ThreatFox IOCs for 2025-12-23
ThreatFox IOCs for 2025-12-23
AI Analysis
Technical Summary
The provided information relates to a ThreatFox feed update containing Indicators of Compromise (IOCs) dated December 23, 2025, categorized under malware with a focus on OSINT (Open Source Intelligence), network activity, and payload delivery. The data does not specify affected software versions or particular vulnerabilities, indicating this is an intelligence aggregation rather than a direct exploit or vulnerability disclosure. The threat level is medium, with no known exploits actively targeting systems and no patches available, suggesting the threat is either emerging or informational. The technical details include a threat level rating of 2 (on an unspecified scale), analysis rating of 1, and distribution rating of 3, which may imply moderate dissemination potential but limited analysis depth. The absence of concrete indicators or CWEs (Common Weakness Enumerations) further supports that this is a situational awareness update rather than a direct attack vector. The focus on OSINT and network activity suggests the threat involves reconnaissance or delivery mechanisms possibly used by malware operators to stage payloads or exfiltrate data. Since no authentication or user interaction details are provided, the exploitation complexity and attack vectors remain unclear. This feed is likely intended for security teams to update their detection capabilities and monitor network traffic for suspicious activity related to known or emerging malware campaigns.
Potential Impact
For European organizations, the impact of this threat is currently limited due to the absence of active exploits and specific affected products or versions. However, the presence of payload delivery and network activity indicators implies potential risks of malware infiltration or data exfiltration if such IOCs are leveraged by threat actors. Organizations relying heavily on OSINT tools or with extensive network infrastructures might experience increased reconnaissance or targeted attacks if adversaries use these IOCs to refine their tactics. The medium severity rating suggests moderate risk, primarily from potential future exploitation or as part of broader attack campaigns. Without patches or direct exploits, the immediate operational impact is low, but failure to incorporate these IOCs into detection systems could delay identification of malicious activity. Additionally, the lack of detailed indicators means some attacks could evade detection if organizations do not maintain updated threat intelligence feeds and network monitoring capabilities.
Mitigation Recommendations
European organizations should integrate the ThreatFox IOCs into their existing Security Information and Event Management (SIEM) and Intrusion Detection/Prevention Systems (IDS/IPS) to enhance detection of related network activity and payload delivery attempts. Regularly updating threat intelligence feeds and correlating them with internal logs will improve early warning capabilities. Network segmentation and strict egress filtering can limit the impact of potential payload delivery and data exfiltration. Conducting threat hunting exercises focused on OSINT-related indicators and unusual network behaviors can proactively identify suspicious activity. Since no patches are available, emphasis should be placed on behavioral detection and anomaly monitoring rather than signature-based defenses alone. Training security analysts to recognize patterns associated with OSINT-driven malware campaigns will also improve response times. Finally, maintaining robust incident response plans that incorporate intelligence feed updates ensures preparedness for emerging threats.
Affected Countries
Germany, France, United Kingdom, Netherlands, Sweden
Indicators of Compromise
- file: 178.17.59.22
- hash: 80
- file: 37.221.66.166
- hash: 80
- file: 80.97.160.144
- hash: 80
- url: https://husnikmeat.com/1q1q.js
- domain: husnikmeat.com
- url: https://husnikmeat.com/js.php
- url: https://ourasolid.com/websockets/local-storage.js
- domain: ourasolid.com
- url: https://ourasolid.com/websockets/service.php
- url: https://ourasolid.com/websockets/session.js
- url: https://positivelike.com/porsche
- url: https://positivelike.com/document
- domain: positivelike.com
- file: 77.110.123.23
- hash: 80
- file: 172.81.133.178
- hash: 80
- domain: setup.digitalpointsec.org
- file: 187.112.166.26
- hash: 7000
- file: 13.220.120.137
- hash: 443
- file: 47.236.96.178
- hash: 3333
- file: 34.71.69.185
- hash: 10443
- file: 196.188.250.153
- hash: 8443
- file: 89.110.93.218
- hash: 443
- file: 77.90.60.32
- hash: 80
- url: http://77.90.60.32/123.txt
- url: http://77.90.60.32/y.gre
- file: 185.39.19.95
- hash: 443
- domain: rentalsmcx.com
- file: 206.238.144.163
- hash: 23051
- file: 23.249.20.61
- hash: 14994
- file: 124.230.195.113
- hash: 9999
- file: 107.174.232.94
- hash: 8089
- file: 188.190.4.219
- hash: 8443
- file: 159.203.71.65
- hash: 443
- file: 93.198.189.106
- hash: 81
- file: 144.172.94.208
- hash: 80
- file: 3.83.164.113
- hash: 7001
- file: 3.83.164.113
- hash: 20001
- file: 2.57.122.219
- hash: 3930
- file: 89.197.167.116
- hash: 7700
- domain: nyfqeg.f0undoutw2y.ru
- domain: juzmat.f0undoutw2y.ru
- domain: sorxep.f0undoutw2y.ru
- file: 45.74.9.54
- hash: 3608
- domain: vaklid.f0undoutw2y.ru
- domain: gipqen.f0undoutw2y.ru
- domain: huzqer.hump7yb0lt.ru
- domain: wytlaf.hump7yb0lt.ru
- domain: doxbim.hump7yb0lt.ru
- domain: jivqot.hump7yb0lt.ru
- domain: mabneg.hump7yb0lt.ru
- url: https://ruzeda.com/blogs/drafts/publish/schedule/seosso/login/mfa/verify/token/refresh/ips/blocklist/whitelist
- url: https://fast-eda.my/dostavka/lavka/kategorii/zakuski/sushi/sety/skidki/regiony/msk/birylievo
- domain: tivqer.g2un7makeup.ru
- domain: hazmiz.g2un7makeup.ru
- domain: murlop.g2un7makeup.ru
- domain: jebxit.g2un7makeup.ru
- url: http://80.76.49.43/login
- url: http://151.242.25.9:9000/login
- file: 151.242.25.9
- hash: 9000
- url: http://77.110.103.209:3000/pages/login.html
- file: 77.110.103.209
- hash: 3000
- url: http://193.177.0.235/user/login
- domain: pafqud.g2un7makeup.ru
- domain: sylqen.narr2tpenici1l.ru
- domain: jodxif.narr2tpenici1l.ru
- domain: vexhup.narr2tpenici1l.ru
- domain: gutqer.narr2tpenici1l.ru
- domain: missmovie.lol
- domain: mazfil.narr2tpenici1l.ru
- file: 8.159.146.72
- hash: 443
- domain: qepxir.m2ximtherm0s.ru
- domain: davlon.m2ximtherm0s.ru
- file: 92.242.38.228
- hash: 5655
- domain: hufqam.m2ximtherm0s.ru
- domain: werpix.m2ximtherm0s.ru
- domain: joltev.m2ximtherm0s.ru
- domain: kavqet.me2n5precede.ru
- domain: wumxib.me2n5precede.ru
- file: 47.115.225.70
- hash: 10001
- domain: jertol.me2n5precede.ru
- file: 163.5.149.126
- hash: 7070
- file: 54.226.113.1
- hash: 7443
- domain: tooki-hzlbsvr.sbs
- file: 188.166.242.35
- hash: 443
- file: 171.232.1.88
- hash: 7001
- file: 34.27.242.178
- hash: 80
- file: 103.177.47.122
- hash: 3790
- file: 196.75.106.156
- hash: 2222
- file: 103.177.46.61
- hash: 3790
- file: 94.130.229.174
- hash: 443
- file: 77.120.128.132
- hash: 443
- file: 213.199.33.111
- hash: 80
- file: 192.169.69.26
- hash: 5580
- domain: sifqen.me2n5precede.ru
- domain: hapdig.me2n5precede.ru
- domain: vyrqet.bramble-zip.ru
- domain: gudxom.bramble-zip.ru
- domain: paxhel.bramble-zip.ru
- domain: sotquv.bramble-zip.ru
- domain: jemniv.bramble-zip.ru
- url: https://mukidashiactive.com/
- domain: zafqon.bramblezip.ru
- domain: mirxet.bramblezip.ru
- domain: dulhev.bramblezip.ru
- domain: wacqis.bramblezip.ru
- domain: tujpen.bramblezip.ru
- domain: goxhel.v-1-nexettle.ru
- domain: buzqer.v-1-nexettle.ru
- domain: safmid.v-1-nexettle.ru
- domain: booloo.hopto.org
- domain: scannerfiles.dynuddns.com
- file: 206.238.144.163
- hash: 23052
- domain: jenxop.v-1-nexettle.ru
- domain: hultiq.v-1-nexettle.ru
- domain: nifqex.caskwander.ru
- domain: vupmex.caskwander.ru
- domain: joltev.caskwander.ru
- domain: derxip.caskwander.ru
- domain: havqon.caskwander.ru
- domain: gexfum.cask-wander.ru
- domain: tumqer.cask-wander.ru
- domain: wilxot.cask-wander.ru
- domain: pafnel.cask-wander.ru
- domain: jorqev.cask-wander.ru
- domain: dexqen.j1tterfoam.ru
- domain: hapxil.j1tterfoam.ru
- domain: worgip.j1tterfoam.ru
- domain: mynqes.j1tterfoam.ru
- file: 43.226.229.228
- hash: 57483
- file: 103.75.116.82
- hash: 443
- file: 105.155.22.136
- hash: 5000
- file: 103.103.23.93
- hash: 443
- file: 182.123.72.158
- hash: 8888
- file: 206.189.36.146
- hash: 9999
- file: 103.20.102.7
- hash: 8848
- file: 104.194.154.98
- hash: 7000
- file: 34.60.209.80
- hash: 80
- file: 103.177.46.103
- hash: 3790
- file: 52.91.103.59
- hash: 10790
- file: 103.177.46.86
- hash: 3790
- file: 103.177.46.82
- hash: 3790
- file: 43.138.157.213
- hash: 50009
- file: 13.223.155.240
- hash: 80
- file: 13.223.155.240
- hash: 443
- file: 51.79.158.254
- hash: 443
- domain: sufvob.j1tterfoam.ru
- file: 158.94.210.88
- hash: 2663
- url: https://steamcommunity.com/id/498hd87wt3rfwe32s
- file: 45.134.26.41
- hash: 9999
- domain: tubqer.t0rquefinch.ru
- domain: vaxhim.t0rquefinch.ru
- domain: wodxet.t0rquefinch.ru
- domain: xtroloozyanimailfeeddeals.shop
- domain: novarandsbvx.info
- domain: stsmithchurchitems.shop
- domain: growinggodsgoodnews.info
- domain: wilkensealsivc.shop
- domain: deuwre.com
- domain: hepnim.t0rquefinch.ru
- file: 34.239.178.12
- hash: 8888
- domain: jylqos.t0rquefinch.ru
- domain: lerqen.v1nexettle.ru
- domain: nextra.in.net
- domain: guzxip.v1nexettle.ru
- domain: dovnig.v1nexettle.ru
- domain: tifqes.v1nexettle.ru
- domain: harbim.v1nexettle.ru
- domain: searchservice.cfd
- domain: mushub.cfd
- domain: xozqet.gr-1-tfable.ru
- domain: reflecrung.run
- domain: tivmon.gr-1-tfable.ru
- url: http://139.59.238.90:8888/supershell/login/
- url: https://d-ac.jp/
- domain: mepxod.gr-1-tfable.ru
- domain: wudhel.gr-1-tfable.ru
- domain: jafqim.gr-1-tfable.ru
- domain: vudxen.quartzjolt.ru
- domain: safqil.quartzjolt.ru
- domain: hemnob.quartzjolt.ru
- domain: jorxep.quartzjolt.ru
- domain: tazqiv.quartzjolt.ru
- domain: www.aliyuncloud.icu
- file: 185.209.42.103
- hash: 31337
- file: 98.93.4.164
- hash: 7443
- file: 185.194.175.132
- hash: 443
- file: 47.98.100.197
- hash: 60000
- file: 43.142.109.146
- hash: 60000
- file: 51.222.136.152
- hash: 3333
- file: 13.60.192.156
- hash: 3333
- file: 91.84.101.151
- hash: 3333
- file: 63.181.237.96
- hash: 80
- file: 63.181.237.96
- hash: 443
- file: 198.13.158.127
- hash: 443
- domain: kezqer.plume-vortex.ru
- domain: wufmib.plume-vortex.ru
- domain: jaxhef.plume-vortex.ru
- domain: tuvqen.plume-vortex.ru
- file: 164.92.134.163
- hash: 4444
- file: 101.42.100.12
- hash: 4444
- file: 191.96.94.159
- hash: 443
- file: 147.45.199.50
- hash: 443
- domain: morxip.plume-vortex.ru
- file: 141.95.72.240
- hash: 5525
- domain: jivqam.sn0cklebeam.ru
- domain: harbex.sn0cklebeam.ru
- file: 193.161.193.99
- hash: 52541
- domain: sousssf-39168.portmap.host
- domain: qesdul.sn0cklebeam.ru
- domain: vupxir.sn0cklebeam.ru
- file: 195.24.237.124
- hash: 2403
- file: 81.17.24.58
- hash: 3812
- file: 213.209.159.105
- hash: 9000
- file: 91.121.34.146
- hash: 80
- file: 202.154.5.83
- hash: 9092
- domain: download.egestx.ru.com
- domain: cdn.egestx.ru.com
- domain: download.koz1.in.net
- domain: logs.koz1.in.net
- domain: cdn.koz1.in.net
- domain: bendecidos8624blessd.dynuddns.com
- domain: download.rieege.mx
- domain: logs.rieege.mx
- domain: download.21food.cn.com
- domain: download.mingxing.cn.com
- domain: download.chis.cn.com
- domain: download.iciba.cn.com
- domain: cdn.aref.co.com
- domain: download.giftingbuddy.in.net
- domain: logs.giftingbuddy.in.net
- domain: tazmel.sn0cklebeam.ru
- domain: motherpure.duckdns.org
- file: 185.214.10.57
- hash: 3920
- domain: zylqen.quartz-jolt.ru
- domain: xet.kievholod.kiev.ua
- domain: mepxuv.quartz-jolt.ru
- domain: tufhel.quartz-jolt.ru
- domain: wodqis.quartz-jolt.ru
- domain: vigilantguildsatori.com
- url: https://raw.githubusercontent.com/machazoo/source/main/main.txt
- domain: jarxim.quartz-jolt.ru
- domain: dexqel.hollowtweak.ru
- domain: vuzmip.hollowtweak.ru
- url: http://103.143.81.175:19091/supershell/login/
- file: 103.143.81.175
- hash: 19091
- domain: hafqes.hollowtweak.ru
- domain: river.skysh1eld.ru
- domain: cloud.skysh1eld.ru
- domain: xw.skysh1eld.ru
- domain: wepay.in.net
- domain: 9nn.skysh1eld.ru
- domain: www.slotmachinesno.sa.com
- domain: digitalhari.in.net
- domain: trace.skysh1eld.ru
- domain: wke.darkfl0w.ru
- domain: a6.darkfl0w.ru
- url: https://emierich.com/2o2o.js
- domain: emierich.com
- url: https://emierich.com/js.php
- domain: shift.darkfl0w.ru
- domain: ridge.darkfl0w.ru
- domain: gbb9.darkfl0w.ru
- domain: pixel.n1ghtbreeze.ru
- file: 85.105.91.10
- hash: 1998
- domain: ersel33640.freedynamicdns.net
- domain: blue.n1ghtbreeze.ru
- domain: airvcastro.duckdns.org
- url: http://45.93.20.61/0462fab2d67b49d5.php
- domain: ember.n1ghtbreeze.ru
- url: https://selcukpeker.com/d.js
- domain: selcukpeker.com
- url: https://www.selcukpeker.com/d.js
- url: https://ourasolid.com/promise/scope.js
- url: https://ourasolid.com/promise/db.php
- url: https://ourasolid.com/promise/json.js
- url: http://79.141.172.212/request
- url: https://fuckingirlz.com/request
- domain: forge.n1ghtbreeze.ru
- file: 192.169.69.26
- hash: 50470
- domain: 0mp8j.n1ghtbreeze.ru
- url: http://146.103.104.211/f999fb4b778f4b7a.php
- domain: miraisystem1337.xyz
- domain: fire.cl0udriver.ru
- domain: alpha.cl0udriver.ru
- domain: qoda.cl0udriver.ru
- file: 193.26.115.208
- hash: 1337
- domain: h26t3.cl0udriver.ru
- domain: koz2.in.net
- domain: shield.cl0udriver.ru
- file: 94.183.183.156
- hash: 80
- domain: dehw4.m1stycliff.ru
- file: 86.106.85.179
- hash: 21381
- file: 130.12.180.50
- hash: 4433
- file: 193.233.201.12
- hash: 8001
- file: 142.202.189.107
- hash: 8808
- file: 161.248.179.38
- hash: 8080
- file: 91.219.239.121
- hash: 9000
- file: 102.98.122.130
- hash: 443
- file: 3.89.250.79
- hash: 48790
- file: 50.17.171.103
- hash: 2077
- file: 174.142.195.203
- hash: 444
- domain: zqb9.m1stycliff.ru
- domain: sj.m1stycliff.ru
- domain: nqr.m1stycliff.ru
- domain: y9zqm.m1stycliff.ru
- domain: cryptocurrencyexchange24.com
- domain: han-duck-soo-apologizes.com
- domain: malware.sun.win
- domain: sarahl.ru.com
- domain: line.bluef0rest.ru
- domain: sct12.app.link
- domain: dekstop-app.app
- domain: n3z.bluef0rest.ru
- domain: form.bluef0rest.ru
- domain: nk.bluef0rest.ru
- file: 193.32.177.63
- hash: 5001
- domain: zs.bluef0rest.ru
- domain: roadyear.xyz
- domain: rifledog.xyz
- domain: flow.cloudf0rm.ru
- domain: beixn.dy-store.tech
- domain: hollow.cloudf0rm.ru
- domain: shadow.cloudf0rm.ru
- domain: t3vlw.cloudf0rm.ru
- domain: dark.cloudf0rm.ru
- domain: nova.storml1ght.ru
- domain: core.storml1ght.ru
- domain: forest.storml1ght.ru
- domain: layer.storml1ght.ru
- domain: 818ne.storml1ght.ru
- domain: 4xm.f1rewave.ru
- domain: money001.duckdns.org
- domain: 0028.duckdns.org
- domain: download.koz2.in.net
- domain: api.koz2.in.net
- domain: logs.koz2.in.net
- domain: unikey.sun.win
- domain: unikey.sarahl.ru.com
- file: 196.251.107.104
- hash: 6606
- file: 196.251.107.104
- hash: 7707
- domain: safeguard.in.net
- domain: safe.safeguard.in.net
- domain: malware.safeguard.in.net
- domain: delta.f1rewave.ru
- domain: safebrowsing.star.co.com
- domain: safebrowsing.amal.sa.com
- domain: safebrowsing.sunwin.moi
- domain: safebrowsing.pbcollege.in.net
- domain: safebrowsing.elijah.ru.com
- domain: vietkey.sarahl.ru.com
- domain: tpxyj-83-252-34-181.a.free.pinggy.link
- domain: v2.ctdrpu.za.com
- domain: security.citystore.in.net
- domain: spam.onthewifi.com
- file: 103.59.103.30
- hash: 6666
- file: 156.254.20.94
- hash: 5050
- file: 91.207.174.14
- hash: 8848
- domain: 802.f1rewave.ru
- file: 206.119.191.106
- hash: 1688
- domain: kjrif.f1rewave.ru
- domain: cliff.f1rewave.ru
- domain: gamma.softsh1ft.ru
- domain: kvrv5.softsh1ft.ru
- file: 102.117.164.165
- hash: 7443
- file: 13.115.235.77
- hash: 443
- domain: 8k.softsh1ft.ru
- file: 188.23.175.59
- hash: 8000
- file: 198.23.173.170
- hash: 33911
- file: 217.76.57.92
- hash: 58008
- file: 223.215.161.165
- hash: 10250
- file: 3.24.130.204
- hash: 443
- file: 39.91.200.45
- hash: 10250
- file: 5.252.21.176
- hash: 443
- file: 74.48.31.97
- hash: 443
- domain: 4wl.softsh1ft.ru
- domain: jmqk.softsh1ft.ru
- domain: omega.silentl1ne.ru
- domain: tsxw.silentl1ne.ru
- domain: 2f.silentl1ne.ru
- domain: lnpw.silentl1ne.ru
- domain: 7iml.silentl1ne.ru
- domain: riod.darkm1nt.ru
- domain: xyyk.darkm1nt.ru
- domain: yap.darkm1nt.ru
- domain: vector.darkm1nt.ru
- file: 115.190.160.206
- hash: 443
- file: 156.238.234.15
- hash: 8080
- file: 101.200.165.71
- hash: 443
- file: 41.147.199.45
- hash: 80
- file: 149.28.247.86
- hash: 9000
- file: 80.78.18.113
- hash: 443
- domain: fonts.sentihey.dedyn.io
- domain: accounts.sentihey.dedyn.io
- domain: ogs.sentihey.dedyn.io
- file: 178.16.55.205
- hash: 4444
- file: 185.237.166.132
- hash: 8000
- domain: meetol.sbs
- file: 91.121.34.146
- hash: 443
- domain: beta.darkm1nt.ru
- domain: rpf.windsh1ft.ru
- domain: i6.windsh1ft.ru
- domain: u4.windsh1ft.ru
- domain: s6h.windsh1ft.ru
- domain: y5ien.windsh1ft.ru
- domain: noverfault.org
- file: 91.92.240.219
- hash: 443
- domain: 7z.nightfl0w.ru
- domain: tt.nightfl0w.ru
- domain: yzf.nightfl0w.ru
- domain: us.nightfl0w.ru
- url: http://westpointwelbyplay.info:8082/updater?for=5120d3fedd36eac912db54c863ce59bb
- domain: wind.nightfl0w.ru
- domain: ah.shadowl1nk.ru
- domain: u1z.shadowl1nk.ru
- domain: jh89g.shadowl1nk.ru
- domain: scq.shadowl1nk.ru
- domain: wave.shadowl1nk.ru
- domain: roh.f1relayer.ru
- domain: silent.f1relayer.ru
- domain: m5ax.f1relayer.ru
- domain: light.f1relayer.ru
- domain: kxc.f1relayer.ru
- file: 172.94.18.103
- hash: 190
- domain: d2.n1ghtcore.ru
- domain: id.n1ghtcore.ru
- domain: spark.n1ghtcore.ru
- domain: nexus.n1ghtcore.ru
- domain: y6gbc.n1ghtcore.ru
- domain: gate.skyf0rge.ru
- domain: 6wz.skyf0rge.ru
- domain: d0.skyf0rge.ru
- domain: mint.skyf0rge.ru
- domain: 679.skyf0rge.ru
- domain: nl.rainst0ne.ru
- domain: storm.rainst0ne.ru
- domain: sky.rainst0ne.ru
ThreatFox IOCs for 2025-12-23
Description
ThreatFox IOCs for 2025-12-23
AI-Powered Analysis
Technical Analysis
The provided information relates to a ThreatFox feed update containing Indicators of Compromise (IOCs) dated December 23, 2025, categorized under malware with a focus on OSINT (Open Source Intelligence), network activity, and payload delivery. The data does not specify affected software versions or particular vulnerabilities, indicating this is an intelligence aggregation rather than a direct exploit or vulnerability disclosure. The threat level is medium, with no known exploits actively targeting systems and no patches available, suggesting the threat is either emerging or informational. The technical details include a threat level rating of 2 (on an unspecified scale), analysis rating of 1, and distribution rating of 3, which may imply moderate dissemination potential but limited analysis depth. The absence of concrete indicators or CWEs (Common Weakness Enumerations) further supports that this is a situational awareness update rather than a direct attack vector. The focus on OSINT and network activity suggests the threat involves reconnaissance or delivery mechanisms possibly used by malware operators to stage payloads or exfiltrate data. Since no authentication or user interaction details are provided, the exploitation complexity and attack vectors remain unclear. This feed is likely intended for security teams to update their detection capabilities and monitor network traffic for suspicious activity related to known or emerging malware campaigns.
Potential Impact
For European organizations, the impact of this threat is currently limited due to the absence of active exploits and specific affected products or versions. However, the presence of payload delivery and network activity indicators implies potential risks of malware infiltration or data exfiltration if such IOCs are leveraged by threat actors. Organizations relying heavily on OSINT tools or with extensive network infrastructures might experience increased reconnaissance or targeted attacks if adversaries use these IOCs to refine their tactics. The medium severity rating suggests moderate risk, primarily from potential future exploitation or as part of broader attack campaigns. Without patches or direct exploits, the immediate operational impact is low, but failure to incorporate these IOCs into detection systems could delay identification of malicious activity. Additionally, the lack of detailed indicators means some attacks could evade detection if organizations do not maintain updated threat intelligence feeds and network monitoring capabilities.
Mitigation Recommendations
European organizations should integrate the ThreatFox IOCs into their existing Security Information and Event Management (SIEM) and Intrusion Detection/Prevention Systems (IDS/IPS) to enhance detection of related network activity and payload delivery attempts. Regularly updating threat intelligence feeds and correlating them with internal logs will improve early warning capabilities. Network segmentation and strict egress filtering can limit the impact of potential payload delivery and data exfiltration. Conducting threat hunting exercises focused on OSINT-related indicators and unusual network behaviors can proactively identify suspicious activity. Since no patches are available, emphasis should be placed on behavioral detection and anomaly monitoring rather than signature-based defenses alone. Training security analysts to recognize patterns associated with OSINT-driven malware campaigns will also improve response times. Finally, maintaining robust incident response plans that incorporate intelligence feed updates ensures preparedness for emerging threats.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- 726dcd0a-65f4-4430-a3b9-2b7bfbfc0d87
- Original Timestamp
- 1766534587
Indicators of Compromise
File
| Value | Description | Copy |
|---|---|---|
file178.17.59.22 | Stealc botnet C2 server (confidence level: 100%) | |
file37.221.66.166 | Stealc botnet C2 server (confidence level: 100%) | |
file80.97.160.144 | Stealc botnet C2 server (confidence level: 100%) | |
file77.110.123.23 | Stealc botnet C2 server (confidence level: 100%) | |
file172.81.133.178 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file187.112.166.26 | Venom RAT botnet C2 server (confidence level: 100%) | |
file13.220.120.137 | Unknown malware botnet C2 server (confidence level: 100%) | |
file47.236.96.178 | Unknown malware botnet C2 server (confidence level: 100%) | |
file34.71.69.185 | Unknown malware botnet C2 server (confidence level: 100%) | |
file196.188.250.153 | Unknown malware botnet C2 server (confidence level: 100%) | |
file89.110.93.218 | BianLian botnet C2 server (confidence level: 100%) | |
file77.90.60.32 | NetSupportManager RAT payload delivery server (confidence level: 100%) | |
file185.39.19.95 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file206.238.144.163 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file23.249.20.61 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file124.230.195.113 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file107.174.232.94 | Sliver botnet C2 server (confidence level: 100%) | |
file188.190.4.219 | Sliver botnet C2 server (confidence level: 100%) | |
file159.203.71.65 | Havoc botnet C2 server (confidence level: 100%) | |
file93.198.189.106 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file144.172.94.208 | Bashlite botnet C2 server (confidence level: 100%) | |
file3.83.164.113 | Meterpreter botnet C2 server (confidence level: 100%) | |
file3.83.164.113 | Meterpreter botnet C2 server (confidence level: 100%) | |
file2.57.122.219 | Meterpreter botnet C2 server (confidence level: 100%) | |
file89.197.167.116 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file45.74.9.54 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file151.242.25.9 | Unknown malware botnet C2 server (confidence level: 100%) | |
file77.110.103.209 | Unknown malware botnet C2 server (confidence level: 100%) | |
file8.159.146.72 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file92.242.38.228 | RMS botnet C2 server (confidence level: 100%) | |
file47.115.225.70 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file163.5.149.126 | Remcos botnet C2 server (confidence level: 100%) | |
file54.226.113.1 | Unknown malware botnet C2 server (confidence level: 100%) | |
file188.166.242.35 | Havoc botnet C2 server (confidence level: 100%) | |
file171.232.1.88 | Venom RAT botnet C2 server (confidence level: 100%) | |
file34.27.242.178 | MimiKatz botnet C2 server (confidence level: 100%) | |
file103.177.47.122 | Meterpreter botnet C2 server (confidence level: 100%) | |
file196.75.106.156 | Meterpreter botnet C2 server (confidence level: 100%) | |
file103.177.46.61 | Meterpreter botnet C2 server (confidence level: 100%) | |
file94.130.229.174 | Unknown malware botnet C2 server (confidence level: 100%) | |
file77.120.128.132 | Unknown malware botnet C2 server (confidence level: 100%) | |
file213.199.33.111 | Unknown malware botnet C2 server (confidence level: 100%) | |
file192.169.69.26 | Nanocore RAT botnet C2 server (confidence level: 100%) | |
file206.238.144.163 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file43.226.229.228 | Remcos botnet C2 server (confidence level: 100%) | |
file103.75.116.82 | Sliver botnet C2 server (confidence level: 100%) | |
file105.155.22.136 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file103.103.23.93 | Unknown malware botnet C2 server (confidence level: 100%) | |
file182.123.72.158 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file206.189.36.146 | Venom RAT botnet C2 server (confidence level: 100%) | |
file103.20.102.7 | DCRat botnet C2 server (confidence level: 100%) | |
file104.194.154.98 | DCRat botnet C2 server (confidence level: 100%) | |
file34.60.209.80 | MimiKatz botnet C2 server (confidence level: 100%) | |
file103.177.46.103 | Meterpreter botnet C2 server (confidence level: 100%) | |
file52.91.103.59 | Meterpreter botnet C2 server (confidence level: 100%) | |
file103.177.46.86 | Meterpreter botnet C2 server (confidence level: 100%) | |
file103.177.46.82 | Meterpreter botnet C2 server (confidence level: 100%) | |
file43.138.157.213 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file13.223.155.240 | Unknown malware botnet C2 server (confidence level: 100%) | |
file13.223.155.240 | Unknown malware botnet C2 server (confidence level: 100%) | |
file51.79.158.254 | Unknown malware botnet C2 server (confidence level: 100%) | |
file158.94.210.88 | Bashlite botnet C2 server (confidence level: 75%) | |
file45.134.26.41 | CastleRAT botnet C2 server (confidence level: 75%) | |
file34.239.178.12 | Sliver botnet C2 server (confidence level: 75%) | |
file185.209.42.103 | Sliver botnet C2 server (confidence level: 90%) | |
file98.93.4.164 | Unknown malware botnet C2 server (confidence level: 100%) | |
file185.194.175.132 | Unknown malware botnet C2 server (confidence level: 100%) | |
file47.98.100.197 | Unknown malware botnet C2 server (confidence level: 100%) | |
file43.142.109.146 | Unknown malware botnet C2 server (confidence level: 100%) | |
file51.222.136.152 | Unknown malware botnet C2 server (confidence level: 100%) | |
file13.60.192.156 | Unknown malware botnet C2 server (confidence level: 100%) | |
file91.84.101.151 | Unknown malware botnet C2 server (confidence level: 100%) | |
file63.181.237.96 | Unknown malware botnet C2 server (confidence level: 100%) | |
file63.181.237.96 | Unknown malware botnet C2 server (confidence level: 100%) | |
file198.13.158.127 | ClearFake payload delivery server (confidence level: 100%) | |
file164.92.134.163 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file101.42.100.12 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file191.96.94.159 | FAKEUPDATES payload delivery server (confidence level: 100%) | |
file147.45.199.50 | FAKEUPDATES payload delivery server (confidence level: 100%) | |
file141.95.72.240 | Brute Ratel C4 botnet C2 server (confidence level: 75%) | |
file193.161.193.99 | XWorm botnet C2 server (confidence level: 75%) | |
file195.24.237.124 | Remcos botnet C2 server (confidence level: 100%) | |
file81.17.24.58 | Remcos botnet C2 server (confidence level: 100%) | |
file213.209.159.105 | SectopRAT botnet C2 server (confidence level: 100%) | |
file91.121.34.146 | Unknown malware botnet C2 server (confidence level: 100%) | |
file202.154.5.83 | Unknown malware botnet C2 server (confidence level: 100%) | |
file185.214.10.57 | Nanocore RAT botnet C2 server (confidence level: 100%) | |
file103.143.81.175 | Unknown malware botnet C2 server (confidence level: 100%) | |
file85.105.91.10 | DarkComet botnet C2 server (confidence level: 100%) | |
file192.169.69.26 | Nanocore RAT botnet C2 server (confidence level: 100%) | |
file193.26.115.208 | Unknown Stealer botnet C2 server (confidence level: 100%) | |
file94.183.183.156 | Stealc botnet C2 server (confidence level: 100%) | |
file86.106.85.179 | Sliver botnet C2 server (confidence level: 100%) | |
file130.12.180.50 | Sliver botnet C2 server (confidence level: 100%) | |
file193.233.201.12 | Sliver botnet C2 server (confidence level: 100%) | |
file142.202.189.107 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file161.248.179.38 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file91.219.239.121 | SectopRAT botnet C2 server (confidence level: 100%) | |
file102.98.122.130 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file3.89.250.79 | Meterpreter botnet C2 server (confidence level: 100%) | |
file50.17.171.103 | Meterpreter botnet C2 server (confidence level: 100%) | |
file174.142.195.203 | Unknown malware botnet C2 server (confidence level: 100%) | |
file193.32.177.63 | Unknown malware botnet C2 server (confidence level: 75%) | |
file196.251.107.104 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file196.251.107.104 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file103.59.103.30 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file156.254.20.94 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file91.207.174.14 | SpyNote botnet C2 server (confidence level: 100%) | |
file206.119.191.106 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file102.117.164.165 | Unknown malware botnet C2 server (confidence level: 75%) | |
file13.115.235.77 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file188.23.175.59 | Eye Pyramid botnet C2 server (confidence level: 75%) | |
file198.23.173.170 | Sliver botnet C2 server (confidence level: 75%) | |
file217.76.57.92 | Sliver botnet C2 server (confidence level: 75%) | |
file223.215.161.165 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file3.24.130.204 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file39.91.200.45 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file5.252.21.176 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file74.48.31.97 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file115.190.160.206 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file156.238.234.15 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file101.200.165.71 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file41.147.199.45 | pupy botnet C2 server (confidence level: 100%) | |
file149.28.247.86 | SectopRAT botnet C2 server (confidence level: 100%) | |
file80.78.18.113 | Unknown malware botnet C2 server (confidence level: 100%) | |
file178.16.55.205 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file185.237.166.132 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file91.121.34.146 | Unknown malware botnet C2 server (confidence level: 100%) | |
file91.92.240.219 | ClearFake payload delivery server (confidence level: 100%) | |
file172.94.18.103 | AsyncRAT botnet C2 server (confidence level: 100%) |
Hash
| Value | Description | Copy |
|---|---|---|
hash80 | Stealc botnet C2 server (confidence level: 100%) | |
hash80 | Stealc botnet C2 server (confidence level: 100%) | |
hash80 | Stealc botnet C2 server (confidence level: 100%) | |
hash80 | Stealc botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash7000 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash10443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | BianLian botnet C2 server (confidence level: 100%) | |
hash80 | NetSupportManager RAT payload delivery server (confidence level: 100%) | |
hash443 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash23051 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash14994 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash9999 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash8089 | Sliver botnet C2 server (confidence level: 100%) | |
hash8443 | Sliver botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash81 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash80 | Bashlite botnet C2 server (confidence level: 100%) | |
hash7001 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash20001 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3930 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash7700 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash3608 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash9000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash5655 | RMS botnet C2 server (confidence level: 100%) | |
hash10001 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash7070 | Remcos botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash7001 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash80 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash2222 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash5580 | Nanocore RAT botnet C2 server (confidence level: 100%) | |
hash23052 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash57483 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash5000 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8888 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash9999 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash8848 | DCRat botnet C2 server (confidence level: 100%) | |
hash7000 | DCRat botnet C2 server (confidence level: 100%) | |
hash80 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash10790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash50009 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash2663 | Bashlite botnet C2 server (confidence level: 75%) | |
hash9999 | CastleRAT botnet C2 server (confidence level: 75%) | |
hash8888 | Sliver botnet C2 server (confidence level: 75%) | |
hash31337 | Sliver botnet C2 server (confidence level: 90%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash60000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash60000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | ClearFake payload delivery server (confidence level: 100%) | |
hash4444 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash4444 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | FAKEUPDATES payload delivery server (confidence level: 100%) | |
hash443 | FAKEUPDATES payload delivery server (confidence level: 100%) | |
hash5525 | Brute Ratel C4 botnet C2 server (confidence level: 75%) | |
hash52541 | XWorm botnet C2 server (confidence level: 75%) | |
hash2403 | Remcos botnet C2 server (confidence level: 100%) | |
hash3812 | Remcos botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash9092 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3920 | Nanocore RAT botnet C2 server (confidence level: 100%) | |
hash19091 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash1998 | DarkComet botnet C2 server (confidence level: 100%) | |
hash50470 | Nanocore RAT botnet C2 server (confidence level: 100%) | |
hash1337 | Unknown Stealer botnet C2 server (confidence level: 100%) | |
hash80 | Stealc botnet C2 server (confidence level: 100%) | |
hash21381 | Sliver botnet C2 server (confidence level: 100%) | |
hash4433 | Sliver botnet C2 server (confidence level: 100%) | |
hash8001 | Sliver botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8080 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash443 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash48790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash2077 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash444 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash5001 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash6606 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash7707 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash6666 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash5050 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash8848 | SpyNote botnet C2 server (confidence level: 100%) | |
hash1688 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash8000 | Eye Pyramid botnet C2 server (confidence level: 75%) | |
hash33911 | Sliver botnet C2 server (confidence level: 75%) | |
hash58008 | Sliver botnet C2 server (confidence level: 75%) | |
hash10250 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash10250 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | pupy botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash4444 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash8000 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | ClearFake payload delivery server (confidence level: 100%) | |
hash190 | AsyncRAT botnet C2 server (confidence level: 100%) |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://husnikmeat.com/1q1q.js | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttps://husnikmeat.com/js.php | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttps://ourasolid.com/websockets/local-storage.js | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://ourasolid.com/websockets/service.php | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://ourasolid.com/websockets/session.js | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://positivelike.com/porsche | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://positivelike.com/document | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttp://77.90.60.32/123.txt | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttp://77.90.60.32/y.gre | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://ruzeda.com/blogs/drafts/publish/schedule/seosso/login/mfa/verify/token/refresh/ips/blocklist/whitelist | Havoc botnet C2 (confidence level: 100%) | |
urlhttps://fast-eda.my/dostavka/lavka/kategorii/zakuski/sushi/sety/skidki/regiony/msk/birylievo | Havoc botnet C2 (confidence level: 100%) | |
urlhttp://80.76.49.43/login | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttp://151.242.25.9:9000/login | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttp://77.110.103.209:3000/pages/login.html | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttp://193.177.0.235/user/login | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://mukidashiactive.com/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://steamcommunity.com/id/498hd87wt3rfwe32s | CastleRAT botnet C2 (confidence level: 100%) | |
urlhttp://139.59.238.90:8888/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://d-ac.jp/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://raw.githubusercontent.com/machazoo/source/main/main.txt | Unknown malware payload delivery URL (confidence level: 100%) | |
urlhttp://103.143.81.175:19091/supershell/login/ | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://emierich.com/2o2o.js | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttps://emierich.com/js.php | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttp://45.93.20.61/0462fab2d67b49d5.php | Stealc botnet C2 (confidence level: 100%) | |
urlhttps://selcukpeker.com/d.js | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://www.selcukpeker.com/d.js | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://ourasolid.com/promise/scope.js | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://ourasolid.com/promise/db.php | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://ourasolid.com/promise/json.js | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttp://79.141.172.212/request | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttps://fuckingirlz.com/request | NetSupportManager RAT payload delivery URL (confidence level: 100%) | |
urlhttp://146.103.104.211/f999fb4b778f4b7a.php | Stealc botnet C2 (confidence level: 100%) | |
urlhttp://westpointwelbyplay.info:8082/updater?for=5120d3fedd36eac912db54c863ce59bb | Unknown malware botnet C2 (confidence level: 100%) |
Domain
| Value | Description | Copy |
|---|---|---|
domainhusnikmeat.com | KongTuke payload delivery domain (confidence level: 100%) | |
domainourasolid.com | NetSupportManager RAT payload delivery domain (confidence level: 100%) | |
domainpositivelike.com | NetSupportManager RAT payload delivery domain (confidence level: 100%) | |
domainsetup.digitalpointsec.org | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainrentalsmcx.com | NetSupportManager RAT botnet C2 domain (confidence level: 100%) | |
domainnyfqeg.f0undoutw2y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjuzmat.f0undoutw2y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsorxep.f0undoutw2y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvaklid.f0undoutw2y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingipqen.f0undoutw2y.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhuzqer.hump7yb0lt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwytlaf.hump7yb0lt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindoxbim.hump7yb0lt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjivqot.hump7yb0lt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmabneg.hump7yb0lt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintivqer.g2un7makeup.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhazmiz.g2un7makeup.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmurlop.g2un7makeup.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjebxit.g2un7makeup.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpafqud.g2un7makeup.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsylqen.narr2tpenici1l.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjodxif.narr2tpenici1l.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvexhup.narr2tpenici1l.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingutqer.narr2tpenici1l.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmissmovie.lol | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainmazfil.narr2tpenici1l.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqepxir.m2ximtherm0s.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindavlon.m2ximtherm0s.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhufqam.m2ximtherm0s.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwerpix.m2ximtherm0s.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjoltev.m2ximtherm0s.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkavqet.me2n5precede.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwumxib.me2n5precede.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjertol.me2n5precede.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintooki-hzlbsvr.sbs | Hook botnet C2 domain (confidence level: 100%) | |
domainsifqen.me2n5precede.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhapdig.me2n5precede.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvyrqet.bramble-zip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingudxom.bramble-zip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpaxhel.bramble-zip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsotquv.bramble-zip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjemniv.bramble-zip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzafqon.bramblezip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmirxet.bramblezip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindulhev.bramblezip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwacqis.bramblezip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintujpen.bramblezip.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingoxhel.v-1-nexettle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbuzqer.v-1-nexettle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsafmid.v-1-nexettle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbooloo.hopto.org | Remcos botnet C2 domain (confidence level: 100%) | |
domainscannerfiles.dynuddns.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainjenxop.v-1-nexettle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhultiq.v-1-nexettle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnifqex.caskwander.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvupmex.caskwander.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjoltev.caskwander.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainderxip.caskwander.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhavqon.caskwander.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingexfum.cask-wander.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintumqer.cask-wander.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwilxot.cask-wander.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpafnel.cask-wander.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjorqev.cask-wander.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindexqen.j1tterfoam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhapxil.j1tterfoam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainworgip.j1tterfoam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmynqes.j1tterfoam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsufvob.j1tterfoam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintubqer.t0rquefinch.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvaxhim.t0rquefinch.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwodxet.t0rquefinch.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxtroloozyanimailfeeddeals.shop | Unknown RAT botnet C2 domain (confidence level: 100%) | |
domainnovarandsbvx.info | Unknown RAT botnet C2 domain (confidence level: 100%) | |
domainstsmithchurchitems.shop | Unknown RAT botnet C2 domain (confidence level: 100%) | |
domaingrowinggodsgoodnews.info | Unknown RAT botnet C2 domain (confidence level: 100%) | |
domainwilkensealsivc.shop | Unknown RAT botnet C2 domain (confidence level: 100%) | |
domaindeuwre.com | Unknown RAT botnet C2 domain (confidence level: 100%) | |
domainhepnim.t0rquefinch.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjylqos.t0rquefinch.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlerqen.v1nexettle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnextra.in.net | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainguzxip.v1nexettle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindovnig.v1nexettle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintifqes.v1nexettle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainharbim.v1nexettle.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsearchservice.cfd | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainmushub.cfd | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainxozqet.gr-1-tfable.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainreflecrung.run | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaintivmon.gr-1-tfable.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmepxod.gr-1-tfable.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwudhel.gr-1-tfable.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjafqim.gr-1-tfable.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvudxen.quartzjolt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsafqil.quartzjolt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhemnob.quartzjolt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjorxep.quartzjolt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintazqiv.quartzjolt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwww.aliyuncloud.icu | Cobalt Strike botnet C2 domain (confidence level: 100%) | |
domainkezqer.plume-vortex.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwufmib.plume-vortex.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjaxhef.plume-vortex.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintuvqen.plume-vortex.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmorxip.plume-vortex.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjivqam.sn0cklebeam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainharbex.sn0cklebeam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsousssf-39168.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainqesdul.sn0cklebeam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvupxir.sn0cklebeam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindownload.egestx.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaincdn.egestx.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindownload.koz1.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainlogs.koz1.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaincdn.koz1.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainbendecidos8624blessd.dynuddns.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindownload.rieege.mx | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainlogs.rieege.mx | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindownload.21food.cn.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindownload.mingxing.cn.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindownload.chis.cn.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindownload.iciba.cn.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaincdn.aref.co.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domaindownload.giftingbuddy.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainlogs.giftingbuddy.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domaintazmel.sn0cklebeam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmotherpure.duckdns.org | Nanocore RAT botnet C2 domain (confidence level: 100%) | |
domainzylqen.quartz-jolt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxet.kievholod.kiev.ua | Vidar botnet C2 domain (confidence level: 100%) | |
domainmepxuv.quartz-jolt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintufhel.quartz-jolt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwodqis.quartz-jolt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvigilantguildsatori.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainjarxim.quartz-jolt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindexqel.hollowtweak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvuzmip.hollowtweak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhafqes.hollowtweak.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainriver.skysh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincloud.skysh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxw.skysh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwepay.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domain9nn.skysh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwww.slotmachinesno.sa.com | vanillarat botnet C2 domain (confidence level: 100%) | |
domaindigitalhari.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaintrace.skysh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwke.darkfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaina6.darkfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainemierich.com | KongTuke payload delivery domain (confidence level: 100%) | |
domainshift.darkfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainridge.darkfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingbb9.darkfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpixel.n1ghtbreeze.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainersel33640.freedynamicdns.net | DarkComet botnet C2 domain (confidence level: 100%) | |
domainblue.n1ghtbreeze.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainairvcastro.duckdns.org | Nanocore RAT botnet C2 domain (confidence level: 100%) | |
domainember.n1ghtbreeze.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainselcukpeker.com | NetSupportManager RAT payload delivery domain (confidence level: 100%) | |
domainforge.n1ghtbreeze.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain0mp8j.n1ghtbreeze.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmiraisystem1337.xyz | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainfire.cl0udriver.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainalpha.cl0udriver.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqoda.cl0udriver.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainh26t3.cl0udriver.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkoz2.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainshield.cl0udriver.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindehw4.m1stycliff.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzqb9.m1stycliff.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsj.m1stycliff.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnqr.m1stycliff.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainy9zqm.m1stycliff.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincryptocurrencyexchange24.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainhan-duck-soo-apologizes.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainmalware.sun.win | Quasar RAT botnet C2 domain (confidence level: 75%) | |
domainsarahl.ru.com | Quasar RAT botnet C2 domain (confidence level: 75%) | |
domainline.bluef0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsct12.app.link | Unknown malware payload delivery domain (confidence level: 100%) | |
domaindekstop-app.app | Unknown malware payload delivery domain (confidence level: 100%) | |
domainn3z.bluef0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainform.bluef0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnk.bluef0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzs.bluef0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainroadyear.xyz | Unknown Loader botnet C2 domain (confidence level: 100%) | |
domainrifledog.xyz | Unknown Loader botnet C2 domain (confidence level: 100%) | |
domainflow.cloudf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbeixn.dy-store.tech | Cobalt Strike botnet C2 domain (confidence level: 100%) | |
domainhollow.cloudf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshadow.cloudf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaint3vlw.cloudf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindark.cloudf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnova.storml1ght.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincore.storml1ght.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainforest.storml1ght.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlayer.storml1ght.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain818ne.storml1ght.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain4xm.f1rewave.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoney001.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domain0028.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domaindownload.koz2.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainapi.koz2.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainlogs.koz2.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainunikey.sun.win | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainunikey.sarahl.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainsafeguard.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainsafe.safeguard.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainmalware.safeguard.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindelta.f1rewave.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsafebrowsing.star.co.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainsafebrowsing.amal.sa.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainsafebrowsing.sunwin.moi | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainsafebrowsing.pbcollege.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainsafebrowsing.elijah.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainvietkey.sarahl.ru.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domaintpxyj-83-252-34-181.a.free.pinggy.link | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainv2.ctdrpu.za.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainsecurity.citystore.in.net | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainspam.onthewifi.com | NjRAT botnet C2 domain (confidence level: 100%) | |
domain802.f1rewave.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkjrif.f1rewave.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincliff.f1rewave.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingamma.softsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkvrv5.softsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain8k.softsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain4wl.softsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjmqk.softsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainomega.silentl1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintsxw.silentl1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain2f.silentl1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlnpw.silentl1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7iml.silentl1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainriod.darkm1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxyyk.darkm1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainyap.darkm1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvector.darkm1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfonts.sentihey.dedyn.io | Havoc botnet C2 domain (confidence level: 100%) | |
domainaccounts.sentihey.dedyn.io | Havoc botnet C2 domain (confidence level: 100%) | |
domainogs.sentihey.dedyn.io | Havoc botnet C2 domain (confidence level: 100%) | |
domainmeetol.sbs | Cobalt Strike botnet C2 domain (confidence level: 100%) | |
domainbeta.darkm1nt.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrpf.windsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaini6.windsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainu4.windsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domains6h.windsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainy5ien.windsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnoverfault.org | ClearFake payload delivery domain (confidence level: 100%) | |
domain7z.nightfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintt.nightfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainyzf.nightfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainus.nightfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwind.nightfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainah.shadowl1nk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainu1z.shadowl1nk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjh89g.shadowl1nk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainscq.shadowl1nk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwave.shadowl1nk.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainroh.f1relayer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsilent.f1relayer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainm5ax.f1relayer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlight.f1relayer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkxc.f1relayer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaind2.n1ghtcore.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainid.n1ghtcore.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspark.n1ghtcore.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnexus.n1ghtcore.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainy6gbc.n1ghtcore.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingate.skyf0rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain6wz.skyf0rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaind0.skyf0rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmint.skyf0rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain679.skyf0rge.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnl.rainst0ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstorm.rainst0ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsky.rainst0ne.ru | ClearFake payload delivery domain (confidence level: 100%) |
Threat ID: 694b2edc0a0f3cdd674e7536
Added to database: 12/24/2025, 12:07:56 AM
Last enriched: 12/24/2025, 12:08:10 AM
Last updated: 12/24/2025, 3:39:57 AM
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
Dissecting a Multi-Stage macOS Infostealer
MediumNew MacSync Stealer Disguised as Trusted Mac App Hunts Your Saved Passwords
MediumRansomware Hits Romanian Water Authority, 1000 Systems Knocked Offline
MediumTrial, Error, and Typos: Why Some Malware Attacks Aren't as 'Sophisticated' as You Think
MediumMacSync Stealer Evolves: From ClickFix to Code-Signed Swift Malware
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.