ThreatFox IOCs for 2025-12-25
ThreatFox IOCs for 2025-12-25
AI Analysis
Technical Summary
The data provided describes a ThreatFox IOC feed entry dated December 25, 2025, categorized under malware with emphasis on OSINT (Open Source Intelligence), payload delivery, and network activity. ThreatFox is a platform that aggregates and shares Indicators of Compromise to aid cybersecurity professionals in detecting and mitigating threats. This entry does not specify any particular malware variant, affected software versions, or vulnerabilities but rather represents a set of threat intelligence indicators intended for situational awareness and detection. The absence of known exploits in the wild and lack of patch availability suggest that this is not an active zero-day or critical vulnerability but rather intelligence on potential or emerging threats. The threat level and analysis scores are low to moderate, indicating limited immediate risk but relevance for monitoring. The data lacks concrete technical details such as specific attack vectors, payload characteristics, or exploitation methods. As such, it is primarily useful for security teams to update detection rules, monitor network traffic for suspicious activity, and enhance their OSINT capabilities. The medium severity rating reflects the potential for these indicators to assist in identifying malicious activity but does not indicate an imminent or widespread threat. This type of intelligence is valuable for proactive defense but requires contextualization with other threat data to assess real risk.
Potential Impact
For European organizations, the impact of this ThreatFox IOC feed entry is primarily in enhancing threat detection and situational awareness rather than responding to an active or critical threat. The medium severity suggests that while the indicators may help identify malicious payload delivery attempts or network activity, there is no direct evidence of exploitation or compromise. Organizations relying on threat intelligence feeds can use this data to improve their detection capabilities, potentially preventing malware infections or network intrusions. However, since no specific vulnerabilities or exploits are detailed, the immediate risk to confidentiality, integrity, or availability is limited. The impact is therefore more strategic, supporting incident response and threat hunting efforts rather than requiring urgent patching or remediation. European entities with mature security operations centers (SOCs) and threat intelligence teams will benefit most from integrating this information. Conversely, organizations without such capabilities may find limited direct impact. Overall, the threat intelligence contributes to a layered defense posture but does not represent a direct operational threat at this time.
Mitigation Recommendations
1. Integrate ThreatFox IOC feeds and similar OSINT sources into Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) systems to enhance detection of suspicious payload delivery and network activity. 2. Regularly update detection rules and signatures based on the latest threat intelligence to identify emerging malware indicators. 3. Conduct proactive threat hunting exercises using the provided IOCs to identify potential compromises early. 4. Ensure network segmentation and strict monitoring of inbound and outbound traffic to detect anomalous payload delivery attempts. 5. Train security analysts to contextualize OSINT data and correlate it with internal logs for effective incident response. 6. Maintain up-to-date asset inventories and vulnerability management programs to reduce attack surface, even though no patches are currently available for this specific threat. 7. Collaborate with European cybersecurity information sharing organizations to validate and enrich threat intelligence. 8. Avoid reliance on this IOC feed alone; use it as part of a comprehensive threat intelligence strategy that includes multiple sources and active monitoring.
Affected Countries
Germany, France, United Kingdom, Netherlands, Italy, Spain
Indicators of Compromise
- url: https://aacobson.com/3w3w.js
- domain: aacobson.com
- url: https://aacobson.com/js.php
- url: https://193.233.198.6/
- domain: dit.kievholod.kiev.ua
- domain: aa888.br.com
- domain: premierservices365.com
- file: 176.65.132.233
- hash: 3778
- file: 139.196.223.82
- hash: 443
- file: 176.188.139.132
- hash: 8000
- file: 137.220.223.158
- hash: 14994
- domain: kyalli3.testingweblink.com
- domain: messagepathconfirmation.download
- file: 13.61.25.218
- hash: 3333
- file: 217.71.203.187
- hash: 1724
- file: 164.92.71.38
- hash: 3333
- file: 198.13.47.54
- hash: 443
- file: 51.91.253.110
- hash: 443
- file: 51.91.253.110
- hash: 3333
- file: 176.96.131.76
- hash: 2083
- file: 34.209.244.2
- hash: 443
- file: 178.130.46.100
- hash: 2083
- file: 178.130.46.100
- hash: 8443
- file: 8.141.11.18
- hash: 8080
- domain: bandizip.band
- domain: capframex.org
- domain: easeus.tech
- domain: ksdbmerge.com
- domain: magixvegaspro.com
- domain: metatrader.forum
- domain: topazphoto.org
- domain: trading-view.io
- domain: userbenchmark.tech
- domain: verdent-ai.com
- domain: wondersharerecoverit.com
- domain: ytddownloader.org
- domain: cakewallet-app.com
- domain: cefaz-notazsp.help
- domain: cefaz-notazsp.click
- domain: cefaz-notazsp.icu
- domain: cemarenergia-portal.help
- domain: cemarenergia-portal.click
- domain: database-download3d.blog
- domain: database-download3d.online
- file: 184.174.32.240
- hash: 8080
- file: 135.225.120.199
- hash: 80
- file: 144.202.27.59
- hash: 443
- file: 66.39.155.182
- hash: 443
- domain: 1p53.fl-0-wmortar.ru
- domain: flint.fl-0-wmortar.ru
- domain: bnh19.fl-0-wmortar.ru
- domain: duit123slot.it.com
- domain: r15yi.fl-0-wmortar.ru
- domain: xt.fl-0-wmortar.ru
- domain: ocev.bracketloam.ru
- domain: vixen.bracketloam.ru
- domain: 3ym.bracketloam.ru
- domain: u0.bracketloam.ru
- domain: jl.bracketloam.ru
- domain: qnb11.bracket-loam.ru
- domain: 6x79j.bracket-loam.ru
- domain: 7gp8l.bracket-loam.ru
- domain: quw6l.bracket-loam.ru
- domain: 86ds.bracket-loam.ru
- domain: ui.dua1i5mmuksun.ru
- domain: alpha.dua1i5mmuksun.ru
- domain: t5.dua1i5mmuksun.ru
- file: 138.68.155.86
- hash: 7707
- domain: ul34.dua1i5mmuksun.ru
- domain: crest.dua1i5mmuksun.ru
- domain: pi87t.ga8tukh1yat.ru
- domain: stone.ga8tukh1yat.ru
- domain: ewrd3.ga8tukh1yat.ru
- domain: wgm.ga8tukh1yat.ru
- domain: deep.ga8tukh1yat.ru
- file: 176.97.210.242
- hash: 3778
- domain: aso.grim1atin0s.ru
- domain: ridge.grim1atin0s.ru
- domain: path.grim1atin0s.ru
- domain: f8bkf.grim1atin0s.ru
- domain: pcjls.grim1atin0s.ru
- domain: breeze.f0rtunmentho1.ru
- domain: 8gr.f0rtunmentho1.ru
- domain: 989.f0rtunmentho1.ru
- domain: blue.f0rtunmentho1.ru
- file: 47.109.189.74
- hash: 8080
- file: 192.121.162.190
- hash: 8081
- file: 105.101.159.176
- hash: 1604
- file: 191.107.84.131
- hash: 5061
- file: 106.52.70.64
- hash: 3389
- file: 184.174.32.240
- hash: 80
- file: 45.143.167.7
- hash: 8001
- file: 5.178.103.58
- hash: 8808
- file: 144.126.149.104
- hash: 3000
- file: 144.126.149.104
- hash: 80
- file: 144.31.207.174
- hash: 9000
- file: 46.32.200.145
- hash: 35
- file: 1.52.68.101
- hash: 443
- domain: llamafr.click
- file: 144.172.109.159
- hash: 443
- file: 154.213.179.33
- hash: 8080
- domain: hyidb.f0rtunmentho1.ru
- file: 47.128.153.134
- hash: 443
- file: 216.92.95.60
- hash: 443
- file: 185.190.250.104
- hash: 80
- file: 217.216.73.61
- hash: 443
- file: 196.251.107.104
- hash: 1177
- file: 196.251.107.23
- hash: 1177
- domain: loop.0ctave5pairi.ru
- domain: 6o2p1.0ctave5pairi.ru
- domain: wrbe.0ctave5pairi.ru
- domain: nova.0ctave5pairi.ru
- domain: 2bej.0ctave5pairi.ru
- file: 91.92.243.55
- hash: 2404
- domain: m5ex.f2rewel1lever.ru
- domain: z5a.f2rewel1lever.ru
- domain: forest.f2rewel1lever.ru
- domain: field.f2rewel1lever.ru
- domain: 0vj.f2rewel1lever.ru
- domain: cw.acr0b2tdiffer.ru
- domain: flow.acr0b2tdiffer.ru
- file: 168.222.28.168
- hash: 6000
- domain: frost.acr0b2tdiffer.ru
- domain: hd.acr0b2tdiffer.ru
- domain: ember.acr0b2tdiffer.ru
- domain: spark.g0rico1ormica.ru
- domain: wfewefwef-51975.portmap.host
- domain: report242424.dynuddns.com
- domain: glow.g0rico1ormica.ru
- domain: zf.g0rico1ormica.ru
- domain: vector.g0rico1ormica.ru
- domain: cq4g.g0rico1ormica.ru
- domain: trace.t2kec2reujo.ru
- domain: 7ew.t2kec2reujo.ru
- domain: ew.t2kec2reujo.ru
- domain: tdh.t2kec2reujo.ru
- file: 172.105.177.140
- hash: 51515
- domain: 5y8t4.t2kec2reujo.ru
- domain: mist.5lau8htwater.ru
- domain: ux6cb.5lau8htwater.ru
- domain: shift.5lau8htwater.ru
- domain: 3m.5lau8htwater.ru
- domain: wu.5lau8htwater.ru
- domain: kvf1h.conf1dcorr0de.ru
- file: 42.193.249.173
- hash: 8888
- file: 81.69.253.132
- hash: 801
- file: 117.72.192.170
- hash: 443
- file: 47.92.110.59
- hash: 8086
- file: 84.241.22.227
- hash: 9090
- file: 167.99.246.88
- hash: 39691
- file: 185.221.199.206
- hash: 12345
- domain: delta.conf1dcorr0de.ru
- file: 23.235.182.120
- hash: 29113
- domain: zh.conf1dcorr0de.ru
- file: 77.83.198.16
- hash: 443
- file: 144.126.149.104
- hash: 2009
- file: 185.39.19.101
- hash: 9000
- file: 118.68.121.69
- hash: 443
- file: 18.167.103.46
- hash: 80
- file: 212.11.64.114
- hash: 80
- file: 167.172.67.216
- hash: 31413
- file: 103.177.47.239
- hash: 3790
- file: 103.177.47.241
- hash: 3790
- file: 103.177.47.179
- hash: 3790
- file: 103.177.47.234
- hash: 3790
- file: 54.173.170.130
- hash: 443
- domain: dx.conf1dcorr0de.ru
- file: 8.219.51.115
- hash: 5868
- file: 27.124.53.62
- hash: 447
- file: 38.181.23.21
- hash: 443
- file: 43.248.172.161
- hash: 5050
- file: 103.241.72.240
- hash: 5050
- file: 108.187.7.148
- hash: 447
- file: 122.10.119.114
- hash: 443
- file: 156.247.40.81
- hash: 6666
- file: 207.148.45.54
- hash: 5050
- domain: pjf.conf1dcorr0de.ru
- domain: m9.s1ogan5timul.ru
- domain: storm.s1ogan5timul.ru
- domain: abd0r.s1ogan5timul.ru
- domain: beta.s1ogan5timul.ru
- domain: sqewtj.za.com
- domain: ehpgqp.sa.com
- domain: shield.s1ogan5timul.ru
- domain: nujwg2.sa.com
- file: 201.204.61.163
- hash: 443
- file: 35.133.217.240
- hash: 443
- domain: qvomu.comp0ser5kid.ru
- domain: mv.comp0ser5kid.ru
- domain: hollow.comp0ser5kid.ru
- domain: dark.comp0ser5kid.ru
- domain: hb999.comp0ser5kid.ru
- domain: cloud.entert2inru8.ru
- domain: kc.entert2inru8.ru
- domain: 8iyp.entert2inru8.ru
- domain: omega.entert2inru8.ru
- domain: bstsj.entert2inru8.ru
- domain: lgq.entire1y5ming.ru
- domain: dw.entire1y5ming.ru
- domain: gate.entire1y5ming.ru
- domain: 4hiyz.entire1y5ming.ru
- domain: 8f.entire1y5ming.ru
- domain: rain.1ntrude7truha.ru
- domain: 50.1ntrude7truha.ru
- domain: 4o.1ntrude7truha.ru
- domain: a1d.1ntrude7truha.ru
- domain: wind.1ntrude7truha.ru
- file: 85.208.110.151
- hash: 7777
- domain: 56i3.n2imenei8hbor.ru
- domain: 4lj.n2imenei8hbor.ru
- domain: ekl.n2imenei8hbor.ru
- file: 103.212.187.23
- hash: 80
- file: 193.134.211.75
- hash: 80
- file: 144.126.149.104
- hash: 2004
- file: 102.117.173.207
- hash: 7443
- file: 23.230.253.148
- hash: 4782
- file: 151.241.113.217
- hash: 3333
- file: 157.173.205.170
- hash: 5448
- file: 167.235.23.30
- hash: 3333
- file: 45.83.131.176
- hash: 3333
- file: 158.160.169.53
- hash: 3333
- domain: sba.n2imenei8hbor.ru
- domain: 972d1.n2imenei8hbor.ru
- domain: shadow.c2dmiumgho5t.ru
- domain: y7z3h.c2dmiumgho5t.ru
- domain: rvzvl.c2dmiumgho5t.ru
- domain: yju0.c2dmiumgho5t.ru
- domain: 0v79.c2dmiumgho5t.ru
- domain: me0.lo5ermedi0c.ru
- domain: line.lo5ermedi0c.ru
- file: 43.134.163.224
- hash: 443
- file: 193.35.154.205
- hash: 2822
- domain: 0zlrw.lo5ermedi0c.ru
- domain: mr4y9.lo5ermedi0c.ru
- domain: hill-modern.gl.at.ply.gg
- domain: iamg7bh-58861.portmap.host
- domain: teens-resource.gl.at.ply.gg
- file: 97.107.138.143
- hash: 6667
- domain: transadvice.org
- domain: proxey.publicvm.com
- domain: malware.sarahl.ru.com
- domain: download.mx1.sa.com
- domain: logs.mx1.sa.com
- domain: download.ojxqy.sa.com
- domain: cdn.ojxqy.sa.com
- domain: download.remont-center.ru.com
- domain: logs.remont-center.ru.com
- domain: images.remont-center.ru.com
- domain: elsa3eed.dynalias.com
- domain: asj177.com
- domain: asj188.com
- domain: asj199.com
- domain: asj277.com
- domain: asj288.com
- domain: asj299.com
- file: 207.148.90.150
- hash: 9002
- file: 144.126.149.104
- hash: 8808
- file: 137.220.224.15
- hash: 443
- domain: download.78win88.co.com
- domain: api.78win88.co.com
- file: 91.151.89.147
- hash: 1604
- file: 69.235.49.58
- hash: 4782
- file: 151.242.63.252
- hash: 4488
- file: 199.101.111.210
- hash: 3790
- file: 199.101.111.212
- hash: 3790
- file: 98.88.75.248
- hash: 443
- file: 3.83.107.167
- hash: 49153
- file: 199.101.111.214
- hash: 3790
- file: 199.101.111.129
- hash: 3790
- domain: odm6j.lo5ermedi0c.ru
- file: 178.79.182.67
- hash: 443
- file: 44.208.147.17
- hash: 80
- url: https://garnevf.cyou/api
- file: 206.119.191.106
- hash: 1699
- domain: qykr.fori5po1u.ru
- domain: 7nt.fori5po1u.ru
- domain: gamma.fori5po1u.ru
- file: 147.182.187.2
- hash: 443
- file: 183.66.27.19
- hash: 58475
- file: 63.178.163.156
- hash: 31337
- domain: vex.fori5po1u.ru
- domain: suhcare.live
- domain: wochelp.top
- domain: trumpisperfect.com
- domain: fox.fori5po1u.ru
- domain: q1ezk.cloudsh1ft.ru
- file: 86.54.42.154
- hash: 443
- domain: xjayj.cloudsh1ft.ru
- domain: vs.cloudsh1ft.ru
- domain: pj.cloudsh1ft.ru
- domain: gj2.cloudsh1ft.ru
- domain: zym.windf0x.ru
- domain: util.advertising-platform.top
- file: 194.14.217.158
- hash: 443
- domain: y9.windf0x.ru
- url: http://svclsc.com/ms/index.php
- domain: 7jy9.windf0x.ru
- domain: akshf.windf0x.ru
- domain: j16.windf0x.ru
- domain: n7c5.rainf0rm.ru
- domain: 9s.rainf0rm.ru
- domain: ob.rainf0rm.ru
- domain: w0.rainf0rm.ru
- domain: qmiq.rainf0rm.ru
- domain: 5s1.silentf0rest.ru
- domain: nexus.silentf0rest.ru
- domain: form.silentf0rest.ru
- domain: k1.silentf0rest.ru
- domain: 61qtv.silentf0rest.ru
- domain: 3qdt.m1stypath.ru
- domain: blb.m1stypath.ru
- file: 202.73.4.100
- hash: 6363
- domain: 0cawm.m1stypath.ru
- domain: mind.m1stypath.ru
- domain: shannonmystiqueeldritch.com
- domain: 4lg.m1stypath.ru
- domain: ij4s4.bluef0rm.ru
- domain: whistlesong.xyz
- domain: k459j.bluef0rm.ru
- domain: pixel.bluef0rm.ru
- domain: 9wk.bluef0rm.ru
- domain: 3ec2k.bluef0rm.ru
- domain: 63.n1ghtcrest.ru
- domain: an7i.n1ghtcrest.ru
- domain: 1y1zd.n1ghtcrest.ru
- domain: yvt.n1ghtcrest.ru
- url: http://62.60.226.159/geter/index.php
- domain: 7bc4p.n1ghtcrest.ru
- domain: w51.cl0udstone.ru
- domain: gn.cl0udstone.ru
- domain: gieo.cl0udstone.ru
- domain: k7.cl0udstone.ru
- domain: qr8m.cl0udstone.ru
- domain: f5d6x.darkw1nd.ru
- domain: zuab.darkw1nd.ru
- domain: 7g.darkw1nd.ru
- domain: lfm9.darkw1nd.ru
- file: 81.136.59.84
- hash: 1339
- file: 38.47.238.110
- hash: 8888
- file: 185.221.22.226
- hash: 8808
- file: 211.197.94.135
- hash: 8808
- file: 195.24.237.17
- hash: 6606
- file: 213.209.159.68
- hash: 9000
- file: 79.110.49.219
- hash: 5555
- file: 137.220.224.16
- hash: 443
- file: 137.220.224.18
- hash: 443
- file: 173.255.252.25
- hash: 443
- domain: rvrc.darkw1nd.ru
- domain: ku.deepc0rest.ru
- domain: aq9.deepc0rest.ru
- domain: 1f.deepc0rest.ru
- domain: kbn.deepc0rest.ru
- domain: aqmj4.deepc0rest.ru
- domain: lgna.windsh1eld.ru
- domain: kk.windsh1eld.ru
- domain: ykf.windsh1eld.ru
- domain: d9j.windsh1eld.ru
- domain: j9o9f.windsh1eld.ru
- domain: 42b.skyfl0w.ru
- domain: ouu.skyfl0w.ru
- domain: hwr.skyfl0w.ru
- domain: et.skyfl0w.ru
- domain: 5mao.skyfl0w.ru
- domain: night.cl0udbreeze.ru
- domain: jp2.cl0udbreeze.ru
- domain: sft.cl0udbreeze.ru
- domain: yp.frostsh1ft.ru
- domain: sdgp3.frostsh1ft.ru
- domain: s3.frostsh1ft.ru
- domain: tqep6.frostsh1ft.ru
- domain: s7.frostsh1ft.ru
- domain: starmls1234-61151.portmap.host
- url: http://95.164.123.123
- domain: ox.windl1ne.ru
- file: 38.148.244.12
- hash: 6666
- file: 38.148.244.12
- hash: 8888
- file: 38.148.244.12
- hash: 80
- file: 138.68.155.86
- hash: 1177
- domain: 13va.windl1ne.ru
- domain: n4.windl1ne.ru
- domain: 9rdg.windl1ne.ru
- domain: oqs9.windl1ne.ru
- domain: 4eie3.rainsh1eld.ru
- domain: ez04d.rainsh1eld.ru
- domain: gelz.rainsh1eld.ru
- domain: 6dr.rainsh1eld.ru
- domain: 2hedr.rainsh1eld.ru
- file: 104.140.154.111
- hash: 30226
- file: 104.140.154.133
- hash: 30219
- file: 104.140.154.49
- hash: 30129
- file: 104.140.154.59
- hash: 30186
- file: 119.36.33.35
- hash: 10250
- domain: m7.shadowm1st.ru
- file: 155.102.62.60
- hash: 4506
- file: 198.23.173.170
- hash: 8008
- file: 209.54.101.164
- hash: 88
- file: 47.158.147.211
- hash: 443
- file: 96.30.193.34
- hash: 8888
- domain: ebhm.shadowm1st.ru
- domain: w0t.shadowm1st.ru
- domain: pgt.shadowm1st.ru
- domain: x94.shadowm1st.ru
- domain: tu1.deepf0rm.ru
- domain: xc7.deepf0rm.ru
- url: http://77.110.123.23/ce369e7324834845.php
- domain: gzif.deepf0rm.ru
- domain: dhtk.deepf0rm.ru
- domain: 6fnuy.deepf0rm.ru
- domain: 1hm2.stormm1nd.ru
- domain: lk51.stormm1nd.ru
- domain: 33y5t.stormm1nd.ru
- domain: z3.stormm1nd.ru
- domain: p7.stormm1nd.ru
- domain: 62spf.n1ghtflow.ru
- file: 159.198.75.249
- hash: 443
- file: 137.220.223.156
- hash: 14994
- file: 154.44.10.137
- hash: 8080
- file: 194.180.49.40
- hash: 2404
- file: 4.216.218.82
- hash: 443
- file: 197.147.55.61
- hash: 8808
- file: 144.31.207.175
- hash: 9000
- file: 47.111.79.13
- hash: 6379
- file: 171.5.179.225
- hash: 30349
- file: 154.213.179.16
- hash: 8080
- file: 44.208.147.17
- hash: 443
- file: 112.196.50.214
- hash: 443
- file: 185.190.250.104
- hash: 443
- domain: u3u9.n1ghtflow.ru
- domain: 3dxd.n1ghtflow.ru
- domain: ao.n1ghtflow.ru
- domain: db33.n1ghtflow.ru
- domain: eqj.cloudf1eld.ru
- domain: eq.cloudf1eld.ru
- domain: j3.cloudf1eld.ru
- domain: zx.cloudf1eld.ru
- file: 197.234.221.30
- hash: 8887
- domain: 1ovxt.cloudf1eld.ru
- domain: u25u.darkf0x.ru
- domain: r7t.darkf0x.ru
- domain: 8z.darkf0x.ru
- domain: 8uh.darkf0x.ru
- domain: vh2f.darkf0x.ru
- domain: awq.bluec0rest.ru
- domain: kuoh.bluec0rest.ru
- domain: dby.bluec0rest.ru
- domain: juph.bluec0rest.ru
- domain: q7ts.bluec0rest.ru
- domain: vexlup.e9uatp2nth.ru
- domain: qar9id.e9uatp2nth.ru
- domain: moltav.e9uatp2nth.ru
- file: 145.249.109.155
- hash: 443
- file: 145.249.109.155
- hash: 80
- domain: syr3un.e9uatp2nth.ru
- url: http://145.249.109.155/bullnecked.php
- url: https://145.249.109.155/bullnecked.php
- domain: jeplox.e9uatp2nth.ru
- domain: brixen.bi1ingnause2.ru
- domain: zul4ep.bi1ingnause2.ru
- domain: havtor.bi1ingnause2.ru
- domain: myn5iq.bi1ingnause2.ru
- domain: tervul.bi1ingnause2.ru
- domain: kudram.hiredp1ayfu1.ru
- domain: wex3il.hiredp1ayfu1.ru
- domain: jomvet.hiredp1ayfu1.ru
- domain: salqor.hiredp1ayfu1.ru
- domain: pixhun.hiredp1ayfu1.ru
- domain: dagvex.a5kin8insur.ru
- domain: felmor.a5kin8insur.ru
- domain: truzik.a5kin8insur.ru
- domain: hav7el.a5kin8insur.ru
- domain: mirdax.a5kin8insur.ru
- domain: blusom.b1uesgr2mp.ru
- domain: ker9al.b1uesgr2mp.ru
- domain: vylgor.b1uesgr2mp.ru
- domain: saflin.b1uesgr2mp.ru
ThreatFox IOCs for 2025-12-25
Description
ThreatFox IOCs for 2025-12-25
AI-Powered Analysis
Technical Analysis
The data provided describes a ThreatFox IOC feed entry dated December 25, 2025, categorized under malware with emphasis on OSINT (Open Source Intelligence), payload delivery, and network activity. ThreatFox is a platform that aggregates and shares Indicators of Compromise to aid cybersecurity professionals in detecting and mitigating threats. This entry does not specify any particular malware variant, affected software versions, or vulnerabilities but rather represents a set of threat intelligence indicators intended for situational awareness and detection. The absence of known exploits in the wild and lack of patch availability suggest that this is not an active zero-day or critical vulnerability but rather intelligence on potential or emerging threats. The threat level and analysis scores are low to moderate, indicating limited immediate risk but relevance for monitoring. The data lacks concrete technical details such as specific attack vectors, payload characteristics, or exploitation methods. As such, it is primarily useful for security teams to update detection rules, monitor network traffic for suspicious activity, and enhance their OSINT capabilities. The medium severity rating reflects the potential for these indicators to assist in identifying malicious activity but does not indicate an imminent or widespread threat. This type of intelligence is valuable for proactive defense but requires contextualization with other threat data to assess real risk.
Potential Impact
For European organizations, the impact of this ThreatFox IOC feed entry is primarily in enhancing threat detection and situational awareness rather than responding to an active or critical threat. The medium severity suggests that while the indicators may help identify malicious payload delivery attempts or network activity, there is no direct evidence of exploitation or compromise. Organizations relying on threat intelligence feeds can use this data to improve their detection capabilities, potentially preventing malware infections or network intrusions. However, since no specific vulnerabilities or exploits are detailed, the immediate risk to confidentiality, integrity, or availability is limited. The impact is therefore more strategic, supporting incident response and threat hunting efforts rather than requiring urgent patching or remediation. European entities with mature security operations centers (SOCs) and threat intelligence teams will benefit most from integrating this information. Conversely, organizations without such capabilities may find limited direct impact. Overall, the threat intelligence contributes to a layered defense posture but does not represent a direct operational threat at this time.
Mitigation Recommendations
1. Integrate ThreatFox IOC feeds and similar OSINT sources into Security Information and Event Management (SIEM) and Endpoint Detection and Response (EDR) systems to enhance detection of suspicious payload delivery and network activity. 2. Regularly update detection rules and signatures based on the latest threat intelligence to identify emerging malware indicators. 3. Conduct proactive threat hunting exercises using the provided IOCs to identify potential compromises early. 4. Ensure network segmentation and strict monitoring of inbound and outbound traffic to detect anomalous payload delivery attempts. 5. Train security analysts to contextualize OSINT data and correlate it with internal logs for effective incident response. 6. Maintain up-to-date asset inventories and vulnerability management programs to reduce attack surface, even though no patches are currently available for this specific threat. 7. Collaborate with European cybersecurity information sharing organizations to validate and enrich threat intelligence. 8. Avoid reliance on this IOC feed alone; use it as part of a comprehensive threat intelligence strategy that includes multiple sources and active monitoring.
Affected Countries
For access to advanced analysis and higher rate limits, contact root@offseq.com
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- 457ec6ac-0d47-426b-9e62-aecc062ca991
- Original Timestamp
- 1766707388
Indicators of Compromise
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://aacobson.com/3w3w.js | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttps://aacobson.com/js.php | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttps://193.233.198.6/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://garnevf.cyou/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttp://svclsc.com/ms/index.php | Amadey botnet C2 (confidence level: 100%) | |
urlhttp://62.60.226.159/geter/index.php | Unknown Stealer botnet C2 (confidence level: 100%) | |
urlhttp://95.164.123.123 | Stealc botnet C2 (confidence level: 100%) | |
urlhttp://77.110.123.23/ce369e7324834845.php | Stealc botnet C2 (confidence level: 100%) | |
urlhttp://145.249.109.155/bullnecked.php | AMOS botnet C2 (confidence level: 100%) | |
urlhttps://145.249.109.155/bullnecked.php | AMOS botnet C2 (confidence level: 100%) |
Domain
| Value | Description | Copy |
|---|---|---|
domainaacobson.com | KongTuke payload delivery domain (confidence level: 100%) | |
domaindit.kievholod.kiev.ua | Vidar botnet C2 domain (confidence level: 100%) | |
domainaa888.br.com | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainpremierservices365.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainkyalli3.testingweblink.com | Havoc botnet C2 domain (confidence level: 100%) | |
domainmessagepathconfirmation.download | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainbandizip.band | Unknown malware botnet C2 domain (confidence level: 75%) | |
domaincapframex.org | Unknown malware botnet C2 domain (confidence level: 75%) | |
domaineaseus.tech | Unknown malware botnet C2 domain (confidence level: 75%) | |
domainksdbmerge.com | Unknown malware botnet C2 domain (confidence level: 75%) | |
domainmagixvegaspro.com | Unknown malware botnet C2 domain (confidence level: 75%) | |
domainmetatrader.forum | Unknown malware botnet C2 domain (confidence level: 75%) | |
domaintopazphoto.org | Unknown malware botnet C2 domain (confidence level: 75%) | |
domaintrading-view.io | Unknown malware botnet C2 domain (confidence level: 75%) | |
domainuserbenchmark.tech | Unknown malware botnet C2 domain (confidence level: 75%) | |
domainverdent-ai.com | Unknown malware botnet C2 domain (confidence level: 75%) | |
domainwondersharerecoverit.com | Unknown malware botnet C2 domain (confidence level: 75%) | |
domainytddownloader.org | Unknown malware botnet C2 domain (confidence level: 75%) | |
domaincakewallet-app.com | Unknown malware botnet C2 domain (confidence level: 75%) | |
domaincefaz-notazsp.help | Unknown malware botnet C2 domain (confidence level: 75%) | |
domaincefaz-notazsp.click | Unknown malware botnet C2 domain (confidence level: 75%) | |
domaincefaz-notazsp.icu | Unknown malware botnet C2 domain (confidence level: 75%) | |
domaincemarenergia-portal.help | Unknown malware botnet C2 domain (confidence level: 75%) | |
domaincemarenergia-portal.click | Unknown malware botnet C2 domain (confidence level: 75%) | |
domaindatabase-download3d.blog | Unknown malware botnet C2 domain (confidence level: 75%) | |
domaindatabase-download3d.online | Unknown malware botnet C2 domain (confidence level: 75%) | |
domain1p53.fl-0-wmortar.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainflint.fl-0-wmortar.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbnh19.fl-0-wmortar.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainduit123slot.it.com | AsyncRAT botnet C2 domain (confidence level: 50%) | |
domainr15yi.fl-0-wmortar.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxt.fl-0-wmortar.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainocev.bracketloam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvixen.bracketloam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain3ym.bracketloam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainu0.bracketloam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjl.bracketloam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqnb11.bracket-loam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain6x79j.bracket-loam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7gp8l.bracket-loam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainquw6l.bracket-loam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain86ds.bracket-loam.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainui.dua1i5mmuksun.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainalpha.dua1i5mmuksun.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaint5.dua1i5mmuksun.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainul34.dua1i5mmuksun.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincrest.dua1i5mmuksun.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpi87t.ga8tukh1yat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstone.ga8tukh1yat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainewrd3.ga8tukh1yat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwgm.ga8tukh1yat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindeep.ga8tukh1yat.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainaso.grim1atin0s.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainridge.grim1atin0s.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpath.grim1atin0s.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainf8bkf.grim1atin0s.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpcjls.grim1atin0s.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbreeze.f0rtunmentho1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain8gr.f0rtunmentho1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain989.f0rtunmentho1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainblue.f0rtunmentho1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainllamafr.click | Havoc botnet C2 domain (confidence level: 100%) | |
domainhyidb.f0rtunmentho1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainloop.0ctave5pairi.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain6o2p1.0ctave5pairi.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwrbe.0ctave5pairi.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnova.0ctave5pairi.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain2bej.0ctave5pairi.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainm5ex.f2rewel1lever.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainz5a.f2rewel1lever.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainforest.f2rewel1lever.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfield.f2rewel1lever.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain0vj.f2rewel1lever.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincw.acr0b2tdiffer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainflow.acr0b2tdiffer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfrost.acr0b2tdiffer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhd.acr0b2tdiffer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainember.acr0b2tdiffer.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainspark.g0rico1ormica.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwfewefwef-51975.portmap.host | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainreport242424.dynuddns.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainglow.g0rico1ormica.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzf.g0rico1ormica.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvector.g0rico1ormica.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincq4g.g0rico1ormica.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintrace.t2kec2reujo.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7ew.t2kec2reujo.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainew.t2kec2reujo.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintdh.t2kec2reujo.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain5y8t4.t2kec2reujo.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmist.5lau8htwater.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainux6cb.5lau8htwater.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshift.5lau8htwater.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain3m.5lau8htwater.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwu.5lau8htwater.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkvf1h.conf1dcorr0de.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindelta.conf1dcorr0de.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzh.conf1dcorr0de.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindx.conf1dcorr0de.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpjf.conf1dcorr0de.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainm9.s1ogan5timul.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstorm.s1ogan5timul.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainabd0r.s1ogan5timul.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbeta.s1ogan5timul.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsqewtj.za.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainehpgqp.sa.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainshield.s1ogan5timul.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnujwg2.sa.com | Quasar RAT botnet C2 domain (confidence level: 75%) | |
domainqvomu.comp0ser5kid.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmv.comp0ser5kid.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhollow.comp0ser5kid.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindark.comp0ser5kid.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhb999.comp0ser5kid.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaincloud.entert2inru8.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkc.entert2inru8.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain8iyp.entert2inru8.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainomega.entert2inru8.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbstsj.entert2inru8.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlgq.entire1y5ming.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindw.entire1y5ming.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingate.entire1y5ming.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain4hiyz.entire1y5ming.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain8f.entire1y5ming.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrain.1ntrude7truha.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain50.1ntrude7truha.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain4o.1ntrude7truha.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaina1d.1ntrude7truha.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwind.1ntrude7truha.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain56i3.n2imenei8hbor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain4lj.n2imenei8hbor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainekl.n2imenei8hbor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsba.n2imenei8hbor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain972d1.n2imenei8hbor.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshadow.c2dmiumgho5t.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainy7z3h.c2dmiumgho5t.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrvzvl.c2dmiumgho5t.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainyju0.c2dmiumgho5t.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain0v79.c2dmiumgho5t.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainme0.lo5ermedi0c.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainline.lo5ermedi0c.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain0zlrw.lo5ermedi0c.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmr4y9.lo5ermedi0c.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhill-modern.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainiamg7bh-58861.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainteens-resource.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domaintransadvice.org | Remcos botnet C2 domain (confidence level: 100%) | |
domainproxey.publicvm.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainmalware.sarahl.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindownload.mx1.sa.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainlogs.mx1.sa.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindownload.ojxqy.sa.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaincdn.ojxqy.sa.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindownload.remont-center.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainlogs.remont-center.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainimages.remont-center.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainelsa3eed.dynalias.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainasj177.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainasj188.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainasj199.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainasj277.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainasj288.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainasj299.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindownload.78win88.co.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainapi.78win88.co.com | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainodm6j.lo5ermedi0c.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqykr.fori5po1u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7nt.fori5po1u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingamma.fori5po1u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvex.fori5po1u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsuhcare.live | Unknown RAT botnet C2 domain (confidence level: 100%) | |
domainwochelp.top | Unknown RAT botnet C2 domain (confidence level: 100%) | |
domaintrumpisperfect.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainfox.fori5po1u.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainq1ezk.cloudsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxjayj.cloudsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvs.cloudsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpj.cloudsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingj2.cloudsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzym.windf0x.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainutil.advertising-platform.top | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domainy9.windf0x.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7jy9.windf0x.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainakshf.windf0x.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainj16.windf0x.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainn7c5.rainf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain9s.rainf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainob.rainf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainw0.rainf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqmiq.rainf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain5s1.silentf0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnexus.silentf0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainform.silentf0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaink1.silentf0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain61qtv.silentf0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain3qdt.m1stypath.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainblb.m1stypath.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain0cawm.m1stypath.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmind.m1stypath.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainshannonmystiqueeldritch.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domain4lg.m1stypath.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainij4s4.bluef0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwhistlesong.xyz | Unknown Loader botnet C2 domain (confidence level: 100%) | |
domaink459j.bluef0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpixel.bluef0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain9wk.bluef0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain3ec2k.bluef0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain63.n1ghtcrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainan7i.n1ghtcrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain1y1zd.n1ghtcrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainyvt.n1ghtcrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7bc4p.n1ghtcrest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainw51.cl0udstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingn.cl0udstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingieo.cl0udstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaink7.cl0udstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqr8m.cl0udstone.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainf5d6x.darkw1nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzuab.darkw1nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain7g.darkw1nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlfm9.darkw1nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainrvrc.darkw1nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainku.deepc0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainaq9.deepc0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain1f.deepc0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkbn.deepc0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainaqmj4.deepc0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlgna.windsh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkk.windsh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainykf.windsh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaind9j.windsh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainj9o9f.windsh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain42b.skyfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainouu.skyfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhwr.skyfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainet.skyfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain5mao.skyfl0w.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainnight.cl0udbreeze.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjp2.cl0udbreeze.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsft.cl0udbreeze.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainyp.frostsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsdgp3.frostsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domains3.frostsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintqep6.frostsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domains7.frostsh1ft.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainstarmls1234-61151.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainox.windl1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain13va.windl1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainn4.windl1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain9rdg.windl1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainoqs9.windl1ne.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain4eie3.rainsh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainez04d.rainsh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingelz.rainsh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain6dr.rainsh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain2hedr.rainsh1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainm7.shadowm1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainebhm.shadowm1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainw0t.shadowm1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpgt.shadowm1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainx94.shadowm1st.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintu1.deepf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainxc7.deepf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaingzif.deepf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindhtk.deepf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain6fnuy.deepf0rm.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain1hm2.stormm1nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainlk51.stormm1nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain33y5t.stormm1nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainz3.stormm1nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainp7.stormm1nd.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain62spf.n1ghtflow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainu3u9.n1ghtflow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain3dxd.n1ghtflow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainao.n1ghtflow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindb33.n1ghtflow.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineqj.cloudf1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaineq.cloudf1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainj3.cloudf1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzx.cloudf1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain1ovxt.cloudf1eld.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainu25u.darkf0x.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainr7t.darkf0x.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain8z.darkf0x.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domain8uh.darkf0x.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvh2f.darkf0x.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainawq.bluec0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkuoh.bluec0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindby.bluec0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjuph.bluec0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainq7ts.bluec0rest.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvexlup.e9uatp2nth.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainqar9id.e9uatp2nth.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoltav.e9uatp2nth.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsyr3un.e9uatp2nth.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjeplox.e9uatp2nth.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrixen.bi1ingnause2.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainzul4ep.bi1ingnause2.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhavtor.bi1ingnause2.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmyn5iq.bi1ingnause2.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintervul.bi1ingnause2.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainkudram.hiredp1ayfu1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainwex3il.hiredp1ayfu1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainjomvet.hiredp1ayfu1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsalqor.hiredp1ayfu1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainpixhun.hiredp1ayfu1.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaindagvex.a5kin8insur.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainfelmor.a5kin8insur.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domaintruzik.a5kin8insur.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainhav7el.a5kin8insur.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainmirdax.a5kin8insur.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainblusom.b1uesgr2mp.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainker9al.b1uesgr2mp.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainvylgor.b1uesgr2mp.ru | ClearFake payload delivery domain (confidence level: 100%) | |
domainsaflin.b1uesgr2mp.ru | ClearFake payload delivery domain (confidence level: 100%) |
File
| Value | Description | Copy |
|---|---|---|
file176.65.132.233 | Mirai botnet C2 server (confidence level: 80%) | |
file139.196.223.82 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file176.188.139.132 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file137.220.223.158 | Ghost RAT botnet C2 server (confidence level: 75%) | |
file13.61.25.218 | Unknown malware botnet C2 server (confidence level: 100%) | |
file217.71.203.187 | Unknown malware botnet C2 server (confidence level: 100%) | |
file164.92.71.38 | Unknown malware botnet C2 server (confidence level: 100%) | |
file198.13.47.54 | Unknown malware botnet C2 server (confidence level: 100%) | |
file51.91.253.110 | Unknown malware botnet C2 server (confidence level: 100%) | |
file51.91.253.110 | Unknown malware botnet C2 server (confidence level: 100%) | |
file176.96.131.76 | Unknown malware botnet C2 server (confidence level: 100%) | |
file34.209.244.2 | Unknown malware botnet C2 server (confidence level: 100%) | |
file178.130.46.100 | Unknown malware botnet C2 server (confidence level: 100%) | |
file178.130.46.100 | Unknown malware botnet C2 server (confidence level: 100%) | |
file8.141.11.18 | Unknown malware botnet C2 server (confidence level: 100%) | |
file184.174.32.240 | Sliver botnet C2 server (confidence level: 100%) | |
file135.225.120.199 | Bashlite botnet C2 server (confidence level: 100%) | |
file144.202.27.59 | Unknown malware botnet C2 server (confidence level: 100%) | |
file66.39.155.182 | Unknown malware botnet C2 server (confidence level: 100%) | |
file138.68.155.86 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file176.97.210.242 | Mirai botnet C2 server (confidence level: 80%) | |
file47.109.189.74 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file192.121.162.190 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file105.101.159.176 | DarkComet botnet C2 server (confidence level: 100%) | |
file191.107.84.131 | Remcos botnet C2 server (confidence level: 100%) | |
file106.52.70.64 | Sliver botnet C2 server (confidence level: 100%) | |
file184.174.32.240 | Sliver botnet C2 server (confidence level: 100%) | |
file45.143.167.7 | Sliver botnet C2 server (confidence level: 100%) | |
file5.178.103.58 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file144.126.149.104 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file144.126.149.104 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file144.31.207.174 | SectopRAT botnet C2 server (confidence level: 100%) | |
file46.32.200.145 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file1.52.68.101 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file144.172.109.159 | Havoc botnet C2 server (confidence level: 100%) | |
file154.213.179.33 | DCRat botnet C2 server (confidence level: 100%) | |
file47.128.153.134 | Unknown malware botnet C2 server (confidence level: 100%) | |
file216.92.95.60 | Unknown malware botnet C2 server (confidence level: 100%) | |
file185.190.250.104 | Unknown malware botnet C2 server (confidence level: 100%) | |
file217.216.73.61 | Unknown malware botnet C2 server (confidence level: 100%) | |
file196.251.107.104 | XWorm botnet C2 server (confidence level: 75%) | |
file196.251.107.23 | XWorm botnet C2 server (confidence level: 75%) | |
file91.92.243.55 | Remcos botnet C2 server (confidence level: 100%) | |
file168.222.28.168 | XWorm botnet C2 server (confidence level: 75%) | |
file172.105.177.140 | Mirai botnet C2 server (confidence level: 80%) | |
file42.193.249.173 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file81.69.253.132 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file117.72.192.170 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file47.92.110.59 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file84.241.22.227 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file167.99.246.88 | Mirai botnet C2 server (confidence level: 75%) | |
file185.221.199.206 | Bashlite botnet C2 server (confidence level: 75%) | |
file23.235.182.120 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file77.83.198.16 | Unknown RAT botnet C2 server (confidence level: 100%) | |
file144.126.149.104 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file185.39.19.101 | SectopRAT botnet C2 server (confidence level: 100%) | |
file118.68.121.69 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file18.167.103.46 | Nimplant botnet C2 server (confidence level: 100%) | |
file212.11.64.114 | Unknown malware botnet C2 server (confidence level: 100%) | |
file167.172.67.216 | Chaos botnet C2 server (confidence level: 100%) | |
file103.177.47.239 | Meterpreter botnet C2 server (confidence level: 100%) | |
file103.177.47.241 | Meterpreter botnet C2 server (confidence level: 100%) | |
file103.177.47.179 | Meterpreter botnet C2 server (confidence level: 100%) | |
file103.177.47.234 | Meterpreter botnet C2 server (confidence level: 100%) | |
file54.173.170.130 | Unknown malware botnet C2 server (confidence level: 100%) | |
file8.219.51.115 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file27.124.53.62 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file38.181.23.21 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file43.248.172.161 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file103.241.72.240 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file108.187.7.148 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file122.10.119.114 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file156.247.40.81 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file207.148.45.54 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file201.204.61.163 | QakBot botnet C2 server (confidence level: 75%) | |
file35.133.217.240 | QakBot botnet C2 server (confidence level: 75%) | |
file85.208.110.151 | XWorm botnet C2 server (confidence level: 75%) | |
file103.212.187.23 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file193.134.211.75 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file144.126.149.104 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file102.117.173.207 | Unknown malware botnet C2 server (confidence level: 100%) | |
file23.230.253.148 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file151.241.113.217 | Unknown malware botnet C2 server (confidence level: 100%) | |
file157.173.205.170 | Unknown malware botnet C2 server (confidence level: 100%) | |
file167.235.23.30 | Unknown malware botnet C2 server (confidence level: 100%) | |
file45.83.131.176 | Unknown malware botnet C2 server (confidence level: 100%) | |
file158.160.169.53 | Unknown malware botnet C2 server (confidence level: 100%) | |
file43.134.163.224 | AdaptixC2 botnet C2 server (confidence level: 75%) | |
file193.35.154.205 | Bashlite botnet C2 server (confidence level: 75%) | |
file97.107.138.143 | Remcos botnet C2 server (confidence level: 100%) | |
file207.148.90.150 | Sliver botnet C2 server (confidence level: 100%) | |
file144.126.149.104 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file137.220.224.15 | Venom RAT botnet C2 server (confidence level: 100%) | |
file91.151.89.147 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file69.235.49.58 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file151.242.63.252 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file199.101.111.210 | Meterpreter botnet C2 server (confidence level: 100%) | |
file199.101.111.212 | Meterpreter botnet C2 server (confidence level: 100%) | |
file98.88.75.248 | Meterpreter botnet C2 server (confidence level: 100%) | |
file3.83.107.167 | Meterpreter botnet C2 server (confidence level: 100%) | |
file199.101.111.214 | Meterpreter botnet C2 server (confidence level: 100%) | |
file199.101.111.129 | Meterpreter botnet C2 server (confidence level: 100%) | |
file178.79.182.67 | Unknown malware botnet C2 server (confidence level: 100%) | |
file44.208.147.17 | Unknown malware botnet C2 server (confidence level: 100%) | |
file206.119.191.106 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file147.182.187.2 | AdaptixC2 botnet C2 server (confidence level: 75%) | |
file183.66.27.19 | AdaptixC2 botnet C2 server (confidence level: 75%) | |
file63.178.163.156 | AdaptixC2 botnet C2 server (confidence level: 75%) | |
file86.54.42.154 | Mirai botnet C2 server (confidence level: 75%) | |
file194.14.217.158 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file202.73.4.100 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file81.136.59.84 | DarkComet botnet C2 server (confidence level: 100%) | |
file38.47.238.110 | Unknown malware botnet C2 server (confidence level: 100%) | |
file185.221.22.226 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file211.197.94.135 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file195.24.237.17 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file213.209.159.68 | SectopRAT botnet C2 server (confidence level: 100%) | |
file79.110.49.219 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file137.220.224.16 | Venom RAT botnet C2 server (confidence level: 100%) | |
file137.220.224.18 | Venom RAT botnet C2 server (confidence level: 100%) | |
file173.255.252.25 | Unknown malware botnet C2 server (confidence level: 100%) | |
file38.148.244.12 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file38.148.244.12 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file38.148.244.12 | ValleyRAT botnet C2 server (confidence level: 100%) | |
file138.68.155.86 | NjRAT botnet C2 server (confidence level: 100%) | |
file104.140.154.111 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file104.140.154.133 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file104.140.154.49 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file104.140.154.59 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file119.36.33.35 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file155.102.62.60 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file198.23.173.170 | Sliver botnet C2 server (confidence level: 75%) | |
file209.54.101.164 | Remcos botnet C2 server (confidence level: 75%) | |
file47.158.147.211 | QakBot botnet C2 server (confidence level: 75%) | |
file96.30.193.34 | Sliver botnet C2 server (confidence level: 75%) | |
file159.198.75.249 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file137.220.223.156 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file154.44.10.137 | Ghost RAT botnet C2 server (confidence level: 100%) | |
file194.180.49.40 | Remcos botnet C2 server (confidence level: 100%) | |
file4.216.218.82 | Sliver botnet C2 server (confidence level: 100%) | |
file197.147.55.61 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file144.31.207.175 | SectopRAT botnet C2 server (confidence level: 100%) | |
file47.111.79.13 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file171.5.179.225 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file154.213.179.16 | DCRat botnet C2 server (confidence level: 100%) | |
file44.208.147.17 | Unknown malware botnet C2 server (confidence level: 100%) | |
file112.196.50.214 | Unknown malware botnet C2 server (confidence level: 100%) | |
file185.190.250.104 | Unknown malware botnet C2 server (confidence level: 100%) | |
file197.234.221.30 | XWorm botnet C2 server (confidence level: 75%) | |
file145.249.109.155 | AMOS botnet C2 server (confidence level: 100%) | |
file145.249.109.155 | AMOS botnet C2 server (confidence level: 100%) |
Hash
| Value | Description | Copy |
|---|---|---|
hash3778 | Mirai botnet C2 server (confidence level: 80%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8000 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash14994 | Ghost RAT botnet C2 server (confidence level: 75%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash1724 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash2083 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash2083 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8080 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8080 | Sliver botnet C2 server (confidence level: 100%) | |
hash80 | Bashlite botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash7707 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash3778 | Mirai botnet C2 server (confidence level: 80%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8081 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash1604 | DarkComet botnet C2 server (confidence level: 100%) | |
hash5061 | Remcos botnet C2 server (confidence level: 100%) | |
hash3389 | Sliver botnet C2 server (confidence level: 100%) | |
hash80 | Sliver botnet C2 server (confidence level: 100%) | |
hash8001 | Sliver botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash3000 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash80 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash35 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash443 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash8080 | DCRat botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash1177 | XWorm botnet C2 server (confidence level: 75%) | |
hash1177 | XWorm botnet C2 server (confidence level: 75%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash6000 | XWorm botnet C2 server (confidence level: 75%) | |
hash51515 | Mirai botnet C2 server (confidence level: 80%) | |
hash8888 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash801 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash8086 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash9090 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash39691 | Mirai botnet C2 server (confidence level: 75%) | |
hash12345 | Bashlite botnet C2 server (confidence level: 75%) | |
hash29113 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Unknown RAT botnet C2 server (confidence level: 100%) | |
hash2009 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash443 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash80 | Nimplant botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash31413 | Chaos botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash5868 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash447 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash443 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash5050 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash5050 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash447 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash443 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash6666 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash5050 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash443 | QakBot botnet C2 server (confidence level: 75%) | |
hash443 | QakBot botnet C2 server (confidence level: 75%) | |
hash7777 | XWorm botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2004 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash4782 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash5448 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | AdaptixC2 botnet C2 server (confidence level: 75%) | |
hash2822 | Bashlite botnet C2 server (confidence level: 75%) | |
hash6667 | Remcos botnet C2 server (confidence level: 100%) | |
hash9002 | Sliver botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash443 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash1604 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash4782 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash4488 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash443 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash49153 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash1699 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash443 | AdaptixC2 botnet C2 server (confidence level: 75%) | |
hash58475 | AdaptixC2 botnet C2 server (confidence level: 75%) | |
hash31337 | AdaptixC2 botnet C2 server (confidence level: 75%) | |
hash443 | Mirai botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash6363 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash1339 | DarkComet botnet C2 server (confidence level: 100%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash6606 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash5555 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash443 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash443 | Venom RAT botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash6666 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash8888 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash80 | ValleyRAT botnet C2 server (confidence level: 100%) | |
hash1177 | NjRAT botnet C2 server (confidence level: 100%) | |
hash30226 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash30219 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash30129 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash30186 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash10250 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash4506 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash8008 | Sliver botnet C2 server (confidence level: 75%) | |
hash88 | Remcos botnet C2 server (confidence level: 75%) | |
hash443 | QakBot botnet C2 server (confidence level: 75%) | |
hash8888 | Sliver botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash14994 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash8080 | Ghost RAT botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash9000 | SectopRAT botnet C2 server (confidence level: 100%) | |
hash6379 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash30349 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash8080 | DCRat botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash8887 | XWorm botnet C2 server (confidence level: 75%) | |
hash443 | AMOS botnet C2 server (confidence level: 100%) | |
hash80 | AMOS botnet C2 server (confidence level: 100%) |
Threat ID: 694dd26a8e70994989cf121e
Added to database: 12/26/2025, 12:10:18 AM
Last enriched: 12/26/2025, 12:10:31 AM
Last updated: 12/26/2025, 4:55:50 AM
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
ThreatFox IOCs for 2025-12-24
MediumThreatFox IOCs for 2025-12-23
MediumDissecting a Multi-Stage macOS Infostealer
MediumNew MacSync Stealer Disguised as Trusted Mac App Hunts Your Saved Passwords
MediumRansomware Hits Romanian Water Authority, 1000 Systems Knocked Offline
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.