Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2025-12-27

0
Medium
Published: Sat Dec 27 2025 (12/27/2025, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2025-12-27

AI-Powered Analysis

AILast updated: 12/30/2025, 22:14:42 UTC

Technical Analysis

The provided information pertains to a ThreatFox feed entry dated December 27, 2025, describing malware-related Indicators of Compromise (IOCs) primarily associated with OSINT and network activity aimed at payload delivery. ThreatFox is a platform that aggregates threat intelligence, including IOCs, to assist in identifying malicious activity. This entry is categorized under OSINT and network activity, indicating that the threat involves leveraging open-source intelligence techniques and network-based vectors to deliver malicious payloads. However, the entry lacks specific technical details such as affected software versions, concrete indicators, or exploit mechanisms. The threat level is rated as medium, with a threatLevel metric of 2 and distribution metric of 3, suggesting moderate dissemination or targeting scope. There are no known exploits in the wild, no patches available, and no CWE identifiers, which implies that this is either a newly observed threat or one that is still under analysis. The absence of detailed indicators limits the ability to perform signature-based detection or targeted mitigation. The threat likely involves network activity that could be used to deliver malware payloads, potentially exploiting OSINT techniques to identify vulnerable targets or gather reconnaissance data. The TLP (Traffic Light Protocol) white tag indicates that the information is publicly shareable without restrictions. Overall, this entry serves as an alert to monitor for emerging IOCs related to OSINT-driven payload delivery malware, emphasizing the need for vigilance in network monitoring and threat intelligence consumption.

Potential Impact

For European organizations, the impact of this threat could manifest as increased exposure to malware delivered through network-based vectors informed by OSINT techniques. Such payload delivery mechanisms can lead to unauthorized access, data exfiltration, or disruption of services depending on the malware's capabilities. The medium severity rating suggests a moderate risk level, with potential impacts on confidentiality and integrity if payloads successfully compromise systems. Given the lack of known exploits and patches, organizations may face challenges in preemptively defending against this threat without updated intelligence. The threat could particularly affect sectors relying heavily on open-source intelligence for operational purposes or those with extensive network exposure. Disruption or compromise could lead to reputational damage, regulatory penalties under GDPR if personal data is involved, and operational downtime. The absence of detailed indicators means that detection and response may rely heavily on heuristic and behavioral analysis rather than signature-based methods. European entities with critical infrastructure or high-value data assets could be targeted for reconnaissance and subsequent payload delivery, amplifying potential impacts.

Mitigation Recommendations

1. Integrate ThreatFox and other OSINT threat intelligence feeds into Security Information and Event Management (SIEM) systems to enhance detection capabilities for emerging IOCs. 2. Employ advanced network monitoring tools capable of detecting anomalous payload delivery activity, including deep packet inspection and behavioral analytics. 3. Conduct regular threat hunting exercises focused on OSINT-driven attack vectors and payload delivery patterns. 4. Harden network perimeter defenses by implementing strict egress and ingress filtering, segmentation, and zero-trust principles to limit lateral movement. 5. Train security teams to recognize OSINT exploitation tactics and incorporate this knowledge into incident response playbooks. 6. Maintain up-to-date endpoint detection and response (EDR) solutions with heuristic and anomaly detection capabilities to identify novel malware behaviors. 7. Collaborate with national and European cybersecurity centers to share intelligence and receive timely alerts on evolving threats. 8. Since no patches are available, emphasize proactive detection and containment rather than reliance on vulnerability remediation. 9. Regularly review and update OSINT usage policies to minimize exposure to adversary reconnaissance. 10. Implement multi-factor authentication and strict access controls to reduce the impact of potential payload delivery compromises.

Need more detailed analysis?Upgrade to Pro Console

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
19c332a3-5fb6-4a65-a5be-134c14db5a20
Original Timestamp
1766880186

Indicators of Compromise

Domain

ValueDescriptionCopy
domainkoz7.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainkoz9.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainkoz3.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainkoz4.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainkoz6.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainkoz8.in.net
AsyncRAT botnet C2 domain (confidence level: 100%)
domainteklynx.eu.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainq.ciberseguridad-eia.xyz
Unknown malware botnet C2 domain (confidence level: 100%)
domainx9ka4m3w.quartz-punch.ru
ClearFake payload delivery domain (confidence level: 100%)
domaind9o15ky4.quartz-punch.ru
ClearFake payload delivery domain (confidence level: 100%)
domainimdeveloper.work.gd
Quasar RAT botnet C2 domain (confidence level: 75%)
domain280krm6i.fl1pbramble.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkg5991s6.fl1pbramble.ru
ClearFake payload delivery domain (confidence level: 100%)
domain4voy0soi.t0gglefern.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsrow43xf.t0gglefern.ru
ClearFake payload delivery domain (confidence level: 100%)
domainbwlhpb27.j1nkspur.ru
ClearFake payload delivery domain (confidence level: 100%)
domainhd01chih.j1nkspur.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxrbjetr5.bristle-cove.ru
ClearFake payload delivery domain (confidence level: 100%)
domainw37usb1b.bristle-cove.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmw6agx4t.hushripple.ru
ClearFake payload delivery domain (confidence level: 100%)
domainc05e0yah.hushripple.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmessikoko2014.no-ip.biz
NjRAT botnet C2 domain (confidence level: 100%)
domainvhglsckb.hush-ripple.ru
ClearFake payload delivery domain (confidence level: 100%)
domaindtr2u19m.hush-ripple.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8rkjy130.bristlecove.ru
ClearFake payload delivery domain (confidence level: 100%)
domaink62hnb6k.bristlecove.ru
ClearFake payload delivery domain (confidence level: 100%)
domainshalyunkotmoroz-104.icu
Unknown malware botnet C2 domain (confidence level: 100%)
domainviewblood.info
Unknown Loader botnet C2 domain (confidence level: 100%)
domainbooksbabies.info
Unknown Loader botnet C2 domain (confidence level: 100%)
domaingrassturkey.info
Unknown Loader botnet C2 domain (confidence level: 100%)
domainpaperbee.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainum2fa09y.j-1-nkspur.ru
ClearFake payload delivery domain (confidence level: 100%)
domainkla87xnt.j-1-nkspur.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintailcoat.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domain5pgut9ly.givin8karba5.ru
ClearFake payload delivery domain (confidence level: 100%)
domain45wyxveb.givin8karba5.ru
ClearFake payload delivery domain (confidence level: 100%)
domain3t29yzra.5purbu7y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainz63jsowz.5purbu7y.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8fltdnni.5purbu7y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainy2sv71w4.5purbu7y.ru
ClearFake payload delivery domain (confidence level: 100%)
domain4uw50lrg.5purbu7y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrnml2bsj.5purbu7y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainerspnnas.5purbu7y.ru
ClearFake payload delivery domain (confidence level: 100%)
domainmiraslkx.c0nfectgod5on.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintfuvb9xb.c0nfectgod5on.ru
ClearFake payload delivery domain (confidence level: 100%)
domain33zvn57u.c0nfectgod5on.ru
ClearFake payload delivery domain (confidence level: 100%)
domainsosato-31557.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domaincepte-kampanya-2026.cfd
Hook botnet C2 domain (confidence level: 100%)
domainy59d2xt3.1nterject0il.ru
ClearFake payload delivery domain (confidence level: 100%)
domainaugox4go.1nterject0il.ru
ClearFake payload delivery domain (confidence level: 100%)
domain1usljhth.1nterject0il.ru
ClearFake payload delivery domain (confidence level: 100%)
domaino11u1d4p.get2b0ut.ru
ClearFake payload delivery domain (confidence level: 100%)
domain95ejtn2v.get2b0ut.ru
ClearFake payload delivery domain (confidence level: 100%)
domain9h54jr6k.get2b0ut.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzh.goog1e.dpdns.org
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainf4s1ud3i.h0wevpro5eca.ru
ClearFake payload delivery domain (confidence level: 100%)
domainypbudxdj.h0wevpro5eca.ru
ClearFake payload delivery domain (confidence level: 100%)
domain7mqyam5a.h0wevpro5eca.ru
ClearFake payload delivery domain (confidence level: 100%)
domainr7ohz2wt.fabu1ou5down.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintd24nm0b.fabu1ou5down.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintybt39bz.fabu1ou5down.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfwmi46ip.ai7uninit1at.ru
ClearFake payload delivery domain (confidence level: 100%)
domainoraamrw7.ai7uninit1at.ru
ClearFake payload delivery domain (confidence level: 100%)
domaintgophp9p.ai7uninit1at.ru
ClearFake payload delivery domain (confidence level: 100%)
domainb2c82xwr.repe2t5tuffy.ru
ClearFake payload delivery domain (confidence level: 100%)
domain5qtw3lvf.repe2t5tuffy.ru
ClearFake payload delivery domain (confidence level: 100%)
domainj7f3fm89.repe2t5tuffy.ru
ClearFake payload delivery domain (confidence level: 100%)
domainaw4e97im.cerem0nyiwas1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqyaf95d8.cerem0nyiwas1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainb12mtww0.cerem0nyiwas1.ru
ClearFake payload delivery domain (confidence level: 100%)
domainh8fd573x.a9uedmu5eum.ru
ClearFake payload delivery domain (confidence level: 100%)
domainm6vc0q91.a9uedmu5eum.ru
ClearFake payload delivery domain (confidence level: 100%)
domainrq44wt3c.a9uedmu5eum.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzwssy2gy.b2dmintonper5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainj73qaq77.b2dmintonper5.ru
ClearFake payload delivery domain (confidence level: 100%)
domainp9xz8kwz.b2dmintonper5.ru
ClearFake payload delivery domain (confidence level: 100%)
domain80jm3i5h.crypt5t2te.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzx5666xc.crypt5t2te.ru
ClearFake payload delivery domain (confidence level: 100%)
domainqm3y81ja.crypt5t2te.ru
ClearFake payload delivery domain (confidence level: 100%)
domainc22.yourbigbro.shop
Cobalt Strike botnet C2 domain (confidence level: 75%)
domainzxv70ud6.s0ci0ltendency.ru
ClearFake payload delivery domain (confidence level: 100%)
domaina5ganxmg.s0ci0ltendency.ru
ClearFake payload delivery domain (confidence level: 100%)
domaink2xyv9zj.s0ci0ltendency.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2jznszsn.redf1ee7.ru
ClearFake payload delivery domain (confidence level: 100%)
domaine6xa096z.redf1ee7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainw2q9lxtj.redf1ee7.ru
ClearFake payload delivery domain (confidence level: 100%)
domaind44vdnpu.dealblitz.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainmhjmwloj.rabattkiste.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainz22sc59w.rabattkiste.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainfi8vr6q1.rabattkiste.qpon
ClearFake payload delivery domain (confidence level: 100%)
domain4ry8jdls.sparmarkt.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainc4y3itze.sparmarkt.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainzylxz5wp.sparmarkt.qpon
ClearFake payload delivery domain (confidence level: 100%)
domain7b4m2pvx.perkmeister.qpon
ClearFake payload delivery domain (confidence level: 100%)
domain4a4cn2sm.perkmeister.qpon
ClearFake payload delivery domain (confidence level: 100%)
domain7ylfs86u.perkmeister.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainozezesx1.couponforge.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainbu7nil0q.couponforge.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainispg4tzl.couponforge.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainvml9rdmh.bonusquelle.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainyyce0en9.bonusquelle.qpon
ClearFake payload delivery domain (confidence level: 100%)
domain6g3xqw6s.bonusquelle.qpon
ClearFake payload delivery domain (confidence level: 100%)
domain84sruvb9.bargainbucht.qpon
ClearFake payload delivery domain (confidence level: 100%)
domaincisun35q.bargainbucht.qpon
ClearFake payload delivery domain (confidence level: 100%)
domain9pbhrc3o.bargainbucht.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainyhkd41e4.savefalke.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainr4ojz98h.savefalke.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainhhgyqyai.savefalke.qpon
ClearFake payload delivery domain (confidence level: 100%)
domaintspmo-40154.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainavatarcoder.ddns.net
XWorm botnet C2 domain (confidence level: 75%)
domainqjrkh8m1.savefalke.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainljogytxh.dealzauber.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainp6baqeca.dealzauber.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainz724fxb3.dealzauber.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainp31dr0bs.dealzauber.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainctnodeexporter.chatutor.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainctdify.chatutor.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainliverfatdiet.stechdaily.com
Havoc botnet C2 domain (confidence level: 100%)
domaingithub.ciberseguridad-eia.xyz
Unknown malware botnet C2 domain (confidence level: 100%)
domainapi.ciberseguridad-eia.xyz
Unknown malware botnet C2 domain (confidence level: 100%)
domain6kl4y41v.preisdrop.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainnci5ab3x.preisdrop.qpon
ClearFake payload delivery domain (confidence level: 100%)
domaintf72zgyh.preisdrop.qpon
ClearFake payload delivery domain (confidence level: 100%)
domain6warimna.preisdrop.qpon
ClearFake payload delivery domain (confidence level: 100%)
domainqfjal5xm.redf1ee7.ru
ClearFake payload delivery domain (confidence level: 100%)
domainfd4ol8zs.redf1ee7.ru
ClearFake payload delivery domain (confidence level: 100%)
domaininhibyln.redf1ee7.ru
ClearFake payload delivery domain (confidence level: 100%)
domain2sv9bgxa.redf1ee7.ru
ClearFake payload delivery domain (confidence level: 100%)
domain83x6d0ks.compres5text0l.ru
ClearFake payload delivery domain (confidence level: 100%)
domainiyhrsk8v.compres5text0l.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8ouero1r.compres5text0l.ru
ClearFake payload delivery domain (confidence level: 100%)
domain5cw7rw2b.compres5text0l.ru
ClearFake payload delivery domain (confidence level: 100%)
domainl4r97zzd.c2bba8etip.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzfbbu8bs.c2bba8etip.ru
ClearFake payload delivery domain (confidence level: 100%)
domainvrna7onz.c2bba8etip.ru
ClearFake payload delivery domain (confidence level: 100%)
domainxaesdb97.c2bba8etip.ru
ClearFake payload delivery domain (confidence level: 100%)
domain7zxnifkk.ecumen1sm0ff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainzqdqgezv.ecumen1sm0ff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainf94vb8l0.ecumen1sm0ff.ru
ClearFake payload delivery domain (confidence level: 100%)
domainai2uuwqw.ecumen1sm0ff.ru
ClearFake payload delivery domain (confidence level: 100%)
domain8uhifp9q.arm2turege7m.ru
ClearFake payload delivery domain (confidence level: 100%)
domain5sreizuv.arm2turege7m.ru
ClearFake payload delivery domain (confidence level: 100%)
domainru38kvwa.arm2turege7m.ru
ClearFake payload delivery domain (confidence level: 100%)
domainyk7vp5q0.arm2turege7m.ru
ClearFake payload delivery domain (confidence level: 100%)

File

ValueDescriptionCopy
file46.151.182.229
Mirai botnet C2 server (confidence level: 80%)
file217.156.122.82
Stealc botnet C2 server (confidence level: 100%)
file95.164.123.123
Stealc botnet C2 server (confidence level: 100%)
file62.164.177.35
Stealc botnet C2 server (confidence level: 100%)
file1.12.231.30
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.201.53.65
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.105.55.111
Cobalt Strike botnet C2 server (confidence level: 100%)
file8.217.97.238
Unknown malware botnet C2 server (confidence level: 100%)
file95.9.236.229
AsyncRAT botnet C2 server (confidence level: 100%)
file188.93.233.106
AsyncRAT botnet C2 server (confidence level: 100%)
file45.156.87.134
AsyncRAT botnet C2 server (confidence level: 100%)
file42.112.102.202
Quasar RAT botnet C2 server (confidence level: 100%)
file139.180.144.53
Havoc botnet C2 server (confidence level: 100%)
file155.117.45.119
Venom RAT botnet C2 server (confidence level: 100%)
file43.153.171.132
Unknown malware botnet C2 server (confidence level: 100%)
file45.33.88.161
Unknown malware botnet C2 server (confidence level: 100%)
file140.82.54.173
Unknown malware botnet C2 server (confidence level: 100%)
file144.172.107.90
Unknown malware botnet C2 server (confidence level: 100%)
file126.209.7.138
Unknown malware botnet C2 server (confidence level: 100%)
file158.101.250.78
Unknown malware botnet C2 server (confidence level: 100%)
file4.231.170.99
Unknown malware botnet C2 server (confidence level: 100%)
file18.139.79.104
Unknown malware botnet C2 server (confidence level: 100%)
file57.129.40.69
Unknown malware botnet C2 server (confidence level: 100%)
file51.21.131.46
Unknown malware botnet C2 server (confidence level: 100%)
file3.106.236.188
Unknown malware botnet C2 server (confidence level: 100%)
file185.173.235.226
Unknown malware botnet C2 server (confidence level: 100%)
file178.16.137.37
Mirai botnet C2 server (confidence level: 80%)
file172.111.169.5
Remcos botnet C2 server (confidence level: 100%)
file106.55.5.111
Unknown malware botnet C2 server (confidence level: 100%)
file23.237.106.59
DCRat botnet C2 server (confidence level: 100%)
file102.98.126.127
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file172.86.88.169
Chaos botnet C2 server (confidence level: 100%)
file72.62.20.196
Unknown malware botnet C2 server (confidence level: 100%)
file35.183.218.216
Unknown malware botnet C2 server (confidence level: 100%)
file138.199.222.6
Unknown malware botnet C2 server (confidence level: 100%)
file18.221.122.235
Unknown malware botnet C2 server (confidence level: 100%)
file77.120.165.2
Unknown malware botnet C2 server (confidence level: 100%)
file195.15.215.249
Unknown malware botnet C2 server (confidence level: 100%)
file185.109.216.74
Unknown malware botnet C2 server (confidence level: 100%)
file13.58.101.213
Unknown malware botnet C2 server (confidence level: 100%)
file157.230.182.134
Unknown malware botnet C2 server (confidence level: 100%)
file206.238.144.183
ValleyRAT botnet C2 server (confidence level: 100%)
file178.236.252.42
Stealc botnet C2 server (confidence level: 100%)
file89.110.110.198
Stealc botnet C2 server (confidence level: 100%)
file34.231.249.185
Sliver botnet C2 server (confidence level: 100%)
file155.117.98.14
Unknown malware botnet C2 server (confidence level: 100%)
file188.69.166.114
AsyncRAT botnet C2 server (confidence level: 100%)
file144.126.149.104
AsyncRAT botnet C2 server (confidence level: 100%)
file199.217.99.210
Unknown malware botnet C2 server (confidence level: 100%)
file83.217.208.170
Unknown malware botnet C2 server (confidence level: 100%)
file201.210.90.254
Quasar RAT botnet C2 server (confidence level: 100%)
file185.76.243.139
Quasar RAT botnet C2 server (confidence level: 100%)
file141.11.0.202
Meterpreter botnet C2 server (confidence level: 100%)
file148.113.205.94
Unknown malware botnet C2 server (confidence level: 100%)
file45.79.202.83
Unknown malware botnet C2 server (confidence level: 100%)
file201.249.59.30
Unknown malware botnet C2 server (confidence level: 100%)
file152.42.225.73
Unknown malware botnet C2 server (confidence level: 100%)
file152.42.225.73
Unknown malware botnet C2 server (confidence level: 100%)
file198.7.124.197
Unknown malware botnet C2 server (confidence level: 100%)
file84.54.33.50
Remcos botnet C2 server (confidence level: 100%)
file185.34.101.146
Quasar RAT botnet C2 server (confidence level: 100%)
file111.230.66.165
Cobalt Strike botnet C2 server (confidence level: 100%)
file103.212.187.23
Cobalt Strike botnet C2 server (confidence level: 100%)
file194.180.158.154
Cobalt Strike botnet C2 server (confidence level: 100%)
file104.248.170.189
Aisuru botnet C2 server (confidence level: 75%)
file46.101.12.38
Aisuru botnet C2 server (confidence level: 75%)
file209.97.153.64
Aisuru botnet C2 server (confidence level: 75%)
file138.68.144.209
Aisuru botnet C2 server (confidence level: 75%)
file134.209.31.183
Aisuru botnet C2 server (confidence level: 75%)
file165.232.105.251
Aisuru botnet C2 server (confidence level: 75%)
file134.209.196.145
Aisuru botnet C2 server (confidence level: 75%)
file107.172.217.220
Cobalt Strike botnet C2 server (confidence level: 100%)
file107.172.217.220
Cobalt Strike botnet C2 server (confidence level: 100%)
file69.197.134.88
Remcos botnet C2 server (confidence level: 100%)
file155.117.98.19
Unknown malware botnet C2 server (confidence level: 100%)
file165.154.224.129
Unknown malware botnet C2 server (confidence level: 100%)
file168.220.236.196
Unknown malware botnet C2 server (confidence level: 100%)
file185.4.64.128
Unknown malware botnet C2 server (confidence level: 100%)
file65.21.248.222
Unknown malware botnet C2 server (confidence level: 100%)
file142.93.179.103
Unknown malware botnet C2 server (confidence level: 100%)
file178.236.16.12
Unknown malware botnet C2 server (confidence level: 100%)
file185.4.65.177
Unknown malware botnet C2 server (confidence level: 100%)
file13.218.57.74
Unknown malware botnet C2 server (confidence level: 100%)
file13.218.57.74
Unknown malware botnet C2 server (confidence level: 100%)
file192.53.167.241
Unknown malware botnet C2 server (confidence level: 100%)
file192.53.167.241
Unknown malware botnet C2 server (confidence level: 100%)
file132.148.78.83
Unknown malware botnet C2 server (confidence level: 100%)
file132.148.78.83
Unknown malware botnet C2 server (confidence level: 100%)
file49.13.228.105
Unknown malware botnet C2 server (confidence level: 100%)
file78.46.240.128
Unknown malware botnet C2 server (confidence level: 100%)
file81.198.74.227
Unknown malware botnet C2 server (confidence level: 100%)
file81.198.74.227
Unknown malware botnet C2 server (confidence level: 100%)
file89.124.66.189
Mirai botnet C2 server (confidence level: 80%)
file38.60.209.55
Meterpreter botnet C2 server (confidence level: 75%)
file178.79.133.112
Sliver botnet C2 server (confidence level: 90%)
file37.60.242.221
ERMAC botnet C2 server (confidence level: 100%)
file66.78.40.90
Unknown malware botnet C2 server (confidence level: 100%)
file191.209.58.15
Unknown malware botnet C2 server (confidence level: 100%)
file20.51.197.118
Unknown malware botnet C2 server (confidence level: 100%)
file143.198.10.134
Unknown malware botnet C2 server (confidence level: 100%)
file123.57.152.240
Unknown malware botnet C2 server (confidence level: 100%)
file13.60.235.49
Unknown malware botnet C2 server (confidence level: 100%)
file221.224.130.226
Unknown malware botnet C2 server (confidence level: 100%)
file45.141.215.113
Remcos botnet C2 server (confidence level: 100%)
file116.102.237.0
Venom RAT botnet C2 server (confidence level: 100%)
file169.50.189.146
Unknown malware botnet C2 server (confidence level: 100%)
file188.166.162.138
Unknown malware botnet C2 server (confidence level: 100%)
file47.129.168.82
Unknown malware botnet C2 server (confidence level: 100%)
file142.93.179.103
Unknown malware botnet C2 server (confidence level: 100%)
file82.165.173.192
Unknown malware botnet C2 server (confidence level: 100%)
file185.4.64.128
Unknown malware botnet C2 server (confidence level: 100%)
file167.86.117.147
Unknown malware botnet C2 server (confidence level: 100%)
file216.92.226.14
Unknown malware botnet C2 server (confidence level: 100%)
file102.206.27.46
Unknown malware botnet C2 server (confidence level: 100%)
file139.196.223.82
Cobalt Strike botnet C2 server (confidence level: 75%)
file43.153.60.198
Cobalt Strike botnet C2 server (confidence level: 75%)
file203.91.74.3
ValleyRAT botnet C2 server (confidence level: 100%)
file83.229.125.215
Cobalt Strike botnet C2 server (confidence level: 100%)
file45.249.208.252
Cobalt Strike botnet C2 server (confidence level: 100%)
file69.164.251.37
Remcos botnet C2 server (confidence level: 100%)
file37.72.172.58
AsyncRAT botnet C2 server (confidence level: 100%)
file158.220.96.15
AsyncRAT botnet C2 server (confidence level: 100%)
file69.164.252.4
Hook botnet C2 server (confidence level: 100%)
file173.191.70.220
Quasar RAT botnet C2 server (confidence level: 100%)
file185.237.166.38
Venom RAT botnet C2 server (confidence level: 100%)
file52.204.219.144
Meterpreter botnet C2 server (confidence level: 100%)
file52.204.219.144
Meterpreter botnet C2 server (confidence level: 100%)
file52.204.219.144
Meterpreter botnet C2 server (confidence level: 100%)
file3.89.221.73
Unknown malware botnet C2 server (confidence level: 100%)
file103.221.252.52
Unknown malware botnet C2 server (confidence level: 100%)
file169.51.48.11
Unknown malware botnet C2 server (confidence level: 100%)
file74.207.236.7
Unknown malware botnet C2 server (confidence level: 100%)
file92.119.121.30
Unknown malware botnet C2 server (confidence level: 100%)
file159.223.173.232
Unknown malware botnet C2 server (confidence level: 100%)
file142.93.83.110
Aisuru botnet C2 server (confidence level: 75%)
file174.138.92.169
Aisuru botnet C2 server (confidence level: 75%)
file134.122.98.230
Aisuru botnet C2 server (confidence level: 75%)
file46.101.78.45
Aisuru botnet C2 server (confidence level: 75%)
file159.203.104.232
Aisuru botnet C2 server (confidence level: 75%)
file161.35.82.49
Aisuru botnet C2 server (confidence level: 75%)
file165.22.3.49
Aisuru botnet C2 server (confidence level: 75%)
file161.35.167.44
Aisuru botnet C2 server (confidence level: 75%)
file138.197.64.170
Aisuru botnet C2 server (confidence level: 75%)
file46.101.75.131
Aisuru botnet C2 server (confidence level: 75%)
file95.40.120.43
ValleyRAT botnet C2 server (confidence level: 100%)
file5.178.103.58
AsyncRAT botnet C2 server (confidence level: 100%)
file5.178.103.58
AsyncRAT botnet C2 server (confidence level: 100%)
file106.225.234.89
DeimosC2 botnet C2 server (confidence level: 75%)
file178.79.133.112
Sliver botnet C2 server (confidence level: 75%)
file98.142.253.183
Eye Pyramid botnet C2 server (confidence level: 75%)
file119.3.156.32
Cobalt Strike botnet C2 server (confidence level: 100%)
file102.117.171.39
Unknown malware botnet C2 server (confidence level: 100%)
file23.237.106.58
DCRat botnet C2 server (confidence level: 100%)
file102.98.76.115
NetSupportManager RAT botnet C2 server (confidence level: 100%)
file98.81.166.227
Meterpreter botnet C2 server (confidence level: 100%)
file159.223.105.127
Unknown malware botnet C2 server (confidence level: 100%)
file124.70.99.232
Unknown malware botnet C2 server (confidence level: 100%)
file43.157.56.250
Unknown malware botnet C2 server (confidence level: 100%)
file216.92.48.31
Unknown malware botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash1999
Mirai botnet C2 server (confidence level: 80%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8811
AsyncRAT botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash8008
AsyncRAT botnet C2 server (confidence level: 100%)
hash443
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash8443
Venom RAT botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Unknown malware botnet C2 server (confidence level: 100%)
hash51777
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3778
Mirai botnet C2 server (confidence level: 80%)
hash5671
Remcos botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash7777
DCRat botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash8080
Chaos botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash23051
ValleyRAT botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash2020
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Quasar RAT botnet C2 server (confidence level: 100%)
hash37585
Quasar RAT botnet C2 server (confidence level: 100%)
hash4444
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Remcos botnet C2 server (confidence level: 100%)
hash1604
Quasar RAT botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash10000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8081
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash444
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash51515
Mirai botnet C2 server (confidence level: 80%)
hash443
Meterpreter botnet C2 server (confidence level: 75%)
hash31337
Sliver botnet C2 server (confidence level: 90%)
hash8082
ERMAC botnet C2 server (confidence level: 100%)
hash60000
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3636
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash41541
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash3333
Unknown malware botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash7000
Venom RAT botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8080
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
ValleyRAT botnet C2 server (confidence level: 100%)
hash4433
Cobalt Strike botnet C2 server (confidence level: 100%)
hash3334
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4047
Remcos botnet C2 server (confidence level: 100%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash3323
AsyncRAT botnet C2 server (confidence level: 100%)
hash8089
Hook botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash4444
Venom RAT botnet C2 server (confidence level: 100%)
hash2380
Meterpreter botnet C2 server (confidence level: 100%)
hash5280
Meterpreter botnet C2 server (confidence level: 100%)
hash8880
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash8001
Aisuru botnet C2 server (confidence level: 75%)
hash553
ValleyRAT botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash7707
AsyncRAT botnet C2 server (confidence level: 100%)
hash10250
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
Sliver botnet C2 server (confidence level: 75%)
hash33312
Eye Pyramid botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash7777
DCRat botnet C2 server (confidence level: 100%)
hash443
NetSupportManager RAT botnet C2 server (confidence level: 100%)
hash19420
Meterpreter botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Unknown malware botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://35.183.218.216/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://72.62.20.196/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://157.230.182.134/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://195.15.215.249/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://206.189.236.65/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://64.23.172.46/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://152.42.225.73/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://45.79.202.83/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://148.113.205.94/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://178.236.252.42
Stealc botnet C2 (confidence level: 100%)
urlhttp://shalyunkotmoroz-104.icu/b5a52ebb310b65f06dd10cfe69f72363/
Unknown malware botnet C2 (confidence level: 100%)
urlhttps://13.218.57.74/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://185.4.64.128/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://192.53.167.241/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://132.148.78.83/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://178.236.16.12/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://49.13.228.105/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://65.21.248.222/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://185.4.65.177/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://81.198.74.227/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://78.46.240.128/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://tuvalul.cyou/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttps://kanekoyozo.jp/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://169.50.189.146/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://82.165.173.192/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://216.92.226.14/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://167.86.117.147/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttps://188.166.162.138/
Unknown malware payload delivery URL (confidence level: 90%)

Threat ID: 69544e27b932a5a22ffaf2d5

Added to database: 12/30/2025, 10:11:51 PM

Last enriched: 12/30/2025, 10:14:42 PM

Last updated: 2/7/2026, 10:25:56 AM

Views: 395

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats