosC2 botnet C2 server (confidence level: 75%)
hash2323
Remcos botnet C2 server (confidence level: 75%)
hash4000
Remcos botnet C2 server (confidence level: 75%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash9878
Cobalt Strike botnet C2 server (confidence level: 100%)
hash1234
Remcos botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash31337
Sliver botnet C2 server (confidence level: 100%)
hash8443
Sliver botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash8080
Havoc botnet C2 server (confidence level: 100%)
hash6000
DCRat botnet C2 server (confidence level: 100%)
hash8090
DCRat botnet C2 server (confidence level: 100%)
hash443
PoshC2 botnet C2 server (confidence level: 100%)
hash4444
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash32788
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
NjRAT botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://138.226.237.34/
Vidar botnet C2 (confidence level: 100%)
urlhttp://196.251.107.4/h8jfdmdws/login.php
Amadey botnet C2 (confidence level: 100%)
urlhttps://138.226.236.31/
Vidar botnet C2 (confidence level: 100%)
urlhttps://fortwaynejubileebrontide.com/category%3aamerican_schoolteachers
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttps://mail.physioxrsize.nl/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://mail.avomawealth.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://steamcommunity.com/profiles/76561198759765485
Vidar botnet C2 (confidence level: 100%)
urlhttps://telegram.me/gal17d
Vidar botnet C2 (confidence level: 100%)
urlhttps://ala.marcialongman.com.br/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ala.cimansazan.top/
Vidar botnet C2 (confidence level: 100%)
urlhttps://77.42.43.16/
Vidar botnet C2 (confidence level: 100%)
urlhttps://95.217.25.136/
Vidar botnet C2 (confidence level: 100%)
urlhttp://80.253.249.252:5000/api/beacon
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://favashop.com.ar/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://www.utama78.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://tnsa.jp/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://worldvacationtour.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://138.226.237.36/
Vidar botnet C2 (confidence level: 100%)
urlhttps://dimelox.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://138.226.236.68/
Vidar botnet C2 (confidence level: 100%)
urlhttps://bakvau-store.evascientific.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://pri.marcialongman.com.br/
Vidar botnet C2 (confidence level: 100%)
urlhttps://pri.diamond-cutting.kiev.ua/
Vidar botnet C2 (confidence level: 100%)
urlhttps://stealer.su/login
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://77.90.53.18:1337/webhook
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttp://94.156.114.203:5000/login.php
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://193.233.198.221/
Vidar botnet C2 (confidence level: 100%)

Domain

ValueDescriptionCopy
domainpepgauge.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainpegasustour.ru
Unknown malware botnet C2 domain (confidence level: 100%)
domainegepefr.ru
Unknown malware botnet C2 domain (confidence level: 100%)
domain14emeliaterracewestroxburyma02132.su
Unknown malware botnet C2 domain (confidence level: 100%)
domain1ay20.lightst0rm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvg.lightst0rm.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindelta.lightst0rm.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine97hx.stormf0rm.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2887k.stormf0rm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxx.stormf0rm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainug3.stormf0rm.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingom.mintp1xel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainps.mintp1xel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqeu.mintp1xel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjgl.mintp1xel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbit.deepw1nd.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindark.deepw1nd.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxk8v.deepw1nd.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincrest.deepw1nd.ru
ClearFake payload delivery domain (confidence level: 100%)
domainridge.darkw1re.ru
ClearFake payload delivery domain (confidence level: 100%)
domaints.darkw1re.ru
ClearFake payload delivery domain (confidence level: 100%)
domain27.darkw1re.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlo68g.darkw1re.ru
ClearFake payload delivery domain (confidence level: 100%)
domainahp.wave5hift.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzbas.wave5hift.ru
ClearFake payload delivery domain (confidence level: 100%)
domainflare.wave5hift.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmint.wave5hift.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhth5.windl1nk.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincopper.windl1nk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpuf0.windl1nk.ru
ClearFake payload delivery domain (confidence level: 100%)
domain9x.windl1nk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainthorax.ent0molobo1t.ru
ClearFake payload delivery domain (confidence level: 100%)
domainprion5.ent0molobo1t.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlarva.ent0molobo1t.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspore.ent0molobo1t.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmyrmex3.ent0molobo1t.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingear.j1tmech2nic.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincam1.j1tmech2nic.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintorque.j1tmech2nic.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlathe.j1tmech2nic.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrhein.c2tt1eschlen.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfeld2.c2tt1eschlen.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnewslbn.publicvm.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainlbnewac1.work.gd
AsyncRAT botnet C2 domain (confidence level: 100%)
domainpfad.c2tt1eschlen.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbroth.s0uponwe2ther.ru
ClearFake payload delivery domain (confidence level: 100%)
domainladle.s0uponwe2ther.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstir3.s0uponwe2ther.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsimmer.s0uponwe2ther.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincohort.b2ckymembe7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainboberkurwa.phoneparts.icu
Mirai botnet C2 domain (confidence level: 100%)
domainstaging.pproxy1.fun
Mirai botnet C2 domain (confidence level: 100%)
domainbadge.b2ckymembe7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainapi.groksearch.net
Mirai botnet C2 domain (confidence level: 100%)
domainnnkjzfaxkjanxzk.14emeliaterracewestroxburyma02132.su
Mirai botnet C2 domain (confidence level: 100%)
domainzachebt.chachasl.de
Mirai botnet C2 domain (confidence level: 100%)
domainzachebt.groksearch.net
Mirai botnet C2 domain (confidence level: 100%)
domainrtrdedge1.samsungcdn.cloud
Mirai botnet C2 domain (confidence level: 100%)
domainfuckzachebt.meowmeowmeowmeowmeow.meow.indiahackgod.su
Mirai botnet C2 domain (confidence level: 100%)
domainsdk-dl-prod.proxiessdk.online
Mirai botnet C2 domain (confidence level: 100%)
domainsdk-dl-production.proxiessdk.store
Mirai botnet C2 domain (confidence level: 100%)
domainlol.713mtauburnctcolumbusoh43085.st
Mirai botnet C2 domain (confidence level: 100%)
domainpawsatyou.eth
Mirai botnet C2 domain (confidence level: 100%)
domainlolbroweborrowtvbro.713mtauburnctcolumbusoh43085.st
Mirai botnet C2 domain (confidence level: 100%)
domainguild2.b2ckymembe7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainroll.b2ckymembe7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmuster.b2ckymembe7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainward.obor1shwron8.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsentry5.obor1shwron8.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrampart.obor1shwron8.ru
ClearFake payload delivery domain (confidence level: 100%)
domainorgan.sv0orchond0.ru
ClearFake payload delivery domain (confidence level: 100%)
domainchord.sv0orchond0.ru
ClearFake payload delivery domain (confidence level: 100%)
domainala.marcialongman.com.br
Vidar botnet C2 domain (confidence level: 100%)
domainala.cimansazan.top
Vidar botnet C2 domain (confidence level: 100%)
domainsynap3.sv0orchond0.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlumen.sv0orchond0.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsigma.calculu5eve7y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlampweight.info
Unknown Loader botnet C2 domain (confidence level: 100%)
domaininstrumentthrone.info
Unknown Loader botnet C2 domain (confidence level: 100%)
domainrepresentativeaddition.info
Unknown Loader botnet C2 domain (confidence level: 100%)
domainlosstwig.info
Unknown Loader botnet C2 domain (confidence level: 100%)
domainnorthbox.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domaincoatberry.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domaindelta2.calculu5eve7y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainproof.calculu5eve7y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlemma.calculu5eve7y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvector.calculu5eve7y.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingrid.l2titsm1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintil3.l2titsm1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstealer.su
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainplane.l2titsm1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainriver.dunkr1n5her.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsplash.dunkr1n5her.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbrine3.dunkr1n5her.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindoc-001.filedocshaering.ru
Unknown RAT botnet C2 domain (confidence level: 100%)
domainspray.dunkr1n5her.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsiper.smartvault.com.ng
Unknown malware botnet C2 domain (confidence level: 100%)
domainnipple.smartvault.com.ng
Unknown malware botnet C2 domain (confidence level: 100%)
domaincivic.articu1urb2n.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmetro.articu1urb2n.ru
ClearFake payload delivery domain (confidence level: 100%)
domainplaza4.articu1urb2n.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzoning.articu1urb2n.ru
ClearFake payload delivery domain (confidence level: 100%)
domaininfill.articu1urb2n.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2yq4.brambleage.ru
ClearFake payload delivery domain (confidence level: 100%)
domaink3p.brambleage.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmowl1.brambleage.ru
ClearFake payload delivery domain (confidence level: 100%)
domainryosweb.com
Vidar payload delivery domain (confidence level: 100%)
domaing7t3.brambleage.ru
ClearFake payload delivery domain (confidence level: 100%)
domainz8sn.sn1pixel.ru
ClearFake payload delivery domain (confidence level: 100%)
domain4p9.sn1pixel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainu3kd.sn1pixel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbrowns.sn1pixel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainq5l.fl0watch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainv2n3.fl0watch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainimage.flash.cn.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainlark.fl0watch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainh3d9.fl0watch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainn7q.quartz-ace.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpri.marcialongman.com.br
Vidar botnet C2 domain (confidence level: 100%)
domainpri.diamond-cutting.kiev.ua
Vidar botnet C2 domain (confidence level: 100%)
domain5vg.quartz-ace.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintapes.quartz-ace.ru
ClearFake payload delivery domain (confidence level: 100%)
domainm1c8.quartz-ace.ru
ClearFake payload delivery domain (confidence level: 100%)
domainc4z.v0rtatouch.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine9h2.v0rtatouch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbrisk.v0rtatouch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainp7qk.v0rtatouch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainr8m.bramble-age.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindawn3.bramble-age.ru
ClearFake payload delivery domain (confidence level: 100%)
domaink2s9.bramble-age.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjule.bramble-age.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstar.co.com
DCRat botnet C2 domain (confidence level: 100%)
domainw3c.quartzace.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmint7.quartzace.ru
ClearFake payload delivery domain (confidence level: 100%)
domainp9fz.quartzace.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzany.quartzace.ru
ClearFake payload delivery domain (confidence level: 100%)
domainh2x.sn-1-pixel.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingleam.sn-1-pixel.ru
ClearFake payload delivery domain (confidence level: 100%)
domains7b4.sn-1-pixel.ru
ClearFake payload delivery domain (confidence level: 100%)
domaink9v3.sn-1-pixel.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmoss.picketcore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainb6n2.picketcore.ru
ClearFake payload delivery domain (confidence level: 100%)
domaint4q9.picketcore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfizz3.picketcore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainj1r.hushdr0pper.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvibe.hushdr0pper.ru
ClearFake payload delivery domain (confidence level: 100%)
domaink8c2.hushdr0pper.ru
ClearFake payload delivery domain (confidence level: 100%)
domains3w9.hushdr0pper.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfleet.t1nkerpove.ru
ClearFake payload delivery domain (confidence level: 100%)
domainc7z1.t1nkerpove.ru
ClearFake payload delivery domain (confidence level: 100%)
domainz9m4.t1nkerpove.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhaze.t1nkerpove.ru
ClearFake payload delivery domain (confidence level: 100%)
domainb4x.ravel-pink.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsilk2.ravel-pink.ru
ClearFake payload delivery domain (confidence level: 100%)
domainn3q7.ravel-pink.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpalm.ravel-pink.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingale.g1zmobrain.ru
ClearFake payload delivery domain (confidence level: 100%)
domainx2k8.g1zmobrain.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsway.g1zmobrain.ru
ClearFake payload delivery domain (confidence level: 100%)
domainm5r1.g1zmobrain.ru
ClearFake payload delivery domain (confidence level: 100%)
domainperk.picket-core.ru
ClearFake payload delivery domain (confidence level: 100%)
domaind3h7.picket-core.ru
ClearFake payload delivery domain (confidence level: 100%)
domainl9c2.picket-core.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrook.picket-core.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincove.ravelpink.ru
ClearFake payload delivery domain (confidence level: 100%)
domainp6z3.ravelpink.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbloom.ravelpink.ru
ClearFake payload delivery domain (confidence level: 100%)
domaint8q1.ravelpink.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstudio.dymk0v5klei.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingesso.dymk0v5klei.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjs.jquery.cn.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainkiln3.dymk0v5klei.ru
ClearFake payload delivery domain (confidence level: 100%)
domainglaze.dymk0v5klei.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrealm.d0minon2me.ru
ClearFake payload delivery domain (confidence level: 100%)
domainedict2.d0minon2me.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvassal.d0minon2me.ru
ClearFake payload delivery domain (confidence level: 100%)
domainaxiom.infide1d0wn.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindoubt.infide1d0wn.ru
ClearFake payload delivery domain (confidence level: 100%)
domainproof3.infide1d0wn.ru
ClearFake payload delivery domain (confidence level: 100%)
domainquery.infide1d0wn.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincanon.infide1d0wn.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsmelt.effu5m0unt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainore2.effu5m0unt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainslag.effu5m0unt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainforge.effu5m0unt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpulse.nerv0u5radic.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspike7.nerv0u5radic.ru
ClearFake payload delivery domain (confidence level: 100%)
domainaxon.nerv0u5radic.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsynap.nerv0u5radic.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfray.nerv0u5radic.ru
ClearFake payload delivery domain (confidence level: 100%)

Threat ID: 6944981c4eb3efac36b4fea2

Added to database: 12/19/2025, 12:11:08 AM

Last enriched: 12/19/2025, 12:11:21 AM

Last updated: 12/19/2025, 12:38:26 PM

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats