Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ThreatFox IOCs for 2026-02-09

0
Medium
Published: Mon Feb 09 2026 (02/09/2026, 00:00:00 UTC)
Source: ThreatFox MISP Feed
Vendor/Project: type
Product: osint

Description

ThreatFox IOCs for 2026-02-09

AI-Powered Analysis

AILast updated: 02/10/2026, 00:30:56 UTC

Technical Analysis

The provided information relates to a ThreatFox feed entry dated February 9, 2026, which contains Indicators of Compromise (IOCs) associated with malware activity. ThreatFox is a platform that aggregates threat intelligence, particularly IOCs, to aid in detection and response. This entry is categorized under OSINT, network activity, and payload delivery, indicating that it involves data useful for identifying malicious network behaviors and malware payloads. However, the entry lacks specific affected product versions, detailed technical indicators, or exploit descriptions. The severity is marked as medium, with no patches available and no known exploits actively used in the wild. The threat level is moderate (level 2), with distribution rated at 3, suggesting some degree of spread or sharing of these IOCs. The absence of CWE identifiers and the lack of CVSS scoring imply that this is not a vulnerability but rather a collection of threat intelligence data. The TLP: white tag indicates that the information is intended for wide dissemination, supporting collaborative defense efforts. This intelligence is valuable for security teams to enhance detection capabilities, particularly in monitoring network traffic for suspicious payload delivery mechanisms. However, without concrete exploit details or affected software versions, it does not represent an immediate or critical threat vector but rather a resource for improving situational awareness and proactive defense.

Potential Impact

The impact of this threat intelligence on European organizations is primarily in enhancing detection and response capabilities rather than indicating an immediate risk of compromise. Since no specific vulnerabilities or exploits are detailed, the direct impact on confidentiality, integrity, or availability is limited. However, the presence of malware-related IOCs related to network activity and payload delivery suggests potential risks if these indicators correspond to active or emerging malware campaigns. European organizations with extensive network infrastructures and exposure to advanced persistent threats may benefit from integrating these IOCs into their security monitoring tools to identify and mitigate potential intrusions early. Failure to incorporate such intelligence could delay detection of malware infections, potentially leading to data breaches or operational disruptions. The lack of patches or known exploits reduces urgency but underscores the importance of maintaining robust network monitoring and incident response processes. Overall, the impact is moderate, emphasizing preparedness and threat hunting rather than immediate remediation.

Mitigation Recommendations

To effectively leverage this threat intelligence, European organizations should: 1) Integrate the provided IOCs into existing Security Information and Event Management (SIEM) systems and intrusion detection/prevention systems (IDS/IPS) to enhance network traffic monitoring for suspicious payload delivery patterns. 2) Conduct regular threat hunting exercises using these IOCs to proactively identify potential malware infections or command and control communications within their networks. 3) Maintain updated endpoint detection and response (EDR) solutions capable of detecting malware payloads associated with the indicators. 4) Share relevant findings with national Computer Security Incident Response Teams (CSIRTs) and participate in information sharing communities to improve collective defense. 5) Ensure network segmentation and strict access controls to limit the lateral movement of malware if detected. 6) Conduct user awareness training focused on recognizing phishing or social engineering tactics that may be used to deliver malware payloads. 7) Continuously update and tune detection rules based on evolving threat intelligence feeds like ThreatFox to maintain relevance. These steps go beyond generic advice by emphasizing integration of specific IOCs into operational security workflows and collaborative defense mechanisms.

Need more detailed analysis?Upgrade to Pro Console

Technical Details

Threat Level
2
Analysis
1
Distribution
3
Uuid
29abcd58-7e71-4669-bf38-f845c01098bb
Original Timestamp
1770681787

Indicators of Compromise

File

ValueDescriptionCopy
file46.151.182.225
Mirai botnet C2 server (confidence level: 100%)
file185.241.211.47
Remcos botnet C2 server (confidence level: 100%)
file95.47.253.116
Remcos botnet C2 server (confidence level: 100%)
file31.57.219.108
XWorm botnet C2 server (confidence level: 100%)
file95.85.235.132
Stealc botnet C2 server (confidence level: 75%)
file138.124.53.228
Stealc botnet C2 server (confidence level: 75%)
file144.31.139.187
Stealc botnet C2 server (confidence level: 75%)
file193.58.121.25
Stealc botnet C2 server (confidence level: 75%)
file8.148.29.29
XWorm botnet C2 server (confidence level: 100%)
file46.246.34.54
Remcos botnet C2 server (confidence level: 100%)
file139.59.59.85
Meterpreter botnet C2 server (confidence level: 100%)
file94.143.231.8
Nanocore RAT botnet C2 server (confidence level: 100%)
file41.186.7.104
Mirai botnet C2 server (confidence level: 100%)
file172.245.195.233
PureLogs Stealer botnet C2 server (confidence level: 100%)
file67.205.147.7
Xtreme RAT botnet C2 server (confidence level: 100%)
file47.254.170.107
Xtreme RAT botnet C2 server (confidence level: 100%)
file34.7.42.123
Cobalt Strike botnet C2 server (confidence level: 100%)
file34.7.42.123
Cobalt Strike botnet C2 server (confidence level: 100%)
file104.223.84.7
Remcos botnet C2 server (confidence level: 100%)
file192.142.45.103
Sliver botnet C2 server (confidence level: 100%)
file185.132.53.123
Quasar RAT botnet C2 server (confidence level: 100%)
file195.177.94.12
Orcus RAT botnet C2 server (confidence level: 100%)
file182.212.9.184
XWorm botnet C2 server (confidence level: 100%)
file45.202.109.72
PureRAT botnet C2 server (confidence level: 100%)
file115.120.244.7
Cobalt Strike botnet C2 server (confidence level: 100%)
file165.245.130.101
Sliver botnet C2 server (confidence level: 90%)
file193.111.30.21
Unknown malware botnet C2 server (confidence level: 100%)
file103.1.40.214
Unknown malware botnet C2 server (confidence level: 100%)
file103.83.87.166
Havoc botnet C2 server (confidence level: 100%)
file51.250.15.222
Havoc botnet C2 server (confidence level: 100%)
file87.121.84.11
MooBot botnet C2 server (confidence level: 100%)
file107.155.52.231
Xtreme RAT botnet C2 server (confidence level: 100%)
file52.69.96.190
Xtreme RAT botnet C2 server (confidence level: 100%)
file151.242.170.208
PureRAT botnet C2 server (confidence level: 100%)
file192.252.181.13
PureRAT botnet C2 server (confidence level: 100%)
file185.243.115.103
Unknown RAT botnet C2 server (confidence level: 100%)
file160.187.229.40
Venom RAT botnet C2 server (confidence level: 100%)
file192.142.18.214
Brute Ratel C4 botnet C2 server (confidence level: 100%)
file103.177.47.65
Meterpreter botnet C2 server (confidence level: 100%)
file56.112.51.180
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.30
Meterpreter botnet C2 server (confidence level: 100%)
file139.180.215.5
Cobalt Strike botnet C2 server (confidence level: 100%)
file15.204.14.143
Havoc botnet C2 server (confidence level: 75%)
file172.86.122.65
Sliver botnet C2 server (confidence level: 75%)
file216.126.237.90
Sliver botnet C2 server (confidence level: 75%)
file35.163.173.124
DeimosC2 botnet C2 server (confidence level: 75%)
file212.11.64.126
XWorm botnet C2 server (confidence level: 100%)
file172.232.216.95
Unknown malware botnet C2 server (confidence level: 100%)
file178.16.54.251
Tofsee botnet C2 server (confidence level: 100%)
file23.235.163.42
Cobalt Strike botnet C2 server (confidence level: 100%)
file130.94.113.130
Cobalt Strike botnet C2 server (confidence level: 100%)
file47.110.69.92
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.162.105.126
Cobalt Strike botnet C2 server (confidence level: 100%)
file173.46.80.95
Sliver botnet C2 server (confidence level: 90%)
file104.249.26.232
PureLogs Stealer botnet C2 server (confidence level: 100%)
file95.216.107.48
Unknown malware botnet C2 server (confidence level: 100%)
file15.204.14.143
Havoc botnet C2 server (confidence level: 100%)
file160.30.209.132
Havoc botnet C2 server (confidence level: 100%)
file161.35.110.36
N-W0rm botnet C2 server (confidence level: 100%)
file31.220.43.205
Quasar RAT botnet C2 server (confidence level: 100%)
file46.225.92.224
Vidar botnet C2 server (confidence level: 100%)
file95.217.26.66
Vidar botnet C2 server (confidence level: 100%)
file65.109.254.182
Vidar botnet C2 server (confidence level: 100%)
file77.91.96.47
Vidar botnet C2 server (confidence level: 100%)
file89.167.31.204
Vidar botnet C2 server (confidence level: 100%)
file49.13.38.253
Vidar botnet C2 server (confidence level: 100%)
file65.109.246.40
Vidar botnet C2 server (confidence level: 100%)
file79.110.49.238
Vidar botnet C2 server (confidence level: 100%)
file46.62.225.178
Vidar botnet C2 server (confidence level: 100%)
file37.27.166.233
Vidar botnet C2 server (confidence level: 100%)
file49.13.36.25
Vidar botnet C2 server (confidence level: 100%)
file37.27.166.235
Vidar botnet C2 server (confidence level: 100%)
file192.177.26.243
Vidar botnet C2 server (confidence level: 100%)
file89.167.18.39
Vidar botnet C2 server (confidence level: 100%)
file49.13.34.188
Vidar botnet C2 server (confidence level: 100%)
file138.226.237.79
Vidar botnet C2 server (confidence level: 100%)
file138.226.237.71
Vidar botnet C2 server (confidence level: 100%)
file46.225.54.34
Vidar botnet C2 server (confidence level: 100%)
file37.27.166.239
Vidar botnet C2 server (confidence level: 100%)
file77.42.49.60
Vidar botnet C2 server (confidence level: 100%)
file138.199.245.21
Vidar botnet C2 server (confidence level: 100%)
file37.27.166.237
Vidar botnet C2 server (confidence level: 100%)
file37.27.166.234
Vidar botnet C2 server (confidence level: 100%)
file37.27.166.236
Vidar botnet C2 server (confidence level: 100%)
file37.27.166.76
Vidar botnet C2 server (confidence level: 100%)
file37.27.166.232
Vidar botnet C2 server (confidence level: 100%)
file159.69.113.85
Vidar botnet C2 server (confidence level: 100%)
file144.31.106.172
Vidar botnet C2 server (confidence level: 100%)
file116.203.9.52
Vidar botnet C2 server (confidence level: 100%)
file83.217.209.44
Vidar botnet C2 server (confidence level: 100%)
file195.201.253.123
Vidar botnet C2 server (confidence level: 100%)
file138.226.236.217
Vidar botnet C2 server (confidence level: 100%)
file138.226.236.17
Vidar botnet C2 server (confidence level: 100%)
file138.226.237.68
Vidar botnet C2 server (confidence level: 100%)
file116.203.7.87
Vidar botnet C2 server (confidence level: 100%)
file85.137.252.142
Vidar botnet C2 server (confidence level: 100%)
file49.13.38.79
Vidar botnet C2 server (confidence level: 100%)
file46.226.167.229
Vidar botnet C2 server (confidence level: 100%)
file116.203.8.174
Vidar botnet C2 server (confidence level: 100%)
file138.226.236.15
Vidar botnet C2 server (confidence level: 100%)
file74.0.48.138
Vidar botnet C2 server (confidence level: 100%)
file116.203.14.212
Vidar botnet C2 server (confidence level: 100%)
file49.13.32.137
Vidar botnet C2 server (confidence level: 100%)
file5.75.217.29
Vidar botnet C2 server (confidence level: 100%)
file195.201.250.234
Vidar botnet C2 server (confidence level: 100%)
file85.192.63.15
Vidar botnet C2 server (confidence level: 100%)
file8.141.93.66
Cobalt Strike botnet C2 server (confidence level: 100%)
file115.190.53.184
Cobalt Strike botnet C2 server (confidence level: 100%)
file89.208.105.207
XWorm botnet C2 server (confidence level: 100%)
file103.254.110.56
XWorm botnet C2 server (confidence level: 100%)
file185.246.113.213
Quasar RAT botnet C2 server (confidence level: 100%)
file8.219.228.71
ValleyRAT botnet C2 server (confidence level: 100%)
file147.124.219.209
PureLogs Stealer botnet C2 server (confidence level: 100%)
file147.45.198.90
StrelaStealer botnet C2 server (confidence level: 75%)
file107.175.88.82
Remcos botnet C2 server (confidence level: 100%)
file46.151.182.10
PureLogs Stealer botnet C2 server (confidence level: 100%)
file193.161.193.99
Quasar RAT botnet C2 server (confidence level: 75%)
file104.223.84.7
Remcos botnet C2 server (confidence level: 100%)
file38.47.208.75
ValleyRAT botnet C2 server (confidence level: 100%)
file185.182.219.14
SystemBC botnet C2 server (confidence level: 100%)
file23.226.58.234
Cobalt Strike botnet C2 server (confidence level: 100%)
file102.117.173.165
Unknown malware botnet C2 server (confidence level: 100%)
file81.70.142.22
Unknown malware botnet C2 server (confidence level: 100%)
file144.91.86.48
Remcos botnet C2 server (confidence level: 100%)
file18.158.58.205
XWorm botnet C2 server (confidence level: 100%)
file3.64.4.198
XWorm botnet C2 server (confidence level: 100%)
file198.13.159.206
Remcos botnet C2 server (confidence level: 100%)
file104.168.115.89
Remcos botnet C2 server (confidence level: 100%)
file38.180.106.24
MimiKatz botnet C2 server (confidence level: 100%)
file196.74.201.148
Meterpreter botnet C2 server (confidence level: 100%)
file103.177.47.125
Meterpreter botnet C2 server (confidence level: 100%)
file199.101.111.121
Meterpreter botnet C2 server (confidence level: 100%)
file47.128.246.233
Meterpreter botnet C2 server (confidence level: 100%)
file178.16.55.171
Stealc botnet C2 server (confidence level: 100%)
file45.119.55.56
ValleyRAT botnet C2 server (confidence level: 100%)
file181.224.24.205
XWorm botnet C2 server (confidence level: 100%)
file161.248.178.69
Remcos botnet C2 server (confidence level: 100%)
file86.105.9.67
Remcos botnet C2 server (confidence level: 100%)
file193.143.1.16
Amadey botnet C2 server (confidence level: 50%)
file78.29.43.89
NjRAT botnet C2 server (confidence level: 100%)
file103.83.87.166
Havoc botnet C2 server (confidence level: 75%)
file117.69.72.181
DeimosC2 botnet C2 server (confidence level: 75%)
file172.86.122.65
Sliver botnet C2 server (confidence level: 75%)
file18.102.135.133
Eye Pyramid botnet C2 server (confidence level: 75%)
file178.16.53.193
DCRat botnet C2 server (confidence level: 100%)
file34.225.69.162
DeimosC2 botnet C2 server (confidence level: 75%)
file193.161.193.99
NjRAT botnet C2 server (confidence level: 100%)
file54.251.43.143
DeimosC2 botnet C2 server (confidence level: 75%)
file95.216.2.96
RedLine Stealer botnet C2 server (confidence level: 75%)
file104.168.70.172
Remcos botnet C2 server (confidence level: 100%)
file45.154.98.251
Unknown malware botnet C2 server (confidence level: 100%)
file148.113.54.36
MimiKatz botnet C2 server (confidence level: 100%)
file95.213.143.102
Cobalt Strike botnet C2 server (confidence level: 90%)
file172.245.4.221
Remcos botnet C2 server (confidence level: 100%)
file172.245.4.221
Remcos botnet C2 server (confidence level: 100%)
file186.169.95.222
Remcos botnet C2 server (confidence level: 100%)
file47.109.45.70
Cobalt Strike botnet C2 server (confidence level: 100%)
file43.243.191.228
Cobalt Strike botnet C2 server (confidence level: 100%)
file18.196.13.161
Sliver botnet C2 server (confidence level: 90%)
file24.137.215.176
Sliver botnet C2 server (confidence level: 90%)
file18.230.60.155
Quasar RAT botnet C2 server (confidence level: 100%)
file181.134.217.128
Remcos botnet C2 server (confidence level: 100%)
file94.154.35.160
DCRat botnet C2 server (confidence level: 100%)
file143.92.32.132
ValleyRAT botnet C2 server (confidence level: 100%)

Hash

ValueDescriptionCopy
hash15390
Mirai botnet C2 server (confidence level: 100%)
hash10002
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash6000
XWorm botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 75%)
hash80
Stealc botnet C2 server (confidence level: 75%)
hash80
Stealc botnet C2 server (confidence level: 75%)
hash80
Stealc botnet C2 server (confidence level: 75%)
hash13108
XWorm botnet C2 server (confidence level: 100%)
hash54073
Remcos botnet C2 server (confidence level: 100%)
hash4444
Meterpreter botnet C2 server (confidence level: 100%)
hash9033
Nanocore RAT botnet C2 server (confidence level: 100%)
hash37215
Mirai botnet C2 server (confidence level: 100%)
hash7705
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 100%)
hash14645
Remcos botnet C2 server (confidence level: 100%)
hash80
Sliver botnet C2 server (confidence level: 100%)
hash5000
Quasar RAT botnet C2 server (confidence level: 100%)
hash1012
Orcus RAT botnet C2 server (confidence level: 100%)
hash55555
XWorm botnet C2 server (confidence level: 100%)
hash56001
PureRAT botnet C2 server (confidence level: 100%)
hash8888
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 90%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8888
Unknown malware botnet C2 server (confidence level: 100%)
hash8443
Havoc botnet C2 server (confidence level: 100%)
hash14447
Havoc botnet C2 server (confidence level: 100%)
hash80
MooBot botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash10001
Xtreme RAT botnet C2 server (confidence level: 100%)
hash56001
PureRAT botnet C2 server (confidence level: 100%)
hash56001
PureRAT botnet C2 server (confidence level: 100%)
hash443
Unknown RAT botnet C2 server (confidence level: 100%)
hash8080
Venom RAT botnet C2 server (confidence level: 100%)
hash8443
Brute Ratel C4 botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash9999
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash40056
Havoc botnet C2 server (confidence level: 75%)
hash541
Sliver botnet C2 server (confidence level: 75%)
hash8443
Sliver botnet C2 server (confidence level: 75%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash2222
XWorm botnet C2 server (confidence level: 100%)
hash39531
Unknown malware botnet C2 server (confidence level: 100%)
hash483
Tofsee botnet C2 server (confidence level: 100%)
hash24114
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash4444
Cobalt Strike botnet C2 server (confidence level: 100%)
hash8080
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7070
Sliver botnet C2 server (confidence level: 90%)
hash7705
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 100%)
hash8443
Havoc botnet C2 server (confidence level: 100%)
hash20780
N-W0rm botnet C2 server (confidence level: 100%)
hash555
Quasar RAT botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash443
Vidar botnet C2 server (confidence level: 100%)
hash8081
Cobalt Strike botnet C2 server (confidence level: 100%)
hash80
Cobalt Strike botnet C2 server (confidence level: 100%)
hash6000
XWorm botnet C2 server (confidence level: 100%)
hash7000
XWorm botnet C2 server (confidence level: 100%)
hash5321
Quasar RAT botnet C2 server (confidence level: 100%)
hash7711
ValleyRAT botnet C2 server (confidence level: 100%)
hash4862
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash80
StrelaStealer botnet C2 server (confidence level: 75%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash7705
PureLogs Stealer botnet C2 server (confidence level: 100%)
hash61262
Quasar RAT botnet C2 server (confidence level: 75%)
hash14643
Remcos botnet C2 server (confidence level: 100%)
hash3301
ValleyRAT botnet C2 server (confidence level: 100%)
hash4001
SystemBC botnet C2 server (confidence level: 100%)
hash59812
Cobalt Strike botnet C2 server (confidence level: 100%)
hash7443
Unknown malware botnet C2 server (confidence level: 100%)
hash8003
Unknown malware botnet C2 server (confidence level: 100%)
hash9596
Remcos botnet C2 server (confidence level: 100%)
hasha9e6652f5001b03df0cfb1e24620ae75
Akira payload (confidence level: 100%)
hashd3cf7a81ddd61e65fc4773257331325d
Akira payload (confidence level: 100%)
hash11193
XWorm botnet C2 server (confidence level: 100%)
hashb356ece2d8150fd0e7e673ae37033554
Unknown malware payload (confidence level: 100%)
hashe8c19bf10d044fe448a60e3fa0f60d58
Unknown malware payload (confidence level: 100%)
hasheb45ff7ea2ccdcceb2e7e14f9cc01397
Hive payload (confidence level: 100%)
hash92a27f2042385e3e9d097cf234c07859
Hive payload (confidence level: 100%)
hash6c1665d8f03efdc96991956f4d7f310d
Hive payload (confidence level: 100%)
hash8240d60d83cb7c0248e64389855e29b4
Hive payload (confidence level: 100%)
hash348c4b8618b06c15495988b461b5c355
Hive payload (confidence level: 100%)
hash516f36f2d29a32ee049caadd4721d884
Hive payload (confidence level: 100%)
hash504bd1695de326bc533fde29b8a69319
Hive payload (confidence level: 100%)
hash309efbf3a3364363b934800e4d3cd1ff
Hive payload (confidence level: 100%)
hash825c22175b75313f756f02a6b0c852e6
Hive payload (confidence level: 100%)
hash65f01cec34931077c63ae9efe2652ae5
Hive payload (confidence level: 100%)
hash4e5df98b89473facb7a29a8b5e5f6959
Hive payload (confidence level: 100%)
hashc0b7829f9faed6853182a2881c376aad
Hive payload (confidence level: 100%)
hash9da97a31801fb72ffc3061137dc3e625
Hive payload (confidence level: 100%)
hash8f3bafcb07d51a4157ca2a89e7127554
Hive payload (confidence level: 100%)
hash829494d97a5e7ff80d876422ba0adecc
Hive payload (confidence level: 100%)
hash39f1c1783f834680ca3ba58b851c20b6
Unknown malware payload (confidence level: 100%)
hash3311b2131007401b2a11a418a5161a7e
Unknown malware payload (confidence level: 100%)
hash3f67f0a9547631fbbc1d507c3c6c7380
Unknown malware payload (confidence level: 100%)
hasha01a4c76c35264c7f162744db0d5dcf6
Unknown malware payload (confidence level: 100%)
hash5c46ae2b51d33afce9926b9b292ad485
Unknown malware payload (confidence level: 100%)
hashd66eb7b6efd9ca13780b2e753df6587c
Unknown malware payload (confidence level: 100%)
hash216400cab8c536f04e7f72edb8f93fb4
Unknown malware payload (confidence level: 100%)
hash2d9c0cc020e43305e044897860de9300
Unknown malware payload (confidence level: 100%)
hashf68d17195fb617e0434ac171adbcfdd0
Unknown malware payload (confidence level: 100%)
hash96831ce727bc81ca277658ba06574e92
Unknown malware payload (confidence level: 100%)
hashe26bf4f10b17276abcd8f8c25f9ba109
Unknown malware payload (confidence level: 100%)
hasha850108f0b59193f8175aa72d38fa705
Unknown malware payload (confidence level: 100%)
hash5a86446479bcd01b14a91a86e2f0cacd
Unknown malware payload (confidence level: 100%)
hasha151b78280c700b76de27359cfcffe7c
Unknown malware payload (confidence level: 100%)
hashc05ae564100e34664a33bd2c9500e4d8
Unknown malware payload (confidence level: 100%)
hash3cf4b0d084500527c29cd8c00a959894
Unknown malware payload (confidence level: 100%)
hash8a15cff5f4cc4cb81a6769fc0ad56b9f
Unknown malware payload (confidence level: 100%)
hash39034417c9d734bb2eb0bce654196cb2
Unknown malware payload (confidence level: 100%)
hash7c568828bda5e18dae8d48871cc5ca4c
Unknown malware payload (confidence level: 100%)
hash617c3e8d37024c85b8ad4896993f2b33
Unknown malware payload (confidence level: 100%)
hash4e7042041d13d8873f1a414b79b0ba97
Unknown malware payload (confidence level: 100%)
hashe01e7b4106c53d169e532a92999d45fd
Unknown malware payload (confidence level: 100%)
hash44e4d5254580ce251c3d2fa9e48afae8
Unknown malware payload (confidence level: 100%)
hash2c1f1347db4725299171bcb108e16fdc
Unknown malware payload (confidence level: 100%)
hash2a1bac670d4cbaf6a89072ab8286c6ce
Unknown malware payload (confidence level: 100%)
hash0f61288b3f081b74f6452694f2c183fa
Unknown malware payload (confidence level: 100%)
hash925867a4775f3cdd87d5cc7c25a78661
Unknown malware payload (confidence level: 100%)
hash5bc2aba4e868132e7c1d3965a3e9eaf6
Unknown malware payload (confidence level: 100%)
hashc8bb051c49233285789a3f8faceeca35
Unknown malware payload (confidence level: 100%)
hash308f1cef04a58b6c2f57fcc536347742
Unknown malware payload (confidence level: 100%)
hash71229aeb820d321fe662ee23f291f784
Unknown malware payload (confidence level: 100%)
hash1743d9045cdbdb3b14bbbc684802f12e
Unknown malware payload (confidence level: 100%)
hashd8833082d3e1e0bbf487085d0b141dd2
Unknown malware payload (confidence level: 100%)
hash534eeb0f149fc3a3c29d6d0f4f454ed6
Unknown malware payload (confidence level: 100%)
hash9dde7fc220e7236bbcb5bc6bfa81fb48
Unknown malware payload (confidence level: 100%)
hash3bef7e917de7253cf027a0ad60e50903
Unknown malware payload (confidence level: 100%)
hash7442bf4b137b95314cb04c4e53b7c6c8
Unknown malware payload (confidence level: 100%)
hash7e4a52c5cf3f915621ea352e1c5bfe8b
Unknown malware payload (confidence level: 100%)
hash512840663f38b60c9017f4588743373c
Unknown malware payload (confidence level: 100%)
hash887dafea0ffe4aa3a7de06ff9c01822f
Unknown malware payload (confidence level: 100%)
hash02e86b907eb6c4bfb7114416cd93adb6
Unknown malware payload (confidence level: 100%)
hash641c96ed513ea57b12cce9765a464d1f
Unknown malware payload (confidence level: 100%)
hashf9880f1d821e341fcc1d02fc3bcd4a46
Unknown malware payload (confidence level: 100%)
hash9cd0dd80ab4e8aea1a5e3bd68f0cc4a1
Unknown malware payload (confidence level: 100%)
hashe94f590d3ffa9249c56abc54da8b9ff9
Unknown malware payload (confidence level: 100%)
hash207098d441658d527aacd47907db18bb
Unknown malware payload (confidence level: 100%)
hash1b14da773ee1587485658af701f6a318
Unknown malware payload (confidence level: 100%)
hashc8126e0403aff22d5244f7c8e833fad5
Unknown malware payload (confidence level: 100%)
hash76ff219037d2002ba15ff108093823c5
Unknown malware payload (confidence level: 100%)
hash6debd4a1b8ffd5815d1193f75a2502fe
Unknown malware payload (confidence level: 100%)
hash31fc85adb2f606efd019c117fb738b18
Unknown malware payload (confidence level: 100%)
hashd178566465c2fac70b23babdb5cd3942
Unknown malware payload (confidence level: 100%)
hash8b82daec9921814642f14663e44725fa
Unknown malware payload (confidence level: 100%)
hash03aedb971e90e7b15f7c243438953ac5
Unknown malware payload (confidence level: 100%)
hash4f8a330e41019ca3e6ad1c9fce8e2ae6
Unknown malware payload (confidence level: 100%)
hash3c6e1ed9589778eb6a809f69020f3559
Unknown malware payload (confidence level: 100%)
hash95b029490dc9cec864fca5ecdcb68a3c
Unknown malware payload (confidence level: 100%)
hash8db9feb81002729678208ea711a7f963
Unknown malware payload (confidence level: 100%)
hashcdb4ee00da5a6c38b157e15851775a54
Unknown malware payload (confidence level: 100%)
hashb309a0503eda65cedfe62ad19bb4787e
Unknown malware payload (confidence level: 100%)
hashb5185c7e4513497c58e05a9d149c33e4
Unknown malware payload (confidence level: 100%)
hashcbbdd351b09deffd2d3103404b644859
Unknown malware payload (confidence level: 100%)
hash989a42c0e736a155153b44d4b3909c0e
Unknown malware payload (confidence level: 100%)
hashbed46ea8881e3ba66a1c3e4e5f3e682c
Unknown malware payload (confidence level: 100%)
hash8fe57b2d875b7aa1628796a112619f85
Unknown malware payload (confidence level: 100%)
hash3592f16911fb0be685bdc5ca53382d24
Unknown malware payload (confidence level: 100%)
hash1eb30ddef447a971b508396931ed4f84
Unknown malware payload (confidence level: 100%)
hash368d2a7420bc7d7ce74daa355b38ebfe
Unknown malware payload (confidence level: 100%)
hash8f58ba60367c52ff4a4fa38c93309d77
Unknown malware payload (confidence level: 100%)
hashc17045623c2d8bb85d1c45efefecfcf3
Unknown malware payload (confidence level: 100%)
hashb4d3a8ffac8f3f963970cc5b9a2d9a9e
Unknown malware payload (confidence level: 100%)
hashfecddd03f2d0b13b7fa858457a8cfc4c
Unknown malware payload (confidence level: 100%)
hashd6decc71b793633fa58fa73bbb343c66
Unknown malware payload (confidence level: 100%)
hash589d799a2705832d63d95208dfe3a01c
Unknown malware payload (confidence level: 100%)
hashfa4d40d736d902738ef1fcd3a1e71047
Unknown malware payload (confidence level: 100%)
hashaf0811b26eef07e9916180ffdddc82c4
Unknown malware payload (confidence level: 100%)
hash7cbd781c7a73fb78180d33123291514d
Unknown malware payload (confidence level: 100%)
hash8192f39f696494b2ade24e7da8cec177
Unknown malware payload (confidence level: 100%)
hasha1c98e8b417d86a71ca3635758245881
Unknown malware payload (confidence level: 100%)
hashb8874058df485767451961e86cf52dce
Unknown malware payload (confidence level: 100%)
hash539f615941af7b598ebc106e396ea4fd
Unknown malware payload (confidence level: 100%)
hash11193
XWorm botnet C2 server (confidence level: 100%)
hash4538232bfc2fc58bbcace6e3821d5e75
Unknown malware payload (confidence level: 100%)
hash5b7b229d5db833a075c21e9f0b8bbb74
Unknown malware payload (confidence level: 100%)
hash425d28263b9cea66a259a86f0fca620f
Unknown malware payload (confidence level: 100%)
hashcce52f8d5fcdf83d6f89de141b62115c
Unknown malware payload (confidence level: 100%)
hash964540e24c4e2e048e4600e5f590bf96
Unknown malware payload (confidence level: 100%)
hash32d489eef7cbbdf51dc41d07648d7d8f
Unknown malware payload (confidence level: 100%)
hash7dd4efd9677a98a7ff1c66dfdba7852a
Unknown malware payload (confidence level: 100%)
hash9c41f4a272c21c620b4183833d504cec
Unknown malware payload (confidence level: 100%)
hash7b60c968072f1bb54ecad394e73680f0
Unknown malware payload (confidence level: 100%)
hash2f2e52c7391c99ef7166776dffff0b8e
Unknown malware payload (confidence level: 100%)
hashee0760a34add4d19972f49a65d810d26
Unknown malware payload (confidence level: 100%)
hashd41a428d6fc6ec7279ef958b6f8b8309
Unknown malware payload (confidence level: 100%)
hash75630ffadad01e23bf60a3e28d40314f
Unknown malware payload (confidence level: 100%)
hashdb45acae445c9dbdb1d4e973a4b667b9
Unknown malware payload (confidence level: 100%)
hash4041e867d38ad9e53f5f66a10f173bf1
Unknown malware payload (confidence level: 100%)
hashc02096360aa94a29a09ff384cb414590
Unknown malware payload (confidence level: 100%)
hashfadea836a7672f52874089ae3ae7dd07
Unknown malware payload (confidence level: 100%)
hashdf4a8ae3e3fde13b4e1400c88acbcafe
Unknown malware payload (confidence level: 100%)
hash3d0c663a3373a0e46a14fe1890144862
Unknown malware payload (confidence level: 100%)
hasha16a1228d5276eec526c21432a403923
Unknown malware payload (confidence level: 100%)
hash6221b0bf4d365454d40c546cf7133570
Unknown malware payload (confidence level: 100%)
hash512c09f594e0f8a12cc40d31a97f447e
Unknown malware payload (confidence level: 100%)
hashbe6efa1f17585408c64e03a9a49fad7d
win.beast payload (confidence level: 100%)
hashd65e4f29f7bfd5488382c8af47579f96
win.beast payload (confidence level: 100%)
hash302f55376a4fe499a1254a3b2dc1cd08
win.beast payload (confidence level: 100%)
hash52e16a3f06a31fe77ecc9d8733087511
win.beast payload (confidence level: 100%)
hash127c17ce1558a7417f61d60ec103b00c
win.beast payload (confidence level: 100%)
hash1e4ef27f4c26fbe83c495ed17ba3cf6c
win.beast payload (confidence level: 100%)
hash8dc0d5476a0aba6c62587f0ad636c77b
win.beast payload (confidence level: 100%)
hash19ad2f04f5f5972a7824e8683a3045a4
win.beast payload (confidence level: 100%)
hash82774a5c91510154d648f02f922afe1e
win.beast payload (confidence level: 100%)
hash2618cb05938899bcedeaa0ad4e092391
win.beast payload (confidence level: 100%)
hashbe10edf2ad5e39d23e0e8e1b19029aa0
win.beast payload (confidence level: 100%)
hash702f39613ffc2dce6302745eafcb87b4
win.beast payload (confidence level: 100%)
hash11b0866e0debcc83f4afecd7d8cfc56f
win.beast payload (confidence level: 100%)
hashea4073bb31ec7beffc2731751733610b
win.beast payload (confidence level: 100%)
hash7d87f436cfd85cbeda7efae8da05a325
win.beast payload (confidence level: 100%)
hashbee1aa2da186b4d6a1eb6cdf6c3f90ec
win.beast payload (confidence level: 100%)
hash2ab9905ee8297092292415ee83194391
win.beast payload (confidence level: 100%)
hash3b5950325efd4aa6865a776daed6a515
win.beast payload (confidence level: 100%)
hashd0728e075e66bda22bb6c030502a689a
win.beast payload (confidence level: 100%)
hash984a4f8544ca2718964aeb7affcf13c2
win.beast payload (confidence level: 100%)
hash9d820d26394e580e2cb99af2cb77aa1e
win.beast payload (confidence level: 100%)
hashcc8fad32545a066be26957fcf1e15a72
win.beast payload (confidence level: 100%)
hashafc1ad28879126eea6da177269f95aca
win.beast payload (confidence level: 100%)
hash3fe9f60d1189ba6e93038546c2c82434
win.beast payload (confidence level: 100%)
hashf1ade7769b7fdc2401798106ec7a9180
win.beast payload (confidence level: 100%)
hash7660fa5b758e5cbd89a16b8581be5488
win.beast payload (confidence level: 100%)
hash07cea63bca641d36f745bf5568bc8126
win.beast payload (confidence level: 100%)
hash4b5cd1447ae2c6bfbdc58688abece860
win.beast payload (confidence level: 100%)
hash63e4d0e113333b0bd2af6adb9f06c639
win.beast payload (confidence level: 100%)
hash62a88d64eea3645ed1652d17baaa1591
win.beast payload (confidence level: 100%)
hash4139d85e5037bb5dd1e0e7ca3a9d9061
win.beast payload (confidence level: 100%)
hashb57221549368a66b954765657a06c288
win.beast payload (confidence level: 100%)
hashbf8804e9d205362bcb606820ded01beb
win.beast payload (confidence level: 100%)
hashed759a0635ed6c4ebe920adc4500cdbe
win.beast payload (confidence level: 100%)
hashad793ac178ca43465c3c1e9fcc50bcbc
win.beast payload (confidence level: 100%)
hash4faf937d887ba56770c91376a1e1f58a
win.beast payload (confidence level: 100%)
hash3bfa839d66d9ea7c001506db06210baf
win.beast payload (confidence level: 100%)
hashd5b88355c3bc65b8b9471201e35597e4
win.beast payload (confidence level: 100%)
hash67ada43a989e3dc4e4976e7c9b3c99ce
win.beast payload (confidence level: 100%)
hash6e4ed24b25751cb9812e8133ff39f16f
win.beast payload (confidence level: 100%)
hash0aca13da401bcb147610ab0a99c753a1
win.beast payload (confidence level: 100%)
hashd53cc574fa69890ea6cb5d446d426f63
win.beast payload (confidence level: 100%)
hash00dae77adbe4c46d1cdf2e8309652545
win.beast payload (confidence level: 100%)
hash9620c50ccbcdbe646d97d26b220e1560
win.beast payload (confidence level: 100%)
hash059ac4569026c1b74e541d98b6240574
win.beast payload (confidence level: 100%)
hash2a976f4af95e9275056cd534d55e4011
win.beast payload (confidence level: 100%)
hashc909d9802b6d64682fa7e02aebd06e15
win.beast payload (confidence level: 100%)
hashd77b1189017544ee50d0dfade5484428
win.beast payload (confidence level: 100%)
hash7dd96ccc46eca19b03244159483e2230
win.beast payload (confidence level: 100%)
hashab13491acebc7751c7948471fd67a539
win.beast payload (confidence level: 100%)
hash867f7be7ae15dbbdd677047d012df8c1
win.beast payload (confidence level: 100%)
hash8b1b50aa9d5950a220a1f5aa241927be
win.beast payload (confidence level: 100%)
hashefab12f90fc8e6c2fcbf876506fc20fe
win.beast payload (confidence level: 100%)
hash11395b5231b765348d210660ea1f68e1
win.beast payload (confidence level: 100%)
hash7fe11977d078da0c3c7ace54ab47f04e
win.beast payload (confidence level: 100%)
hash2623a27403f3c247bf0f404bf249ac02
win.beast payload (confidence level: 100%)
hashabc78bf584bd59ad6653649c0299d8ab
win.beast payload (confidence level: 100%)
hash1630ebc68e2664d3ce8e7d7ebbdd9629
win.beast payload (confidence level: 100%)
hashe37ae4c4daded943894651c44cc283be
win.beast payload (confidence level: 100%)
hash5679c70050aac4050018f9899cf6e230
win.beast payload (confidence level: 100%)
hash74fd302390dc8e8b5f49d2da186e3e8c
win.beast payload (confidence level: 100%)
hashcc4f429af4c97010a2072f72ea0d674e
win.beast payload (confidence level: 100%)
hash443
Remcos botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash8080
MimiKatz botnet C2 server (confidence level: 100%)
hash2222
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash3790
Meterpreter botnet C2 server (confidence level: 100%)
hash5985
Meterpreter botnet C2 server (confidence level: 100%)
hash80
Stealc botnet C2 server (confidence level: 100%)
hash443
ValleyRAT botnet C2 server (confidence level: 100%)
hash8000
XWorm botnet C2 server (confidence level: 100%)
hash2404
Remcos botnet C2 server (confidence level: 100%)
hash42830
Remcos botnet C2 server (confidence level: 100%)
hash80
Amadey botnet C2 server (confidence level: 50%)
hash40299
NjRAT botnet C2 server (confidence level: 100%)
hash443
Havoc botnet C2 server (confidence level: 75%)
hash10250
DeimosC2 botnet C2 server (confidence level: 75%)
hash443
Sliver botnet C2 server (confidence level: 75%)
hash443
Eye Pyramid botnet C2 server (confidence level: 75%)
hash7777
DCRat botnet C2 server (confidence level: 100%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash57231
NjRAT botnet C2 server (confidence level: 100%)
hash443
DeimosC2 botnet C2 server (confidence level: 75%)
hash33816
RedLine Stealer botnet C2 server (confidence level: 75%)
hash4551
Remcos botnet C2 server (confidence level: 100%)
hash5555
Unknown malware botnet C2 server (confidence level: 100%)
hash8000
MimiKatz botnet C2 server (confidence level: 100%)
hash443
Cobalt Strike botnet C2 server (confidence level: 90%)
hash24040
Remcos botnet C2 server (confidence level: 100%)
hash24060
Remcos botnet C2 server (confidence level: 100%)
hash7070
Remcos botnet C2 server (confidence level: 100%)
hash12345
Cobalt Strike botnet C2 server (confidence level: 100%)
hash59812
Cobalt Strike botnet C2 server (confidence level: 100%)
hash443
Sliver botnet C2 server (confidence level: 90%)
hash443
Sliver botnet C2 server (confidence level: 90%)
hash4782
Quasar RAT botnet C2 server (confidence level: 100%)
hash7010
Remcos botnet C2 server (confidence level: 100%)
hash888
DCRat botnet C2 server (confidence level: 100%)
hash443
ValleyRAT botnet C2 server (confidence level: 100%)

Url

ValueDescriptionCopy
urlhttps://namzcp.org/
Unknown malware payload delivery URL (confidence level: 90%)
urlhttp://193.143.1.16/g8hrs4f4vh/index.php
Amadey botnet C2 (confidence level: 100%)
urlhttp://130.12.180.121/file/all
Unknown malware payload delivery URL (confidence level: 75%)
urlhttp://130.12.180.20:34029/cat.sh
Unknown malware payload delivery URL (confidence level: 75%)
urlhttp://cg651919.tw1.ru/8830ffbd.php
DCRat botnet C2 (confidence level: 100%)
urlhttps://steamcommunity.com/profiles/76561198742173262
Vidar botnet C2 (confidence level: 100%)
urlhttps://telegram.me/ho00rq
Vidar botnet C2 (confidence level: 100%)
urlhttps://steamcommunity.com/profiles/76561198742377525
Vidar botnet C2 (confidence level: 100%)
urlhttps://telegram.me/dikkh0k
Vidar botnet C2 (confidence level: 100%)
urlhttps://uyu.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://als.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://kis.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://xtr.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://cro.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://din.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://nwk.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://tog.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://log.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://reg.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ale.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://wnd.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://vid.deshsaradin.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://vip.dokantrack.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://pal.dokantrack.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://fal.dokantrack.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://stk.dokantrack.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://rfg.dokantrack.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://vid.dokantrack.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://opa.dokantrack.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://uyu.munsitex.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://kis.munsitex.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://xtr.munsitex.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://cro.munsitex.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://din.munsitex.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://nwk.munsitex.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://wnd.munsitex.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://vip.skjeelanhemas.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://pal.skjeelanhemas.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://fal.skjeelanhemas.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://al.skjeelanhemas.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://stk.skjeelanhemas.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://rfg.skjeelanhemas.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://vid.skjeelanhemas.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://id.skjeelanhemas.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://opa.skjeelanhemas.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttps://nwo.emiraride.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://pin.emiraride.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://hdl.emiraride.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://c2h.emiraride.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://pin.itho.eu.org/
Vidar botnet C2 (confidence level: 100%)
urlhttps://c2h.itho.eu.org/
Vidar botnet C2 (confidence level: 100%)
urlhttps://hdl.re-v.co.id/
Vidar botnet C2 (confidence level: 100%)
urlhttps://nwo.re-v.co.id/
Vidar botnet C2 (confidence level: 100%)
urlhttps://74.0.32.189/
Vidar botnet C2 (confidence level: 100%)
urlhttps://151.247.193.226/
Vidar botnet C2 (confidence level: 100%)
urlhttps://46.225.92.224/
Vidar botnet C2 (confidence level: 100%)
urlhttps://95.217.26.66/
Vidar botnet C2 (confidence level: 100%)
urlhttps://65.109.254.182/
Vidar botnet C2 (confidence level: 100%)
urlhttps://77.91.96.47/
Vidar botnet C2 (confidence level: 100%)
urlhttps://89.167.31.204/
Vidar botnet C2 (confidence level: 100%)
urlhttps://151.247.193.213/
Vidar botnet C2 (confidence level: 100%)
urlhttps://49.13.38.253/
Vidar botnet C2 (confidence level: 100%)
urlhttps://65.109.246.40/
Vidar botnet C2 (confidence level: 100%)
urlhttps://79.110.49.238/
Vidar botnet C2 (confidence level: 100%)
urlhttps://37.27.166.233/
Vidar botnet C2 (confidence level: 100%)
urlhttps://138.199.198.141/
Vidar botnet C2 (confidence level: 100%)
urlhttps://49.13.36.25/
Vidar botnet C2 (confidence level: 100%)
urlhttps://37.27.166.235/
Vidar botnet C2 (confidence level: 100%)
urlhttps://192.177.26.243/
Vidar botnet C2 (confidence level: 100%)
urlhttps://89.167.18.39/
Vidar botnet C2 (confidence level: 100%)
urlhttps://49.13.34.188/
Vidar botnet C2 (confidence level: 100%)
urlhttps://138.226.237.103/
Vidar botnet C2 (confidence level: 100%)
urlhttps://138.226.237.79/
Vidar botnet C2 (confidence level: 100%)
urlhttps://138.226.237.102/
Vidar botnet C2 (confidence level: 100%)
urlhttps://138.226.237.71/
Vidar botnet C2 (confidence level: 100%)
urlhttps://46.225.54.34/
Vidar botnet C2 (confidence level: 100%)
urlhttps://37.27.166.239/
Vidar botnet C2 (confidence level: 100%)
urlhttps://77.42.49.60/
Vidar botnet C2 (confidence level: 100%)
urlhttps://138.199.245.21/
Vidar botnet C2 (confidence level: 100%)
urlhttps://37.27.166.237/
Vidar botnet C2 (confidence level: 100%)
urlhttps://37.27.166.234/
Vidar botnet C2 (confidence level: 100%)
urlhttps://37.27.166.236/
Vidar botnet C2 (confidence level: 100%)
urlhttps://37.27.166.76/
Vidar botnet C2 (confidence level: 100%)
urlhttps://37.27.166.232/
Vidar botnet C2 (confidence level: 100%)
urlhttps://159.69.113.85/
Vidar botnet C2 (confidence level: 100%)
urlhttps://144.31.106.172/
Vidar botnet C2 (confidence level: 100%)
urlhttps://116.203.9.52/
Vidar botnet C2 (confidence level: 100%)
urlhttps://83.217.209.44/
Vidar botnet C2 (confidence level: 100%)
urlhttps://89.167.29.89/
Vidar botnet C2 (confidence level: 100%)
urlhttps://195.201.253.123/
Vidar botnet C2 (confidence level: 100%)
urlhttps://138.226.236.217/
Vidar botnet C2 (confidence level: 100%)
urlhttps://138.226.236.17/
Vidar botnet C2 (confidence level: 100%)
urlhttps://138.226.237.68/
Vidar botnet C2 (confidence level: 100%)
urlhttps://116.203.7.87/
Vidar botnet C2 (confidence level: 100%)
urlhttps://85.137.252.142/
Vidar botnet C2 (confidence level: 100%)
urlhttps://49.13.38.79/
Vidar botnet C2 (confidence level: 100%)
urlhttps://46.226.167.229/
Vidar botnet C2 (confidence level: 100%)
urlhttps://116.203.8.174/
Vidar botnet C2 (confidence level: 100%)
urlhttps://138.226.236.16/
Vidar botnet C2 (confidence level: 100%)
urlhttps://138.226.236.15/
Vidar botnet C2 (confidence level: 100%)
urlhttps://74.0.48.138/
Vidar botnet C2 (confidence level: 100%)
urlhttps://138.226.237.78/
Vidar botnet C2 (confidence level: 100%)
urlhttps://49.13.32.137/
Vidar botnet C2 (confidence level: 100%)
urlhttps://5.75.217.29/
Vidar botnet C2 (confidence level: 100%)
urlhttps://195.201.250.234/
Vidar botnet C2 (confidence level: 100%)
urlhttps://85.192.63.15/
Vidar botnet C2 (confidence level: 100%)
urlhttp://msdpoll2000.com/serv.php
StrelaStealer botnet C2 (confidence level: 100%)
urlhttps://jfo.emiraride.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://jfo.ezln.net/
Vidar botnet C2 (confidence level: 100%)
urlhttps://tefalle.com/5a7h.js
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://tefalle.com/js.php
KongTuke payload delivery URL (confidence level: 100%)
urlhttps://thesnackbee.com/j.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://missjump.com/auth/admin-request.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://missjump.com/auth/proxy-fetch.php
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://missjump.com/auth/settings-server.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttp://193.42.38.8/path
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://number1sci.com/path
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://193.42.38.8/args
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttp://159.198.75.187/d076201aa1664664.php
Stealc botnet C2 (confidence level: 100%)
urlhttps://socialiteration.com/callback/principal-controller.php
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://socialiteration.com/callback/role-sessionstore.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttp://185.81.115.250/serve
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://nimbusious.com/serve
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://185.81.115.250/stream
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://heywl.com/auth/proxy-fetch.php
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://heywl.com/auth/settings-server.js
SmartApeSG payload delivery URL (confidence level: 100%)
urlhttps://ffo.emiraride.com/
Vidar botnet C2 (confidence level: 100%)
urlhttps://ffo.ubsstores.com.lk/
Vidar botnet C2 (confidence level: 100%)
urlhttp://191.252.214.115/ouro/inspecionando.php
Metamorfo botnet C2 (confidence level: 100%)
urlhttp://191.252.214.115/matrix/inspecionando.php
Metamorfo botnet C2 (confidence level: 100%)

Domain

ValueDescriptionCopy
domainoculusr.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domainverbala.cyou
Lumma Stealer botnet C2 domain (confidence level: 75%)
domainallwheelwealth.duckdns.org
XWorm botnet C2 domain (confidence level: 100%)
domainarmyshoe.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainceleryerror.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domaingrandfatherquiver.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainmountainsurprise.cfd
Unknown Loader botnet C2 domain (confidence level: 100%)
domainpeacetongue.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainargumentablyfile.space
Unknown Loader botnet C2 domain (confidence level: 100%)
domainrabbitsbird.info
Unknown Loader botnet C2 domain (confidence level: 100%)
domaintoescloth.space
Unknown Loader botnet C2 domain (confidence level: 100%)
domaincreamfurniture.space
Unknown Loader botnet C2 domain (confidence level: 100%)
domaincrackfood.space
Unknown Loader botnet C2 domain (confidence level: 100%)
domainwoundsecretary.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainglassmove.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainapparelplate.space
Unknown Loader botnet C2 domain (confidence level: 100%)
domainarchairport.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainsparkrice.space
Unknown Loader botnet C2 domain (confidence level: 100%)
domaincrimestreet.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domaintoespiders.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domaingeeseairport.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainmilkname.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainbranchmorning.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainbabyvein.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainholemuscle.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainwastewine.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainbellplayground.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainboytank.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domaintreesboard.xyz
Unknown Loader botnet C2 domain (confidence level: 100%)
domainalienmesh.servehttp.com
Unknown malware botnet C2 domain (confidence level: 100%)
domainmsdpoll2000.com
StrelaStealer botnet C2 domain (confidence level: 75%)
domainuyu.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domainals.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domainkis.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domainxtr.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domaincro.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domaindin.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domainnwk.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domaintog.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domainlog.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domainreg.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domainale.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domainwnd.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domainvid.deshsaradin.com
Vidar botnet C2 domain (confidence level: 100%)
domainvip.dokantrack.com
Vidar botnet C2 domain (confidence level: 100%)
domainpal.dokantrack.com
Vidar botnet C2 domain (confidence level: 100%)
domainfal.dokantrack.com
Vidar botnet C2 domain (confidence level: 100%)
domainstk.dokantrack.com
Vidar botnet C2 domain (confidence level: 100%)
domainrfg.dokantrack.com
Vidar botnet C2 domain (confidence level: 100%)
domainvid.dokantrack.com
Vidar botnet C2 domain (confidence level: 100%)
domainopa.dokantrack.com
Vidar botnet C2 domain (confidence level: 100%)
domainuyu.munsitex.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainkis.munsitex.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainxtr.munsitex.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domaincro.munsitex.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domaindin.munsitex.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainnwk.munsitex.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainwnd.munsitex.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainvip.skjeelanhemas.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainpal.skjeelanhemas.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainfal.skjeelanhemas.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainal.skjeelanhemas.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainstk.skjeelanhemas.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainrfg.skjeelanhemas.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainvid.skjeelanhemas.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainid.skjeelanhemas.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainopa.skjeelanhemas.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainnwo.emiraride.com
Vidar botnet C2 domain (confidence level: 100%)
domainpin.emiraride.com
Vidar botnet C2 domain (confidence level: 100%)
domainhdl.emiraride.com
Vidar botnet C2 domain (confidence level: 100%)
domainc2h.emiraride.com
Vidar botnet C2 domain (confidence level: 100%)
domainpin.itho.eu.org
Vidar botnet C2 domain (confidence level: 100%)
domainc2h.itho.eu.org
Vidar botnet C2 domain (confidence level: 100%)
domainnwo.re-v.co.id
Vidar botnet C2 domain (confidence level: 100%)
domainonebigbucks2026.duckdns.org
XWorm botnet C2 domain (confidence level: 100%)
domainnews.sa.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domain7pzq4w03j.localto.net
SpyNote botnet C2 domain (confidence level: 100%)
domainwjozjs8a3.localto.net
SpyNote botnet C2 domain (confidence level: 100%)
domainjfo.emiraride.com
Vidar botnet C2 domain (confidence level: 100%)
domainjfo.ezln.net
Vidar botnet C2 domain (confidence level: 100%)
domainwww.grossmanchev.com
Remcos botnet C2 domain (confidence level: 75%)
domainwww.imagearyth.fit
Remcos botnet C2 domain (confidence level: 75%)
domainwww.regclineeatry.ink
Remcos botnet C2 domain (confidence level: 75%)
domaintefalle.com
KongTuke payload delivery domain (confidence level: 100%)
domainthesnackbee.com
SmartApeSG payload delivery domain (confidence level: 100%)
domainmissjump.com
SmartApeSG payload delivery domain (confidence level: 100%)
domainmacsendsync.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainmacfileatelier.com
Unknown Stealer payload delivery domain (confidence level: 100%)
domainx1esalwanazeeze.duckdns.org
Remcos botnet C2 domain (confidence level: 100%)
domainsicarilxx2br6esqnhad4w26bcgb5j2snbbnhyo4b6t7kby2oy4x3jad.onion
Unknown malware botnet C2 domain (confidence level: 100%)
domainsicari7zpu3mtxqggde7mu3ywppntdqg22arcukvlaihjbfcb2rnktid.onion
Unknown malware botnet C2 domain (confidence level: 100%)
domainfewcriet5rhoy66k6c4cyvb2pqrblxtx4mekj3s5l4jjt4t4kn4vheyd.onion
Unknown malware botnet C2 domain (confidence level: 50%)
domaincephalus6oiypuwumqlwurvbmwsfglg424zjdmywfgqm4iehkqivsjyd.onion
Unknown malware botnet C2 domain (confidence level: 100%)
domainbeast6azu4f7fxjakiayhnssybibsgjnmy77a6duufqw5afjzfjhzuqd.onion
win.beast botnet C2 domain (confidence level: 100%)
domainooie6tet7ggcmlgvtmyvok4s6vha6ecwczssbchbyxrg2r6v2m6zkkad.onion
win.beast botnet C2 domain (confidence level: 100%)
domainsocialiteration.com
SmartApeSG payload delivery domain (confidence level: 100%)
domain4kiwmn32z8feawr.top
GhostWeaver botnet C2 domain (confidence level: 100%)
domainernyxqdbgkfemuq.fun
GhostWeaver botnet C2 domain (confidence level: 100%)
domain4ec74y9kph5vko2.fun
GhostWeaver botnet C2 domain (confidence level: 100%)
domainx6v1cp7x3xrl6nr.top
GhostWeaver botnet C2 domain (confidence level: 100%)
domainw2c6dlttlx56bdg.top
GhostWeaver botnet C2 domain (confidence level: 100%)
domainmo2ekup2uvwn97r.top
GhostWeaver botnet C2 domain (confidence level: 100%)
domain5zrm1p5ky8mfyqg.top
GhostWeaver botnet C2 domain (confidence level: 100%)
domainheywl.com
SmartApeSG payload delivery domain (confidence level: 100%)
domainffo.ubsstores.com.lk
Vidar botnet C2 domain (confidence level: 100%)
domainffo.emiraride.com
Vidar botnet C2 domain (confidence level: 100%)
domainseatlace.space
Unknown Loader botnet C2 domain (confidence level: 100%)
domainbei.tfuuuk.com
ValleyRAT botnet C2 domain (confidence level: 75%)
domaintuu.tfuuuk.com
ValleyRAT botnet C2 domain (confidence level: 75%)
domainjordonofficials.de.com
AsyncRAT botnet C2 domain (confidence level: 75%)
domainslot365-vn01.com
AsyncRAT botnet C2 domain (confidence level: 75%)
domaincarki.duckdns.org
AsyncRAT botnet C2 domain (confidence level: 100%)
domainhuige.yunduans.com
ValleyRAT botnet C2 domain (confidence level: 100%)
domainwww.yussllm.life
ValleyRAT botnet C2 domain (confidence level: 100%)
domaindekito-34501.portmap.host
SpyNote botnet C2 domain (confidence level: 100%)
domain4d3snjw5.degenjudges.digital
ClearFake payload delivery domain (confidence level: 100%)
domainbyebopfx.degenjudges.digital
ClearFake payload delivery domain (confidence level: 100%)
domainvlxx.eu.com
AsyncRAT botnet C2 domain (confidence level: 75%)
domainginabraz1985bk.duckdns.org
Remcos botnet C2 domain (confidence level: 75%)
domainjawared1-63785.portmap.host
AsyncRAT botnet C2 domain (confidence level: 100%)
domainv2.www.youngabout.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainv3.www.youngabout.com
AsyncRAT botnet C2 domain (confidence level: 100%)
domainmalware.vn168.cam
AsyncRAT botnet C2 domain (confidence level: 100%)
domainremcosnuevo5.duckdns.org
Remcos botnet C2 domain (confidence level: 75%)
domainmacsignal.com
Unknown Stealer payload delivery domain (confidence level: 100%)

Threat ID: 698a78994b57a58fa17a85c0

Added to database: 2/10/2026, 12:15:21 AM

Last enriched: 2/10/2026, 12:30:56 AM

Last updated: 2/11/2026, 6:59:13 PM

Views: 89

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats