Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-02-08

0
Medium
Published: Sun Feb 08 2026 (02/08/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2026-02-08

AI-Powered Analysis

AILast updated: 02/09/2026, 00:30:40 UTC

Technical Analysis

The provided information pertains to a set of Indicators of Compromise (IOCs) published on February 8, 2026, via the ThreatFox MISP feed, which is an OSINT resource for sharing threat intelligence. The threat is classified as malware-related, specifically involving network activity and payload delivery, but lacks detailed technical specifics such as affected software versions or known exploits in the wild. The absence of CWE identifiers and patch availability suggests that this is an intelligence-sharing event rather than a newly discovered vulnerability or active exploit. The threat level is rated as 2 (on an unspecified scale), with a distribution rating of 3, indicating moderate dissemination or relevance. The medium severity rating reflects potential risks associated with malware payload delivery mechanisms that could be used in targeted attacks or broader campaigns. However, the lack of concrete exploit data or affected product versions limits the ability to assess direct technical impact. The indicators are tagged with TLP:WHITE, indicating they are intended for broad sharing and use in defensive measures. Overall, this represents a situational awareness update rather than an immediate, active threat.

Potential Impact

For European organizations, the primary impact of this threat lies in the potential for malware payload delivery through network activity, which could lead to unauthorized access, data exfiltration, or disruption if exploited. Although no active exploits are currently known, the presence of IOCs in OSINT feeds suggests that threat actors may be preparing or conducting reconnaissance activities. Organizations with extensive network infrastructure or those in critical sectors such as finance, government, and telecommunications could be targeted for initial access or lateral movement. The medium severity indicates a moderate risk level, emphasizing the importance of vigilance but not signaling an immediate crisis. The lack of patches means that defensive measures must rely on detection and response capabilities rather than remediation of a vulnerability. Failure to monitor and act on these IOCs could result in delayed detection of intrusion attempts or malware infections, potentially impacting confidentiality, integrity, and availability of systems.

Mitigation Recommendations

1. Integrate ThreatFox IOCs into existing Security Information and Event Management (SIEM) and intrusion detection systems to enhance detection capabilities. 2. Conduct regular network traffic analysis to identify unusual payload delivery attempts or suspicious network activity aligned with the shared IOCs. 3. Employ endpoint detection and response (EDR) tools to monitor for malware behaviors consistent with the threat profile. 4. Maintain up-to-date threat intelligence feeds and ensure security teams are trained to interpret and act on OSINT data. 5. Implement network segmentation to limit the potential spread of malware if payload delivery is successful. 6. Conduct phishing awareness and social engineering training to reduce the risk of initial compromise vectors. 7. Establish incident response playbooks that incorporate OSINT-derived indicators for rapid containment and remediation. 8. Collaborate with national and European cybersecurity centers to share intelligence and coordinate defenses against emerging threats.

Need more detailed analysis?Upgrade to Pro Console

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
c030920a-8218-4d8b-bb86-0168b3dcb18e
Original Timestamp
1770595387

