Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2025-12-23

0
Medium
Published: Tue Dec 23 2025 (12/23/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-12-23

AI-Powered Analysis

AILast updated: 12/24/2025, 00:08:10 UTC

Technical Analysis

The provided information relates to a ThreatFox feed update containing Indicators of Compromise (IOCs) dated December 23, 2025, categorized under malware with a focus on OSINT (Open Source Intelligence), network activity, and payload delivery. The data does not specify affected software versions or particular vulnerabilities, indicating this is an intelligence aggregation rather than a direct exploit or vulnerability disclosure. The threat level is medium, with no known exploits actively targeting systems and no patches available, suggesting the threat is either emerging or informational. The technical details include a threat level rating of 2 (on an unspecified scale), analysis rating of 1, and distribution rating of 3, which may imply moderate dissemination potential but limited analysis depth. The absence of concrete indicators or CWEs (Common Weakness Enumerations) further supports that this is a situational awareness update rather than a direct attack vector. The focus on OSINT and network activity suggests the threat involves reconnaissance or delivery mechanisms possibly used by malware operators to stage payloads or exfiltrate data. Since no authentication or user interaction details are provided, the exploitation complexity and attack vectors remain unclear. This feed is likely intended for security teams to update their detection capabilities and monitor network traffic for suspicious activity related to known or emerging malware campaigns.

Potential Impact

For European organizations, the impact of this threat is currently limited due to the absence of active exploits and specific affected products or versions. However, the presence of payload delivery and network activity indicators implies potential risks of malware infiltration or data exfiltration if such IOCs are leveraged by threat actors. Organizations relying heavily on OSINT tools or with extensive network infrastructures might experience increased reconnaissance or targeted attacks if adversaries use these IOCs to refine their tactics. The medium severity rating suggests moderate risk, primarily from potential future exploitation or as part of broader attack campaigns. Without patches or direct exploits, the immediate operational impact is low, but failure to incorporate these IOCs into detection systems could delay identification of malicious activity. Additionally, the lack of detailed indicators means some attacks could evade detection if organizations do not maintain updated threat intelligence feeds and network monitoring capabilities.

Mitigation Recommendations

European organizations should integrate the ThreatFox IOCs into their existing Security Information and Event Management (SIEM) and Intrusion Detection/Prevention Systems (IDS/IPS) to enhance detection of related network activity and payload delivery attempts. Regularly updating threat intelligence feeds and correlating them with internal logs will improve early warning capabilities. Network segmentation and strict egress filtering can limit the impact of potential payload delivery and data exfiltration. Conducting threat hunting exercises focused on OSINT-related indicators and unusual network behaviors can proactively identify suspicious activity. Since no patches are available, emphasis should be placed on behavioral detection and anomaly monitoring rather than signature-based defenses alone. Training security analysts to recognize patterns associated with OSINT-driven malware campaigns will also improve response times. Finally, maintaining robust incident response plans that incorporate intelligence feed updates ensures preparedness for emerging threats.

Need more detailed analysis?Get Pro

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
726dcd0a-65f4-4430-a3b9-2b7bfbfc0d87
Original Timestamp
1766534587

Indicators of Compromise

File

ValueDescriptionCopy
file178.17.59.22
Stealc botnet C2 server (confidence level: 100%)
file37.221.66.166
Stealc botnet C2 server (confidence level: 100%)
file80.97.160.144
Stealc botnet C2 server (confidence level: 100%)
file77.110.123.23
Stealc botnet C2 server (confidence level: 100%)
file172.81.133.178
Cobalt Strike botnet C2 server (confidence level: 100%)
file187.112.166.26
Venom RAT botnet C2 server (confidence level: 100%)
file13.220.120.137
Unknown malware botnet C2 server (confidence level: 100%)
file47.236.96.178
Unknown malware botnet C2 server (confidence level: 100%)
file34.71.69.185
Unknown malware botnet C2 server (confidence level: 100%)
file196.188.250.153
Unknown malware botnet C2 server (confidence level: 100%)
file89.110.93.218
BianLian botnet C2 server (confidence level: 100%)
file77.90.60.32
NetSupportManager RAT payload delivery server (confidence level: 100%)
file185.39.19.95
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file206.238.144.163
ValleyRAT botnet C2 server (confidence level: 100%)
file23.249.20.61
Ghost RAT botnet C2 server (confidence level: 100%)
file124.230.195.113
Ghost RAT botnet C2 server (confidence level: 100%)
file107.174.232.94
Sliver botnet C2 server (confidence level: 100%)
file188.190.4.219
Sliver botnet C2 server (confidence level: 100%)
file159.203.71.65
Havoc botnet C2 server (confidence level: 100%)
file93.198.189.106
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file144.172.94.208
Bashlite botnet C2 server (confidence level: 100%)
file3.83.164.113
Meterpreter botnet C2 server (confidence level: 100%)
file3.83.164.113
Meterpreter botnet C2 server (confidence level: 100%)
file2.57.122.219
Meterpreter botnet C2 server (confidence level: 100%)
file89.197.167.116
Empire Downloader botnet C2 server (confidence level: 100%)
file45.74.9.54
AsyncRAT botnet C2 server (confidence level: 100%)
file151.242.25.9
Unknown malware botnet C2 server (confidence level: 100%)
file77.110.103.209
Unknown malware botnet C2 server (confidence level: 100%)
file8.159.146.72
Cobalt Strike botnet C2 server (confidence level: 75%)
file92.242.38.228
RMS botnet C2 server (confidence level: 100%)
file47.115.225.70
Cobalt Strike botnet C2 server (confidence level: 100%)
file163.5.149.126
Remcos botnet C2 server (confidence level: 100%)
file54.226.113.1
Unknown malware botnet C2 server (confidence level: 100%)
file188.166.242.35
Havoc botnet C2 server (confidence level: 100%)
file171.232.1.88
Venom RAT botnet C2 server (confidence level: 100%)
file34.27.242.178
MimiKatz botnet C2 server (confidence level: 100%)
file103.177.47.122
Meterpreter botnet C2 server (confidence level: 100%)
file196.75.106.156
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.46.61
Meterpreter botnet C2 server (confidence level: 100%)
file94.130.229.174
Unknown malware botnet C2 server (confidence level: 100%)
file77.120.128.132
Unknown malware botnet C2 server (confidence level: 100%)
file213.199.33.111
Unknown malware botnet C2 server (confidence level: 100%)
file192.169.69.26
Nanocore RAT botnet C2 server (confidence level: 100%)
file206.238.144.163
ValleyRAT botnet C2 server (confidence level: 100%)
file43.226.229.228
Remcos botnet C2 server (confidence level: 100%)
file103.75.116.82
Sliver botnet C2 server (confidence level: 100%)
file105.155.22.136
AsyncRAT botnet C2 server (confidence level: 100%)
file103.103.23.93
Unknown malware botnet C2 server (confidence level: 100%)
file182.123.72.158
Quasar RAT botnet C2 server (confidence level: 100%)
file206.189.36.146
Venom RAT botnet C2 server (confidence level: 100%)
file103.20.102.7
DCRat botnet C2 server (confidence level: 100%)
file104.194.154.98
DCRat botnet C2 server (confidence level: 100%)
file34.60.209.80
MimiKatz botnet C2 server (confidence level: 100%)
file103.177.46.103
Meterpreter botnet C2 server (confidence level: 100%)
file52.91.103.59
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.46.86
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.46.82
Meterpreter botnet C2 server (confidence level: 100%)
file43.138.157.213
Empire Downloader botnet C2 server (confidence level: 100%)
file13.223.155.240
Unknown malware botnet C2 server (confidence level: 100%)
file13.223.155.240
Unknown malware botnet C2 server (confidence level: 100%)
file51.79.158.254
Unknown malware botnet C2 server (confidence level: 100%)
file158.94.210.88
Bashlite botnet C2 server (confidence level: 75%)
file45.134.26.41
CastleRAT botnet C2 server (confidence level: 75%)
file34.239.178.12
Sliver botnet C2 server (confidence level: 75%)
file185.209.42.103
Sliver botnet C2 server (confidence level: 90%)
file98.93.4.164
Unknown malware botnet C2 server (confidence level: 100%)
file185.194.175.132
Unknown malware botnet C2 server (confidence level: 100%)
file47.98.100.197
Unknown malware botnet C2 server (confidence level: 100%)
file43.142.109.146
Unknown malware botnet C2 server (confidence level: 100%)
file51.222.136.152
Unknown malware botnet C2 server (confidence level: 100%)
file13.60.192.156
Unknown malware botnet C2 server (confidence level: 100%)
file91.84.101.151
Unknown malware botnet C2 server (confidence level: 100%)
file63.181.237.96
Unknown malware botnet C2 server (confidence level: 100%)
file63.181.237.96
Unknown malware botnet C2 server (confidence level: 100%)
file198.13.158.127
ClearFake payload delivery server (confidence level: 100%)
file164.92.134.163
Cobalt Strike botnet C2 server (confidence level: 100%)
file101.42.100.12
Cobalt Strike botnet C2 server (confidence level: 100%)
file191.96.94.159
FAKEUPDATES payload delivery server (confidence level: 100%)
file147.45.199.50
FAKEUPDATES payload delivery server (confidence level: 100%)
file141.95.72.240
Brute Ratel C4 botnet C2 server (confidence level: 75%)
file193.161.193.99
XWorm botnet C2 server (confidence level: 75%)
file195.24.237.124
Remcos botnet C2 server (confidence level: 100%)
file81.17.24.58
Remcos botnet C2 server (confidence level: 100%)
file213.209.159.105
SectopRAT botnet C2 server (confidence level: 100%)
file91.121.34.146
Unknown malware botnet C2 server (confidence level: 100%)
file202.154.5.83
Unknown malware botnet C2 server (confidence level: 100%)
file185.214.10.57
Nanocore RAT botnet C2 server (confidence level: 100%)
file103.143.81.175
Unknown malware botnet C2 server (confidence level: 100%)
file85.105.91.10
DarkComet botnet C2 server (confidence level: 100%)
file192.169.69.26
Nanocore RAT botnet C2 server (confidence level: 100%)
file193.26.115.208
Unknown Stealer botnet C2 server (confidence level: 100%)
file94.183.183.156
Stealc botnet C2 server (confidence level: 100%)
file86.106.85.179
Sliver botnet C2 server (confidence level: 100%)
file130.12.180.50
Sliver botnet C2 server (confidence level: 100%)
file193.233.201.12
Sliver botnet C2 server (confidence level: 100%)
file142.202.189.107
AsyncRAT botnet C2 server (confidence level: 100%)
file161.248.179.38
AsyncRAT botnet C2 server (confidence level: 100%)
file91.219.239.121
SectopRAT botnet C2 server (confidence level: 100%)
file102.98.122.130
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file3.89.250.79
Meterpreter botnet C2 server (confidence level: 100%)
file50.17.171.103
Meterpreter botnet C2 server (confidence level: 100%)
file174.142.195.203
Unknown malware botnet C2 server (confidence level: 100%)
file193.32.177.63
Unknown malware botnet C2 server (confidence level: 75%)
file196.251.107.104
AsyncRAT botnet C2 server (confidence level: 100%)
file196.251.107.104
AsyncRAT botnet C2 server (confidence level: 100%)
file103.59.103.30
ValleyRAT botnet C2 server (confidence level: 100%)
file156.254.20.94
ValleyRAT botnet C2 server (confidence level: 100%)
file91.207.174.14
SpyNote botnet C2 server (confidence level: 100%)
file206.119.191.106
ValleyRAT botnet C2 server (confidence level: 100%)
file102.117.164.165
Unknown malware botnet C2 server (confidence level: 75%)
file13.115.235.77
DeimosC2 botnet C2 server (confidence level: 75%)
file188.23.175.59
Eye Pyramid botnet C2 server (confidence level: 75%)
file198.23.173.170
Sliver botnet C2 server (confidence level: 75%)
file217.76.57.92
Sliver botnet C2 server (confidence level: 75%)
file223.215.161.165
DeimosC2 botnet C2 server (confidence level: 75%)
file3.24.130.204
DeimosC2 botnet C2 server (confidence level: 75%)
file39.91.200.45
DeimosC2 botnet C2 server (confidence level: 75%)
file5.252.21.176
DeimosC2 botnet C2 server (confidence level: 75%)
file74.48.31.97
DeimosC2 botnet C2 server (confidence level: 75%)
file115.190.160.206
Cobalt Strike botnet C2 server (confidence level: 100%)
file156.238.234.15
Cobalt Strike botnet C2 server (confidence level: 100%)
file101.200.165.71
Cobalt Strike botnet C2 server (confidence level: 100%)
file41.147.199.45
pupy botnet C2 server (confidence level: 100%)
file149.28.247.86
SectopRAT botnet C2 server (confidence level: 100%)
file80.78.18.113
Unknown malware botnet C2 server (confidence level: 100%)
file178.16.55.205
AdaptixC2 botnet C2 server (confidence level: 100%)
file185.237.166.132
Cobalt Strike botnet C2 server (confidence level: 100%)
file91.121.34.146
Unknown malware botnet C2 server (confidence level: 100%)
file91.92.240.219
ClearFake payload delivery server (confidence level: 100%)
file172.94.18.103
AsyncRAT botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash80
Stealc botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7000
Venom RAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash10443
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
BianLian botnet C2 server (confidence level: 100%)
hash80
NetSupportManager RAT payload delivery server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash23051
ValleyRAT botnet C2 server (confidence level: 100%)
hash14994
Ghost RAT botnet C2 server (confidence level: 100%)
hash9999
Ghost RAT botnet C2 server (confidence level: 100%)
hash8089
Sliver botnet C2 server (confidence level: 100%)
hash8443
Sliver botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash81
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash80
Bashlite botnet C2 server (confidence level: 100%)
hash7001
Meterpreter botnet C2 server (confidence level: 100%)
hash20001
Meterpreter botnet C2 server (confidence level: 100%)
hash3930
Meterpreter botnet C2 server (confidence level: 100%)
hash7700
Empire Downloader botnet C2 server (confidence level: 100%)
hash3608
AsyncRAT botnet C2 server (confidence level: 100%)
hash9000
Unknown malware botnet C2 server (confidence level: 100%)
hash3000
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash5655
RMS botnet C2 server (confidence level: 100%)
hash10001
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7070
Remcos botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash7001
Venom RAT botnet C2 server (confidence level: 100%)
hash80
MimiKatz botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash2222
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash5580
Nanocore RAT botnet C2 server (confidence level: 100%)
hash23052
ValleyRAT botnet C2 server (confidence level: 100%)
hash57483
Remcos botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash5000
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Quasar RAT botnet C2 server (confidence level: 100%)
hash9999
Venom RAT botnet C2 server (confidence level: 100%)
hash8848
DCRat botnet C2 server (confidence level: 100%)
hash7000
DCRat botnet C2 server (confidence level: 100%)
hash80
MimiKatz botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash10790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash50009
Empire Downloader botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash2663
Bashlite botnet C2 server (confidence level: 75%)
hash9999
CastleRAT botnet C2 server (confidence level: 75%)
hash8888
Sliver botnet C2 server (confidence level: 75%)
hash31337
Sliver botnet C2 server (confidence level: 90%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
ClearFake payload delivery server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
FAKEUPDATES payload delivery server (confidence level: 100%)
hash443
FAKEUPDATES payload delivery server (confidence level: 100%)
hash5525
Brute Ratel C4 botnet C2 server (confidence level: 75%)
hash52541
XWorm botnet C2 server (confidence level: 75%)
hash2403
Remcos botnet C2 server (confidence level: 100%)
hash3812
Remcos botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash9092
Unknown malware botnet C2 server (confidence level: 100%)
hash3920
Nanocore RAT botnet C2 server (confidence level: 100%)
hash19091
Unknown malware botnet C2 server (confidence level: 100%)
hash1998
DarkComet botnet C2 server (confidence level: 100%)
hash50470
Nanocore RAT botnet C2 server (confidence level: 100%)
hash1337
Unknown Stealer botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash21381
Sliver botnet C2 server (confidence level: 100%)
hash4433
Sliver botnet C2 server (confidence level: 100%)
hash8001
Sliver botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8080
AsyncRAT botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash48790
Meterpreter botnet C2 server (confidence level: 100%)
hash2077
Meterpreter botnet C2 server (confidence level: 100%)
hash444
Unknown malware botnet C2 server (confidence level: 100%)
hash5001
Unknown malware botnet C2 server (confidence level: 75%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash6666
ValleyRAT botnet C2 server (confidence level: 100%)
hash5050
ValleyRAT botnet C2 server (confidence level: 100%)
hash8848
SpyNote botnet C2 server (confidence level: 100%)
hash1688
ValleyRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash8000
Eye Pyramid botnet C2 server (confidence level: 75%)
hash33911
Sliver botnet C2 server (confidence level: 75%)
hash58008
Sliver botnet C2 server (confidence level: 75%)
hash10250
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash10250
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
pupy botnet C2 server (confidence level: 100%)
hash9000
SectopRAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash4444
AdaptixC2 botnet C2 server (confidence level: 100%)
hash8000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
ClearFake payload delivery server (confidence level: 100%)
hash190
AsyncRAT botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://husnikmeat.com/1q1q.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://husnikmeat.com/js.php
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://ourasolid.com/websockets/local-storage.js
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://ourasolid.com/websockets/service.php
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://ourasolid.com/websockets/session.js
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://positivelike.com/porsche
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://positivelike.com/document
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttp://77.90.60.32/123.txt
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttp://77.90.60.32/y.gre
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://ruzeda.com/blogs/drafts/publish/schedule/seosso/login/mfa/verify/token/refresh/ips/blocklist/whitelist
Havoc botnet C2 (confidence level: 100%)
urlhttps://fast-eda.my/dostavka/lavka/kategorii/zakuski/sushi/sety/skidki/regiony/msk/birylievo
Havoc botnet C2 (confidence level: 100%)
urlhttp://80.76.49.43/login
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://151.242.25.9:9000/login
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://77.110.103.209:3000/pages/login.html
Unknown malware botnet C2 (confidence level: 100%)
urlhttp://193.177.0.235/user/login
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://mukidashiactive.com/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://steamcommunity.com/id/498hd87wt3rfwe32s
CastleRAT botnet C2 (confidence level: 100%)
urlhttp://139.59.238.90:8888/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://d-ac.jp/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://raw.githubusercontent.com/machazoo/source/main/main.txt
Unknown malware payload delivery URL (confidence level: 100%)
urlhttp://103.143.81.175:19091/supershell/login/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://emierich.com/2o2o.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://emierich.com/js.php
KongTuke payload delivery URL (confidence level: 100%)
urlhttp://45.93.20.61/0462fab2d67b49d5.php
Stealc botnet C2 (confidence level: 100%)
urlhttps://selcukpeker.com/d.js
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://www.selcukpeker.com/d.js
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://ourasolid.com/promise/scope.js
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://ourasolid.com/promise/db.php
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://ourasolid.com/promise/json.js
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttp://79.141.172.212/request
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttps://fuckingirlz.com/request
NetSupportManager RAT payload delivery URL (confidence level: 100%)
urlhttp://146.103.104.211/f999fb4b778f4b7a.php
Stealc botnet C2 (confidence level: 100%)
urlhttp://westpointwelbyplay.info:8082/updater?for=5120d3fedd36eac912db54c863ce59bb
Unknown malware botnet C2 (confidence level: 100%)

Domain

ValueDescriptionCopy
domainhusnikmeat.com
KongTuke payload delivery domain (confidence level: 100%)
domainourasolid.com
NetSupportManager RAT payload delivery domain (confidence level: 100%)
domainpositivelike.com
NetSupportManager RAT payload delivery domain (confidence level: 100%)
domainsetup.digitalpointsec.org
Unknown malware botnet C2 domain (confidence level: 100%)
domainrentalsmcx.com
NetSupportManager RAT botnet C2 domain (confidence level: 100%)
domainnyfqeg.f0undoutw2y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjuzmat.f0undoutw2y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsorxep.f0undoutw2y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvaklid.f0undoutw2y.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingipqen.f0undoutw2y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhuzqer.hump7yb0lt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwytlaf.hump7yb0lt.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindoxbim.hump7yb0lt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjivqot.hump7yb0lt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmabneg.hump7yb0lt.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintivqer.g2un7makeup.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhazmiz.g2un7makeup.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmurlop.g2un7makeup.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjebxit.g2un7makeup.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpafqud.g2un7makeup.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsylqen.narr2tpenici1l.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjodxif.narr2tpenici1l.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvexhup.narr2tpenici1l.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingutqer.narr2tpenici1l.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmissmovie.lol
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainmazfil.narr2tpenici1l.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqepxir.m2ximtherm0s.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindavlon.m2ximtherm0s.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhufqam.m2ximtherm0s.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwerpix.m2ximtherm0s.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjoltev.m2ximtherm0s.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkavqet.me2n5precede.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwumxib.me2n5precede.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjertol.me2n5precede.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintooki-hzlbsvr.sbs
Hook botnet C2 domain (confidence level: 100%)
domainsifqen.me2n5precede.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhapdig.me2n5precede.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvyrqet.bramble-zip.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingudxom.bramble-zip.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpaxhel.bramble-zip.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsotquv.bramble-zip.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjemniv.bramble-zip.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzafqon.bramblezip.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmirxet.bramblezip.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindulhev.bramblezip.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwacqis.bramblezip.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintujpen.bramblezip.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingoxhel.v-1-nexettle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbuzqer.v-1-nexettle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsafmid.v-1-nexettle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbooloo.hopto.org
Remcos botnet C2 domain (confidence level: 100%)
domainscannerfiles.dynuddns.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainjenxop.v-1-nexettle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhultiq.v-1-nexettle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnifqex.caskwander.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvupmex.caskwander.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjoltev.caskwander.ru
ClearFake payload delivery domain (confidence level: 100%)
domainderxip.caskwander.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhavqon.caskwander.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingexfum.cask-wander.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintumqer.cask-wander.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwilxot.cask-wander.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpafnel.cask-wander.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjorqev.cask-wander.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindexqen.j1tterfoam.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhapxil.j1tterfoam.ru
ClearFake payload delivery domain (confidence level: 100%)
domainworgip.j1tterfoam.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmynqes.j1tterfoam.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsufvob.j1tterfoam.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintubqer.t0rquefinch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvaxhim.t0rquefinch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwodxet.t0rquefinch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxtroloozyanimailfeeddeals.shop
Unknown RAT botnet C2 domain (confidence level: 100%)
domainnovarandsbvx.info
Unknown RAT botnet C2 domain (confidence level: 100%)
domainstsmithchurchitems.shop
Unknown RAT botnet C2 domain (confidence level: 100%)
domaingrowinggodsgoodnews.info
Unknown RAT botnet C2 domain (confidence level: 100%)
domainwilkensealsivc.shop
Unknown RAT botnet C2 domain (confidence level: 100%)
domaindeuwre.com
Unknown RAT botnet C2 domain (confidence level: 100%)
domainhepnim.t0rquefinch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjylqos.t0rquefinch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlerqen.v1nexettle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnextra.in.net
AsyncRAT botnet C2 domain (confidence level: 50%)
domainguzxip.v1nexettle.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindovnig.v1nexettle.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintifqes.v1nexettle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainharbim.v1nexettle.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsearchservice.cfd
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainmushub.cfd
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainxozqet.gr-1-tfable.ru
ClearFake payload delivery domain (confidence level: 100%)
domainreflecrung.run
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaintivmon.gr-1-tfable.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmepxod.gr-1-tfable.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwudhel.gr-1-tfable.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjafqim.gr-1-tfable.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvudxen.quartzjolt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsafqil.quartzjolt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhemnob.quartzjolt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjorxep.quartzjolt.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintazqiv.quartzjolt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwww.aliyuncloud.icu
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainkezqer.plume-vortex.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwufmib.plume-vortex.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjaxhef.plume-vortex.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintuvqen.plume-vortex.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmorxip.plume-vortex.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjivqam.sn0cklebeam.ru
ClearFake payload delivery domain (confidence level: 100%)
domainharbex.sn0cklebeam.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsousssf-39168.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainqesdul.sn0cklebeam.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvupxir.sn0cklebeam.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindownload.egestx.ru.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaincdn.egestx.ru.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindownload.koz1.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainlogs.koz1.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domaincdn.koz1.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainbendecidos8624blessd.dynuddns.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindownload.rieege.mx
AsyncRAT botnet C2 domain (confidence level: 100%)
domainlogs.rieege.mx
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindownload.21food.cn.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindownload.mingxing.cn.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindownload.chis.cn.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindownload.iciba.cn.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domaincdn.aref.co.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domaindownload.giftingbuddy.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainlogs.giftingbuddy.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domaintazmel.sn0cklebeam.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmotherpure.duckdns.org
Nanocore RAT botnet C2 domain (confidence level: 100%)
domainzylqen.quartz-jolt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxet.kievholod.kiev.ua
Vidar botnet C2 domain (confidence level: 100%)
domainmepxuv.quartz-jolt.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintufhel.quartz-jolt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwodqis.quartz-jolt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvigilantguildsatori.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainjarxim.quartz-jolt.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindexqel.hollowtweak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvuzmip.hollowtweak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhafqes.hollowtweak.ru
ClearFake payload delivery domain (confidence level: 100%)
domainriver.skysh1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincloud.skysh1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxw.skysh1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwepay.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domain9nn.skysh1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwww.slotmachinesno.sa.com
vanillarat botnet C2 domain (confidence level: 100%)
domaindigitalhari.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domaintrace.skysh1eld.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwke.darkfl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domaina6.darkfl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domainemierich.com
KongTuke payload delivery domain (confidence level: 100%)
domainshift.darkfl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domainridge.darkfl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingbb9.darkfl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domainpixel.n1ghtbreeze.ru
ClearFake payload delivery domain (confidence level: 100%)
domainersel33640.freedynamicdns.net
DarkComet botnet C2 domain (confidence level: 100%)
domainblue.n1ghtbreeze.ru
ClearFake payload delivery domain (confidence level: 100%)
domainairvcastro.duckdns.org
Nanocore RAT botnet C2 domain (confidence level: 100%)
domainember.n1ghtbreeze.ru
ClearFake payload delivery domain (confidence level: 100%)
domainselcukpeker.com
NetSupportManager RAT payload delivery domain (confidence level: 100%)
domainforge.n1ghtbreeze.ru
ClearFake payload delivery domain (confidence level: 100%)
domain0mp8j.n1ghtbreeze.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmiraisystem1337.xyz
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainfire.cl0udriver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainalpha.cl0udriver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqoda.cl0udriver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainh26t3.cl0udriver.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkoz2.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainshield.cl0udriver.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindehw4.m1stycliff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzqb9.m1stycliff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsj.m1stycliff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnqr.m1stycliff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainy9zqm.m1stycliff.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincryptocurrencyexchange24.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainhan-duck-soo-apologizes.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainmalware.sun.win
Quasar RAT botnet C2 domain (confidence level: 75%)
domainsarahl.ru.com
Quasar RAT botnet C2 domain (confidence level: 75%)
domainline.bluef0rest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsct12.app.link
Unknown malware payload delivery domain (confidence level: 100%)
domaindekstop-app.app
Unknown malware payload delivery domain (confidence level: 100%)
domainn3z.bluef0rest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainform.bluef0rest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnk.bluef0rest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzs.bluef0rest.ru
ClearFake payload delivery domain (confidence level: 100%)
domainroadyear.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainrifledog.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainflow.cloudf0rm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbeixn.dy-store.tech
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainhollow.cloudf0rm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshadow.cloudf0rm.ru
ClearFake payload delivery domain (confidence level: 100%)
domaint3vlw.cloudf0rm.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindark.cloudf0rm.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnova.storml1ght.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincore.storml1ght.ru
ClearFake payload delivery domain (confidence level: 100%)
domainforest.storml1ght.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlayer.storml1ght.ru
ClearFake payload delivery domain (confidence level: 100%)
domain818ne.storml1ght.ru
ClearFake payload delivery domain (confidence level: 100%)
domain4xm.f1rewave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmoney001.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domain0028.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domaindownload.koz2.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainapi.koz2.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainlogs.koz2.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainunikey.sun.win
AsyncRAT botnet C2 domain (confidence level: 100%)
domainunikey.sarahl.ru.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainsafeguard.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainsafe.safeguard.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainmalware.safeguard.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domaindelta.f1rewave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsafebrowsing.star.co.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainsafebrowsing.amal.sa.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainsafebrowsing.sunwin.moi
AsyncRAT botnet C2 domain (confidence level: 100%)
domainsafebrowsing.pbcollege.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainsafebrowsing.elijah.ru.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainvietkey.sarahl.ru.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domaintpxyj-83-252-34-181.a.free.pinggy.link
Quasar RAT botnet C2 domain (confidence level: 100%)
domainv2.ctdrpu.za.com
Quasar RAT botnet C2 domain (confidence level: 100%)
domainsecurity.citystore.in.net
Quasar RAT botnet C2 domain (confidence level: 100%)
domainspam.onthewifi.com
NjRAT botnet C2 domain (confidence level: 100%)
domain802.f1rewave.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkjrif.f1rewave.ru
ClearFake payload delivery domain (confidence level: 100%)
domaincliff.f1rewave.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingamma.softsh1ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkvrv5.softsh1ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8k.softsh1ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domain4wl.softsh1ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjmqk.softsh1ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domainomega.silentl1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintsxw.silentl1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2f.silentl1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlnpw.silentl1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domain7iml.silentl1ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainriod.darkm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxyyk.darkm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyap.darkm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvector.darkm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfonts.sentihey.dedyn.io
Havoc botnet C2 domain (confidence level: 100%)
domainaccounts.sentihey.dedyn.io
Havoc botnet C2 domain (confidence level: 100%)
domainogs.sentihey.dedyn.io
Havoc botnet C2 domain (confidence level: 100%)
domainmeetol.sbs
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainbeta.darkm1nt.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrpf.windsh1ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domaini6.windsh1ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domainu4.windsh1ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domains6h.windsh1ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domainy5ien.windsh1ft.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnoverfault.org
ClearFake payload delivery domain (confidence level: 100%)
domain7z.nightfl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintt.nightfl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyzf.nightfl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domainus.nightfl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwind.nightfl0w.ru
ClearFake payload delivery domain (confidence level: 100%)
domainah.shadowl1nk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainu1z.shadowl1nk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainjh89g.shadowl1nk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainscq.shadowl1nk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainwave.shadowl1nk.ru
ClearFake payload delivery domain (confidence level: 100%)
domainroh.f1relayer.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsilent.f1relayer.ru
ClearFake payload delivery domain (confidence level: 100%)
domainm5ax.f1relayer.ru
ClearFake payload delivery domain (confidence level: 100%)
domainlight.f1relayer.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkxc.f1relayer.ru
ClearFake payload delivery domain (confidence level: 100%)
domaind2.n1ghtcore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainid.n1ghtcore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainspark.n1ghtcore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnexus.n1ghtcore.ru
ClearFake payload delivery domain (confidence level: 100%)
domainy6gbc.n1ghtcore.ru
ClearFake payload delivery domain (confidence level: 100%)
domaingate.skyf0rge.ru
ClearFake payload delivery domain (confidence level: 100%)
domain6wz.skyf0rge.ru
ClearFake payload delivery domain (confidence level: 100%)
domaind0.skyf0rge.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmint.skyf0rge.ru
ClearFake payload delivery domain (confidence level: 100%)
domain679.skyf0rge.ru
ClearFake payload delivery domain (confidence level: 100%)
domainnl.rainst0ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainstorm.rainst0ne.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsky.rainst0ne.ru
ClearFake payload delivery domain (confidence level: 100%)

Threat ID: 694b2edc0a0f3cdd674e7536

Added to database: 12/24/2025, 12:07:56 AM

Last enriched: 12/24/2025, 12:08:10 AM

Last updated: 12/24/2025, 3:39:57 AM

Views: 6

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats