ThreatFox IOCs for 2026-02-08
ThreatFox IOCs for 2026-02-08
AI Analysis
Technical Summary
The provided information pertains to a set of Indicators of Compromise (IOCs) published on February 8, 2026, via the ThreatFox MISP feed, which is an OSINT resource for sharing threat intelligence. The threat is classified as malware-related, specifically involving network activity and payload delivery, but lacks detailed technical specifics such as affected software versions or known exploits in the wild. The absence of CWE identifiers and patch availability suggests that this is an intelligence-sharing event rather than a newly discovered vulnerability or active exploit. The threat level is rated as 2 (on an unspecified scale), with a distribution rating of 3, indicating moderate dissemination or relevance. The medium severity rating reflects potential risks associated with malware payload delivery mechanisms that could be used in targeted attacks or broader campaigns. However, the lack of concrete exploit data or affected product versions limits the ability to assess direct technical impact. The indicators are tagged with TLP:WHITE, indicating they are intended for broad sharing and use in defensive measures. Overall, this represents a situational awareness update rather than an immediate, active threat.
Potential Impact
For European organizations, the primary impact of this threat lies in the potential for malware payload delivery through network activity, which could lead to unauthorized access, data exfiltration, or disruption if exploited. Although no active exploits are currently known, the presence of IOCs in OSINT feeds suggests that threat actors may be preparing or conducting reconnaissance activities. Organizations with extensive network infrastructure or those in critical sectors such as finance, government, and telecommunications could be targeted for initial access or lateral movement. The medium severity indicates a moderate risk level, emphasizing the importance of vigilance but not signaling an immediate crisis. The lack of patches means that defensive measures must rely on detection and response capabilities rather than remediation of a vulnerability. Failure to monitor and act on these IOCs could result in delayed detection of intrusion attempts or malware infections, potentially impacting confidentiality, integrity, and availability of systems.
Mitigation Recommendations
1. Integrate ThreatFox IOCs into existing Security Information and Event Management (SIEM) and intrusion detection systems to enhance detection capabilities. 2. Conduct regular network traffic analysis to identify unusual payload delivery attempts or suspicious network activity aligned with the shared IOCs. 3. Employ endpoint detection and response (EDR) tools to monitor for malware behaviors consistent with the threat profile. 4. Maintain up-to-date threat intelligence feeds and ensure security teams are trained to interpret and act on OSINT data. 5. Implement network segmentation to limit the potential spread of malware if payload delivery is successful. 6. Conduct phishing awareness and social engineering training to reduce the risk of initial compromise vectors. 7. Establish incident response playbooks that incorporate OSINT-derived indicators for rapid containment and remediation. 8. Collaborate with national and European cybersecurity centers to share intelligence and coordinate defenses against emerging threats.
Affected Countries
Germany, France, United Kingdom, Netherlands, Italy
Indicators of Compromise
- file: 89.243.54.145
- hash: 4444
- url: https://116.203.14.212/
- url: https://46.62.225.178/
- domain: dusty-comet-jazz.com
- file: 103.252.116.60
- hash: 1543
- url: http://165.232.165.152:8080/xoner.sh
- url: https://74.0.48.145/
- domain: hdl.re-v.co.id
- file: 51.79.142.142
- hash: 2555
- file: 46.175.167.158
- hash: 2404
- url: https://dinglev.cyou/api
- file: 146.70.226.138
- hash: 5812
- file: 93.171.44.221
- hash: 7004
- file: 193.58.121.74
- hash: 5533
- domain: heysilentpanel.onrender.com
- domain: network-sync-protocol.net
- file: 2.56.165.13
- hash: 666
- domain: connect.kedi.lol
- file: 83.168.95.235
- hash: 1999
- file: 8.148.29.29
- hash: 10495
- file: 45.95.146.23
- hash: 25565
- file: 47.239.230.84
- hash: 20000
- file: 172.120.245.3
- hash: 3000
- file: 129.226.81.142
- hash: 443
- file: 176.65.151.201
- hash: 4443
- file: 158.94.211.127
- hash: 443
- file: 80.78.18.111
- hash: 443
- domain: robl0x.work.gd
- file: 123.60.154.181
- hash: 10001
- file: 80.91.79.204
- hash: 1312
- file: 193.187.132.49
- hash: 2404
- file: 109.205.211.40
- hash: 2404
- file: 15.204.95.228
- hash: 443
- file: 65.2.131.54
- hash: 587
- file: 123.99.198.201
- hash: 21068
- file: 45.74.8.75
- hash: 7000
- domain: dd.lumibiki.xyz
- file: 92.118.124.53
- hash: 80
- file: 31.57.243.100
- hash: 35333
- file: 102.117.169.127
- hash: 7443
- file: 16.63.158.159
- hash: 1521
- file: 47.129.119.137
- hash: 44248
- file: 173.249.23.17
- hash: 8081
- file: 34.70.150.180
- hash: 1337
- file: 27.50.54.213
- hash: 14994
- file: 188.23.173.255
- hash: 8000
- file: 194.180.36.111
- hash: 60000
- file: 31.57.243.100
- hash: 443
- file: 117.72.194.248
- hash: 8088
- file: 221.234.36.123
- hash: 10000
- file: 39.127.45.254
- hash: 3000
- domain: frame-donut.info
- domain: th3hunt3r-48288.portmap.host
- domain: entershopst.ru.com
- url: http://185.174.133.12/98926703060a4fbf.php
- domain: vvnc.ddns.net
- file: 185.234.73.46
- hash: 80
- file: 195.20.17.150
- hash: 80
- file: 146.19.125.14
- hash: 8080
- file: 172.86.122.65
- hash: 7070
- file: 185.225.226.53
- hash: 31337
- file: 45.155.68.13
- hash: 59401
- file: 108.226.207.109
- hash: 80
- file: 192.109.200.11
- hash: 31337
- file: 89.213.41.224
- hash: 80
- file: 158.94.209.27
- hash: 4782
- file: 15.204.14.143
- hash: 80
- file: 77.234.1.132
- hash: 40500
- file: 198.163.204.20
- hash: 40500
- file: 2.134.57.117
- hash: 40500
- file: 38.165.21.125
- hash: 80
- file: 212.11.64.78
- hash: 2404
- file: 51.17.120.197
- hash: 82
- file: 43.210.100.31
- hash: 23356
- file: 196.75.252.0
- hash: 2222
- file: 39.106.81.175
- hash: 5002
- file: 217.23.9.206
- hash: 666
- file: 45.83.207.194
- hash: 3778
- file: 45.61.151.200
- hash: 80
- file: 194.58.38.64
- hash: 20001
- domain: logicmesh.pro
- url: https://logicmesh.pro/api/bot/heartbeat
- domain: theengn.cyou
- domain: capitaf.cyou
- domain: carpoba.cyou
- domain: limulit.cyou
- domain: manufao.cyou
- domain: primedatahost1.cyou
- domain: primedatahost2.cyou
- domain: primedatahost3.cyou
- domain: primedatahost4.cyou
- domain: pestcontrolinsarasota.com
- domain: joeyapple.com
- domain: cameework.com
- file: 46.151.182.230
- hash: 3778
- file: 147.124.218.184
- hash: 7680
- file: 154.94.237.240
- hash: 8888
- file: 211.197.94.135
- hash: 6606
- domain: email-api.argelni.site
- file: 172.104.142.39
- hash: 10001
- file: 106.12.219.245
- hash: 443
- file: 106.13.29.104
- hash: 443
- file: 106.38.201.95
- hash: 443
- file: 106.75.162.108
- hash: 443
- file: 106.75.215.96
- hash: 443
- file: 106.75.224.31
- hash: 443
- file: 113.44.67.52
- hash: 443
- file: 115.190.161.178
- hash: 443
- file: 117.72.102.110
- hash: 443
- file: 117.72.242.9
- hash: 443
- file: 120.48.168.57
- hash: 443
- file: 121.40.18.128
- hash: 443
- file: 122.51.93.94
- hash: 443
- file: 134.122.140.185
- hash: 443
- file: 139.196.41.201
- hash: 443
- file: 139.224.16.185
- hash: 443
- file: 14.103.175.50
- hash: 443
- file: 150.187.25.242
- hash: 443
- file: 152.32.251.78
- hash: 443
- file: 154.201.74.112
- hash: 443
- file: 179.43.186.214
- hash: 443
- file: 192.140.176.79
- hash: 443
- file: 36.140.162.173
- hash: 443
- file: 39.105.165.37
- hash: 443
- file: 45.115.236.152
- hash: 443
- file: 47.107.136.106
- hash: 443
- file: 47.109.145.121
- hash: 443
- file: 47.109.198.8
- hash: 443
- file: 47.120.70.161
- hash: 443
- file: 47.121.137.8
- hash: 443
- file: 47.121.29.60
- hash: 443
- file: 47.93.28.103
- hash: 443
- file: 60.205.139.210
- hash: 443
- domain: lcowpowerlite.italynorth.cloudapp.azure.com
- file: 8.137.149.67
- hash: 443
- file: 8.153.205.30
- hash: 443
- file: 83.229.123.61
- hash: 443
- file: 83.229.126.183
- hash: 443
- file: 83.229.126.65
- hash: 443
- file: 81.71.159.99
- hash: 443
- file: 81.70.255.195
- hash: 443
- file: 81.69.98.230
- hash: 443
- file: 8.210.78.137
- hash: 443
- file: 61.166.154.109
- hash: 443
- file: 49.235.177.231
- hash: 443
- file: 47.243.175.24
- hash: 443
- file: 47.239.188.48
- hash: 443
- file: 47.122.30.177
- hash: 443
- file: 47.122.1.243
- hash: 443
- file: 47.111.146.110
- hash: 443
- file: 47.100.168.4
- hash: 443
- file: 43.139.169.60
- hash: 443
- file: 43.139.146.100
- hash: 443
- file: 43.133.41.106
- hash: 443
- file: 42.192.49.72
- hash: 443
- file: 39.107.85.83
- hash: 443
- file: 39.106.144.162
- hash: 443
- file: 38.190.224.63
- hash: 443
- file: 222.255.214.236
- hash: 443
- file: 192.252.187.60
- hash: 443
- file: 178.16.52.194
- hash: 443
- file: 172.245.215.43
- hash: 443
- file: 165.154.125.212
- hash: 443
- file: 156.233.233.134
- hash: 443
- file: 154.201.91.224
- hash: 443
- file: 152.136.139.105
- hash: 443
- file: 129.204.103.151
- hash: 443
- file: 124.223.47.219
- hash: 443
- file: 124.223.199.39
- hash: 443
- file: 124.221.32.87
- hash: 443
- file: 124.220.48.168
- hash: 443
- file: 124.220.164.98
- hash: 443
- file: 121.41.167.80
- hash: 443
- file: 120.48.50.33
- hash: 443
- file: 117.72.214.50
- hash: 443
- file: 115.190.178.249
- hash: 443
- file: 114.132.150.96
- hash: 443
- file: 110.40.176.194
- hash: 443
- file: 106.52.208.143
- hash: 443
- file: 106.13.137.229
- hash: 443
- file: 101.43.2.116
- hash: 443
- file: 101.133.148.66
- hash: 443
- file: 1.15.25.148
- hash: 443
- file: 45.150.108.229
- hash: 80
- file: 192.3.233.166
- hash: 59850
- file: 207.56.138.31
- hash: 444
- file: 172.234.99.50
- hash: 14829
- domain: 5.ooocyber.cfd
- domain: 4.ooocyber.cfd
- domain: ladydosug.cfd
- domain: sdn-cloudflare-js-botstrup.cfd
- domain: sdn-cloudflare-js.cfd
- domain: www.winabla.com
- file: 31.13.208.223
- hash: 443
- file: 104.168.100.26
- hash: 61011
- domain: 4wpv9rkz.breathforgiv.digital
- domain: 2wjmdomc.breathforgiv.digital
- domain: rmaa7-37443.portmap.host
- domain: turkirma7-53217.portmap.host
- domain: penispro8ty2-54766.portmap.host
- file: 1.244.185.175
- hash: 28192
- domain: qlb.uk.com
- file: 101.35.239.183
- hash: 4449
- file: 194.32.87.78
- hash: 4444
- file: 171.225.223.126
- hash: 6443
- domain: zxccvinorez738-44567.portmap.host
- file: 83.31.173.20
- hash: 41144
- file: 185.156.175.43
- hash: 29848
- file: 38.247.131.5
- hash: 10008
- file: 89.243.54.145
- hash: 6666
- file: 173.211.46.18
- hash: 7777
- file: 94.154.35.160
- hash: 111
- domain: qiye.163.educn.xin
- file: 45.150.149.163
- hash: 1234
- domain: namzcp.org
- file: 103.37.2.30
- hash: 59812
- file: 80.97.44.102
- hash: 2404
- file: 20.206.201.190
- hash: 4449
- domain: www.jira.devergent.net
- file: 51.16.40.109
- hash: 53919
- url: http://192.168.226.132:18088/tjm2
- domain: mta-251.70.ou2in.in
- file: 216.126.237.90
- hash: 7070
- file: 144.172.91.208
- hash: 8808
- domain: ir.alchemyapi.io
- file: 108.226.207.109
- hash: 7443
- file: 45.150.34.120
- hash: 80
- domain: birdiethirty.com
- file: 8.219.199.61
- hash: 10001
ThreatFox IOCs for 2026-02-08
Description
ThreatFox IOCs for 2026-02-08
AI-Powered Analysis
Technical Analysis
The provided information pertains to a set of Indicators of Compromise (IOCs) published on February 8, 2026, via the ThreatFox MISP feed, which is an OSINT resource for sharing threat intelligence. The threat is classified as malware-related, specifically involving network activity and payload delivery, but lacks detailed technical specifics such as affected software versions or known exploits in the wild. The absence of CWE identifiers and patch availability suggests that this is an intelligence-sharing event rather than a newly discovered vulnerability or active exploit. The threat level is rated as 2 (on an unspecified scale), with a distribution rating of 3, indicating moderate dissemination or relevance. The medium severity rating reflects potential risks associated with malware payload delivery mechanisms that could be used in targeted attacks or broader campaigns. However, the lack of concrete exploit data or affected product versions limits the ability to assess direct technical impact. The indicators are tagged with TLP:WHITE, indicating they are intended for broad sharing and use in defensive measures. Overall, this represents a situational awareness update rather than an immediate, active threat.
Potential Impact
For European organizations, the primary impact of this threat lies in the potential for malware payload delivery through network activity, which could lead to unauthorized access, data exfiltration, or disruption if exploited. Although no active exploits are currently known, the presence of IOCs in OSINT feeds suggests that threat actors may be preparing or conducting reconnaissance activities. Organizations with extensive network infrastructure or those in critical sectors such as finance, government, and telecommunications could be targeted for initial access or lateral movement. The medium severity indicates a moderate risk level, emphasizing the importance of vigilance but not signaling an immediate crisis. The lack of patches means that defensive measures must rely on detection and response capabilities rather than remediation of a vulnerability. Failure to monitor and act on these IOCs could result in delayed detection of intrusion attempts or malware infections, potentially impacting confidentiality, integrity, and availability of systems.
Mitigation Recommendations
1. Integrate ThreatFox IOCs into existing Security Information and Event Management (SIEM) and intrusion detection systems to enhance detection capabilities. 2. Conduct regular network traffic analysis to identify unusual payload delivery attempts or suspicious network activity aligned with the shared IOCs. 3. Employ endpoint detection and response (EDR) tools to monitor for malware behaviors consistent with the threat profile. 4. Maintain up-to-date threat intelligence feeds and ensure security teams are trained to interpret and act on OSINT data. 5. Implement network segmentation to limit the potential spread of malware if payload delivery is successful. 6. Conduct phishing awareness and social engineering training to reduce the risk of initial compromise vectors. 7. Establish incident response playbooks that incorporate OSINT-derived indicators for rapid containment and remediation. 8. Collaborate with national and European cybersecurity centers to share intelligence and coordinate defenses against emerging threats.
Affected Countries
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- c030920a-8218-4d8b-bb86-0168b3dcb18e
- Original Timestamp
- 1770595387
Indicators of Compromise
File
| Value | Description | Copy |
|---|---|---|
file89.243.54.145 | XWorm botnet C2 server (confidence level: 100%) | |
file103.252.116.60 | Mirai botnet C2 server (confidence level: 80%) | |
file51.79.142.142 | Mirai botnet C2 server (confidence level: 100%) | |
file46.175.167.158 | Remcos botnet C2 server (confidence level: 100%) | |
file146.70.226.138 | DCRat botnet C2 server (confidence level: 100%) | |
file93.171.44.221 | XWorm botnet C2 server (confidence level: 100%) | |
file193.58.121.74 | XWorm botnet C2 server (confidence level: 100%) | |
file2.56.165.13 | XWorm botnet C2 server (confidence level: 100%) | |
file83.168.95.235 | Mirai botnet C2 server (confidence level: 80%) | |
file8.148.29.29 | XWorm botnet C2 server (confidence level: 100%) | |
file45.95.146.23 | Mirai botnet C2 server (confidence level: 100%) | |
file47.239.230.84 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file172.120.245.3 | Mirai botnet C2 server (confidence level: 100%) | |
file129.226.81.142 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file176.65.151.201 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file158.94.211.127 | Unknown malware botnet C2 server (confidence level: 100%) | |
file80.78.18.111 | Havoc botnet C2 server (confidence level: 100%) | |
file123.60.154.181 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
file80.91.79.204 | Mirai botnet C2 server (confidence level: 80%) | |
file193.187.132.49 | Remcos botnet C2 server (confidence level: 100%) | |
file109.205.211.40 | Remcos botnet C2 server (confidence level: 100%) | |
file15.204.95.228 | Havoc botnet C2 server (confidence level: 100%) | |
file65.2.131.54 | Meterpreter botnet C2 server (confidence level: 100%) | |
file123.99.198.201 | Gh0stnet botnet C2 server (confidence level: 100%) | |
file45.74.8.75 | XWorm botnet C2 server (confidence level: 100%) | |
file92.118.124.53 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file31.57.243.100 | Sliver botnet C2 server (confidence level: 90%) | |
file102.117.169.127 | Unknown malware botnet C2 server (confidence level: 100%) | |
file16.63.158.159 | Meterpreter botnet C2 server (confidence level: 100%) | |
file47.129.119.137 | Meterpreter botnet C2 server (confidence level: 100%) | |
file173.249.23.17 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file34.70.150.180 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file27.50.54.213 | Gh0stnet botnet C2 server (confidence level: 100%) | |
file188.23.173.255 | Eye Pyramid botnet C2 server (confidence level: 75%) | |
file194.180.36.111 | Sliver botnet C2 server (confidence level: 75%) | |
file31.57.243.100 | Sliver botnet C2 server (confidence level: 75%) | |
file117.72.194.248 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file221.234.36.123 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file39.127.45.254 | Mirai botnet C2 server (confidence level: 100%) | |
file185.234.73.46 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file195.20.17.150 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file146.19.125.14 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file172.86.122.65 | Sliver botnet C2 server (confidence level: 90%) | |
file185.225.226.53 | Sliver botnet C2 server (confidence level: 90%) | |
file45.155.68.13 | Sliver botnet C2 server (confidence level: 90%) | |
file108.226.207.109 | Sliver botnet C2 server (confidence level: 90%) | |
file192.109.200.11 | Sliver botnet C2 server (confidence level: 90%) | |
file89.213.41.224 | Hook botnet C2 server (confidence level: 100%) | |
file158.94.209.27 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file15.204.14.143 | Havoc botnet C2 server (confidence level: 100%) | |
file77.234.1.132 | Phorpiex botnet C2 server (confidence level: 100%) | |
file198.163.204.20 | Phorpiex botnet C2 server (confidence level: 100%) | |
file2.134.57.117 | Phorpiex botnet C2 server (confidence level: 100%) | |
file38.165.21.125 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file212.11.64.78 | Remcos botnet C2 server (confidence level: 100%) | |
file51.17.120.197 | Meterpreter botnet C2 server (confidence level: 100%) | |
file43.210.100.31 | Meterpreter botnet C2 server (confidence level: 100%) | |
file196.75.252.0 | Meterpreter botnet C2 server (confidence level: 100%) | |
file39.106.81.175 | Unknown malware payload delivery server (confidence level: 100%) | |
file217.23.9.206 | Cerberus botnet C2 server (confidence level: 100%) | |
file45.83.207.194 | Mirai botnet C2 server (confidence level: 100%) | |
file45.61.151.200 | Meterpreter botnet C2 server (confidence level: 75%) | |
file194.58.38.64 | VShell botnet C2 server (confidence level: 100%) | |
file46.151.182.230 | Mirai botnet C2 server (confidence level: 100%) | |
file147.124.218.184 | PureLogs Stealer botnet C2 server (confidence level: 100%) | |
file154.94.237.240 | Unknown malware botnet C2 server (confidence level: 100%) | |
file211.197.94.135 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file172.104.142.39 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
file106.12.219.245 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file106.13.29.104 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file106.38.201.95 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file106.75.162.108 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file106.75.215.96 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file106.75.224.31 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file113.44.67.52 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file115.190.161.178 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file117.72.102.110 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file117.72.242.9 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file120.48.168.57 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file121.40.18.128 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file122.51.93.94 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file134.122.140.185 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file139.196.41.201 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file139.224.16.185 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file14.103.175.50 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file150.187.25.242 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file152.32.251.78 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file154.201.74.112 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file179.43.186.214 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file192.140.176.79 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file36.140.162.173 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file39.105.165.37 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file45.115.236.152 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.107.136.106 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.109.145.121 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.109.198.8 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.120.70.161 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.121.137.8 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.121.29.60 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.93.28.103 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file60.205.139.210 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file8.137.149.67 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file8.153.205.30 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file83.229.123.61 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file83.229.126.183 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file83.229.126.65 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file81.71.159.99 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file81.70.255.195 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file81.69.98.230 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file8.210.78.137 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file61.166.154.109 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file49.235.177.231 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.243.175.24 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.239.188.48 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.122.30.177 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.122.1.243 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.111.146.110 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file47.100.168.4 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file43.139.169.60 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file43.139.146.100 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file43.133.41.106 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file42.192.49.72 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file39.107.85.83 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file39.106.144.162 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file38.190.224.63 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file222.255.214.236 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file192.252.187.60 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file178.16.52.194 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file172.245.215.43 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file165.154.125.212 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file156.233.233.134 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file154.201.91.224 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file152.136.139.105 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file129.204.103.151 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file124.223.47.219 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file124.223.199.39 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file124.221.32.87 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file124.220.48.168 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file124.220.164.98 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file121.41.167.80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file120.48.50.33 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file117.72.214.50 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file115.190.178.249 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file114.132.150.96 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file110.40.176.194 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file106.52.208.143 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file106.13.137.229 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file101.43.2.116 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file101.133.148.66 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file1.15.25.148 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
file45.150.108.229 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file192.3.233.166 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file207.56.138.31 | Unknown RAT botnet C2 server (confidence level: 100%) | |
file172.234.99.50 | XWorm botnet C2 server (confidence level: 100%) | |
file31.13.208.223 | Unknown malware botnet C2 server (confidence level: 100%) | |
file104.168.100.26 | VShell botnet C2 server (confidence level: 100%) | |
file1.244.185.175 | Remcos botnet C2 server (confidence level: 100%) | |
file101.35.239.183 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file194.32.87.78 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file171.225.223.126 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file83.31.173.20 | Meterpreter botnet C2 server (confidence level: 100%) | |
file185.156.175.43 | Remcos botnet C2 server (confidence level: 100%) | |
file38.247.131.5 | XWorm botnet C2 server (confidence level: 100%) | |
file89.243.54.145 | XWorm botnet C2 server (confidence level: 100%) | |
file173.211.46.18 | AsyncRAT botnet C2 server (confidence level: 75%) | |
file94.154.35.160 | DCRat botnet C2 server (confidence level: 75%) | |
file45.150.149.163 | DarkComet botnet C2 server (confidence level: 100%) | |
file103.37.2.30 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file80.97.44.102 | Remcos botnet C2 server (confidence level: 100%) | |
file20.206.201.190 | Remcos botnet C2 server (confidence level: 100%) | |
file51.16.40.109 | Meterpreter botnet C2 server (confidence level: 100%) | |
file216.126.237.90 | Sliver botnet C2 server (confidence level: 90%) | |
file144.172.91.208 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file108.226.207.109 | Unknown malware botnet C2 server (confidence level: 100%) | |
file45.150.34.120 | Hook botnet C2 server (confidence level: 100%) | |
file8.219.199.61 | Xtreme RAT botnet C2 server (confidence level: 100%) |
Hash
| Value | Description | Copy |
|---|---|---|
hash4444 | XWorm botnet C2 server (confidence level: 100%) | |
hash1543 | Mirai botnet C2 server (confidence level: 80%) | |
hash2555 | Mirai botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash5812 | DCRat botnet C2 server (confidence level: 100%) | |
hash7004 | XWorm botnet C2 server (confidence level: 100%) | |
hash5533 | XWorm botnet C2 server (confidence level: 100%) | |
hash666 | XWorm botnet C2 server (confidence level: 100%) | |
hash1999 | Mirai botnet C2 server (confidence level: 80%) | |
hash10495 | XWorm botnet C2 server (confidence level: 100%) | |
hash25565 | Mirai botnet C2 server (confidence level: 100%) | |
hash20000 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash3000 | Mirai botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash4443 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash10001 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
hash1312 | Mirai botnet C2 server (confidence level: 80%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash587 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash21068 | Gh0stnet botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash35333 | Sliver botnet C2 server (confidence level: 90%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash1521 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash44248 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash8081 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash1337 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash14994 | Gh0stnet botnet C2 server (confidence level: 100%) | |
hash8000 | Eye Pyramid botnet C2 server (confidence level: 75%) | |
hash60000 | Sliver botnet C2 server (confidence level: 75%) | |
hash443 | Sliver botnet C2 server (confidence level: 75%) | |
hash8088 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash10000 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash3000 | Mirai botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash8080 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash7070 | Sliver botnet C2 server (confidence level: 90%) | |
hash31337 | Sliver botnet C2 server (confidence level: 90%) | |
hash59401 | Sliver botnet C2 server (confidence level: 90%) | |
hash80 | Sliver botnet C2 server (confidence level: 90%) | |
hash31337 | Sliver botnet C2 server (confidence level: 90%) | |
hash80 | Hook botnet C2 server (confidence level: 100%) | |
hash4782 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash80 | Havoc botnet C2 server (confidence level: 100%) | |
hash40500 | Phorpiex botnet C2 server (confidence level: 100%) | |
hash40500 | Phorpiex botnet C2 server (confidence level: 100%) | |
hash40500 | Phorpiex botnet C2 server (confidence level: 100%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash82 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash23356 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash2222 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash5002 | Unknown malware payload delivery server (confidence level: 100%) | |
hash666 | Cerberus botnet C2 server (confidence level: 100%) | |
hash3778 | Mirai botnet C2 server (confidence level: 100%) | |
hash80 | Meterpreter botnet C2 server (confidence level: 75%) | |
hash20001 | VShell botnet C2 server (confidence level: 100%) | |
hash3778 | Mirai botnet C2 server (confidence level: 100%) | |
hash7680 | PureLogs Stealer botnet C2 server (confidence level: 100%) | |
hash8888 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash6606 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash10001 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 75%) | |
hash80 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash59850 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash444 | Unknown RAT botnet C2 server (confidence level: 100%) | |
hash14829 | XWorm botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash61011 | VShell botnet C2 server (confidence level: 100%) | |
hash28192 | Remcos botnet C2 server (confidence level: 100%) | |
hash4449 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash4444 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash6443 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash41144 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash29848 | Remcos botnet C2 server (confidence level: 100%) | |
hash10008 | XWorm botnet C2 server (confidence level: 100%) | |
hash6666 | XWorm botnet C2 server (confidence level: 100%) | |
hash7777 | AsyncRAT botnet C2 server (confidence level: 75%) | |
hash111 | DCRat botnet C2 server (confidence level: 75%) | |
hash1234 | DarkComet botnet C2 server (confidence level: 100%) | |
hash59812 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash4449 | Remcos botnet C2 server (confidence level: 100%) | |
hash53919 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash7070 | Sliver botnet C2 server (confidence level: 90%) | |
hash8808 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Hook botnet C2 server (confidence level: 100%) | |
hash10001 | Xtreme RAT botnet C2 server (confidence level: 100%) |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://116.203.14.212/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://46.62.225.178/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttp://165.232.165.152:8080/xoner.sh | Unknown malware payload delivery URL (confidence level: 75%) | |
urlhttps://74.0.48.145/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://dinglev.cyou/api | Lumma Stealer botnet C2 (confidence level: 100%) | |
urlhttp://185.174.133.12/98926703060a4fbf.php | Stealc botnet C2 (confidence level: 100%) | |
urlhttps://logicmesh.pro/api/bot/heartbeat | Unknown Stealer botnet C2 (confidence level: 100%) | |
urlhttp://192.168.226.132:18088/tjm2 | Cobalt Strike botnet C2 (confidence level: 75%) |
Domain
| Value | Description | Copy |
|---|---|---|
domaindusty-comet-jazz.com | SantaStealer botnet C2 domain (confidence level: 100%) | |
domainhdl.re-v.co.id | Vidar botnet C2 domain (confidence level: 100%) | |
domainheysilentpanel.onrender.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainnetwork-sync-protocol.net | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainconnect.kedi.lol | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainrobl0x.work.gd | Unknown malware botnet C2 domain (confidence level: 100%) | |
domaindd.lumibiki.xyz | Mirai botnet C2 domain (confidence level: 100%) | |
domainframe-donut.info | SantaStealer botnet C2 domain (confidence level: 100%) | |
domainth3hunt3r-48288.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainentershopst.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainvvnc.ddns.net | Unknown RAT botnet C2 domain (confidence level: 100%) | |
domainlogicmesh.pro | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domaintheengn.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaincapitaf.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaincarpoba.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainlimulit.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainmanufao.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainprimedatahost1.cyou | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainprimedatahost2.cyou | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainprimedatahost3.cyou | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainprimedatahost4.cyou | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainpestcontrolinsarasota.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainjoeyapple.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domaincameework.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainemail-api.argelni.site | Havoc botnet C2 domain (confidence level: 100%) | |
domainlcowpowerlite.italynorth.cloudapp.azure.com | Cobalt Strike botnet C2 domain (confidence level: 75%) | |
domain5.ooocyber.cfd | Unknown malware botnet C2 domain (confidence level: 100%) | |
domain4.ooocyber.cfd | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainladydosug.cfd | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainsdn-cloudflare-js-botstrup.cfd | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainsdn-cloudflare-js.cfd | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainwww.winabla.com | Unknown malware botnet C2 domain (confidence level: 100%) | |
domain4wpv9rkz.breathforgiv.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domain2wjmdomc.breathforgiv.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainrmaa7-37443.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainturkirma7-53217.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainpenispro8ty2-54766.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainqlb.uk.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainzxccvinorez738-44567.portmap.host | NjRAT botnet C2 domain (confidence level: 100%) | |
domainqiye.163.educn.xin | Cobalt Strike botnet C2 domain (confidence level: 100%) | |
domainnamzcp.org | Unknown malware payload delivery domain (confidence level: 100%) | |
domainwww.jira.devergent.net | Hook botnet C2 domain (confidence level: 100%) | |
domainmta-251.70.ou2in.in | Cobalt Strike botnet C2 domain (confidence level: 100%) | |
domainir.alchemyapi.io | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainbirdiethirty.com | Unknown malware botnet C2 domain (confidence level: 100%) |
Threat ID: 698927194b57a58fa1dddc2d
Added to database: 2/9/2026, 12:15:21 AM
Last enriched: 2/9/2026, 12:30:40 AM
Last updated: 2/21/2026, 12:18:15 AM
Views: 106
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
ThreatFox IOCs for 2026-02-20
MediumAndroid threats using GenAI usher in a new era
MediumMaltrail IOC for 2026-02-20
MediumFBI: $20 Million Losses Caused by 700 ATM Jackpotting Attacks in 2025
MediumPromptSpy Android Malware Abuses Gemini AI at Runtime for Persistence
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.