Indicators of Compromise

File

ValueDescriptionCopy
file89.243.54.145
XWorm botnet C2 server (confidence level: 100%)
file103.252.116.60
Mirai botnet C2 server (confidence level: 80%)
file51.79.142.142
Mirai botnet C2 server (confidence level: 100%)
file46.175.167.158
Remcos botnet C2 server (confidence level: 100%)
file146.70.226.138
DCRat botnet C2 server (confidence level: 100%)
file93.171.44.221
XWorm botnet C2 server (confidence level: 100%)
file193.58.121.74
XWorm botnet C2 server (confidence level: 100%)
file2.56.165.13
XWorm botnet C2 server (confidence level: 100%)
file83.168.95.235
Mirai botnet C2 server (confidence level: 80%)
file8.148.29.29
XWorm botnet C2 server (confidence level: 100%)
file45.95.146.23
Mirai botnet C2 server (confidence level: 100%)
file47.239.230.84
Cobalt Strike botnet C2 server (confidence level: 75%)
file172.120.245.3
Mirai botnet C2 server (confidence level: 100%)
file129.226.81.142
Cobalt Strike botnet C2 server (confidence level: 100%)
file176.65.151.201
Cobalt Strike botnet C2 server (confidence level: 100%)
file158.94.211.127
Unknown malware botnet C2 server (confidence level: 100%)
file80.78.18.111
Havoc botnet C2 server (confidence level: 100%)
file123.60.154.181
Xtreme RAT botnet C2 server (confidence level: 100%)
file80.91.79.204
Mirai botnet C2 server (confidence level: 80%)
file193.187.132.49
Remcos botnet C2 server (confidence level: 100%)
file109.205.211.40
Remcos botnet C2 server (confidence level: 100%)
file15.204.95.228
Havoc botnet C2 server (confidence level: 100%)
file65.2.131.54
Meterpreter botnet C2 server (confidence level: 100%)
file123.99.198.201
Gh0stnet botnet C2 server (confidence level: 100%)
file45.74.8.75
XWorm botnet C2 server (confidence level: 100%)
file92.118.124.53
Cobalt Strike botnet C2 server (confidence level: 100%)
file31.57.243.100
Sliver botnet C2 server (confidence level: 90%)
file102.117.169.127
Unknown malware botnet C2 server (confidence level: 100%)
file16.63.158.159
Meterpreter botnet C2 server (confidence level: 100%)
file47.129.119.137
Meterpreter botnet C2 server (confidence level: 100%)
file173.249.23.17
Empire Downloader botnet C2 server (confidence level: 100%)
file34.70.150.180
Empire Downloader botnet C2 server (confidence level: 100%)
file27.50.54.213
Gh0stnet botnet C2 server (confidence level: 100%)
file188.23.173.255
Eye Pyramid botnet C2 server (confidence level: 75%)
file194.180.36.111
Sliver botnet C2 server (confidence level: 75%)
file31.57.243.100
Sliver botnet C2 server (confidence level: 75%)
file117.72.194.248
Cobalt Strike botnet C2 server (confidence level: 100%)
file221.234.36.123
Cobalt Strike botnet C2 server (confidence level: 100%)
file39.127.45.254
Mirai botnet C2 server (confidence level: 100%)
file185.234.73.46
Cobalt Strike botnet C2 server (confidence level: 75%)
file195.20.17.150
Cobalt Strike botnet C2 server (confidence level: 75%)
file146.19.125.14
Cobalt Strike botnet C2 server (confidence level: 100%)
file172.86.122.65
Sliver botnet C2 server (confidence level: 90%)
file185.225.226.53
Sliver botnet C2 server (confidence level: 90%)
file45.155.68.13
Sliver botnet C2 server (confidence level: 90%)
file108.226.207.109
Sliver botnet C2 server (confidence level: 90%)
file192.109.200.11
Sliver botnet C2 server (confidence level: 90%)
file89.213.41.224
Hook botnet C2 server (confidence level: 100%)
file158.94.209.27
Quasar RAT botnet C2 server (confidence level: 100%)
file15.204.14.143
Havoc botnet C2 server (confidence level: 100%)
file77.234.1.132
Phorpiex botnet C2 server (confidence level: 100%)
file198.163.204.20
Phorpiex botnet C2 server (confidence level: 100%)
file2.134.57.117
Phorpiex botnet C2 server (confidence level: 100%)
file38.165.21.125
Cobalt Strike botnet C2 server (confidence level: 100%)
file212.11.64.78
Remcos botnet C2 server (confidence level: 100%)
file51.17.120.197
Meterpreter botnet C2 server (confidence level: 100%)
file43.210.100.31
Meterpreter botnet C2 server (confidence level: 100%)
file196.75.252.0
Meterpreter botnet C2 server (confidence level: 100%)
file39.106.81.175
Unknown malware payload delivery server (confidence level: 100%)
file217.23.9.206
Cerberus botnet C2 server (confidence level: 100%)
file45.83.207.194
Mirai botnet C2 server (confidence level: 100%)
file45.61.151.200
Meterpreter botnet C2 server (confidence level: 75%)
file194.58.38.64
VShell botnet C2 server (confidence level: 100%)
file46.151.182.230
Mirai botnet C2 server (confidence level: 100%)
file147.124.218.184
PureLogs Stealer botnet C2 server (confidence level: 100%)
file154.94.237.240
Unknown malware botnet C2 server (confidence level: 100%)
file211.197.94.135
AsyncRAT botnet C2 server (confidence level: 100%)
file172.104.142.39
Xtreme RAT botnet C2 server (confidence level: 100%)
file106.12.219.245
Cobalt Strike botnet C2 server (confidence level: 75%)
file106.13.29.104
Cobalt Strike botnet C2 server (confidence level: 75%)
file106.38.201.95
Cobalt Strike botnet C2 server (confidence level: 75%)
file106.75.162.108
Cobalt Strike botnet C2 server (confidence level: 75%)
file106.75.215.96
Cobalt Strike botnet C2 server (confidence level: 75%)
file106.75.224.31
Cobalt Strike botnet C2 server (confidence level: 75%)
file113.44.67.52
Cobalt Strike botnet C2 server (confidence level: 75%)
file115.190.161.178
Cobalt Strike botnet C2 server (confidence level: 75%)
file117.72.102.110
Cobalt Strike botnet C2 server (confidence level: 75%)
file117.72.242.9
Cobalt Strike botnet C2 server (confidence level: 75%)
file120.48.168.57
Cobalt Strike botnet C2 server (confidence level: 75%)
file121.40.18.128
Cobalt Strike botnet C2 server (confidence level: 75%)
file122.51.93.94
Cobalt Strike botnet C2 server (confidence level: 75%)
file134.122.140.185
Cobalt Strike botnet C2 server (confidence level: 75%)
file139.196.41.201
Cobalt Strike botnet C2 server (confidence level: 75%)
file139.224.16.185
Cobalt Strike botnet C2 server (confidence level: 75%)
file14.103.175.50
Cobalt Strike botnet C2 server (confidence level: 75%)
file150.187.25.242
Cobalt Strike botnet C2 server (confidence level: 75%)
file152.32.251.78
Cobalt Strike botnet C2 server (confidence level: 75%)
file154.201.74.112
Cobalt Strike botnet C2 server (confidence level: 75%)
file179.43.186.214
Cobalt Strike botnet C2 server (confidence level: 75%)
file192.140.176.79
Cobalt Strike botnet C2 server (confidence level: 75%)
file36.140.162.173
Cobalt Strike botnet C2 server (confidence level: 75%)
file39.105.165.37
Cobalt Strike botnet C2 server (confidence level: 75%)
file45.115.236.152
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.107.136.106
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.109.145.121
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.109.198.8
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.120.70.161
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.121.137.8
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.121.29.60
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.93.28.103
Cobalt Strike botnet C2 server (confidence level: 75%)
file60.205.139.210
Cobalt Strike botnet C2 server (confidence level: 75%)
file8.137.149.67
Cobalt Strike botnet C2 server (confidence level: 75%)
file8.153.205.30
Cobalt Strike botnet C2 server (confidence level: 75%)
file83.229.123.61
Cobalt Strike botnet C2 server (confidence level: 75%)
file83.229.126.183
Cobalt Strike botnet C2 server (confidence level: 75%)
file83.229.126.65
Cobalt Strike botnet C2 server (confidence level: 75%)
file81.71.159.99
Cobalt Strike botnet C2 server (confidence level: 75%)
file81.70.255.195
Cobalt Strike botnet C2 server (confidence level: 75%)
file81.69.98.230
Cobalt Strike botnet C2 server (confidence level: 75%)
file8.210.78.137
Cobalt Strike botnet C2 server (confidence level: 75%)
file61.166.154.109
Cobalt Strike botnet C2 server (confidence level: 75%)
file49.235.177.231
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.243.175.24
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.239.188.48
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.122.30.177
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.122.1.243
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.111.146.110
Cobalt Strike botnet C2 server (confidence level: 75%)
file47.100.168.4
Cobalt Strike botnet C2 server (confidence level: 75%)
file43.139.169.60
Cobalt Strike botnet C2 server (confidence level: 75%)
file43.139.146.100
Cobalt Strike botnet C2 server (confidence level: 75%)
file43.133.41.106
Cobalt Strike botnet C2 server (confidence level: 75%)
file42.192.49.72
Cobalt Strike botnet C2 server (confidence level: 75%)
file39.107.85.83
Cobalt Strike botnet C2 server (confidence level: 75%)
file39.106.144.162
Cobalt Strike botnet C2 server (confidence level: 75%)
file38.190.224.63
Cobalt Strike botnet C2 server (confidence level: 75%)
file222.255.214.236
Cobalt Strike botnet C2 server (confidence level: 75%)
file192.252.187.60
Cobalt Strike botnet C2 server (confidence level: 75%)
file178.16.52.194
Cobalt Strike botnet C2 server (confidence level: 75%)
file172.245.215.43
Cobalt Strike botnet C2 server (confidence level: 75%)
file165.154.125.212
Cobalt Strike botnet C2 server (confidence level: 75%)
file156.233.233.134
Cobalt Strike botnet C2 server (confidence level: 75%)
file154.201.91.224
Cobalt Strike botnet C2 server (confidence level: 75%)
file152.136.139.105
Cobalt Strike botnet C2 server (confidence level: 75%)
file129.204.103.151
Cobalt Strike botnet C2 server (confidence level: 75%)
file124.223.47.219
Cobalt Strike botnet C2 server (confidence level: 75%)
file124.223.199.39
Cobalt Strike botnet C2 server (confidence level: 75%)
file124.221.32.87
Cobalt Strike botnet C2 server (confidence level: 75%)
file124.220.48.168
Cobalt Strike botnet C2 server (confidence level: 75%)
file124.220.164.98
Cobalt Strike botnet C2 server (confidence level: 75%)
file121.41.167.80
Cobalt Strike botnet C2 server (confidence level: 75%)
file120.48.50.33
Cobalt Strike botnet C2 server (confidence level: 75%)
file117.72.214.50
Cobalt Strike botnet C2 server (confidence level: 75%)
file115.190.178.249
Cobalt Strike botnet C2 server (confidence level: 75%)
file114.132.150.96
Cobalt Strike botnet C2 server (confidence level: 75%)
file110.40.176.194
Cobalt Strike botnet C2 server (confidence level: 75%)
file106.52.208.143
Cobalt Strike botnet C2 server (confidence level: 75%)
file106.13.137.229
Cobalt Strike botnet C2 server (confidence level: 75%)
file101.43.2.116
Cobalt Strike botnet C2 server (confidence level: 75%)
file101.133.148.66
Cobalt Strike botnet C2 server (confidence level: 75%)
file1.15.25.148
Cobalt Strike botnet C2 server (confidence level: 75%)
file45.150.108.229
Cobalt Strike botnet C2 server (confidence level: 100%)
file192.3.233.166
Cobalt Strike botnet C2 server (confidence level: 100%)
file207.56.138.31
Unknown RAT botnet C2 server (confidence level: 100%)
file172.234.99.50
XWorm botnet C2 server (confidence level: 100%)
file31.13.208.223
Unknown malware botnet C2 server (confidence level: 100%)
file104.168.100.26
VShell botnet C2 server (confidence level: 100%)
file1.244.185.175
Remcos botnet C2 server (confidence level: 100%)
file101.35.239.183
AsyncRAT botnet C2 server (confidence level: 100%)
file194.32.87.78
Quasar RAT botnet C2 server (confidence level: 100%)
file171.225.223.126
Quasar RAT botnet C2 server (confidence level: 100%)
file83.31.173.20
Meterpreter botnet C2 server (confidence level: 100%)
file185.156.175.43
Remcos botnet C2 server (confidence level: 100%)
file38.247.131.5
XWorm botnet C2 server (confidence level: 100%)
file89.243.54.145
XWorm botnet C2 server (confidence level: 100%)
file173.211.46.18
AsyncRAT botnet C2 server (confidence level: 75%)
file94.154.35.160
DCRat botnet C2 server (confidence level: 75%)
file45.150.149.163
DarkComet botnet C2 server (confidence level: 100%)
file103.37.2.30
Cobalt Strike botnet C2 server (confidence level: 100%)
file80.97.44.102
Remcos botnet C2 server (confidence level: 100%)
file20.206.201.190
Remcos botnet C2 server (confidence level: 100%)
file51.16.40.109
Meterpreter botnet C2 server (confidence level: 100%)
file216.126.237.90
Sliver botnet C2 server (confidence level: 90%)
file144.172.91.208
AsyncRAT botnet C2 server (confidence level: 100%)
file108.226.207.109
Unknown malware botnet C2 server (confidence level: 100%)
file45.150.34.120
Hook botnet C2 server (confidence level: 100%)
file8.219.199.61
Xtreme RAT botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash4444
XWorm botnet C2 server (confidence level: 100%)
hash1543
Mirai botnet C2 server (confidence level: 80%)
hash2555
Mirai botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash5812
DCRat botnet C2 server (confidence level: 100%)
hash7004
XWorm botnet C2 server (confidence level: 100%)
hash5533
XWorm botnet C2 server (confidence level: 100%)
hash666
XWorm botnet C2 server (confidence level: 100%)
hash1999
Mirai botnet C2 server (confidence level: 80%)
hash10495
XWorm botnet C2 server (confidence level: 100%)
hash25565
Mirai botnet C2 server (confidence level: 100%)
hash20000
Cobalt Strike botnet C2 server (confidence level: 75%)
hash3000
Mirai botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash1312
Mirai botnet C2 server (confidence level: 80%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash587
Meterpreter botnet C2 server (confidence level: 100%)
hash21068
Gh0stnet botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash35333
Sliver botnet C2 server (confidence level: 90%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash1521
Meterpreter botnet C2 server (confidence level: 100%)
hash44248
Meterpreter botnet C2 server (confidence level: 100%)
hash8081
Empire Downloader botnet C2 server (confidence level: 100%)
hash1337
Empire Downloader botnet C2 server (confidence level: 100%)
hash14994
Gh0stnet botnet C2 server (confidence level: 100%)
hash8000
Eye Pyramid botnet C2 server (confidence level: 75%)
hash60000
Sliver botnet C2 server (confidence level: 75%)
hash443
Sliver botnet C2 server (confidence level: 75%)
hash8088
Cobalt Strike botnet C2 server (confidence level: 100%)
hash10000
Cobalt Strike botnet C2 server (confidence level: 100%)
hash3000
Mirai botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 75%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7070
Sliver botnet C2 server (confidence level: 90%)
hash31337
Sliver botnet C2 server (confidence level: 90%)
hash59401
Sliver botnet C2 server (confidence level: 90%)
hash80
Sliver botnet C2 server (confidence level: 90%)
hash31337
Sliver botnet C2 server (confidence level: 90%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash80
Havoc botnet C2 server (confidence level: 100%)
hash40500
Phorpiex botnet C2 server (confidence level: 100%)
hash40500
Phorpiex botnet C2 server (confidence level: 100%)
hash40500
Phorpiex botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash82
Meterpreter botnet C2 server (confidence level: 100%)
hash23356
Meterpreter botnet C2 server (confidence level: 100%)
hash2222
Meterpreter botnet C2 server (confidence level: 100%)
hash5002
Unknown malware payload delivery server (confidence level: 100%)
hash666
Cerberus botnet C2 server (confidence level: 100%)
hash3778
Mirai botnet C2 server (confidence level: 100%)
hash80
Meterpreter botnet C2 server (confidence level: 75%)
hash20001
VShell botnet C2 server (confidence level: 100%)
hash3778
Mirai botnet C2 server (confidence level: 100%)
hash7680
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash6606
AsyncRAT botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash443
Cobalt Strike botnet C2 server (confidence level: 75%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash59850
Cobalt Strike botnet C2 server (confidence level: 100%)
hash444
Unknown RAT botnet C2 server (confidence level: 100%)
hash14829
XWorm botnet C2 server (confidence level: 100%)
hash443
Unknown malware botnet C2 server (confidence level: 100%)
hash61011
VShell botnet C2 server (confidence level: 100%)
hash28192
Remcos botnet C2 server (confidence level: 100%)
hash4449
AsyncRAT botnet C2 server (confidence level: 100%)
hash4444
Quasar RAT botnet C2 server (confidence level: 100%)
hash6443
Quasar RAT botnet C2 server (confidence level: 100%)
hash41144
Meterpreter botnet C2 server (confidence level: 100%)
hash29848
Remcos botnet C2 server (confidence level: 100%)
hash10008
XWorm botnet C2 server (confidence level: 100%)
hash6666
XWorm botnet C2 server (confidence level: 100%)
hash7777
AsyncRAT botnet C2 server (confidence level: 75%)
hash111
DCRat botnet C2 server (confidence level: 75%)
hash1234
DarkComet botnet C2 server (confidence level: 100%)
hash59812
Cobalt Strike botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash4449
Remcos botnet C2 server (confidence level: 100%)
hash53919
Meterpreter botnet C2 server (confidence level: 100%)
hash7070
Sliver botnet C2 server (confidence level: 90%)
hash8808
AsyncRAT botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash80
Hook botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://116.203.14.212/
Vidar botnet C2 (confidence level: 100%)
urlhttps://46.62.225.178/
Vidar botnet C2 (confidence level: 100%)
urlhttp://165.232.165.152:8080/xoner.sh
Unknown malware payload delivery URL (confidence level: 75%)
urlhttps://74.0.48.145/
Vidar botnet C2 (confidence level: 100%)
urlhttps://dinglev.cyou/api
Lumma Stealer botnet C2 (confidence level: 100%)
urlhttp://185.174.133.12/98926703060a4fbf.php
Stealc botnet C2 (confidence level: 100%)
urlhttps://logicmesh.pro/api/bot/heartbeat
Unknown Stealer botnet C2 (confidence level: 100%)
urlhttp://192.168.226.132:18088/tjm2
Cobalt Strike botnet C2 (confidence level: 75%)

Domain

ValueDescriptionCopy
domaindusty-comet-jazz.com
SantaStealer botnet C2 domain (confidence level: 100%)
domainhdl.re-v.co.id
Vidar botnet C2 domain (confidence level: 100%)
domainheysilentpanel.onrender.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainnetwork-sync-protocol.net
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainconnect.kedi.lol
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainrobl0x.work.gd
Unknown malware botnet C2 domain (confidence level: 100%)
domaindd.lumibiki.xyz
Mirai botnet C2 domain (confidence level: 100%)
domainframe-donut.info
SantaStealer botnet C2 domain (confidence level: 100%)
domainth3hunt3r-48288.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainentershopst.ru.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainvvnc.ddns.net
Unknown RAT botnet C2 domain (confidence level: 100%)
domainlogicmesh.pro
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaintheengn.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincapitaf.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domaincarpoba.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainlimulit.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainmanufao.cyou
Lumma Stealer botnet C2 domain (confidence level: 100%)
domainprimedatahost1.cyou
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainprimedatahost2.cyou
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainprimedatahost3.cyou
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainprimedatahost4.cyou
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainpestcontrolinsarasota.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainjoeyapple.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domaincameework.com
Unknown Stealer botnet C2 domain (confidence level: 100%)
domainemail-api.argelni.site
Havoc botnet C2 domain (confidence level: 100%)
domainlcowpowerlite.italynorth.cloudapp.azure.com
Cobalt Strike botnet C2 domain (confidence level: 75%)
domain5.ooocyber.cfd
Unknown malware botnet C2 domain (confidence level: 100%)
domain4.ooocyber.cfd
Unknown malware botnet C2 domain (confidence level: 100%)
domainladydosug.cfd
Unknown malware botnet C2 domain (confidence level: 100%)
domainsdn-cloudflare-js-botstrup.cfd
Unknown malware botnet C2 domain (confidence level: 100%)
domainsdn-cloudflare-js.cfd
Unknown malware botnet C2 domain (confidence level: 100%)
domainwww.winabla.com
Unknown malware botnet C2 domain (confidence level: 100%)
domain4wpv9rkz.breathforgiv.digital
ClearFake payload delivery domain (confidence level: 100%)
domain2wjmdomc.breathforgiv.digital
ClearFake payload delivery domain (confidence level: 100%)
domainrmaa7-37443.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainturkirma7-53217.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainpenispro8ty2-54766.portmap.host
XWorm botnet C2 domain (confidence level: 100%)
domainqlb.uk.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainzxccvinorez738-44567.portmap.host
NjRAT botnet C2 domain (confidence level: 100%)
domainqiye.163.educn.xin
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainnamzcp.org
Unknown malware payload delivery domain (confidence level: 100%)
domainwww.jira.devergent.net
Hook botnet C2 domain (confidence level: 100%)
domainmta-251.70.ou2in.in
Cobalt Strike botnet C2 domain (confidence level: 100%)
domainir.alchemyapi.io
Unknown malware botnet C2 domain (confidence level: 100%)
domainbirdiethirty.com
Unknown malware botnet C2 domain (confidence level: 100%)

Threat ID: 698927194b57a58fa1dddc2d

Added to database: 2/9/2026, 12:15:21 AM

Last enriched: 2/9/2026, 12:30:40 AM

Last updated: 2/21/2026, 12:18:15 AM

Views: 106

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats