ThreatFox IOCs for 2026-02-19
ThreatFox IOCs for 2026-02-19
AI Analysis
Technical Summary
The provided information describes a malware-related threat entry from the ThreatFox MISP feed dated February 19, 2026. This entry is primarily an OSINT (Open Source Intelligence) artifact that catalogs indicators of compromise (IOCs) associated with network activity and payload delivery. However, the entry lacks specific details such as affected software versions, concrete technical indicators, or exploit mechanisms. No known exploits in the wild have been reported, and no patches or remediation links are available. The threat level is marked as medium, reflecting a moderate risk based on the limited data. The technical details include a low threat level (2 out of an unspecified scale), minimal analysis (1), and moderate distribution (3), suggesting some dissemination but limited confirmed impact. The absence of CWEs and specific indicators implies this is an intelligence-sharing record rather than a direct vulnerability or active exploit. This type of entry is typically used by security teams to enhance situational awareness and prepare defenses against potential payload delivery attempts that may emerge from the observed network activity patterns. The lack of detailed technical data restricts deeper analysis but highlights the importance of continuous monitoring of OSINT feeds and network traffic for early detection of emerging threats.
Potential Impact
Given the limited information and absence of known exploits or patches, the immediate impact on organizations is likely low to medium. However, the presence of payload delivery and network activity tags indicates potential risks of malware infections if related IOCs are encountered in operational environments. Organizations relying heavily on OSINT tools or integrating ThreatFox feeds into their security operations may be better positioned to detect and respond to such threats. The lack of specific affected versions or vulnerabilities suggests this is not a targeted exploit but rather a general malware campaign or intelligence artifact. If payload delivery attempts succeed, impacts could include data compromise, system disruption, or lateral movement within networks. The medium severity rating suggests a moderate risk that warrants attention but does not indicate an imminent critical threat. Overall, the impact is contingent on the ability of organizations to detect and mitigate suspicious network activity and payloads associated with these IOCs.
Mitigation Recommendations
1. Integrate ThreatFox and other OSINT feeds into Security Information and Event Management (SIEM) systems to enable real-time detection of related IOCs. 2. Enhance network monitoring to identify unusual payload delivery attempts or suspicious network activity patterns. 3. Employ endpoint detection and response (EDR) tools to detect and block malware payloads early in the infection chain. 4. Conduct regular threat hunting exercises focusing on network traffic anomalies and payload signatures associated with the shared IOCs. 5. Maintain updated and comprehensive incident response plans that include procedures for handling malware infections and network intrusions. 6. Educate security teams on interpreting OSINT threat intelligence and correlating it with internal telemetry for proactive defense. 7. Since no patches are available, focus on hardening network segmentation and access controls to limit potential malware spread. 8. Validate and tune intrusion detection/prevention systems (IDS/IPS) to recognize patterns consistent with the described threat activity. These steps go beyond generic advice by emphasizing the operational integration of OSINT feeds and proactive network and endpoint monitoring tailored to the threat characteristics.
Affected Countries
United States, United Kingdom, Germany, France, Canada, Australia, Japan, South Korea, Netherlands, Sweden
Indicators of Compromise
- file: 8.162.5.187
- hash: 14701
- url: https://www.gorscts.shop/
- file: 193.161.193.99
- hash: 44688
- domain: systemcore.murta46unprin.coupons
- file: 45.150.32.124
- hash: 80
- file: 45.94.31.178
- hash: 8990
- url: https://hodorit.com/identity/route-sandbox.php
- domain: hodorit.com
- url: https://hodorit.com/identity/rate-util.js
- url: https://cirealci.com/froute1
- url: https://185.33.87.29/zipp2
- domain: 3mi05cn7h7k4ecsb.frostapi.com
- file: 206.123.132.224
- hash: 39558
- url: https://74.0.48.206/
- file: 198.244.201.139
- hash: 7181
- domain: botnet.exiled.fit
- file: 172.105.85.143
- hash: 20809
- url: https://mieyabi.com/5j1s.js
- domain: mieyabi.com
- url: https://mieyabi.com/js.php
- file: 89.167.52.86
- hash: 853
- file: 146.70.181.238
- hash: 5675
- file: 172.111.162.252
- hash: 2620
- file: 23.26.129.38
- hash: 24024
- url: http://91.92.243.29/klob
- file: 193.161.193.99
- hash: 25340
- file: 193.161.193.99
- hash: 51173
- file: 87.242.106.13
- hash: 64370
- file: 107.152.32.98
- hash: 2491
- file: 193.161.193.99
- hash: 61682
- file: 157.15.98.138
- hash: 80
- file: 54.89.163.179
- hash: 179
- file: 43.209.225.147
- hash: 44819
- file: 78.12.9.38
- hash: 59161
- domain: stonepath.rockwood.coupons
- domain: solidleaf.rockwood.coupons
- domain: fruitcase.plum63box.coupons
- file: 128.90.102.133
- hash: 7000
- domain: redplum.plum63box.coupons
- domain: boxstore.plum63box.coupons
- domain: sweetstock.plum63box.coupons
- domain: coldbreeze.snowwind.coupons
- domain: wintertrack.snowwind.coupons
- domain: purewhite.snowwind.coupons
- domain: chillstream.snowwind.coupons
- domain: quickpath.fastlane.coupons
- domain: roadrunner.fastlane.coupons
- domain: drivelogic.fastlane.coupons
- domain: shiftpoint.fastlane.coupons
- domain: shipfresh.mint5ship.coupons
- domain: greenleaf.mint5ship.coupons
- domain: swiftcore.cloudbridge.city
- file: 112.68.47.218
- hash: 2323
- domain: linkflow.cloudbridge.city
- domain: openport.cloudbridge.city
- domain: 21.yunduans.com
- domain: fastgate.cloudbridge.city
- domain: greenleaf.natureway.city
- file: 147.185.221.181
- hash: 17288
- file: 165.232.45.1
- hash: 7000
- file: 156.246.95.51
- hash: 80
- domain: nexit-53294.portmap.host
- domain: nexit-62461.portmap.host
- domain: 26068482b66202d6ca29e1bb210288c8.444ef3f25893ae427338085e576fa9fb.traefik.default
- file: 3.81.3.110
- hash: 443
- file: 130.164.164.220
- hash: 443
- file: 38.127.8.3
- hash: 443
- file: 45.89.140.80
- hash: 80
- file: 45.89.140.78
- hash: 80
- domain: earthmap.natureway.city
- domain: wildtrack.natureway.city
- domain: riverflow.natureway.city
- file: 137.184.61.113
- hash: 8001
- file: 159.65.252.42
- hash: 8001
- file: 165.22.193.95
- hash: 8001
- file: 174.138.15.64
- hash: 8001
- file: 157.245.86.38
- hash: 8001
- file: 178.128.247.58
- hash: 8001
- file: 142.93.137.168
- hash: 8001
- file: 104.131.8.3
- hash: 8001
- file: 165.232.80.66
- hash: 8001
- file: 143.110.139.54
- hash: 8001
- domain: smartstep.urbanlab.city
- domain: pulseview.urbanlab.city
- domain: gridlock.urbanlab.city
- domain: 52wyvwc0.cabinetslyuka.digital
- domain: pxkpoxt8.cabinetslyuka.digital
- domain: brightsky.starpoint.city
- domain: goldlight.goldstar.coupons
- domain: brightsky.goldstar.coupons
- domain: shinepoint.goldstar.coupons
- file: 94.73.17.125
- hash: 8088
- domain: next-dance.gl.at.ply.gg
- domain: spacecore.goldstar.coupons
- file: 134.209.55.29
- hash: 8001
- file: 101.132.167.9
- hash: 8088
- domain: boxlayer.box1fig7.coupons
- url: https://polygon.qbetfhwz.xyz/gate/health
- domain: polygon.qbetfhwz.xyz
- domain: figstore.box1fig7.coupons
- domain: roundpack.box1fig7.coupons
- domain: baseflow.box1fig7.coupons
- file: 144.172.108.230
- hash: 9000
- file: 167.172.48.226
- hash: 8001
- domain: desertroad.sandwave.coupons
- file: 165.227.115.71
- hash: 5505
- file: 122.225.30.226
- hash: 10001
- domain: raterake.cfd
- domain: drywind.sandwave.coupons
- url: https://rss.gadgetwalabd.com/
- url: https://rss.alpinematters.com/
- domain: rss.gadgetwalabd.com
- domain: rss.alpinematters.com
- domain: donothg.cyou
- domain: francek.cyou
- domain: goldensand.sandwave.coupons
- domain: houstongaragedoorinstallers.com
- domain: biopranica.com
- domain: pressureulcerlawyer.com
- domain: usedteslabuyers.com
- domain: warmtrack.sandwave.coupons
- domain: pearbox.pack12pear.coupons
- file: 84.38.133.182
- hash: 41000
- domain: fruitpack.pack12pear.coupons
- domain: localstore.pack12pear.coupons
- domain: www.safebrowse.io
- domain: greenlabel.pack12pear.coupons
- domain: ironcore.ironstar.coupons
- domain: steelsync.ironstar.coupons
- file: 138.91.32.183
- hash: 8888
- domain: powerbeat.ironstar.coupons
- file: 165.245.130.101
- hash: 9090
- file: 172.86.91.226
- hash: 443
- file: 185.179.189.122
- hash: 443
- file: 24.20.225.162
- hash: 8080
- file: 52.146.70.84
- hash: 8013
- domain: hardlink.ironstar.coupons
- domain: moonlight.eastmoon.coupons
- domain: darksky.eastmoon.coupons
- domain: eastorbit.eastmoon.coupons
- domain: glowpoint.eastmoon.coupons
- domain: gsm.ftp.sh
- domain: plm.ftp.sh
- file: 172.233.46.113
- hash: 6667
- domain: mintbase.ship48mint.coupons
- domain: coldship.ship48mint.coupons
- domain: xxblessingswealths.duckdns.org
- file: 209.54.103.184
- hash: 1909
- domain: yupangco.com
- file: 138.199.59.6
- hash: 60736
- domain: freshroute.ship48mint.coupons
- url: http://158.94.211.76:3232/ceoznp
- file: 158.94.211.76
- hash: 3232
- domain: fastpack.ship48mint.coupons
- domain: kiwitalk.ship46kiwi.coupons
- domain: greenbird.ship46kiwi.coupons
- domain: fastkiwi.ship46kiwi.coupons
- file: 172.94.100.227
- hash: 29811
- domain: skyline.ship46kiwi.coupons
- domain: colaba.ru.com
- domain: wsc.in.net
- domain: hg0088.co.com
- domain: 789f.br.com
- domain: bertran.ru.com
- domain: frunglewump.gb.net
- domain: hcolaba.ru.com
- domain: wwn.uk.com
- file: 158.94.210.95
- hash: 6606
- file: 83.228.224.244
- hash: 7443
- domain: daroughgan1.com
- domain: daroughgan8hajous30.duckdns.org
- domain: daroughgan8hajous40.duckdns.org
- domain: daroughgan8hajous50.duckdns.org
- file: 62.102.148.154
- hash: 3066
- file: 183.2.143.61
- hash: 10001
- file: 183.2.143.61
- hash: 43350
- file: 223.109.90.98
- hash: 10001
- domain: dawdawf-45472.portmap.host
- url: https://bra.gadgetwalabd.com/
- url: https://bra.alpinematters.com/
- domain: bra.gadgetwalabd.com
- domain: bra.alpinematters.com
- domain: westcoast.westwind.coupons
- domain: strongblow.westwind.coupons
- domain: openfield.westwind.coupons
- domain: apiv4.frostapi.com
- domain: velvet-parrot.com
- file: 178.16.53.96
- hash: 888
- file: 94.237.58.158
- hash: 8000
- file: 65.87.7.237
- hash: 8888
- file: 80.71.235.24
- hash: 8888
- file: 168.245.203.52
- hash: 3790
- file: 168.245.203.54
- hash: 3790
- domain: api-metadata-v6.is
- domain: stormtrack.westwind.coupons
- domain: pearline.pear7pack.coupons
- file: 213.152.161.162
- hash: 5103
- domain: sweetfruit.pear7pack.coupons
- domain: brotherspizza.kozow.com
- domain: pizzashop.kozow.com
- domain: goldpack.pear7pack.coupons
- url: https://trofeyincs.top/login/middleware-json.php
- domain: trofeyincs.top
- url: https://trofeyincs.top/login/auth-response.js
- url: https://trombolistic.com/111-file-r
- url: https://79.141.163.163/320-zip
- domain: farmfresh.pear7pack.coupons
- domain: blackfire.darkfire.coupons
- domain: sys-kernel-update.to
- domain: telemetry-pipe.sh
- domain: hotelement.darkfire.coupons
- domain: smoketrace.darkfire.coupons
- domain: coalpoint.darkfire.coupons
- domain: figbranch.fig08box.coupons
- domain: smallbox.fig08box.coupons
- file: 134.122.140.89
- hash: 7000
- file: 134.122.152.135
- hash: 7000
- file: 134.122.154.171
- hash: 7000
- file: 202.95.17.184
- hash: 7000
- file: 202.95.18.16
- hash: 7000
- file: 103.163.219.252
- hash: 7000
- file: 141.11.213.91
- hash: 8282
- file: 147.45.45.110
- hash: 7777
- file: 193.233.113.137
- hash: 7000
- domain: virtualspeechtherapists.com
- domain: megafilehub1.baby
- domain: kys.li
- file: 5.230.159.62
- hash: 7000
- file: 20.234.151.26
- hash: 6000
- file: 45.61.149.192
- hash: 6000
- file: 45.137.98.189
- hash: 6666
- file: 45.141.26.201
- hash: 6000
- file: 82.26.104.128
- hash: 6000
- file: 91.208.197.30
- hash: 1605
- domain: freshfig.fig08box.coupons
- domain: megafilehub2.baby
- domain: megafilehub3.baby
- domain: megafilehub4.baby
- domain: boxflow.fig08box.coupons
- domain: abnewszamanpaper72.sa.com
- domain: p-93kketo.ru.com
- file: 149.28.151.106
- hash: 443
- file: 89.125.50.65
- hash: 7443
- domain: www.lighter500.com
- domain: vnwns-188-163-102-33.a.free.pinggy.link
- file: 103.109.234.117
- hash: 4782
- domain: plumfield.box671plum.coupons
- file: 193.161.193.99
- hash: 63603
- file: 37.4.250.173
- hash: 63603
- domain: heavybox.box671plum.coupons
- domain: blueplum.box671plum.coupons
- file: 69.5.189.249
- hash: 7701
- file: 15.229.32.243
- hash: 1234
- domain: stockhub.box671plum.coupons
- domain: kiwitransit.kiwi9ship3.coupons
- domain: oceanbird.kiwi9ship3.coupons
- domain: portside.kiwi9ship3.coupons
- domain: globalfruit.kiwi9ship3.coupons
- file: 136.0.157.17
- hash: 9304
- file: 195.177.94.71
- hash: 4000
- domain: bluecloud.skyrain.in.net
- domain: highwind.skyrain.in.net
- domain: clearair.skyrain.in.net
- domain: softmist.skyrain.in.net
- file: 39.101.174.60
- hash: 8084
- file: 119.45.214.169
- hash: 8443
- file: 103.83.86.162
- hash: 1985
- domain: blueocean.deepwave.in.net
- file: 172.86.68.38
- hash: 28886
- domain: 92lottery.coach
- file: 178.116.38.74
- hash: 1912
- file: 95.156.205.13
- hash: 55575
- domain: darkwater.deepwave.in.net
- file: 117.187.252.19
- hash: 10250
- domain: seacurrent.deepwave.in.net
- file: 149.28.151.106
- hash: 8888
- file: 178.236.252.109
- hash: 7443
- file: 44.198.60.243
- hash: 443
- file: 107.189.27.83
- hash: 8443
- domain: saltreef.deepwave.in.net
- domain: hotstone.firepath.in.net
- domain: ashcloud.firepath.in.net
- file: 95.85.239.201
- hash: 443
- domain: glowtrace.firepath.in.net
- domain: coalbase.firepath.in.net
- domain: freezepoint.coldwind.in.net
- file: 192.227.219.80
- hash: 2404
- file: 181.235.2.89
- hash: 2404
- file: 87.106.187.97
- hash: 443
- file: 18.221.223.195
- hash: 443
- file: 159.203.79.29
- hash: 443
- file: 3.148.25.195
- hash: 7443
- file: 155.117.40.221
- hash: 443
- file: 20.39.130.27
- hash: 443
- file: 178.236.252.109
- hash: 3000
- file: 3.140.254.73
- hash: 443
- file: 18.236.192.145
- hash: 80
- file: 51.84.9.169
- hash: 9999
- file: 51.92.40.130
- hash: 1234
- file: 54.91.209.10
- hash: 16930
- file: 89.58.25.125
- hash: 443
- domain: winterblast.coldwind.in.net
- file: 156.225.19.99
- hash: 2324
- domain: snowtrack.coldwind.in.net
- domain: northgale.coldwind.in.net
- domain: lightbeam.brightstar.in.net
- domain: spacecore.brightstar.in.net
- file: 176.108.250.50
- hash: 443
- domain: huntpack.graywolf.in.net
- domain: wildstep.graywolf.in.net
- domain: greytrack.graywolf.in.net
- domain: forestnode.graywolf.in.net
- domain: bluehunt.bluewolf.in.net
- domain: nightrun.bluewolf.in.net
- domain: leadpulse.bluewolf.in.net
- domain: lightcore.coolstar.in.net
- domain: brightpoint.coolstar.in.net
- domain: 423vlwlb.blue128cinder.digital
- domain: y5d9oidj.blue128cinder.digital
- domain: spaceview.coolstar.in.net
- file: 154.219.97.70
- hash: 5758
- file: 154.219.97.142
- hash: 5758
- file: 154.219.97.206
- hash: 5758
- file: 155.138.162.127
- hash: 443
- file: 165.232.45.1
- hash: 8088
- domain: manager.3utilities.com
- file: 16.58.121.239
- hash: 443
- domain: bkn-partr.com
- domain: juandaza2025pu.camdvr.org
- file: 3.148.25.195
- hash: 80
- file: 75.119.151.20
- hash: 80
- file: 3.85.107.177
- hash: 8443
- file: 209.74.82.76
- hash: 3333
- domain: coldbeam.coolstar.in.net
- domain: steelsync.ironwave.in.net
- domain: hardflow.ironwave.in.net
- domain: powerlink.ironwave.in.net
ThreatFox IOCs for 2026-02-19
Description
ThreatFox IOCs for 2026-02-19
AI-Powered Analysis
Technical Analysis
The provided information describes a malware-related threat entry from the ThreatFox MISP feed dated February 19, 2026. This entry is primarily an OSINT (Open Source Intelligence) artifact that catalogs indicators of compromise (IOCs) associated with network activity and payload delivery. However, the entry lacks specific details such as affected software versions, concrete technical indicators, or exploit mechanisms. No known exploits in the wild have been reported, and no patches or remediation links are available. The threat level is marked as medium, reflecting a moderate risk based on the limited data. The technical details include a low threat level (2 out of an unspecified scale), minimal analysis (1), and moderate distribution (3), suggesting some dissemination but limited confirmed impact. The absence of CWEs and specific indicators implies this is an intelligence-sharing record rather than a direct vulnerability or active exploit. This type of entry is typically used by security teams to enhance situational awareness and prepare defenses against potential payload delivery attempts that may emerge from the observed network activity patterns. The lack of detailed technical data restricts deeper analysis but highlights the importance of continuous monitoring of OSINT feeds and network traffic for early detection of emerging threats.
Potential Impact
Given the limited information and absence of known exploits or patches, the immediate impact on organizations is likely low to medium. However, the presence of payload delivery and network activity tags indicates potential risks of malware infections if related IOCs are encountered in operational environments. Organizations relying heavily on OSINT tools or integrating ThreatFox feeds into their security operations may be better positioned to detect and respond to such threats. The lack of specific affected versions or vulnerabilities suggests this is not a targeted exploit but rather a general malware campaign or intelligence artifact. If payload delivery attempts succeed, impacts could include data compromise, system disruption, or lateral movement within networks. The medium severity rating suggests a moderate risk that warrants attention but does not indicate an imminent critical threat. Overall, the impact is contingent on the ability of organizations to detect and mitigate suspicious network activity and payloads associated with these IOCs.
Mitigation Recommendations
1. Integrate ThreatFox and other OSINT feeds into Security Information and Event Management (SIEM) systems to enable real-time detection of related IOCs. 2. Enhance network monitoring to identify unusual payload delivery attempts or suspicious network activity patterns. 3. Employ endpoint detection and response (EDR) tools to detect and block malware payloads early in the infection chain. 4. Conduct regular threat hunting exercises focusing on network traffic anomalies and payload signatures associated with the shared IOCs. 5. Maintain updated and comprehensive incident response plans that include procedures for handling malware infections and network intrusions. 6. Educate security teams on interpreting OSINT threat intelligence and correlating it with internal telemetry for proactive defense. 7. Since no patches are available, focus on hardening network segmentation and access controls to limit potential malware spread. 8. Validate and tune intrusion detection/prevention systems (IDS/IPS) to recognize patterns consistent with the described threat activity. These steps go beyond generic advice by emphasizing the operational integration of OSINT feeds and proactive network and endpoint monitoring tailored to the threat characteristics.
Technical Details
- Threat Level
- 2
- Analysis
- 1
- Distribution
- 3
- Uuid
- f2105172-eac8-48e8-879c-29e61ead3d19
- Original Timestamp
- 1771545787
Indicators of Compromise
File
| Value | Description | Copy |
|---|---|---|
file8.162.5.187 | XWorm botnet C2 server (confidence level: 100%) | |
file193.161.193.99 | NjRAT botnet C2 server (confidence level: 100%) | |
file45.150.32.124 | Stealc botnet C2 server (confidence level: 100%) | |
file45.94.31.178 | DoublePulsar botnet C2 server (confidence level: 100%) | |
file206.123.132.224 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file198.244.201.139 | XWorm botnet C2 server (confidence level: 100%) | |
file172.105.85.143 | XWorm botnet C2 server (confidence level: 100%) | |
file89.167.52.86 | Mirai botnet C2 server (confidence level: 100%) | |
file146.70.181.238 | Remcos botnet C2 server (confidence level: 100%) | |
file172.111.162.252 | Remcos botnet C2 server (confidence level: 100%) | |
file23.26.129.38 | Remcos botnet C2 server (confidence level: 100%) | |
file193.161.193.99 | XWorm botnet C2 server (confidence level: 100%) | |
file193.161.193.99 | XWorm botnet C2 server (confidence level: 100%) | |
file87.242.106.13 | NonEuclid RAT botnet C2 server (confidence level: 100%) | |
file107.152.32.98 | DoublePulsar botnet C2 server (confidence level: 100%) | |
file193.161.193.99 | XWorm botnet C2 server (confidence level: 100%) | |
file157.15.98.138 | MooBot botnet C2 server (confidence level: 100%) | |
file54.89.163.179 | Meterpreter botnet C2 server (confidence level: 100%) | |
file43.209.225.147 | Meterpreter botnet C2 server (confidence level: 100%) | |
file78.12.9.38 | Meterpreter botnet C2 server (confidence level: 100%) | |
file128.90.102.133 | XWorm botnet C2 server (confidence level: 100%) | |
file112.68.47.218 | Mirai botnet C2 server (confidence level: 100%) | |
file147.185.221.181 | XWorm botnet C2 server (confidence level: 100%) | |
file165.232.45.1 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file156.246.95.51 | MooBot botnet C2 server (confidence level: 100%) | |
file3.81.3.110 | Havoc botnet C2 server (confidence level: 100%) | |
file130.164.164.220 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file38.127.8.3 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file45.89.140.80 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file45.89.140.78 | Empire Downloader botnet C2 server (confidence level: 100%) | |
file137.184.61.113 | Aisuru botnet C2 server (confidence level: 75%) | |
file159.65.252.42 | Aisuru botnet C2 server (confidence level: 75%) | |
file165.22.193.95 | Aisuru botnet C2 server (confidence level: 75%) | |
file174.138.15.64 | Aisuru botnet C2 server (confidence level: 75%) | |
file157.245.86.38 | Aisuru botnet C2 server (confidence level: 75%) | |
file178.128.247.58 | Aisuru botnet C2 server (confidence level: 75%) | |
file142.93.137.168 | Aisuru botnet C2 server (confidence level: 75%) | |
file104.131.8.3 | Aisuru botnet C2 server (confidence level: 75%) | |
file165.232.80.66 | Aisuru botnet C2 server (confidence level: 75%) | |
file143.110.139.54 | Aisuru botnet C2 server (confidence level: 75%) | |
file94.73.17.125 | XWorm botnet C2 server (confidence level: 100%) | |
file134.209.55.29 | Aisuru botnet C2 server (confidence level: 75%) | |
file101.132.167.9 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
file144.172.108.230 | Bashlite botnet C2 server (confidence level: 75%) | |
file167.172.48.226 | Aisuru botnet C2 server (confidence level: 75%) | |
file165.227.115.71 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file122.225.30.226 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
file84.38.133.182 | Remcos botnet C2 server (confidence level: 100%) | |
file138.91.32.183 | Sliver botnet C2 server (confidence level: 75%) | |
file165.245.130.101 | Sliver botnet C2 server (confidence level: 75%) | |
file172.86.91.226 | Havoc botnet C2 server (confidence level: 75%) | |
file185.179.189.122 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file24.20.225.162 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file52.146.70.84 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file172.233.46.113 | Unknown malware botnet C2 server (confidence level: 75%) | |
file209.54.103.184 | XWorm botnet C2 server (confidence level: 100%) | |
file138.199.59.6 | Remcos botnet C2 server (confidence level: 100%) | |
file158.94.211.76 | Unknown malware botnet C2 server (confidence level: 50%) | |
file172.94.100.227 | Remcos botnet C2 server (confidence level: 100%) | |
file158.94.210.95 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file83.228.224.244 | Unknown malware botnet C2 server (confidence level: 100%) | |
file62.102.148.154 | Remcos botnet C2 server (confidence level: 100%) | |
file183.2.143.61 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
file183.2.143.61 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
file223.109.90.98 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
file178.16.53.96 | Remcos botnet C2 server (confidence level: 100%) | |
file94.237.58.158 | MimiKatz botnet C2 server (confidence level: 100%) | |
file65.87.7.237 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file80.71.235.24 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file168.245.203.52 | Meterpreter botnet C2 server (confidence level: 100%) | |
file168.245.203.54 | Meterpreter botnet C2 server (confidence level: 100%) | |
file213.152.161.162 | XWorm botnet C2 server (confidence level: 100%) | |
file134.122.140.89 | XWorm botnet C2 server (confidence level: 100%) | |
file134.122.152.135 | XWorm botnet C2 server (confidence level: 100%) | |
file134.122.154.171 | XWorm botnet C2 server (confidence level: 100%) | |
file202.95.17.184 | XWorm botnet C2 server (confidence level: 100%) | |
file202.95.18.16 | XWorm botnet C2 server (confidence level: 100%) | |
file103.163.219.252 | XWorm botnet C2 server (confidence level: 100%) | |
file141.11.213.91 | XWorm botnet C2 server (confidence level: 100%) | |
file147.45.45.110 | XWorm botnet C2 server (confidence level: 100%) | |
file193.233.113.137 | XWorm botnet C2 server (confidence level: 100%) | |
file5.230.159.62 | XWorm botnet C2 server (confidence level: 100%) | |
file20.234.151.26 | XWorm botnet C2 server (confidence level: 100%) | |
file45.61.149.192 | XWorm botnet C2 server (confidence level: 100%) | |
file45.137.98.189 | XWorm botnet C2 server (confidence level: 100%) | |
file45.141.26.201 | XWorm botnet C2 server (confidence level: 100%) | |
file82.26.104.128 | XWorm botnet C2 server (confidence level: 100%) | |
file91.208.197.30 | XWorm botnet C2 server (confidence level: 100%) | |
file149.28.151.106 | Sliver botnet C2 server (confidence level: 90%) | |
file89.125.50.65 | Unknown malware botnet C2 server (confidence level: 100%) | |
file103.109.234.117 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file193.161.193.99 | XWorm botnet C2 server (confidence level: 100%) | |
file37.4.250.173 | XWorm botnet C2 server (confidence level: 100%) | |
file69.5.189.249 | Remcos botnet C2 server (confidence level: 100%) | |
file15.229.32.243 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
file136.0.157.17 | Quasar RAT botnet C2 server (confidence level: 100%) | |
file195.177.94.71 | Loda botnet C2 server (confidence level: 100%) | |
file39.101.174.60 | VShell botnet C2 server (confidence level: 100%) | |
file119.45.214.169 | VShell botnet C2 server (confidence level: 100%) | |
file103.83.86.162 | XWorm botnet C2 server (confidence level: 100%) | |
file172.86.68.38 | VShell botnet C2 server (confidence level: 100%) | |
file178.116.38.74 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
file95.156.205.13 | SpyNote botnet C2 server (confidence level: 100%) | |
file117.187.252.19 | DeimosC2 botnet C2 server (confidence level: 75%) | |
file149.28.151.106 | Sliver botnet C2 server (confidence level: 75%) | |
file178.236.252.109 | Unknown malware botnet C2 server (confidence level: 75%) | |
file44.198.60.243 | Havoc botnet C2 server (confidence level: 100%) | |
file107.189.27.83 | Havoc botnet C2 server (confidence level: 100%) | |
file95.85.239.201 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
file192.227.219.80 | Remcos botnet C2 server (confidence level: 100%) | |
file181.235.2.89 | Remcos botnet C2 server (confidence level: 100%) | |
file87.106.187.97 | Sliver botnet C2 server (confidence level: 100%) | |
file18.221.223.195 | Sliver botnet C2 server (confidence level: 100%) | |
file159.203.79.29 | Sliver botnet C2 server (confidence level: 100%) | |
file3.148.25.195 | Unknown malware botnet C2 server (confidence level: 100%) | |
file155.117.40.221 | Unknown malware botnet C2 server (confidence level: 100%) | |
file20.39.130.27 | Unknown malware botnet C2 server (confidence level: 100%) | |
file178.236.252.109 | Unknown malware botnet C2 server (confidence level: 100%) | |
file3.140.254.73 | Havoc botnet C2 server (confidence level: 100%) | |
file18.236.192.145 | Havoc botnet C2 server (confidence level: 100%) | |
file51.84.9.169 | Meterpreter botnet C2 server (confidence level: 100%) | |
file51.92.40.130 | Meterpreter botnet C2 server (confidence level: 100%) | |
file54.91.209.10 | Meterpreter botnet C2 server (confidence level: 100%) | |
file89.58.25.125 | Unknown malware botnet C2 server (confidence level: 100%) | |
file156.225.19.99 | ValleyRAT botnet C2 server (confidence level: 75%) | |
file176.108.250.50 | Cobalt Strike botnet C2 server (confidence level: 90%) | |
file154.219.97.70 | Ghost RAT botnet C2 server (confidence level: 75%) | |
file154.219.97.142 | Ghost RAT botnet C2 server (confidence level: 75%) | |
file154.219.97.206 | Ghost RAT botnet C2 server (confidence level: 75%) | |
file155.138.162.127 | Sliver botnet C2 server (confidence level: 90%) | |
file165.232.45.1 | AsyncRAT botnet C2 server (confidence level: 100%) | |
file16.58.121.239 | Unknown malware botnet C2 server (confidence level: 100%) | |
file3.148.25.195 | Havoc botnet C2 server (confidence level: 100%) | |
file75.119.151.20 | Havoc botnet C2 server (confidence level: 100%) | |
file3.85.107.177 | Havoc botnet C2 server (confidence level: 100%) | |
file209.74.82.76 | Unknown malware botnet C2 server (confidence level: 100%) |
Hash
| Value | Description | Copy |
|---|---|---|
hash14701 | XWorm botnet C2 server (confidence level: 100%) | |
hash44688 | NjRAT botnet C2 server (confidence level: 100%) | |
hash80 | Stealc botnet C2 server (confidence level: 100%) | |
hash8990 | DoublePulsar botnet C2 server (confidence level: 100%) | |
hash39558 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash7181 | XWorm botnet C2 server (confidence level: 100%) | |
hash20809 | XWorm botnet C2 server (confidence level: 100%) | |
hash853 | Mirai botnet C2 server (confidence level: 100%) | |
hash5675 | Remcos botnet C2 server (confidence level: 100%) | |
hash2620 | Remcos botnet C2 server (confidence level: 100%) | |
hash24024 | Remcos botnet C2 server (confidence level: 100%) | |
hash25340 | XWorm botnet C2 server (confidence level: 100%) | |
hash51173 | XWorm botnet C2 server (confidence level: 100%) | |
hash64370 | NonEuclid RAT botnet C2 server (confidence level: 100%) | |
hash2491 | DoublePulsar botnet C2 server (confidence level: 100%) | |
hash61682 | XWorm botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hash179 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash44819 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash59161 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash2323 | Mirai botnet C2 server (confidence level: 100%) | |
hash17288 | XWorm botnet C2 server (confidence level: 100%) | |
hash7000 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash80 | MooBot botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash443 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash443 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash80 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash80 | Empire Downloader botnet C2 server (confidence level: 100%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8088 | XWorm botnet C2 server (confidence level: 100%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash8088 | Cobalt Strike botnet C2 server (confidence level: 100%) | |
hash9000 | Bashlite botnet C2 server (confidence level: 75%) | |
hash8001 | Aisuru botnet C2 server (confidence level: 75%) | |
hash5505 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash10001 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
hash41000 | Remcos botnet C2 server (confidence level: 100%) | |
hash8888 | Sliver botnet C2 server (confidence level: 75%) | |
hash9090 | Sliver botnet C2 server (confidence level: 75%) | |
hash443 | Havoc botnet C2 server (confidence level: 75%) | |
hash443 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash8080 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash8013 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash6667 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash1909 | XWorm botnet C2 server (confidence level: 100%) | |
hash60736 | Remcos botnet C2 server (confidence level: 100%) | |
hash3232 | Unknown malware botnet C2 server (confidence level: 50%) | |
hash29811 | Remcos botnet C2 server (confidence level: 100%) | |
hash6606 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3066 | Remcos botnet C2 server (confidence level: 100%) | |
hash10001 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
hash43350 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
hash10001 | Xtreme RAT botnet C2 server (confidence level: 100%) | |
hash888 | Remcos botnet C2 server (confidence level: 100%) | |
hash8000 | MimiKatz botnet C2 server (confidence level: 100%) | |
hash8888 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash8888 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash3790 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash5103 | XWorm botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash8282 | XWorm botnet C2 server (confidence level: 100%) | |
hash7777 | XWorm botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash7000 | XWorm botnet C2 server (confidence level: 100%) | |
hash6000 | XWorm botnet C2 server (confidence level: 100%) | |
hash6000 | XWorm botnet C2 server (confidence level: 100%) | |
hash6666 | XWorm botnet C2 server (confidence level: 100%) | |
hash6000 | XWorm botnet C2 server (confidence level: 100%) | |
hash6000 | XWorm botnet C2 server (confidence level: 100%) | |
hash1605 | XWorm botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 90%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash4782 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash63603 | XWorm botnet C2 server (confidence level: 100%) | |
hash63603 | XWorm botnet C2 server (confidence level: 100%) | |
hash7701 | Remcos botnet C2 server (confidence level: 100%) | |
hash1234 | AdaptixC2 botnet C2 server (confidence level: 100%) | |
hash9304 | Quasar RAT botnet C2 server (confidence level: 100%) | |
hash4000 | Loda botnet C2 server (confidence level: 100%) | |
hash8084 | VShell botnet C2 server (confidence level: 100%) | |
hash8443 | VShell botnet C2 server (confidence level: 100%) | |
hash1985 | XWorm botnet C2 server (confidence level: 100%) | |
hash28886 | VShell botnet C2 server (confidence level: 100%) | |
hash1912 | RedLine Stealer botnet C2 server (confidence level: 100%) | |
hash55575 | SpyNote botnet C2 server (confidence level: 100%) | |
hash10250 | DeimosC2 botnet C2 server (confidence level: 75%) | |
hash8888 | Sliver botnet C2 server (confidence level: 75%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 75%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash8443 | Havoc botnet C2 server (confidence level: 100%) | |
hash443 | NetSupportManager RAT botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash2404 | Remcos botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash443 | Sliver botnet C2 server (confidence level: 100%) | |
hash7443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash3000 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash443 | Havoc botnet C2 server (confidence level: 100%) | |
hash80 | Havoc botnet C2 server (confidence level: 100%) | |
hash9999 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash1234 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash16930 | Meterpreter botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash2324 | ValleyRAT botnet C2 server (confidence level: 75%) | |
hash443 | Cobalt Strike botnet C2 server (confidence level: 90%) | |
hash5758 | Ghost RAT botnet C2 server (confidence level: 75%) | |
hash5758 | Ghost RAT botnet C2 server (confidence level: 75%) | |
hash5758 | Ghost RAT botnet C2 server (confidence level: 75%) | |
hash443 | Sliver botnet C2 server (confidence level: 90%) | |
hash8088 | AsyncRAT botnet C2 server (confidence level: 100%) | |
hash443 | Unknown malware botnet C2 server (confidence level: 100%) | |
hash80 | Havoc botnet C2 server (confidence level: 100%) | |
hash80 | Havoc botnet C2 server (confidence level: 100%) | |
hash8443 | Havoc botnet C2 server (confidence level: 100%) | |
hash3333 | Unknown malware botnet C2 server (confidence level: 100%) |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://www.gorscts.shop/ | Unknown malware payload delivery URL (confidence level: 90%) | |
urlhttps://hodorit.com/identity/route-sandbox.php | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://hodorit.com/identity/rate-util.js | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://cirealci.com/froute1 | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://185.33.87.29/zipp2 | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://74.0.48.206/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://mieyabi.com/5j1s.js | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttps://mieyabi.com/js.php | KongTuke payload delivery URL (confidence level: 100%) | |
urlhttp://91.92.243.29/klob | Phorpiex payload delivery URL (confidence level: 100%) | |
urlhttps://polygon.qbetfhwz.xyz/gate/health | Unknown Stealer botnet C2 (confidence level: 100%) | |
urlhttps://rss.gadgetwalabd.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://rss.alpinematters.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttp://158.94.211.76:3232/ceoznp | Unknown malware botnet C2 (confidence level: 100%) | |
urlhttps://bra.gadgetwalabd.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://bra.alpinematters.com/ | Vidar botnet C2 (confidence level: 100%) | |
urlhttps://trofeyincs.top/login/middleware-json.php | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://trofeyincs.top/login/auth-response.js | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://trombolistic.com/111-file-r | SmartApeSG payload delivery URL (confidence level: 100%) | |
urlhttps://79.141.163.163/320-zip | SmartApeSG payload delivery URL (confidence level: 100%) |
Domain
| Value | Description | Copy |
|---|---|---|
domainsystemcore.murta46unprin.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainhodorit.com | SmartApeSG payload delivery domain (confidence level: 100%) | |
domain3mi05cn7h7k4ecsb.frostapi.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainbotnet.exiled.fit | Mirai botnet C2 domain (confidence level: 100%) | |
domainmieyabi.com | KongTuke payload delivery domain (confidence level: 100%) | |
domainstonepath.rockwood.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainsolidleaf.rockwood.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainfruitcase.plum63box.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainredplum.plum63box.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainboxstore.plum63box.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainsweetstock.plum63box.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domaincoldbreeze.snowwind.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainwintertrack.snowwind.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainpurewhite.snowwind.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainchillstream.snowwind.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainquickpath.fastlane.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainroadrunner.fastlane.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domaindrivelogic.fastlane.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainshiftpoint.fastlane.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainshipfresh.mint5ship.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domaingreenleaf.mint5ship.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainswiftcore.cloudbridge.city | ClearFake payload delivery domain (confidence level: 100%) | |
domainlinkflow.cloudbridge.city | ClearFake payload delivery domain (confidence level: 100%) | |
domainopenport.cloudbridge.city | ClearFake payload delivery domain (confidence level: 100%) | |
domain21.yunduans.com | ValleyRAT botnet C2 domain (confidence level: 75%) | |
domainfastgate.cloudbridge.city | ClearFake payload delivery domain (confidence level: 100%) | |
domaingreenleaf.natureway.city | ClearFake payload delivery domain (confidence level: 100%) | |
domainnexit-53294.portmap.host | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainnexit-62461.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domain26068482b66202d6ca29e1bb210288c8.444ef3f25893ae427338085e576fa9fb.traefik.default | Cobalt Strike botnet C2 domain (confidence level: 50%) | |
domainearthmap.natureway.city | ClearFake payload delivery domain (confidence level: 100%) | |
domainwildtrack.natureway.city | ClearFake payload delivery domain (confidence level: 100%) | |
domainriverflow.natureway.city | ClearFake payload delivery domain (confidence level: 100%) | |
domainsmartstep.urbanlab.city | ClearFake payload delivery domain (confidence level: 100%) | |
domainpulseview.urbanlab.city | ClearFake payload delivery domain (confidence level: 100%) | |
domaingridlock.urbanlab.city | ClearFake payload delivery domain (confidence level: 100%) | |
domain52wyvwc0.cabinetslyuka.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainpxkpoxt8.cabinetslyuka.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrightsky.starpoint.city | ClearFake payload delivery domain (confidence level: 100%) | |
domaingoldlight.goldstar.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrightsky.goldstar.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainshinepoint.goldstar.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainnext-dance.gl.at.ply.gg | XWorm botnet C2 domain (confidence level: 100%) | |
domainspacecore.goldstar.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainboxlayer.box1fig7.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainpolygon.qbetfhwz.xyz | Unknown RAT botnet C2 domain (confidence level: 100%) | |
domainfigstore.box1fig7.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainroundpack.box1fig7.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainbaseflow.box1fig7.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domaindesertroad.sandwave.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainraterake.cfd | Unknown Loader botnet C2 domain (confidence level: 100%) | |
domaindrywind.sandwave.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainrss.gadgetwalabd.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainrss.alpinematters.com | Vidar botnet C2 domain (confidence level: 100%) | |
domaindonothg.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domainfrancek.cyou | Lumma Stealer botnet C2 domain (confidence level: 100%) | |
domaingoldensand.sandwave.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainhoustongaragedoorinstallers.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainbiopranica.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainpressureulcerlawyer.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainusedteslabuyers.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainwarmtrack.sandwave.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainpearbox.pack12pear.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainfruitpack.pack12pear.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainlocalstore.pack12pear.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainwww.safebrowse.io | ClearFake payload delivery domain (confidence level: 100%) | |
domaingreenlabel.pack12pear.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainironcore.ironstar.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainsteelsync.ironstar.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainpowerbeat.ironstar.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainhardlink.ironstar.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainmoonlight.eastmoon.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domaindarksky.eastmoon.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domaineastorbit.eastmoon.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainglowpoint.eastmoon.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domaingsm.ftp.sh | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainplm.ftp.sh | Unknown malware botnet C2 domain (confidence level: 100%) | |
domainmintbase.ship48mint.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domaincoldship.ship48mint.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainxxblessingswealths.duckdns.org | XWorm botnet C2 domain (confidence level: 75%) | |
domainyupangco.com | Snake botnet C2 domain (confidence level: 100%) | |
domainfreshroute.ship48mint.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainfastpack.ship48mint.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainkiwitalk.ship46kiwi.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domaingreenbird.ship46kiwi.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainfastkiwi.ship46kiwi.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainskyline.ship46kiwi.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domaincolaba.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainwsc.in.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainhg0088.co.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domain789f.br.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainbertran.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainfrunglewump.gb.net | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainhcolaba.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainwwn.uk.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindaroughgan1.com | Remcos botnet C2 domain (confidence level: 100%) | |
domaindaroughgan8hajous30.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domaindaroughgan8hajous40.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domaindaroughgan8hajous50.duckdns.org | Remcos botnet C2 domain (confidence level: 100%) | |
domaindawdawf-45472.portmap.host | XWorm botnet C2 domain (confidence level: 100%) | |
domainbra.gadgetwalabd.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainbra.alpinematters.com | Vidar botnet C2 domain (confidence level: 100%) | |
domainwestcoast.westwind.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainstrongblow.westwind.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainopenfield.westwind.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainapiv4.frostapi.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainvelvet-parrot.com | SantaStealer botnet C2 domain (confidence level: 100%) | |
domainapi-metadata-v6.is | XOR DDoS botnet C2 domain (confidence level: 100%) | |
domainstormtrack.westwind.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainpearline.pear7pack.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainsweetfruit.pear7pack.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrotherspizza.kozow.com | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domainpizzashop.kozow.com | AsyncRAT botnet C2 domain (confidence level: 75%) | |
domaingoldpack.pear7pack.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domaintrofeyincs.top | SmartApeSG payload delivery domain (confidence level: 100%) | |
domainfarmfresh.pear7pack.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainblackfire.darkfire.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainsys-kernel-update.to | XOR DDoS botnet C2 domain (confidence level: 100%) | |
domaintelemetry-pipe.sh | XOR DDoS botnet C2 domain (confidence level: 100%) | |
domainhotelement.darkfire.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainsmoketrace.darkfire.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domaincoalpoint.darkfire.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainfigbranch.fig08box.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainsmallbox.fig08box.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainvirtualspeechtherapists.com | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainmegafilehub1.baby | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainkys.li | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainfreshfig.fig08box.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainmegafilehub2.baby | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainmegafilehub3.baby | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainmegafilehub4.baby | Unknown Stealer botnet C2 domain (confidence level: 100%) | |
domainboxflow.fig08box.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainabnewszamanpaper72.sa.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainp-93kketo.ru.com | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domainwww.lighter500.com | Remcos botnet C2 domain (confidence level: 100%) | |
domainvnwns-188-163-102-33.a.free.pinggy.link | Quasar RAT botnet C2 domain (confidence level: 100%) | |
domainplumfield.box671plum.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainheavybox.box671plum.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainblueplum.box671plum.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainstockhub.box671plum.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainkiwitransit.kiwi9ship3.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainoceanbird.kiwi9ship3.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainportside.kiwi9ship3.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainglobalfruit.kiwi9ship3.coupons | ClearFake payload delivery domain (confidence level: 100%) | |
domainbluecloud.skyrain.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainhighwind.skyrain.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainclearair.skyrain.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsoftmist.skyrain.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainblueocean.deepwave.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain92lottery.coach | AsyncRAT botnet C2 domain (confidence level: 100%) | |
domaindarkwater.deepwave.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainseacurrent.deepwave.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsaltreef.deepwave.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainhotstone.firepath.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainashcloud.firepath.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainglowtrace.firepath.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaincoalbase.firepath.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainfreezepoint.coldwind.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwinterblast.coldwind.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsnowtrack.coldwind.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnorthgale.coldwind.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlightbeam.brightstar.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainspacecore.brightstar.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainhuntpack.graywolf.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainwildstep.graywolf.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domaingreytrack.graywolf.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainforestnode.graywolf.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbluehunt.bluewolf.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainnightrun.bluewolf.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainleadpulse.bluewolf.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainlightcore.coolstar.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainbrightpoint.coolstar.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domain423vlwlb.blue128cinder.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainy5d9oidj.blue128cinder.digital | ClearFake payload delivery domain (confidence level: 100%) | |
domainspaceview.coolstar.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainmanager.3utilities.com | Remcos botnet C2 domain (confidence level: 100%) | |
domainbkn-partr.com | Havoc botnet C2 domain (confidence level: 100%) | |
domainjuandaza2025pu.camdvr.org | Remcos botnet C2 domain (confidence level: 100%) | |
domaincoldbeam.coolstar.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainsteelsync.ironwave.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainhardflow.ironwave.in.net | ClearFake payload delivery domain (confidence level: 100%) | |
domainpowerlink.ironwave.in.net | ClearFake payload delivery domain (confidence level: 100%) |
Threat ID: 6997a7c9d7880ec89b3e18d1
Added to database: 2/20/2026, 12:16:09 AM
Last enriched: 2/20/2026, 12:16:23 AM
Last updated: 2/20/2026, 4:09:06 AM
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Related Threats
Uncovering Malicious Cryptocurrency Scam Domains and Hacked YouTube Channels
MediumClickFix in action: how fake captcha can encrypt an entire company
MediumFake Homebrew Pages Deliver Cuckoo Stealer via ClickFix | macOS Threat Hunting Analysis
MediumThe Curious Case of the Triton Malware Fork
MediumMaltrail IOC for 2026-02-19
MediumActions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console in Console -> Billing for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.